The core finding of the new ISD report is blunt: the biggest traffic sources sending people to sites that create fake explicit images of real people are not dark corners of the internet. They are YouTube and X.
Between December 2025 and March 2026, social networks drove more than 5.7 million visits to these sites. YouTube contributed 1.82 million of those visits through videos that reviewed specific apps, walked users through how to use them, and in some cases shared promotional codes for free credits. This goes beyond passive referral: YouTube's own policies prohibit links to sexually explicit websites, yet the content was, according to researchers, easily discoverable.
X was the second-largest source at over 1.3 million visits. This matters especially because X's own AI tool, Grok, became a public controversy in January 2026 when it began generating sexually explicit images of women without consent, including some minors. X eventually restricted Grok access to paying subscribers, but the underlying traffic pattern continued.
The market behind this is real and growing. The apps collectively may generate as much as $36 million in revenue, with entry prices as low as $1 per image. A separate investigation by the Tech Transparency Project found that nudify apps across Apple and Google's stores had been downloaded 483 million times and earned over $122 million in lifetime revenue. Both companies officially prohibit these apps, yet researchers kept finding them through basic keyword searches, and in some cases through the platforms' own promoted ad results.
The targets of these tools are not abstract. The most frequently named victims in usage data are ex-partners and current partners. Researchers were also surprised to find that relatives such as sisters and cousins appeared as common targets. The motivation is not always what you might assume: ISD researchers found that a significant portion of requests were oriented around destroying someone's professional reputation or getting them fired, not sexual gratification.
Schools are becoming a serious pressure point. Deepfake abuse cases have been reported in over 90 schools globally. A survey by the Center for Democracy and Technology found that 15% of students reported knowing about AI-generated explicit images of a classmate. Girls and LGBTQ+ students are disproportionately targeted, and schools, by their own teachers' accounts, have almost no policies in place to handle it.
On the legal side, the US has moved quickly relative to previous technology controversies. The Take It Down Act, signed into law in May 2025, took full effect in May 2026, requiring platforms to remove non-consensual intimate images within 48 hours of a victim's request. The FTC is actively enforcing it, with civil penalties of up to $53,088 per violation. The DOJ secured its first criminal conviction under the law in April 2026.
Minnesota went further. In May 2026, it became the first US state to ban the apps themselves, not just the distribution of images they produce. Companies operating nudify tools face civil penalties of up to $500,000 per violation, and victims can sue directly for damages including mental anguish.
The gap between these laws and what is actually happening online is still wide. Laws targeting distribution, like the Take It Down Act, do not reach tools used privately. Minnesota's law targets creation, but applies only within one state, and apps hosted internationally are hard to touch. The FTC has sent warning letters to major platforms including Alphabet, Amazon, Apple, Meta, TikTok, and X, signaling it is watching.
For business operators, the regulatory expansion is the thing to track. Any platform or app that hosts user-generated content, including community forums, image sharing features, or messaging tools built into a product, may already fall under the Take It Down Act's definition of a covered platform. The law's scope is broader than most people assume, and legal experts say the FTC is not planning to interpret it narrowly.