The New Prohibition on AI-Generated Intimate Imagery: Not What You Intended, But What You Can Prove

REGULATORY UPDATE · AUGUST 2026
The New Prohibition on AI-Generated Intimate Imagery: Not What You Intended, But What You Can Prove

Two lawsuits filed this year, one against an AI company and one brought by it, sit on opposite sides of the same question. They illustrate the gap between two regimes: Israeli law treats publication as the offence, while the new European prohibition, effective 2 December 2026, is aimed at the tool that produced the material.

LEGISLATIVE UPDATE

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Known as the Digital Omnibus on AI, it amends the Artificial Intelligence Act, Regulation (EU) 2024/1689. It postpones most obligations applying to high-risk systems while adding two new prohibitions to Article 5, both of which apply from 2 December 2026.

CONTENTS

  1. Two lawsuits over Grok: one against the company, one brought by it against a user
  2. What the new Regulation actually prohibits, and what falls outside it
  3. The provider is caught even without intent; the deployer only on deliberate use
  4. What was postponed to December 2027, and what already applies from December 2026
  5. In Israel the prohibition reaches publication, not the tool that created the material
  6. Two liability regimes, and what they mean for an Israeli company

1. Two lawsuits over Grok: one against the company, one brought by it against a user

At the end of December 2025 image editing was enabled in xAI's Grok model. In January 2026 X was flooded with sexualised images generated in response to simple prompts from anonymous users, including images of real women, identifiable by full name and face, depicted nude or minimally clothed without their consent. The United Kingdom announced an investigation on 12 January 2026, the Attorney General of California opened one of his own on 14 January 2026, Indonesia, Malaysia and the Philippines temporarily blocked access to the model, and on 3 February 2026 the French cyber police searched X's offices in Paris.

Two legal proceedings grew out of those events.

The first was filed in Israel. In March 2026 the content creator Shir Shahaf brought a civil claim in the Tel Aviv Magistrates' Court against X.AI Corp for ILS 277,000, pleading two causes of action: sexual harassment and invasion of privacy. What is novel is not the causes of action, which are well established in Israeli law, but that the claim is directed at the artificial intelligence company itself rather than at the anonymous user who entered the prompt. The claim is pending and no judgment has been handed down.

The second proceeding was filed in the United States, over the same technology, save that this time the plaintiff is the company itself. In July 2026 xAI sued one of Grok's users, a 67-year-old South Carolina resident previously arrested on suspicion of child sexual exploitation offences, alleging that he crafted misleading and sophisticated prompts in order to deliberately circumvent the safety mechanisms built into the system and turn innocuous images into sexual material.

While the Israeli claim asserts that the company bears responsibility for the output, the company is, in the very same months, assembling the evidentiary basis for the opposite proposition: safeguards existed, they were reasonable, and the user deliberately circumvented them.

That is precisely the defence the new European Regulation makes available to a provider from 2 December 2026, and it turns entirely on the quality of the documentation.

2 Dec 2026New prohibition takes effect
EUR 35mor 7% of worldwide turnover, whichever is higher. For an SME, whichever is lower
5 yearsImprisonment in Israel for publication under the Videos Law
ILS 120,000Damages without proof of loss, per publication

2. What the new Regulation actually prohibits, and what falls outside it

Article 5 of the Artificial Intelligence Act lists the prohibited practices, the highest tier, which is not subject to risk management but to outright prohibition. The new Regulation adds two items to that list: AI systems that generate or alter realistic images, video or audio depicting the intimate parts of an identifiable person or that person's explicit sexual activity without their consent, and systems that generate child sexual abuse material. Both prohibitions apply from 2 December 2026.

The prohibition was not part of the Commission's original proposal of November 2025. It was introduced by the Council in its negotiating position in March 2026, following the events described above.

The Regulation clarifies that altering existing material in a way that neither increases the exposure of intimate parts nor changes the character of the sexual activity depicted does not amount to alteration for the purposes of the prohibition. This is a targeted provision, not a blanket restriction on image editing.

3. The provider is caught even without intent; the deployer only on deliberate use

The two roles are defined separately in the Act, and a party occupying both, such as a company that has built a model and also runs it within its own service, is measured against both tests.

Two terms recur throughout the Act and are worth fixing at the outset. Placing on the market means making the system available on the Union market for the first time, whether or not for payment. Putting into service means supplying it for first use, whether to a customer or for the company's own internal use. Either one is enough to bring the system within scope.

Provider

Placing the system on the Union market or putting it into service is prohibited in two situations.

The first: generating the prohibited material is the intended purpose of the system.

The second: the system was not built for that purpose, but its design, training, architecture or functionality make that outcome a reasonably foreseeable and reproducible one, and no reasonable and appropriate technical safety measures have been put in place to prevent it.

Deployer

Caught by the prohibition only where the system is used for the specific purpose of generating or altering the prohibited material. A party that integrates a general-purpose system into its own service, where that is not the purpose of use, does not fall within the prohibition by reason of the integration alone.

The assessment a provider must carry out is narrow and precise: is the prohibited outcome reasonably foreseeable, and can it be reached again without significant technical modification to the system. If the answer is yes, the question moves immediately to the measures in place. The recitals expressly identify the kinds of measures capable of meeting the requirement, among them training the model to refuse such requests, input-stage restrictions, filtering of outputs before they are displayed, and detecting and reporting instances of misuse. The measures must also withstand reasonably foreseeable circumvention, and where circumvention is observed or reported, appropriate correction must follow.

What this means in practice: the prohibition is not framed as a question of intent but as a question of documentation. A provider unable to show which measures it implemented, when, how their resistance to circumvention was tested, and what it did once misuse was reported to it, will struggle to mount a defence even if it never intended its system to be used in that way.

An infringement of Article 5 falls within the highest fine tier in the Act, up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Article 99(6) reverses that rule for small and medium-sized enterprises and start-ups, for which the lower of the two amounts applies. For an Israeli company with a turnover of EUR 10 million the ceiling is therefore EUR 700,000 rather than EUR 35 million, an amount that still warrants preparation but is far removed from the headline.

4. What was postponed to December 2027, and what already applies from December 2026

The Artificial Intelligence Act does not take effect all at once, but through a series of dates, each of which triggers a different set of obligations. The new Regulation moved only two of them, both relating to the high-risk regime, and left everything else in place.

THE TERMS BEHIND THE TIMELINE

Prohibited practices (Article 5)
The most serious category in the Act. There is no risk management and no conformity procedure here, only prohibition. The original list covered, among other things, social scoring and the exploitation of vulnerable groups, as well as real-time remote biometric identification in public spaces for law enforcement purposes, the last of these subject to defined exceptions. The two prohibitions discussed here have now been added to that list, and an infringement attracts the highest fine tier.
AI literacy (Article 4)
An obligation on providers and deployers to ensure that staff involved in operating the systems have a sufficient understanding of their capabilities and limitations. This is not formal certification but an organisational requirement for training appropriate to the role.
General-purpose AI models (GPAI)
Large models not built for a single purpose but serving as a foundation for a range of applications, such as the large language and image models. The obligations on their providers concern technical documentation, information to be supplied to those building on top of them, copyright policy, and systemic risk in the most capable models.
Transparency obligations (Article 50)
A set of obligations designed to prevent a person from being misled when faced with machine output. It includes the duty to inform a person that they are interacting with an AI system rather than a human, and the duty to mark content generated by artificial intelligence.
Machine-readable marking (Article 50(2))
A sub-obligation within Article 50, under which marking is not satisfied by a notice to the human eye alone but must be embedded in the output itself in machine-readable form, so that another system can automatically detect that the content is synthetic. This is the mechanism commonly known as watermarking.
High-risk systems, Annex III
Standalone systems used in fields the legislature identified as particularly sensitive: employment and candidate screening, education, credit scoring, biometric identification, critical infrastructure, law enforcement and border management. These are not prohibited, but they carry the heaviest package of obligations: risk management, data quality, technical documentation, human oversight, accuracy and security, registration in a European database, and incident reporting.
High-risk systems, Annex I
AI systems embedded in products already subject to European product safety legislation, such as medical devices, machinery, lifts and toys. Because a parallel supervisory mechanism already applies to them, their timetable is longer.
Regulatory sandboxes
A supervised framework in which an AI system can be developed and tested in coordination with the competent authority, before it is placed on the market and without immediate exposure to full enforcement. The Act requires every Member State to establish at least one.
  • 2 February 2025The original prohibited practices under Article 5 and the AI literacy obligation under Article 4 took effect. The new Regulation did not touch them.
  • 2 August 2025Obligations on providers of general-purpose AI models took effect. These too were left unchanged.
  • 2 August 2026The transparency obligations under Article 50 apply in full, including notification of interaction with a machine and the marking of generated content. This is the original date around which most compliance programmes were built, and it stands.
  • 2 December 2026The two new prohibitions take effect: generation of intimate imagery without consent, and child sexual abuse material. On the same date the machine-readable marking obligation under Article 50(2) also applies to systems already on the market before August 2026, for which an extension was granted.
  • 2 August 2027The date by which each Member State must have at least one national regulatory sandbox in place.
  • 2 December 2027Full obligations for standalone high-risk systems under Annex III. Postponed from the original date of 2 August 2026, by sixteen months.
  • 2 August 2028Obligations for high-risk systems embedded in products under Annex I, a postponement of twelve months.

5. In Israel the prohibition reaches publication, not the tool that created the material

The principal Israeli provision is found in Amendment No. 10 of 2014 to the Prevention of Sexual Harassment Law, 5758-1998, known as the Videos Law. Section 3(a)(5a) provides that publishing a photograph, film or recording of a person that focuses on their sexuality, in circumstances in which the publication is liable to humiliate or degrade them and without their consent, constitutes sexual harassment. The section expressly adds that the term includes editing or compositing, provided that the person can be identified in the circumstances. That wording, enacted years before the term deepfake entered common usage, applies to the new technology almost by accident. The penalty reaches five years' imprisonment, alongside a civil cause of action for damages of up to ILS 120,000 without proof of loss for each publication.

In late January 2026, against the background of those same events, the Israeli Privacy Protection Authority published a warning that the use of technological means to depict a person nude or minimally clothed without their consent may constitute a criminal offence. The Authority identified four possible avenues of exposure: invasion of privacy, sexual harassment, unlawful processing of personal data, and potential liability of the platforms and companies themselves rather than only of the user who entered the prompt. In parallel, a Penal Law amendment bill on deepfake offences, 5786-2025, is making its way through the Knesset, seeking to establish graduated penalties and a rapid takedown duty on platforms, together with a separate bill that would allow the identity of anonymous distributors to be revealed, drawing on the existing mechanism in the Copyright Act of 2007.

Israeli law, as it currently stands, treats publication and distribution as the offence. It does not address the tool that created the material, and imposes no independent duty of care on a party that has placed such a capability on the market. The new European regime takes precisely the opposite approach: it is not concerned with the distributor, but with whether the system was placed on the market with adequate preventive measures.

European Union
Prohibition on placing the system on the market unless documented preventive measures are in place. Liability at provider level, independent of any actual distribution.
Israel, current law
Criminal and civil prohibition on publication and distribution. Applies to the publisher, including a person who received the material and passed it on.
Israel, pending bills
Graduated penalties for deepfake offences, a takedown duty on platforms, and power to reveal the identity of anonymous distributors.
Cross-cutting layer
The Protection of Privacy Law, 5741-1981, as a parallel cause of action. The Privacy Protection Authority's January 2026 position also points to potential liability of the operating company.

6. Two liability regimes, and what they mean for an Israeli company

Question Israeli law today Regulation (EU) 2026/1744
Who is exposed The publisher or distributor, including a person who passed on material they received The provider that placed the system on the market, and a deployer that used it for this purpose
Is distribution required Yes. Publication is an element of the offence No. Placing the system on the market without adequate measures suffices
Mental element Required, subject to the good faith, legitimate purpose and public interest defences Not central. It is enough that the outcome is reasonably foreseeable and can be reached again
The principal defence The defences set out in the Prevention of Sexual Harassment Law Reasonable and appropriate technical safety measures, documented and resistant to circumvention
The sanction Up to five years' imprisonment, and civil damages of up to ILS 120,000 without proof of loss The highest fine tier, up to EUR 35 million or 7% of worldwide turnover, whichever is higher. For an SME or start-up, whichever is lower, under Article 99(6)

Practical implications for Israeli technology companies

The Artificial Intelligence Act has extraterritorial reach. It applies to providers, deployers, importers and distributors placing systems on the Union market, and to any company whose system outputs are used within the Union, regardless of its place of incorporation or physical presence in Europe.

Israeli companies that develop, integrate or offer media generators and image editing tools can therefore no longer rely on terms of use prohibiting unlawful use by end users. From December 2026 the compliance burden moves from legal damage control to product architecture, and it requires engineering documentation, documented adversarial testing of the red teaming kind, and proof of technical resilience established in advance.

This review is general in nature and does not constitute legal advice. Regulation in the fields of artificial intelligence and data protection is developing rapidly, and the provisions described may be updated. Last updated: 19 August 2026.

SOURCES

  • Regulation (EU) 2026/1744 of the European Parliament and of the Council, Official Journal of the European Union, 24 July 2026
  • Regulation (EU) 2024/1689, the Artificial Intelligence Act, Articles 4, 5, 50, 99(3) and 99(6), and Annexes I and III
  • Council of the European Union announcement of final adoption, 29 June 2026
  • Prevention of Sexual Harassment Law, 5758-1998, section 3(a)(5a), as amended by Amendment No. 10 of 2014
  • Protection of Privacy Law, 5741-1981
  • Israeli Privacy Protection Authority warning on the use of technological tools to depict a person unclothed, January 2026
  • Penal Law (Amendment, Deepfake Offences) Bill, 5786-2025
x
סייען נגישות
הגדלת גופן
הקטנת גופן
גופן קריא
גווני אפור
גווני מונוכרום
איפוס צבעים
הקטנת תצוגה
הגדלת תצוגה
איפוס תצוגה

אתר מונגש

אנו רואים חשיבות עליונה בהנגשת אתר האינטרנט שלנו לאנשים עם מוגבלויות, וכך לאפשר לכלל האוכלוסיה להשתמש באתרנו בקלות ובנוחות. באתר זה בוצעו מגוון פעולות להנגשת האתר, הכוללות בין השאר התקנת רכיב נגישות ייעודי.

סייגי נגישות

למרות מאמצנו להנגיש את כלל הדפים באתר באופן מלא, יתכן ויתגלו חלקים באתר שאינם נגישים. במידה ואינם מסוגלים לגלוש באתר באופן אופטימלי, אנה צרו איתנו קשר

רכיב נגישות

באתר זה הותקן רכיב נגישות מתקדם, מבית all internet - בניית אתרים.רכיב זה מסייע בהנגשת האתר עבור אנשים בעלי מוגבלויות.