Intimate Deepfakes

From 6 February 2026, England and Wales criminalise creating or requesting non-consensual purported intimate images of adults, even where the image is never shared. Barrister Aemen Zulfikar Maluka examines sections 66E and 66F of the Sexual Offences Act 2003, AI nudification tools, platform liability and the lessons for Pakistan.

There is something jurisprudentially remarkable about punishing a person for manufacturing evidence of an event that never occurred.

No photograph was taken.

No intimate encounter happened.

The person depicted may never have removed a single item of clothing.

The supposed camera was never present.

And yet the resulting image can injure reputation, dignity, employment, family relationships and psychological security almost as effectively as a genuine intimate photograph disclosed without consent.

Artificial intelligence has forced criminal law to confront a peculiar truth:

an event need not have happened for somebody to be violated by an image purporting to show that it did.

On 6 February 2026, an important change to the criminal law of England and Wales came into force.

Section 138 of the Data (Use and Access) Act 2025 inserted new sections 66E to 66H into the Sexual Offences Act 2003, creating offences concerning the creation and requesting of purported intimate images of adults without consent or reasonable belief in consent. The commencement regulations expressly brought section 138 into force on 6 February 2026.

Despite occasional shorthand describing this as a new “UK deepfake offence”, territorial precision matters: the core section 138 adult offences discussed here extend and apply to England and Wales, rather than constituting a single identical criminal offence throughout every constituent jurisdiction of the United Kingdom.

The legislation is remarkable for another reason.

It does not merely criminalise distributing the synthetic image.

It moves the criminal law upstream.

Creating it can itself constitute the offence.

Requesting its creation can itself constitute another offence.

The victim does not have to discover the image on social media before the law becomes interested.

The image does not even have to reach another person.

Indeed, for the requesting offence, the requested image does not ultimately have to be created at all.

And the British legal response has already moved further upstream again.

Since 29 June 2026, separate provisions inserted by the Crime and Policing Act 2026 criminalise making, adapting, supplying or offering to supply certain generators of purported intimate images—the category commonly associated with so-called “nudification” or “nudify” applications.

In the space of a few months, the legal focus has therefore migrated:

from sharing the image,
to creating the image,
to requesting the image,
to supplying the technology designed to generate the image.

That is a significant development in criminal-law philosophy.

It deserves considerably more attention than the familiar headline that “deepfakes are now illegal”.

Because that headline is both too broad and not broad enough.

This is not a general prohibition on deepfakes

Deepfakes are not categorically unlawful in England and Wales.

AI-generated films, satire, visual effects, artistic works, synthetic actors, historical reconstruction and fictional imagery do not suddenly become crimes because artificial intelligence was involved.

The legislation is targeted.

Section 66E of the Sexual Offences Act 2003 now provides an offence where one person intentionally creates a purported intimate image of another person, that other person does not consent to its creation, and the creator does not reasonably believe that consent exists.

Section 66F separately criminalises intentionally requesting the creation of such a purported intimate image where the depicted person has not consented to that request and there is no reasonable belief in their consent.

The relevant legal wrong is therefore constructed around several ideas:

a real person;

an intimate representation;

artificial creation or manipulation;

intentional conduct;

and absence of consent or reasonable belief in consent.

That is much narrower than “AI imagery is unlawful”.

But it is considerably broader than the old model of “revenge pornography”.

The phrase “revenge porn” has become legally inadequate

The terminology was always troublesome.

It implied that intimate-image abuse was principally committed by disgruntled former partners seeking revenge.

That is not necessarily so.

The Crown Prosecution Service itself cautions that the phrase can mislead because offenders may be motivated by sexual gratification, money, notoriety, control, humiliation or other reasons, and the relevant images are not necessarily “pornographic” in the conventional sense.

AI deepfakes make the terminology even less useful.

A stranger can now create a sexualised image of somebody they have never met.

A school acquaintance may generate one as a joke.

An online harasser may manufacture hundreds.

A commercial service may automate the process.

A political opponent may seek humiliation.

An abusive partner may use synthetic imagery as another instrument of coercive control.

A criminal may use an image for extortion.

A group chat may create material collectively without any romantic relationship ever having existed.

There may be no revenge.

And there may never have been any genuine intimate photograph in the first place.

The law therefore increasingly speaks of intimate image abuse.

That is a more accurate concept.

The most radical proposition is that publication is unnecessary

This deserves to be stated plainly.

A person does not necessarily have to upload, transmit, send or publish the synthetic intimate image before criminal liability can arise under section 66E.

The creation itself is the conduct prohibited where the statutory elements are satisfied. The CPS describes the offence accordingly: intentionally creating a purported intimate image without the depicted person’s consent or reasonable belief in consent.

This represents a major departure from the traditional structure of image-based abuse.

Historically, much of the law was concerned with disclosure.

The photograph existed lawfully or unlawfully.

The criminal event occurred when it was distributed.

The new offence recognises that synthetic intimate imagery creates a different kind of harm.

The violation can begin at creation.

Why should a private image which nobody has seen be criminal?

This is where the legislation becomes philosophically interesting.

One might ask:

If somebody generates a synthetic intimate image privately, never posts it, never sends it to anyone and never tells the depicted person that it exists, where is the harm sufficiently serious to justify criminal law?

That is not a frivolous objection.

Criminal law ordinarily demands a persuasive justification before entering purely private conduct.

There are powerful counterarguments.

First, creating such an image manufactures sexually explicit material using another person’s identity without their consent.

Secondly, the existence of the file creates the permanent possibility of disclosure, hacking, theft, blackmail or accidental circulation.

Thirdly, its creation itself may form part of stalking, harassment, coercive control or obsessive conduct.

Fourthly, AI changes the economics of production so dramatically that waiting for publication may allow enormous volumes of abusive content to be created before law can intervene.

But perhaps the deepest argument concerns sexual autonomy.

The wrong is not merely that strangers might see the person naked.

The wrong is that someone has appropriated that person’s likeness to manufacture a sexual representation which the individual never chose to create.

That is a form of representational violation.

We are acquiring a law of sexual identity

Traditional sexual autonomy concerns what may physically be done to a person.

Modern privacy law extends protection to what may be recorded.

Intimate-image law extends it to what may be disclosed.

Deepfake law goes one step further.

It protects, in defined circumstances, what may be falsely represented as having happened to or been done by the person at all.

That is novel.

The person’s body is not physically involved.

But their identity is.

The harm arises because the image says:

“This is you.”

The criminal law is beginning to recognise that a person’s sexual identity can be appropriated digitally even where their physical body was never photographed.

What counts as a “purported intimate image”?

The statutory terminology is deliberately broader than “AI nude”.

The CPS explains that a purported intimate image is one which appears to be, or include, a photograph or film of a person but is not, or is not only, an authentic photograph or film of them; it must appear to depict an adult and appear to show that person in an intimate state.

This formulation catches obvious AI deepfakes.

It can also catch composites and manipulated material in which authentic and artificial elements are combined.

The law is interested not simply in images generated entirely from nothing, but in fabricated representations which purport to depict a real person intimately.

That distinction is sensible.

Many of the most convincing synthetic images will begin with something real.

A photograph from Facebook.

A professional headshot.

A wedding photograph.

An employee biography.

A public speech.

A social-media profile.

The offender supplies the face.

The software manufactures the rest.

The definition of an “intimate state” is broader than complete nudity

The Sexual Offences Act framework does not restrict intimate imagery to explicit intercourse or complete nudity.

CPS guidance explains that the statutory concept includes, amongst other things, depictions appearing to show sexual acts or sexual behaviour, exposed genitals, buttocks or breasts, and certain circumstances where those areas remain covered only by underwear or visible through transparent clothing.

That is important in the AI context.

“Nudification” does not need to produce total nudity before a serious legal issue arises.

Nor should organisations assume that putting a synthetic victim in underwear rather than depicting complete nudity necessarily removes the conduct from intimate-image legislation.

The statutory concept is intentionally broader than the colloquial expression “nude deepfake”.

The offence concerns real people, not purely imaginary people

Another boundary is important.

The section 66E/66F framework is directed towards purported imagery of another person. Legislative materials expressly distinguish images of actual persons from images of purely imaginary persons for these purposes.

That makes conceptual sense.

A wholly fictional adult generated by AI raises different moral and regulatory questions.

The distinctive wrong addressed here is the non-consensual appropriation of an identifiable person’s likeness into an intimate representation.

This does not mean every synthetic image of an imaginary person is legally harmless; other areas of obscenity, intellectual-property, child-protection or communications law may potentially arise depending upon the content.

It simply means that sections 66E and 66F are built around a victim whose identity is being represented.

Consent is the legal centre of gravity

The architecture of the offence is strikingly straightforward.

Did the person consent?

If not, did the accused reasonably believe that the person consented?

This moves the law away from difficult enquiries about whether the creator intended revenge, humiliation or emotional distress.

The victim does not need to demonstrate that the accused hated them.

Nor is it necessary to prove that the creator wanted the victim to discover the image.

The essential issue is unauthorised creation of the intimate representation.

That is a cleaner legal rule.

Consent to one thing should not be assumed to mean consent to another

This will become important in practice.

A person may consent to an ordinary photograph.

That does not logically entail consent to the photograph being transformed into a synthetic sexual image.

A person may previously have shared an intimate photograph consensually with a partner.

That does not necessarily authorise creation of additional synthetic imagery.

A model may consent to commercial photography.

That does not automatically authorise an advertiser to generate intimate material from her likeness.

An actor may license use of their image for a film.

That does not necessarily amount to consent for every synthetic alteration imaginable.

The legal and contractual lesson is straightforward:

consent should be specific enough to the use being made of identity.

Artificial intelligence makes vague consent particularly dangerous because once a digital likeness is available, the range of possible transformations becomes almost limitless.

Requesting the image can itself be criminal

Section 66F is perhaps even more intellectually interesting than section 66E.

It addresses the person who asks for the image to be made.

The legislation captures requests framed generally or specifically. Parliamentary materials explaining the provision make clear that it can apply not merely to “create an intimate image of X”, but to requests concerning particular characteristics of the resulting image.

This matters because AI abuse is often outsourced.

The person who wants the material need not possess image-generation expertise.

They may ask someone else.

They may participate in an online community.

They may respond to an offer.

They may pay a service.

The law therefore refuses to let the commissioning party hide behind the person performing the technical work.

The image does not have to be successfully created

This is one of the most important elements.

For the requesting offence, parliamentary legislative material states expressly that the offence may be committed regardless of whether the requested purported intimate image is ultimately created.

That means the criminal wrong can crystallise at the request.

Consider the significance.

A person attempts to commission intimate synthetic imagery of a colleague.

The service refuses.

No image exists.

No file is generated.

No victim sees anything.

Yet the law can still recognise the request itself as wrongful conduct where the statutory requirements are satisfied.

This is preventative criminal law.

“It was only a joke” may be a dangerous assumption

Both creation and requesting offences contain a reasonable-excuse defence.

That defence is important.

There may conceivably be unusual circumstances involving legitimate investigation, evidential testing, research or other justified conduct.

But it should not be treated as a general “humour” exemption.

The explanatory materials specifically address an attempted satire justification and indicate the Government’s view that a person creating a non-consensual purported intimate image of somebody engaged in sexual activity would be extremely unlikely to establish a reasonable excuse merely by calling the work satire.

That distinction matters because abusive digital behaviour is frequently trivialised after the event.

“It was banter.”

“It was just for the group chat.”

“It was a meme.”

“Everybody knew it was fake.”

“It was satire.”

Criminal liability depends upon the statutory facts, not the label supplied by the creator afterwards.

A group chat is not a law-free zone

This point deserves particular emphasis for younger users and employers.

Digital culture has created semi-private environments in which users sometimes behave as though normal legal standards have been suspended.

WhatsApp groups.

Discord servers.

Telegram channels.

Workplace chats.

Private social-media groups.

School or university group chats.

The fact that conduct occurs inside a small digital circle does not necessarily make it legally trivial.

And under the creation offence, sharing is not the prerequisite in any event.

A person may have crossed the relevant legal line before uploading anything to the group.

That profoundly changes the risk analysis.

The maximum sentence reflects the offence’s summary character—but the conviction still matters

The new creation and requesting offences are punishable on summary conviction by imprisonment up to the statutory maximum term for the offence, or a fine, or both; the relevant legislative provisions identify a maximum term of 51 weeks for offences committed after the applicable commencement point.

One should not judge significance solely by headline sentence length.

A sexual-offence conviction can have serious reputational, professional, immigration, employment and personal consequences beyond the immediate sentence.

Further, intimate-image conduct often occurs alongside other offending.

Harassment.

Stalking.

Coercive control.

Blackmail.

Threatening communications.

Unauthorised computer access.

Fraud.

Sharing intimate imagery.

A prosecutor does not necessarily encounter each digital act in isolation.

The CPS expressly advises prosecutors examining online abuse to consider the wider pattern of behaviour and potentially associated offences, particularly in domestic-abuse contexts.

Victims also receive more time for prosecution than ordinary summary offences would suggest

Sections 66E and 66F have an extended prosecution timetable.

CPS guidance explains that proceedings may be commenced within a framework allowing up to three years from commission of the offence, subject also to the requirement that the information or charge be brought within six months from the date on which sufficient evidence to justify prosecution comes to the prosecutor’s knowledge.

That is sensible for digital abuse.

Victims may not immediately discover what has been created.

A file may circulate privately for months.

The perpetrator may conceal it.

Digital forensic evidence may emerge during another investigation.

A rigid six-month period beginning only when the image was generated could allow serious misconduct to escape prosecution before anyone knew it happened.

The law can deprive offenders of the images and associated property

The statutory architecture also recognises that conviction alone does not solve the practical problem if the offender retains the material.

CPS guidance notes that the intimate image itself and material containing it can be treated as property used for the purposes of the offence for deprivation-order purposes.

The later Crime and Policing Act 2026 strengthens the remedial architecture further by introducing image deletion orders in connection with specified intimate-image offences, expressly including sections 66E and 66F.

This reflects an important principle.

Justice cannot end with:

“The offender has been punished.”

The victim may also reasonably ask:

“Why does the offender still possess the image?”

Digital remedies increasingly need to address persistence as well as punishment.

Britain then went after the machine

The legislative story did not end in February.

On 29 June 2026, the Crime and Policing Act 2026 brought into force a new section 66I offence concerning the making or supply of purported intimate-image generators. CPS guidance describes the target as technologies often called “nudification” applications—tools designed to create or facilitate purported intimate images.

The relevant “thing” can include a programme, electronically stored information or a service.

This is a much more aggressive form of legal intervention.

The February offence asks:

What did the user create?

The June offence asks:

What did the supplier build or supply?

The law has moved from user behaviour into product design.

Why criminalise the tool?

There is a respectable objection.

Many technologies are capable of lawful and unlawful use.

Image-editing software is not criminal merely because somebody might misuse it.

A camera is not criminal because it can be used voyeuristically.

A messaging service is not criminal because users can threaten others.

Code is often dual use.

The 2026 nudification offence therefore raises an important boundary question:

When is a technology sufficiently directed towards an abusive purpose that supplying the technology itself should become criminal?

The Government’s legislative explanation focused upon generators which a reasonable person would regard as made or supplied for use in generating purported intimate images, while providing defences and safeguards within the statutory scheme. The Government stated during passage that the provision was intended to capture applications, websites, AI models, bots and similar tools designed around that functionality.

That is not a ban on Photoshop.

It is an attempt to distinguish general creative technology from a product whose commercially meaningful purpose is synthetic intimate-image generation.

The law is attacking the economics of abuse

This is perhaps the most interesting policy development.

A person creating one illegal image can be prosecuted.

But if a commercial tool enables one million users to create millions of images, individual prosecution alone becomes structurally inadequate.

The supplier has reduced the cost of abuse.

Automation has removed the need for technical skill.

Scalability has converted something once requiring sophisticated editing into a consumer service.

The State therefore moves up the supply chain.

We have seen this logic elsewhere in law.

Regulation may target not merely the individual wrongdoer but the infrastructure enabling misconduct at scale.

Money-laundering law imposes duties upon financial intermediaries.

Product-safety law regulates manufacturers.

Cybercrime law can regulate malicious tools.

Platform law imposes obligations upon intermediaries.

AI now adds another category:

the automated abuse generator.

This raises an uncomfortable question about general-purpose AI

The truly difficult cases will concern systems which were not primarily built for abusive imagery but can nevertheless produce it.

A dedicated “remove her clothes” service is comparatively straightforward.

A sophisticated general-purpose image model is not.

It may generate:

architecture;

advertising;

art;

fashion;

educational images;

film concepts;

medical illustrations;

and millions of entirely legitimate outputs.

Suppose users discover prompt techniques capable of circumventing safeguards and creating unlawful intimate deepfakes.

At what point does the provider’s responsibility change?

What if the provider knows?

What if it repeatedly patches the system?

What if the safeguards are obviously inadequate?

What if abusive prompts account for a tiny proportion of use?

What if they account for a commercially significant proportion?

The distinction between a tool capable of abuse and a tool supplied for abuse will become legally critical.

Criminal law must resist technological overbreadth

This is where restraint matters.

A free society should be cautious about criminalising software merely because software can produce objectionable things.

The legislation therefore needs to maintain a principled distinction between:

general-purpose technologies;

specialised image-generation systems;

tools whose objective functionality strongly indicates prohibited use;

and providers actively designing or supplying services to facilitate intimate-image abuse.

Otherwise regulation could chill legitimate software development.

Good technology law must punish culpable design without making programmability itself suspicious.

The Online Safety Act creates the platform layer

Britain’s response now extends beyond creators and software suppliers.

The Online Safety Act 2023 already provides a regulatory structure for illegal content, and the 2026 legislative package adds the sections 66E and 66F intimate-image offences to the Act’s priority-offence architecture. The effect of priority status is to impose enhanced proactive duties upon regulated services concerning the risk that users encounter content amounting to those offences.

This creates another regulatory layer:

creator;

commissioning user;

generator supplier;

platform.

The theory is increasingly clear.

No single actor should be permitted to say:

“Somebody else in the digital chain is responsible.”

Responsibility depends upon role and control.

This is a much more sophisticated response than merely telling victims to sue

The traditional legal response to reputational or privacy injury often came afterwards.

The image is posted.

Millions see it.

The victim retains lawyers.

A platform is contacted.

An injunction is considered.

Damages are pursued.

The publisher may be anonymous or overseas.

By then the image has been downloaded and redistributed hundreds of times.

The internet has a cruel characteristic:

successful litigation cannot make millions of human memories forget.

That makes purely compensatory remedies inadequate.

The British framework increasingly attempts intervention at several earlier points:

prevent the abusive tool;

criminalise the request;

criminalise the creation;

regulate platform exposure;

permit removal and deletion;

and prosecute distribution where applicable.

That is preventative law.

A synthetic sexual image creates real-world damage

There is a persistent tendency to minimise deepfakes because “everyone knows it is fake”.

That misunderstands both human psychology and digital circulation.

An intimate deepfake can affect:

employment;

professional reputation;

family relations;

education;

marriage;

community standing;

physical security;

mental wellbeing;

and vulnerability to extortion.

The victim may also face the impossible burden of repeatedly explaining:

“That is not actually me.”

Every denial republishes the allegation conceptually.

The distinction between authentic and synthetic content may eventually be established forensically, but the social harm occurs much faster.

Law therefore has good reason to recognise synthetic sexual imagery as more than false information.

The law is protecting dignity without requiring physical contact

Traditional criminal law frequently organises harm around physical conduct.

Assault.

Touching.

Penetration.

Physical damage.

Technology has steadily expanded the category of legally cognisable non-physical harm.

Stalking can terrorise without touching.

Coercive control can destroy autonomy without obvious physical injury.

Harassment can create serious fear and distress through communication.

Intimate-image abuse can violate sexual privacy without physical proximity.

Synthetic intimate imagery continues that development.

The offender may never occupy the same room as the victim.

The violation is nevertheless personal.

Deepfake abuse can become a form of coercive control

This is particularly significant in intimate and family relationships.

Imagine an abusive partner saying:

“If you leave, I will create images showing you with other men.”

Or:

“I can make your family believe anything.”

Or:

“Nobody will know whether the images are real.”

The synthetic image then becomes a weapon of control.

The CPS specifically treats intimate-image abuse as conduct which may sit within broader patterns of domestic abuse, stalking, harassment and coercive behaviour, and advises prosecutors to consider the surrounding pattern rather than isolating each online act.

This contextual approach is essential.

AI may create new tools.

It does not necessarily create new motives.

Control remains control.

Humiliation remains humiliation.

Blackmail remains blackmail.

The legislation is formally gender-neutral

The offences protect “another person”.

Men can be victims.

Women can be offenders.

Same-sex abuse can occur.

Synthetic sexual imagery can target anybody.

That formal neutrality is correct.

Yet policy discussions have understandably emphasised violence against women and girls because intimate-image abuse disproportionately arises within wider patterns of gendered online abuse. The UK Government expressly framed its January 2026 intervention around the protection of women and girls and the harms associated with non-consensual AI-generated sexual imagery.

Law should be neutral in whom it protects while remaining capable of recognising patterns in whom particular harms disproportionately affect.

Those propositions are compatible.

What about children?

The section 66E and 66F offences are framed around purported intimate images appearing to depict adults.

That does not mean synthetic sexual imagery of children falls into a legal void.

CPS guidance separately identifies long-standing child sexual abuse image offences under the Protection of Children Act 1978 and Criminal Justice Act 1988, including law applicable to pseudo-photographs and certain computer-generated representations.

Indeed, the criminal-law response to synthetic child sexual imagery has historically been more developed precisely because the law learned earlier that an image need not depict an actual photographed child to create serious harm and illegality.

Adult deepfake law is, in one sense, catching up with an insight already familiar in child-protection law:

fabrication does not necessarily neutralise sexual harm.

The evidence in these prosecutions will be fascinating

How does the prosecution prove that somebody created the image?

Digital forensics will often become central.

Investigators may seek:

device histories;

prompt records;

cloud accounts;

payment records;

generation logs;

download timestamps;

application data;

browser history;

metadata;

communications with another creator;

messages requesting particular alterations;

and copies stored across devices.

The defence may contest attribution.

Did the accused actually control the account?

Was somebody else using the device?

Was the file automatically generated?

Was it downloaded rather than created?

Did the accused know what a particular service would produce?

Was consent given?

Was belief in consent reasonable?

Does the image actually satisfy the statutory definition?

AI crime remains ordinary criminal litigation in one important respect:

the prosecution must prove the elements of the offence.

The prompt may become evidence of intent

Artificial intelligence creates unusually revealing evidence.

Traditional offenders may conceal intention.

AI users frequently write it down.

A prompt can effectively record:

who should be depicted;

what they should be wearing;

what should be removed;

what act should appear to occur;

what modifications should be made;

and how realistic the result should look.

The command history can therefore become an evidential narrative of intentionality.

This should be remembered by anyone who thinks interaction with an AI generator is ephemeral.

Digital systems may retain logs.

Cloud providers may preserve records.

Screenshots may exist.

Payment processors may identify subscriptions.

Other participants may preserve messages.

The perceived privacy of a prompt is not the same thing as evidential invisibility.

“I deleted it” may not end the matter

Deletion is another dangerous assumption.

Digital information may persist in:

cloud backups;

temporary storage;

cached files;

message histories;

application servers;

device backups;

synced accounts;

recipient devices;

and forensic remnants.

Deletion may reduce harm.

It does not retrospectively mean the creation never occurred.

Nor does deleting the image necessarily eliminate evidence that the offence was committed.

The criminal act, if established, occurred at creation or request.

Employers should update AI-use policies

This legislation is not relevant only to police and criminal practitioners.

Employers should pay attention.

A member of staff uses company technology to create a synthetic intimate image of a colleague.

The conduct may engage:

criminal law;

harassment policies;

discrimination law;

employment duties;

data protection;

workplace safety;

reputational risk;

and potentially corporate investigations.

Employers should therefore consider explicitly addressing non-consensual synthetic intimate imagery within:

AI acceptable-use policies;

harassment policies;

disciplinary rules;

information-security policies;

and workplace investigation procedures.

Calling it “AI misuse” may be insufficient.

Some misuse is now potentially criminal.

Schools and universities face an equally urgent problem

Generative imagery creates particular risks in educational settings because young people often adopt new technologies faster than institutions understand them.

A student takes another student’s ordinary social-media photograph and feeds it into a nudification tool.

The resulting image circulates through a class group.

Someone says:

“It was just a prank.”

The law may view the matter very differently.

Educational institutions need clear safeguarding protocols dealing with:

synthetic intimate imagery;

device preservation;

reporting;

victim protection;

police referral where appropriate;

disciplinary procedure;

and prevention of further circulation.

Digital literacy must include legal literacy.

Businesses developing AI need criminal-law advice, not merely privacy advice

Technology companies frequently frame AI compliance around:

data protection;

intellectual property;

contractual terms;

and cybersecurity.

Those are important.

But increasingly, product design can intersect directly with criminal law.

If a company creates image-generation functionality capable of producing intimate synthetic material, it needs to understand:

what the service is designed to do;

what users actually use it for;

which safeguards exist;

how consent is addressed;

whether identity-based sexualisation is technically blocked;

what happens after circumvention attempts;

what reporting systems exist;

what logs are retained;

and whether particular product features could bring the service within criminal legislation concerning intimate-image generators.

That analysis should occur before launch.

Terms and conditions are not a defence to deliberately dangerous product design

A company cannot necessarily solve a dangerous feature by writing:

“Users must not use this tool unlawfully.”

Terms matter.

But so does architecture.

If a product is marketed around the precise functionality that legislation prohibits, a contractual prohibition inserted deep within user terms may have limited persuasive force.

The harder questions are:

What did you build?

How did you market it?

What safeguards did you install?

What did you know users were doing?

What proportion of use was abusive?

How did you respond?

Modern regulation increasingly looks beyond disclaimers towards actual system design.

There is a free-expression question—but it needs to be framed properly

Criminalising image creation inevitably engages expressive freedom.

Pictures are expression.

Satire is expression.

Art is expression.

Political commentary is expression.

AI-assisted creativity is expression.

That is why the reasonable-excuse defence and carefully drawn statutory elements matter.

But freedom of expression has never meant an unlimited right to manufacture every representation of another person without legal consequence.

Defamation law regulates false reputational claims.

Harassment law regulates abusive communications.

Privacy law restricts misuse of private information.

Intellectual-property law restricts appropriation.

Threatening communications can be criminal.

The relevant question is therefore not whether expression is implicated.

It plainly is.

The question is whether the interference is justified and proportionate to the harm addressed.

Sexualised falsification occupies an unusual category

The speech argument is especially weak where the expressive value consists principally in making a real person appear sexually exposed without consent.

There may be edge cases.

Artistic works.

Political satire.

Documentary or educational simulation.

Medical contexts.

Research.

Those deserve careful treatment.

But the ordinary non-consensual creation of fabricated sexual imagery of a recognisable individual is difficult to defend as a core exercise of democratic expression.

Freedom of speech should protect difficult ideas.

It does not follow that it must protect every technologically manufactured humiliation.

The law is really protecting the right not to be conscripted into somebody else’s sexual fiction

That may be the cleanest philosophical formulation.

AI enables one person to take another person’s identity and cast them into a scene they did not enter.

The target becomes an unwilling actor in someone else’s sexual production.

No physical performance occurred.

But the social representation exists.

The law says that consent matters before another person’s identity is used that way.

There is an intuitive moral coherence to that rule.

There is nevertheless a danger of criminalising curiosity at the margins

Hard cases remain.

What if a person uses their spouse’s image in consensual private experimentation but consent is ambiguous?

What if previous consent existed for similar material?

What if an artist creates a grotesque political collage?

What if the image is so obviously absurd that nobody could perceive it as photographic?

What if an academic researcher creates test material while studying deepfake detection?

What if police or cybersecurity researchers create samples for investigative purposes?

What if an AI system generates intimate elements unexpectedly?

Criminal law cannot be administered through outrage alone.

Intent, consent, reasonable belief, definition and reasonable excuse must retain real legal meaning.

That is how principled legislation differs from moral panic.

The reasonable-belief test is particularly important

The law does not demand omniscience.

The accused may argue that they reasonably believed the depicted person consented.

But “reasonable” matters.

A subjective assumption is not automatically enough.

The surrounding communications, relationship, previous conduct and nature of the requested image may become relevant.

The proper lesson is therefore not:

“Get a lawyer to draft a consent form before every joke.”

It is simpler.

Do not manufacture intimate imagery of real people unless there is genuine reason to believe they have consented.

The moral intuition and the legal risk point in approximately the same direction.

Pakistan already has a surprisingly relevant statutory starting point

For Pakistani lawyers, the British development is particularly interesting because Pakistan is not beginning from zero.

Section 21 of the Prevention of Electronic Crimes Act 2016 already criminalises specified offences against the modesty of natural persons and minors. The Sindh High Court has reproduced the provision in reported proceedings: it includes intentionally and publicly exhibiting, displaying or transmitting information which superimposes a person’s face upon a sexually explicit image or video, as well as certain other sexually explicit representations, intimidation and related conduct. The adult offence carries imprisonment which may extend to five years, a fine which may extend to five million rupees, or both.

That wording is remarkably prescient when viewed from the age of generative AI.

Pakistan’s Parliament enacted language addressing face superimposition onto sexually explicit imagery in 2016, years before contemporary consumer generative AI made convincing deepfakes inexpensive and widely accessible.

That deserves recognition.

But the British legislation exposes an important potential gap in the Pakistani model

Section 21 PECA is built around intentional and public exhibition, display or transmission of the prohibited information. The Sindh High Court’s reproduction of the statutory text makes that publication/transmission element clear.

England and Wales have now gone further.

Their 2026 offence can attach to creation itself, before publication.

And section 66F separately attacks the request for creation, even where no resulting image is successfully produced.

That creates a useful comparative question for Pakistan:

Should Pakistani law continue waiting for a sexually explicit deepfake to be publicly exhibited, displayed or transmitted before the specific intimate-image offence becomes complete, or should the law recognise non-consensual creation itself as the relevant wrong?

That is a serious policy question.

Pakistan should amend carefully rather than copy emotionally

A dramatic foreign development often produces calls to “bring the same law to Pakistan”.

That is not how good comparative law works.

Pakistan should ask which parts of the British approach solve genuine gaps in PECA and which require modification for local constitutional and institutional conditions.

Several issues deserve examination.

Should intentional creation itself be prohibited?

Should requesting creation be separately criminalised?

Should dedicated nudification services be regulated?

What definition of consent should apply?

What reasonable-excuse defence should exist?

How should artistic or research uses be treated?

Should synthetic sexualisation that clearly cannot be mistaken for reality still fall within the offence?

What investigative authority should obtain platform records?

How should cross-border evidence be gathered?

What rapid removal remedy should exist?

How should victims preserve evidence without repeatedly possessing traumatising material?

And perhaps most importantly:

how do we draft narrowly enough that a law protecting dignity does not become another vaguely worded instrument capable of abuse against legitimate expression?

PECA’s history makes drafting precision especially important

Pakistan’s cybercrime regime has repeatedly generated controversy concerning the breadth of online-speech offences and their potential use against journalists, political speech and public criticism.

That history matters.

A narrowly drafted intimate-deepfake offence is fundamentally different from a vague prohibition upon “false information”.

The victim is identifiable.

The type of depiction is defined.

Consent is central.

The conduct is specific.

The protected interest is intelligible.

The prosecution should prove clear statutory elements.

This is exactly where criminal law can be precise.

Pakistan should distinguish “false information” from “synthetic sexual abuse”

A deepfake of a politician falsely announcing a tax policy and a deepfake sexually exposing a private person create different harms.

The first raises misinformation, reputation and political-expression issues.

The second concerns sexual autonomy, dignity and intimate representation.

Trying to regulate both through one broad concept of “fake information” is undesirable.

The law should classify harm properly.

That improves both enforcement and civil liberties.

Section 21 PECA already points in the right conceptual direction

Pakistan’s existing offence against modesty is valuable precisely because it identifies specific sexually abusive conduct rather than criminalising falsity in the abstract.

The next logical question is whether the statutory language should evolve from the era of Photoshop-style “superimposition” towards generative AI.

Modern systems do not necessarily superimpose one photograph onto another.

They may synthesise a new body.

Alter clothing.

Generate imagined movement.

Create video from still photographs.

Clone voices.

Animate faces.

Construct scenes through diffusion models.

The final image may contain no traditional photographic cut-and-paste at all.

Technology has moved beyond the language through which earlier law understood manipulation.

Pakistan may need a technology-neutral definition

A better future statutory model may focus upon the result rather than the technique.

For example, the legal concept could address an artificially generated or manipulated image, audio-visual representation or other synthetic media which appears to depict an identifiable person in a defined intimate state.

That would avoid constant statutory amendment whenever the technical method changes.

Good technology legislation should survive the technology which inspired it.

Voice cloning should be considered separately

The British provisions under sections 66E and 66F focus upon images.

But generative AI increasingly produces synthetic audio.

Imagine a fabricated sexual audio recording attributed to another person.

It may damage reputation and dignity without containing an image.

Should intimate-image legislation be expanded?

Should communications, harassment or impersonation laws apply instead?

The answer requires careful thought.

Legislation written around photographs may soon confront synthetic media which is not photographic at all.

AI repeatedly exposes categorical boundaries inherited from earlier technology.

Deepfake blackmail may become particularly dangerous in Pakistan

There is a socio-legal dimension which should not be ignored.

In societies where accusations concerning sexuality can carry severe familial, professional or social consequences, a fabricated intimate image can possess enormous coercive power.

A criminal need not convince the entire internet.

They may only need to convince:

a spouse;

a parent;

an employer;

a fiancé;

a school;

or a small community.

Even the threat:

“I will make images of you”

may therefore carry significant coercive force.

Pakistan should approach synthetic intimate-image abuse not merely as obscenity or online indecency.

It can be an instrument of extortion, coercion, reputational violence and control.

Lawyers should also anticipate matrimonial and family-law disputes

Synthetic evidence will increasingly appear in family litigation.

One spouse produces an intimate photograph allegedly proving infidelity.

The other says it is generated.

What does the court do?

The dispute may involve:

forensic authentication;

metadata;

original devices;

platform records;

expert testimony;

chain of custody;

and corroborating evidence.

Family lawyers should become considerably more cautious about advising clients based upon screenshots alone.

The emotional persuasiveness of a photograph must not substitute for evidential authentication.

Synthetic imagery can weaponise honour and reputation

The Pakistani context makes this especially sensitive.

An intimate deepfake may be capable of generating serious harm even where technically sophisticated viewers would eventually establish that it is false.

The initial audience may not wait for forensic evidence.

Rumour travels faster than authentication.

The law therefore needs both:

criminal remedies against the creator; and

rapid procedural mechanisms for limiting circulation.

Punishment months later is important.

Stopping circulation today may matter more to the victim.

Platforms need a rapid evidential-preservation protocol

Removal and evidence preservation can conflict.

A victim understandably wants the image deleted immediately.

Investigators may need evidence showing:

the original upload;

account identity;

IP information;

timestamps;

generation history;

message chains;

recipient lists;

and hashes of the relevant material.

Platforms and investigators therefore need procedures capable of preserving necessary evidence while preventing continued public availability.

Otherwise victims face an intolerable choice:

leave the abusive material online so the case can be proved, or remove it and risk losing evidence.

Good digital procedure should eliminate that choice.

Cross-border AI services make jurisdiction difficult

The creator may be in Pakistan.

The victim may be in Britain.

The AI service may be incorporated in the United States.

The servers may be in Ireland.

The payment processor may be elsewhere.

The platform distributing the image may operate globally.

That is not an exotic scenario.

It is ordinary internet architecture.

Criminal investigation may therefore require:

international preservation requests;

mutual legal assistance;

platform cooperation;

cross-border data requests;

and careful jurisdictional analysis.

Deepfake law is inherently international.

This creates real advisory work for international lawyers

Technology companies should no longer ask merely:

“Is our AI legal where our engineers sit?”

They should ask:

Where are users?

Where are victims?

Where are outputs accessible?

Which jurisdiction criminalises the relevant conduct?

Are our moderation systems capable of responding?

Do our terms prohibit conduct local law prohibits?

Can we preserve evidence lawfully?

Are we subject to platform safety obligations?

Can our employees inadvertently expose the company to criminal investigations overseas?

International digital businesses need legal maps, not merely headquarters.

AI developers should build consent-sensitive systems where feasible

Technology cannot solve every legal problem.

But product design can reduce risk.

An image system capable of realistically modifying photographs of identifiable humans should consider safeguards around sexualised transformation.

Possible risk controls may include:

classification filters;

identity-protection systems;

prompt restrictions;

abuse detection;

rate limits;

account controls;

repeat-offender detection;

reporting mechanisms;

audit logs;

and escalation systems.

The correct design will depend upon the product.

But “we’ll respond after somebody complains” may increasingly appear inadequate where the foreseeable use is severe.

Privacy law and criminal law are beginning to converge around identity

An ordinary photograph is personal data.

A biometric face may be particularly sensitive in certain contexts.

A synthetic intimate image may contain data derived from that identity.

The conduct can engage privacy, data protection and criminal law simultaneously.

This overlap matters.

Technology advisers should resist organising risk into isolated boxes.

A single AI feature may involve:

copyright;

privacy;

sexual offences;

platform regulation;

defamation;

consumer law;

employment law;

and contractual rights.

Artificial intelligence is not a new legal silo.

It is a technology cutting across old ones.

The offence creates an interesting problem of “false evidence without falsehood”

Imagine an entirely synthetic intimate image that is visibly labelled:

AI-generated.

Could creation still amount to the offence?

The relevant statutory offence is centred upon consent to creation rather than requiring proof that the creator intended the public to believe the image authentic.

That illustrates why this law differs from misinformation regulation.

The wrong is not necessarily deception.

It is the non-consensual sexual representation itself.

That is jurisprudentially significant.

A person may say:

“I never claimed she really did this.”

The law can answer:

“That does not necessarily answer why you were entitled to create the intimate representation of her at all.”

This marks a movement from privacy to personality

Privacy law traditionally asks:

What true information about me may you reveal?

Deepfake law asks:

What false representation of me may you manufacture?

Those are different rights.

The first protects secrecy.

The second protects identity.

The law is therefore moving towards something resembling a right of control over certain deeply personal uses of one’s likeness.

Common-law jurisdictions have historically been cautious about broad personality rights.

AI may force them to reconsider.

Celebrities are not the only people who need image rights

Historically, disputes about commercial control of likeness often concerned famous people.

Actors.

Athletes.

Musicians.

Models.

Influencers.

Deepfakes democratise the problem.

Everyone with a photograph online now possesses an identity capable of synthetic manipulation.

The ordinary employee may need protection previously associated with celebrities.

The teenager.

The teacher.

The lawyer.

The doctor.

The former partner.

The stranger on Instagram.

AI converts every visible face into raw material.

Law has to respond to that fact.

There is a moral difference between imagining and rendering

Criminal law does not police private thoughts.

A person may imagine another person sexually.

The State cannot and should not enter the mind.

Generative AI introduces a technological boundary.

The fantasy is externalised.

Rendered.

Stored.

Potentially reproducible infinitely.

Capable of being copied.

Capable of being searched.

Capable of being hacked.

Capable of circulation.

Capable of becoming evidence in blackmail.

The transition from thought to file therefore matters.

The law is not criminalising imagination.

It is regulating what happens when imagination becomes a digital artefact built out of somebody else’s identity.

The permanence of the file changes the ethical analysis

A thought disappears.

A digital image may not.

This is a crucial distinction.

Once an intimate deepfake exists, control becomes uncertain.

The creator’s device may synchronise automatically.

A cloud platform may retain copies.

Someone else may gain access.

A hacked account may expose it.

A relationship may deteriorate years later.

An employee may discover it.

The creator may later decide to publish it.

The victim therefore acquires an enduring risk merely because the file exists.

The criminalisation of creation reflects that reality.

Yet proportionality should remain central

Not every boundary case deserves prosecution.

Prosecutorial discretion matters.

Evidence matters.

Context matters.

Reasonable excuse matters.

Public interest matters.

The criminal law is at its best when it combines clear statutory rules with proportionate enforcement.

A serious intimate deepfake intended for sexual gratification, harassment or humiliation sits far from the difficult margins.

An inadvertent technical output may sit differently.

Lawyers should resist both extremes:

trivialising genuine abuse;

and treating every unexpected AI image as equivalent criminality.

Precision is a form of justice.

What should individuals in England and Wales understand?

The practical rule is strikingly simple.

Do not intentionally create synthetic intimate imagery of an identifiable adult without their consent or a reasonable basis for believing they consent.

Do not commission somebody else to do it.

Do not assume that keeping it private eliminates criminal risk.

Do not assume the conduct is lawful because the image is obviously AI-generated.

Do not assume “joke”, “meme” or “satire” automatically supplies a defence.

And do not assume that asking someone else to create the image avoids liability merely because you did not operate the software yourself.

What should organisations understand?

Employers, schools, universities, AI developers, social-media companies, content platforms and professional organisations should update their understanding of intimate-image abuse.

They should consider:

whether policies expressly cover synthetic imagery;

how allegations will be investigated;

how digital evidence will be preserved;

how victims will be protected from re-exposure;

when law enforcement should be engaged;

whether internal AI tools could produce prohibited content;

whether company devices are being used;

whether platform reporting routes are adequate;

and whether technical safeguards can reduce foreseeable abuse.

This should not be left entirely to an “AI ethics committee”.

Some of the relevant conduct is criminal law.

What should Pakistani lawmakers examine?

Pakistan should review section 21 PECA specifically against generative AI rather than commencing yet another broad exercise in regulating online speech.

The important questions are narrow and practical:

Does existing “superimposition” language adequately capture fully synthetic generative imagery?

Should private creation of an intimate deepfake constitute an offence before transmission?

Should commissioning or requesting creation be separately criminalised?

Should dedicated nudification tools attract specific liability?

What reasonable-excuse protections are necessary?

What expedited removal mechanism should victims possess?

How should forensic evidence be preserved?

How should cross-border platforms respond?

Should courts have explicit deletion powers?

How should victim confidentiality be protected?

These are answerable questions.

They do not require censorship of the internet.

Pakistan should also resist moralistic terminology

Victims of intimate-image abuse do not need law to judge their sexuality.

The law should focus on consent and misuse.

A person who voluntarily created or shared a genuine intimate image should not be treated as having somehow forfeited legal protection.

Nor should a victim be blamed because an ordinary photograph was publicly available before it was manipulated.

The moral responsibility belongs with the person who misused the identity or image.

This distinction is especially important in conservative social environments, where victims may already fear stigma.

A legal regime which protects “modesty” but shames the victim can defeat its own purpose.

Dignity requires a more careful approach.

The better legal concept is autonomy

“Modesty” is culturally contingent.

“Consent” is more legally precise.

The British legislation’s strongest conceptual feature is its focus upon whether the depicted person consented to creation.

Pakistan can learn from that without abandoning its own constitutional or cultural vocabulary.

The issue is not whether the State approves of the victim’s sexuality.

The issue is whether another person was entitled to manufacture a sexualised representation of them.

That is an autonomy question.

Frequently Asked Questions

Did the United Kingdom criminalise all deepfakes in February 2026?

No. The new offences are specifically concerned with purported intimate images of adults created or requested without consent or reasonable belief in consent. The core section 138 offences apply to England and Wales.

When did the offences come into force?

Section 138 of the Data (Use and Access) Act 2025 came into force on 6 February 2026.

Where are the offences actually found?

Section 138 inserted new sections 66E, 66F, 66G and 66H into the Sexual Offences Act 2003.

Is it illegal merely to create the deepfake without posting it?

Potentially, yes. Section 66E criminalises intentional creation itself where the other statutory elements are satisfied. Publication is not an element of that offence.

Can asking somebody else to make the image be an offence?

Yes. Section 66F separately criminalises intentionally requesting creation of a purported intimate image where the person depicted does not consent and the requester does not reasonably believe they consent.

What if the requested image is never created?

That does not necessarily prevent the requesting offence. The statutory framework expressly provides that the offence can be committed regardless of whether the image ultimately comes into existence.

What if somebody says it was satire?

Sections 66E and 66F contain reasonable-excuse defences, but the explanatory materials indicate that simply characterising a non-consensual synthetic sexual image as satire is extremely unlikely, by itself, to establish reasonable excuse in the kind of scenario considered by the Government.

Does an intimate image have to show complete nudity?

No. The statutory concept of an intimate state is broader and can encompass sexual acts and specified exposure, including certain circumstances involving underwear or transparent clothing.

What is the maximum penalty?

The offences are summary offences carrying imprisonment up to the applicable maximum term, which the relevant statutory framework identifies as 51 weeks for offences committed after the applicable commencement point, or a fine, or both.

Can prosecutions be brought after the ordinary six-month period for a summary offence?

The legislation provides an extended framework. CPS guidance states that proceedings under sections 66E and 66F may be commenced within three years of the offence, while also requiring action within six months of sufficient prosecutorial evidence coming to light.

Are “nudify” applications now illegal?

England and Wales introduced a separate offence in 2026 concerning making, adapting, supplying or offering to supply purported intimate-image generators. CPS guidance confirms that this provision came into force on 29 June 2026 and specifically identifies so-called nudification tools as the type of technology it addresses.

Does this legislation apply to children?

Sections 66E and 66F address purported intimate images appearing to depict adults. Separate criminal legislation already applies to indecent and pseudo-photographic imagery of children, including certain computer-generated material.

Does Pakistan already criminalise sexual deepfakes?

Pakistan’s section 21 PECA already addresses, amongst other things, intentionally and publicly exhibiting, displaying or transmitting information superimposing a natural person’s face over sexually explicit imagery. The statutory provision has been reproduced and applied by the Sindh High Court.

What is the principal difference between the Pakistani and new English approach?

A major difference is timing. Pakistan’s section 21 is framed around public exhibition, display or transmission of the specified information, whereas England and Wales now criminalise creation itself and separately criminalise requesting creation in the circumstances specified.

Should Pakistan simply copy the British law?

No. Pakistan should examine the British model comparatively and close identifiable generative-AI gaps while preserving clear definitions, proportionality, reasonable defences and safeguards against misuse of criminal law.

The larger legal development: the victim no longer has to prove that the picture was ever true

There is a profound shift occurring underneath these statutes.

Older privacy law protected reality.

Someone genuinely took the photograph.

Someone genuinely disclosed it.

Someone genuinely invaded the private moment.

Deepfake law protects something different.

It protects a person against fabricated reality.

The victim’s complaint is not:

“You showed people something private that really happened.”

It may instead be:

“You used my identity to manufacture something intimate that never happened at all.”

The distinction is enormous.

AI has created evidence without events

For centuries, pictures derived their power from an assumed causal relationship.

  • The event happened.
  • Light reached the camera.
  • The camera recorded the event.
  • Digital manipulation weakened that relationship.
  • Generative AI can destroy it entirely.
  • The image may now exist without any originating event.
  • There was no scene.
  • No camera.
  • No body.
  • No physical occurrence corresponding with the representation.
  • Yet the human brain still responds to a convincing photograph as though some evidential relationship exists.
  • That mismatch is the source of extraordinary power.

Law is beginning to say that fabricated intimacy is still intimacy abuse

That is the important normative move.

The objection:

“But she was never really naked”

ceases to answer the legal problem.

Precisely.

She was not.

That is why another person had no entitlement to create an image pretending otherwise.

Synthetic falsity does not erase the violation.

It constitutes it.

We may eventually recognise a broader right of digital bodily integrity

The concept is still emerging, but intimate-deepfake legislation points towards it.

People increasingly possess a digital body.

  • Photographs.
  • Voice samples.
  • Video.
  • Biometric characteristics.
  • Movement.
  • Facial geometry.
  • Online identity.

Artificial intelligence can detach these characteristics from the physical person and reassemble them elsewhere.

Law may therefore need to protect not merely bodily integrity in the physical world but digital bodily integrity—the right not to have one’s recognisable identity technologically reconstructed into certain intimate, degrading or fraudulent representations without consent.

That concept will travel far beyond sexual deepfakes.

The photograph may be fake; the violation is not

That is ultimately the clearest answer to those who regard intimate deepfakes as harmless because “nothing really happened”.

Something did happen.

A person took somebody else’s identity.

They used technology to manufacture an intimate representation.

They created an artefact capable of being copied forever.

The victim never consented.

The fact that the depicted sexual event did not occur does not make the act of manufacture imaginary.

The file is real.

The appropriation is real.

The risk is real.

The humiliation can be real.

The coercion can be real.

The reputational consequences can be real.

And, in England and Wales from 6 February 2026, the criminal offence can be real too.

The law has crossed an important line

Once, criminal law largely intervened when an intimate image was disclosed.

Now it can intervene when the image is manufactured.

When it is requested.

When specialised technology is supplied to create it.

And through online-safety legislation, when digital platforms encounter systemic risks associated with illegal content.

That trajectory tells us something important about where technology regulation is going.

The law is moving closer to the point at which foreseeable harm is engineered.

Sometimes that point is publication.

Sometimes it is product design.

Sometimes it is the prompt.

Pakistan should pay particular attention

Pakistan already possesses statutory language which anticipated manipulated sexual imagery surprisingly early.

But generative AI changes the scale and nature of the conduct.

The next Pakistani reform should not simply add the fashionable word “AI” to PECA.

It should ask the harder questions.

At what moment should criminal responsibility arise?

What precisely is the protected interest?

How should consent operate?

What constitutes a sufficiently intimate synthetic representation?

When should software suppliers become responsible?

How do we protect legitimate art and research?

How quickly can harmful content be removed?

How do we preserve evidence?

And how do we ensure that a law protecting women and men against sexualised digital abuse does not itself become a vague mechanism for policing lawful expression?

Those are questions worthy of careful legislation.

Perhaps the strangest crime of the AI age is a crime built around something that never happened

That sounds paradoxical only until one understands the nature of the harm.

No intimate encounter happened.

No real photograph was taken.

No truthful evidence existed.

The accused manufactured the appearance of all three.

Law has finally begun separating the reality of the depicted event from the reality of the violation involved in creating the depiction.

That distinction will become increasingly important as synthetic media improves.

Soon the phrase:

“It’s fake”

  • may cease to function as an answer to legal liability.
  • Sometimes the fact that it was deliberately fabricated is precisely the point.
  • And that is why the 2026 reform matters far beyond England and Wales.
  • It represents an important step towards a legal principle which other jurisdictions—including Pakistan—will increasingly have to confront:

your identity should not become somebody else’s raw material for manufactured sexual reality simply because an algorithm makes the manufacture easy.

About the Author

Barrister Aemen Zulfikar Maluka is the founder of Josh and Mak International, an Islamabad-based law practice advising Pakistani, overseas and international clients on cross-border commercial, regulatory, technology, public-law and emerging digital issues.

Her international legal commentary focuses upon developments which reveal where law is moving before those questions become routine client problems. Artificial intelligence makes that comparative perspective increasingly important: conduct originating in Pakistan may involve a victim in Britain, an AI service in the United States, servers elsewhere and a platform operating simultaneously across dozens of jurisdictions.

Barrister Aemen’s approach to emerging technology law combines conventional legal analysis with the practical questions businesses and individuals actually face: where liability begins, how evidence should be preserved, what contractual and compliance measures are necessary, how international regulation may affect Pakistani clients, and which foreign developments may foreshadow changes Pakistan itself should consider.

For further insights, cross-border technology advice, cybercrime and digital-evidence analysis, international regulatory advice or legal assistance concerning matters connected with Pakistan, contact Barrister Aemen at Aemen@joshandmak.com.

Josh and Mak International
www.joshandmakinternational.com

This article is general legal and regulatory commentary and does not constitute legal advice concerning any particular allegation, individual, AI system, criminal investigation or jurisdiction. Criminal liability depends upon the legislation in force at the relevant time and the specific facts and evidence of the matter.

Filed Under :  UK deepfake law 2026, intimate deepfake law UK, non consensual intimate image UK, AI nude deepfake law, section 138 Data Use and Access Act 2025, section 66E Sexual Offences Act 2003, section 66F Sexual Offences Act 2003, purported intimate image offence, creating deepfake criminal offence UK, requesting deepfake criminal offence UK, AI intimate image crime England Wales, deepfake sexual offence 2026, nudification app law UK, nudify app criminal law, Crime and Policing Act 2026 nudification, section 66I Sexual Offences Act, AI image generator criminal liability, deepfake consent law, synthetic intimate images law, revenge porn deepfake, intimate image abuse UK, AI revenge porn law, sexual deepfake criminal offence, synthetic pornography law, fake nude image law, AI generated nude legal consequences, deepfake image consent, AI sexual harassment law, workplace deepfake harassment, employee deepfake legal liability, school deepfake law UK, university deepfake offence, AI deepfake evidence, deepfake criminal investigation, AI prompt criminal evidence, synthetic evidence law, digital forensics deepfake, deepfake deletion order, intimate image deletion order UK, Online Safety Act intimate images, deepfake platform liability UK, AI platform criminal law, online safety priority offence deepfake, artificial intelligence sexual offences, digital bodily integrity law, personality rights AI, digital likeness law, AI identity misuse, AI image rights, deepfake defamation law, deepfake privacy law, intimate image abuse Pakistan, deepfake law Pakistan, PECA section 21, section 21 Prevention Electronic Crimes Act, Pakistan cybercrime sexual images, superimposed photograph PECA, fake nude images Pakistan law, AI generated intimate images Pakistan, deepfake blackmail Pakistan, cyber harassment Pakistan, cyberstalking Pakistan, PECA modesty offence, Pakistan AI law deepfakes, AI nudification Pakistan, synthetic media Pakistan law, deepfake evidence Pakistan courts, digital evidence Pakistan, family law deepfake evidence Pakistan, matrimonial deepfake Pakistan, AI criminal law Pakistan, artificial intelligence lawyer Pakistan, cybercrime lawyer Islamabad, technology lawyer Pakistan, international AI legal advisory Pakistan, cross border cybercrime lawyer, international technology regulation Pakistan, online sexual abuse law Pakistan, image based abuse Pakistan, consent and AI images law, AI platform compliance Pakistan, generative AI legal advice Pakistan.

 

By The Josh and Mak Team

Josh and Mak International is a distinguished law firm with a rich legacy that sets us apart in the legal profession. With years of experience and expertise, we have earned a reputation as a trusted and reputable name in the field. Our firm is built on the pillars of professionalism, integrity, and an unwavering commitment to providing excellent legal services. We have a profound understanding of the law and its complexities, enabling us to deliver tailored legal solutions to meet the unique needs of each client. As a virtual law firm, we offer affordable, high-quality legal advice delivered with the same dedication and work ethic as traditional firms. Choose Josh and Mak International as your legal partner and gain an unfair strategic advantage over your competitors.

error: Content is Copyright protected !!
Josh and Mak International
Privacy Overview

Dear website visitor,

We use third-party cookies on our law firm website to enhance your browsing experience and provide you with relevant content and services. Third-party cookies are created by domains other than our website and are used for various purposes, such as tracking website analytics and serving targeted ads. The third-party cookies we use on our website are provided by Google Analytics, a web analytics service provided by Google, Inc. Google Analytics uses cookies to analyze how visitors use our website and provide us with reports on website activity. The information generated by these cookies is transmitted to and stored by Google on servers in the United States. We also use third-party cookies to serve targeted advertisements to website visitors. These cookies are provided by advertising networks and allow us to deliver advertisements that are relevant to your interests. By using our website, you consent to our use of third-party cookies as described in this policy. If you do not wish to accept cookies from our website, you can disable or delete them through your browser settings. However, please note that disabling or deleting cookies may affect your browsing experience and prevent you from accessing certain features of our website. If you have any questions or concerns about our use of cookies, please contact us using the contact details provided on our website. Thank you for visiting our website.

Best regards,

The Josh and Mak Team