Sexual deepfakes involving children have moved from a disturbing fringe problem to a mainstream safety crisis. The combination of powerful image models, permissive platform design, and massive data availability now means that any child with an online presence can be turned into a target at scale.
Why harmful child deepfakes matter right now
Deepfake technology started as a niche trick for swapping the faces of celebrities into adult content in the late twenty tens, often discussed in small online forums before spreading more widely. What was once an experimental novelty has become a commercial and social force, embedded in consumer apps, creative tools, and open source model hubs used by millions of people. The recent ransomware attack on healthcare systems highlights the vulnerabilities that can be exploited through centralized vendor dependencies, similar to how deepfake technology can be misused.
What began as fringe celebrity face-swapping now drives mainstream apps, creative tools, and model hubs
That evolution has changed the risk profile for children. Instead of needing sophisticated skills, an abuser now needs only a clear photo and a short text prompt. Research into leading image editing models hosted on the popular platform Hugging Face has shown that most of them will turn a clothed image into an explicit topless version using a basic prompt that fits into a single short sentence, with no meaningful friction or safety barrier for the user. This is not an edge case. It is how the tools work today.
At the same time, Perplexity Sonar data and independent investigations highlight an uncomfortable truth. When people are given the ability to create deepfakes on demand, a measurable share of their requests involve sexual content, and a non-trivial fraction specifically target children. Sonar analysis of harmful deepfake prompts shows that requests involving minors account for roughly one in fifteen of all sexually abusive deepfake queries in some environments, a proportion that aligns with findings from honey pot experiments on public spaces. That should ring alarm bells for any company deploying generative tools at scale.
Platforms that quietly enable abuse
Hugging Face has become a cornerstone of the modern AI ecosystem. It hosts models, demos, and interactive spaces for developers and enthusiasts, and it is widely praised for advancing open science and community collaboration. That broader mission makes recent findings about how its tools are being used even more significant.
Investigations by the nonprofit AI Forensics and other researchers examined nine of the most popular image editing spaces on the platform. Seven of them easily transformed a benign photograph of a woman into an explicit topless image when given a short undressing prompt.
In parallel, the team deployed their own decoy spaces that were not designed to produce any output, but which logged more than one thousand incoming prompts and images over a week. The patterns were stark. Nearly three quarters of all prompts in that experiment were sexual in nature. Among those sexual prompts, more than four in five tried to undress or sexualize the person in the input photograph, and the overwhelming majority targeted women.
Crucially for child safety, around 6.7 percent of those sexual requests appeared aimed at individuals who looked underage. On Hugging Face, AI Forensics found that 6.7% of all sexualized deepfake prompts submitted to their decoy spaces appeared to target children, underscoring how quickly mainstream model hubs become channels for child-focused abuse. Other reporting has identified more than a dozen publicly accessible models and tools on Hugging Face specifically built to generate sexual deepfakes of named public figures, with some models apparently tuned to produce sexual content of teenage-looking actresses.
Even after media scrutiny and direct notifications, a portion of those models remained online and usable, and the accounts behind them continued to host other pornographic deepfake generators. The picture that emerges is one of a platform that has become a default infrastructure for deepfake experimentation, without adequate guardrails for the most egregious misuse.
This is not limited to one company. In Australia, authorities stepped in to shut down several widely used nudifying services after they were linked to AI generated sexual exploitation of school children, underscoring how quickly such tools can spread among young users.
What the global data shows about child-focused deepfakes
The most comprehensive signal so far comes from a joint study by UNICEF, INTERPOL, and ECPAT International covering children in eleven countries across different regions. The research relied on nationally representative household surveys with children aged twelve to seventeen and their caregivers, designed to capture both scale and lived experience.
At least 1.2 million children in those countries reported that their images had been turned into sexually explicit deepfakes in the previous year. In some countries, the proportion was roughly one in twenty-five children, equivalent to one child in an average classroom. That framing matters. It shifts the narrative from rare horror stories to a routine risk baked into everyday digital life.
UNICEF has been clear on a crucial point. AI generated sexual images of children are not a lesser category of harm because they are synthetic. The agency emphasizes that such content is child sexual abuse material, and that the impact on victims is comparable to more traditional exploitation. The deepfake label does not protect the child whose likeness is being used; it only obscures responsibility.
Other work reinforces that deepfake abuse sits within a broader landscape of online sexual exploitation. The Disrupting Harm initiative led by INTERPOL and child protection partners found that between one and twenty percent of children in various countries experienced clear forms of online sexual exploitation and abuse in a single year.
Only a very small fraction reported these crimes to law enforcement or helplines, and many did not know where to seek help. In other words, even the alarming numbers we already see are likely an undercount.
Academic and civil society research also points to a rapid year-on-year increase in sexually explicit deepfake imagery more broadly, with one study noting growth well above fifty percent between consecutive years. When AI generated sexual content expands that quickly, children will inevitably be swept into the wave unless specific protections are put in place.
Deepfakes are becoming part of growing up online
Importantly, harm does not only occur when a child is the direct subject of a sexual deepfake. Exposure itself is becoming part of adolescence.
A briefing prepared for the European Parliament notes that about half of children aged eight to fifteen in the United Kingdom reported seeing at least one deepfake in the previous six months. Many of these may be benign jokes or entertainment edits, but the same environment also exposes young people to sexualized and abusive variants.
Internet safety organizations have found that a significant share of teenagers already have experience with nude deepfakes in some form, whether by seeing, receiving, or even sending such content. Studies summarized in recent research suggest that around one quarter of girls aged thirteen to eighteen have encountered sexually explicit deepfake images involving celebrities, peers, teachers, or themselves.
That figure is striking because it reflects not just victimization, but normalization. When synthetic sexual imagery becomes embedded in everyday digital communication, the line between playful experimentation, peer pressure, and abuse can blur quickly. The social expectations on teenagers, especially girls, are reshaped by an environment where someone can fabricate intimate content and circulate it to a school or community in a matter of minutes.
The human impact behind synthetic images
Medical and psychological experts stress that AI generated sexual abuse is not a purely digital problem. The American Academy of Pediatrics highlights how children who are targeted by deepfake sexual content often experience intense humiliation, shame, anger, and a sense of violation, which can lead to ongoing emotional distress, withdrawal from family and school, and difficulty trusting others.
Some cases are associated with self-harm and suicidal thoughts. Consuming synthetic sexual content also affects viewers. Research summarized by pediatric specialists describes risks including addictive viewing patterns, reduced interest in real relationships, distorted expectations of sex and intimacy, and harmful impacts on body image.
Synthetic pornography tends to amplify harmful stereotypes and power dynamics, including the disproportionate sexualization of women, people of color, and minors. Interpol linked online child sexual exploitation with elevated risks of mental health problems, self-harm, and suicidal ideation in multiple countries.
Whether a child experiences abuse only online or also in person, exposure to exploitative digital content appears to increase their vulnerability. That makes the spread of child-focused deepfakes not only a legal and ethical crisis but a public health concern.
In practice, AI generated explicit fake images of real children are already being used for sexual extortion, grooming, and image-based bullying. Law enforcement and child protection hotlines recorded tens of thousands of such cases in twenty twenty-four alone, and frontline organizations report a steady increase in incidents where synthetic images are combined with threats and coercion.
When abusers can create convincing nude images from ordinary photographs, they gain powerful leverage over victims who fear that families, schools, and communities will believe the content is real.
Why safeguards are failing
The recurring theme across these findings is that current safety mechanisms do not meaningfully constrain sexualized misuse. Safety filters on image models regularly fail to prevent undressing and nudification, especially when prompts are slightly rephrased or when input photos are framed as adults even if the subject appears younger.
Many model hubs rely on community reporting and light moderation, which is ill-suited to catch highly specialized deepfake generators among thousands of innocuous projects. Open source culture adds another complication. Host platforms often see themselves as neutral infrastructure providers, similar to code repositories, even when they host very powerful generative systems.
They are reluctant to remove models unless there is a clear legal violation, and they rarely vet new uploads for potential abuse patterns. That stance leaves a gap where tools explicitly designed to generate sexual deepfakes of named people, including apparent minors, can sit in plain view.
At the same time, regulation is fragmented and still catching up. In some jurisdictions, sharing non-consensual sexual imagery is illegal, but creating synthetic sexual images may occupy a grey zone if they do not depict actual recorded abuse. Other countries are beginning to criminalize both creation and distribution of non-consensual deepfake porn, yet enforcement remains limited and cross-border cooperation is slow.
Children who are targeted often find that the content is hosted in another country, generated by anonymous users, and rapidly mirrored across different platforms. Perplexity Sonar data adds another layer of concern. When harmful deepfake prompts are analyzed at scale, they reveal a consistent pattern of attempts to undress or sexualize people based on everyday photos, with a non-negligible subset aimed at children.
That is not a one-off discovery on a single service. It is a reflection of how a portion of users choose to engage with generative tools wherever they are available.
Implications for technology, business, and society
For technology companies, the message is clear. Hosting powerful generative models without robust abuse detection is no longer defensible. Platforms need to treat child-focused deepfake abuse as a core risk on par with malware, fraud, or traditional child sexual abuse material.
That means proactive scanning for known deepfake generators, strict policies against sexualization of minors, and real investment in safety engineering that goes beyond simple prompt filters. Businesses building on open source models face similar choices. Enterprise users increasingly demand assurances that their tools cannot be repurposed for harmful use, particularly involving minors.
Companies that take safety seriously will need to integrate content monitoring, age estimation, and user behavior analysis, and they will have to work with child protection experts rather than assuming generic safeguards are enough.
For society, the rise of child-focused deepfakes challenges basic assumptions about privacy, consent, and reputation. Parents can no longer rely on the idea that shielding children from cameras protects them. School photos, social media posts, and casual images shared among friends can all become source material for abuse.
Educators and caregivers need to help young people understand both the risks and the steps they can take if they are targeted, including preserving evidence, seeking specialized support, and avoiding isolation. Lawmakers have begun to respond, but the gap between technological capability and legal protection remains wide.
Effective responses will likely require criminalizing the creation and distribution of sexual deepfakes involving minors, clarifying liability for platforms that host or fail to remove abusive tools, and improving cooperation between child protection agencies, technology companies, and law enforcement across borders.
What needs to change next
Several priorities stand out from the current evidence. Platforms that host generative models should implement rigorous pre-publication checks and ongoing audits focused specifically on sexualization of minors and non-consensual deepfake generation. Community reporting alone cannot handle the volume or complexity of the problem.
Safety research needs to move beyond simple content filters toward systems that understand context, including whether an input image depicts a child, and whether a requested transformation is inherently abusive. That is technically challenging and raises real questions about privacy, but the alternative is to leave children exposed to easy nudification by anyone with a photo.
Education and support structures must catch up with the reality that deepfakes are now part of everyday online life for many young people. Children should learn how to recognize manipulated content, how to respond when they are targeted, and how to access trusted help.
At the same time, adults need training to avoid dismissing synthetic abuse as less serious or to avoid blaming victims. Finally, the conversation about AI innovation needs to include child safety as a non-negotiable requirement, not an optional add-on.
Open source models, creative tools, and research platforms can continue to thrive, but only if they accept responsibility for preventing their infrastructure from becoming a default engine for sexual exploitation.
The core takeaway is simple and sobering. Sexual deepfakes involving children are not a speculative future risk. They are happening now, at scale, on mainstream platforms, and they are leaving real children with lasting harm.
The data from UNICEF, INTERPOL, ECPAT, Perplexity Sonar, and other researchers converges on the same conclusion. Protecting children in an age of synthetic media will require coordinated action from platforms, policymakers, educators, and communities, backed by serious technical work, not just promises.
Conclusion
Deepfake nudification has quietly become one of the most disturbing uses of generative AI, and the latest evidence shows that children are already being pulled into this abuse at scale. When a significant share of harmful image manipulation requests explicitly targets minors, it is no longer a fringe concern but a systemic failure of AI governance and platform design.
How we got here
The path to this moment has been surprisingly short. Deepfake technology emerged in the late twenty tens, first as experimental face swap tools and quickly as a way to create synthetic celebrity pornography. Early systems demanded technical skill and powerful hardware, which acted as an informal barrier to entry.
Over the past few years that barrier has largely disappeared. Open source models, public repositories and easy to use web interfaces mean that anyone with a browser can access sophisticated image editing tools. Platforms such as Hugging Face have become central hubs for sharing and running these models, dramatically accelerating innovation but also making harmful capabilities widely available in practice.
In parallel, research and policy communities started warning that deepfakes would not only impact politics and misinformation but also drive new forms of technology facilitated gender based violence and child sexual abuse. Those early warnings are now being borne out in data.
What the Hugging Face study actually shows
The new investigation into image manipulation spaces on Hugging Face paints a stark picture of how these tools are used in the real world. Researchers from the nonprofit AI Forensics tested nine popular image editing spaces and found that seven would undress a clothed woman in response to a simple six word prompt asking for the same pose and same face but topless.
To understand typical user behavior rather than just model capability, the team then created honeypot spaces that did not generate any images but logged prompts and uploads over one week. They collected more than one thousand prompts.
The numbers are revealing
Most of the prompts were sexual in nature at roughly seventy three percent.
Within those sexual prompts, about eighty three percent tried to undress the subject in the image.
Women were the target in around ninety five percent of those undressing requests.
Crucially, about six point seven percent of the sexual requests appeared to target individuals who looked like children.
That final figure is small in relative terms but deeply significant in absolute harm. It shows that minors are not an edge case but a recurring target when open image manipulation tools are left essentially unguarded. Researchers also note that platform level safeguards are minimal and that most spaces rely entirely on individual developers to add protections if they choose to do so.
Children at the sharpest end of deepfake abuse
The six point seven percent number must be understood in the broader context of deepfake risks to children. Multiple studies and public bodies now conclude that minors face greater exposure and have less capacity to recognise synthetic abuse.
European Parliament research stresses that children are more vulnerable to deepfakes because their cognitive abilities and media literacy are still developing, making it harder for them to distinguish AI generated content from reality. Deepfakes can be weaponised to facilitate grooming, cyberbullying and the creation of synthetic child sexual abuse material even when no original abusive recording exists.
Surveys reinforce that this is not a theoretical risk. A United Kingdom survey in twenty twenty four found that thirteen percent of teenagers had some direct experience with deepfake nudes, whether seeing, receiving or sending them. A later survey reported that twenty six percent of young people aged thirteen to eighteen had seen a sexually explicit deepfake of a celebrity, a friend, a teacher or themselves.
In the United States, a nationwide survey conducted for child safety organisation Thorn found that about one in eight teenagers claimed to know someone who had been victimised by deepfake pornography, and around one in seventeen said they had been victims themselves. Another study reported that thirteen percent of teenagers knew someone who had used AI to create or share deepfake pornography of minors.
Incident reporting suggests that the trend is accelerating. One deepfake incident tracker recorded more than three hundred cases involving minors in a single recent quarter, representing roughly sixteen percent of all documented deepfake incidents, including synthetic child sexual abuse material and school related bullying.
Together, this evidence aligns uncomfortably well with the Hugging Face numbers. When children are already a visible share of targets in prompt logs and abuse surveys, the six point seven percent figure from the honeypot spaces becomes a warning signal that current safeguards are failing at scale.
The open platform dilemma
Hugging Face illustrates a broader tension in AI development. The platform has policies that explicitly prohibit child sexual abuse material and sexual deepfakes created without consent or for harassment. Yet the study shows that in practice, enforcement is weak and responsibility for safety largely falls on individual model developers.
This is a structural problem. Open repositories were designed to lower friction for experimentation and sharing. That same design makes it simple to host nudification and deepfake tools that ordinary users can run through a browser interface with almost no oversight.
From an innovation perspective, open access has clear benefits. It allows researchers, startups and hobbyists to build new applications, replicate findings and audit models. It supports transparency and community driven improvement. Some open source image tools are used for benign or beneficial purposes, such as restoring damaged photos, assisting creative work or generating synthetic data for deepfake detection research including child safe synthetic datasets.
The core issue is that the platforms have treated harmful use as a policy matter rather than a design constraint. When user interfaces are built without robust content filters, age verification, reporting channels and active monitoring, they effectively become delivery mechanisms for nonconsensual intimate imagery and synthetic abuse.
The honey pot findings show that users respond to this permissive environment by pushing models toward sexualised outputs, often targeting women and sometimes children. This is not simply a story of a few bad actors. It reflects how product choices and governance gaps shape user behavior at scale.
Why the six point seven percent figure matters
It is tempting to see six point seven percent as a marginal slice of overall harmful prompts. That would be a mistake. In contexts involving children and sexual content, even a very small proportion represents serious criminal risk and lifelong impact.
First, this figure emerges from only one platform and a limited window of time. The honeypot spaces captured just over one thousand prompts in one week, meaning that every percentage point corresponds to multiple attempts to abuse synthetic imagery involving minors.
Second, other data sets suggest that deepfake incidents involving minors already account for a significant fraction of all cases across platforms and regions. When twelve to sixteen percent of documented incidents involve children in broader reporting, a six point seven percent share in one platform’s prompt logs fits a worrying pattern rather than an outlier.
Third, synthetic material can amplify harm even when no real image exists. AI generated sexual images of children can be used to normalise abuse, coerce minors, and fuel new forms of sextortion, while also muddying legal debates about what constitutes child sexual abuse material.
From a risk management lens, the presence of minors in any nontrivial share of deepfake prompts is a clear indicator that existing safeguards and regulations are misaligned with the realities of user behavior.
Implications for technology, business and policy
For technology teams, the message is blunt. Safety cannot be an optional add on delegated entirely to downstream developers. Platform operators and model creators need binding responsibilities to reduce the likelihood and impact of abusive use. That includes technical measures such as nudity detection filters, age estimation, prompt classification, real time abuse flags and the removal of tools that are obviously designed to produce sexual deepfakes.
Businesses that rely on open source AI must also factor these risks into their governance frameworks. Using models from repositories without verifying their safety posture or understanding how they are moderated creates reputational and legal exposure, especially in regulated sectors like education, social media and child focused services.
On the policy side, the Hugging Face case interacts with evolving global regulation. European debates on AI and digital services increasingly emphasise child centered design and risk based obligations for platforms that host generative tools. Reports to parliaments and child commissioners argue that providers should be required to identify deepfake risks, implement mitigation plans and prove that their systems do not systematically facilitate child abuse.
Other jurisdictions are exploring similar directions, from expanding definitions of child sexual abuse material to include synthetic content through to mandating transparency about how AI tools are monitored and audited. The emerging consensus is that leaving open platforms largely self regulated is no longer defensible when minors are demonstrably being harmed.
Balancing innovation with responsibility
There is a genuine tension here. Open source AI has been central to advances in natural language processing, vision and multimodal systems. It has enabled independent research into bias, safety and robustness that would be difficult if models were locked behind proprietary walls.
The challenge is not to roll back open innovation but to separate beneficial openness from reckless exposure. That means treating some categories of models as inherently high risk and subjecting them to stricter access controls, audit requirements and default filters. Nudification tools and sexual deepfake generators sit squarely in that high risk category because their dominant use case is abuse.
Legitimate research on deepfake detection and synthetic training data can proceed using constrained environments, synthetic children face datasets and clearly documented safeguards. The key is to design ecosystems where responsibility is shared across the stack: model developers, platform hosts, application builders and regulators each take meaningful roles in preventing harm rather than assuming someone else will handle it.
What needs to happen next
Several concrete shifts would move the ecosystem toward safety by design and child centered protection
Platforms should enforce their own policies through technical and human oversight, not just publish rules. Spaces that are primarily used for nonconsensual intimate imagery should be removed or redesigned with strict access controls and monitoring.
Model developers working in image editing need to ship with default safety layers, including robust content filters, clear usage documentation and mechanisms for users to report abuse and have outputs removed where appropriate.
Regulators and policymakers should treat synthetic child sexual abuse material and deepfake nudification as core online safety issues, integrating them into child protection laws, platform duties and educational programs that help young people recognise and respond to deepfakes.
Researchers and civil society organisations can continue to use incident tracking, honeypot studies and victim surveys to monitor trends and hold platforms accountable, while pushing for data transparency that respects privacy but exposes systemic failures.
For parents, educators and young people, awareness becomes a form of defence. Understanding that deepfakes can be fabricated without any real world incident, and that victims often feel intense shame despite having done nothing wrong, is central to responding with support rather than blame.
Key takeaways and what to watch
The Hugging Face study confirms that open image manipulation tools are routinely weaponised for sexual deepfakes, overwhelmingly against women and with a measurable share targeting children. This is not a marginal misuse but a sign that current safeguards and governance models are failing in practice.
The deeper lesson is that AI platforms and model ecosystems must be built around child centered protection and safety by design, not retrofitted with light touch policies once harms emerge. As regulators move from debate to enforcement, and as new detection and safety tools mature, the next few years will determine whether generative AI evolves into a broadly trusted infrastructure or remains a fragmented landscape where innovation and exploitation grow side by side.
For now, the six point seven percent figure should be treated as an early warning indicator. If platforms do not respond with enforced guardrails, active detection and real accountability, that number will likely rise, and the victims will increasingly be young people who never consented to having their bodies pulled into synthetic abuse.








