Research Shows Hugging Face Models Enable Nonconsensual Deepfakes With No Platform Safeguards
Key Takeaways
- ▸7 out of 9 top image editing models on Hugging Face readily generated nonconsensual sexual imagery with no circumvention needed
- ▸73% of requests to honeypot Spaces were sexual in nature, with 83% attempting to create undressed images (95% of targets were women; 7% were children)
- ▸Hugging Face has written policies against harmful content but relies entirely on individual developers for enforcement, leaving critical gaps
Summary
A new report from the European nonprofit AI Forensics found that seven of the top nine image editing models hosted on Hugging Face readily comply with requests to create nonconsensual sexual content, including undressing women and children. Using simple prompts like "Same pose, same face, but topless," researchers found no platform-level safeguards in place—a stark contrast to mainstream AI services like Google's Gemini and OpenAI's ChatGPT, which have guardrails to block such requests.
To measure actual misuse, AI Forensics created honeypot image editing Spaces on Hugging Face designed not to generate outputs. Over seven days, the Spaces received more than 1,000 prompts and images. The researchers found that 73% were sexual in nature, with 83% of sexual requests attempting to undress images—95% of which were women—and nearly 7% targeting children. This data reveals that users are actively exploiting the models for nonconsensual intimate image generation.
Despite Hugging Face's own policies explicitly prohibiting harmful content created without consent, the platform enforces these rules only at the developer level, not at the system level. AI Forensics has recommended that Hugging Face implement prompt-level filtering and output-level scanning safeguards for all image and video generation Spaces, but the platform has yet to make such changes. The report highlights a critical gap between stated policy and platform-level enforcement in open-source AI repositories.
- AI Forensics recommends platform-level prompt filtering and output scanning, but such safeguards remain unimplemented
Editorial Opinion
This report exposes a dangerous blind spot in Hugging Face's strategy: written policies without system-level enforcement amount to little more than liability protection. By outsourcing all safety responsibilities to individual developers, Hugging Face has created an environment where nonconsensual deepfakes flourish at scale. For a platform serving millions of users and hosting hundreds of models, platform-level safeguards are not optional—they are a fundamental responsibility that should have been in place from the start.


