EU AI Act Adds Prohibition on AI-Generated NCII and CSAM Under New Regulation 2026/1744
Summary
- • EU Regulation 2026/1744 amends the AI Act to add two new top-tier prohibited practices: AI-generated non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM).
- • The NCII prohibition requires that depictions be realistic and the subject identifiable; consent must be explicit, specific, and informed — prior consent to an original image does not extend to AI-generated versions.
- • General-purpose image/video generators, API providers, and white-label AI solutions may fall within scope — not just specialist deepfake or 'nudify' applications.
- • A liability carve-out under Article 5(1a) protects providers whose systems cannot reasonably foresee or reproduce harmful outputs and that have adequate technical safeguards in place.
Details
EU Regulation 2026/1744 adds NCII and CSAM bans to AI Act Article 5
Amends Regulation (EU) 2024/1689 (the AI Act) by adding two new prohibited AI practice categories under Article 5(1): generating/manipulating NCII (point ba) and generating/manipulating CSAM (point bb).
NCII prohibition requires realistic depiction, identifiable subject, and explicit consent
Images or videos must be realistic and the person must be identifiable. Consent must be freely given, specific, informed, unambiguous, and explicit. Prior consent to an original image does not automatically extend to AI-generated intimate content derived from it.
CSAM prohibition expressly covers wholly or partially AI-generated material
References Directive 2011/93/EU definitions. The ban explicitly includes AI-generated CSAM. An exception applies where conduct is justified under national law, such as for certain law enforcement activities.
General-purpose AI image/video providers and API operators potentially in scope
The regulation extends beyond specialist nudify or deepfake apps to cover general-purpose image/video generators, platform operators, and companies providing AI functions via APIs, white-label solutions, or own products — depending on system design and foreseeable use.
Article 5(1a) carve-out: liability requires foreseeability AND inadequate safeguards
Placing an AI system on the market is not prohibited merely because a determined user could misuse it. Prohibition requires that harmful generation is an intended purpose or a reasonably foreseeable and reproducible outcome, AND that the system lacks reasonable technical measures to prevent it.
Safety-by-design and misuse prevention become primary compliance obligations for providers
Providers must assess whether harmful content generation is possible without significant technical modification and whether foreseeable misuse should have been anticipated. This merges risk-based and design-based compliance frameworks, making proactive safety architecture legally mandatory.
Analysis from Taylor Wessing law firm briefing, published August 25, 2026.
What This Means
The EU is closing a significant regulatory gap: AI-generated NCII and CSAM were previously addressed piecemeal under member-state laws, but this amendment elevates them to the AI Act's top-tier prohibition framework with uniform EU-wide force. The carve-out in Article 5(1a) is critical for the industry — it means well-designed general-purpose models with proper safeguards won't be banned outright, but it places enormous pressure on providers to demonstrate that harmful outputs are genuinely not foreseeable or producible through normal use. For providers of image generation APIs, white-label tools, and general-purpose AI platforms, this creates new 'safety by design' compliance obligations that go well beyond content moderation into core architecture and training decisions.
