Manhattan DA Seizes 12 Deepfake Pornography Sites Hosting AI‑Generated Images of 1,200 Public Figures
What Happened — The Manhattan District Attorney’s Office seized the domains of twelve websites that offered non‑consensual intimate deepfake videos. The sites collectively hosted AI‑generated pornographic videos of more than 1,200 individuals, ranging from politicians and actors to musicians and social‑justice advocates.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for robust AI‑governance controls that require continuous monitoring of AI model usage and content‑generation pipelines.
- Highlights gaps in third‑party oversight: AI tool providers, hosting services, and cryptocurrency payment processors can become vectors for illicit content distribution.
- Provides a concrete example of why a continuous control‑assurance program must capture evidence of due‑diligence, vendor risk assessments, and audit‑ready documentation of AI‑related policies.
Who Is Affected – Media & entertainment firms, political organizations, advocacy groups, and any entity whose public‑facing images could be weaponized.
Recommended Actions –
- Inventory all AI‑enabled services and third‑party providers that could generate or host synthetic media.
- Implement AI‑governance policies that require risk assessments, usage monitoring, and incident‑response playbooks for non‑consensual deepfake creation.
- Collect and retain evidence of vendor due‑diligence and control testing to support audit readiness under frameworks such as NIST AI RMF.
Technical Notes – The deepfake content was produced using publicly available generative‑AI models; no specific software vulnerability was disclosed. Law‑enforcement action focused on domain seizure, but operators can quickly migrate to new infrastructure, underscoring the importance of ongoing vendor monitoring. Source: Malwarebytes Labs