110 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 27 July 2026
← The incident library
HD-INC-101
Technology · United States · 2024 · Non-consensual deepfake imagery

Sexually explicit AI deepfakes of Taylor Swift spread on X, and the platform could not stop them before millions had seen them

By Ellie Harris · Filed Images spread late January 2024

Alleged: X (formerly Twitter) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Sexually explicit AI deepfakes of Taylor Swift spread on X, and the platform could not stop them before millions had seen them

What happened

It was reported that in late January 2024, sexually explicit AI-generated images of the musician Taylor Swift spread rapidly across X, formerly Twitter, after surfacing on other sites including 4chan. According to reporting, one post carrying the images was viewed more than 47 million times before it was taken down, and the material circulated for hours before X acted. On 27 January 2024, X took the unusual step of blocking searches for Swift’s name entirely, returning an error message to anyone who tried, and restored the search about two days later. Swift’s fans mobilised under a #ProtectTaylorSwift hashtag, flooding the platform with genuine images and reporting the accounts sharing the fakes.

The images were synthetic and non-consensual, and Swift had no involvement in their creation. The episode drew comment from the White House and renewed pressure for a legal response, and lawmakers and advocates widely cited it as adding momentum to the TAKE IT DOWN Act, which the United States Congress passed in April 2025 and which President Trump signed into law on 19 May 2025 (Public Law 119-12). The Act makes it a federal crime to publish non-consensual intimate images, including AI-generated “digital forgeries”, and requires covered platforms to remove such material within 48 hours of a valid request, a duty that took effect in May 2026.

What an auditable version would have shown

The harm here was not only that the images were made, but that a platform carried them to tens of millions of people before it could act, so an auditable version treats synthetic intimate imagery as something a platform must be able to detect, block and later account for. A record, per item, of when the content was posted, when it was flagged, what the system did and how long it stayed up, turns “we acted as fast as we could” from an assertion into something a regulator or a victim can actually check. Provenance markings on AI-generated media would let the platform, and the people resharing it, see that an image was synthetic before it travelled, rather than after it had been seen millions of times.

Where the gap was

An image that should never have been distributed was carried to a mass audience, and the platform could neither stop it quickly nor show, afterward, how its response had actually gone. A ConstraintGate encodes the rule that non-consensual intimate imagery, including synthetic forgeries, must be blocked rather than allowed to spread, and checks content against that rule as it is posted, not after it has been seen millions of times. A ConductRecord keeps the account of each item, when it appeared, when it was reported, what action was taken and when, so the speed and adequacy of the response is a matter of record rather than a claim. The technology to generate the images is now cheap and widely available, so what was missing was a control that stopped their distribution and a record that could prove how the platform had responded.

What governance should have looked like

When a platform can reach millions of people in minutes, its ability to remove harmful material has to move at the same speed, and it should be able to show, from its own records, how quickly it acted and how much reach the content got before it did. The TAKE IT DOWN Act now puts a clock on that, a 48-hour removal window, which only means something if a platform can produce the record of when it was notified and when it acted. The lesson of this episode is that generation has become cheap while removal stayed slow, and the gap between the two is measured in millions of views.

Failure Pattern: synthetic, non-consensual intimate imagery was distributed at mass scale before a platform could remove it, and there was no record able to show how quickly or adequately the platform responded.

Governance Principle: a platform that can distribute content at scale should be able to detect and block non-consensual synthetic imagery as it spreads, and keep a record of what was posted, reported and removed, and when.

The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and X (formerly Twitter) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed June 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →