Published: 23.09.2026
When a malicious actor uses a diffusion model to map an acquaintance’s face onto an explicit body, the resulting image causes immediate, tangible harm. Yet the legal system’s response is anything but immediate. The fundamental constraint facing litigants is that common law evolves incrementally, while generative adversarial networks and diffusion models iterate overnight. Courts are left to apply doctrines designed for physical trespass or printed libel to pixel arrays that never existed in a camera’s viewfinder. The gap between technological capability and legal remedy defines the current landscape.
Plaintiffs typically reach for privacy torts, defamation, or the right of publicity. Each presents distinct trade-offs when applied to AI-generated intimate imagery. Defamation requires a false statement of fact that harms reputation. However, if an image is widely recognised as a deepfake, the defence often argues that no reasonable person would believe it to be true, undermining the falsity or reputational harm elements. Conversely, if the image is convincing enough to deceive, the harm is evident, but proving the specific financial or reputational damage remains difficult.
Privacy torts—specifically intrusion upon seclusion and public disclosure of private facts—face a structural paradox. The disclosure of private facts requires the information disclosed to be true. An AI-generated forgery is, by definition, false. Courts are therefore forced to shoehorn these claims into "false light" publicity, a tort recognised in some jurisdictions but viewed with deep scepticism in others due to its overlap with defamation and free expression constraints.
The right of publicity, which prevents the unauthorised commercial use of an individual's likeness, seems like a natural fit. The constraint, however, is intent and context. Right of publicity statutes generally require commercial exploitation—such as using a celebrity's face to sell a product without consent. The vast majority of AI-generated explicit forgeries are produced for non-commercial reasons: harassment, voyeurism, or status within anonymous online communities. Without a commercial nexus, publicity claims routinely fail, leaving victims without a remedy that matches the harm.
This mismatch forces a fragmented jurisdictional response. In the United States, states like Virginia and California have amended their existing non-consensual intimate imagery (NCII) statutes to explicitly include computer-generated depictions. The United Kingdom has taken a broader approach through the Online Safety Act, placing duties on platforms to remove such material. Yet these statutory patches vary wildly in their scope, evidentiary requirements, and penalties. A victim in one jurisdiction may have a clear criminal pathway, while a victim elsewhere must rely on untested civil theories.
Perhaps the most significant structural barrier is intermediary immunity. In the United States, Section 230 of the Communications Decency Act broadly shields platforms from liability for user-generated content. Unless a specific federal carve-out applies, platforms have no affirmative duty to remove AI-generated forgeries. The European Union’s e-Commerce Directive operates under a similar "notice and takedown" regime, though the Digital Services Act is tightening the obligations for very large online platforms.
The cause-and-effect dynamic is stark: because platforms are shielded, victims must pursue the anonymous creators. Identifying the individual who prompted the model and uploaded the output is often prohibitively expensive and technically complex, especially when routed through VPNs and offshore hosts. The intermediary shield effectively shifts the burden of enforcement entirely onto the individual, creating an asymmetry where the cheapest action is inaction by the platform.
Even where a legal theory fits, the evidentiary requirements present formidable constraints. How does a plaintiff prove they did not consent to the creation of an image that never existed? How do they establish that a specific defendant generated it? The chain of causation is obfuscated by the technology. A user inputs a text prompt; the model generates the pixels. The user did not draw the image, nor did they composite the faces in the traditional sense. This raises novel questions of direct versus indirect liability.
Furthermore, proving the psychological harm requires more than demonstrating the image exists. Courts demand concrete evidence of distress, often requiring expert testimony and documented impacts on employment or physical health. The assumption that the mere existence of an explicit deepfake causes compensable harm is not universally accepted in civil procedure, forcing practitioners to meticulously document the downstream consequences.
Given these structural constraints, practitioners and victims must adopt a multi-pronged, pragmatic approach rather than relying on a single legal theory. Success often depends on combining overlapping claims to increase pressure on both creators and hosts.
Legislatures are beginning to recognise the friction between existing law and generative capabilities. Proposed legislation, such as the SHIELD Act in the United States, and various initiatives across the European Union, aim to create federal or union-wide baselines for criminalising the distribution of non-consensual deepfakes. The EU AI Act explicitly classifies AI systems that generate or manipulate images as carrying specific risks, imposing transparency obligations on deployers.
The trade-off, however, is enforcement capacity. Statutes without funded investigative mechanisms are largely symbolic. Policing the distribution of AI-generated forgeries requires technical expertise that most local constabularies lack. Furthermore, overbroad statutes risk criminalising satire, parody, or consensual adult content, raising significant freedom of expression concerns. The drafting must precisely target the non-consensual distribution of intimate imagery without accidentally criminalising the underlying generative technology itself.
The legal infrastructure surrounding AI-generated intimate forgeries remains a patchwork of adapted torts, fragmented state laws, and untested statutory provisions. Until a cohesive jurisprudence emerges, success in these cases relies on creative lawyering—stacking copyright claims, data protection demands, and traditional tort theories to overwhelm the structural defences of anonymity and platform immunity. The primary takeaway for practitioners is that relying solely on the "deepfake" nature of the image is insufficient; one must attack the unauthorised use of the source data, the processing of personal identifiers, and the documented psychological injury simultaneously.