The EU Has Banned Nudification Apps. Here Is What Actually Changed
Buried in the Digital Omnibus, the package best known for delaying the AI Act’s high risk deadlines, sits a provision that moves in the opposite direction. It adds a new entry to Article 5, the Act’s list of prohibited practices. From 2 December 2026, AI systems built to generate non consensual intimate images of real, identifiable people are banned in the EU. So are systems generating child sexual abuse material.
The direct target is the so called nudification app: a tool that edits clothing out of a photograph to reveal intimate parts of a real person. These apps have spread fast in the last three years, they are trivially easy to use, and their victims are overwhelmingly women and, far too often, minors. Existing remedies were a patchwork of national image abuse laws and slow platform takedowns. The EU has now put the technology itself on the banned list.
Why the placement matters
Article 5 is the sharpest instrument the AI Act has. Prohibited practices carry the top penalty tier: fines up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. And while the high risk obligations moved to 2027 and 2028, this prohibition applies from December 2026. The EU delayed the paperwork and accelerated the red lines.
Who is caught
The prohibition works on two triggers. Providers are caught when generating non consensual sexual or intimate content is the intended purpose of the system they place on the market. Deployers are caught when they actually use a system for that purpose, whatever the system was built for. In plain terms: the ban covers both the purpose built undressing app and the person who bends a general image tool to the same end.
The uncomfortable question for legitimate builders
If you ship image generation or editing, the question a regulator will eventually ask is simple: what stops your product from doing this? The Omnibus names refusal training, safe prompt design, output controls and content filtering as examples of safeguards. None of them is mandatory as such. But if your model can undress a real person in three clicks and you have no controls and no paper trail, your intended purpose argument gets very thin, very fast.
My advice to image and video AI companies is short. Test whether your product can be misused this way, fix what you find, write down both, and keep the record with your technical documentation. That one afternoon of work is the difference between an incident and a liability.
The bigger picture
The EU is not acting alone. The UK has moved to criminalise creating sexually explicit deepfakes, and the US Take It Down Act now forces platforms to remove non consensual intimate imagery on tight deadlines. Whatever happens to the rest of the AI Act under future simplification rounds, this line is only getting brighter. Build accordingly.
Mike Nimród is an IT and data protection lawyer (AIGP, CIPT, CIPP) and researcher at Corvinus University of Budapest. If you build image or video AI and want a clear read on where your product stands, get in touch.