"Given the relentless advancement in artificial intelligence models, we have some concerns about the lines these cases draw, but we are not free to redraw them ourselves."
That sentence sits on page 3 of the opinion a federal appeals court in Chicago issued on August 25, 2026, and it speaks for all three judges on the panel (Lee, Pryor and Kolar). I think it is the most honest sentence in the case — a court admitting it has doubts about where the law leads, and following it there anyway.
If the headlines left you thinking an American court had just legalized AI-generated child abuse imagery, you can be forgiven — it did not. Steven Anderegg of Wisconsin is charged over sexual images of children that, the government says, he made with an AI image generator. The ruling covers one of his four charges, possessing the images at home; the charges for producing, distributing and sending them to a minor under 16 are still pending.
Some ground rules, since there is no comfortable way into this subject: the images are described no further than the law requires, everything about the defendant is an allegation (he has not been tried), and nothing here argues the material is harmless. So why did the government lose?
Because every justification it offered for treating these images like real abuse imagery, the court found, the Supreme Court had already heard and rejected in 2002. One argument that is new since then (that the models producing these images can be trained on real abuse imagery) the government did not make on appeal. Two of the three judges flagged it themselves, then wrote that the record was too thin to weigh it.
One charge, one house, and a rule from 1969
Two concessions shaped the case. The government concedes the images "do not depict an actual child, nor can they be linked to an actual child," and at oral argument it conceded that for the possession count it planned to rely "solely on the fact that Anderegg possessed the obscene material in his home."
Three Supreme Court precedents govern that situation. In 1969, Stanley v. Georgia barred punishing private possession of obscene material at home; the Seventh Circuit quoted its line about a man's living room, that a State "has no business telling a man, sitting alone in his own house, what books he may read or what films he may watch." In 1990, Osborne v. Ohio made an exception for images of real children. In 2002, Ashcroft v. Free Speech Coalition refused to stretch that exception to images made without any child: "The Government may not suppress lawful speech as the means to suppress unlawful speech." Congress answered in 2003 with a law that does not require a real child, 18 U.S.C. § 1466A, whose charged provision covers obscene images.
Put those together — obscene material is protected at home, the real-child exception cannot apply when there is no real child, and the 2002 Court refused to extend it to images made without one. Stanley's holding, the panel wrote, "was predicated on the location—the home." It protects a place, not a kind of picture.
Why the government lost: it argued 2002 again
The court's answer: "the justifications it offers here for proscribing the possession of obscene virtual CSAM were all expressly discussed and rejected by the Supreme Court in Free Speech Coalition." (CSAM is child sexual abuse material; "virtual" means no real child was used.)
First, grooming: the court granted that "it is well-known that abusers utilize obscene images to groom their minor victims," but "the Supreme Court flatly rejected the same argument the government advances here." Rather than offering more support, the government "merely restates the same arguments it made in Free Speech Coalition."
Second, the market: the claim that fakes feed demand for real abuse imagery, which the 2002 Court called "somewhat implausible" for a reason worth remembering: "Few pornographers would risk prosecution by abusing real children if fictional, computerized images would suffice." Third, the difficulty of telling real from fake, which the court found "still identical to the one the Supreme Court rejected in Free Speech Coalition." (Two other arguments, about how far Stanley reaches, lost on the panel's reading of that case instead.)
What was left standing? The trial judge had already declined to extend Stanley to making the images, and the other charges wait in a case on hold during the appeal. Images made from a real child's photograph are a different matter: such "morphed" images "implicate the interests of real children," the Supreme Court has said, and when an image shows a real, identifiable person, other laws apply, as HAIA covered in August.
So far, so good — but two of the judges were not finished.
The argument the government left on the table
Judge Lee then wrote again, joined only by Judge Kolar: "we would benefit from additional guidance from the Supreme Court regarding the intersection between the First Amendment and virtual CSAM if an appropriate case should arise." They recalled Justice Thomas's 2002 warning that if technology made real abuse imagery impossible to prosecute, the government "may well have a compelling interest" in regulating "some narrow category" of lawful speech. "According to some experts," the two judges wrote, "that day may have arrived." Then the passage this piece is named for:
"What is more, AI-generated CSAM may also present other challenges not raised by the government in this appeal. For example, researchers have found that “a major dataset used for training image-generating AI contained hundreds of CSAM images.”"
Why does that matter? The 2002 Court assumed fakes would replace the real thing. The concurrence asks what happens if the fakes are built on the real thing: the market for AI-made images "may impact the demand for actual CSAM on which the AI models can train," and "Such a finding would implicate many of the concerns raised in Osborne" (the precedent that lets the government follow abuse imagery into the home). The government did not make that argument on appeal — its opening brief led with grooming. And the judges were candid: "In this case, the record is insufficient to evaluate these complex issues, and, of course, we are bound by the dictates of Free Speech Coalition."
Where does "hundreds" come from? The judges quoted a 2026 Michigan Law Review article by Benjamin Sobel, which cites a December 2023 Stanford Internet Observatory report. Stanford announced "hundreds of known images" in an open training dataset. That dataset, LAION-5B, is a list of links, and its maintainers say they removed 2,236 of them and re-released it in August 2024. (Nothing in the opinion says what the software in this case was trained on.)
Would the new argument have won? Not obviously
Before blaming the government, weigh the case against that theory. The Stanford report itself cautions that the tainted entries may not drastically change what a model produces beyond what it can already do by combining concepts learned separately, though "it likely does still exert influence." Thorn, the child-safety nonprofit behind an industry pledge to keep abuse material out of training data, warns that some models can "combine concepts" to produce such images anyway. Sobel himself calls liability that hinges on tainted training data "both over- and underinclusive." His reasons: it would taint every image such a model makes, however innocuous, and miss realistic fakes that owe nothing to real abuse.
The 1969 question is not settled either. Before Chicago ruled, a federal judge in Idaho upheld the statute "as applied to Yeasley’s private, in-home possession," because the image had allegedly reached him over the internet, and a federal judge in Ohio called the Wisconsin trial court's holding "unpersuasive." Neither binds anyone else, but the disagreement is real.
So only the Supreme Court can settle this, and the clock is running. The Justice Department asked for more time so the Solicitor General could decide whether to seek rehearing — and the court set October 8, 2026, as the deadline for any rehearing petition. If none is filed by then, a Supreme Court petition is due within 90 days of the judgment: November 23, 2026, absent an extension.
Britain wrote a crime for the tool
What about the software that makes the images? The Chicago court was never asked.
Britain started from a different place. There, the images were already a crime and the models were the gap: the British government's May 2026 factsheet says AI-made abuse imagery is "illegal to make, possess and distribute in the UK," while "these fine-tuned models are not currently illegal." British law already covers images "made by computer-graphics or otherwise howsoever" that look like photographs, and its possession offense, as I read the text, has no exception for the home.
So Parliament went after the tool. Section 72 of the Crime and Policing Act 2026 adds offenses to the Sexual Offences Act 2003 for anyone who makes or adapts "a thing for use for creating, or facilitating the creation of, CSA images," or who possesses or supplies one; a thing includes "a program, information in electronic form and a service." The maximum is five years, and companies can be liable. The factsheet says the offense "will not criminalise AI developers" but targets offenders who "optimise AI models specifically to enhance their ability to create child sexual abuse material," for example by "training the models on vast quantities of abuse imagery, or the likeness of a specific child." That is the link the Chicago concurrence could not evaluate on its record.
One caution: the new offense is not in force. The Act received Royal Assent on April 29, 2026, but section 72 starts only on a day a minister appoints by regulations; when checked on September 24, 2026, the official record still marked it "prospective," none of the three commencement regulations made by then (the latest on September 2) included it, and the Home Office says the rest will be "commenced by regulations in due course." Passed in April — not yet switched on.
Back home, the line runs through the front door. In 2024 a federal appeals court in Atlanta said the First Amendment protects private possession of obscene images of virtual minors "in one’s own home," not "outside the home." The defendant, whom the court called "a homeless fugitive," had been convicted by a jury — a shelter built around a house did nothing for a man without one. In January 2026, a Miami federal judge declined to extend that protection to a phone found on a defendant at a diner. That order binds no one beyond its case, predates the Chicago ruling by seven months, and distinguished the Wisconsin trial decision on its facts. (The case is pending, and the government's own trial list includes "dozens of cartoons or other drawings.")
Texas took a third route: since September 1, 2025, it has been a felony to use an image of an actual child with the intent to train an AI model to produce child pornography (Texas also bans possessing obscene AI-made abuse images). So the appeals courts in this story draw the line at the front door, Britain at the tool, Texas at the training data. Two of those lines sit where real children can enter the pipeline; the constitutional one is drawn around a room.
Picture the next case, and the one after it
Now picture the next few years. (This is my extrapolation; none of these cases exists yet.)
The next prosecution arrives with the record the two judges said was missing: an expert who has traced a model's training data back to real abuse imagery. It cites Osborne, the concurrence and Justice Thomas's "compelling interest," and it might win. The win may be smaller than it looks, though, once the defense reads out the Stanford caveat about combining concepts and notes that LAION urged labs still using the old dataset to "migrate to Re-LAION-5B datasets as soon as possible." A theory tied to one training set lasts only as long as that training set.
Or picture the fight over where home ends. A phone at a diner is outside, said Miami; a file at home is inside, said Chicago. What about a file in a cloud account that syncs to both? No ruling in this story touches that question; treat it as my guess, not anyone's forecast.
And picture London on the day a minister switches on section 72: the first British prosecution for possessing a model adapted to produce abuse imagery, while American courts are still arguing about the pictures the same kind of model makes. Two democracies, one technology, two different questions. I suspect the British one will prove easier to answer, and the American one harder to dodge.
Where civil libertarians, conservatives and child-safety groups land
Start with what very different voices agree on: the ruling is narrow. Enough Abuse, a child-protection group, says so bluntly: "The headlines were alarming, but the AI-CSAM ruling is considerably narrower than they suggest—and it does not make AI-CSAM broadly legal." Focus on the Family's Daily Citizen, from the social-conservative side, calls it "undeniably unnerving — but it’s also fairly narrow."
Where they split is 2002, and the split does not sort neatly by party. FIRE, which backed the result in a friend-of-the-court brief, calls prosecuting protected expression because it is "close enough" to banned material "a dangerous road to start down." Hans von Spakovsky of the conservative Advancing American Freedom agrees the court "had no choice" but thinks "Technology may have overtaken and overwhelmed the reasoning used in those prior decisions." Pensacola police chief Eric Winstrom thinks the courts got it wrong and wants "clear instructions" from the Supreme Court. AEI's Clay Calvert argued in 2024 that AI companies carry "an ethical and legal responsibility" to purge abuse material from their training sets.
The National Center for Missing & Exploited Children (NCMEC) says fakes slow the search for real victims: "Even the images that do not depict a real child put a strain on law enforcement resources and impede identification of real child victims." Riana Pfefferkorn of Stanford's Institute for Human-Centered AI argued after the trial ruling that "the government has enough tools," and she doubts the home shelter covers much: "If all you can do is privately possess something, well, how do you come into possession of it?"
The states have not waited: as of September 2026, Enough Abuse's state-law tracker counts 47 that criminalize AI-generated or computer-edited abuse material. In Congress, the ENFORCE Act from Senators John Cornyn, Richard Blumenthal, Mike Lee and John Kennedy passed the Senate unanimously in December 2025 and still sits at the House desk; as I read its text, it tightens enforcement and leaves the home question alone (no statute could overrule a constitutional holding anyway).
What does this mean for you?
If you come across this material, report it instead of forwarding it. NCMEC's CyberTipline takes reports of suspected child sexual abuse material, AI-made included.
If a fake sexual image of your child appears online, Enough Abuse's advice is to "preserve the evidence without redistributing the image, report it to the NCMEC CyberTipline, use NCMEC’s free Take It Down tool where applicable, and contact law enforcement." (I would note the link, the account and the time rather than download a copy.) NCMEC's Take It Down covers images "taken of you when you were under 18," and it is not the TAKE IT DOWN Act.
In the UK, report it to the Internet Watch Foundation, anonymously if you prefer.
Talk to older children before anything happens about sexual deepfakes and sextortion, and set family accounts to private, as Enough Abuse also advises.
Correct the headline when you hear it. Enough Abuse notes that the Seventh Circuit "directly binds federal courts only in Illinois, Indiana, and Wisconsin" (all three are among the 47 states on the group's tracker) and that the ruling "does not automatically invalidate state laws." Nor does it reach making or sharing the images, carrying them outside the home, or images of real children.
Follow the dockets. The rehearing deadline was set for October 8, 2026; absent a rehearing petition or an extension, the Supreme Court deadline is November 23, 2026. The case's public docket and the Supreme Court's docket search showed neither kind of petition when checked on September 24, 2026.
The lesson, as I see it
The court told us plainly that it had concerns and no power to act on them, and I prefer judges who say so. The government lost because it brought 2002's arguments to a 2026 problem, and the Supreme Court had answered the market argument with a bet that fakes would drive out the real thing. Whether that bet holds when the fakes come from models trained on scraped data is the question worth asking. Two judges asked it. The government, on appeal, did not.
My vote? Build the record before the next appeal, not during it: experts, a specific model, and an answer to the Stanford caveat. Even Pfefferkorn, who thinks prosecutors already have enough tools, has written (as Sobel quotes her) that "it is likely constitutional to criminalize ML-generated images of child sex abuse where the ML model was trained on actual abuse imagery." And put the stronger lever where Britain and Texas have: on the tool built for abuse and the real child's image fed into training. I suspect an American version of Britain's offense would face its own First Amendment fight — but a fight about where real children can be harmed, not about a room.
The Solicitor General's first deadline was set for October 8. Whatever the government decides, I hope the next prosecution comes with evidence.
The HAIA Foundation works for AI policy that protects real people and holds up in court. Subscribe on Substack to follow this case wherever it goes next.





