ISHIGHRISK AI
Analysis

What does the EU AI Act nudify apps ban cover, and who does it catch?

From 2 December 2026 Article 5 bans AI that generates non-consensual intimate imagery or CSAM. General-purpose generators are caught only if safeguards fail.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Regulation (EU) 2026/1744 added points (ba) and (bb) to Article 5(1), banning AI systems that generate or manipulate realistic intimate material of an identifiable person without explicit consent, or child sexual abuse material, from 2 December 2026. A dedicated nudify app is caught because that generation is its intended purpose. A general-purpose image or video generator is caught only under Article 5(1a)(a)(ii): where the output is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate safeguards to reliably prevent it and correct observed or reported misuse. Breach carries the top Article 99(3) ceiling of 35,000,000 euro or 7 percent of worldwide turnover, and small mid-caps get no relief on it.

The ban in one paragraph

From 2 December 2026, the EU AI Act nudify apps ban makes it unlawful to place on the market, put into service or use an AI system that generates or manipulates "realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent". That is Article 5(1)(ba). Its companion, Article 5(1)(bb), bans the same acts for systems that generate or manipulate child sexual abuse material as defined in Directive 2011/93/EU. Both were inserted by Regulation (EU) 2026/1744, the Digital Omnibus on AI, and both apply under Article 113, third paragraph, point (a), as amended.

The harder question is not what the ban covers but whom it reaches. Article 5(1a) narrows it sharply for providers whose systems are not built for this purpose, and that narrowing is where every general-purpose image, video and voice generator will have to make its case. The overview of all the Article 5 prohibitions places these two points alongside the rest; this page goes into the one test that decides most real cases.

2 Dec 2026 Article 5(1)(ba) and (bb), and the scoping paragraphs 5(1a) and 5(1b), apply under Article 113, third paragraph, point (a), as amended by Regulation (EU) 2026/1744.

The legislature's own reasoning is short. Recital 11 of Regulation (EU) 2026/1744 states that "non-consensual intimate material constitutes sexual violence and abuse against individuals, in particular women", and that "the proliferation of such technologies, often described as 'nudification' applications, has created an urgent need for an explicit regulatory prohibition". The recitals cited on this page are numbered as in the signed text, PE-CONS 30/1/26 REV 1.

What points (ba) and (bb) cover

The two points look like one rule but are built differently. Point (ba) is anchored on a real, identifiable adult or child and on consent. Point (bb) is anchored on a criminal-law definition and has no consent route.

Element Point (ba), intimate material Point (bb), child sexual abuse material
Subject An identifiable natural person Material or performance within Article 2(c) and (e) of Directive 2011/93/EU
Media Realistic images, videos, audio or similar material Material or performance as the Directive defines it
Consent Explicit consent of the depicted person takes the output outside the ban No consent route
Exception Article 5(1b) manipulation carve-out A "without right" defence under national law
Provider and deployer scope Narrowed by Article 5(1a) Narrowed by Article 5(1a)

Realistic. Recital 12 limits point (ba) to "realistic depictions of intimate parts, notably the genitals, pubic area, anus, exposed buttocks or exposed female breasts, nipples or areolae, or of sexually explicit activity". Realism "refers to the depiction of the person's face, voice or their body in a credible real-life manner, regardless of the realism of the context of that depiction or whether it fully corresponds to the actual voice or appearance of the depicted person". A fabricated body attached to a real face can therefore be within scope where it depicts intimate parts or sexually explicit activity. The same recital "excludes cartoonish or physically impossible depictions of a person's body".

Identifiable. Recital 12 states that the ban "does not affect the generation or manipulation of other forms of nude material, such as material that does not depict identifiable natural persons", nor partially nude depictions where intimate parts are not revealed, nor non-realistic artistic nude works.

Manipulation. Article 5(1b) provides that a system "that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation" for point (ba). Recital 12 gives changing the background, adding a text heading or enhancing the contrast or the brightness as examples, and adds that any manipulation which increases exposure or alters the nature of the act "falls under the scope of this prohibition", even where the source already depicted intimate parts.

Child sexual abuse material. Directive 2011/93/EU, Article 2(c), defines the material to include any depiction of "any person appearing to be a child" engaged in sexually explicit conduct, and "realistic images of a child engaged in sexually explicit conduct or realistic images of the sexual organs of a child, for primarily sexual purposes". Article 2(e) covers pornographic performance, a live exhibition including by means of information and communication technology. Nothing in point (bb) requires the child to be identifiable, and the Article 5(1b) carve-out applies to point (ba) only. Recital 13 explains the "without right" exception as covering authorities generating material in criminal proceedings and "the legitimate use of the AI system in the context of red-teaming and evaluation activities for the purpose of assessing the system's compliance with the prohibition".

When a provider is caught: Article 5(1a)

Article 5(1a)(a) provides that placing on the market or putting into service a system that generates or manipulates the material in point (ba) or (bb) "is only prohibited where" one of two routes is met.

  1. Intended purpose. Under Article 5(1a)(a)(i), the generation or manipulation "is the intended purpose of the AI system". Article 3(12) defines intended purpose by reference to the provider's own instructions for use, "promotional or sales materials and statements" and technical documentation. What the product says it does is evidence against it.
  2. Foreseeable outcome without adequate safeguards. Under Article 5(1a)(a)(ii), "the system's design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse".

The second route is cumulative. A system is caught only if all of these hold at once: the output is reasonably foreseeable, it is reproducible, it needs no significant technical modification, and the safeguards are not reasonable and adequate to prevent it and to correct misuse. Remove any one and the provider limb does not bite. Article 3(13) defines reasonably foreseeable misuse as use "not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems", so a determined user trying to get round a filter is part of what the safeguards are measured against.

Recital 12 says what adequate means. Measures "are considered adequate if they align with the state-of-the-art measures and demonstrably prevent or sufficiently reduce in each specific case the likelihood of generating or manipulating such material, taking into account known and reasonably foreseeable misuse, including reasonably foreseeable circumvention of the preventive measures without significant technical modification". Two words carry the weight: "state-of-the-art", which moves with the field, and "demonstrably", which puts the burden on evidence rather than intention.

The test is about the system as shipped. Article 5(1a)(a)(ii) looks at outcomes reachable "without requiring significant technical modification", and recital 12 expects corrective measures for observed or reported circumvention where they are reasonable, "taking into account the specific AI system, including its release and distribution strategy (such as open-source releases)". A hosted service and a downloadable model are judged on different facts, but both are judged.

Dedicated nudify apps against general-purpose generators

The two routes sort products into three groups, and the group decides what the provider has to argue.

Dedicated nudify apps. A system marketed to undress photos of real people has non-consensual intimate material as its intended purpose under Article 5(1a)(a)(i). Safeguards do not rescue it, because the safeguards defence belongs only to route (ii). The only way out of point (ba) for a system built for intimate generation is consent: recital 12 says such a system's measures "should include appropriate means for the distribution of the AI system aimed at enabling the reliable collection and demonstration of consent of the depicted person to such generation or manipulation, in compliance with Regulation (EU) 2016/679". A consent tick-box completed by the uploader, not the person depicted, does not meet that description.

General-purpose image, video and voice generators. Here the provider is outside the ban if its safeguards are reasonable and adequate. Recital 12 is explicit that the prohibition "should not prevent providers from developing the technical capabilities of AI systems to generate or manipulate images, videos, audio or similar material", and lists measures that could count: "data cleaning, refusal training, safe prompt design and output controls, runtime prompt guardrails, content classification and filtering mechanisms, usage restrictions, abuse detection mechanisms, and notice and action mechanisms". It adds that providers "retaining effective control over AI systems, for instance through a platform or a web interface" could follow and report misuse cases, in full compliance with privacy and data protection law. A photo-editing or face-swap feature that accepts an uploaded picture of a real person is the case where the reasonably foreseeable outcome is closest to the prohibited one.

Products where exposure is consented or not in issue. Recital 12 states the ban "does not cover generative AI applications where intimate parts are not exposed or, if exposed, this is subject to the freely given, specific, informed, unambiguous and explicit consent of the depicted person", giving try-on applications and medical applications such as anatomical simulations and mammograms as examples. It also preserves the exceptional medical use where the person concerned is incapable of consent, in accordance with fundamental rights, data protection and medical law.

Hypothetical, for illustration only: a provider ships a general image editor with an inpainting tool. Red-teaming shows that a short sequence of ordinary prompts reliably removes clothing from an uploaded photograph of a real person, and nothing in the pipeline classifies the output. That is a reproducible outcome needing no technical modification, with safeguards that do not prevent it, which is the combination Article 5(1a)(a)(ii) describes. The same editor with a tested output classifier and a working report-and-remove channel is making a different argument.

Being outside Article 5 is not the end of the analysis. A generative system still owes the Article 50(2) machine-readable marking duty, and deployers publishing realistic synthetic content of real people owe the Article 50(4) deep fake disclosure. The deep fake disclosure article and the Article 50 guide cover both.

When a deployer is caught, and when the AI Act stops

Article 5(1a)(b) prohibits use "only where the deployer uses the system for the purpose of generating or manipulating such material or performance". Recital 12 spells out both edges. It covers a deployer who uses a system lacking safeguards, who "circumvents the preventive measures", or who uses for that purpose "lawful AI systems not intended to generate or manipulate such material". It does not cover use for lawful purposes even where the provider's safeguards are missing, "nor does it cover accidental generation or manipulation of such content".

The provider and deployer limbs are independent: a provider can breach Article 5(1a)(a)(ii) through missing safeguards even if no deployer has yet misused the system, and a deployer can breach Article 5(1a)(b) by jailbreaking a system whose provider has done everything right. The provider and deployer guide explains how the two roles are assigned.

The AI Act then stops at the private individual. Article 2(10) provides that the regulation "does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity". That is not a gap in protection so much as a hand-off. Article 5(8) preserves prohibitions that apply where a practice infringes other Union law, recital 15 states that the conduct may also violate other law, including criminal law, and that the prohibitions "do not preclude prosecution under such law", and recital 16 keeps national remedies for rights to image, privacy and dignity intact.

What a provider should be able to show by 2 December 2026

Article 5 creates no documentation duty and no conformity assessment. But route (ii) turns on whether safeguards "reliably prevent" an outcome and whether misuse is corrected, and recital 12 asks that measures "demonstrably" work. A provider that cannot evidence its safeguards will struggle to show they exist in the sense the text requires. The checklist below is a reading of those words, not a statutory list.

  1. An intended-purpose record. Article 3(12) makes instructions for use, promotional and sales material and statements the evidence of purpose. Review them for anything that markets undressing, body swapping or explicit generation of real people.
  2. A reproducibility assessment. Red-team the system as shipped against both prohibited outputs, using the circumvention techniques a determined user would try, and record what is reachable without significant technical modification. Recital 13 treats legitimate red-teaming for compliance with the prohibition as within the "without right" defence for point (bb) material, under the national law that defines it.
  3. A safeguards inventory mapped to recital 12. Data cleaning, refusal training, prompt and output controls, classifiers and filters, usage restrictions and abuse detection, each with test results showing what it prevents and how often it fails.
  4. A correction loop. Article 5(1a)(a)(ii) requires safeguards "to correct observed or reported misuse". Keep the reporting channel, the response procedure and a log showing reports leading to fixes.
  5. A state-of-the-art review. Adequacy is measured against state-of-the-art measures under recital 12, so record what comparable systems deploy and revisit it, because the benchmark moves.
  6. Consent machinery where intimate generation is the purpose. Recital 12 expects means for "the reliable collection and demonstration of consent of the depicted person", processed in line with the GDPR.

The Commission's guidelines on prohibited practices were issued in February 2025, before these points existed, so for now the article text and the recitals are the material to work from. The classifier screens the other Article 5 practices and the high-risk categories in the same pass.

Penalties, timing and who has no relief

Breach falls in the top Article 99(3) tier. Article 99(6a), inserted by the omnibus, gives small mid-caps a lower-of rule only for "each fine referred to in paragraphs 4 and 5", so it never reaches Article 5. The penalties guide sets out the full tier structure.

Operator Article 5 ceiling Source
Undertaking 35,000,000 euro or 7 percent of worldwide turnover, whichever is higher Art 99(3)
SME or start-up The same figures, whichever is lower Art 99(6)
Small mid-cap The same as any undertaking, no relief Art 99(3), 99(6a)

Three points on reach. First, there is no grandfathering: Article 111 contains no transitional provision for points (ba) and (bb), and its paragraphs 1 and 2 are expressly "without prejudice to the application of Article 5". Second, an open licence does not help: Article 2(12) takes free and open-source systems outside the regulation "unless they are placed on the market or put into service" as, among other things, "an AI system that falls under Article 5". Third, recital 15 requires member states to respect ne bis in idem where an Article 99 penalty of a criminal nature and a criminal sanction cover the same conduct. The rest of the omnibus is mapped in the Digital Omnibus guide.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

When does the EU AI Act ban on nudify apps apply?

From 2 December 2026. Article 113, third paragraph, point (a), as amended by Regulation (EU) 2026/1744, applies Chapters I and II from 2 February 2025 "with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026". Article 111 contains no transitional relief for systems already on the market.

Are general-purpose image generators banned under the AI Act?

No, not as such. Under Article 5(1a)(a) a provider of a system not intended to produce intimate or abuse material is caught only where that output is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate technical safety measures and other safeguards to reliably prevent it and to correct observed or reported misuse. Recital 12 of Regulation (EU) 2026/1744 says the ban "should not prevent providers from developing the technical capabilities" to generate images. The safeguards are what keep a general-purpose generator outside the ban.

Is consensual AI-generated intimate content banned?

Not under point (ba), provided the depicted person gave "freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation", as Article 5(1)(ba) puts it. Recital 12 adds that a system intended for such generation should include means enabling "the reliable collection and demonstration of consent of the depicted person". Point (bb) on child sexual abuse material has no consent route at all.

Does the AI Act ban apply to someone using a nudify app at home?

Not through the AI Act. Article 2(10) excludes the obligations of deployers who are natural persons using AI systems in a purely personal non-professional activity. Recital 15 of Regulation (EU) 2026/1744 records that the conduct may also violate other law, including criminal law, and that the prohibitions "do not preclude prosecution under such law".

Does editing an existing intimate image count as manipulation?

Only if the edit increases the exposure of intimate parts or alters the nature of a depicted sexually explicit activity. Article 5(1b) provides that manipulation which "does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation" for point (ba). Recital 12 gives changing the background, adding a text heading or enhancing the contrast or the brightness as examples outside the ban.

What is the fine for breaching the nudify ban?

Up to 35,000,000 euro or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(3). SMEs and start-ups pay whichever is lower under Article 99(6). The new small mid-cap relief in Article 99(6a) covers only the fines in paragraphs 4 and 5, so it does not reach a prohibited practice.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 5 October 2026. Final classification for ambiguous cases needs qualified counsel.