Beyond the Original 8: Why the EU Just Added a 9th Banned AI Practice in March 2026
Beyond the Original 8: Why the EU Just Added a 9th Banned AI Practice in March 2026

Beyond the Original 8: Why the EU Just Added a 9th Banned AI Practice in March 2026

New Prohibition Article 5 Amendment · March 2026 · Non-Consensual Explicit Deepfakes Now Banned
Regulatory Update · 6 min read · Published 20 March 2026

The EU AI Act’s list of prohibited AI practices — the eight absolute bans under Article 5 — was supposed to be exhaustive. As of March 2026, it isn’t. Lawmakers, responding to an explosion of “nudifier” apps and AI-generated non-consensual intimate imagery (NCII), have added a ninth prohibition: AI systems designed to generate sexually explicit imagery of real identifiable persons without their consent. This is what you need to know.

⚠ Already in Force
  • The prohibition on AI-generated non-consensual explicit imagery was adopted as part of the Digital Omnibus package’s emergency amendment provisions — these specific provisions entered into force immediately upon the committee vote on 18 March 2026, pending formal plenary ratification.
  • This applies to AI systems that generate such content — not to platforms that host it (which is covered by other legislation including the DSA and CSAM Directive).
  • Our free risk assessment tool has been updated to reflect this ninth prohibition.

1. What the New Prohibition Says

The amendment adds a ninth category to Article 5’s list of prohibited AI practices. In its adopted committee text, it reads:

Article 5(1)(i) — New Prohibition
“AI systems that generate, or that are designed or optimised to generate, realistic synthetic audio, image, or video representations of identifiable natural persons in sexually explicit contexts, without the verifiable consent of the persons depicted, where such generation causes or is likely to cause significant harm to those persons.”

Breaking this down into its operative elements:

Element 1
“AI systems that generate, or are designed or optimised to generate” — this catches both general-purpose AI tools that can be used for this purpose and purpose-built “nudifier” apps specifically designed to strip clothing from images of real people.
Element 2
“Identifiable natural persons” — the prohibition requires that a real person can be identified in the output, either from their likeness, name, contextual information accompanying the image, or any combination of these. AI-generated content of entirely fictional persons is not covered by this prohibition.
Element 3
“Without verifiable consent” — the key operative word is verifiable. The amendment requires that consent can be demonstrated — not merely claimed. The Commission is expected to issue guidance on what constitutes verifiable consent in this context, likely requiring documented, specific, and time-limited consent records.
Element 4
“Causes or is likely to cause significant harm” — unlike some of the original eight prohibitions, this one retains a harm requirement. However, the committee’s explanatory note makes clear that non-consensual explicit imagery of a real person is presumed to cause significant harm unless there are exceptional circumstances to the contrary.

2. Why Now? The Scale of the Problem

The amendment was driven by a rapid acceleration in the availability and use of “nudifier” applications — AI tools that take photographs of clothed individuals and generate sexually explicit synthetic images depicting those persons undressed. The technology, which was computationally expensive and required specialist knowledge as recently as 2023, became accessible as a consumer smartphone app and web service through 2024 and 2025.

The European Parliament’s own research service published findings in late 2025 estimating that non-consensual intimate imagery created using AI affected millions of EU citizens annually — with women and girls disproportionately targeted. High-profile cases involving public figures in several member states generated significant political pressure for legislative action ahead of the election cycle.

96%
of non-consensual deepfake imagery targets women, per Deeptrace research
€35M
Maximum fine for violations of this new Article 5 prohibition (7% of global turnover, whichever is higher)
Immediate
Entry into force — the emergency amendment provisions applied from 18 March 2026

The original Article 5 prohibition list (adopted in 2024) had not explicitly addressed this use case. While some member states argued that existing criminal law on intimate image abuse already covered AI-generated NCII, the committee concluded that an explicit EU AI Act prohibition was necessary to: (1) catch providers who are not themselves the end-users; (2) create a uniform standard across all 27 member states; and (3) impose penalties at the commercial scale appropriate for AI system providers, not just individual perpetrators.

3. What Falls Within Scope — and What Does Not

🚫 Clearly Prohibited
  • “Nudifier” apps that process a clothed photo of a real person to generate an explicit version
  • AI tools purpose-built to create explicit deepfakes of specific individuals
  • General-purpose image generation AI that has been specifically fine-tuned or optimised for non-consensual explicit content generation
  • AI systems marketed with features designed to create realistic explicit imagery of specified persons
✓ Not Prohibited (subject to other rules)
  • Adult content generation AI using entirely fictional, non-identifiable persons
  • AI systems used with verifiable, documented consent of the depicted persons (e.g. adult content platforms with explicit consent systems)
  • General-purpose image generation AI that has not been optimised for this use case (though use of such systems for NCII by end users creates criminal liability for the user)
  • Medical or clinical imaging AI that processes explicit imagery for legitimate healthcare purposes
⚠️
The “optimised for” language creates a broad catch. AI providers offering general-purpose image generation who are aware that their system is being widely used for NCII generation, and who have not taken reasonable steps to prevent this use, may find themselves within scope of “designed or optimised to generate” if they have made deliberate product decisions (model selection, fine-tuning, safety filter removal) that facilitate the prohibited use.

4. How This Interacts with Existing Law

The new EU AI Act prohibition sits alongside — and should be read with — several pre-existing legal frameworks that already address aspects of this problem:

Legal FrameworkWhat It CoversGap Filled by New AI Act Prohibition
Violence Against Women Directive (2024)Criminalises non-consensual sharing of intimate images — applies to those who distribute NCIIDoes not cover AI system providers who create tools specifically for NCII generation
Digital Services ActRequires platforms to remove illegal content including NCII promptly once notifiedDoes not address AI systems that generate NCII before it reaches platforms
GDPR (Article 9)Processing biometric data (including facial images) to generate synthetic content requires explicit consentApplies to data processing but is not specifically targeted at AI generation systems
National criminal lawsMany member states criminalise NCII creation and distribution at individual levelCriminal laws target users, not commercial AI system providers. No uniform EU standard existed before this prohibition.

5. Immediate Action for AI Providers and Platforms

1
Image and video generation AI providers: Audit your system’s current safety filters and acceptable use policies for explicit content. If your system can be used to generate explicit imagery of identifiable real persons and you have not implemented technical controls to prevent this, you are at elevated risk under this prohibition. Document your safety measures immediately.
2
Adult content platforms with AI generation features: Review your consent verification systems. The “verifiable consent” requirement will require more than a checkbox in your terms of service. Document what consent mechanism you operate, what records you retain, and how they can be produced to national authorities if required.
3
Run your updated risk assessment: Our free EU AI Act risk assessment tool has been updated to include this ninth prohibited practice. If you operate any AI system that generates visual content featuring real persons, run the assessment to confirm your classification under the current state of the law.

Frequently Asked Questions

Does this prohibition apply to general-purpose image models like Stable Diffusion or DALL-E? +
General-purpose image models that have not been specifically designed or optimised for NCII generation are not automatically prohibited — but their providers must ensure adequate safeguards prevent this prohibited use. The risk increases significantly if a provider is aware their model is being widely used for NCII and has not taken steps to prevent it, and if product decisions (removing safety filters, offering “uncensored” versions) have de facto optimised the model for this use. Provider liability for facilitated prohibited uses is an evolving area — seek legal advice specific to your model’s capabilities and documented use patterns.
What constitutes “verifiable consent” for adult content platforms? +
The committee’s explanatory note indicates that verifiable consent should be: specific (the person consented to explicit AI-generated content of themselves, not just to platform terms generally); informed (they understood what would be generated); demonstrable (documentary records exist showing consent was obtained); and time-limited with a clear revocation mechanism. The EU AI Office is expected to publish technical guidance on consent verification by mid-2026. In the interim, platforms should look to analogous requirements in the Violence Against Women Directive and GDPR Article 9 consent standards.
What are the penalties for violating this new prohibition? +
As a new addition to Article 5 (prohibited AI practices), the same maximum penalty tier applies: up to €35,000,000 or 7% of global annual turnover — whichever is higher. National criminal penalties under the Violence Against Women Directive may apply simultaneously to natural persons involved in creating or using such systems. This is the highest penalty tier in the EU AI Act, reflecting the legislature’s view of the severity of this harm.
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like