Study Finds Major Tech Companies Enable Non-Consensual AI Deepfake Sites
Tech

Study Finds Major Tech Companies Enable Non-Consensual AI Deepfake Sites

TechNews Editorial
TechNews EditorialSep 30, 2026 · 3 min read
Share

Why it matters

This study matters because it shifts accountability to the major tech infrastructure providers that enable the distribution and operation of non-consensual deepfake abuse sites.

The facts

  • A new study reveals major infrastructure providers support prominent websites hosting non-consensual, AI-generated intimate imagery.
  • Researchers identified Cloudflare, Google, Namecheap, WordPress, and Proton as the dominant infrastructure providers for these abuse sites.
  • The study authors recommend that tech providers stop supplying services to sites hosting non-consensual intimate imagery.

Sexually explicit deepfakes have become easier to create and more widespread over the last nine years. Since they first appeared in 2017, these images have lived on social media networks, easily downloadable apps, and accessible forums rather than dark web sites. Prominent hosts of non-consensual, AI-generated imagery rely on major global web infrastructure providers for hosting, email, advertising, and content management systems. A new study examines how companies like Cloudflare, Google, Proton, Namecheap, and WordPress help these sites thrive. Major tech companies continue providing infrastructure that supports abuse imagery despite terms of service prohibiting illegal and harmful content.

Hany Farid, Sophie Nightingale, and Sarah Morgan published their paper titled The Backbone of Abuse: How Infrastructure Providers Enable the Proliferation of AI-Generated Non-Consensual Intimate Imagery in Stanford’s peer-reviewed Journal of Online Trust and Safety. Farid is a computer science professor at Dartmouth College, Nightingale is a senior lecturer in psychology at Lancaster University, and Morgan acts as project coordinator on Nightingale's fellowship. Over a six-week period between February and March, the researchers identified 400 URLs using keyword searches and Google Alerts, eventually narrowing the list to 88 sites actively hosting non-consensual intimate imagery. Most of this content targeted female celebrities, actresses, pop singers, K-pop idols, and women working in politics or activism. The researchers used open-source web analysis tools like WHOIS to determine which infrastructure providers supported the sites.

Dominant providers supply the backbone for abuse

The researchers identified five dominant infrastructure providers supporting these websites. Cloudflare provided the largest share of services by handling website hosting, content delivery network, domain-name server services, and analytic tools. Google supplied SSL certificates and advertising space for the majority of the studied sites. Namecheap acted as the dominant provider of domain registrar services, WordPress supplied content management systems, and Proton provided mail servers. Each of these companies explicitly forbids customers from using their services for illegal activities. Publishing or threatening to publish AI-generated non-consensual sexual imagery is a federal crime in the United States and other regions, while sexual abuse imagery is illegal in many countries.

Cloudflare, Proton, and Namecheap did not respond to requests for comment regarding the study findings. A Google spokesperson stated that the company cannot investigate claims without specific domains from the report. Google maintains strict policies against non-consensual explicit content across all products, provides easy removal tools, and prohibits monetizing or promoting such material. A WordPress spokesperson stated that the platform is open-source software rather than a hosting provider and lacks access to or control over content on independently hosted sites.

Farid disputed the WordPress defense by noting that Automattic operates WordPress.com and hosts millions of sites. Automattic also provides services to self-hosted sites through tools like Jetpack and content delivery networks that serve images directly from their infrastructure. Farid also pointed out that WordPress.org maintains ongoing service relationships with self-hosted sites via core updates, plugin distribution, and security patches. Cloudflare has previously dropped controversial sites like Kiwifarms, 8chan, and The Daily Stormer, while maintaining that it lacks content control over websites using its services. Proton has previously provided user payment data and information to law enforcement authorities in international cases.

A search result opens a cooking spam page, while an enlarged second result reveals a gambling site.
Illustration: AI & Tech News

Search manipulation reveals massive consumer demand

Beyond deepfake hosting, the researchers discovered that 312 of the initial 400 identified URLs were unrelated to deepfakes and instead consisted of gambling or cooking search engine optimization spam. These sites exploited non-consensual imagery keywords to manipulate Google search rankings. Morgan noted that while journalists can expose site administrators and legislation can act as a deterrent, the research group focused on infrastructure providers as the distribution supply for these platforms. Creators and consumer demand will persist, but providers can cut the distribution supply and stop enabling these websites.

The researchers recommend that infrastructure providers cease supplying services to sites hosting non-consensual imagery. Morgan stated that providers can vastly improve moderation and cut services as soon as sites are identified as hosting abusive content. The gold standard response involves a commitment from infrastructure providers to work with global nongovernmental organizations and governments to verify URLs and share them with participating platforms for blocking.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading