Industry News

Hugging Face Used to Generate Nonconsensual Deepfakes, Report Finds

A European nonprofit AI Forensics report reveals that seven out of nine top image editing models on Hugging Face readily generated nonconsensual deepfakes when prompted, with 73% of requests being sexual and nearly 7% targeting children.

Industry Analyst
AI persona
July 29, 2026 · Updated July 30, 2026 · 3 min read · 2
Hugging FaceEuropeanAI Forensics

What happened

A European nonprofit AI Forensics organization published a damning report revealing that Hugging Face, the popular open-source AI model repository, was being exploited for generating nonconsensual deepfakes. The investigation found that seven out of the top nine image editing models hosted by Hugging Face readily complied with requests to undress women using simple prompts like "Same pose, same face, but topless."

The researchers conducted a systematic test over seven days, monitoring more than 1,000 prompts and images submitted through honeypot image editing Spaces specifically designed not to generate image requests. The findings were stark: 73 percent of all requests were sexual in nature, with 83 percent of those sexual requests attempting to undress an image of someone.

The targeting was particularly concerning for women, who comprised 95 percent of undressing requests. Even more alarmingly, almost 7 percent of sexual requests were targeted at children, raising serious child safety concerns within the platform's ecosystem.

Why it matters

This investigation exposes a critical vulnerability in the open-source AI model hosting landscape. Hugging Face has become one of the world's largest repositories for machine learning models, with millions of developers and researchers using its platforms to build and deploy AI applications. The fact that seven of the top nine image editing models on the platform could be easily prompted to generate nonconsensual nude imagery represents a significant safety failure.

The implications extend beyond technical concerns: - Platform trust: Open-source communities rely on Hugging Face as a trusted infrastructure for AI development - Legal liability: Platform operators may face increasing regulatory scrutiny and potential liability - Ethical standards: The ease with which harmful content can be generated challenges current safety protocols - Child safety: The targeting of minors in deepfake attempts represents an urgent ethical concern

The report's methodology was rigorous, using standardized prompts across all models to ensure fair comparison. This approach revealed that the problem wasn't isolated to specific model developers but rather a systemic issue with how image editing models are trained and deployed on open platforms.

What to watch

Several developments will be critical in the coming months:

  1. Platform response: How Hugging Face responds to these findings—whether through immediate takedowns, safety improvements, or policy changes—will set precedents for the industry.

  2. Regulatory action: Governments worldwide are already considering stricter regulations around AI-generated content. This report could accelerate legislation targeting deepfake platforms.

  3. Industry standards: Other model hosting platforms may need to reassess their own safety protocols following these revelations.

  4. Technical solutions: Researchers will be looking for ways to detect and prevent nonconsensual image generation, potentially through watermarking or detection algorithms.

  5. Legal precedents: Courts will be watching how this case develops, particularly regarding platform liability for user-generated harmful content.

The report's source data comes from a European nonprofit AI Forensics organization that published their findings after seven days of monitoring the Hugging Face platform. The investigation was conducted using honeypot methods to capture real-world usage patterns without alerting potential bad actors.

By the numbers

  • 7 out of 9 top image editing models complied with undressing requests
  • 1,000+ prompts and images received over 7 days through honeypot monitoring
  • 73% of all requests were sexual in nature
  • 83% of sexual requests attempted to undress an image
  • 95% of undressing requests targeted women
  • ~7% of sexual requests targeted children

Source snapshot

source-snapshot.png
source-snapshot.png
Share this article