Expert IP, Digital Media & Commercial Contracts Solicitor
Authorised international solicitors in IP, media & commerce. Experts in contracts, licensing, reputation & disputes.
PAIL-Solicitors-Digital-Media-Solicitors-Blog.png

Digital Media, IP & Technology Law Insights

Legal analysis for founders, creators, technology businesses and brands across intellectual property, digital media, AI, platforms and commercial law.

PAIL Solicitors digital media, intellectual property and technology law insights
PAIL® INSIGHTS Ideas · Rights · Technology · Commercial Strategy
The Idea Behind PAIL® Insights

Why “My Way”?

Frank Sinatra’s My Way captures something fundamental about intellectual property: the distinction between an idea and the individual expression of it.

Copyright does not give someone ownership of an idea itself, but it can protect the particular way that idea is expressed through music, literature, art and other creative works.

That principle of creating, building and expressing something your way sits at the heart of this blog. PAIL® Insights explores the legal issues that arise when creativity, technology and commerce meet — and the rights, relationships and decisions that determine who can control and benefit from what has been created.

About the Blog

Practical Legal Insight for a Digital World

PAIL® Insights brings together legal analysis, practical guidance and commentary across intellectual property, digital media, AI and technology, creators and talent, reputation, platforms and commercial law.

The articles are written for founders, businesses, creators and professionals who need to understand not only what the law says, but how legal developments affect ownership, commercialisation, contracts, risk and growth.

Every article is written, reviewed or edited by Peter Adediran, Founder Solicitor at PAIL® Solicitors.

Written & Reviewed By Peter Adediran Founder Solicitor · Intellectual Property · Digital Media · Technology · Commercial Law
About Peter →

Discover Insights:

AI Deepfake & Intimate Image Removal: A UK Solicitor's 48-Hour Action Plan

UK solicitor advising a victim, creator or brand on removing an AI deepfake or non-consensual intimate image

What Every Victim, Creator and Brand Needs to Know Right Now

What victims, creators, agencies and brands can do immediately — and how UK law, platform reporting and cross-border routes may apply.

An AI-generated sexual deepfake, or a genuine intimate image shared without consent, can reach dozens of platforms, search results and messaging services before most victims have worked out where to report it. Reposting accounts, mirror sites and search-engine indexing routinely outpace any single takedown request. Until recently, UK law addressed the sharing of such images but largely left their creation untouched — a gap that closed only in February 2026, after years of law reform work that most people affected by this have never heard of.

If this has happened to you or someone you represent, do not begin by arguing publicly with the uploader. It rarely helps, and it can make the legal and practical position worse.

This article is general information, not legal advice on your specific facts, and several of the laws described below are less than a year old.

"Act now" emergency panel

Content is live right now?

Preserve the URL and take screenshots first. Do not forward, download or publicly confront the uploader. Report the content through the platform's own non-consensual intimate image (NCII) reporting route, and seek urgent advice if there are threats, reposts, or commercial consequences.

For immediate free support: Revenge Porn Helpline 0345 6000 459 (UK, adults 18+). See the full checklist below for what to do next.

"If a child is depicted" safety panel

If a child is depicted

If the material may depict a child, do not save, share or investigate it further. Report it immediately to the police or the Internet Watch Foundation (iwf.org.uk). This article concerns adults only and is not a guide to handling suspected child sexual abuse material (CSAM) — that is a safeguarding and criminal-reporting matter, not a content-removal or reputation matter.

If the Content Is Online Now: The First 48 Hours

What happens in the first day or two after discovering a non-consensual intimate image or deepfake often shapes how quickly it can be contained.

- Preserve evidence before reporting or blocking.** Save URLs, usernames, timestamps, screenshots, screen recordings, post IDs and search-result pages, and keep copies of related messages.

- Record where the content appears, including reposts, private groups or channels, and whether it is appearing in search-engine results.

- Avoid engaging directly with the uploader unless advised to. Engagement can increase visibility, complicate evidence, and in some cases escalate harassment.

- Use the platform's official reporting route and keep a record of when you reported and what response you received. (PAIL's own step-by-step guides cover the reporting process for Instagram, Facebook, X and Reddit.

- Consider StopNCII.org, a free hash-matching tool that lets a person generate a digital fingerprint of an intimate image of themselves — without uploading the image itself — so participating platforms can detect and block matching content.

- Treat threats, extortion, stalking or identity misuse as urgent, and involve the police as well as taking the steps above.

- Get legal advice early if: content is being reposted faster than it can be reported, a platform rejects or ignores your report, the person responsible is identifiable, a brand or employment relationship is at risk, or content is spreading across multiple platforms or jurisdictions. PAIL's Global Online Content Removal service handles exactly this kind of escalation. Need a solicitor-led response plan?PAIL® Solicitors' fixed-fee Initial Legal Takedown Assessment reviews the evidence, identifies the strongest reporting and legal routes, and sets out the immediate steps for the next 48 hours. Get in touch.

Which route fits your situation
Situation Immediate route Why timing matters
Content has been posted Preserve evidence, report to platform, consider police/civil action Copies and search indexing can multiply quickly
Content is threatened but not posted Preserve messages, assess police/platform intervention The threat itself may already be a criminal offence
A sexual deepfake has been created Preserve proof of creation/request, assess the criminal route Creation and sharing are legally distinct issues
The uploader is anonymous Preserve identifiers, consider a disclosure strategy Identification may be necessary for a viable civil claim
A brand/agency relationship is affected Review contractual notification and communications duties A rushed public statement can create fresh legal or commercial risk

Who This Article Is For

This article is for you if:

- you or someone you represent has discovered a non-consensual intimate image or AI-generated deepfake of themselves online;

- you are a creator, influencer or public-facing professional and want to understand your options before an incident happens, not during one;

- you manage talent, an agency, or a brand and need a workable escalation plan if a creator or employee is targeted;

- a platform has ignored, rejected or slow-walked a report you have already made; or

- you need specialist advice on the interaction between intimate-image offences, harassment, data protection, defamation and platform obligations across the UK, US and EU.

The Law Is Changing Fast — Here Is Where It Stands

In England and Wales, creating or requesting the creation of a purported intimate image of an identifiable adult without consent can be a criminal offence. Sharing, or threatening to share, an intimate image without consent is separately criminalised. Different provisions carry different commencement dates and different tests, so advice should always be based on the specific facts and timing of an incident, not a general summary.

The rest of this section explains how that position was reached, because the sequence matters for anyone assessing older conduct as well as new.

The original UK offence — disclosing a private sexual photograph or film without consent — dates to section 33 of the Criminal Justice and Courts Act 2015. It was widely criticised almost from the outset: it required proof of intent to cause distress, did not cover images that had been digitally altered or fabricated, and left the creation of an intimate image entirely outside its scope. The Law Commission was asked to review the area in 2019, following an earlier 2018 scoping report, published a consultation paper in February 2021, and delivered its final report — Intimate Image Abuse, Law Com No 407 — on 7 July 2022, recommending a comprehensive new framework of offences. The government accepted those recommendations that November.

The Online Safety Act 2023 implemented the bulk of that reform, replacing and expanding the 2015 offence for conduct from 31 January 2024, and extending it to cover deepfakes that appear to depict a real, identifiable person for the first time. Until 6 February 2026, however, the reformed law still targeted sharing such images, not creating them — a gap the Law Commission itself had flagged as a significant inconsistency, particularly for deepfake content created but never distributed. Section 138 of the Data (Use and Access) Act 2025 closed that gap. The Crime and Policing Act 2026 extends the framework again, adding further offences around taking or recording intimate images without consent and the supply of tools built specifically to create sexualised fakes, together with a new statutory takedown duty for platforms described below. Ofcom's own work on illegal intimate-image harms has continued to develop alongside these changes; the exact services in scope and current technical expectations should always be checked against Ofcom's latest published guidance rather than relied on from any single article, including this one.

None of this gives a completely settled picture. It confirms that platform obligations, criminal exposure, and removal timelines in this area are being actively rewritten; that the reforms are the product of considered, multi-year policy work rather than a rushed reaction to AI specifically; and that the position taken even a year ago is likely out of date.

UK Law: Statutes and Enforcement

The UK's framework for intimate-image abuse (sometimes still searched for by the older term "revenge porn" — see the FAQ below for why this article avoids that phrase) has been built up in stages since 2015, with the most significant recent additions targeting AI-generated content specifically.

Sharing intimate images without consent

The Online Safety Act 2023 (OSA) inserted new sections into the Sexual Offences Act 2003, in force from 31 January 2024:

- Section 66A — cyberflashing (sending photographs or films of genitals without consent), inserted by s.187 OSA 2023

- Section 66B — sharing, or threatening to share, an intimate photograph or film without consent (including deepfakes that appear to depict a real, identifiable person), inserted by s.188 OSA 2023

- Sections 66C and 66D — related sharing offences, including where the image is shared with a wider intention to cause alarm, distress or humiliation, or for sexual gratification

The base offence under s.66B(1) is summary-only, requiring only that the sharing was intentional, without consent, and without a reasonable belief in consent — no proof of motive is needed. The more serious variants under s.66B(2) and (3) — sharing with intent to cause alarm, distress or humiliation, or for sexual gratification — are either-way offences carrying up to 2 years' imprisonment and/or an unlimited fine. Section 66B(4) makes threatening to share such an image its own offence, and the prosecution does not need to prove the image actually exists. Consent is a valid defence throughout, and the prosecution must be able to disprove any genuine belief in consent the defendant raises.

Complainants in a number of these offences — confirmed for cyberflashing and the aggravated sharing offences under s.66B(2)–(4) — are entitled to lifetime anonymity in reporting under the Sexual Offences (Amendment) Act 1992 as extended by the Online Safety Act 2023, in the same way as complainants in other sexual offences. Whether anonymity extends identically to the base s.66B(1) offence in every circumstance is a point worth confirming against the current statutory text for the specific facts of a case, rather than assumed automatically.

Creating, or requesting the creation of, a deepfake intimate image

Until early 2026, UK law targeted sharing non-consensual intimate images but not, in most circumstances, creating them. Section 138 of the Data (Use and Access) Act 2025 closed that gap, in force from 6 February 2026, by inserting four new sections into the Sexual Offences Act 2003:

- Section 66E — intentionally creating a purported sexual image of an identifiable adult, without their consent and without a reasonable belief in consent

- Section 66F — intentionally requesting that someone else create such an image, again without consent or a reasonable belief in consent

- Section 66G — definitions applying to both offences

- Section 66H — an extended time limit for prosecution: proceedings may be brought within six months of sufficient evidence coming to a prosecutor's knowledge, and in any event within three years of the offence itself

These are two separate offences, not one. The section 66E offence can be committed even if the resulting image is never shared. The section 66F offence—requesting the creation of an image—can be committed even if no image is ever produced; submitting a photograph to a third-party "nudification" tool or service can amount to the offence in its own right. Both carry an unlimited fine on conviction. On conviction under section 66E, a court can also make a deprivation order over the image itself and anything containing it, such as a phone, laptop or hard drive — the same power applies in the Armed Forces service justice system for the equivalent service offence.

The Crime and Policing Act 2026: platform takedown duty and further offences

The Crime and Policing Act 2026 (CPA) received Royal Assent on 29 April 2026. Sections 100 and 101 insert a new statutory duty directly into the Online Safety Act 2023: a duty to operate a service using proportionate systems and processes designed to take down content subject to a valid intimate image content report, and any other content that is the same or substantially the same, as soon as reasonably practicable and no later than 48 hours after the report is received, subject to specified exceptions set out in the Act. An equivalent duty applies to regulated search services, requiring them to ensure such content can no longer be encountered through search results within the same timeframe. This applies to regulated user-to-user and regulated search services as defined by the Online Safety Act — not to every online service indiscriminately.

Non-compliance carries real teeth on two levels. At the corporate level, Ofcom's existing enforcement powers allow fines of up to 10% of global annual revenue, or in serious cases a service being blocked from the UK entirely. At the individual level, the Act introduces personal criminal liability: where Ofcom issues a confirmation decision requiring a specific person to ensure content is removed within 48 hours, that person commits a criminal offence if they fail to comply — the precise scope of who can be given such a decision and what defences are available is a detail worth checking against the operative text for any specific enforcement scenario.

The Act also: bans the creation, modification, distribution or supply of "nudification" tools designed to generate fake nude or sexualised images; creates new offences around taking or recording an intimate image without consent, addressing the separate harm of covert recording itself; and confers a duty on ministers to designate a registry — government material has pointed to the existing Revenge Porn Helpline as a likely candidate, though as of publication this remains a power to be exercised rather than a confirmed operative registry — through which internet services may in future be required to share image hashes to support detection across platforms.

Further reading on all of the above: see the Useful Links and Resources accordion at the end of this article for direct links to every statute, case and commencement instrument referenced here.

The Cases UK Practitioners Need to Know

Alongside the statutes above, a small number of civil authorities do much of the practical work for victims considering a claim, and the enforcement record shows the criminal offences are being used, not left dormant.

The leading authority is FGX v Gaunt [2023] EWHC 419 (KB). The claimant's former partner had covertly recorded intimate videos of her — including footage taken while she was naked and unaware she was being filmed — and later uploaded them, with identifying details, to a pornographic website. The High Court, in a judgment handed down by Mrs Justice Thornton on 27 February 2023, awarded total damages of approximately £97,041, made up of general damages for the misuse of private information and infringement of privacy, aggravated damages reflecting the deliberate and humiliating manner of the disclosure, and special damages for the chronic post-traumatic stress disorder and lasting personality change the claimant developed (the exact component breakdown of that total is worth checking directly against the judgment for anyone relying on it as a precedent figure). The judgment confirmed that repeated, continuing publication has a cumulative psychiatric effect that can properly increase an award, and that the absence of any single case directly on point did not prevent the court from applying general privacy-damages principles by analogy.

In reaching its figure, the court drew on earlier privacy authorities including Reid v Price [2020] EWHC 594 (QB) — a similar case involving the covert recording and disclosure of intimate images and video during a relationship — and ABC and WH v Willock [2015] EWHC 2687, which addressed the particular vulnerability of a young claimant pressured into producing and sending intimate images. Together, these cases confirm that UK courts had already been building a body of privacy-damages principles specific to intimate-image abuse well before the criminal law caught up.

Before the Online Safety Act 2023 came into force, the base criminal offence sat in section 33 of the Criminal Justice and Courts Act 2015. That offence still governs conduct that took place before 31 January 2024, and the underlying civil claim in misuse of private information (as in FGX v Gaunt) has always run alongside it, independent of whether a prosecution takes place.

On the criminal side, the UK secured its first conviction under the Online Safety Act's new communications offences on 19 March 2024 — a cyberflashing case resulting in a 66-week custodial sentence (worth re-confirming against current court records for anyone citing the specific sentence). Prosecutions under the newer sections 66E and 66F, in force only since February 2026, are just beginning to move through the courts, and reported outcomes are expected over 2027 as the first cases conclude.

UK, US and EU Rules: The Cross-Border Position

Most UK victims, creators and brands are not dealing with a UK-only problem — the platform, the host, or the audience is very often based elsewhere. The practical question is rarely just where the victim lives; it is which entity controls the content, and which legal notice or reporting channel that entity must act on. The three leading frameworks differ in what they require, how quickly, and who is entitled to enforce them.

The United States. Until 2025, the US relied entirely on a patchwork of state laws — at least 45 states now have some form of law addressing non-consensual sexual deepfakes, up from a much smaller number just two years ago, with California, Texas and Virginia among the earliest and most frequently used. The TAKE IT DOWN Act (S.146) changed the federal position on 19 May 2025. It criminalises knowingly publishing non-consensual intimate images, including AI-generated deepfakes, of both adults and minors — carrying up to 2 years' imprisonment for offences against adults and up to 3 years where a minor is depicted — and separately requires "covered platforms" to implement a notice-and-removal process and remove reported content within 48 hours of a valid, written notice. Platform compliance has been required since 19 May 2026, with enforcement falling to the Federal Trade Commission. The Act does not pre-empt state law: a UK claimant dealing with a US-hosted platform may in practice have both the federal 48-hour mechanism and a relevant state statute available at the same time. The first reported conviction under the Act came in April 2026. As with any recently enacted law, the exact scope and how the FTC applies it in practice should be checked against current guidance before it is relied on for a specific case.

The European Union. The EU addresses the same harm through three overlapping instruments rather than one consolidated law. The AI Act (Regulation (EU) 2024/1689), Article 50 requires from 2 August 2026 that providers of AI systems generating deepfakes ensure the output is technically marked as artificially generated, and that anyone publishing a deepfake discloses that it has been artificially generated or manipulated — a transparency duty, not a prohibition or a removal mechanism, so labelling a non-consensual sexual deepfake does not make it lawful and does not reduce the harm to the person depicted. The Digital Services Act (Regulation (EU) 2022/2065, Articles 16–17 is the more directly useful mechanism for removal: it requires online platforms to operate accessible, easy-to-use mechanisms allowing any individual to notify illegal content, and to act on well-founded notices "in a timely, diligent, non-arbitrary and objective manner". Directive (EU) 2024/1385 on combating violence against women adds a harmonisation layer, requiring every Member State to criminalise the non-consensual creation, manipulation and sharing of intimate images, including AI-generated ones. Enforcement is not merely theoretical: the European Commission opened investigations into X under both the DSA and GDPR within days of the widely reported "Grok" deepfake incident reported in December 2025 (the exact investigation dates are worth confirming against the Commission's own case register before being cited as settled fact).

PAIL® Solicitors can advise on a cross-border escalation strategy, including which UK, US, or EU mechanism is likely most effective for a specific platform, host, or audience, and can prepare correspondence in the form each regime expects.

For Brands, Agencies and Employers

A deepfake or intimate-image incident involving a creator, employee or brand ambassador is rarely only a personal matter — it typically raises commercial and contractual questions at the same time, and is a natural fit for PAIL's Platform Enforcement & Reputation Protection and [Influencer & Creator Legal Services:

- Who needs to be informed internally, and on what timeline, once an incident is identified

- What can be said publicly without amplifying the content or creating avoidable legal risk

- Whether talent, endorsement, production or employment contracts allocate responsibility and cooperation obligations clearly

- Whether there is a workable escalation route if a platform's initial response is slow or inadequate

- Whether existing crisis-communications policies actually cover AI impersonation and coordinated harassment, or only more conventional reputational risks

- Whether brand partners hold approval, suspension or termination rights that need to be understood before a rushed public response

These questions are usually easier to answer in advance than in the middle of an active incident. Agencies and brands can commission a review of existing talent and crisis-response agreements before a problem arises, rather than after, and the review is typically far less costly, and far calmer, done outside a live incident.

A related but distinct scenario is worth planning for separately: an employee or contractor is the person responsible for creating or sharing content about someone else, rather than the person affected by it. Employers in that position face their own exposure — including potential vicarious liability questions where company systems, accounts or working time were involved — and need a considered internal process rather than an improvised one.

What We Are Seeing in Practice

Four patterns come up repeatedly in the platform-enforcement and reputation matters PAIL® Solicitors advises on, and each illustrates why this rarely stays a single, tidy legal question.

The first is the single-platform escalation that stalls. An individual reports a non-consensual image through a platform's standard in-app process, receives no meaningful response within days, and the content is reposted faster than each new copy can be reported individually. In one recent multi-platform matter, the immediate priority was not a damages claim; it was preserving evidence before copies disappeared, then coordinating removal requests across the original platform, repost accounts and search results.

The second is the multi-platform spread. Content originally posted on one platform is mirrored, screenshotted and reposted across several others, sometimes in different jurisdictions, before the original report has even been actioned. This is where evidence discipline from day one — a single, dated record of every URL and platform involved — determines whether a coordinated response is realistically possible later.

The third involves a commercial relationship rather than a stranger. A creator, employee or contractor becomes aware that a former partner, colleague or client has created or threatened to share intimate content, and the immediate legal question becomes entangled with a live agency, employment or brand relationship that also needs managing. In a brand-facing version of this scenario, the core legal work often includes not only platform escalation but reviewing whether an endorsement agreement requires notification, whether public comment is needed, and who controls communications.

The fourth is the threat that never materialises into an actual post. Someone receives a message threatening to create or share a deepfake or intimate image unless a demand is met — frequently a form of sextortion. Because the threat to share is itself an offence under section 66B, and because the section 66F offence can be engaged even before any image exists, more can often be done at this stage than clients expect.

Key Points

- Creating, or requesting the creation of, a non-consensual sexual deepfake of an adult has been criminalised as two separate offences (sections 66E and 66F of the Sexual Offences Act 2003) since 6 February 2026, distinct from the pre-existing offence of sharing one

- FGX v Gaunt [2023] EWHC 419 (KB) remains the leading UK civil authority on damages for image-based abuse, awarding approximately £97,041

- The Crime and Policing Act 2026 places regulated platforms under a duty to take down reported intimate image content as soon as reasonably practicable and no later than 48 hours, subject to statutory exceptions, backed by corporate fines and personal criminal liability for non-compliance

- The US TAKE IT DOWN Act gives a federal 48-hour notice-and-removal route, enforceable since May 2026, independent of any UK criminal process

- EU law addresses the same harm through three separate mechanisms — the AI Act, the DSA and a dedicated violence-against-women directive — which apply together

- Content depicting a child is CSAM (child sexual abuse material), not NCII, and must be reported to the police or the Internet Watch Foundation as an urgent safeguarding matter, not handled as a takedown or reputation matter

Why Choose PAIL® Solicitors for Deepfake and Intimate Image Advice

Peter Adediran founded PAIL® Solicitors because internet, technology, and reputation law needed specialist practitioners, not generalists treating each platform incident as a one-off. He was among the first UK solicitors to concentrate specifically on internet law, and has advised on online defamation and reputation management matters — domestic and international — for over a decade.

We combine legal analysis with practical knowledge of the reporting, evidence and escalation routes used by major platforms, so contractual, brand and talent-management questions can be handled alongside the removal itself. Deepfake and intimate-image matters rarely arrive in isolation — a platform escalation is often connected to a harassment pattern, a data protection complaint, or a live commercial relationship that needs managing at the same time. Instructing a firm that can hold the full picture is usually faster and produces a more coherent strategy than coordinating separately between a reputation consultant, a criminal solicitor and a commercial lawyer.

What Happens When You Instruct PAIL® Solicitors

1. Initial Legal Takedown Assessment

For a relatively straightforward matter — a single identifiable post on one platform, involving parties known to you and limited to the UK — we begin with a fixed-fee assessment, usually during a 60-minute paid consultation. This includes: a review of the evidence and what has been preserved so far; identification of the relevant platform and reporting routes available now; an initial assessment of the UK civil and criminal options realistically engaged on the facts; a recommended escalation sequence; and, where relevant, an initial view on commercial or reputation communications issues. We do not promise a guaranteed removal outcome — we assess and pursue the strongest available strategy.

2. Evidence and Escalation Strategy

Where a standard platform report has stalled, been rejected, or the content is spreading faster than it can be individually reported, we structure the evidence to the standard needed for escalation, a regulatory complaint, or civil proceedings, and coordinate reporting across multiple platforms where content has been reposted.

3. Legal Correspondence and Identification

Where an uploader, host, publisher or business is identifiable, we send targeted legal correspondence setting out the legal basis for removal and, where appropriate, a claim for damages along the lines recognised in FGX v Gaunt. Where the person responsible is not identifiable, we advise on the available routes to identify an anonymous poster. In suitable cases, a Norwich Pharmacal application may be available to seek information from a third party who is mixed up in the wrongdoing, with a view to identifying an anonymous wrongdoer. It is a court process, not an automatic platform disclosure route, and its suitability depends on the evidence, jurisdiction, proportionality and the information likely to be held.

4. Cross-Border and Regulatory Advice

Where the uploader, host or platform sits outside the UK, we advise on which of the UK, US or EU mechanisms described above is likely to be most effective for that specific platform and jurisdiction, and prepare correspondence in the form each mechanism expects.

5. Brand, Agency and Contractual Support

For agencies, brands and employers, we review existing talent, endorsement and crisis-response agreements against the specific facts of the incident, prepare risk-controlled internal and external communications, and advise on cooperation, indemnity, suspension and termination provisions relevant to the relationship.

Frequently Asked Questions

Is it illegal to create an AI deepfake of someone in the UK?

If the image is a purported sexual or intimate image of an identifiable adult, created without their consent and without a reasonable belief in consent, yes — since 6 February 2026 this is a criminal offence under section 66E of the Sexual Offences Act 2003. Separately, under section 66F, it is also an offence to request that someone else create such an image, whether or not it is ever produced. Both were inserted by the Data (Use and Access) Act 2025.

Does it matter if the image was never actually shared publicly?

No. Both the section 66E creation offence and the section 66F request offence can be committed whether or not the image is ever produced or shared. Sharing or threatening to share an intimate image remains its own, separate offence under section 66B of the Sexual Offences Act 2003.

Can I claim compensation, rather than relying on a criminal prosecution?

Potentially, yes. FGX v Gaunt [2023] EWHC 419 (KB) confirms that a civil claim for misuse of private information can succeed independently of any criminal case, and can result in a substantial damages award reflecting psychiatric harm as well as the privacy breach itself.

How quickly must a platform remove reported content?

In the US, the TAKE IT DOWN Act requires covered platforms to remove content within 48 hours of a valid notice, enforceable since May 2026. In the UK, the Crime and Policing Act 2026 places regulated user-to-user and search services under a duty to take down qualifying intimate image reports as soon as reasonably practicable, and in any event no later than 48 hours, subject to statutory exceptions. The exact scope, qualifying conditions and how this is being enforced in practice should be checked against Ofcom's current published guidance for the service in question.

What if the platform ignores my report or is based outside the UK?

This is one of the more common reasons to involve a solicitor. Options can include escalation through the platform's formal legal or law-enforcement request channels, correspondence with the host or publisher directly, a regulatory complaint (to Ofcom in the UK, or an equivalent body elsewhere), or, in appropriate cases, an application to identify an anonymous poster.

Do these laws cover content generated entirely from a text prompt, with no original photo involved?

UK guidance available at the time of writing suggests the offence is directed at images that depict a real, identifiable person, however they were produced — including images generated from text prompts alone, provided the person depicted is identifiable. This is a genuinely developing area of law rather than settled practice, and identifiability can be a real evidential question in individual cases; treat this specific point as one to confirm at the time of any actual matter, not as fixed law.

Can I find out who created or shared the image if the account is anonymous?

Sometimes. Where a platform holds identifying information about an anonymous account, a Norwich Pharmacal application may, in suitable cases, be available to compel disclosure of that information for the purpose of bringing a claim. This is a discretionary court process rather than an automatic right, and its availability depends on the evidence, jurisdiction and proportionality — but it is often one of the most valuable things a solicitor can assess early.

Does reporting the content to the police stop it from being removed from platforms?

No, and the two should generally happen in parallel rather than one after the other. A police report does not itself take content down, and a platform report does not itself constitute a criminal complaint. Where there is a safety risk, extortion or identifiable perpetrator, both routes are usually worth pursuing at the same time.

Why does this article avoid the term "revenge porn"?

Some people still search using that term, so it appears here for that reason. Legal and support bodies increasingly prefer "intimate image abuse" or "non-consensual intimate images" because the conduct need not involve revenge, pornography, or a former partner — a stranger creating a deepfake from a public photograph is covered by the same laws.

A Note on Data Protection: Special Category Data

Alongside the criminal and civil routes above, intimate imagery will commonly involve personal data and may engage the special category data regime under Article 9 of the UK GDPR (data concerning a person's sex life or sexual orientation), depending on the information processed and the context. Where it does, processing requires not only an ordinary lawful basis under Article 6 but a specific condition under Article 9, and non-consensual publication will often struggle to satisfy either. The party processing or hosting the image may be a data controller or processor for that content, depending on its role and the facts.

This can give rise to a further route that is sometimes overlooked: a complaint to the Information Commissioner's Office, and a right under Article 17 UK GDPR to request erasure. In some cases, a properly framed privacy request may require a platform to consider the matter through a route distinct from its ordinary in-app report. That does not guarantee removal, but it can be worth assessing alongside platform-policy and legal notices, and it runs alongside any criminal report or civil claim rather than instead of it.

Conclusion — The Content Moves Fast. Your Response Should Move Just as Fast.

AI-generated deepfakes and non-consensual intimate images are not a future risk for UK individuals, creators and brands to plan for eventually. Ofcom's ongoing enforcement work, the US TAKE IT DOWN Act, and the EU's overlapping frameworks all point the same direction: platforms are being pushed toward faster removal and greater accountability, and the legal routes available to victims are widening, not narrowing.

Two distinctions are worth holding onto above everything else in this article. Preserving evidence before reporting is not optional—it is often the difference between a fast resolution and a stalled one. And a platform report is a starting point, not a strategy: the fastest available legal mechanism is often not the first one that comes to mind.

Urgent online content, deepfake or intimate image issue?

A fixed-fee Initial Legal Takedown Assessment: evidence preservation, platform escalation options and a clear next-steps plan, scoped before you commit to anything further.

Call 0207 305 7491   |   Email us

Managing risk for an agency, brand or creator?

A fixed-fee review of your existing talent, endorsement and crisis-response agreements, before an incident forces the pace.

Email us to arrange a review

Useful Links and Resources

Urgent support:

- Revenge Porn Helpline — free UK helpline for adults affected by intimate image abuse: 0345 6000 459

- StopNCII.org — hash-matching service to help prevent known images being shared

This article is for general information purposes only and does not constitute legal advice. Nothing in this article creates a solicitor-client relationship between the reader and PAIL Solicitors Limited. If you have a specific situation involving a non-consensual intimate image, an AI-generated deepfake, or a platform's response to a report you have made, you should seek independent legal advice. Contact PAIL Solicitors for a confidential, fixed-fee consultation: peter@pailsolicitors.co.uk | 0207 305 7491 | pailsolicitors.co.uk

PAIL Solicitors Limited is authorised and regulated by the Solicitors Regulation Authority (SRA No. 827265). Peter Adediran is the author of A Practical Guide to Business, Law & the Internet (Kogan Page, 2002), the UK's first internet law textbook.