180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-167
Social media · United States · 2025 · Impersonation of real people through user created personas

Reuters found chatbots on Meta's apps using real celebrities' names and likenesses without permission, and its own testing produced intimate images including one of a teenage actor

By Ellie Harris · Filed Reported 29 August 2025 after several weeks of testing

Alleged: Meta Platforms developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Reuters found chatbots on Meta's apps using real celebrities' names and likenesses without permission, and its own testing produced intimate images including one of a teenage actor

What happened

It was reported in August 2025 that dozens of chatbots on Facebook, Instagram and WhatsApp used the names and likenesses of real celebrities without their permission. Most had been built by users through Meta’s chatbot tool, but a product leader inside Meta’s own generative AI division had made at least three of them.

It was reported that over several weeks of testing the avatars insisted they were the real person, made sexual advances, and when asked for intimate pictures produced photorealistic images. One chatbot named after an actor who was sixteen at the time produced a shirtless image of him on request. Meta said its policies prohibit that imagery and that its tools should not have produced it, and deleted about a dozen of the bots shortly before publication.

What an auditable version would have shown

The existence of these personas was established by a reporter opening the products and talking to them for several weeks. No figure for how many personas carried a real person’s name, how many were tested against the impersonation rule, or how many were refused was identified in the sources reviewed.

Each persona could carry a record showing the name and likeness it claimed, the identity check that ran and the result. The same could be recorded when an image was requested. Put those records together and the operator could see how many prohibited personas were caught before publication, and how many were only found after a reporter asked.

Where the gap was

It was reported that direct impersonation was already prohibited by Meta’s rules, and that personas carrying real people’s names and likenesses were nonetheless publicly reachable across three apps. A PersonaGuard is designed to test a persona against the identity rules the operator has declared, when it is created and again when it replies, and to record whether a persona built on a real person’s name was refused before it became publicly reachable. A ConstraintGate runs the prohibition on intimate imagery as a check before an image is returned, including where the person named is a minor. A ConductRecord preserves the persona, the request, the check and the output. None of these decides what a platform should allow users to create. What they change is that a rule written in the policy becomes something the operator can demonstrate it applied.

What governance should have looked like

Meta’s stated position is that its policies prohibit this imagery and that its tools should not have produced it. The reporting reviewed here records that the personas were publicly reachable until an outside reporter tested them, and that the removals happened around publication.

Where an organisation lets users create personas that others can reach, best practice would be to test a prohibition on impersonating real people before a persona becomes reachable rather than after it is reported, to run a separate check on image requests naming a real person, and to record what was checked so the organisation can state how much of its enforcement is its own.

Failure Pattern: personas carrying the names and likenesses of real people were publicly reachable on the operator’s own apps, some built by its own staff, and the behaviour was established by a reporter testing the shipped product over several weeks rather than by any check the operator ran before publication.

Governance Principle: an organisation that lets users create personas should be able to test a new persona against its own prohibitions on impersonation and on intimate imagery before it becomes reachable, and to show what it checked.

The reference implementation of PersonaGuard, ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Meta Platforms could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed August 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →