Tech • AI • Robotics • Game

VIDEO
ENFR

Daily Podcast full article

Deepfake porn reaches 8 million

A new peer-reviewed study says AI-generated non-consensual intimate videos ballooned from about 500,000 in 2023 to an estimated 8 million in 2025. The finding shifts the debate from individual “bad actors” to the internet infrastructure, search, hosting and content-delivery systems that let abusive deepfake pornography scale faster than victims can report it.

Generated October 1, 2026 at 6:17 PM1542 words

The number is no longer a warning. It is a system failure

The headline figure is stark: AI-generated non-consensual intimate imagery has grown from roughly 500,000 videos in 2023 to an estimated 8 million by 2025, a sixteenfold jump in two years . That estimate comes from a new peer-reviewed study, “The Backbone of Abuse,” published on September 30, 2026, in the Journal of Online Trust and Safety and led by Sarah Morgan of Lancaster University, with Sophie Nightingale of Lancaster and Hany Farid of Dartmouth College .

The study matters because it does not treat deepfake pornography as a fringe internet horror or a niche moderation problem. It frames it as an industrialized abuse market. The researchers found that nearly all of the AI-generated non-consensual intimate content they identified targeted women and girls, with sites focusing heavily on Hollywood and Hindi-film actors, K-pop artists, public feminists and activists . The pattern is not random. It is a gendered abuse pipeline using cheap generation tools, public photos, search discovery, hosting infrastructure and social sharing to turn identity into a raw material.

The internet’s moderation queue has, in the subject’s own grimly accurate joke, hit a cursed stack overflow. But the overflow is not only about volume. It is about design. Once a fake intimate video is generated, copied, mirrored, indexed and reposted, the burden usually falls on the targeted person to find each instance and request removal. At 8 million files, that model is no longer merely unfair. It is mechanically impossible.

What the new study actually mapped

“The Backbone of Abuse” looked beneath the surface of the abusive sites themselves. According to reporting on the paper, the researchers collected 400 URLs during a six-week period between February and March using keyword searches and Google Alerts, then narrowed that pool to 88 active websites hosting non-consensual intimate imagery . Of those, 38 exclusively hosted this type of content .

The study then used open-source web-analysis tools, including WHOIS-style infrastructure checks, to identify which services those sites relied on . Five names appeared as dominant infrastructure providers: Cloudflare, Google, Namecheap, WordPress and Proton . The researchers described Cloudflare as providing the largest share of services, including hosting, content delivery, domain-name server functions and analytics; Google supplied SSL certificates and advertising space for many of the sites; Namecheap was prominent in domain registration; WordPress appeared through publishing and content-management services; and Proton appeared through mail services .

That does not mean these companies created the images, approved the abuse, or necessarily knew about every domain. The more important point is structural: dedicated deepfake abuse sites do not float in a dark-web vacuum. They sit on ordinary internet rails. They use the same infrastructure that legitimate sites use to load quickly, appear trustworthy, receive traffic, serve ads, register domains and communicate with users.

This is why the study’s emphasis is different from a typical content-moderation story. The researchers are asking whether infrastructure companies should withdraw services from confirmed abuse sites, especially those built primarily or exclusively to host AI-generated non-consensual intimate imagery . If the creation layer has become easy and cheap, then distribution becomes the pressure point.

Search makes the abuse discoverable

One of the most disturbing findings is not just that the sites exist, but that they are easy to find. Forbes reported that 93 percent of the 88 identified AI-generated non-consensual intimate imagery sites were accessible through a standard Google search . That turns a supposedly hidden abuse economy into a searchable one.

Discoverability is crucial. A deepfake file on an obscure server can still cause harm, but a deepfake file indexed by search becomes reputational ammunition. It can be found by classmates, employers, fans, journalists, political opponents, stalkers or strangers. For public figures, the result is mass humiliation. For private people, it can become blackmail, workplace harassment, school bullying or domestic abuse.

The study’s focus on search, hosting and infrastructure also helps explain why watermarking alone cannot solve the problem. Watermarks may signal that a file was AI-generated at the moment of creation, if the tool applies them and if they survive editing. But abusive networks copy, crop, transcode, re-upload and mirror content. They can strip visible indicators, degrade metadata and move files across domains. Provenance can help, especially for lawful media and platform accountability, but it cannot carry the whole enforcement burden once a file enters an adversarial distribution system.

The law is moving, but takedowns are still victim-heavy

The legal landscape is changing. Forbes noted that countries including England have enacted rules prohibiting the sharing, creation or solicitation of pornographic deepfakes, and that the U.S. TAKE IT DOWN Act, signed in 2025, gives people protections when intimate images, including deepfakes, are shared without consent . The law requires covered websites to establish a notice-and-removal process to take down non-consensual intimate imagery within two days of receiving a victim’s notice .

That is important, but the researchers argue that law alone is not enough. A notice-and-takedown regime still often begins after the harm has occurred. It can also force victims into a repetitive search-and-report loop: find the image, document it, submit a request, wait, repeat when a mirror appears. When the abusive ecosystem produces millions of files, that process becomes a punishment layered on top of the original violation.

Sarah Morgan put the prevention question directly: can the distribution supply be cut? The research team calls on infrastructure providers to block sites that exclusively host AI-generated non-consensual intimate imagery and to suspend services for mixed-content sites until good-faith efforts are made to remove the abuse . They also recommend perceptual hashing, a method that creates digital signatures of confirmed abusive material so services can detect and stop redistribution .

Hashing is not a magic wand either. It works best for known content and can struggle when files are heavily altered. But in combination with fast reporting channels, trusted flaggers, platform-to-platform signals and infrastructure-level enforcement, it can reduce the whack-a-mole problem. The strategic aim is not to make abuse impossible in every corner of the internet. It is to make mass distribution harder, slower, more expensive and less searchable.

The infrastructure debate will be hard

The immediate policy challenge is that “infrastructure” is not one thing. A company may host a site, protect it from denial-of-service attacks, provide DNS, serve ads, issue certificates, supply a content-management system, process email, or distribute open-source software. Each layer has different knowledge, control and legal obligations.

That distinction is already part of the debate. Superpower Daily reported that Google said it needs specific domains to investigate and that its policies prohibit non-consensual explicit imagery, including AI-generated images, while WordPress disputed the framing that software distribution is equivalent to hosting or control over independently operated sites . Hany Farid countered that some WordPress-linked services can host sites or deliver images even when the core website is hosted elsewhere .

These details matter because overbroad infrastructure enforcement can create due-process risks, while under-enforcement lets abuse sites hide behind technical complexity. A workable system would need verified reporting, clear definitions of AI-generated non-consensual intimate imagery, appeal mechanisms for mistaken identification, and special urgency for sites built around abuse. The study’s most practical suggestion is not that providers blindly block whatever is accused. It is that they investigate confirmed reports and stop supplying essential services to sites whose business model is sexual abuse.

Victim support must be built in, not bolted on

The 8 million figure should not flatten the people behind it into a statistic. The study’s authors stress that the blame belongs to perpetrators and facilitators, not to targets whose photos were available online . That point is essential. Telling people, especially women and girls, to disappear from the internet is not a safety policy. It is a surrender.

A serious response would pair enforcement with support: fast takedown assistance, evidence-preservation tools, trauma-informed legal guidance, school and workplace protocols, and cross-platform reporting that does not require victims to restate the violation again and again. Platforms should also design creation-layer safeguards against generating sexualized images of real people without consent, particularly from a single uploaded photo.

The current state of the story is therefore larger than one shocking number. The jump from 500,000 to 8 million shows that deepfake pornography has moved from isolated misuse to an abuse supply chain . The new study identifies the ordinary internet services that make that chain scalable . The policy answer cannot be only watermarking, only criminal law, only takedowns, or only voluntary trust-and-safety pledges. It needs consent rules with teeth, infrastructure accountability, better detection, victim-centered support and prevention at the point of creation.

The internet built systems for copying faster than it built systems for consent. Deepfake porn reaching 8 million is what that imbalance looks like when generative AI is plugged into it.

Comments

Be the first to comment.

Sources from the last 72 hours

  1. [1]Call for technology providers to take action on AI non-consensual ‘deepfake pornography’Sep 30, 2026, 2:00 AM
  2. [2]Internet Infrastructure Services Empower Deepfake Abuse, New Study FindsSep 30, 2026, 2:00 AM
  3. [3]Study Finds 88 Deepfake Abuse Sites Rely on Major Internet ProvidersSep 30, 2026, 6:56 PM
  4. [4]AI Deepfake Porn Videos Grew From 500,000 To 8 Million In 2 Years, Study SaysSep 30, 2026, 8:27 PM

AI-generated article based on recent web research, then preserved as a dated editorial snapshot.