Category: Law & Policy

  • Platforms under pressure in UK over intimate images

    Platforms under pressure in UK over intimate images

    Online platforms operating in Britain have until the end of this month to put automated detection technology in place to stop the spread of non-consensual intimate images, including AI-generated deepfakes, or to demonstrate that what they do instead works as well.

    The communications regulator Ofcom opened an enforcement programme on 9 September to monitor how technology firms are meeting that duty. Companies that fail to comply face fines of up to 10 per cent of their global annual revenue.

    The technology at issue is hash matching, which converts an image into a digital fingerprint that can be checked against later attempts to upload the same picture, without the image itself having to be compared by hand or leave the victim’s possession.

    “Non-consensual intimate image abuse can have a devastating impact on victims, causing lasting distress and harm,” said Almudena Lara, Ofcom’s online safety policy development director.

    “Technology companies now have a legal responsibility to put the right tools in place to stop this kind of deeply harmful content spreading on their services. The deadline is fast approaching and firms that ultimately fail to comply with their duties can expect us to take robust action under our enforcement programme.”

    The helpline behind the database

    Ofcom said it had partnered with SWGfL, the organisation that runs the StopNCII.org hash database and the Revenge Porn Helpline, to share information and evidence on what works. It continues to recommend that platforms use StopNCII’s tool.

    David Wright, SWGfL’s chief executive, said demand on the helpline was growing sharply, and that the organisation’s research suggested more than 369,000 women in the United Kingdom experience this abuse each year.

    “Requiring platforms to adopt hash matching is a vital shift toward stopping this abuse before it spreads, rather than only responding once the damage is already done,” he said. “The infrastructure is already in place and ready for platforms to use.”

    Forty-eight hours

    Ofcom said it would consult by the end of this year on strengthening its Illegal Harms Codes of Practice to reflect a change in the law that will require platforms to take down reported non-consensual intimate images within 48 hours.

    That is the same deadline set by the Take It Down Act in the United States, under which a man in Ohio was sentenced to 15 years last week in the first prosecution brought since the law was enacted.

    A wider call for evidence

    Separately, Ofcom has asked academics, survivor and victim support groups and others for evidence on how women’s and girls’ experiences online have changed since it published guidance for a safer life online for women and girls last year. Responses are due by 6 November.

    Alongside intimate image abuse, that guidance asked services to reduce the reach and spread of misogynistic abuse and sexual violence, prevent coordinated pile-ons and harassment, strengthen privacy protections including limits on location-sharing features, and improve reporting and support tools for victims.

    Ofcom said it would publish a report next summer on how far the industry had got. If the industry falls short, it said, it will consider making formal recommendations to government on where the Online Safety Act may need to be strengthened.

  • Fifteen years in the first sentence under America’s deepfake law

    Fifteen years in the first sentence under America’s deepfake law

    A man who used artificial intelligence to create sexual images of women he knew and sent them to their colleagues and families has been sentenced to 15 years in prison, in the first case brought under the American law against non-consensual intimate imagery.

    James Strahler II, 37, of Columbus, Ohio, was sentenced to 180 months by Chief US District Judge Sarah D. Morrison on Tuesday. He pleaded guilty in April to cyberstalking, producing obscene visual representations of child sexual abuse, and publication of digital forgeries.

    The last of those charges falls under the Take It Down Act, the law enacted in 2025 that prohibits the non-consensual online publication of intimate images and AI forgeries, and requires platforms to remove such material within 48 hours of a valid report. The Department of Justice said Strahler was the first person in the country convicted under it.

    What he did

    Between December 2024 and June 2025, Strahler sent harassing messages to at least six adult women, including nude images of them that were both real and AI-generated, the department said.

    He used AI to create pornographic videos showing at least one of the women having sex with her father, and sent them to her colleagues.

    He contacted the women’s mothers and demanded nude photographs of them, threatening to circulate the images he had made of their daughters if they refused. He telephoned the women and left voicemail messages that were sexually explicit or threatened rape, and referred to their home addresses.

    Strahler had installed more than 24 AI platforms and more than 100 web-based AI models on his telephone.

    He also created obscene AI material depicting children, using the faces of boys from his own community, and posted more than 700 images of real and animated people to a website dedicated to child sexual abuse material. A further 2,400 images and videos on his telephone were flagged as depicting nudity, morphed child sexual abuse material or violence.

    The case

    The conduct was first reported to Hilliard Police and the Delaware County Sheriff’s Office before being referred to the FBI. Strahler was arrested on federal charges in June 2025.

    “I’m proud of my Office’s prosecution of this case — the first in the Nation under the Take It Down Act,” said Dominick S. Gerace II, the US Attorney for the Southern District of Ohio. “Thanks to this new law, we can now show offenders like Strahler that they will not get away with producing and posting disturbing AI-generated content.”

    Jason Cromartie, the FBI’s special agent in charge in Cincinnati, said the Act “was enacted to protect innocent victims from AI-generated deepfakes or intimate images shared online without permission”.

    The prosecution was brought by assistant US attorney Emily Czerniejewski. The sentence was announced alongside officials from the Maryland AI and Synthetic Media Threats Task Force.

  • Canadian officer who made AI images of female colleagues will not be charged

    Canadian officer who made AI images of female colleagues will not be charged

    An Alberta peace officer who used artificial intelligence to create sexualised images of women including his own colleagues will not face criminal charges, the province’s police watchdog has found.

    The Alberta Serious Incident Response Team, known as ASIRT, said in a report issued on Wednesday that the officer, a member of the Alberta Sheriffs, had committed no offence under the law as it stood when the images were found.

    “The [officer’s] conduct is serious,” the report said. “It will have lasting impacts on his female co-workers and their ability to feel safe in the workplace.”

    What was found

    The investigation began earlier this year after a family member found AI-generated photographs of women on the officer’s telephone and the employer became involved, according to the report as reported by CBC News.

    The officer admitted using an AI application to create the images. He used non-intimate photographs the women had posted on social media as the source material.

    ASIRT found no evidence that he had tried to distribute the images.

    The law

    Canada’s Criminal Code has for years made it an offence to publish, distribute, transmit, sell, make available or advertise an intimate image of a person without their consent, under section 162.1. The definition required a visual recording of the person, which meant fabricated images did not clearly fall within it.

    That changed with Bill C-16, the Protecting Victims Act, which received Royal Assent on 18 June and whose main Criminal Code provisions came into force on 18 July. It adds to the definition of an intimate image “a visual representation that is made by any electronic or mechanical means and that shows an identifiable person who is depicted as nude, as exposing their sexual organs or as engaged in explicit sexual activity, if the depiction is likely to be mistaken for a visual recording of that person”, according to the Canadian Bar Association’s submission on the bill.

    The Act also made it a separate offence to threaten to distribute an intimate image, including a fabricated one, even where nothing is shared.

    Distribution carries a maximum of five years’ imprisonment. Creation or possession with intent to share carries two years.

    Those changes took effect weeks after the photographs were found and the investigation began.

    What the watchdog would not say

    ASIRT noted the change in its report. A spokesman for the Police Review Commission, the independent body that includes ASIRT, said it was mentioned only to show the agency was aware of it.

    “Including this information is not intended to state, or even imply, that the sheriff would have been charged under the law as it’s currently written,” Jason van Rassel said in an email.

    Because ASIRT’s mandate covers criminal matters only, the report said the officer’s conduct was best addressed by the Alberta Sheriffs under their code of conduct.

    At work

    Alberta’s Ministry of Public Safety, which oversees the sheriffs, said the officer had been removed from active duty pending an internal investigation.

    “The Alberta Sheriffs Branch is committed to upholding the values of accountability, integrity and respect,” a spokeswoman, Sheena Campbell, said in a statement.

    The ministry would not say whether he was still being paid, saying it would be inappropriate to comment further while the internal investigation continued.

    The Alberta Union of Provincial Employees, which represents about 1,000 sheriffs, declined to comment when contacted by CBC News.

    The Alberta Sheriffs are a provincially managed service employing peace officers in court and government security, fish and wildlife conservation and highway patrol.

  • Camera glasses should blur faces by default, Australian regulator says

    Camera glasses should blur faces by default, Australian regulator says

    Companies that make camera glasses should automatically blur the faces of people who have not consented to being filmed, Australia’s online safety regulator has told the industry.

    In a report published in August and reported on Monday, the eSafety Commissioner set out five measures it wants manufacturers to adopt, and described how the devices are being used against women.

    “‘Pick up artist’ content creators use smart glasses to film themselves flirting with women and asking them on dates, then upload the footage to social media under the guise of providing ‘dating advice’,” the report says. “Most of the women do not realise they are being filmed. These posts often attract misogynistic comments, compounding the harm.”

    Used that way, it says, the glasses “can reinforce and normalise watching, recording and controlling women in public without their knowledge”, contributing to “harmful gendered stereotypes” and undermining “women’s agency in public spaces”.

    The report records that perpetrators have demanded money from victims to take down viral footage recorded with the glasses, which it calls an extension of existing forms of online extortion. It says the same covert recording features could be used to commit image-based abuse.

    The five measures

    Some glasses already use a light to show they are recording, the report says, but “bystanders often do not notice these lights, particularly if they are unfamiliar with the technology”. It calls for “a clear and unmistakeable recording indicator that cannot be disabled or easily obscured”, and says recording should be blocked if the light is tampered with.

    Companies “should automatically blur the faces of people who have not provided informed consent”, it says, which “would help prevent people from being filmed without their knowledge in ways that could later cause harm”.

    Live streaming should run on a delay, with visual and audio indicators when it begins, and the delay should be long enough for moderation software to review the content before broadcast.

    The glasses should not be able to record when they are not being worn. And users should not be able to use them to retrieve information about members of the public.

    The report also records benefits, including live speech-to-text for deaf users and descriptions of surroundings for people with low vision.

    Enforcement

    The recommendations are not binding. The report notes that eSafety’s Online Safety Codes and Standards oblige service providers to prevent, detect and remove unlawful material, which it says may include content captured and shared through smart glasses. The regulator can investigate compliance and impose civil penalties of up to A$54.6 million.

    The government’s answer

    Australia’s attorney-general, Michelle Rowland, said on Monday the government was not considering a ban on importing the glasses, which the Greens and independent members of parliament had sought. “We are not specifically, in this consultation, consulting on an import ban,” she told reporters, adding that it was “not ruling anything out in terms of other measures”. A ban would have consequences across trade and foreign affairs, she said.

    She released draft privacy legislation instead, out for consultation, which includes a right to erasure from large social media platforms and search engines and is drafted to be technology-neutral. Rowland said councils and businesses could restrict the glasses themselves, pointing to Brisbane City Council’s ban on non-consensual filming at its 21 public pools last week.

    Greens senator David Shoebridge called the draft laws a modest step forward but said they should cover the glasses, and repeated the call for an import ban.

    Elsewhere

    Norway’s Ministry of Digitalisation said on 25 August it was seeking stricter regulation and would appoint an expert group, and was considering banning facial recognition of other people in public spaces. Hong Kong’s privacy commissioner has warned the glasses could become a tool for covert filming, and civil society organisations in Brazil have asked the authorities to examine the privacy risks of Meta’s Ray-Ban glasses. France’s data protection authority said in May that recording indicators were of limited use and absent for some functions.

    Meta closed a way of defeating its recording light on 27 August, the second such change in under two months. Cheaper models have driven the take-up: earlier versions cost about $500, and some now sell for under $100.

  • Glasses that record without consent face growing scrutiny

    Glasses that record without consent face growing scrutiny

    Norway is preparing stricter rules on smart glasses and Australia’s attorney-general has asked the national privacy regulator to give them priority, as wearable cameras that pose come under official scrutiny in a growing number of countries.

    The glasses hold a camera and a microphone in the frame and connect to the wearer’s telephone. They take photographs and record video, in some cases on a spoken command. What distinguishes them from a telephone is that a person nearby cannot tell they are in use. A telephone has to be held up and pointed.

    What Australia has said

    The Attorney-General, Michelle Rowland, wrote to the Privacy Commissioner on 7 August asking that the devices be given priority consideration.

    Her department said the glasses “may have significant privacy implications, especially for women and children who could be disproportionately affected by inappropriate recording, harassment, surveillance or other harmful conduct enabled by this technology”.

    “Unlike other forms of technology, smart glasses may be used more discreetly, making it harder to know when you are being recorded,” Rowland said.

    The Privacy Commissioner, Carly Kind, set out her own position the same day. Writing on the website of the Office of the Australian Information Commissioner, she said there was a meaningful difference between surveillance fixed to a place, such as in an airport, and “surveillance wearables in the hands of every roving individual, designed for discretion (or even concealment)”.

    For most people most of the time, she wrote, being recorded would have few consequences. “But there will be exceptions to benign usage — where smart glasses users are able to use the tech in harmful ways to exploit or surveil vulnerable groups, such as children or victims of domestic violence, or for other untoward ends, such as corporate espionage, data theft, extortion or bribery.”

    Kind said the office was monitoring the market to establish whether intervention was warranted.

    The gap in the law

    Australia’s Privacy Act applies to businesses and government agencies. It does not apply to individuals, and it applies only when a regulated entity collects personal information.

    Where images are held on the device itself rather than passing to a company, Kind wrote, the Act may not reach them at all. She pointed instead to Australia’s recently introduced tort of serious invasions of privacy, which allows a claim against an individual who intentionally breached another’s privacy and caused serious distress, offence or harm.

    Norway

    Norway’s Ministry of Digitalisation announced on 25 August that it was seeking stricter regulation of the devices and urging the public and private sectors to consider their own guidelines.

    “We see that people’s privacy and data protection are being put under pressure by new technology, so I will therefore regulate smart glasses and similar devices more strictly than today,” the Minister of Digitalisation and Public Governance, Karianne Tung, said, according to Euronews.

    “This could, for example, involve banning functions such as facial recognition of other people in public spaces.”

    The ministry is to appoint an expert group to advise it. It has not proposed a general ban.

    The Australian bill

    The Australian Greens say they will introduce a bill when parliament returns in September to prohibit the import of wearable recording devices for at least twelve months, until privacy law can be revised, the ABC reported. The independent members David Pocock and Kate Chaney have indicated support.

    The bill would amend the Privacy Act so that filming, storing or sharing footage from such a device without consent is a breach of the law, and would give the Information Commissioner and the eSafety Commissioner power to investigate complaints and impose penalties, according to the same reports. That would extend the Act to individuals for the first time.

    The Greens are a minor party and the bill is unlikely to proceed without the federal government’s support.

    The recording light

    Meta said on 27 August that it was closing a way of defeating the light that shows its glasses are recording. The camera was already built not to start recording while the light was covered; people were starting a recording and then covering it.

    “A fix for this is starting to roll out — the camera will now stop working if the light is covered during a recording,” Meta’s vice-president for augmented reality, Alex Himel, wrote on Threads, in comments reported by Engadget.

    It was the second such change in under two months. Meta said last month that it would disable the cameras if it detected that the recording light had been physically damaged.

    Engadget reported that the company has not stopped every method, and that there is a market in cheap accessories that bypass the light without detection. It also reported that Instagram has banned the accounts of some of the people posting videos filmed this way.

    Meta has begun what it calls an education and awareness campaign, including a billboard in Los Angeles saying the glasses are “designed for everyone” and “not just the people wearing them”.

    France’s data protection authority reached a similar conclusion in an action plan published on 11 May, finding that lights and other means of telling people they were being recorded were of limited use, and were absent altogether for some functions. A survey it commissioned in January found 67 per cent of French respondents considered the glasses a risk to privacy.

    Brisbane

    Brisbane City Council banned the non-consensual use of camera-enabled devices, including wearables, at all 21 of its public pools on 25 August. Visitors may still bring the glasses in but may not film without permission, and lifeguards may eject those who do. Under Queensland law it is otherwise lawful to film people in public without their knowledge.

    The Lord Mayor, Adrian Schrinner, said swimmers were increasingly worried about being filmed, and that the concern had grown with the arrival of cheaper glasses sold under the Anko brand.

    “We want everyone that uses our pools to know that they’re not secretly being recorded by other users of the pool, that their children are not being recorded,” he said, according to the ABC.

    What is coming

    The market is widening. Kind noted that Google plans to launch smart glasses later this year and Apple in 2027, that cut-price versions are being sold by retailers including Kmart and Amazon, and that OpenAI has its own plans for a wearable device.

  • Not only image abuse hurts women: Korean law challenged

    Not only image abuse hurts women: Korean law challenged

    South Korean law on digital sexual violence is built around images and does not reach cases in which no image is shared, the head of the country’s specialist organisation in the field said on Thursday.

    Kim Yeo-jin, who leads the Korea Cyber Sexual Violence Response Centre, said women’s reputations were being destroyed in private online groups using only their names and personal details.

    “Even if photographs or videos are not distributed, the victim’s reputation can be damaged by their personal information and information implying the harm alone,” she said, according to the newspaper Women News.

    She was speaking at a roundtable convened in Seoul by Amnesty International Korea, a week after the government announced its largest package of measures against digital sex crime.

    Kim said Korean law regulates the making, distribution and possession of images, but that an image is only one of the kinds of digital information used against women. She pointed to what are known in Korea as acquaintance humiliation rooms — private groups, often on Telegram, in which women known to the participants are discussed and degraded. In some of them, she said, the victim’s image never appears.

    South Korea reported 4,273 digital sex crime cases in 2025, up from 2,314 in 2023.

    The plan

    The Ministry of Gender Equality and Family, the Broadcasting and Media Communications Commission and the National Police Agency announced an integrated response plan on 20 August. It would make setting up a site that distributes illegal sexual images a principal offence, allow investigators to connect directly to such a site to gather evidence and delete what is held there, block its advertising revenue and freeze the accounts used to run it.

    Kim described it as “the most advanced plan produced so far”.

    She said deletion and prosecution mattered, but that victims needed to be able to recover even when material was not fully removed and no one was caught.

    “Now we must think about how a victim can live when it has not been 100 per cent deleted,” she said. “The victim must be able to have the power to respond to the harm.”

    The definition

    Kim also questioned the legal definition the system works from. Korean law frames the offence around filming a person’s body in a way capable of arousing sexual desire or causing shame, without their consent.

    She asked what such a body part is, and said the premise had to be broken — that women’s bodies are inherently arousing and that their exposure is shameful. As drafted, she said, the law treats the wrong as an offence against sexual mores rather than against a person.

    Digital sexual violence should be treated as gender-based violence, she said, meaning violence premised on the idea that a woman has broken the norm that she should stay in her place.

    Her recommendations were to change the legal definition, to accept reports of online gender-based violence more broadly than the current categories allow, to expand support provided by women’s organisations, and to build a gender-equal online environment through education.

    Background

    Unbowed reported on 18 August on a South Korean school student referred to prosecutors over an account called 지인평가 — acquaintance rating — on which photographs of female classmates were posted for strangers to rate.

    The newspaper Hankook Ilbo reported from the same roundtable that four in ten requests for data in digital sex crime cases are refused, and described Korean investigators as blocked by foreign platforms.

    Thursday’s session was the first of three Amnesty International Korea is holding this year. The second is to cover the human rights risks of generative artificial intelligence and the responsibility of platforms; the third is to be built around young people’s experiences. Officials from the Broadcasting and Media Communications Standards Commission, the Central Digital Sex Crime Victim Support Centre, the Seoul Metropolitan Police Agency’s cyber investigation unit and the National Assembly Research Service also took part.

  • Two years after Ema died, deputies pass the law in her name

    Two years after Ema died, deputies pass the law in her name

    On Friday 23 August 2024, Ema Bondaruk spent longer than usual at the mirror. The annual school photograph was being taken that day and she wanted her fringe right. Her mother sounded the car horn from the drive, as most mornings.

    That day a boy from her school shared, without her consent, an intimate video of the two of them. It moved through the school’s WhatsApp groups within hours. The school telephoned her mother to say they had taken the boy’s phone and reprimanded him.

    Ema died the following day, Saturday 24 August, at the family home in Longchamps, in Buenos Aires province of Argentina. She was 15.

    Two years on, the law that carries her name has passed the Buenos Aires Chamber of Deputies.

    Deputies approved the Ley Ema on Thursday and sent it to the provincial Senate, where it must pass again to become law. Mayra Mendoza, the Quilmes deputy who introduced it, said she expected it to take effect across the province soon.

    Where the bill stands

    The Ley Ema cleared the second of two committees on Wednesday last week, when the Buenos Aires Chamber of Deputies’ general legislation committee gave it a favourable report, Parlamentario reported. The education committee had approved it the week before.

    It reached the floor at the chamber’s fourth ordinary session of the year, on Thursday 27 August, alongside disability and education measures and an agency to manage seized assets.

    The bill was presented in May by Mayra Mendoza, a deputy for Quilmes with the governing provincial bloc Unión por la Patria, who chairs the education committee. Parlamentario reports that she worked on it with Ema’s mother, Laura Sánchez, and with organisations specialising in digital rights.

    Not everyone has supported it. When the education committee approved the bill this month, the two deputies on it from La Libertad Avanza, the party of President Javier Milei, voted against, according to Página|12.

    What it would require

    The bill would oblige the province’s education authority to teach consent, privacy, digital rights and the ethical and critical use of artificial intelligence. It would update school protocols to set out what staff must do when digital violence occurs — halting the harm, preserving digital evidence, and avoiding revictimising the pupil. And it would make training compulsory and continuing for everyone working in the education system, so that teachers and managers can recognise risk and act.

    It covers cyberbullying, non-consensual distribution of intimate images, impersonation, grooming and harms involving manipulated content and AI.

    The province that got there first

    Santa Fe passed its own version last month. Its Senate approved the Ley Ema unanimously in late July, making it the first Argentine province with a law specifically on digital violence in schools, according to the province’s Defensoría de Niñas, Niños y Adolescentes, the children’s ombudsman.

    That law binds every public and private school in the province at every level, and reaches pupils, teachers, management, families and non-teaching staff. It puts digital citizenship, consent and privacy into the curriculum and guarantees psychological, educational and legal support to victims. Rosario’s city council adopted its provisions on Friday.

    The ombudsman describes the approach in one phrase: no punitivista — not punitive.

    That is deliberate, and Sánchez has explained why. The bill she worked on does not provide prison sentences for those who share the images. “Because these are minors, the idea is to create awareness through some kind of activity or course,” she told Infobae, “so that they realise that what they did can kill the victim.”

  • South Korea moves against illegal image websites

    South Korea moves against illegal image websites

    South Korea will seek to criminalise the act of setting up a website that distributes illegal sexual images, and to give investigators the power to break into such sites to gather evidence and delete the material held on them, under a plan announced in Seoul on Thursday.

    The Ministry of Gender Equality and Family, the Broadcasting and Media Communications Commission and the National Police Agency published the “integrated response plan for illegal sites” at the Government Complex in Jongno, central Seoul. Minister Won Min-kyung presented it alongside Shin Young-gyu, director-general of the commission’s broadcasting and telecommunications user policy bureau, and Yoo Jae-sung, acting commissioner general of the police, according to Hanguk NGO Sinmun.

    The premise is that removing material has stopped working. “As long as there is a structure through which sexual exploitation material is distributed, digital sex crime repeats,” a ministry official told MBC, “so we have set the direction of neutralising the illegal sites.”

    The numbers behind it

    Digital sex crime in South Korea fell for three years and then turned. Hanguk NGO Sinmun, citing the ministry, reported 4,439 cases in 2021, 3,201 in 2022 and 2,314 in 2023, before a rise to 3,579 in 2024 and 4,273 in 2025.

    Refusals have risen alongside. The share of deletion requests from the Central Digital Sex Crime Victim Support Centre that went unmet climbed from 24.4 per cent in 2022 to 28.5 per cent in 2025, the same report said.

    Opening a site as an offence

    The Ministry of Justice intends to amend the Act on Special Cases Concerning the Punishment of Sexual Crimes so that a person who opens an illegal site can be punished as a principal rather than as an accessory.

    Hanguk NGO Sinmun reported the analogy the government is using: criminal law already punishes not only the person who gambles but the person who opens the gambling house.

    “Lawful hacking”

    The plan would introduce what the government calls an active defence system, and what Korean coverage has uniformly rendered as “lawful hacking” — investigators connecting directly to an illegal site to collect evidence and delete the original data held there.

    Hanguk NGO Sinmun reported that comparable powers operate in the United Kingdom and Australia. British police and intelligence agencies may carry out equipment interference, the remote access of computers and phones, under the Investigatory Powers Act 2016, subject to approval by both a secretary of state and a judicial commissioner. In Australia, data disruption warrants introduced in 2021 allow the federal police and the Australian Criminal Intelligence Commission to modify, add, copy or delete data in order to frustrate serious offences, and are issued by a judge or a nominated tribunal member.

    Police would also form special investigation teams of 20 officers at the Seoul, Busan, Gyeonggi Nambu and Jeonnam agencies, working on their own initiative against those running the sites rather than waiting on complaints, and would widen cooperation with foreign bodies including the FBI and the National Center for Missing and Exploited Children.

    Cutting the money

    The government intends to legislate a basis for prohibiting advertising on such sites, which Hanguk NGO Sinmun described as their main source of revenue, and to freeze accounts used to run them through the enhanced due diligence provisions of the Act on Reporting and Using Specified Financial Transaction Information.

    It also plans to work with the US Federal Trade Commission to sanction platform operators that repeatedly refuse deletion requests, and to create an emergency blocking mechanism allowing the minister to ask telecommunications carriers directly to cut access. Platform operators would be placed under a duty to delete and report child and youth sexual exploitation material when they find it.

    The domain problem

    The plan addresses directly the tactic that has defeated blocking elsewhere. Hanguk NGO Sinmun reported that sites are reopening under a new domain within one to two hours of being blocked — a practice Korean officials call domain shuttling.

    The government will fund research to detect it automatically, and build a system that blocks a new domain without a fresh review where its similarity to the blocked site is high. It also plans to develop means of blocking encrypted traffic, rather than relying on existing decryption methods.

    The wider picture

    The proposal arrives three days after the Centre for Information Resilience, a UK-based open-source investigations organisation, published findings on nudification bots that reached a similar conclusion by a different route: that the visible service is the cheapest part of the operation to replace, and that referral networks, backup domains, payment routes and upstream providers survive its removal. CIR reported bots carrying serial numbers in their names, which it read as a count of accounts already taken down and replaced.

    It is also the fourth Korean government move on this subject in ten days, following a review of the legal framework, an expert meeting on AI deepfake offences and work by the Sentencing Commission on guidelines for digital sex crimes.

  • India’s Supreme Court leaves harmful takedowns to the government

    India’s Supreme Court leaves harmful takedowns to the government

    India’s Supreme Court told three government ministries to look at a proposal for an emergency mechanism to take down non-consensual intimate images, deepfakes and online threats rather than taking on the petition itself.

    The petition was brought by Narender Kumar Goswami. He sought what he called a constitutionally compliant, time-bound, URL-specific and judicially supervised emergency mechanism to address five categories of harm: threats of physical or sexual violence or death; doxxing that creates a reasonable fear of harm; disclosure of the details, photographs or school information of children; non-consensual intimate, morphed, synthetic or AI-generated material; and deepfake impersonation causing immediate grave harm to safety, dignity, livelihood or reputation.

    His case rested on what he called the “speed gap” between digital harm and legal remedy. “A specific threat of rape or murder may silence a woman from public discourse before the police or courts act,” the petition said. A deepfake can destroy identity, livelihood, family life and reputation “before forensic truth can catch up”. Therefore, it argued, “delay in remedy may itself become denial of remedy”.

    What the court did

    A bench of Chief Justice Surya Kant and Justices Joymalya Bagchi and V. Mohana accepted the issues were comprehensively raised, and disposed of the case.

    “Since remedial actions are required to be taken by the addressee authorities, we dispose of this petition at this stage,” the order reads, directing the ministries of electronics and information technology, home affairs, and law and justice, “and all other stakeholders”, to examine a representation Goswami had sent them on 22 June and take such measures “as may be required in accordance with law”.

    The chief justice put it to him directly: “How to detect them, what preventive measures — these are to be taken by domain experts. You have already raised this issue through a representation, and therefore, we direct the authorities first of all to examine that.”

    Goswami had told the court he received no effective decision on that representation.

    The gap he was pointing at

    India is not short of takedown deadlines. Amendments to the information technology intermediary rules, notified on 10 February and in force from 20 February, require platforms to remove unlawful synthetically generated content within three hours of a valid government or court order, down from 36. For sensitive categories, including non-consensual sexual imagery and impersonation, the window is two hours. Failure costs a platform its safe harbour protection under section 79 of the Information Technology Act.

    On paper those are among the fastest statutory deadlines anywhere. But they run from an order a woman must first obtain.

    Goswami’s petition accepted that the existing rules recognise urgency, and argued they provide no uniform, judicially supervised, time-bound route. Criminal law is no answer either, it said: the Bharatiya Nyaya Sanhita of 2023 covers criminal intimidation, stalking, defamation and impersonation, but prosecution “punishes the offender; it does not by itself guarantee immediate, URL-specific disabling of harmful content or preservation of digital evidence before viral dissemination”.

    He proposed safeguards against overreach — that any disabling order be reasoned, confined to the content complained of, limited to India, subject to evidence preservation, notified to the uploader where identifiable, and followed by a hearing within a short period. He also asked the court to have the government convene an expert committee including the National Commission for Women, the child rights commission, CERT-In, and free speech, privacy and women’s safety specialists.

    Two weeks earlier

    On 28 July the same three judges urged the government to make “digital arrest” — a fraud in which victims are convinced they are under remote police detention — a standalone offence, and pressed for a law on deepfakes. Solicitor General Tushar Mehta told them a draft bill was coming that would cover both. It is expected in the current session.

    Across both hearings the pattern is the same: the court naming the gap, and the government saying it will fill it.

  • Forty-eight US states now have laws on sexually explicit deepfakes

    Forty-eight US states now have laws on sexually explicit deepfakes

    Forty-eight American states have now enacted laws covering the creation or distribution of sexually explicit deepfakes, according to the third annual survey of state legislation by Ballotpedia, a non-profit that tracks US politics and policy.

    The count rose from 46 in January to 48 by 23 July, the cut-off for the report. Only Ohio and New Mexico have no such law.

    What those 48 laws do is not uniform. Ballotpedia describes them as laws “concerning the creation or distribution of deepfakes that depict explicit sexual acts or other sensitive content”, and notes that some address only the creation and distribution of child sexual abuse material, while others cover the non-consensual creation and distribution of adult intimate images. A woman whose image is used to make a sexual deepfake is therefore not equally protected across the 48.

    The two gaps

    Ohio has enacted no deepfake legislation of any kind — neither on sexual material nor on political communications. Its Senate passed Senate Bill 163 unanimously on 20 May, criminalising the making, sending or possession of AI-generated child sexual abuse material and requiring AI systems to watermark the images they produce. It went to the House and has not become law. It does not cover adults.

    New Mexico’s position is different. It is one of 33 states with a law regulating deepfakes in political advertising, but it has not legislated on sexual ones. It has addressed the use of synthetic media against candidates, and not against women.

    Neither state is without any law. All 50 states and the District of Columbia prohibit the distribution or production of non-consensual intimate images, according to Ballotpedia’s separate tracking, current as of June. The gap in Ohio and New Mexico is specifically about material that has been generated or altered by artificial intelligence.

    Federal law also reaches it. The Take It Down Act, signed in May 2025, criminalises the non-consensual publication of intimate images including deepfakes in some circumstances, and required covered platforms to put removal processes in place by 19 May this year.

    The first person convicted under that act was from Ohio. James Strahler II, 37, pleaded guilty on 7 April to cyberstalking, producing child sexual abuse material and publishing digital forgeries — the statute’s term for deepfakes. The Justice Department said he had used images of boys he knew to create sexual material of them. In May it announced the arrests of two men over albums said to depict about 140 female victims, and in June it seized two websites that distributed AI-generated nude images of women.

    Slowing down

    State legislating on deepfakes is losing pace. Lawmakers enacted 58 deepfake-related bills of all kinds in 2026 up to 23 July, against 64 by the same date in 2025. Almost half of this year’s enacted bills had sponsors from both parties.

    Laws on political deepfakes grew faster this year than sexual ones, from 28 states in January to 33 in July. Those laws have run into the First Amendment in a way the sexual ones have not: Senior US District Judge John Mendez blocked enforcement of California’s AB 2839 in October 2024, and Ballotpedia records three states whose pre-election prohibitions carry no exemption for material that discloses it is synthetic.

    Ballotpedia tracks bills, not prosecutions, and no state publishes figures on charges brought under its deepfake laws. Minnesota’s ban on nudification tools, which took effect on 1 August after a federal judge refused Elon Musk’s xAI an order pausing it, is among the newest and the most directly aimed at the tools themselves rather than the people who use them.