← Back to feed
7

EU AI Act Adds Prohibition on AI-Generated NCII and CSAM Under New Regulation 2026/1744

Policy1 source·Aug 25

Summary

  • • EU Regulation 2026/1744 amends the AI Act to add two new top-tier prohibited practices: AI-generated non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM).
  • • The NCII prohibition requires that depictions be realistic and the subject identifiable; consent must be explicit, specific, and informed — prior consent to an original image does not extend to AI-generated versions.
  • • General-purpose image/video generators, API providers, and white-label AI solutions may fall within scope — not just specialist deepfake or 'nudify' applications.
  • • A liability carve-out under Article 5(1a) protects providers whose systems cannot reasonably foresee or reproduce harmful outputs and that have adequate technical safeguards in place.
Adjust signal

Details

Policy

EU Regulation 2026/1744 adds NCII and CSAM bans to AI Act Article 5

Amends Regulation (EU) 2024/1689 (the AI Act) by adding two new prohibited AI practice categories under Article 5(1): generating/manipulating NCII (point ba) and generating/manipulating CSAM (point bb).

Legal

NCII prohibition requires realistic depiction, identifiable subject, and explicit consent

Images or videos must be realistic and the person must be identifiable. Consent must be freely given, specific, informed, unambiguous, and explicit. Prior consent to an original image does not automatically extend to AI-generated intimate content derived from it.

Legal

CSAM prohibition expressly covers wholly or partially AI-generated material

References Directive 2011/93/EU definitions. The ban explicitly includes AI-generated CSAM. An exception applies where conduct is justified under national law, such as for certain law enforcement activities.

Industry Update

General-purpose AI image/video providers and API operators potentially in scope

The regulation extends beyond specialist nudify or deepfake apps to cover general-purpose image/video generators, platform operators, and companies providing AI functions via APIs, white-label solutions, or own products — depending on system design and foreseeable use.

Policy

Article 5(1a) carve-out: liability requires foreseeability AND inadequate safeguards

Placing an AI system on the market is not prohibited merely because a determined user could misuse it. Prohibition requires that harmful generation is an intended purpose or a reasonably foreseeable and reproducible outcome, AND that the system lacks reasonable technical measures to prevent it.

Insight

Safety-by-design and misuse prevention become primary compliance obligations for providers

Providers must assess whether harmful content generation is possible without significant technical modification and whether foreseeable misuse should have been anticipated. This merges risk-based and design-based compliance frameworks, making proactive safety architecture legally mandatory.

Analysis from Taylor Wessing law firm briefing, published August 25, 2026.

What This Means

The EU is closing a significant regulatory gap: AI-generated NCII and CSAM were previously addressed piecemeal under member-state laws, but this amendment elevates them to the AI Act's top-tier prohibition framework with uniform EU-wide force. The carve-out in Article 5(1a) is critical for the industry — it means well-designed general-purpose models with proper safeguards won't be banned outright, but it places enormous pressure on providers to demonstrate that harmful outputs are genuinely not foreseeable or producible through normal use. For providers of image generation APIs, white-label tools, and general-purpose AI platforms, this creates new 'safety by design' compliance obligations that go well beyond content moderation into core architecture and training decisions.

Sources

Similar Events