In Minnesota, xAI suffers an initial legal setback over “nudify” applications

Minnesota may proceed with the implementation of its law targeting so-called “nudify” applications, after a judge rejected xAI’s request to block its enforcement. The news, reported by TechCrunch in an article titled “Judge denies xAI’s request to block Minnesota ban on ‘nudify’ apps”, represents a significant procedural setback for the artificial intelligence company founded by Elon Musk.

The dispute concerns a very specific category of services: those that allow an ordinary photograph of a person, often clothed, to be used to produce a synthetic image showing them unclothed or in an intimate situation. These tools, commonly referred to as “nudify,” rely on image generation and editing techniques. They do not necessarily reproduce a real event, but can create a result credible enough to be mistaken for an authentic photograph, or used as such against the person depicted.

The central point of Minnesota’s law is therefore the absence of consent. It is not limited to the question of whether an image is made by AI: it targets services capable of generating non-consensual intimate depictions from ordinary photos. This distinction is fundamental in the current regulatory debate. Deepfakes, broadly speaking, can be used for satire, art, film, education, advertising or disinformation. Non-consensual sexual deepfakes, however, raise an issue immediately linked to violations of victims’ privacy, dignity, reputation and safety.

xAI had argued that the ban raised a freedom-of-expression issue. The company requested that the law be suspended before it took effect. The judge denied that request, meaning the law can take effect while the litigation proceeds. This decision does not necessarily settle all constitutional debates on the merits, but it deprives xAI of the immediate freeze it sought.

The case extends far beyond the local level. In the United States, federal and state lawmakers have been seeking for several years to respond to the proliferation of non-consensual intimate content, including when it is produced or altered by AI systems. The particular feature of Minnesota’s initiative lies in its approach: rather than focusing only on the distribution of an unlawful image once it exists, it targets services that make available the ability to produce this type of content.

It is precisely this logic that places the xAI case at the intersection of three major questions. The first is technical: at what point does a general-purpose image-generation model become a tool for creating fake sexual content? The second is economic: who should bear responsibility when generation features are integrated into products used by millions of people? The third is constitutional: how far can a state restrict a software tool without disproportionately infringing the freedom of expression invoked by its publisher or users?

For now, the decision reported by TechCrunch sends a clear signal. AI companies cannot assume that the protected-expression argument alone will be enough to obtain the suspension of a law when it specifically targets non-consensual intimate images. For victims, this approach opens the prospect of earlier intervention in the content-production chain. For platforms and model providers, it makes the issue of technical safeguards, usage policies and the regulatory geolocation of their services more urgent.

A law designed to address production, not just the circulation of images

Public policies against non-consensual intimate images have long focused on their publication or sharing. This approach addresses an old problem, often described as “revenge porn,” although that expression does not cover every situation: the perpetrator may be a former partner, but also a classmate, a harasser, an unknown person or an organized network. With generative AI, a decisive change has occurred: it is no longer necessary to have access to an authentic intimate photograph to harm someone.

An image posted on a social network, a profile photograph, a photo taken in a school or professional setting, or even an image extracted from a video, may be enough as source material. Generative AI can then produce a fictional sexualized depiction. The target is real, but the scene is not. Yet the social consequences can be very real: humiliation, harassment, extortion, threats, the breakdown of professional or personal relationships, and difficulty getting copies removed when they circulate across several services.

Minnesota’s law reflects this finding. As TechCrunch summarizes it, it targets services capable of generating non-consensual intimate images from ordinary photographs. The law thus seeks to regulate “nudify” applications upstream of publication. This shift is significant: rather than exclusively requiring a victim to report content after the fact, the legislature is examining the technological offering that makes its creation accessible.

This strategy nevertheless raises a definitional challenge. Image-generation technologies are not, by nature, reserved for producing sexual content. The same set of methods can be used to retouch a portrait, change clothing in a fashion image, create a fictional character, make a humorous montage or generate entirely imaginary scenes. A law targeting “nudify apps” must therefore be sufficiently precise to reach tools designed or offered to undress people without consent, without indiscriminately equating all AI-assisted visual creation with an unlawful risk.

This precision also matters for developers. Some companies provide foundation models, others operate consumer-facing interfaces, while still others offer APIs that third-party services can integrate into their own applications. Practical responsibility may differ depending on the level of control exercised over the user experience. An operator that explicitly promotes an undressing function is not in the same position as a general-purpose technology provider that imposes contractual restrictions but does not control all interfaces built by its customers. Regulators will have to establish this boundary in many cases.

xAI’s challenge illustrates this tension. A company developing AI products may argue that its tools have many lawful and expressive uses, and that an overly broad restriction risks targeting general capabilities rather than precisely identified harmful conduct. Conversely, supporters of the law may argue that the purpose of the legislation is not to prohibit generative AI as a whole, but to limit the provision of services tailored to generating non-consensual intimate images.

The refusal to suspend the law does not automatically decide every future case. It does mean, however, that at this stage of the proceedings, xAI’s challenge did not lead the court to prevent the law’s enforcement. This is an important consideration for companies following the case: legal uncertainty does not exempt them from anticipating local obligations, particularly when their products are aimed directly at the general public.

This issue of anticipation is all the more sensitive because “nudify” applications can be distributed quickly. They can take the form of websites, messaging bots, services accessible through social networks or mobile applications. They can also change their name, hosting provider or domain. A rule that addressed only the removal of content after distribution would run up against the speed of digital reproduction. Minnesota’s response seeks to reduce this gap by treating access to the tool as a regulatory issue in its own right.

For victims, this development has concrete significance. Removal procedures remain essential, but they often take place after the image has been seen, copied or saved. Regulating generation capability does not guarantee that the phenomenon will disappear, particularly because models can be distributed in a decentralized manner or operated from other jurisdictions. It can nevertheless increase the legal and operational cost for services that make the creation of fake nudes their commercial proposition.

Freedom of expression and harm: the heart of the American legal conflict

xAI’s freedom-of-expression argument places the case within a highly influential American legal tradition. In the United States, computer-created content, artistic works, software and certain forms of communication may fall under constitutional protections. But these protections do not make every restriction impossible. Courts examine, in particular, the wording of the law, the type of conduct targeted, the existence of an important public interest and the measure’s actual scope.

Non-consensual intimate images are a particularly difficult area because they combine several dimensions. They may be an image, and therefore a form of representation. But that representation can also be the instrument of a targeted violation against an identifiable person. When AI makes it possible to artificially create a sexual image attributed to someone who has never posed nude, the debate is not only about the truthfulness of the image. It concerns the fact that the person is placed, against their will, in a fabricated and potentially distributed sexual situation.

Opponents of broad bans fear that poorly drafted regulation will reduce the space for parody, creation or technological experimentation. Supporters of targeted laws respond that the existence of legitimate uses of AI should not serve as a shield for products whose purpose or marketing method is the non-consensual sexualization of real people. That is the full difficulty: identifying the tool, use or functionality that justifies intervention, without turning the law into a general prohibition on synthetic imagery.

Minnesota offers a concrete example of this confrontation. The law targets “nudify” services rather than deepfakes as a whole. This approach is politically and legally narrower than legislation targeting all visual manipulation. It also reflects a reality: the harm associated with fake intimate content is particularly well documented and can affect adults and minors alike, with serious effects on mental health, schooling, employment or personal safety.

The litigation initiated by xAI nevertheless serves as a reminder that legislative drafting will be decisive. Companies examine, in particular, the terms used to define an intimate image, how the law describes consent, the degree of knowledge required of the operator, possible exceptions, penalties and territorial scope. In a digital environment, territorial jurisdiction is itself complex: a company may be established in one state, host its services elsewhere and serve users across the country.

The denial of xAI’s request must also be placed in procedural context. A request for suspension seeks immediate protection before a final decision on the merits. When a judge rejects such a request, the law can apply, but the legal debate may continue. It would therefore be premature to present this stage as definitive and exhaustive validation of every aspect of the legislation. For industry players, however, the immediate effect is tangible: they cannot rely on a judicial suspension to postpone necessary adaptations.

The case comes in a changing federal context. In the United States, the TAKE IT DOWN Act, enacted in 2025, targets the non-consensual publication of intimate images, including when they are created by AI, and provides removal obligations for certain covered platforms following notification. This federal framework primarily addresses the posting and circulation of content. Minnesota’s approach differs in that it examines the availability of generation technologies themselves.

The two approaches are not mutually exclusive. The first seeks to reduce the persistence and visibility of content after its distribution; the second seeks to limit access to certain means of production. But their coexistence shows that the American legal response is becoming more fragmented. A company may have to account for a federal removal rule, state rules on intimate images, separate rules on fraud, identity theft or the protection of minors, as well as requirements from its app stores and payment partners.

For major AI companies, this fragmentation increases pressure to adopt reusable compliance mechanisms. These may include explicit usage rules, limitations built into interfaces, reporting mechanisms, rapid-response procedures or controls concerning prompts and results. None of these measures is an absolute guarantee, especially against open models or services operated beyond the immediate reach of authorities. They nevertheless are becoming an increasingly central element of the responsibility expected from publishers.

From the generative model to the platform: responsibility moving up the technical chain

The rise of image generators has transformed the issue of sexual deepfakes. A few years ago, creating realistic manipulations often required editing skills, time, reference images and specialized software. Advances in diffusion models and conversational interfaces have lowered these barriers. A user can now expect a service to interpret a natural-language prompt, transform an uploaded image or make a modification based on a small number of instructions.

This reduction in friction is a central factor in the attention paid to “nudify” applications. The risk lies not only in an algorithm’s theoretical ability to produce an image. It depends on the product’s accessibility, the simplicity of the user journey, the ability to process photos of real people, and the absence or ineffectiveness of safeguards. A service may be technically sophisticated while remaining difficult to use; conversely, a very simple interface can industrialize malicious use.

Minnesota’s decision thus raises a question of technological governance: at what level should action be taken? Operators of applications directly intended for “nudify” are the most obvious targets. But upstream models and infrastructure may also be questioned, particularly if their tools are deployed in interfaces controlled by the company. App stores, hosting providers, social networks, payment services and advertising providers can also become control points, depending on the applicable legal frameworks and their own policies.

It is nevertheless necessary to avoid confusing responsibility with omnipotence. Model providers do not always control the subsequent uses of their technologies, particularly when a model is downloaded, modified or run locally. Automated filters can make mistakes. Detection systems can be bypassed. A manipulated photograph can be re-encoded, cropped or slightly altered to make its identification more difficult. Regulation therefore does not eliminate the need for prevention, education, victim support and cooperation between services.

In this context, product policies take on a legal dimension. A company that explicitly prohibits the creation of non-consensual sexual content in its terms of use does not automatically solve the problem. It must still be determined how it enforces that rule, what features are available, how users can report abuse and how it handles repeat offenses. Authorities and courts may be led to examine not only stated principles, but also the operational choices that make conduct more or less easy.

The confrontation between xAI and Minnesota also comes as companies in the sector seek to assert that their tools are versatile. This versatility is real: generative models can be used for graphic creation, prototyping, entertainment or professional uses. But the more widely a product is distributed to the public, the more companies must answer a simple question: what capabilities have been put in place to prevent a visual tool from being used to create a targeted intimate violation?

The answer cannot rest exclusively on ex post moderation. In the case of a “nudify” application, the harm can be produced at the very moment of generation, before any public publication. The image may be sent directly to the victim, used to pressure them or shared in a closed group. Removal rules are then essential, but they intervene after the file exists. This explains lawmakers’ interest in prevention mechanisms integrated into access to the service.

For the market, this development may accentuate the divide between two models. On one side are general-purpose services, whose publishers invest in safety policies and seek to demonstrate prevention efforts. On the other are services that explicitly present themselves as undressing tools and whose commercial value is tied to removing these barriers. Minnesota’s law directly targets the latter case, but the litigation surrounding xAI shows that the dividing line will have to be tested in practice and, probably, in other jurisdictions.

What this American precedent means for France and Europe

Minnesota’s decision does not apply in France or in the European Union. It is nevertheless being closely watched, because it illustrates an approach found on both sides of the Atlantic: synthetic content is no longer treated solely as an abstract issue of disinformation, but as a concrete risk for people whose image or voice is used without consent.

In Europe, the Artificial Intelligence Act, the AI Act, contains transparency requirements for certain AI-generated or manipulated content, including deepfakes. These transparency obligations are to apply from August 2026. They follow a different logic from Minnesota’s: they aim, in particular, to make it possible to indicate that content has been artificially generated or manipulated. Such an indication can improve public information, but it does not by itself address the problem of a sexual image created without authorization. Content may be clearly labeled as synthetic while still being seriously harmful to the person targeted.

European data protection law, rules relating to platforms and national criminal legislation may also be applied depending on the circumstances. In France, the distribution of intimate images without the consent of the person concerned is already punishable. The law aimed at securing and regulating the digital space, enacted in 2024, also created an offense related to the distribution of images or sounds generated by an algorithm without the consent of the person depicted or heard, when they are presented without mention of their artificial nature and are likely to cause that person harm.

The French framework therefore already partly addresses the issue of harmful artificial content. But comparison with Minnesota highlights a difference in method. A large part of the existing rules concerns distribution, misleading presentation or the harm caused by content. The U.S. law discussed in the xAI case is more directly concerned with making available certain applications capable of producing non-consensual intimate images.

For companies operating in France and Europe, the lesson is not that an American model would automatically be transferable. Legal traditions, authorities’ powers and applicable texts differ. Products, however, circulate globally. An application accessible online can be downloaded in several countries, receive payments through international services and host its data outside the European Union. Actors designing visual-generation tools must therefore anticipate heterogeneous requirements, rather than merely checking legality in their country of origin.

The Minnesota case could also inform European thinking on prevention. Deepfake transparency is useful in electoral, media or advertising contexts. For fake nudes, the issue is more immediate: preventing abusive generation, enabling rapid reporting, preserving evidence, removing copies and supporting victims. Lawmakers will have to decide whether general rules on unlawful content and personal data are sufficient, or whether more specific obligations for tool providers are necessary.

In the long term, the litigation between xAI and Minnesota could serve as a reference point in defining a clearer regulatory boundary. If U.S. courts sustainably accept that targeted restrictions on “nudify” services can coexist with freedom-of-expression protections, other states could adopt comparable legislation. Companies would then be encouraged to design global safeguards rather than multiply local adaptations.

This prospect does not mean the debate is closed. Tensions between innovation, expression and the protection of individuals will intensify as generative tools become more capable, faster and more integrated into consumer services. But the refusal to suspend Minnesota’s law already shows that the technological argument can no longer be separated from its social uses. In the field of sexual deepfakes, the question facing platforms is no longer only what their models can produce: it is what capabilities they choose to make available, to whom, and under what responsibilities.

Back to all news

Comments· 1 comment

  1. Hannah Miller· 2 août 2026

    I’m really glad to see this issue being taken seriously. Protecting people from non-consensual sexual deepfakes feels like an essential step forward.

Leave a comment