TLDRocket
Sign in

Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds

404 Media Samantha Cole

A new study says big web providers are helping run deepfake abuse sites. The ugly part: the sites rely on ordinary internet tools, not hidden corners of the web.

Based on reporting by 404 Media, Samantha Cole — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

A new study says the deepfake abuse economy is being propped up by the same companies that run a lot of the internet’s plumbing. The researchers looked at non-consensual, AI-generated intimate imagery sites and found they were using services from Cloudflare, Google, Namecheap, WordPress and Proton.

The paper, published Wednesday in Stanford’s Journal of Online Trust and Safety, was led by Dartmouth’s Hany Farid, Lancaster University’s Sophie Nightingale, and Sarah Morgan. Over six weeks in February and March, they found 400 URLs through keyword searches and Google Alerts, then cut that down to 88 sites that were actively hosting non-consensual intimate imagery. Most of the material featured female celebrities, actresses, pop singers, K-pop idols, and women in politics or activism.

The part that should make everyone squirm is how ordinary all of this looks. Cloudflare was the biggest provider in the study, supplying hosting, content delivery, DNS and analytics. Google showed up for SSL certificates and ads, Namecheap for domain registration, WordPress for content management, and Proton for mail servers. These companies say their terms forbid illegal or harmful content, but the researchers argue the sites are still getting the infrastructure they need to stay online.

Google said it could not investigate without the specific domains, and said it has policies against non-consensual explicit content, including AI-generated imagery. WordPress pushed back harder, saying WordPress.org is open-source software, not a host. Farid countered that WordPress.com is a hosting service, and said Automattic also serves images through its CDN and maintains an ongoing relationship with self-hosted sites through updates, plugins and security patches.

The study also found that 312 of the 400 sites first identified were not deepfake sites at all, but unrelated pages using non-consensual imagery keywords to climb search results. That detail matters. It suggests the abuse business is tangled up with plain old search manipulation, and that cutting off the infrastructure layer may be harder for the platforms to ignore than chasing each bad actor one by one.

My take — AI-written commentary, not fact-checked reporting

This is the part of the AI story that actually matters: not model demos, but the boring companies that keep terrible sites alive. The industry loves talking about safety while cashing the checks from the pipes underneath. If a provider can cut off a neo-Nazi site or a piracy hub, pretending it’s helpless here is just corporate incense.

Read more about this at: 404 Media

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.