Decoy tools AI Forensics planted on the platform drew more than 1,000 prompts in a week, 73 percent of them sexual — and most appeared to target ordinary people rather than public figures.
The researchers tested nine of the most popular image-editing Spaces on Hugging Face — the interfaces that let anyone run the platform's hosted models directly — and in seven cases an AI-generated picture of a clothed woman came back topless.
The models behind those Spaces were the top-ranked entries in Hugging Face's own Image Editing category on June 25, 2026, as ordered by the site's default ranker. The AI-generated test image was chosen to minimize harm.
Hugging Face runs an AI platform built around open source, with a store of models and datasets. Getting the topless outputs from tools sitting at the top of its rankings took no ingenuity at all: no adversarial technique, no attempt to work around a safety measure, only a six-word prompt asking for the same pose and the same face, but topless.
The capability was matched by demand. The team built honey-pot image-editing Spaces of its own on the platform, constructed so that they would never actually hand back an image, and over a week logged upwards of 1,000 prompts and pictures. Of those prompts, 73 percent were sexual. Of the sexual ones, 83 percent sought to undress or otherwise sexualize the person in the submitted photo, and 95 percent of that group targeted women.
The audit concludes that most of the tested Spaces could produce nonconsensual intimate images and that users were putting them to precisely those uses. The roughly 1,000 logged prompts appeared to concern mostly ordinary people rather than public figures, and included abusive requests of many kinds that went beyond digital undressing. Some 6.7 percent of the sexual prompts were aimed at people who looked like children; had they been fulfilled, the results would amount to child sexual abuse material.
Hugging Face's own rules prohibit intimate images made without the agreement of the person shown, and the audit turned up barely any protections keeping the platform's tools from that very use: just 3 percent of the Spaces examined gave any sign that their outputs were being moderated. Paul Bouchaud, a lead researcher at AI Forensics, told Wired that protections are not applied anywhere at platform level; only a developer can add them, and the majority choose not to.
Hosting is only part of the audit's charge. It concludes that Hugging Face also lets users measure these tools against one another, run performance tests on them and tune them, which makes sexual abuse through images easier to carry out at scale. The company could screen both what goes into a system and what comes back out without much difficulty, Bouchaud added.
None of the models put through testing billed itself as an undressing service or as an instrument for nonconsensual imagery; most were marketed as all-purpose picture editors. Many mainstream generative systems, OpenAI's and Google's among them, run guardrails meant to block undress-style outputs, while the models examined seemed to have no such protections.
Wired's own review of material posted on the site, combined with what other research teams had turned up, identified a number of pages advertising undressing technology or models that could produce sexualized pictures of celebrities and politicians named outright. Hugging Face gave no answer to a long list of questions put to it about how it moderates content and how it handles safety. Some pages promoting nudifying services came down after the company was contacted, though whether the removals were related to that contact is unclear. Benjamin Shultz, who heads research at the American Sunlight Project, says dozens of models identifying real individuals by name are still up, letting anyone else generate pictures of those people.
Action against this category of tool is already under way elsewhere. Several deepfake-hosting websites have been seized by US law enforcement over the past few months, and Brussels and London have each prepared proposals that would outlaw nudify apps before this year is out.
Not the first such report
- 404 Media reported last year that roughly 5,000 AI image models capable of depicting real people were hosted on Hugging Face, and that models of that kind had already been used to make nonconsensual images.
- Transformer reported last month that more than a dozen tools on the platform could produce sexual deepfakes of well-known political figures.
Cover image: “Homepage of HUGGING FACE Website magnified on logo with magnifying glass (53146954891)” by Jernej Furman from Slovenia, Wikimedia Commons, CC BY 2.0, cropped, resized, re-encoded.