Artificial intelligence has made it easier to create and share non-consensual intimate images. A new report from the University of California, Berkeley, says AI has lowered the technical skills needed to create this type of sexual abuse material.
The report, published by UC Berkeley’s Center for Long-Term Cybersecurity (CLTC), says the problem is no longer limited to individuals making fake nude images. Researchers describe a larger system that includes AI models, training data, apps, cloud services, payment systems, app stores, search engines and social media platforms.
The report, titled Closing Gaps Across the Ecosystem: Regulating the Technologies that Enable AI-Powered Nonconsensual Intimate Images and Child Sexual Abuse Materials, looks at how U.S. laws currently address these different parts of the system. The researchers say most laws focus on people who create or share abusive material, while fewer rules cover the technologies and services that can help this activity happen on a larger scale.
Berkeley Report Maps the Four Layers of AI Abuse
The researchers divided the AI-powered NCII and CSAM ecosystem into four main layers: the human layer, model layer, product deployment layer and distribution layer. The human layer includes people who create or share abusive AI-generated content.
The model layer includes the technology used to build AI systems, such as training datasets, open-source AI models and platforms that host datasets or models. The product deployment layer covers the apps and services that allow people to use AI systems. This includes generative AI apps, payment processors, infrastructure providers, app stores and search engines.
The distribution layer includes platforms where abusive content can be shared or spread, such as social media sites and other public or private platforms.
The researchers use this framework to show that the problem goes beyond the person who creates an image. Other technologies, services and platforms can also play a role in making the creation and spread of abusive content easier.
AI Makes the Creation of Abusive Images Easier
The Berkeley report says artificial intelligence has made it easier for people to create non-consensual intimate images (NCII) and other abusive material, including child sexual abuse material (CSAM).
In the past, creating manipulated images could require technical skills and specialized software. Generative AI tools can make some types of image manipulation much easier, allowing people with limited technical knowledge to create realistic-looking fake images.
Researchers say this easier access has also helped create a wider network of tools and services that can support the creation and spread of abusive content. This includes AI systems, applications, hosting services and online platforms. Because these parts can work together, removing individual images or shutting down one service may not be enough to stop the wider system.
The report also warns that AI abuse is not limited to adults. As these tools become easier to access, younger people may also use them to create harmful fake images involving classmates, other young people or adults.
Berkeley researchers therefore call for greater education about deepfakes, consent and the potential harm caused by synthetic sexual images. They say people should understand that creating or sharing such images can cause serious harm, even when the images are not real.
Berkeley Study Finds Legal Gaps Across the AI Abuse Chain
A review of 28 federal and state laws by Berkeley researchers found that U.S. regulations do not cover all parts of the technology chain involved in AI-generated sexual abuse.
The laws examined covered California, New York, Texas and Utah. The researchers found that most of the laws focus on people who create or distribute abusive material, while fewer rules address the companies, platforms and infrastructure that can help create, host or distribute it.
These gaps can involve AI model developers, open-source platforms, infrastructure providers and other services involved in deploying AI systems.
Infrastructure providers were one of the clearest examples. According to the Berkeley report, only 4% of the laws examined in the four states provide a pathway to prosecute infrastructure providers that host harmful content.
Researchers say this matters because cloud services, app stores and other infrastructure can help AI models and applications reach users and operate at scale. The report therefore argues that efforts to address AI abuse need to consider the wider technology chain, rather than focusing only on the person who creates or shares the material.
Existing Federal Law Does Not Cover Every Scenario
The Berkeley report also looks at the federal TAKE IT DOWN Act, which was signed into law in May 2025. The law makes it a crime to publish authentic or AI-manipulated intimate images without a person’s consent. It also requires covered online platforms to take steps to remove such content after receiving a valid notice.
However, Berkeley researchers say the law does not address every situation involving AI-generated sexual abuse. One concern is that the law mainly focuses on non-consensual distribution. This may leave gaps in cases where someone creates an abusive image for personal use but does not share it publicly.
The researchers also call for victims to have a private right of action, which would allow them to take legal action against people who create or distribute abusive material and seek compensation for damages.
According to the report, relying only on criminal cases can create challenges for victims and may not provide them with financial compensation for the harm they have experienced.
Berkeley Calls for Greater Oversight of AI Platforms and Infrastructure
Berkeley researchers say the product deployment layer offers the biggest opportunity for stronger regulation. This layer includes the apps and services people use to access AI tools, such as AI applications, payment processors, infrastructure providers, app stores and search engines.
The report recommends policies that would require these platforms to identify and address harmful AI models and training datasets. It also suggests creating ways for people to report harmful models or datasets, along with clear processes for reviewing reports and removing material that violates the rules.
The researchers see the distribution layer as the next area where intervention could be useful, followed by the model layer.
The report’s broader approach is to address potential risks earlier in the process. Instead of waiting for abusive images to spread online, researchers argue that action could also be taken at the platforms, services and technologies that help make such content possible.
Researchers Call for Restrictions on Nudify App Ads
The Berkeley report also recommends that states consider banning advertisements for AI “nudify” apps on social media platforms.
These apps can be promoted as tools that turn ordinary photos into sexually explicit images without the person’s consent. Researchers say limiting these advertisements could reduce people’s exposure to such services and make it harder for the apps to attract new users.
The recommendation focuses on state-level action because individual states may be able to introduce and pass laws faster than the federal government. The researchers see advertising restrictions as one way to address the problem before people use these services to create or share abusive images.
Berkeley Report Calls for Faster Removal of AI Abuse Content
The report also recommends mandatory takedown rules for AI-generated non-consensual intimate images (NCII) and child sexual abuse material (CSAM).
Under the proposal, online platforms that host this type of content would have to remove it within a set period after receiving a valid report or notice.
The researchers identify social media platforms and deepfake websites as important areas for intervention. They also recommend requiring platforms to remove content that helps enable harmful activities, including sextortion.
The proposal would shift some responsibility toward the platforms that host or distribute abusive material. Instead of relying only on criminal investigations after the abuse happens, the researchers say platforms could also have clear legal duties to identify and remove harmful content quickly.
Report Calls for a Clear Data Trail From Training to AI Output
The Berkeley report also recommends stronger controls over the data used to train AI systems. Researchers say AI developers should check training datasets for illegal material and keep records showing where the data and generated content come from.
The report also recommends using standardized cryptographic hashing for training data before it is added to AI systems. Hashing creates a unique digital fingerprint for a file, such as an image or video. This can help systems identify matching material without needing to store or compare the original file directly.
For AI-generated content, the researchers recommend stronger content provenance requirements. These measures could make it easier to identify where synthetic content came from and trace it back to the systems or sources involved in creating it.
Berkeley Says AI Abuse Is Bigger Than Individual Offenders
The report’s central finding is that AI-powered sexual abuse involves more than the individuals who create abusive images. Researchers say a wider network of technologies and online services can help people produce and distribute this material.
This network includes AI models, training datasets, applications, cloud infrastructure and online platforms. These different parts can work together, making it possible for abusive content to be created and shared more easily.
As a result, removing one image or prosecuting one person may not stop similar content from appearing again. The researchers say regulators also need to consider the systems and services that support its creation and distribution.
The report therefore calls for rules covering the full AI NCII and CSAM value chain, with greater attention on platforms and infrastructure providers that may currently face fewer legal obligations.
Berkeley Wants Policymakers to Look Beyond Content Removal
The Berkeley report says policymakers should look beyond the AI models that generate images and examine the wider technology system that helps these tools and their content reach users.
This system includes AI developers, model and dataset platforms, application providers, cloud and other infrastructure companies, payment services, app stores, search engines and social media platforms.
The report’s analysis suggests that existing laws have focused more on individual offenders than on the technology and services that can support AI-generated abuse. The researchers propose shifting some regulatory attention to earlier stages, including where harmful models and applications are developed, deployed, sold and distributed.
As AI image-generation tools become easier to access, the researchers say the challenge is not only removing a fake intimate image after it appears online. Policymakers also need to consider how to reduce the systems and services that can make it easier to create and spread such material in the first place.





