News
Seven of Nine AI Tools on Hugging Face Generated Illegal Nude Images, Study Finds
European research group AI Forensics tested popular photo-editing tools on Hugging Face and found that nearly all of them easily generate nude images without the subject's consent, despite the platform's rules banning such content.
Contents
European research organization AI Forensics tested the nine most popular photo-editing tools available on Hugging Face and found that seven of them generate nude images with no safeguards at all, simply in response to a request to remove someone's clothing. The finding undercuts the platform's own terms of service, which ban sexual content created without consent and any material depicting minors.
The researchers at AI Forensics, a European non-profit that audits AI systems, did not use any advanced tricks to bypass safeguards. An eight-word prompt along the lines of "same pose, same face, but without the top" was enough to make the tool generate a nude image based on the uploaded photo. For the tests, the researchers used an AI-generated photo rather than a real person, to avoid causing additional harm.
How the test worked
The team examined the nine highest-rated and most frequently used photo-editing Spaces hosted on Hugging Face. In seven cases, a simple request to remove clothing was enough to make the tool produce an image of a nude person. In parallel, the researchers set up their own decoy Spaces and tracked, over the course of a week, what prompts users were actually entering.
They collected more than a thousand prompts and uploaded photos. Nearly three quarters of them were explicitly sexual in nature, and the vast majority of those requests involved undressing or sexualizing the person shown in the photo. Nine out of ten victims were women, and a small but troubling share of the requests involved people who appeared to be minors in the photos.
Banned in the rules, not in practice
Hugging Face's terms of service explicitly prohibit posting sexual content created without the consent of the person depicted, as well as any material depicting nudity involving minors. The problem is that the platform does not enforce that ban at a technical level. Responsibility for adding filters and blocks falls entirely on the creators of individual tools, and according to the study, only a tiny fraction of them actually do so.
No safeguards are implemented at the platform level. Only the developer can add them, if they choose to, and most don't - Paul Bouchaud, lead researcher at AI Forensics
Bouchaud stresses that the problem isn't limited to a theoretical risk of misuse. Data collected in the researchers' control Spaces shows that users are actually and extensively using these tools for exactly their worst possible application.
Most of the Spaces we tested can be used to create non-consensual, intimate images, and users are in fact using them for exactly that purpose - Paul Bouchaud, lead researcher at AI Forensics
The legal context in Europe
The findings land at a moment when the European Union and the United Kingdom are preparing rules to ban so-called nudify apps, tools that strip clothing from people in photos. The EU itself has already introduced a ban on generating AI deepnude-type content as part of its Digital Omnibus package, but the AI Forensics report shows that a ban on paper and the real-world availability of such tools on major platforms are two very different things.
US law enforcement has in recent months seized several websites hosting ready-made deepfakes, but the problem of tools distributed as open models or scripts on developer platforms remains largely unresolved. As one of the largest repositories of AI models and applications in the world, Hugging Face has become, in this context, a natural test of whether major platforms' moderation claims actually hold up.
What it means for users and regulators
For users in Poland and across Europe, the practical takeaway is the most important one: tools capable of producing illegal, non-consensual images are available without any login or age verification, on one of the most popular platforms for AI developers. That means anyone with a publicly available photo online could become a victim, and prosecuting offenders remains difficult, because the material is generated locally, in the browser, leaving no trace on the platform's side.
The report increases pressure on Hugging Face to introduce moderation at the platform level, rather than relying solely on the goodwill of individual tool creators. Other services hosting open models and applications face similar pressure, since the mechanism described by AI Forensics, easy access to powerful image-editing tools with no output filter whatsoever, is not unique to one platform.
This article does not include a statement from Hugging Face regarding the report's findings, as the company has not yet publicly responded to the study's results in the cited source material.
