Abusive, sexually explicit deepfakes have become easier to make and more widespread over the last nine years. They are no longer confined to dark web sites or shadowy networks. Instead, they appear on social media, show up in basic web searches, and live on easily downloadable apps and accessible forums.
The most prominent hosts of non-consensual, AI-generated imagery rely on some of the largest web infrastructure providers in the world. A new study examines how companies like Cloudflare, Google, Proton, Namecheap, and WordPress help these sites thrive. Despite years of knowledge about these popular platforms, big tech companies continue to provide services that prop up abuse imagery, even though their own terms of service often prohibit illegal and harmful content.
Who built the sites
Hany Farid, a professor in Computer Science at Dartmouth College, Sophie Nightingale, a senior lecturer in psychology at Lancaster University, and Sarah Morgan, who acts as the project coordinator on Nightingale’s “Protecting Ordinary People from Deepfake Harms” fellowship, published their paper in Stanford’s peer-reviewed Journal of Online Trust and Safety on Wednesday. The paper is titled “The Backbone of Abuse: How Infrastructure Providers Enable the Proliferation of AI-Generated Non-Consensual Intimate Imagery”.
In a six-week period between February and March, the researchers identified 400 URLs based on keyword searching and Google Alerts. They narrowed the list down to 88 sites actively hosting non-consensual intimate imagery. Most of the content featured female celebrities, actresses, pop singers, K-pop idols, and women working in politics or activism. The team used open-source web-analysis tools like WHOIS to determine which infrastructure providers supported these sites.
Five players emerged as dominant infrastructure providers: Cloudflare, Google, Namecheap, WordPress, and Protonmail. Cloudflare provided the lion’s share of services, offering website hosting, content delivery networks, domain-name server services, and analytic tools. Google supplied SSL certificates and advertising space for the majority of the sites studied. Namecheap was the dominant provider of domain registrar services. WordPress provided the majority of their content management system services, while Proton provided mail servers.
Each of these service providers forbids customers from using their services for illegal activity. Publishing or threatening to publish AI-generated non-consensual sexual imagery is a federal crime in the U.S. and elsewhere, and sexual abuse imagery in general is illegal in many countries.
Cloudflare, Proton, and Namecheap did not respond to 404 Media’s requests for comment about these findings.
A spokesperson for Google told 404 Media in a statement: “Without the specific domains from the report, we can’t investigate these claims. We have strict policies against non-consensual explicit content — including AI-generated imagery — across all our products. We make it easy for people to quickly remove this content on Search, continuously update our systems to limit its visibility, and we prohibit monetizing or promoting non-consensual and sexually explicit content.”
The Google spokesperson added that its advertising platform prohibits monetizing or promoting non-consensual and sexually explicit content. The company treats this content as egregious violations, blocking ads on the sites or suspending the advertiser accounts involved. People can request the removal of non-consensual explicit images from Search, and Google has a recently-updated removal request process. The company also updated its ranking algorithms by promoting non-explicit content where possible and demoting sites in search results that have a high number of removals against them.
A WordPress spokesperson said WordPress is “open-source software, not a hosting provider.” They wrote in a statement: “WordPress.org does not host websites or provide hosting services to sites that use WordPress, and we do not have access to or control over content published on independently hosted WordPress sites.” They noted that WordPress’s software is distributed under the general public use license, allowing anyone to use it for any purpose. “We take the issue of non-consensual intimate imagery seriously, but describing WordPress as providing services or infrastructure to these sites conflates the software a site uses with the services that host and operate it,” the spokesperson said.
In response to WordPress’s statement, Farid noted that while WordPress.org is not a host, WordPress.com is a hosting service. “It’s operated by Automattic, which Matt Mullenweg also runs, and it hosts millions of sites. Any NCII site on WordPress.com is squarely within scope,” he told 404 Media. “Automattic provides services to self-hosted sites. Jetpack and the WordPress.com CDN serve images from i0.wp.com/i1.wp.com for sites that enable it, meaning the intimate images themselves can be served from Automattic infrastructure even when the site is hosted elsewhere. That’s infrastructure by any definition.”
Farid also noted that WordPress.org maintains “an ongoing service relationship with self-hosted sites,” with core updates, plugin and theme distribution, and security patches coming from WordPress.org servers. Farid mentioned Automattic’s ongoing legal battle with WP Engine, during which, in 2024, Mullenweg announced WP Engine was blocked and then unblocked from accessing WordPress servers. He said this “showed the project can and will cut a specific operator off from those services.”
“So ‘no access to or control over’ is not entirely accurate,” Farid said.
‘The Most Dejected I’ve Ever Felt: Harassers Made Nude AI Images of Her, Then Started an OnlyFans’
Kylie Brewer isn’t unaccustomed to harassment online. But when people started using Grok-generated nudes of her on an OnlyFans account, it reached another level.
These providers do draw their own moral and legal lines on what kinds of customers they will tolerate and when they cooperate with authorities. After initially refusing to do so, Cloudflare dropped hate speech and doxing site Kiwifarms from its protection services in 2022, and terrorist manifesto host 8chan in 2019. In 2018, Cloudflare banned sex work harm reduction social network Switter from using its services, citing anti-trafficking legislation FOSTA/SESTA. In 2017, it stopped services to neo-Nazi site The Daily Stormer. In 2023, victims of the sex trafficking ring Girls Do Porn demanded Cloudflare stop providing services to sites hosting their abuse. Cloudflare claimed it does not have “control over the content of websites using those services,” does not have “the ability to alter or remove content on them,” and does not “have knowledge of the people or entities who post any specific content to such websites.”
404 Media previously reported that Proton gave the Swiss government payment data related to a Stop Cop City Protonmail account, which in turn handed it to the FBI. In 2024, Proton gave Spanish police information that identified a pseudonymous activist.
New Research Shows Deepfake Harassment Tools Spread on Social Media and Search Engines
An analysis of how tools to make non-consensual sexually explicit deepfakes spread online, from the Institute for Strategic Dialogue, shows X and search engines surface these sites easily.
Aside from the infrastructure issue the researchers were studying, they found that 312 of the 400 sites they initially identified were unrelated to deepfakes, like gambling or random travel or cooking SEO-slop sites. These sites used non-consensual imagery keywords as a way to rank higher in search results. This shows how incredibly popular the marketplace is for AI-generated abuse imagery and how sites are able to manipulate Google search to appear higher in results if they use related terms.
Sarah Morgan told 404 Media that while journalists can expose site administrators and legislation can act as a deterrent, the research group wanted to focus on infrastructure providers as the “distribution supply” for these sites. “Creators are going to create and people are going to demand. We can’t stop that. But we can call for providers to cut the distribution supply and stop enabling these sites. This content needs preventing from being shared in the first place. All parts of the ecosystem have to work together to play a part,” she said.
The researchers recommend in their paper that these providers stop supplying services to sites hosting non-consensual imagery.
“We aren’t saying that infrastructure providers are knowingly facilitating this content — or that they are aware of what’s on every site that uses their provisions — but it’s in providers’ power to vastly improve their moderation and cease services to sites.
What it means
The study highlights a gap between the terms of service of major tech companies and their actual operations. While these firms publicly prohibit illegal content, they continue to provide the essential digital plumbing that allows abusive sites to exist. The research suggests that stopping the flow of infrastructure services is a more effective way to reduce the spread of non-consensual imagery than relying solely on site administrators or legislation.




