Author: Staff reporter

  • Not only image abuse hurts women: Korean law challenged

    Not only image abuse hurts women: Korean law challenged

    South Korean law on digital sexual violence is built around images and does not reach cases in which no image is shared, the head of the country’s specialist organisation in the field said on Thursday.

    Kim Yeo-jin, who leads the Korea Cyber Sexual Violence Response Centre, said women’s reputations were being destroyed in private online groups using only their names and personal details.

    “Even if photographs or videos are not distributed, the victim’s reputation can be damaged by their personal information and information implying the harm alone,” she said, according to the newspaper Women News.

    She was speaking at a roundtable convened in Seoul by Amnesty International Korea, a week after the government announced its largest package of measures against digital sex crime.

    Kim said Korean law regulates the making, distribution and possession of images, but that an image is only one of the kinds of digital information used against women. She pointed to what are known in Korea as acquaintance humiliation rooms — private groups, often on Telegram, in which women known to the participants are discussed and degraded. In some of them, she said, the victim’s image never appears.

    South Korea reported 4,273 digital sex crime cases in 2025, up from 2,314 in 2023.

    The plan

    The Ministry of Gender Equality and Family, the Broadcasting and Media Communications Commission and the National Police Agency announced an integrated response plan on 20 August. It would make setting up a site that distributes illegal sexual images a principal offence, allow investigators to connect directly to such a site to gather evidence and delete what is held there, block its advertising revenue and freeze the accounts used to run it.

    Kim described it as “the most advanced plan produced so far”.

    She said deletion and prosecution mattered, but that victims needed to be able to recover even when material was not fully removed and no one was caught.

    “Now we must think about how a victim can live when it has not been 100 per cent deleted,” she said. “The victim must be able to have the power to respond to the harm.”

    The definition

    Kim also questioned the legal definition the system works from. Korean law frames the offence around filming a person’s body in a way capable of arousing sexual desire or causing shame, without their consent.

    She asked what such a body part is, and said the premise had to be broken — that women’s bodies are inherently arousing and that their exposure is shameful. As drafted, she said, the law treats the wrong as an offence against sexual mores rather than against a person.

    Digital sexual violence should be treated as gender-based violence, she said, meaning violence premised on the idea that a woman has broken the norm that she should stay in her place.

    Her recommendations were to change the legal definition, to accept reports of online gender-based violence more broadly than the current categories allow, to expand support provided by women’s organisations, and to build a gender-equal online environment through education.

    Background

    Unbowed reported on 18 August on a South Korean school student referred to prosecutors over an account called 지인평가 — acquaintance rating — on which photographs of female classmates were posted for strangers to rate.

    The newspaper Hankook Ilbo reported from the same roundtable that four in ten requests for data in digital sex crime cases are refused, and described Korean investigators as blocked by foreign platforms.

    Thursday’s session was the first of three Amnesty International Korea is holding this year. The second is to cover the human rights risks of generative artificial intelligence and the responsibility of platforms; the third is to be built around young people’s experiences. Officials from the Broadcasting and Media Communications Standards Commission, the Central Digital Sex Crime Victim Support Centre, the Seoul Metropolitan Police Agency’s cyber investigation unit and the National Assembly Research Service also took part.

  • Two years after Ema died, deputies pass the law in her name

    Two years after Ema died, deputies pass the law in her name

    On Friday 23 August 2024, Ema Bondaruk spent longer than usual at the mirror. The annual school photograph was being taken that day and she wanted her fringe right. Her mother sounded the car horn from the drive, as most mornings.

    That day a boy from her school shared, without her consent, an intimate video of the two of them. It moved through the school’s WhatsApp groups within hours. The school telephoned her mother to say they had taken the boy’s phone and reprimanded him.

    Ema died the following day, Saturday 24 August, at the family home in Longchamps, in Buenos Aires province of Argentina. She was 15.

    Two years on, the law that carries her name has passed the Buenos Aires Chamber of Deputies.

    Deputies approved the Ley Ema on Thursday and sent it to the provincial Senate, where it must pass again to become law. Mayra Mendoza, the Quilmes deputy who introduced it, said she expected it to take effect across the province soon.

    Where the bill stands

    The Ley Ema cleared the second of two committees on Wednesday last week, when the Buenos Aires Chamber of Deputies’ general legislation committee gave it a favourable report, Parlamentario reported. The education committee had approved it the week before.

    It reached the floor at the chamber’s fourth ordinary session of the year, on Thursday 27 August, alongside disability and education measures and an agency to manage seized assets.

    The bill was presented in May by Mayra Mendoza, a deputy for Quilmes with the governing provincial bloc Unión por la Patria, who chairs the education committee. Parlamentario reports that she worked on it with Ema’s mother, Laura Sánchez, and with organisations specialising in digital rights.

    Not everyone has supported it. When the education committee approved the bill this month, the two deputies on it from La Libertad Avanza, the party of President Javier Milei, voted against, according to Página|12.

    What it would require

    The bill would oblige the province’s education authority to teach consent, privacy, digital rights and the ethical and critical use of artificial intelligence. It would update school protocols to set out what staff must do when digital violence occurs — halting the harm, preserving digital evidence, and avoiding revictimising the pupil. And it would make training compulsory and continuing for everyone working in the education system, so that teachers and managers can recognise risk and act.

    It covers cyberbullying, non-consensual distribution of intimate images, impersonation, grooming and harms involving manipulated content and AI.

    The province that got there first

    Santa Fe passed its own version last month. Its Senate approved the Ley Ema unanimously in late July, making it the first Argentine province with a law specifically on digital violence in schools, according to the province’s Defensoría de Niñas, Niños y Adolescentes, the children’s ombudsman.

    That law binds every public and private school in the province at every level, and reaches pupils, teachers, management, families and non-teaching staff. It puts digital citizenship, consent and privacy into the curriculum and guarantees psychological, educational and legal support to victims. Rosario’s city council adopted its provisions on Friday.

    The ombudsman describes the approach in one phrase: no punitivista — not punitive.

    That is deliberate, and Sánchez has explained why. The bill she worked on does not provide prison sentences for those who share the images. “Because these are minors, the idea is to create awareness through some kind of activity or course,” she told Infobae, “so that they realise that what they did can kill the victim.”

  • Tech abuse linked to partner killings: The UK evidence

    Tech abuse linked to partner killings: The UK evidence

    Technology-facilitated abuse featured in two in five intimate partner homicides in the United Kingdom, according to an analysis of statutory death reviews published by The Observer on Tuesday.

    The newspaper examined every report on an intimate partner killing in the government’s Domestic Homicide Review Library up to April. The library records 647 deaths between 2004 and 2022, of which intimate partner cases account for 75 per cent, or 487 reports. In 85 per cent of those the victim was a woman and the perpetrator a man.

    Domestic Homicide Reviews are statutory multi-agency reviews, carried out when the death of a person over 16 is thought to have resulted from domestic abuse. They are conducted with the participation of the agencies involved, which makes them a different kind of record from survey data or press reports.

    Nicole Jacobs, the domestic abuse commissioner, was quoted as saying the analysis showed the “devastating consequences” of technology abuse and called for stronger responses from police and public services. She said she hears “daily” from survivors who report it and are told by police to “simply stop using it, change the password, or block their perpetrator”.

    “As technology evolves, so do abusers’ tactics. Right now our current risk indicator tools, used by the police and other public services to safeguard victims, are not keeping up with the danger of this abuse.”

    What was found

    The Observer identified four methods of technology-facilitated abuse, and a fifth category in which perpetrators restricted a victim’s access to technology. It reports that many cases featured more than one form. Its findings, in its own terms:

    • Harassment — using technology to bombard victims with communication, send threatening messages, and distribute intimate images without consent — was “the most common category, found in 58% of cases”
    • Monitoring — overtly controlling a victim’s use of devices, or checking their messages — “featured in 40% of all cases”
    • Surveillance — covert use of technology to track or record — “featured in a third”
    • Deception — creating fake accounts, or falsifying messages or evidence — “was present in 15% of cases”
    • Restricting access to technology — destroying devices, changing passwords to lock victims out of accounts, preventing them calling for help — in “44% of cases”

    In five cases, the analysis found technology was used to facilitate or conceal the killing itself: perpetrators falsified messages from victims after their deaths, or used surveillance technology to locate them beforehand.

    Not recorded as a risk

    The finding the analysis returns to is what happened when victims reported it.

    In the case of Alice Ruggles, murdered in Gateshead in 2016 after a campaign of stalking that included her social media being hacked, police advised her to block the perpetrator, turn off her phone and delete her social media accounts. No technology-facilitated abuse was taken into account in the risk assessments carried out into her safety.

    In a Dorset case from 2021, in which the review gave the victim and perpetrator the pseudonyms Daisy and Robert, there was no documented physical violence between them. She reported his messages to police one lunchtime and was asked to confirm that she had told him to stop and had blocked his number. Her report was placed in a queue. No officer had attended when, 23 hours later, he entered her home and killed her.

    What the specialists said

    Emma Pickering, head of technology-facilitated abuse and economic empowerment at the charity Refuge, said the findings were likely “the tip of the iceberg”, and that officers “can be slow or reluctant to obtain evidence directly from perpetrators’ devices”. Police forces, she said, need to be resourced “to investigate tech-facilitated crime and secure digital evidence in a timely and effective manner”.

    Refuge research in 2021 found that one in three women in the UK had experienced online abuse, one in six of them at the hands of a partner or former partner — which the charity puts at almost two million women. Its own client figures show a 258 per cent rise in technology-facilitated abuse between 2018 and 2022. Pickering said Refuge has since seen a rise in reports involving wearable technology, hidden cameras and microphones.

    Jen Reed, head of policy at University College London’s gender and tech research lab, said the findings showed technology had “transformed the way perpetrators commit abuse”. Such abuse is “increasingly normalised, with many people not recognising this form of abuse early enough”, she said, and survivors who seek help “are not always taken as seriously as they may be for other forms of abuse”.

    The data stops in 2022

    The most recent death in the published reviews occurred in 2022. Pickering noted that technology has moved on since, “including the unregulated development of AI”.

    The analysis therefore predates the period in which AI-generated sexual imagery became widely available — and predates every development this publication has reported this month.

    Six days earlier, a scoping review published in PLOS One had found that evidence on escalation from online abuse to offline violence “remains extremely limited”, identifying a single study tracing that progression among the research it examined for sub-Saharan Africa. The two documents measure different things in different places. Read together, they suggest the evidence base is thin because few have looked.

  • South Korea moves against illegal image websites

    South Korea moves against illegal image websites

    South Korea will seek to criminalise the act of setting up a website that distributes illegal sexual images, and to give investigators the power to break into such sites to gather evidence and delete the material held on them, under a plan announced in Seoul on Thursday.

    The Ministry of Gender Equality and Family, the Broadcasting and Media Communications Commission and the National Police Agency published the “integrated response plan for illegal sites” at the Government Complex in Jongno, central Seoul. Minister Won Min-kyung presented it alongside Shin Young-gyu, director-general of the commission’s broadcasting and telecommunications user policy bureau, and Yoo Jae-sung, acting commissioner general of the police, according to Hanguk NGO Sinmun.

    The premise is that removing material has stopped working. “As long as there is a structure through which sexual exploitation material is distributed, digital sex crime repeats,” a ministry official told MBC, “so we have set the direction of neutralising the illegal sites.”

    The numbers behind it

    Digital sex crime in South Korea fell for three years and then turned. Hanguk NGO Sinmun, citing the ministry, reported 4,439 cases in 2021, 3,201 in 2022 and 2,314 in 2023, before a rise to 3,579 in 2024 and 4,273 in 2025.

    Refusals have risen alongside. The share of deletion requests from the Central Digital Sex Crime Victim Support Centre that went unmet climbed from 24.4 per cent in 2022 to 28.5 per cent in 2025, the same report said.

    Opening a site as an offence

    The Ministry of Justice intends to amend the Act on Special Cases Concerning the Punishment of Sexual Crimes so that a person who opens an illegal site can be punished as a principal rather than as an accessory.

    Hanguk NGO Sinmun reported the analogy the government is using: criminal law already punishes not only the person who gambles but the person who opens the gambling house.

    “Lawful hacking”

    The plan would introduce what the government calls an active defence system, and what Korean coverage has uniformly rendered as “lawful hacking” — investigators connecting directly to an illegal site to collect evidence and delete the original data held there.

    Hanguk NGO Sinmun reported that comparable powers operate in the United Kingdom and Australia. British police and intelligence agencies may carry out equipment interference, the remote access of computers and phones, under the Investigatory Powers Act 2016, subject to approval by both a secretary of state and a judicial commissioner. In Australia, data disruption warrants introduced in 2021 allow the federal police and the Australian Criminal Intelligence Commission to modify, add, copy or delete data in order to frustrate serious offences, and are issued by a judge or a nominated tribunal member.

    Police would also form special investigation teams of 20 officers at the Seoul, Busan, Gyeonggi Nambu and Jeonnam agencies, working on their own initiative against those running the sites rather than waiting on complaints, and would widen cooperation with foreign bodies including the FBI and the National Center for Missing and Exploited Children.

    Cutting the money

    The government intends to legislate a basis for prohibiting advertising on such sites, which Hanguk NGO Sinmun described as their main source of revenue, and to freeze accounts used to run them through the enhanced due diligence provisions of the Act on Reporting and Using Specified Financial Transaction Information.

    It also plans to work with the US Federal Trade Commission to sanction platform operators that repeatedly refuse deletion requests, and to create an emergency blocking mechanism allowing the minister to ask telecommunications carriers directly to cut access. Platform operators would be placed under a duty to delete and report child and youth sexual exploitation material when they find it.

    The domain problem

    The plan addresses directly the tactic that has defeated blocking elsewhere. Hanguk NGO Sinmun reported that sites are reopening under a new domain within one to two hours of being blocked — a practice Korean officials call domain shuttling.

    The government will fund research to detect it automatically, and build a system that blocks a new domain without a fresh review where its similarity to the blocked site is high. It also plans to develop means of blocking encrypted traffic, rather than relying on existing decryption methods.

    The wider picture

    The proposal arrives three days after the Centre for Information Resilience, a UK-based open-source investigations organisation, published findings on nudification bots that reached a similar conclusion by a different route: that the visible service is the cheapest part of the operation to replace, and that referral networks, backup domains, payment routes and upstream providers survive its removal. CIR reported bots carrying serial numbers in their names, which it read as a count of accounts already taken down and replaced.

    It is also the fourth Korean government move on this subject in ten days, following a review of the legal framework, an expert meeting on AI deepfake offences and work by the Sentencing Commission on guidelines for digital sex crimes.

  • Minnesota’s nudification ban goes too far: Justice Department

    Minnesota’s nudification ban goes too far: Justice Department

    The United States Justice Department has told a federal court that Minnesota’s ban on nudification technology reaches further than federal law and risks “paralyzing the AI industry and hampering United States leadership in AI”.

    The 14-page statement of interest, filed on 18 August and read by Unbowed, was submitted under a provision allowing the attorney general to direct any officer of the department to attend to the interests of the United States in a pending case. It is signed by Associate Attorney General Stanley E. Woodward Jr, Deputy Associate Attorney General John K. Adams, and two counsel to the associate attorney general, Michael Weisbuch and Henrique Carneiro.

    It intervenes in a challenge brought by Elon Musk’s xAI, which asked Judge Donovan W. Frank in St Paul the following day to suspend the law while its case proceeds. Frank took the motion under advisement after a two-hour hearing and has not ruled. Attorney General Keith Ellison attended in person, according to the court’s minute entry.

    The department states its own interest

    The filing opens by placing the department between the two sides. “Like the Attorney General of Minnesota, the United States has a compelling interest in combating harmful computer-generated sexual imagery and obscenity,” it says. “And like xAI, the United States has an interest in promoting the safe and productive use of Artificial Intelligence.”

    It goes on to argue that federal law is “carefully calibrated” where Minnesota’s is not, and that the state statute “sweeps up constitutional and productive conduct not prohibited under federal law”.

    A footnote answers an objection before it is made. The statute under which the department filed “contains no time limitation and does not require the Court’s leave”, it says, citing two district court decisions. The same footnote adds that federal law does not confine the attorney general to filing statements of interest, that he “may intervene in any case to vindicate the supremacy of federal law”, and that the United States “reserves all rights”.

    MPR News reported that Assistant Attorney General Janine Kimble asked the court to strike the memo, arguing it was filed after the deadline for amicus briefs and that the federal government has no clear stake in the case. The court docket records the department’s submission as a motion to appear as amicus curiae; the document itself is styled a statement of interest and asserts that no permission is required. No ruling on it appears on the docket.

    The court had already turned away one set of would-be supporters of xAI. On 12 August, Frank refused permission to the Foundation for Individual Rights and Expression, the First Amendment Lawyers Association and the Woodhull Freedom Foundation, writing that “the expedited timeline of this case does not allow for additional briefs”. He had earlier admitted a brief from the Liberty Justice Center supporting xAI, and invited briefs supporting the attorney general.

    What the law does

    HF 1606 took effect on 1 August. It exposes companies to penalties of as much as $500,000, the department’s filing records, “for each unlawful access, download, or use” of their technology to nudify an image or video.

    It is a strict liability rule. Liability turns on whether a user altered an image in a proscribed way, not on whether the company knew or intended it.

    Minnesota’s own account of the law’s purpose, quoted in the federal filing from the state’s opposition brief, is that it exists to prevent child sexual abuse material and “harmful weaponizations of nudity”. The bill passed the state Senate unanimously and the House with a single dissenting vote, MPR News reported.

    The argument about a definition

    The department’s most specific criticism concerns a single defined term, and it is sharper than it first appears.

    Minnesota took its definition of “intimate part” from a criminal sexual conduct statute written about non-consensual physical contact rather than about images. That definition covers the inner thigh and the breast, male or female, alongside the genital area, groin and buttocks. Federal law, under the TAKE IT DOWN Act, reaches “the uncovered genitals, pubic area, anus, or post-pubescent female nipple”.

    The department then makes the point that gives the argument its force. Minnesota has a separate deepfake statute of its own, and that one defines intimate parts narrowly, in terms close to the federal wording. The state had a tighter definition available in its own statute book and did not use it.

    Hence the example that has been widely reported: an artificially generated image of a shirtless man in a swimming pool would fall outside federal law, the department writes, and inside Minnesota’s.

    Consent, knowledge and public concern

    Three further gaps are identified. Federal offences require that an act be done knowingly, or else give platforms a chance to remove an image after notification before civil liability attaches. HF 1606 does neither.

    Federal law applies where an adult has not consented. Minnesota’s has no equivalent provision, so that on the department’s reading it reaches a platform even where a user made an image of themselves.

    Federal law also exempts matters of public concern, and material used for medical, scientific or educational purposes. Minnesota offers what the filing calls “a nebulous savings clause” for technological or artistic skill and judgment.

    The department describes the federal scheme it prefers at some length: the PROTECT Act of 2003, and the TAKE IT DOWN Act signed by President Trump in May 2025, which criminalises publishing intimate images including digital forgeries and requires platforms to remove flagged material within 48 hours, enforced by the Federal Trade Commission. The filing notes that xAI is itself a covered platform under that Act.

    The policy argument

    The last section of the filing is about artificial intelligence rather than sexual imagery. It cites executive orders stating that it is United States policy to sustain “global AI dominance” through “a minimally burdensome national policy framework” — one national standard rather than, in the orders’ words, “50 discordant state ones”.

    It cites a memorandum by the attorney general of 9 January 2026 establishing an Artificial Intelligence Litigation Task Force, which it says recognises that state AI laws can interfere with American AI leadership.

    The filing does concede a limit. The United States has determined not to interfere with “states’ rights to pass prudent laws that are not unduly restrictive to innovation”, it says, quoting the administration’s AI action plan of July 2025.

    Its closing line is that as the country remains in the earliest days of a technological revolution and “in a race with adversaries for supremacy within it”, states “must be careful not to impose excessive measures that hinder American national and economic security”.

    In court

    xAI’s attorney Robert Dunn told the hearing the statute is too broad and has no exception for consent, artistic expression or parody. “There can be no question that the state’s purpose is to restrict speech,” he said, according to MPR News. Courthouse News, cited by The Next Web, reported him saying the state “would punish xAI for allowing a user to nudify themselves”. He said the company already forbids sexualised images of real people without consent and has banned thousands of users.

    Kimble argued that terms of service are not working, noting that xAI is still reporting tens of thousands of users who create such images. “The repercussions only happen after the fact,” she said, according to The Next Web: someone has to see an image, report it, locate it, and the user has to be within reach of a court. Distribution is already unlawful; the state’s case is that creation has to be reached as well. She described the law to the court as a way of “stopping the issue at its source”, MPR News reported, and pointed to lawsuits brought by families who say the company’s platform was used to depict their children in child sexual abuse material.

    Where it stands

    Frank refused an emergency restraining order on 31 July, writing that xAI had filed “nearly three months after the law was signed, and only three days before the law is set to take effect”, and that “such a delay in bringing the action and the motion suggests that harm is not immediate”. He set an expedited schedule instead and heard the injunction on 19 August.

    The law remains in force. After the hearing, Ellison’s office filed a motion to dismiss, arguing xAI has no standing to assert the First Amendment on behalf of its users. That is listed for 5 November.

    An 84-page transcript of the hearing has been filed but is restricted from public release until 17 November.

    Outside the courthouse

    Senator Erin Maye Quade, a Democratic-Farmer-Labor member who wrote the law, said companies should not be permitted to offer such tools at all. “They are giving people the tool to do it,” she said, according to MPR News. “This is technology that does not need to exist. Our law is narrow. It is specific to the conduct we want to regulate. It implicates nothing else.” She said that if Frank rules against the state she will bring a new ban to the legislature next session.

    Jessica Guistolise, who told Minnesota lawmakers she was the subject of AI-generated pornographic videos made without her consent and was left afraid to leave her house, joined them outside court. “I’m ready to continue to support this and offer my story and my experience all the way up to the Supreme Court if that needs to happen,” she said.

  • Korean police shelved a deepfake case. The survivors filed their own.

    Korean police shelved a deepfake case. The survivors filed their own.

    A South Korean school student has been referred to prosecutors over allegations he produced sexual deepfakes of about 20 female classmates, a year after police received an allegation about the same account and closed it because they could not identify who was behind it, according to the regional publication Kyungin Ilbo.

    The cyber investigation unit of the Gyeonggi Nambu Provincial Police Agency said it had sent the case to prosecutors under the Act on Special Cases Concerning the Punishment of Sexual Crimes, in announcements reported on Tuesday by South Korean media. Police alleged the student had used photographs of girls he knew, without their consent, to make sexual images and then to post them online.

    Kyungin Ilbo said the account was called “지인평가” — acquaintance rating. On it, the paper reported, he posted photographs of girls he knew and asked others to rate their appearance, alongside deepfake material made using their photographs and video.

    The case that was closed

    Kyungin Ilbo reported that in October last year a complaint reached Hwaseong West Police Station alleging that someone was running what the publication described as a room for humiliating acquaintances. It said the station could not identify a suspect and therefore classified the case as unsolved and closed it. It said the student was subsequently identified as the suspect.

    Kyungin Ilbo said it was the survivors that got the case reopened after they filed criminal complaints early this year.

    How many

    Police estimated the number of victims at about 20, according to Kyunghyang Shinmun. Kyungin Ilbo quoted a parent as saying the number confirmed through the accused’s own lawyer was more than 30.

    The school

    Without attributing the information to a named source, Kyungin Ilbo said it understood that a school violence committee had ordered the student to transfer to another school, and that he has since applied to leave education.

    The paper quoted another parent as saying the committee met only after parents made an anonymous tip-off to the school, and that parents have had to arrange psychological support for their children themselves.

    Another parent told Kyungin Ilbo their child “is living with the anxiety that someone around them may have been involved in the crime”, and feels “considerable fear” in everyday activity — using social media, going to school.

    The school has not commented publicly, and Kyungin Ilbo does not report a response from it.

    Not unusual

    According to figures published by the National Police Agency in November 2025 and reported by the Korea Herald, teenagers are the largest group of suspects in South Korean deepfake sexual offences: about 62 per cent of those arrested for such offences were teenagers.

    The same figures, as reported by the Korea Herald, recorded 3,557 people detained for cyber sexual violence between November 2024 and October 2025, with deepfake offences the largest single category at 1,553 cases, a rise of 47.8 per cent on the previous year.

    Since October 2024, the Act on Special Cases Concerning the Punishment of Sexual Crimes has made producing such material an offence whether or not it is distributed, carrying up to seven years’ imprisonment.

  • Sexual imagery was 96 per cent of deepfake files researchers found

    Sexual imagery was 96 per cent of deepfake files researchers found

    Sexualised imagery made up 96 per cent of 3.46 million synthetic files recorded across 821 deepfake attacks worldwide in the first half of 2026, according to a report by deepfake detection company Resemble AI.

    One in six of the total attacks detected involved non-consensual intimate imagery of adults or children. But those 137 incidents produced nearly all of the material.

    An incident in its dataset is one reported event no matter the size. Resemble AI said 87 per cent of all the files it counted — about 3.01 million — came from one tool, Grok. The Center for Countering Digital Hate puts the number of sexualised images produced during the Grok episode at three million. Set against roughly 3.32 million sexualised files in total, that event accounts for about nine in ten.

    Still images predominate

    A still image appears in 90.5 per cent of the 137 incidents rather than other forms of content.

    Resemble AI says that is due to the minimal effort required. It characterises this category as impulsive and without repeat targets: the opposite of political disinformation.

    Who was targeted

    Four in five of these attacks involved women or a mixed group when gender could be determined — 39 of 49 incidents. Thirty-six identified women only, three women and men, and two men only, with eight unspecified in the coverage. The report notes the first male victims appearing in its data, through extortion and fandom cases.

    The single largest event was down to Grok. On 29 December, X gave every user a one-click image-editing button powered by Elon Musk’s chatbot. xAI put the feature behind a paywall on 9 January and restricted “undressing” prompts on 14 January.

    Citing the Center for Countering Digital Hate, the report puts output at three million sexualised images — 190 a minute across an 11-day window, and 84 times the combined output of the five largest dedicated deepfake websites. Around 23,000 appeared to depict children: one in every 130 images, or one every 41 seconds. The New York Times separately estimated 1.8 million posts likely containing sexualised images of women.

    What the report says about its own limits

    The dataset is built from 1,760 news reports, so it counts reported attacks rather than attacks. And sexual imagery is the category most likely to surface late: 17 per cent of child sexual abuse material incidents were documented more than 90 days after the event, against 3 per cent of every other category. All four cases that took more than 250 days to surface reached the public record only through court proceedings.

    The company also calculates that the 14,915 documented victims of sexual imagery represent $2.24 billion in potential liability under the U.S. statute allowing $150,000 per victim.

  • Sexual deepfake apps on Apple’s App Store, research finds

    Sexual deepfake apps on Apple’s App Store, research finds

    Updated on Aug. 20

    Nearly 50 apps on Apple’s App Store were found to deliver sexually explicit face- and body-swapping once installed, according to research published by Copyleaks, an AI-detection company.

    Apple, responding to a request for comment from Unbowed, said only three examples were provided by Copyleaks in its article and all had been removed on July 29, two weeks before Copyleaks released its report. It had no record of Copyleaks reporting any of the apps to Apple.

    Apple said App Review Guidelines specifically prohibit overtly sexual or pornographic content, including ‘nudification’ apps and that the App Review team works round the clock to keep the App Store a safe and trusted place.

    Copyleaks’ research describes listings that disclose no sexual capability. The advertising that brings users to those listings runs on TikTok. And a number of the apps block screenshots and screen recording, which makes it harder for researchers or journalists to document what the apps actually generate, it says.

    Copyleaks says its researchers reviewed the apps over a six-month period.

    TikTok did not immediately respond to a request for comment.

    What the research describes

    Every app reviewed promoted benign features in its App Store listing, Copyleaks said, and none disclosed that it could generate sexualised imagery. Users encountered the explicit features only after downloading. The company said several user reviews came from people who had downloaded an app on the strength of its description and found the sexual content afterwards, including one reviewer who identified themselves as under 18.

    Almost all the apps operated on subscription or virtual-credit models, with sample templates viewable free and generation requiring payment. Some, Copyleaks said, may not work at all: several appeared to rely on pre-recorded or wholly synthetic material rather than processing uploaded photographs, and reviews reported apps that stopped functioning after payment.

    The finding with the widest implications concerns discovery. Virtually all the apps were found through advertisements on TikTok, Copyleaks said, and the advertisements were sexual in nature. In several cases, the company said, they explicitly promoted non-consensual use.

    “There is virtually no barrier to entry for these services anymore,” Copyleaks chief executive Alon Yamin said in the research.

    Apple said that when its App Review team identified malicious and fraudulent apps, they were analyzed in order to strengthen detection models. It noted that customers can visit https://reportaproblem.apple.com to report offensive, illegal, or abusive content, as well as scams or fraudulent activity on the App Store.

    The end of the chain

    The Independent also reported that it had found apps on Apple’s App Store offering to “strip” uploaded photographs.

    That app listed dozens of generated scenarios into which a user could place a photograph of a real person, the paper reported, including one labelled “bedroom rape”, each illustrated with graphic video.

    The app was removed after the publication flagged it to Apple, it said. Apple declined to comment directly but pointed to guidelines prohibiting overtly sexual or pornographic content, and said a number of the apps flagged to it had added violating features after being reviewed — which, if correct, describes a review process that inspects an app once and not again.

    Janaya Walker, interim director of the End Violence Against Women Coalition, told the Independent that such material allowed users to “role play violent and dehumanising acts against women” and had a “desensitising effect”, and that images created this way were “directly used to intimidate, threaten and harass women”. She called for legally binding safety-by-design requirements on platforms.

    Regulation shortfall

    The Online Safety Act reaches TikTok. By Ofcom’s account, it does not reach the App Store.

    Asked by the Independent about generative AI pornography sites and apps, an Ofcom spokesperson said the regulator was “actively assessing” their compliance with the Act and would “not hesitate” to act on failings. The spokesperson then added: “We have no powers to regulate app stores at present, but have been tasked with assessing the role they play in children encountering harmful content. We will report our findings later this year.”

    Updated on Aug. 20 at 11.09 a.m. ET with comment from Apple

  • India’s Supreme Court leaves harmful takedowns to the government

    India’s Supreme Court leaves harmful takedowns to the government

    India’s Supreme Court told three government ministries to look at a proposal for an emergency mechanism to take down non-consensual intimate images, deepfakes and online threats rather than taking on the petition itself.

    The petition was brought by Narender Kumar Goswami. He sought what he called a constitutionally compliant, time-bound, URL-specific and judicially supervised emergency mechanism to address five categories of harm: threats of physical or sexual violence or death; doxxing that creates a reasonable fear of harm; disclosure of the details, photographs or school information of children; non-consensual intimate, morphed, synthetic or AI-generated material; and deepfake impersonation causing immediate grave harm to safety, dignity, livelihood or reputation.

    His case rested on what he called the “speed gap” between digital harm and legal remedy. “A specific threat of rape or murder may silence a woman from public discourse before the police or courts act,” the petition said. A deepfake can destroy identity, livelihood, family life and reputation “before forensic truth can catch up”. Therefore, it argued, “delay in remedy may itself become denial of remedy”.

    What the court did

    A bench of Chief Justice Surya Kant and Justices Joymalya Bagchi and V. Mohana accepted the issues were comprehensively raised, and disposed of the case.

    “Since remedial actions are required to be taken by the addressee authorities, we dispose of this petition at this stage,” the order reads, directing the ministries of electronics and information technology, home affairs, and law and justice, “and all other stakeholders”, to examine a representation Goswami had sent them on 22 June and take such measures “as may be required in accordance with law”.

    The chief justice put it to him directly: “How to detect them, what preventive measures — these are to be taken by domain experts. You have already raised this issue through a representation, and therefore, we direct the authorities first of all to examine that.”

    Goswami had told the court he received no effective decision on that representation.

    The gap he was pointing at

    India is not short of takedown deadlines. Amendments to the information technology intermediary rules, notified on 10 February and in force from 20 February, require platforms to remove unlawful synthetically generated content within three hours of a valid government or court order, down from 36. For sensitive categories, including non-consensual sexual imagery and impersonation, the window is two hours. Failure costs a platform its safe harbour protection under section 79 of the Information Technology Act.

    On paper those are among the fastest statutory deadlines anywhere. But they run from an order a woman must first obtain.

    Goswami’s petition accepted that the existing rules recognise urgency, and argued they provide no uniform, judicially supervised, time-bound route. Criminal law is no answer either, it said: the Bharatiya Nyaya Sanhita of 2023 covers criminal intimidation, stalking, defamation and impersonation, but prosecution “punishes the offender; it does not by itself guarantee immediate, URL-specific disabling of harmful content or preservation of digital evidence before viral dissemination”.

    He proposed safeguards against overreach — that any disabling order be reasoned, confined to the content complained of, limited to India, subject to evidence preservation, notified to the uploader where identifiable, and followed by a hearing within a short period. He also asked the court to have the government convene an expert committee including the National Commission for Women, the child rights commission, CERT-In, and free speech, privacy and women’s safety specialists.

    Two weeks earlier

    On 28 July the same three judges urged the government to make “digital arrest” — a fraud in which victims are convinced they are under remote police detention — a standalone offence, and pressed for a law on deepfakes. Solicitor General Tushar Mehta told them a draft bill was coming that would cover both. It is expected in the current session.

    Across both hearings the pattern is the same: the court naming the gap, and the government saying it will fill it.

  • Online violence is pushing Kenyan women out of politics, UN study finds

    Online violence is pushing Kenyan women out of politics, UN study finds

    Online violence is driving women out of politics in Kenya, and the patterns that disfigured the last general election are already repeating ahead of the next one, a UN Women study has found.

    It is happening in a country where a man convicted of sharing a woman’s intimate images without her consent faces a maximum compensation order of KES 200,000 ($1,500). A man who pirates music can be fined up to KES 5 million, 25 times more. UN Women calls the gap “a statement of values encoded in statute”, one that says “women’s bodily integrity, dignity and psychological well-being are valued well below commercial intellectual property”. The compensation cap comes from the Computer Misuse and Cybercrimes Act 2018, the fine from the Copyright Act.

    The Cost of Silence, published last month by UN Women’s Kenya country office under its DigiKen programme, describes itself as the first comprehensive assessment of technology-facilitated gender-based violence in the country. It says its chapter on political participation offers the most detailed picture yet of the effect on Kenyan women in public life, at a moment when the 2027 general election is approaching and the 2022 patterns are, on the testimony of multiple respondents, “already repeating and intensifying”.

    How candidates were attacked

    Researchers documented coordinated campaigns that combined online character assassination with physical intimidation. Online attacks on women candidates were in some cases followed by organised disruption of their rallies, which the report says suggests digital attack networks were coordinating with operatives on the ground.

    AI-generated deepfakes of women candidates were circulated inside their own constituencies, largely through community WhatsApp groups the candidates could not join and had no means of correcting.

    Analysis by Pollicy and the National Democratic Institute, cited in the study, found 55.7 per cent of the Facebook accounts of women candidates received online violence during the 2022 election. Eighty per cent of women candidates stayed active online throughout that campaign, against 93 per cent of men.

    Eight moderators for a continent

    The report attributes to its own interviews a figure it does not source elsewhere: that Meta has eight content moderation staff covering the whole of Africa, which it describes as a continent of 1.4 billion people speaking more than 50 languages. It calls that “not merely a resource allocation problem” but “a governance design problem”.

    It also records participants describing platforms rolling back moderation between 2023 and 2025 — content once removed being reinstated, human teams replaced by automated systems the report says cannot read Sheng or Swahili or the cultural context of Kenyan gendered abuse, and trust and safety teams cut entirely. The timing, it says, “coinciding with the approach of Kenya’s 2027 electoral cycle, is a cause for specific concern”.

    What participants said

    The study is qualitative: 22 key informant interviews and focus groups in Nairobi, Kisumu and Mombasa. Participants are identified by role only, under the consent protocol agreed with them.

    One survivor described a former partner posting her intimate photographs in 2018 to a Facebook group tied to her home village. “Everyone had access. Messages and calls came from every direction. It was a very dark, lonely period.”

    Another respondent said: “The online-to-offline continuum is not theoretical. It is the story of how women are dying in this country.”

    A third pointed at the vacuum the report wants filled. “We have policies in the country, but there is no policy that addresses TFGBV directly. Nobody knows what to call it.”

    The first of its seven recommendations is a standalone legal framework with an official definition, closing gaps in the Sexual Offences Act. Amendments to that Act, reported by the Daily Nation on 4 August, would create offences of making or sharing sexually explicit deepfakes, sextortion, stalking and voyeurism — two decades after it was passed, and two years before Kenyans vote again.