AI-generated intimate-image abuse — the manufacture of sexually explicit images or video depicting a specific real person, without that person's consent, using generative machine-learning systems — is the second-generation form of non-consensual intimate imagery. Where the original revenge-porn problem required a real image taken at some point with the subject in it, the synthetic-imagery problem requires only a photograph of the subject's face and a moderately capable model. The face can be lifted from LinkedIn, a yearbook, an Instagram tag, a school newsletter. The output can be a still nude, a sex-act image, or a video. The fidelity has crossed the threshold of plausibility for most viewers; the cost has collapsed; the tooling is widely distributed.

Henry Ajder's 2019 report for Deeptrace was the first systematic mapping: 96% of deepfake video then online was non-consensual pornography, almost entirely of women. The proportion has shifted as deepfakes have proliferated into other categories (political, scam), but the absolute volume of non-consensual intimate deepfakes has grown by orders of magnitude. The 2023 wave of "nudify" apps and websites — services that take a clothed photo and return a synthetic nude — pushed the harm from celebrity-targeted to mass-targeted: high school students were generating images of their female classmates, sending them around the school, and arriving at a Monday morning where the law, the school, and the parents had no playbook.

The collective response moved faster than usual. The U.S. federal TAKE IT DOWN Act of 2025 explicitly covers AI-generated non-consensual intimate imagery, with the same 48-hour platform takedown obligation and criminal penalties as for authentic-image cases. State statutes — California AB 602 (civil), Texas Penal Code §21.165, New York Penal Law §245.15 amendments, and others — created criminal and civil liability for synthetic intimate imagery before federal action. The EU's AI Act addresses synthetic-content disclosure obligations, and the Digital Services Act compels platform takedown. The UK Online Safety Act 2023 criminalized sharing without consent and the Criminal Justice Bill 2024 extended to creation without consent. South Korea, after the Telegram "nth room" cases and a 2024 deepfake wave targeting school students, accelerated criminal penalties for both creation and possession of deepfake intimate imagery.

The harm profile mirrors revenge porn but with two additional features. First, the no real image required feature means anyone with a public face can be victimized; there is no protective behavior — never sending nudes, never letting a partner photograph you — that prevents it. Second, the plausible deniability is gone feature means the subject cannot truthfully say "that is not me" in a way the viewer believes, because the viewer can see her face. The combination produces a particularly cruel harm pattern: schoolgirls targeted by classmates; women in politics and journalism whose credibility is undermined by manufactured sex tapes; women whose families and employers cannot reliably distinguish the synthetic from the real.

The doctrinal architecture is still settling. Three questions dominate. First, who is liable: the creator, the host, the model developer, the API provider? TAKE IT DOWN targets creators and distributors. Some state statutes reach those who knowingly facilitate. The upstream question — whether providing a model fine-tuned for sexually explicit generation makes the provider liable when users target real people — sits uneasily with Section 230, the AI Act, and product-liability doctrine. Second, consent and intent: must the prosecution prove the perpetrator knew the depicted person was real and did not consent, or is recklessness enough? Statutes vary. Third, what counts as the depicted person: a fully synthetic face that resembles a specific person, a "morph" combining real face and synthetic body, a video generated from a single photo — courts are working out where the line falls.

The romantic intersection is sharp and worsening. The pattern of post-breakup harm now includes the ex who never had nudes manufacturing them. Coercive-control playbooks include threats to generate and distribute synthetic intimate imagery. The school-bullying pattern includes the boy who pays $5 to generate his classmate's nudes and AirDrops them around the cafeteria. The collective regulatory response is necessary but not sufficient: the technology will keep advancing, the prosecution rate is low, and the cultural norm — that this conduct is unacceptable and the recipient should not pass the image along — is the actual point of intervention. Law 4 has built the doctrine. Law 0 — humility about what doctrine alone can do — is what makes the next decade of work honest. The harm is fast; the courts are slow; the schools are the front line.