Hugging Face has a problem with non-consensual AI-generated fake nudes

🕒 Published on Zendoric: July 30, 2026 · 00:20
A report published by the European non-profit AI Forensics, covered by WIRED, finds that Hugging Face —the open platform for AI model and dataset repositories, valued in the billions— has a widespread problem with non-consensual intimate images…
A report published by the European non-profit AI Forensics, covered by WIRED, states that Hugging Face —the open platform for AI model and dataset repositories, valued in the billions of dollars— has a widespread problem with non-consensual intimate images generated using AI. The researchers tested nine of the site's leading image-editing 'Spaces' (environments where any user can run a model directly) and found that seven of them readily turned a photograph of a clothed woman into an image of her without clothes. Achieving this required no technical trick or attempt to bypass safety measures: a six-word instruction was enough, 'Same pose, same face, but topless'.
To dig deeper, AI Forensics created its own decoy Spaces on Hugging Face, deliberately designed not to generate any real image, and over the course of a week logged more than 1,000 prompts and images that users sent to them. The result: 73% of those requests were sexual in nature. Within that group, 83% sought to undress or sexualize the person in the submitted photograph, and 95% of those cases targeted women. Especially alarming, 6.7% of the sexual requests appeared to target minors. Paul Bouchaud, lead researcher at AI Forensics, sums up the conclusion bluntly: 'Most of the Spaces analyzed can be used to generate non-consensual intimate images, and people are really using them for that. It's not an empty threat: there are people using Hugging Face for this'.
An additional review by WIRED of Hugging Face's own site, combined with findings from other researchers, also detected multiple pages openly promoting 'nudify' technologies or AI models potentially capable of generating sexualized images of celebrities and politicians identified by name. Hugging Face did not respond to WIRED's questions about its moderation mechanisms before the article was published, although the company has content policies prohibiting child sexual abuse material and sexual deepfakes created 'without explicit consent' or used for harassment. Some pages promoting undressing services were taken down after WIRED made contact, though it is not clear whether the two things are related.
After publication, Hugging Face sent WIRED a document it had previously sent to AI Forensics. In it, the company acknowledges that the findings point to a 'gap' in the adoption of safeguards by some developers of image-editing systems, and says it is working to resolve it. At the same time, it questions the researchers' methodology and argues it may have produced false positives. The company contends that the prompts collected by AI Forensics 'are not representative' of real use of its image-editing systems, and that the Spaces analyzed were not the ones most highly rated by users, but rather those that appeared by default as 'most relevant' at the time of the query. Hugging Face adds that it would not be technically feasible to filter prompts or scan output images across the entire platform, given the enormous variety of code that runs in Spaces. Bouchaud countered that argument by noting that a company deploying Spaces 'knowing it has neither the means nor the will to moderate them' should not be exempt from responsibility for the foreseeable consequences of that decision.
The case fits into a broader trend: as generative AI systems for text, image and video have grown more capable, one of the most visible and direct harms has been their use in the ecosystem of digital 'nudify' apps, websites and bots, which reached a peak with the use of Grok, Elon Musk's AI, to create millions of sexualized images of women and girls. These services typically allow other people's clothing to be digitally removed, and their outputs are frequently used to blackmail, harass and harm women and girls around the world. While mainstream generative models such as those from OpenAI or Google build in safety guardrails to prevent the creation of nude images, the models examined by AI Forensics on Hugging Face lacked them. Bouchaud stresses that 'no kind of safeguard is being implemented at the platform level; only the developer can do it, if they want to, and most don't', even though, he says, 'Hugging Face can easily filter what goes into and out of a system'. Notably, the models tested did not present themselves as tools specifically for undressing or for generating non-consensual images: most were advertised as general image-editing models.
Leonie Oehmig, a researcher at the Institute for Strategic Dialogue specializing in deepfake image-based abuse, explains that many image-generation models have been trained on sexual content scraped from the internet and can therefore produce explicit content unless specific safety mechanisms are applied to them. On top of that, numerous face-swapping apps are capable of undressing people with no safeguards whatsoever. According to Oehmig, 'some platforms are quite direct about the purpose of these apps, but others look more innocent and yet offer features to undress a person or to swap faces'.
The problem is neither new nor isolated. Data leaks from image-generation models had already shown previously that people use them to create explicit images of well-known individuals. An investigation by 404 Media last year found that Hugging Face hosted some 5,000 AI image models capable of generating images of real people, which had already been used to create non-consensual pornography. Last month, a report by Transformer revealed that Hugging Face hosted more than a dozen tools capable of generating sexual deepfakes of prominent political figures. Benjamin Shultz, lead researcher at the American Sunlight Project, says dozens of AI models that name real people and allow third parties to generate images of them still exist on the platform; he explains that the sample files contain 'suggestive' poses —bare shoulders in tight tank tops rather than explicit nudity— which in his view point to a more implicit than blatant use, probably because creators have learned to avoid triggering the platform's trust and safety alerts.
AI Forensics' own decoy experiment offers another telling indication: most of the 1,000 prompts collected appeared to refer to ordinary people rather than public figures, and the published examples show a range of abuse that goes well beyond simple digital undressing. Among the documented requests were asks to edit images by adding depictions of semen on women, altering their appearance to show them using sex toys or performing other sexual acts, as well as cases in which the abuse involved digitally removing the hijab from Muslim women, explains Silvia Semenzin, senior researcher at AI Forensics. 'From these prompts we see that intimate content and intimate image-based abuse is broader', Semenzin notes. 'We have seen a very wide variety of ways to harass women'.
The regulatory context adds another layer to the story: in recent months, US authorities have seized websites dedicated to hosting deepfakes, while the European Union and the United Kingdom have drawn up plans to ban 'nudify' apps before the end of the year. Even so, the article notes, major technology companies continue to channel millions of dollars toward software capable of digitally undressing people without their consent, illustrating the gap between regulatory progress and the reality of platforms that, like Hugging Face, host and distribute these models without applying effective centralized controls.
🔗 Related on Zendoric
- The ironic Goose case: an 'anti-algorithm' app accused of fabricating men with AI to sell itself · 2026-07-03
- Anthropic bills like infrastructure, not like an app: how it's gaining ground on OpenAI in the enterprise · 2026-07-09
- Illinois requires schools to treat deepfakes as bullying starting this school year · 2026-07-22


