Author: Benjamin Shultz | Notes: Charts and graphic illustrations are included only in the PDF version of the paper. The project is led by Benjamin Shultz, Data Fellow at Agora Digitale Transformation, who serves as the point of contact. He is supervised by Dr. Vivien Benert, Innovation Lead for Digital Public Sphere.
This brief summarizes findings from an external audit of AI-generated non-consensual intimate imagery (NCII), colloquially known as deepfake pornography, depicting sitting members of national parliaments across the European Union. We find that exposure to this harm is not randomly distributed: it falls overwhelmingly on women, is amplified by institutional visibility, and is not reliably predicted by whether a country has passed deepfake-specific legislation. We map new forms of exposure that parliamentarians face and argue that takedown-based governance, built around removing content after the fact, cannot reach a harm produced upstream, often using locally downloaded tools. We then propose three concrete points of intervention.
Generative AI systems can now produce convincing sexualized imagery of any person whose photograph is public without that person’s participation, knowledge, or any expressive act. Governments around the world are warning parents, schools, and sports teams to exercise caution when posting photos of children and young people, as routine, well-intentioned image-sharing has itself become raw material for AI-generated NCII.[1] For sitting parliamentarians, the problem is similar. The only “act” required is holding office: a single official portrait, or a photograph or recording from an event, published as a routine condition of the role, is sufficient raw material for a generative model to extract and recombine one’s likeness. This is a technological escalation from how vulnerability to online harms has typically been understood and regulated.
In October 2025, Italy created a criminal offense for deepfake dissemination. Enforcement, however, activates only on the victim’s own complaint, and targets the individual who disseminates content, not the tools or infrastructure that made it possible. France’s and Australia’s 2024 deepfake statutes, as well as the 2025 US TAKE IT DOWN Act, all share the same underlying architecture: report the content, then remove it and then — sometimes — prosecute. Each of these instruments activates only after a depiction already exists, has already been found, and has usually already circulated. The deepfake-producing ecosystem has, however, moved into the shadows in the last year, following the takedown and seizure of several prolific publicly available repositories, including MrDeepFakes and CFake and SOCFake.
The evidence for this is now substantial and convergent, and 2026 has seen myriad research mapping the ecosystem. The Center for Countering Digital Hate estimates xAI’s Grok chatbot generated, in a sudden and uncontrolled rampage, three-million sexualized, non-consensual deepfakes in January, including 23,000 of children — an amount nearly impossible to prosecute in full. In March, Open Measures documented a functioning commission-based deepfake economy on 4Chan’s requests board, with daily activity nearly tripling from 2025-2026, before the board was shut down in May. In July, research published from AI Forensics shows the most-used image-editing tools on the machine learning community board HuggingFace comply instantly with undressing prompts, with an estimated 95% of sexualization attempts targeting women and 6.7% targeting children. There remains zero safeguards on the platform. And the Institute for Strategic Dialogue found this ecosystem to live off mainstream infrastructure using app stores, search engines, and payment processors to produce and distribute deepfake NCII.
Despite the documentation of the novel tactics, tools, marketplaces, technical and payment infrastructure involved, little measurement of how this harm is distributed across a defined, comparable population at intergovernmental scale has occurred, nor an assessment of its direct impact on democracy. Elected officials, from the UK, to the US, to the European Union, have been depicted and bravely come forward to testify about how this harm has affected them. Motivated by these accounts and the already-gendered state of online abuse, this brief reports, to our knowledge, the first complete, 27-member-state-audit of AI-generated NCII targeting sitting parliamentarians across the European Union.
Between 16-20 July we queried the names of 5,872 sitting members of national parliaments from the 27 European Union member states (94.4% coverage) against 160 domains known to host deepfake pornography, “celebrity leaks,” and inappropriate candid images of women in public life (e.g., upskirting). There are approximately 6,218 sitting members in lower and unicameral houses of the European Union’s national parliaments; after excluding temporarily vacant seats at the time of analysis, as well as gender non-binary, and independent and non-attached members, on account of these groups being too underrepresented to conduct statistical analysis on, we reached a population figure of 5,872 members. We constructed eight Google Custom Search engines, assigning 20 domains to each, and leveraged Google’s application programming interface (API) to pull down results. Our methodology was designed to be non-intrusive: we neither interacted with any producers or distributors of depictive content, nor downloaded or stored depictive content at any stage. Each valid ‘hit’ from the API was coded into one of six categories capturing: 1) whether deepfake NCII was actively hosted; 2) whether a generation tool was linked next to a named individual’s biographical information, with or 3) without raw material present; 4) whether an indexed search record persisted, with or 5) without a named webpage or a production request specific to a parliamentarian; or 6) whether a domain had been formally removed by authorities. The full coding regime can be seen in the appendix.
36 domains yielded hits. Our method was validated against 100 non-existent names, created using a name generator. With the exception of seven name collisions with real adult performers, this test produced no positive results, confirming that the patterns we observe reflect targeted rather than indiscriminate activity. Exposure was then modeled against gender, age, name-perceived migration background,[2] institutional prominence (current or former cabinet or party leadership), political orientation, and the presence of deepfake-specific legislation in each country.[3] Shortly before the publication of this report, eight domains were seized by the Manhattan (New York) District Attorney’s Office, eliminating the exposure that 19 MPs faced.
1. Women MPs are 33x more likely to face exposure than their male colleagues
Odds ratios show that women are 33-times more likely than their male colleagues to be depicted in or associated with deepfake pornography. Thus, gender is the dominant predictor in the model (p=0.000). While women were exposed at sxcale in all categories, among the nine men, eight were identified in only indexed, non-findable search results. We note that a limited number of active depictions of women (less than ten) were potentially photoshopped rather than AI-generated. However, we counted these nonetheless as non-consensual depictions. In line with AI Forensics’ research detailing the proliferation of custom-built machine learning models meant to nudify women, we did find one likeness and associated downloadable model on HuggingFace, which we classified as an active depiction. The full count of exposed MPs by category can be seen in the Appendix.
2. Institutional prominence compounds the gap
Among women parliamentarians specifically, those in senior office (cabinet ministers, party leaders) face substantially higher predicted exposure than their more junior colleagues (p=0.000). Because these are positions conferred primarily through political success rather than personal characteristics, this compounding effect is itself a structural pattern: achieving greater public standing carries a cost for women that it does not carry for men in equivalent positions.[4] We also tested whether political leaning factored into a parliamentarian’s probability of being depicted. We found left- (p=0.003) and right-leaning (p=0.038) parliamentarians to face a higher probability of exposure than their centrist colleagues. This aligns with prior work from the American Sunlight Project analyzing the US Congress, which demonstrated that exposure does not concentrate in any one place along the political spectrum.
3. “Gateways” link raw material and biographic information to “nudifier” apps
We term domains which showcased specific, named pages for parliamentarians and linked directly on these pages to AI-generation tools designed to produce sexualized or nude depictions of subjects as “gateways.” In total, we observed 61 instances of gateways with raw material present and 36 instances of gateways without raw material present. Notably, gateways for three parliamentarians did show active deepfake NCII. Destinations of the gateways we identified appeared to include three notable “nudifier apps,” as well as two in-house generation capabilities. During the course of writing this report, one gateway website removed its out-links to one of the three nudifier apps and two gateways originally observed without raw material gained raw material. Two examples can be seen below of a gateway, respectively, with (obstructed by the black box below), and without, raw material.
On all variations of gateways, there is a specific biography or newsfeed (termed interchangeably), as well as links to parliamentarians’ social media accounts. Some also exhibited ‘ratings’ of women’s bodies. To the earlier question of enforcement, it may well be that these sites are not technically in violation of deepfake-specific laws, as they do not show active deepfake NCII. However, even where they do not provide raw material, they provide all of the information and tools necessary for a user to acquire or use raw material to create a non-consensual, sexually explicit deepfake depicting a parliamentarian.
4. Legislation alone does not predict lower exposure
Counter to expectation, countries with deepfake-specific criminal legislation did not show lower exposure. We do not read this as evidence that legal protection is ineffective. Several countries without a specific deepfake NCII statute, including the Netherlands, actively prosecute this material under existing privacy or image-abuse laws, while some countries with a statute on the books show limited enforcement activity. The relevant policy variable, therefore, is enforcement, not statutory text, a distinction current legal tracking does not consistently capture. To the point of the Netherlands, we retroactively re-coded it as having a deepfake-specific law given its robust enforcement apparatus. We aim to grapple with this dynamic and better measure enforcement in subsequent runs of this study.
5. Indexing is a distinct layer of exposure which outlives takedowns
In the course of planning this study, the prolific deepfake-hosting domain CFake was seized by US and French authorities. We theorized that parliamentarians’ vulnerability to exposure in deepfake NCII was regulated on distinct layers, including — amongst other sociotechnical factors like gendered attention and interface accessibility — indexing and hosting infrastructures. As a control, we included CFake in our list of domains and were able to retrieve 47 still-indexed records via the Google Custom Search API, more than a month after the seizure. We were unable to replicate this manually searching via Google; however, the API is documented as returning a less-localized, more general search result. This finding still requires external replication, but is in line with research showing de-indexing to constitute its own process in the context of, e.g., the EU GDPR’s ‘right to be forgotten.’ In the case of deepfake-specific laws or proposals to give individuals copyright over their likeness, this finding demonstrates a renewed need to look upstream from just content that may be publicly googleable.
Current platform governance is built primarily around circulation: what gets posted, ranked, amplified, or removed after the fact. This framework is well suited to harms that begin with something a user posted. It has little, however, to offer in solving a harm that affects someone who posted nothing at all, who has had their likeness exploited and co-opted. Our findings point to three upstream points where intervention is possible before a depiction ever exists.
This brief is the first release of a project funded by Agora Digitale Transformation and the Mercator Foundation, tracking exposure of European public officials in deepfake NCII. Upcoming releases will re-audit the same population using the same methodology, allowing us to observe how exposure moves in response to specific, dateable events (e.g. platform shutdowns, new legislation taking effect, enforcement actions) rather than relying on a single snapshot. The seizure of eight domains shortly before this report’s publication demonstrates the need for continuous monitoring, as well as a limitation of most current evidence in this space, including this baseline release: a one-time measurement cannot distinguish a policy intervention that reduces harm from one that merely displaces it to another platform or jurisdiction. Recent evidence suggests displacement, not elimination, is the more common outcome following platform shutdowns. Subsequent releases in this series will report quarter-over-quarter change in exposure rates; the impact of any identifiable enforcement or platform events occurring within the quarter; and an updated assessment of which EU member states show measurable enforcement activity.
[1] See, e.g., July 2026 warnings from the Australian and British governments.
[2] Assessing name-perceived migration background across such a wide swath of states with differing definitions of race, ethnicity, and religion, as well as naming conventions, is a challenge; we attempted this to the best of our ability using Nationalize.io.
[3] We used a Firth-corrected logistic regression for this analysis specifically because it performs reliably on rare-outcome and group-concentrated data of this kind. Further explanation can be seen in the appendix.
[4] To validate this finding, we ran our model a second time with an interaction term between gender and institutional prominence, which proved statistically insignificant (p=0.485), indicating these variables operate independently.
For the full appendix, refer to the PDF version of the paper at the top of this page.

Medien ohne Macht.
Dr. Torben Klausa

Die Digitalagentur als Schaltstelle für die digitale Transformation der Bundesverwaltung.
Dr. Florian Theißing

Digitalisierung messbar machen: Ein anwendungsorientierter Indikatorenkatalog für Politik und Verwaltung.
Dr. Vivien Benert, Benedikt Göller
Wer sich für unsere Arbeit interessiert, kann sich hier für unseren Newsletter eintragen.