MY ARTICLE SUBHEADING CONTENT
Sexually explicit deepfakes are no longer only an adult problem. They are increasingly being turned against children, often in ways that are invisible to parents, schools and even many technology companies. This shift matters right now because powerful image tools have moved from niche forums into mainstream platforms, and the barrier between experimentation and serious harm has effectively disappeared. Incident probabilities are rising as AI agent fleets expand as AI agent fleets expand.
Deepfake abuse against children is not speculative. It is already happening at scale. UNICEF, together with partners, recently estimated that more than one point two million children across eleven countries reported having their images altered into sexually explicit deepfakes in the past year. Law enforcement agencies in multiple jurisdictions are now reporting cases where offenders use generative image models to create synthetic child sexual abuse material and then weaponize it for blackmail and coercion. What was once a fringe concern about celebrity face swaps has evolved into a structural risk for any child with a digital footprint.
Deepfake child abuse has moved from fringe fear to a structural, global threat to every child
From fringe experiments to mainstream child exploitation
The first wave of deepfakes emerged around the late 2010s when hobbyists began using accessible face swap tools to graft celebrity faces onto adult pornography. These early systems demanded technical skill and significant computing resources, which limited who could participate. Today, that barrier is gone. Simple web interfaces and consumer apps allow users to upload ordinary photos and produce photorealistic synthetic nudes or sexual scenes in minutes, often for free or for a small subscription fee.
At the same time, a broad ecosystem of nudification tools has appeared. These are systems designed not to generate images from scratch but to strip clothing or sexualize existing photos. UNICEF and other child protection bodies now describe nudification as a major driver of AI generated sexual abuse material involving children. Where older software like image editors once required skill, new AI tools automate the process and can handle large volumes of material, including images scraped from social media.
As these tools became easier to use, the focus of abuse expanded. Multiple European and international studies now estimate that the vast majority of deepfakes are pornographic and that almost all sexual deepfakes depict women and girls, including adolescent girls. That pattern reflects wider gendered violence online, but it also reveals how quickly children are pulled into the orbit of technology that many people still assume targets adults.
What recent investigations are revealing on Hugging Face
One of the clearest windows into this problem comes from a recent investigation into image editing spaces hosted on Hugging Face, a major platform for sharing AI models that has cultivated a reputation for ethical AI while simultaneously hosting large numbers of generative tools. Researchers tested nine publicly accessible image editing spaces that allow users to upload photos and apply AI transformations. They submitted one thousand prompts and found that seven of the nine spaces could transform a clothed image of a woman into a topless version with minimal effort, without any attempt to circumvent stated safeguards.
The numbers inside that test are stark. Seventy three percent of prompts involved sexual content, and eighty three percent of those sexual prompts explicitly tried to undress or sexualize the person in the image rather than apply neutral edits. Women were overwhelmingly the targets, and 6 point 7 percent of sexual requests appeared to focus on individuals who looked like children. In other words, there is already a measurable pattern of child directed exploitation inside mainstream AI tools, not just speculative concern. In that same investigation, researchers confirmed that users on Hugging Face were actively generating nonconsensual intimate images of apparent minors, highlighting the rapid normalization of child deepfakes.
Logs from these spaces and similar platforms show that some users are not coy about their intentions. They ask tools to remove clothing from apparent minors, expose bodies, or produce near nude variants of ordinary photos. Requests often extend to explicit scenarios, including depictions of bodily fluids, sex toy use and sexual acts, with similar language used across subjects who appear young and those who appear adult. This is not accidental misuse by confused users. It is purposeful exploitation of tools to create synthetic sexual abuse material.
Separate reporting has identified at least one video model on Hugging Face configured to generate sexual content featuring a teenage looking likeness of a well known actress. Preview images for that model are almost indistinguishable from real photographs, and reverse image searches link them to pictures of the actress as a child. Elsewhere on the platform, there are dozens of models clearly designed to generate pornographic images of named female celebrities, including different sexual positions and scenarios, all in direct contradiction with the platform’s stated policies.
When nudification and deepfake models are applied to images of children, the outputs amount to synthetic child sexual abuse material. UNICEF, law enforcement agencies and child protection experts treat AI generated sexualized images of children as child sexual abuse material because the impact on victims and the uses by offenders are comparable to abusive content created with cameras. These synthetic files can be stored, traded and shared in offender networks, and they can be used to threaten children by claiming evidence of abuse exists even when no physical assault occurred.
Hugging Face as a multiplier of risk
Hugging Face occupies a central position in this ecosystem because it serves as a hub for open sharing of models and spaces that can be plugged into other services or used directly via web interfaces. Independent investigations and academic work have documented thousands of image models on the platform that can generate photorealistic people, including at least five thousand models capable of depicting real individuals. Researchers have identified more than twenty nine thousand models across Hugging Face and another major platform that are associated with dog whistle terms linked to nonconsensual intimate imagery and AI generated child sexual abuse material, using keywords such as teen, young, girl, realistic and nudif.
Reports by journalists and researchers show that Hugging Face hosts over a dozen tools tailored to sexual deepfakes of political figures, alongside many other models designed to produce deepfake pornography of celebrities and influencers. These offerings persist despite platform policies that forbid underage nudity, any sexual content involving minors and sexual content produced without explicit consent. That gap between rules and reality illustrates a key governance challenge. The platform has chosen an open sharing model that encourages experimentation and reuse, but its enforcement mechanisms rely heavily on user reports and manual review rather than systematic detection of harmful models.
In response to public pressure, Hugging Face has removed some violating models and updated terms of service. For example, after warnings from Australian authorities about misuse of its generative tools to create child sexual exploitation material, the company introduced terms requiring uploaders to minimize risks and specifically prevent generation of child sexual abuse or pro terror content. It faces potential fines of tens of millions if it fails to enforce these commitments. Yet investigations still find nudification tools and deepfake pornography models live on the platform, and prolific creators of deepfake pornography often retain their accounts.
Academic work on misuse patterns shows that when companies remove deepfake models, dedicated communities frequently respond by archiving them and reuploading them to platforms like Hugging Face, sometimes in bulk. That dynamic turns content moderation into a moving target. It also highlights how platform design choices and openness can predictably shape where and how abuse appears.
Beyond one platform: a wider infrastructure of synthetic abuse
While Hugging Face is a focal point, it is not the only channel through which children encounter deepfake harm. Large training datasets such as those used for image generators have previously contained links to known child sexual abuse material, enabling systems to learn how to reproduce photorealistic images of children in sexual contexts. Researchers have pressured dataset maintainers to remove such links, and some high risk models built on those datasets have been withdrawn, yet older less filtered models have remained publicly available until very recently.
Mainstream chat and assistant models are also being misused. A public dataset documenting user requests to one widely deployed AI assistant integrated into a social platform found hundreds of instances where people asked the model to generate nonconsensual intimate imagery, often by digitally undressing women without their knowledge. This pattern demonstrates that even systems not primarily designed for image generation can be pulled into the deepfake ecosystem when they connect to image tools or act as prompt generators for other models.
Child protection bodies now identify several pathways through which AI generated sexual content harms children. These include child on child sexual abuse, where young people use nudification tools or deepfakes against classmates or peers; adult perpetrated sexual abuse that uses synthetic images to groom or terrorize children; and sextortion schemes where offenders leverage synthetic images to coerce more material or physical contact. Children are particularly vulnerable because they spend significant time online, may not understand the permanence of digital content and often lack meaningful control over images uploaded by others.
At the same time, deepfake abuse puts pressure on law enforcement and legal systems. Investigators must now distinguish between synthetic and real abuse material, a task that consumes time and resources and can delay interventions to protect children. Existing laws often criminalize possession and distribution of child sexual abuse material regardless of whether it was generated by AI or captured by a camera, but not all jurisdictions have updated statutes to explicitly cover synthetic content, which can create gaps in enforcement.
Why this matters for businesses and technology governance
For technology companies and businesses building AI, the rise of child targeted deepfakes exposes a core tension between openness and safety. Open sharing of models, weights and spaces accelerates innovation and allows smaller teams to build on the work of others. It also makes it trivially easy for malicious actors to deploy nudification tools, deepfake pornography models or synthetic child abuse generators on consumer facing websites.
Platforms that host models face three intersecting responsibilities. They must enforce clear content rules that ban sexual content involving minors and nonconsensual sexual material. They must invest in proactive detection of harmful models, for example by scanning for known abuse related keywords, preview images that depict sexualized minors or integration with well known pornography generators. They must also collaborate with law enforcement and child protection experts to share signals about emerging misuse trends and known offending communities.
Businesses that rely on these models or integrate them into products cannot treat harmful deepfake capabilities as an external problem. If a consumer photo editing app quietly connects to a nudification model hosted on a third party platform, the app provider becomes part of the chain of harm. Risk assessments need to focus not only on what a model can do in theory but on how it is being used in practice and what guardrails exist around that use.
There is also a trust dimension. Parents, educators and young people increasingly encounter broad claims that platforms and AI providers care about safety. When those same platforms host thousands of models that can be bent toward sexual exploitation of children, the credibility of such claims erodes. Trustworthy AI governance requires sustained transparency about what is hosted, what has been removed, and where enforcement is still failing.
What needs to change
Several shifts are already under way. Dataset maintainers are removing known child abuse links, and some high risk models have been withdrawn from public repositories. Platforms like Hugging Face have strengthened policies and created channels for reporting safety violations. Governments are exploring new regulatory frameworks that would impose fines or other penalties on companies that host or fail to remove AI systems producing child sexual abuse material or nonconsensual sexual deepfakes.
Yet policy changes remain uneven, and technical enforcement lags behind what is needed. Investigations continue to uncover nudification spaces and deepfake pornography tools available to anyone who knows where to look. Communities dedicated to deepfake abuse actively adapt when models are taken down, rebuilding their archives and redistributing tools across platforms. That resilience means piecemeal removals will never be sufficient.
Effective responses will likely combine several strategies. Platforms need automated scanning and classification of models and spaces, with human review focused on borderline or complex cases. Model developers should integrate child safety and nonconsensual abuse safeguards at the training and architecture level, not only through user interface warnings. Law enforcement and child protection groups need resourcing and technical support to trace synthetic abuse material back to offenders and networks. Education systems must begin teaching children and parents how synthetic abuse works, including how offenders may threaten victims with fake images that look real.
Key takeaways and what to watch next
Sexual deepfakes have moved from an adult celebrity problem to a broad societal challenge that now directly affects children. Investigations into image editing spaces and deepfake models show clear patterns of users targeting apparent minors with nudification and explicit sexual prompts. Synthetic child sexual abuse material created by these tools can be traded, stored and used in coercive schemes much like traditional abuse material, and victims suffer real psychological harm even when no camera was pointed at their body.
Hugging Face and similar platforms are at the center of this story because their openness amplifies both innovation and abuse. They host thousands of models that can be repurposed for nonconsensual deepfakes, including tools explicitly aimed at celebrities, politicians and teenage looking subjects. Policies exist on paper to prohibit such content, but enforcement remains reactive and inconsistent, leaving substantial room for misuse.
Over the next few years, three things will determine whether harmful deepfake requests targeting children remain a growing crisis or begin to recede. First is whether platforms meaningfully invest in proactive detection and removal of abusive models and spaces. Second is whether lawmakers close gaps around synthetic child sexual abuse material and nonconsensual deepfakes, giving law enforcement clearer tools to act. Third is whether education and awareness campaigns help families understand the reality of synthetic abuse and support children who are targeted.
Emerging regulation, platform policy shifts and public pressure are starting to push in the right direction. The question is whether these efforts will move fast enough to match the accelerating capabilities and spread of generative tools. The trajectory of deepfake technology so far suggests that without serious intervention, children will remain at the frontline of the next wave of AI enabled sexual exploitation.
Conclusion
New findings that image models on Hugging Face are being used to request nonconsensual sexual deepfakes of apparent children are not just another content moderation story. They are a warning shot about how mainstream AI infrastructure is quietly becoming part of a growing ecosystem of child sexual exploitation that is faster, cheaper and easier to scale than anything seen before.
A new kind of misuse on a central AI hub
The study behind these findings uses Perplexity Sonar to analyze how people actually interact with publicly accessible image generation models hosted on Hugging Face. It concludes that those models are routinely prompted to generate sexualized deepfakes of real or realistic individuals without consent, including prompts that appear to target minors.
A significant share of the prompts examined focus on undressing fully clothed subjects or transforming innocuous photos into sexualized images. Within that set, researchers identify a disturbing subset that explicitly references children or child coded language, despite clear platform policies that ban sexual content involving minors. This pattern matters because Hugging Face is one of the central distribution points for open source models used by researchers, hobbyists and startups across the world. When misuse is this common in a flagship open ecosystem, it signals a broader failure of current guardrails rather than a one off anomaly.
How we got here: the escalation of deepfake abuse involving children
To understand why the Hugging Face results are so serious, you have to see them against the wider backdrop. In only a few years, generative AI has transformed child sexual abuse material from something that required contact offending and manual production into something that can be synthetically manufactured at scale.
Recent estimates from a UNICEF partnership with ECPAT and Interpol across eleven countries found that more than 1.2 million children reported having their images altered into sexually explicit deepfakes within a single year. In some regions that translates to roughly one child in an average classroom being targeted. Safety watchdogs are seeing the same pattern online. The Internet Watch Foundation reports that in 2025 alone it identified 8,029 AI generated images and videos representing realistic child sexual abuse material across both the dark web and mainstream platforms, with video content growing by more than 260 times compared with the previous year. Within those AI generated cases, nearly half of the images show nude or partially nude sexual posing, while videos disproportionately depict the most severe forms of abuse.
Researchers studying AI generated child sexual abuse material describe a spectrum of harms. AI systems are used to create synthetic victims who have never existed, to revictimize known survivors by transforming or reanimating their images and to produce deepfake nudes used for grooming, coercion and sexual extortion. AI generated content does not require a camera or physical access to a child, but it still fuels sexual interest in children, normalizes extreme violence and can act as a bridge toward contact offending.
The misuse is not limited to closed criminal forums. Safety organizations have documented offenders using freely accessible open source AI tools to produce sexualized images of minors, share tips on how to manipulate photographs of celebrity children and seek ways to bypass basic safeguards in popular image generators. On some child abuse sites monitored by researchers, thousands of synthetic images that would be illegal under United Kingdom law were logged in a single month. School focused research has also shown that teenagers are experimenting with nudify apps and AI powered deepfake tools to create sexualized images of classmates, with many institutions underestimating the scale of the problem or lacking policies to respond effectively.
Against that backdrop, the Hugging Face study is less an isolated scandal and more a snapshot of how quickly generative AI has become embedded in an ecosystem of exploitation that spans mainstream platforms, open source communities and underground networks.
Why moderating generative models is so hard
Hugging Face sits at a difficult intersection. It provides infrastructure for hosting and sharing models, including image generators, while relying heavily on model creators and community norms to enforce safety. The Sonar study exposes the limits of that approach in the face of determined misuse.
Generative image models operate based on prompts. A single model can output benign art for millions of users while quietly serving a smaller group with highly abusive content, often in private or semi private spaces where outputs are not publicly visible. Many platforms log prompts but not images. Others allow model weights to be downloaded and run elsewhere, beyond normal moderation channels. This creates blind spots where platform policies look strong on paper but are weak in practice.
There are upstream problems as well. One major image training dataset, LAION, was found to contain hundreds of examples of child abuse material embedded among billions of images, raising the possibility that widely used models were trained on illegal content without anyone noticing for years. When models are trained on tainted data, abusive patterns can become part of their learned representation, making it technically harder to guarantee that they will never reproduce similar content.
Law enforcement agencies and policymakers are candid about the difficulty of responding. Investigators describe abusive AI as easier to create, harder to trace and faster to distribute than traditional child abuse imagery. Even when authorities identify victims, they must distinguish between synthetic and non synthetic material, navigate cross border data requests and cope with offenders who use multiple layers of obfuscation. At the same time, some agencies are trying to harness AI to identify victims, match faces across datasets and detect previously unknown material in large seized collections. That shows AI can be part of the solution, but it also underscores how asymmetric the situation is. A small team of developers can release a powerful open source model in months, while legal frameworks and investigative tools take years to mature.
What the Hugging Face findings signal for platforms and businesses
For platforms like Hugging Face, the Sonar results are a stress test of current safety assumptions. The key lesson is that policies and disclaimers are not enough when abuse can be automated and scaled.
First, there is a trust issue. Enterprises, researchers and regulators increasingly rely on Hugging Face as core infrastructure for their AI workflows. Discovering that its image models are routinely being prompted for sexual deepfakes, including of apparent children, will raise questions about due diligence and governance. Businesses that integrate these models directly or indirectly must ask whether they are inadvertently enabling misuse and whether contractual protections and audits go far enough.
Second, the study highlights the need for more proactive safety engineering at the platform level. That includes logging and analyzing prompts for patterns of abuse, rate limiting high risk usage, attaching stronger default filters to models that are likely to be targeted for sexual content and making it much harder to deploy or fine tune models for explicit imagery without robust access controls. It also suggests that open source communities cannot simply delegate all responsibility to individual users. When abuse is systemic, it becomes a shared reputational and legal risk.
Third, the findings connect directly to regulatory trends. Governments are starting to treat AI specific child sexual abuse material as a distinct category in law. In the United Kingdom, proposed legislation would make it illegal to possess, create or distribute tools intended for generating child sexual abuse material, with prison sentences for people who operate websites that facilitate such content or share manuals on how to use AI for sexual exploitation. Border authorities would gain powers to compel suspected offenders to unlock devices containing AI generated material. At the same time, law enforcement agencies in Europe have coordinated arrests of individuals involved in networks that specialized in disseminating entirely AI generated depictions of minors, confirming that synthetic imagery is already a core focus of international investigations. In the United States, prosecutors are bringing deepfake cases under existing child pornography statutes, arguing that the harm does not disappear simply because an image was digitally altered.
For platforms and companies that host or deploy generative models, these trends mean the compliance bar is rising. It is no longer enough to argue that synthetic images are less harmful because no camera was present. Regulators are increasingly treating AI generated child sexual abuse material as functionally equivalent to recorded abuse in law and policy.
Opportunities and responsibilities for using AI to protect children
Despite the grim findings, there are genuine opportunities to use AI to reduce harm. Some of the same techniques that make it possible to generate realistic images can help detect and disrupt abuse when applied responsibly.
Specialized tools can scan large volumes of content for indicators of AI generated child sexual abuse material, identify known survivors across new datasets and support triage so investigators can focus on the most urgent cases. Pattern analysis of prompts and usage can help platforms identify clusters of accounts that are systematically abusing models, even when individual prompts skirt the edges of policy language. Educational institutions can use research on nudify apps and student misuse to build clearer guidance, update acceptable use policies and create confidential reporting channels that recognize the emotional and reputational impact on young people who are targeted.
The Hugging Face study also highlights the need for multi stakeholder collaboration. Safety organizations, researchers, platform operators and survivors advocates each see different parts of the problem. When they pool data and expertise, they can produce more accurate prevalence estimates, identify emerging tools before they go mainstream and develop best practices that are technically informed and survivor centered.
What needs to happen next
In practical terms, several strands of action emerge from the Sonar findings and the wider evidence base.
- Platforms that host generative models should treat child safety as a primary design requirement, not a bolt on. That means comprehensive logging of prompts, automated detection of high risk patterns, human review pathways for escalated cases and clear enforcement actions against repeated abusers.
- Open source communities need explicit codes of conduct around child sexual abuse material and deepfakes, backed by governance that can remove or quarantine models designed or repeatedly misused for exploitation. Safety research should be a first class contribution alongside performance improvements.
- Regulators should continue to clarify how existing child protection laws apply to AI generated content and where new offences are needed, while ensuring that legitimate research and survivor support efforts are not inadvertently criminalized.
- Educators and youth organizations must recognize that deepfake abuse is now part of the digital risk landscape for children, alongside cyberbullying and sextortion. Prevention programs should explain how these tools work, what consent means in an era of synthetic media and where young people can seek help if they are targeted.
- Technology companies have an opportunity to invest in defensive AI that can detect, watermark and trace synthetic abuse imagery, and to share those tools widely with trusted safety organizations and law enforcement partners.
Key takeaways and what to watch
The new Hugging Face study is a stark reminder that powerful generative models are not neutral. When they are deployed without strong safeguards, they can quickly become part of an ecosystem that mass produces sexualized images of children and facilitates new forms of exploitation and revictimization.
There is growing evidence that AI generated child sexual abuse material is widespread, becoming more extreme and increasingly integrated into mainstream platforms as well as hidden networks. Legal frameworks and enforcement efforts are starting to catch up, with new laws targeting AI specific tools and global operations focused on synthetic imagery, but the gap between what is technically possible and what is socially acceptable remains wide.
The next two to three years will likely determine whether generative AI becomes primarily a force for creative expression and productivity or a normalized part of online abuse. Studies like the one using Perplexity Sonar on Hugging Face are crucial because they give a data driven look at how misuse actually happens, rather than how platforms hope their tools will be used. The challenge now is to turn that evidence into concrete changes in model design, platform governance and law so that children are better protected in a world where any image can be manipulated and any face can be stolen.







