On the Taylor Swift deepfake

In this article

  1. The Swift case, a short timeline
  2. What was happening in parallel that almost nobody covered
  3. The key difference, the capacity to respond
  4. The legal response, in progress
  5. The question the Swift case diverted
  6. The political question
  7. To go deeper
  8. You might also like

Definitions · References · Elsewhere

Today we talk about the case that best shows how media attention selectively shields people with resources and leaves unprotected those who have none. In January 2024, a series of fake pornographic images of Taylor Swift generated with artificial intelligence circulated massively on X for seventeen hours before the platform reacted. The outrage was global, laws were passed, the platforms announced fixes. Why does this case matter for understanding a wider problem? Because while all the attention was fixed on the celebrity, in at least two dozen schools across Spain, the United States and Europe, pornographic deepfakes of minors aged between eleven and fourteen were circulating, produced by their own classmates with free apps. Nobody wrote viral articles about them. My take is biased, because the Almendralejo case hit me as a father. Form your own with care.

I've been reading every newly reported case of non-consensual deepfakes of minors since September 2023, when Almendralejo broke. The trajectory is predictable, and it's worth looking at soberly, because the pattern is structural, not anecdotal.

The Swift case, a short timeline

The fake pornographic images of Taylor Swift were generated, according to investigations by 404 Media and NBC News, on a 4chan forum, built from public images of the singer combined with commercially available image generators, including, according to the technical analyses, Microsoft Designer in the version of that moment. Whoever made them spread them through Telegram, from where they reached X (the former Twitter) between 24 and 25 January 2024.

On X the images circulated for roughly 17 hours before the platform took them down and blocked the search «Taylor Swift» as a temporary measure. One of the main images racked up, according to X's own public figures, around 47 million impressions before being removed. The pressure of the fan base —the #ProtectTaylorSwift movement— and the immediate coverage in the Los Angeles Times, Variety, Rolling Stone and The Wall Street Journal sped up the reaction.

In the following days, X announced policy changes, Microsoft announced adjustments to the models behind its Designer generator to reinforce the filters meant to block the generation of pornographic content of real people, the White House issued a statement from the then press secretary Karine Jean-Pierre calling the incident «alarming», and Democratic senator Mazie Hirono, along with other members of Congress, revived legislative proposals that had been stalled for months.

That sequence produced, within three weeks, more institutional response on deepfakes than all the media coverage of the previous two years combined. The asymmetry tells you something.

What was happening in parallel that almost nobody covered

It's worth telling, without specific names out of respect for the victims, what was happening at the same time elsewhere.

In September 2023, in Almendralejo (Extremadura, Spain), around thirty minors aged between 11 and 17 discovered that pornographic deepfakes of themselves were circulating on WhatsApp, produced by their classmates with a free image-generation mobile app. The media coverage was locally intense, nationally moderate, internationally limited. El País, eldiario.es, El Periódico published serious pieces. The victims and their families held a press conference with the support of the psychologist Miriam Al Adib. The judicial investigation found that the perpetrators were minors, mostly boys, aged between 13 and 15.

In Westfield, New Jersey, United States, in October 2023, a group of male high school students distributed pornographic deepfakes of female classmates generated with AI apps. The case got moderate local and national coverage.

In Beverly Hills, California, in February 2024, a similar situation hit students at a school. And from there, the documented cases multiplied to the point where the Internet Watch Foundation —a British organization specializing in online child sexual abuse— reported in its 2024 annual report a 256% increase in detected pornographic deepfakes of minors compared to the previous year.

The operative question: what share of the world's media coverage of deepfakes in 2024 was about Taylor Swift, and what share was about these other cases? Without exact figures, the qualitative observation is clear. A person reads the Spanish and international press daily or weekly. They remember the Swift case in detail. Of the other cases they remember, at most, Almendralejo if they lived in Spain. Westfield, Beverly Hills and the rest exist for them as rumor, or don't exist at all.

The key difference, the capacity to respond

The asymmetry isn't only one of media coverage. It's one of operational capacity to react.

Taylor Swift has a full-time legal team. She has direct relationships with executives at the digital platforms: Elon Musk himself posted a personalized response to the case. She has the capacity for political pressure through senators and representatives she has worked with on other causes. She has an organized fan base, mobilizable on a global scale. When the incident happened, the combination of these resources produced a response in 17 hours.

The minors in Almendralejo have none of that. They have parents with limited resources, a school that supported them partially, a local psychologist who spoke up, lawyers who carried the case forward pro bono or against the family's modest means. The complaint, the investigation, the first court ruling took months. The images circulated far longer. The likelihood that the images keep surfacing in corners of the internet for years, despite the takedowns, is high.

That contrast isn't down to individual malice. It's down to structure. The protection system against non-consensual deepfakes works, today, mainly as a reactive response to visible, high-profile cases. The cases that aren't visible, especially when the victims are anonymous minors without access to legal teams, get a much slower response. The reaction speed of the platforms and of the courts is directly proportional to the media noise the case generates.

The legal frameworks have advanced significantly between 2023 and 2025, partly because of the pressure from the Swift case and partly because of the accumulation of cases like Almendralejo and Westfield.

In the United States, the TAKE IT DOWN Act (Public Law 119-12) was signed by President Trump on 19 May 2025 after bipartisan approval in Congress. The law requires digital platforms to remove non-consensual intimate synthetic images within a maximum of 48 hours from the notification of the victim or their legal representative, criminalizes the production and distribution of these images with prison sentences, and provides for civil penalties. Effective enforcement remains to be seen, but the legal framework exists.

In the European Union, Regulation (EU) 2024/1689 on Artificial Intelligence —the AI Act— requires mandatory labeling of AI-generated synthetic content and prohibits certain manipulative uses. The Digital Services Act (DSA) obliges large platforms to set up fast takedown mechanisms. And in Spain, the reform of the Criminal Code processed during 2024 and 2025 added specific offenses for the generation and distribution of non-consensual intimate images, with aggravated penalties when the victims are minors.

The problem isn't the absence of laws. It's the speed of their application. The rules require the victim to report, the report to be processed, the perpetrator to be identified, the case to follow the corresponding criminal or civil procedure. The real timelines are measured in months or years. The images, meanwhile, have already circulated. The speed of the harm outpaces the speed of justice, and the current frameworks don't fix that gap.

The question the Swift case diverted

Here comes the uncomfortable matter that the coverage of the Swift case never seriously raised. The question isn't whether the platforms will have better filters and stricter laws —they will—. The question is structural and prior.

Should there exist, as a mass consumer product, an accessible tool that lets anyone generate synthetic pornographic images indistinguishable from real ones from a single source photograph? The tools exist today: free apps that any minor with a phone can download and operate in a matter of minutes. Some are openly advertised for this use. Others allow it as a side capability. Almost all of them are undetectable by the platforms' general filters.

The very existence of the product is the question. Not the regulation of its use. Because, once the technical capability exists, assuming the problem will solve itself by regulating individual behavior and platform responses is failing to understand the nature of the problem.

The public conversation in January 2024 never reached this question. The attention went to the visible individual harm of a celebrity and to the immediate response of platforms and institutions. That mattered. But it wasn't enough. And nearly two years after Swift, the conversation still hasn't got there.

The political question

This is personal opinion, but the trajectory of the record backs it. Reactive regulation of deepfakes without addressing the accessibility of the tools that produce them is like regulating smuggling without addressing the production of the goods. It reduces something, yes, but it leaves the source untouched.

The generative AI industry has handed the market image-generation tools capable of producing hyperrealistic synthetic content without seriously weighing the foreseeable consequences for vulnerable populations. The big labs —Microsoft Designer, OpenAI DALL-E, Google Imagen, Adobe Firefly— have put in place filters that, with uneven effort, try to limit the use for producing non-consensual intimate content. But the ecosystem also includes open models (Stable Diffusion, Flux and variants) with no filters, freely distributed, on top of which apps specifically designed for this use are built. The mass accessibility is real.

What I would ask for —and with some realism, because some measures are already being discussed— is a more demanding European regulatory framework for mobile apps and online services whose main or advertised function is the generation of intimate images of real people. Three minimum requirements. First, robust verification of the identity of whoever uploads images to these services, with explicit and verifiable consent from the people depicted. Second, a ban on selling these apps in official stores (Google Play, Apple App Store) unless they comply with that verification. Third, specific criminal liability for developers who design apps with this function as their main goal. None of the three eliminates the problem; all three make it operationally harder.

Meanwhile, readers who are fathers, mothers, teachers, youth workers can do at least three things. First, talk to the minors in their care about the existence of these tools and the harm they cause, without alarmism but with clarity. Second, know the legal and psychological support resources available should the problem affect someone in their circle —in Spain, INCIBE-CERT runs a specialized help service—. Third, demand from their public representatives —members of parliament, councillors, regional officials— that specific regulation advances and doesn't stop at headlines.

The hard fact to close on. According to Sensity AI's State of Deepfakes 2023 report, a European organization specializing in deepfake monitoring, 98% of the deepfakes detected online are non-consensual pornography, and between 99% and 100% of the victims of those deepfakes are women. The figures have stayed relatively stable in the later 2024 and 2025 reports. That figure —virtually 100% of victims are women— is the structural reality the Swift case made visible by accident and that the rest of the cases confirm without proportional coverage. Treating the problem as a matter of specific gender-based digital violence, instead of as a neutral category of «image manipulation», is probably the most important reframing the public conversation needs.

Definitions

Deepfake: an image, audio or video generated or modified with artificial intelligence to depict a person doing or saying something they didn't actually do or say. The term combines «deep learning» and «fake».

Non-consensual pornographic deepfake: a deepfake of sexual content generated from a person's image without their consent. It is the majority category of deepfakes detected online.

TAKE IT DOWN Act: a US federal law passed in 2025 requiring digital platforms to remove non-consensual intimate images, including deepfakes, within a maximum of 48 hours after notification.

Gender-based digital violence: a set of violent practices aimed specifically at women and girls and made possible by digital technologies. The vast majority of non-consensual pornographic deepfakes fall into this category.

References

Sensity AI, State of Deepfakes 2023 and 2024-2025 updates (sensity.ai). Figures on the prevalence, distribution and demographic characteristics of detected deepfakes.

Internet Watch Foundation, Annual Report 2024 (iwf.org.uk, April 2025). Figures on the increase in detected deepfakes of minors.

TAKE IT DOWN Act, Public Law 119-12 (United States Congress, signed 19 May 2025). Federal framework on the mandatory removal of non-consensual intimate images.

Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act). European framework on the labeling of synthetic content and the prohibition of specific manipulations.

El País, coverage of the Almendralejo case (September 2023 - 2024). Field reporting and judicial follow-up.

404 Media and NBC News, investigations into the origin of the Taylor Swift deepfakes on 4chan and their distribution through Telegram (January 2024). Technical traceability of the case.

Danielle Keats Citron, The Fight for Privacy: Protecting Dignity, Identity, and Love in the Digital Age (W. W. Norton, 2022). Legal and conceptual framework on the violation of privacy through technology.

To go deeper

Joy Buolamwini, Unmasking AI: My Mission to Protect What Is Human in a World of Machines (Random House, 2023). Research on the biases of computer vision systems and their impact on specific populations.

Internet Watch Foundation (iwf.org.uk). British organization specializing in online child sexual abuse; it maintains annual reports and a reporting hotline.

Sensity AI (sensity.ai). European organization that monitors deepfakes and publishes periodic reports on their prevalence and characteristics.

INCIBE-CERT (incibe.es). Spain's security incident response center; it offers a specialized help line for cases of digital violence.

You might also like

Elsewhere

Comments0

No comments yet.

Leave a comment