Skip to news

New York’s Deepfake Takedown Tests AI Abuse Enforcement

The seizure of 12 sites targeting 1,200 people shows authorities can disrupt AI abuse—but not yet erase the market or repair victims’ harm.

By THE COLDAI TIMES deskPublished 5 min read1,006 words

The takedown

The Manhattan District Attorney’s Office has seized 12 domain names used to distribute and sell non-consensual AI-generated sexual imagery, in what prosecutors describe as the largest known seizure of websites dedicated to this form of abuse. The sites allegedly used photographs and videos of roughly 1,200 real people—primarily women, including actors, politicians, athletes, musicians, advocates, and social-media personalities—to create fabricated depictions of sexual conduct.

The operation, announced September 14, is consequential less because it removed a particular group of websites than because it demonstrates a change in enforcement posture. Authorities are no longer treating synthetic sexual imagery only as a platform-moderation problem or a civil dispute over reputation. They are pursuing the infrastructure that hosts, monetizes, and distributes it.

The Manhattan DA said the domains were seized pursuant to court orders and that the investigation remains active. The office is also asking victims to come forward, suggesting that prosecutors are still mapping the people and businesses behind the sites rather than treating the seizure as a completed case.

Independent reporting by WIRED adds an important operational detail: several domains had already been replaced with seizure notices before the public announcement, after the publication had independently observed the sites. That makes the action look like a coordinated infrastructure intervention rather than a symbolic warning. The websites were not merely removed from a search index; their domains were taken under legal control.

Why it matters

The central shift is from deleting individual images to disrupting the business model around them. Deepfake pornography is often described as frictionless because image-generation tools are cheap, widely available, and capable of producing convincing results from ordinary photographs. But the distribution layer still needs domains, payment mechanisms, search visibility, hosting, and audiences. Removing those components raises the cost of operating at scale.

That distinction matters because the alleged network was not an isolated prank involving one person and one victim. The Manhattan DA says the 12 sites were operated by five online vendors and marketed explicit synthetic content as a commercial product. In other words, the case presents AI abuse as an organized digital industry, with suppliers and customers, rather than simply a new form of interpersonal harassment.

The action also tests whether existing criminal law can be adapted quickly enough to a technology that changes faster than statutes. New York prosecutors framed the conduct as unlawful dissemination and sale of non-consensual intimate imagery, including content created or altered with AI. That approach avoids waiting for a perfect “deepfake” statute. It treats consent and exploitation as the legal core, with artificial intelligence as the method.

This is strategically important. A narrow legal framework focused only on whether an image is technically authentic would leave a large loophole: perpetrators could argue that a victim was not actually photographed in a sexual act. A consent-centered framework reaches the harm more directly. The injury is not limited to factual deception. It includes the theft of a person’s likeness, the public sexualization of that likeness, and the loss of control over how it is circulated.

The case also shows why enforcement against websites may become a more practical near-term tool than trying to regulate every image-generation model. Model providers can impose safeguards, but open-source systems, overseas services, and locally run tools complicate prevention. Prosecutors cannot easily eliminate the capacity to create manipulated images. They can, however, target identifiable businesses that profit from publishing and selling them.

That does not make the problem easy. Domain seizures are disruptive, but they are not the same as removal from the internet. Operators can register replacement domains, move servers, rebrand, or distribute content through encrypted channels and user-to-user networks. Search engines and social platforms may also continue to encounter copies after the original sites disappear. Enforcement therefore becomes a repeated contest of adaptation rather than a single decisive takedown.

The limits of infrastructure enforcement

The most important uncertainty is what happens beyond the seized domains. The DA’s announcement identifies approximately 1,200 victims, but that number may change as investigators examine archives, customer records, payment trails, and mirrored content. It also does not tell us how many images were produced, how long the sites operated, or how much revenue they generated.

Nor does a seizure automatically provide restitution. Victims may face years of reputational damage, workplace consequences, family distress, impersonation, and repeated reuploads. Even if every domain disappears, copies may remain in private collections or on foreign platforms beyond the immediate reach of New York authorities. The legal action can interrupt distribution while leaving the underlying harm durable.

There is also a question of selectivity. The victims identified in this case are mostly public-facing women, which may have made the sites easier to discover and the prosecution easier to explain publicly. But the same tools are used against private individuals, students, former partners, and people without the resources to hire lawyers or attract media attention. A successful high-profile prosecution should not become the model’s entire definition of the problem.

The next test will be whether authorities can identify and charge the operators, payment intermediaries, advertisers, and repeat distributors connected to the seized domains. If the case ends with domain forfeitures but no broader accountability, the operation may deter some businesses while leaving the ecosystem intact. If it produces prosecutions and reusable investigative methods, it could establish a template for other jurisdictions.

A new enforcement baseline

New York’s action signals that the policy debate over generative AI is moving toward a more concrete question: who is responsible when synthetic content becomes a commercial abuse pipeline? The answer is unlikely to rest with model companies alone. Platforms, domain registrars, payment processors, hosting firms, advertisers, and users all occupy different points in the chain.

The seizure does not prove that authorities can control AI-generated abuse. It proves something narrower and more useful: even when creation is cheap, organized distribution leaves infrastructure that can be investigated and attacked. That may become the first durable enforcement baseline for a category of harm that technology has made scalable, but not entirely invisible.

Related stories