Apple and Google both have written rules banning sexually explicit apps from their stores. Those rules are not new, they are not obscure, and both companies point to them in public statements. Yet for at least a year, apps designed to create fake nude images of real people have been sitting in their stores, passing review, earning revenue, and in some cases being pushed to users through the stores' own search and advertising systems.
That is the core finding behind the cease-and-desist letters San Francisco city attorney David Chiu sent to both companies this week. The letters target 13 specific apps: eight on Apple's App Store and five on Google Play. They broadly advertise themselves as face-swapping or photo-editing tools, with the ability to produce explicit images available once a user opens them.
Chiu has been building this case for a while. His office previously filed a lawsuit against 16 websites offering similar tools. The new legal notices go further by targeting the stores themselves, not just the developers. The argument is that Apple and Google reviewed these apps, listed them, collected payments, and in some cases ran ads promoting them when users searched for terms like "nudify." That makes the stores participants, not passive hosts.
California already has law on this. A 2025 state law, AB 621, which took effect on January 1 of this year, expanded the definition of illegal deepfake sexual content, clarified that minors cannot consent to its creation, raised damages for malicious violations to as high as $250,000 per case, and explicitly gave public attorneys civil enforcement powers. A separate California law criminalizes "knowingly facilitating" or "recklessly aiding" the creation of nonconsensual deepfake pornography. Chiu's letters warn Apple and Google they could face civil penalties and ask for a response within 28 days.
Google confirmed it removed all five Android apps flagged in the letters and said it has suspended hundreds of similar apps over the past year. Apple confirmed it removed three of the eight flagged apps and is terminating those developers' accounts, while requiring four others to fix violations or face removal. Both responses follow a pattern: act after being publicly named, then say the policy was always there.
The problem is that the pattern keeps repeating. The Tech Transparency Project, a nonprofit watchdog, published reports in January and again in April 2026 identifying dozens of these apps still available, with some rated suitable for children. In the April report, TTP found the stores were actively steering users toward these apps through autocomplete search suggestions and paid ads. Combined download counts for apps identified in those investigations stood at around 483 million, with roughly $122 million in estimated lifetime revenue.
The harder finding comes from academic research published in May. Researchers from Cornell University and Georgetown University tested 155 general face-swap apps, the kind that describe themselves as playful photo tools. Seventy percent had no safeguards to stop a user from creating explicit fake images. None of those apps describe themselves as nudification tools, which is precisely why they pass app store review. The problem is no longer confined to a specific category of obvious apps: it is embedded in ordinary editing software.
There is also a data privacy angle that rarely gets attention. Several of the apps identified in these investigations list developers based in China. Under Chinese law, companies are required to share data with the government on request. That means non-consensual intimate images of private individuals, created using these apps, could end up accessible to a foreign government.
For businesses and professionals, the direct exposure here is reputational and legal rather than operational. Any organization, employer, or institution whose staff or customers are targeted by these tools faces real harm to those individuals, and in some jurisdictions, potential liability depending on how images are created or distributed in a workplace context. The legal environment is moving fast: 46 U.S. states now have laws covering sexually explicit deepfakes, and San Francisco's action establishes a replicable template for other city and state attorneys to follow without waiting for federal action. The 28-day clock Chiu has set for Apple and Google is a small window, but the legal pressure building behind it is not going away.