AI Porn in 2026: How Much Is Out There, Who Makes It, and What the Law Does

How much AI-generated sexual content is being uploaded to video hosts and social platforms? The honest answer is that nobody outside the platforms can say, and the platforms are not saying. Checking the public policies and transparency reports of Aylo (Pornhub’s parent), YouTube, Meta, Reddit, X and Telegram, we found no published count or share of AI-generated sexual uploads on any of them. Some policy pages could not be read directly, so read this as “none found” rather than a proof that none exists, but the absence is itself the first finding of this article.
What exists instead is a set of indirect measurements: child-safety hotline counts, audits of the advertising and traffic behind “nudify” tools, one-off studies of a single chatbot’s output, and population surveys. Each measures something different, and several are easy to misread. This guide walks through what each one actually shows, who profits from the tool ecosystem, and where regulation and enforcement stand as of 4 October 2026.
Two scope notes. First, this is an analysis of measurement, harm and policy: it contains no explicit description, no instructions, and no directory of services. Companies are named only where a regulator, court or credible investigation named them. Second, “AI porn” covers three very different things, and most of the confusion in public debate comes from blending them:
- Consensual adult content made or enhanced with AI, such as synthetic performers or AI companions. Legal in most places, and a business-model question.
- Non-consensual intimate imagery (NCII): sexual images or videos of a real person made without their consent, usually called deepfakes, including images produced by “nudify” or “undress” tools. This is the category where almost all of the documented harm and almost all of the new law sit.
- AI-generated child sexual abuse material (CSAM): illegal everywhere this article discusses, whether or not a real child is identifiable.
The technology is the same across all three. Consent is what separates them.
The number nobody publishes
The 2023 “State of Deepfakes” report from the vendor Security Hero is still the most-quoted baseline: it counted 95,820 deepfake videos online, 98% of them pornographic, and 99% of the people targeted in that pornography were women. It is worth being clear about what that is. It is a 2023 snapshot from a security company’s own sample, not a peer-reviewed census, and it predates the current generation of video models. It is useful for the direction and for the gender skew; it is not a measure of today’s volume.
Nothing comparable has been published for 2026, and the reasons are structural:
- Platforms do not label. A video hosted on a tube site or social platform is not reliably tagged as generated, so even the host often cannot say how much of its catalogue is synthetic.
- Detection is weak. Classifiers that look strong in a vendor’s lab are less reliable on new generators in the wild, which is why serious studies rely on sampling plus human review rather than automated counts.
- Consent is invisible. Even a perfect count of synthetic sexual images would not tell you which ones depict a real person who never agreed. The largest study of its kind, covered below, says so explicitly.
What the measurements do show
Child-safety hotlines: the most rigorous data, and the most misread
The Internet Watch Foundation (IWF) in the UK has analysts who manually assess reported material, which makes its AI figures the most reliable on this subject. In its 2025 annual report, the IWF recorded 3,443 AI-generated child sexual abuse videos in 2025, up from 13 in 2024, more than 260 times as many. It also recorded 491 reports containing realistic AI-generated child sexual abuse imagery, up 154% from 193 the year before, and 8,029 criminal images and videos identified from those reports.
The US National Center for Missing & Exploited Children (NCMEC) reports far larger numbers, and they need a warning label. NCMEC says its CyberTipline received more than 400,000 reports with a generative-AI “nexus” in 2025, more than 182,000 of which involved offenders possessing, generating or attempting to generate AI-made abuse material, out of 21.3 million reports in total. For comparison, the 2024 figure for AI-related reports was about 67,000.
The catch, documented by Stanford researcher Riana Pfefferkorn in January 2026, is that the “Generative AI” box on NCMEC’s reporting form means different things to different companies. Bloomberg found that one company’s roughly 380,000 flagged reports in the first half of 2025 were all hash matches against known abuse material found while screening AI training data, and the company said none of them was AI-generated material. By Pfefferkorn’s arithmetic, at least 78% of the roughly 485,000 AI-flagged reports in that half-year did not involve AI-generated abuse material at all. Her conclusion is that NCMEC’s form needs more than one checkbox. For this reason we treat NCMEC’s totals as a measure of reporting activity involving AI, and the IWF’s analyst-verified counts as the better measure of AI-generated material itself.
Surveys: how many people are affected
A UNICEF, ECPAT and INTERPOL study across 11 countries, published in February 2026, found that at least 1.2 million children said their images had been manipulated into sexually explicit deepfakes in the past year, in some countries as many as 1 in 25 children. These are nationally representative household surveys, so they measure victims rather than uploads, which is arguably the more important number. UNICEF’s position is that sexualised AI images of children are child sexual abuse material, “and there is nothing fake about the harm it causes.”
One chatbot, eleven days
The sharpest single measurement came from a platform failure rather than a platform report. After the Grok image tool on X introduced a one-click editing feature, the Center for Countering Digital Hate (CCDH) sampled 20,000 of the 4,621,335 images Grok posted on X between 29 December 2025 and 8 January 2026. It classified 65% of the sample as sexualised photorealistic images of people, and extrapolated to an estimated 3.0 million sexualised images in 11 days, about 190 per minute, including an estimated 23,338 that appeared to depict children.
Read the method carefully, because it is a modelled estimate, not a platform count. CCDH did not analyse the prompts, so its own report states that the findings “do not provide an assessment of how many of the images were created without the consent of the people pictured.” What the study does establish is that a mainstream platform’s built-in tool produced sexualised imagery at a rate no moderation team could review by hand. Regulators noticed: the UK regulator Ofcom opened a formal Online Safety Act investigation into X in January 2026, the European Commission opened Digital Services Act proceedings on 26 January 2026, and California’s attorney general sent a cease-and-desist letter on 16 January. As of reporting at the end of September 2026, we found no fine or final decision in any of them.
The ecosystem: who makes money
Behind the content is a commercial ecosystem of “nudify” or “undress” sites and apps that turn an ordinary photo of a real person into a fabricated nude. Because these services generate the images on request, they are the main source of non-consensual material rather than a side channel.
The most detailed economic analysis is by the investigative outlet Indicator, which manually reviewed 85 such websites in 2025. Its estimate is that the nudifier economy may be worth up to $36 million a year. That is an estimate built from traffic and pricing data, and Indicator labels it as one. The same review found the sites leaning on mainstream infrastructure: source-code inspection suggested Amazon and Cloudflare provided hosting or content delivery for 62 of the 85, and Google sign-in was enabled on 53.
The services also depend on mainstream advertising. In a September 2026 audit, Indicator found at least 11,336 ads for nudify tools on Meta’s platforms since February 2026. Meta eventually removed 85.7% of them, leaving 1,616 with no moderation action, and at least 5,909 of the ads promoted domains or publishers that Indicator had already documented and shared with Meta. Meta had sued the maker of one such app, CrushAI, in Hong Kong in June 2025; the audit suggests the broader problem persisted after the lawsuit.
Enforcement so far
Enforcement has produced real closures, but it has been slow and partial:
- San Francisco City Attorney sued 16 nudify sites in August 2024, later expanded to 22 operators; reporting says roughly ten were taken offline or geo-blocked in California, and one operator agreed to a permanent injunction and a $100,000 penalty in 2025.
- Mr. Deepfakes, long the best-known deepfake-porn forum, shut down in early May 2025, after investigative reporting by several outlets, with a notice saying a critical service provider had terminated service permanently.
- Civitai, a large model-sharing platform, banned models designed to reproduce real people’s likenesses on 27 May 2025, a change attributed to payment-processor pressure and new US and EU rules. 404 Media’s assessment was that it “significantly” hampered the non-consensual ecosystem “at least temporarily.”
- Italy’s data-protection authority ordered an emergency halt to the processing of Italian users’ data by the app Clothoff in October 2025, citing no consent mechanism, no age barrier and weak labelling.
- Ofcom fined a nudification site £50,000 in November 2025 for having no effective age checks.
- In Australia, a court ordered a man to pay A$343,500 over sexual deepfakes of six women in the first case of its kind, and the eSafety Commissioner’s formal warning led one UK-based provider to withdraw its nudify services from the country.
Payment processors have been the most effective pressure point. A bipartisan group of US state attorneys general wrote to Visa, Mastercard, American Express, PayPal, Google and Apple in August 2025 demanding they stop enabling deepfake-porn payments.
What the law says in October 2026
| Jurisdiction | What exists | Status |
|---|---|---|
| United States, federal | TAKE IT DOWN Act: criminalises publishing non-consensual intimate images, including AI “digital forgeries”, and requires covered platforms to remove them within 48 hours of a valid request | Signed May 2025. The platform duty took effect on 19 May 2026, when the FTC began enforcement and sent compliance letters to 15 platforms. We found no FTC enforcement case yet |
| United States, civil | DEFIANCE Act: a federal right to sue over sexual deepfakes | Passed the Senate by unanimous consent on 13 January 2026; reported as stalled in the House in July 2026 |
| United Kingdom | Offence of creating or requesting a sexually explicit deepfake of an adult without consent; Crime and Policing Act 2026 adds an offence for making or supplying tools designed to generate intimate images | Creation offence in force from 6 February 2026. Act received Royal Assent on 29 April 2026; we could not confirm the in-force date of the tool offence |
| European Union | Directive 2024/1385 requires member states to criminalise non-consensual sexual deepfakes. The AI Act adds disclosure duties for AI-generated content | Directive transposition deadline 14 June 2027. AI Act Article 50 was due from 2 August 2026; law-firm reporting says a 2026 amendment moved some marking deadlines to 2 December 2026 and added a new prohibition on systems that generate non-consensual intimate imagery. Check the Official Journal text before relying on the details |
| Australia | Criminal offence for sharing sexual deepfakes, up to 6 years (7 aggravated); the government announced plans to ban nudify tools | Offence in force; the tool ban’s status is unconfirmed |
| South Korea | Possessing or viewing sexual deepfakes is punishable | Police figures reported by the Korea Times: 1,553 deepfake cases between November 2024 and October 2025, about 35% of all cybersex-crime cases, with roughly 62% of suspects teenagers |
| Denmark | Proposal to give people copyright-style control over their likeness | Politically agreed in 2025; adoption not confirmed |
The pattern across jurisdictions is a shift from punishing the person who posts an image toward regulating the tool and the platform: banning nudify tools, imposing takedown deadlines, and making platforms prove their risk assessments. The US platform duty is the clearest test case, because it has a date, an enforcer, and a public complaint portal.
The consensual side, and why it is hard to size
A fair article has to say that consensual AI adult content exists and that nobody has measured it credibly. We looked for a methodologically transparent market-size figure for AI-generated adult content and found none; the numbers that circulate come from aggregator and SEO sites that do not disclose their methods, so we do not cite them. The closest quantified neighbour is AI companion apps generally: Appfigures estimated roughly $82 million in consumer app-store spending on them in the first half of 2025, but that covers all companion apps and does not separate out sexual use.
We also could not read the primary AI-content policies of the largest adult platforms, so claims about their rules, such as requirements that AI content depict a verified creator, rest on trade blogs and should be checked against the platforms’ own terms. What is clear is that the boundary between legitimate and abusive use is consent and identity, not the technology, and that payment processors are enforcing that boundary more consistently than most platform moderation teams.
Detection and moderation: where it breaks
- Hash matching works for known images, not new ones. StopNCII.org, the main tool for adults, reports more than 2 million images protected, with partners including Meta, TikTok, Reddit, Snap, Aylo, OnlyFans and X. It works by matching a digital fingerprint of an image the person already has, so it protects against the spread of a known file; it does not catch a newly generated one. It covers adults only, and only on participating public platforms.
- Labelling is unreliable. An Indicator audit of 516 AI-generated posts across five major platforms found about 30% correctly labelled.
- Reporting systems have failed visibly. In a July 2024 decision about an AI-generated intimate image of a public figure in India, Meta’s Oversight Board found Meta had failed to remove it until the Board intervened, after the user’s report was automatically closed within 48 hours.
- The ad systems are a gap of their own, as the Meta audit above shows: repeat domains and shell advertiser names passed review.
Ofcom has also made hash matching a recommended measure for in-scope UK services, in force from 30 September 2026, which will increase coverage but, again, only for previously shared images.
What a real measurement would look like
Based on the gaps above, four changes would turn this from estimation into measurement: platforms publishing counts of AI-generated sexual content removed, split by whether a real person was depicted; redesigning NCMEC’s reporting form so a “generative AI” flag has one meaning; independent audits of ad-review systems, which Indicator has effectively been performing; and provenance labelling that survives upload, which today it mostly does not. Until then, the figures in this article are the best available, and each one should be read with its definition attached.
If you or someone you know is affected
- Adults: StopNCII.org creates a digital fingerprint of an image on your own device, without uploading it, so participating platforms can block it.
- Under-18s: Take It Down from NCMEC does the same for images of people who are, or were, under 18.
- In the US: TakeItDown.ftc.gov accepts complaints about platforms that fail to act on a valid removal request.
Frequently asked questions
How much AI-generated porn is uploaded to video sites?
There is no reliable public number. None of the platforms we reviewed publishes a count or share of AI-generated sexual uploads, and no independent audit of tube-site uploads that we could find fills the gap. The measurements that exist, from hotlines, surveys, ad audits and one-off studies, measure related things.
What is a “nudify” app?
A tool that takes a photo of a real person, usually a clothed one, and generates a fabricated nude or sexualised version. Because the person in the photo did not consent, the output is non-consensual intimate imagery, and when the person is a minor it is child sexual abuse material.
Is making a sexual deepfake illegal?
In a growing number of places, yes. The UK criminalised creating or requesting one for an adult from 6 February 2026, Australia has a criminal offence of up to six years, South Korea punishes possession, and in the US the TAKE IT DOWN Act criminalises publishing them and requires platforms to remove them within 48 hours of a valid request. Details and thresholds vary by jurisdiction.
Are the NCMEC numbers for AI-generated abuse reliable?
Treat them as a measure of reports involving AI, not of AI-generated material. A Stanford analysis showed that one company’s large batch of reports were hash matches on known material found in AI training data, not AI-generated content, so the IWF’s analyst-verified counts are the more precise measure.
Who is making money from nudify tools?
Indicator estimated the economy at up to $36 million a year across the 85 sites it reviewed, with the sites relying on mainstream hosting, sign-in and payment services. Payment-processor pressure has been the most effective enforcement lever so far.
Why has regulation taken so long?
Most of the harm falls on people who cannot easily identify who made the content, the services are often offshore, and platform duties only began to bite in 2026, such as the US takedown requirement from 19 May. The first decisions in the larger regulatory cases, including those about X and Grok, were still pending at the end of September 2026.
Related
- Uncensored AI Models: What They Are and How They’re Made, on how safety behaviour in models can be removed and what that has been used for
- Deepfake and generative AI in the glossary
- LLM Hallucinations: Why They Happen and How to Reduce Them, for a different way AI output fails without anyone intending harm