AI Deepfake Porn Is Exploding: What Women Can Do if Their Face Is Used Without Permission

Steps to Take If Your Likeness Is Used in AI-Generated Pornography

AI Deepfake Detection
As AI deepfakes proliferate, victims face severe personal and emotional harm from non-consensual sexual imagery ChatGPT AI-Generated

Artificial intelligence has made it easier than ever to create convincing fake images and videos — and one of the most damaging uses of the technology is sexually explicit content made without a person's consent.

AI deepfake pornography can take an ordinary photograph and digitally place a person's face into an intimate image or video, making it appear as though they participated in something that never happened. The technology can also be used to alter existing photographs or create entirely fabricated sexual images.

Women have been disproportionately targeted by this abuse. A 2024 study of more than 16,000 people across 10 countries found that 2.2 per cent of respondents reported being victims of non-consensual synthetic intimate imagery, while 1.8 per cent reported having created such material. The researchers warned that existing laws alone may not be enough to deter the behaviour.

The problem is not simply that an image is fake. For the person depicted, the consequences can include humiliation, harassment, threats, reputational damage, and fear that friends, colleagues or family members will believe the material is genuine.

Research published in 2026 has also argued that deepfake research has focused too heavily on whether synthetic media is authentic, rather than on the harm suffered by the person whose likeness has been exploited.

So what can someone do if their face has been used in AI-generated pornography?

First, Remember That You Are Not Responsible for the Abuse

The most important point is also the easiest to overlook: the victim did not consent simply because their photograph was publicly available.

A person can take an ordinary selfie, profile photograph or social media image and manipulate it into sexually explicit material. The fact that the original photograph was public does not mean permission was given for it to be transformed into pornography.

The US Federal Trade Commission describes image-based abuse as including intimate material that is real, digitally altered, or generated using AI. It can affect adults as well as minors and may be used for harassment, coercion, revenge, or financial extortion.

Preserve Evidence Before Reporting Anything

If you discover a deepfake of yourself, resist the temptation to immediately delete every message or account connected to it. Instead, preserve evidence that could help a platform, lawyer or police investigator identify what happened.

Save the URL where the material appears, the account or username responsible, dates and times, messages, threats, and any demands for money. Screenshots can also be useful, particularly when the material or account could disappear after a report is made.

D'Angelo recommends preserving that information before trying to make the material disappear. 'My first recommendation is usually: preserve the evidence before trying to make it disappear,' he said.

'Take screenshots, preserve relevant communications, and do not immediately start confronting suspected perpetrators. Confrontation can cause accounts, messages, or other evidence to disappear.'

He said timing can also matter in a digital investigation. 'From a forensic standpoint, speed matters. The longer someone waits, the greater the chance that logs expire, accounts disappear, content gets copied, and evidence becomes more difficult to obtain.'

For victims, that means the priority is not simply to get the image removed, but also to document where it appeared, who posted it and when. As D'Angelo put it: 'You may only get one opportunity to capture that information before an account disappears.'

However, do not deliberately download, forward or redistribute explicit material simply to create evidence. Where possible, document the location of the content and preserve the surrounding information without helping it spread further.

If someone is threatening to publish the material unless you pay money or provide additional photographs, keep records of the threats. Do not assume that paying will make the problem disappear.

Report the Image to the Platform

The first removal request should normally go to the website or platform hosting the material.

Look for options such as 'non-consensual intimate imagery', 'sexual exploitation', 'nudity', 'harassment', or 'intimate image abuse'. Explain clearly that the image is fabricated or manipulated, depicts you in a sexual context, and was created or distributed without your consent.

This distinction matters because ordinary reports for manipulated or misleading content may not always place the material in the category that receives the appropriate response.

Research has also shown why reporting systems matter. In a 2024 audit of X, researchers tested two reporting mechanisms for AI-generated non-consensual intimate images. The images reported through a copyright mechanism were removed within 25 hours in that experim

ent, while those reported through the platform's non-consensual nudity mechanism were not removed during the three-week observation period.

The study involved a controlled research experiment rather than ordinary victim reports, but it illustrates how the choice of reporting pathway can affect outcomes.

Use StopNCII if You Are an Adult

One of the most useful tools available to adults dealing with intimate image abuse is StopNCII.org.

The service creates a digital fingerprint, or 'hash', of an image directly on the person's device. The image itself is not uploaded to StopNCII. Participating platforms can then use the hash to identify matching material and take action under their policies.

The service does have an important limitation: it cannot remove material from the entire internet. It works only with participating platforms.

StopNCII's partner network includes services such as Microsoft and OnlyFans, among others. That means it should be viewed as one part of a wider removal strategy, rather than a universal 'delete it from the internet' button.

D'Angelo said platforms are particularly important because they can limit how quickly abusive material spreads. 'Platforms have an increasingly important role because they are often in the best position to stop amplification,' he said.

He pointed to hashing and duplicate detection as technologies platforms can use to prevent previously identified material from being repeatedly uploaded.

'Under the TAKE IT DOWN Act, covered platforms must provide a process for reporting nonconsensual intimate imagery and generally remove validly reported images and known identical copies within 48 hours,' D'Angelo said. 'The FTC began enforcing those platform requirements in May 2026.'

The FTC's own guidance says covered platforms should consider technologies such as hashing to prevent intimate content that has already been removed from reappearing.

Google Can Remove Fake Sexual Images From Search

Even after an image is removed from a website, copies or search results can continue to cause problems.

Google now has a specific removal process for fake sexual or nude content involving an identifiable person. Its current guidance explicitly covers AI-generated images and other fabricated sexual material.

A person can report an image directly through Google Images by opening the image, selecting the additional options and choosing the removal process for sexual content involving them. Google also allows people to request protection against duplicates and future searches involving similar images.

But there is an important distinction: removing a result from Google does not necessarily remove the underlying image from the internet.

Google says the most effective approach is to ask the website hosting the material to remove it. If the source website removes the image, Google can subsequently update its search results.

If You Are in the US, the Law Now Gives Victims an Additional Option

There is a significant change in the United States in 2026. The TAKE IT DOWN Act took effect for platform removal obligations on May 19, 2026. The law requires covered platforms to provide a process for victims to request removal of non-consensual intimate images, including AI-generated and digitally altered material.

Michael D'Angelo, a digital forensics and cybersecurity expert and founder of Alethean Group, said the legal environment has changed considerably with the introduction of the law.

'At the federal level, the TAKE IT DOWN Act now specifically addresses nonconsensual intimate imagery, including AI-generated or digitally altered sexual images. It also requires covered online platforms to establish a process for victims to request removal of this material,' D'Angelo said.

Once a valid request is received, covered platforms must remove the material and any known identical copies within 48 hours. The FTC began enforcing these requirements on May 19, 2026. The FTC has also launched a process for reporting platforms that fail to comply with the law.

D'Angelo also cautioned that creating a deepfake and distributing it are not necessarily equivalent from a harm or investigative perspective.

'Creating an image privately and publishing it to thousands or millions of people produce different levels of harm. Distribution introduces reputational damage, harassment, search-engine exposure, repeated copying, and the possibility that the content becomes effectively impossible to completely remove,' he said.

'Current federal law is particularly focused on publication and distribution. That distinction is worth understanding because simply proving that an image exists is not necessarily the same thing as proving who published it or under what circumstances.'

The legislation does not mean every website on the internet will automatically remove an image within 48 hours. It applies to covered platforms and requires a valid removal request through the platform's process.

UK Victims Have Stronger Protections Too

The UK has also introduced measures specifically addressing intimate image abuse and deepfakes.

The Crime and Policing Act 2026 includes offences covering the creation, adaptation, supply and offering of tools designed to generate purported intimate images. It also places duties on online platforms to take down non-consensual intimate images as soon as reasonably practical and no later than 48 hours after receiving a report.

UK police guidance explicitly recognises fake intimate images that appear real as a form of non-consensual intimate image abuse.

The Revenge Porn Helpline also provides guidance specifically for adults whose likeness has been used to create synthetic sexual content. It advises victims to follow the same reporting and support processes used for other forms of intimate image abuse.

What if the Victim Is Under 18?

Different rules and tools apply when the person depicted was under 18.

The National Center for Missing & Exploited Children's Take It Down service allows people to create a digital fingerprint for explicit images or videos of themselves taken when they were under 18. The original material remains on the user's device rather than being uploaded to the service. Participating platforms can use the resulting hash to detect matching content.

People should not download or share explicit material of a minor to submit it to a removal service. If a child is being threatened, exploited, or blackmailed, contacting the relevant law-enforcement or child-protection authorities is also important.

Reporting the Perpetrator Can Matter

Removing an image addresses the immediate problem, but victims may also want to report the person responsible.

Even when the person responsible is anonymous, identifying them may still be possible, according to D'Angelo.

'Anonymity makes the investigation harder, but it does not necessarily make someone untraceable,' he said.

'Investigators may look at platform records, IP addresses, account-registration information, email accounts, payment records, cryptocurrency activity, cloud-service logs, device information, and connections between online identities.'

International cases can be more difficult, however, because, as D'Angelo noted, 'obtaining evidence may require cooperation between service providers, law enforcement agencies, and foreign governments.'

Depending on where the victim and perpetrator are located, creating, possessing, threatening to distribute, or distributing sexually explicit deepfakes may constitute a criminal offence or expose someone to civil liability.

The precise law varies considerably between countries and even between jurisdictions within countries, so victims should avoid relying on generic advice about 'revenge porn' laws. A local lawyer, police officer, or specialist victim-support organisation can explain which offences may apply.

In India, for example, the Government's National Cyber Crime Reporting Portal provides a route for reporting cybercrime and has a dedicated section for crimes involving women and children.

Do Not Pay Someone Who Promises a Guaranteed Removal

Victims may encounter people or companies offering to 'erase' deepfakes from the internet for a large fee.

Extreme caution is warranted.

There is no legitimate service that can guarantee that every copy of an image will disappear from the internet. Google itself warns that removing a search result does not remove the underlying content from the website hosting it.

Similarly, removal services cannot necessarily control private messages, closed groups, overseas websites, encrypted services or copies that have already been downloaded.

A person facing sextortion should also be particularly wary of anyone demanding payment in exchange for removing material. Paying may not end the threats and can encourage further demands.

The Technology May Be New, but the Abuse Is Not

AI has dramatically lowered the technical barrier for creating convincing fake sexual material, but the underlying abuse is part of a broader pattern of image-based sexual exploitation.

What has changed is the speed and scale at which somebody's ordinary photograph can be transformed into something sexually explicit and distributed.

That is why simply telling victims to 'prove it is fake' misses the central issue. The harm does not disappear because an image is synthetic.

For anyone affected, the practical priority is to preserve evidence, report the content to the platform, use available removal and hash-matching services, request removal from search engines, and report serious threats or criminal behaviour to the appropriate authorities.

Most importantly, the responsibility lies with the person who created or distributed the material — not with the woman whose face was used without her permission.

D'Angelo said the gap between technological development and law enforcement is likely to remain difficult to close.

'The law is catching up, but technology moves much faster. This has always been true and, unfortunately, might remain true into the future,' he said. 'Investigators are always learning new tactics and methods being used by perpetrators and criminals, so it will continue to be a cat/mouse game.'


Frequently Asked Questions

  • What is AI-generated non-consensual intimate imagery?
    It is sexually explicit content created using AI technology without the consent of the person depicted.
  • What should I do if I find a deepfake of myself?
    Preserve evidence, report it to the platform, and use available removal services.
  • Can I remove a deepfake from the internet completely?
    Complete removal is challenging, but you can request removal from platforms and search engines.
  • What legal options are available in the US for victims?
    The TAKE IT DOWN Act requires platforms to remove non-consensual intimate images within 48 hours of a valid request.
  • What should I avoid doing if I am a victim?
    Avoid paying anyone who promises guaranteed removal of the content.