Deepfake cyberbullying, social media platform policies, and regulatory responses

0

1. AI-facilitated abuse and cyberbullying

Generative Artificial Intelligence (GenAI) technologies have fundamentally altered the production methods of non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM), expanding the magnitude of this threat (Ó Ciardha et al., 2025). Manipulations that previously required advanced technical skills can now be executed in seconds using simple text commands (‘prompts’). ‘Nudifying’ applications that digitally remove clothing from photographs, along with inpainting techniques that allow for the modification of specific parts of visuals, are being utilized to transform photos of real individuals into abuse materials (The Guardian, 2025).

A concrete case emerged in late 2025 with the integration of Grok’s image generation feature (marketed with ‘spicy mode’) into the social media X platform. This feature enabled X’s users to alter photos of real individuals through digital undressing (Reuters, 2026) and create synthetic nude images (‘deepnudes’), often of people engaging in sexually explicit conduct. According to the Center for Countering Digital Hate, over an 11-day period between late December 2025 and early January 2026, Grok generated approximately three million sexualised images, of which 23,000 appeared to depict children (CCDH, 2026).

The Grok case exemplifies a wider trend, in which the production of sexual abuse material is facilitated by Artificial Intelligence. Reports from child protection organizations indicate a significant increase in AI-generated CSAM in recent years; the Internet Watch Foundation identified a 26,385% increase in AI-generated child sexual abuse videos in 2025 compared to the previous year (IWF, 2026).

Next to harmful impacts on victims from the generation of the abusive material as such, there are significant other consequences. Such material is used to harass, bully, or even blackmail and extort users (UNICEF, 2025), in many cases minors. Deepfake cyberbullying in specific has emerged as a phenomenon, following the broad accessibility to the generation of deepfakes. Cyberbullying in general is the intentional and repeated use of digital technologies to cause harm to others (Patchin et al. 2015).

Deepfake bullying, as a form of cyberbullying, “operates in a far more insidious manner by leveraging fabricated videos to humiliate or discredit victims” (Alexander, 2025). Re-sharing of an AI-generated CSAM is re-victimising and re-traumatising the person portrayed in the video or image. Impacts amount to a range of psychosomatic effects. (Peprah et al, 2024).

2. Regulatory responsiveness

Following the Grok case, responses related to the abuse of the functionality of Grok were immediate. In the United States, a formal investigation has been launched against xAI in the state of California (California DOJ, 2026). In the UK, Ofcom launched an investigation for the violation of the UK’s Online Safety Act (Ofcom, 2026). The European Commission opened an investigation against X based on the Digital Services Act (European Commission, 2026). Further, the Paris Public Prosecutor’s Office supported by the Europol Cybercrime Centre conducted an investigation into the proliferation of deepfake and CSAM content on the platform and carried out investigative measures at X’s offices in France (Europol, 2026). In the Netherlands, the NGO Offlimits won summary proceedings against Grok, which was ordered to disable this functionality for its users (Offlimits, 2026). In Australia, the eSafety Commissioner inquired of Grok how they are meeting the expectations under the Australian Safety Act (eSafety, 2026).

While the reactions were fast and timely in the case of Grok, the same has not been observed in other older cases. Deepnudes and wide public access to nudification apps and functionalities have existed since 2019, even on app stores, until recent actions (Wired, 2026). The Almendralejo case in 2023 was one of the first to show how minors harass and bully their female peers relying on deepfake images (Irish Legal News, 2024).

The question that arises is what due diligence measures do online social media platforms implement and (where) do those fail?

3. Social media platform policies on cyberbullying

As examples like the Grok case illustrate, the increasing accessibility of GenAI tools tests the boundaries of platforms’ ‘online bullying’ and ‘abuse’ policies. Under the DSA, Very Large Online Platforms (VLOPs) must diligently identify, analyse, and mitigate systemic risks stemming from the design or functioning of their services (European Parliament and Council of the EU, 2022, Art 34(1)). We examined several publicly available community standards and user policies of Instagram, TikTok, and X, focusing on definitions of (cyber)bullying, reporting mechanisms, and enforcement measures.

Definitions and scope

The three platforms describe certain harmful conduct, without however explicitly defining cyberbullying, usually referring only to harassment.

Instagram does not provide a direct definition for the term ‘cyberbullying’ or ‘online bullying’ in its policies. Instead, the platform categorizes violations under ‘bullying and harassment’ detailing prohibited behaviours such as making threats, disclosing personal information, and engaging in unwanted malicious contact. Instagram applies a tiered violation definition based on the target’s status. Minors and other private individuals are more broadly protected, while public figures receive protection only against specific attacks or direct tagging (Meta, 2025a).

X defines bullying as behaviour that targets specific individuals with personal attacks and can cause harm to the targeted person (TikTok, 2025a). Such conduct is addressed under its ‘Abusive Behaviour’ policy, which is defined as “behavior and content that harasses, shames, or degrades others” (X, 2024). AI-generated violations are handled under a separate ‘Non-Consensual Nudity’ policy, which prohibits the sharing of intimate images produced or distributed without the person’s consent (X, 2021).

TikTok, under its ‘Safety and Civility’ principles, prohibits doxxing, retaliatory harassment, and sexual harassment (TikTok, 2025b). Violations, according to the platform’s policy, are assessed contextually by considering the victim’s profile, distinguishing between private persons and public figures.

Reporting mechanisms

As regards reporting and enforcement, Instagram gives priority to reports coming from institutions and organisations, most notably the School Partnerships Program in the US (Instagram, 2025a). To mitigate systemic risks, Meta introduced Teen Accounts in September 2024, meaning that accounts for users under 16 years of age default to private, and the platform states that protection settings cannot be lowered without parental consent (Instagram, 2025b).

Reporting in TikTok categorizes complaints based on the victim’s identity, such as, for example, an acquaintance of the abuser, or a public figure. states that it reports suspected youth exploitation to the National Center for Missing and Exploited Children (NCMEC) and notifies authorities regarding imminent threats to human life (TikTok, 2025c). Moreover, under the DSA, as a VLOP, TikTok introduced a reporting option for EU users to flag illegal content (TikTok, 2023). TikTok uses automated technology and algorithmic models for enforcement processes. In Q4 2025, the platform removed 96,753,730 comments. The company reports a proactive detection rate of 94.7% for harassment and bullying, stating that it removed 84.1% of these items within 24 hours and deleted 58.1% at zero views (TikTok, 2026). Alongside content removal and account bans, TikTok applies visibility restrictions as a design-based enforcement tool by excluding lower-severity violations from the algorithmic For You Feed (FYF) (TikTok, 2025c).

In X users can report violations directly through posts, profiles, or Direct Messages (X, no date). According to its policy, X defaults the accounts of users under 18 to private (‘Protected posts’) and restricts the direct messages sent by those accounts to only accounts they already follow (X, no date). Furthermore, X provides a reporting form allowing unregistered EU users to flag illegal content, and the platform states that it prioritizes notices submitted by Trusted Flaggers during human review (X, no date).

Self-enforcement of platforms’ policies

Instagram’s enforcement mechanism is strike-based. In Q4 2025, Instagram actioned 1.5 million pieces of content. Users appealed 201,100 decisions; the platform restored 19,000 items with an appeal and 1,100 items without an appeal. According to Meta, the proactive detection rate for cyberbullying stood at 73.7% in Q4 2025 (Meta, 2026). This rate decreased from 95-96% in 2024 following Meta’s January 2025 policy shift, in which Meta stated that its prior automated moderation systems had “gone too far” in over-enforcing rules and removing harmless content, and announced a “more speech, fewer mistakes” approach (Meta, 2025b). However, the system has been met with criticism as it fails to filter significantly harmful content (BBC, 2025; FairPlay study, 2025)

X’s enforcement includes read-only account restrictions, content removal, and visibility limits such as exclusion from search results and downranked replies (X, no date). The platform states that it reserves fully automated enforcement for categories where detection accuracy is highest, including child sexual exploitation, terrorism, and fake accounts; cyber harassment falls outside this group (X, 2026). Accordingly, the H2 2025 DSA Transparency Report records a 0% automated enforcement rate for cyber harassment, with all 24,644 proactive actions in this category carried out through human review (X, 2026).

Need for further legislative refinements or more effective public enforcement?

The analysis of the policies and community standards shows elusive or narrow definitions and divergence in reporting and enforcement mechanisms. Considering that abuse follows the victims across platforms, as reported by the European Institute for Gender Equality (EIGE, 2026), the divergence in platform policies and community standards is problematic. Further, reporting and enforcement are slower than the rapid creation and spreading of the NCII and CSAM, and subsequent deepfake cyberbullying. Whistleblowers attribute such phenomena to the business model and financial drives of certain online platforms (Spring et al, 2026).

The DSA provides a due diligence framework (Kamara, 2023), and as shown in the Grok case, a solid legal basis for the EU regulatory responsive actions that took place following that case. At the same time, there are risks of ‘creative compliance’ and box-ticking exercises, especially when the resources for effective enforcement are not sufficient (Zingales, 2022) and given the lack of meaningful information and transparency over the practices of those platforms (Arning, 2026).

Next to enforcement, the European legislator is indeed currently in the process of revising several legal instruments, essential for different aspects of AI. The recently adopted recast Child Sexual Abuse Directive (CSA) establishes new criminal offences regarding AI-generated abuse material (European Commission, 2026). Those were certainly necessary changes, especially after the lengthy CSA negotiations (Lenaers, 2026). However, the scope of the recast CSA Directive focuses on specific crimes related to child sexual abuse, not addressing other forms of (online) abuse and violence. Further, the Digital Omnibus on AI explicitly introduces an amendment to the AI Act, which prohibits AI systems that generate non-consensual sexual and intimate content and CSAM (European Parliament and Council of the EU, 2026, see Art. 5(1)(ba)).

The complex nature of AI-facilitated violence and, in particular, harmful behaviours such as deepfake cyberbullying with long-lasting, and not always directly visible harm (Kamara, 2025), requires multi-faceted regulatory responses and consistent public enforcement.

 

Share this article!

About Author

Irene Kamara

Associate Professor at the Tilburg Institute for Law, Technology, and Society (TILT) at Tilburg Law School in the Netherlands, where she conducts research on legal aspects of cybersecurity and cyberviolence.

Nalan Doğanci

Lawyer and research assistant at the Tilburg Institute for Law Technology and Society (TILT).

Leave A Reply