You probably assume the image tool on your phone will refuse to undress a stranger's photo. On paper, you are right. xAI's own rules forbid undressing or nudifying real persons. OpenAI's usage policies bar "non-consensual intimate content". Google's policy prohibits anything that facilitates non-consensual intimate imagery. Three companies, three rulebooks, one promise.
But a rulebook is a promise, and the law asks a different question. Under a Minnesota law in effect since August 1, whoever owns or controls the tool must not let a user nudify an image with it, or face a civil penalty of up to $500,000 for each unlawful access, download or use. Under a criminal offense in force in England and Wales since June 29, a company that is charged can defend itself by proving it took all reasonable steps to stop its tool being used to make nonconsensual intimate images.
xAI, the company behind Grok, has sued Minnesota, and its complaint says there is "no safe harbor for good-faith efforts." So I read the statute from its first definition to its effective date, looking for one. It isn't there: no knowledge requirement, no mention of consent, nothing for a company that tried and failed.
The lawsuit is about more than that absence (the bigger fight, as you'll see, is over what counts as nudity), but the absence is where two legislatures, aiming at the same kind of tool in the same spring, parted ways.
A ban addressed to whoever owns the tool
Why does this law look so different from the deepfake laws you may have heard about? Because it points at a different person. Those laws, as the Associated Press put it, "typically penalize the people who use the tools to make these images, not the makers of the tools themselves." Minnesota went straight to the makers.
The operative subdivision is headed, simply, "Nudification prohibited." Whoever "owns or controls a website, application, software, program, or other service must not" let a user use it "to nudify an image or video," meaning alter or generate an image of an identifiable person to show "an intimate part not depicted in an original unaltered image," realistically enough that "a reasonable person would believe that the intimate part belongs to the identifiable individual." (Identifiable "by the person depicted in the image" counts, so a picture of yourself can too.)
Then comes the choice the lawsuit turns on. "Intimate part" is borrowed from Minnesota's criminal sexual-conduct code, where the definition "includes the primary genital area, groin, inner thigh, buttocks, or breast of a human being." (A human being, it says, without saying whose.) As introduced in February 2025, the bill had used a narrower definition from Minnesota's deepfake-dissemination law and a penalty floor of "not less than $500,000." The enacted version made the floor a ceiling, added a skill exemption and required both parts of the nudify test (the introduced bill accepted either), but it took the broader definition. The legislature had the narrower one in hand and chose the other.
That exemption covers tools that require "the technical skill of a user." (Think Photoshop, not a one-tap app.) The attorney general enforces the ban, and anyone depicted can also sue the company for up to three times their actual damages.
It passed the House 132–1 and the Senate 65–0, and the governor signed it on May 7, 2026. The lone no came from the right: Rep. Drew Roach, a Farmington Republican, objected that it would "attack a software, a manufacturer" instead of the perpetrators.
What the judge decided, and what he left for later
xAI filed X.AI LLC v. Ellison against Minnesota's attorney general on July 27, five days before the law took effect. On September 4, Judge Donovan W. Frank refused to pause the law while the case proceeds. So why did he refuse?
Delay, and harm. "If xAI genuinely feared irreparable harm, the Court does not doubt it would have acted more quickly to file this action and move for injunctive relief," he wrote, and the feature was already restricted for Minnesota users anyway: "by xAI's own account, the adjustment has already been made." The motion, he concluded, "is properly denied for these reasons alone." Weighing the equities regardless, he found they tip "steeply in favor of the State."
What he did not decide is whether the law is constitutional. Those issues "are complex," he wrote, and "deserve, and will receive, full consideration." To be clear, then: no court has upheld Minnesota's law. This one declined to freeze it.
xAI appealed the same day. At the Eighth Circuit, as No. 26-2806, it asked on September 11 for an injunction "barring the Attorney General from enforcing" the law against it while the appeal runs, and Minnesota opposed on September 21. On October 2, the court granted the motion in one sentence, with no reasons: "Appellant's motion for injunction pending appeal is granted." (The order names the appellant SpaceXAI, the name xAI took on August 6.)
Reuters reported that the order "put the law on hold for now," and Minnesota's attorney general's office said it was disappointed and would defend the law as the appeal moves forward. Read the motion, though, and the hold is narrower than that: what xAI asked for, and got, is protection for itself from the attorney general, not a pause for everyone. Nor is the order a verdict on the Constitution. A motion like this turns, xAI's motion says, on four factors, the first "whether plaintiff is likely to succeed on the merits," so the grant is a signal; but the court gave no reasons, and no court has yet decided whether the law is constitutional. The district case is on hold in the meantime (a November hearing on the State's motion to dismiss was struck from the calendar on September 1), and the constitutional question waits behind the appeal.
The swimsuit problem
When xAI took California's training-data law to court, I wrote: "Now take xAI's side, because it is stronger than the headlines suggest." That holds here, too.
The complaint calls HF 1606 "an overbroad, content-based ban on free speech and the tools of visual expression," and the core of that charge is the definition. Because "intimate part" reaches the inner thigh and any human being's breast, xAI argues, the law "bans ordinary depictions of men without shirts, people in shorts or swimsuits, and other body parts routinely displayed in public." Liability, it adds, is "keyed solely to whether a user succeeded," so a service whose users made a hundred thousand covered images "could owe an eye-popping $50 billion dollars." (That figure is xAI's own hypothetical, at the ceiling.)
Yet xAI "does not contest Minnesota's interest in prohibiting the dissemination of artificially generated" nude images of real people without their consent. Its quarrel is with reach and liability, not with the idea that such images do harm.
The Justice Department sided with xAI's reading: "whereas HF 1606 would apply to an artificially generated image of a shirtless man in a swimming pool, federal law does not," though it said the United States shares Minnesota's "compelling interest" and, as Gizmodo noted, did not explicitly ask the judge to grant xAI's request for an injunction.
Then comes the most candid moment in the case. Minnesota does not deny the reach; its lawyers defend it:
"There are different dignitary interests at stake when a competitive swimmer presents themselves to the world in a speedo than when an identifiable individual is photographed in full clothing but nevertheless is depicted, by virtue of nudification technology, wearing a speedo. The Nudification Ban only reaches the latter."
So on the core example, both sides agree on what the law covers. They disagree about whether the dignity of someone photographed fully clothed justifies reaching an AI-made image of them in swimwear, a genuine constitutional question no court has answered.
Why aim at the tool at all?
Because, its supporters say, laws aimed at the people who share these images left the burden on victims. Molly Kelley, one of about 80 Minnesota women a single man had nudified, told MPR News what that burden looked like: "The burden is on us to show dissemination of these images, and you know, that's hard to do, and sometimes we just don't have it."
Minnesota's brief turns that into a theory. The law, it argues, "regulates conduct—whether a technical tool can have a certain feature and whether technical tools with such features can be provided for access, download, or use by others." Chasing dissemination instead "is like trying to stop a room from flooding by setting out buckets rather than simply staunching the leak at its source."
Then there was January. Ofcom, the UK's communications regulator, first made contact with X on January 5, after what The Register called "widespread reports" that Grok "was being used to digitally undress images and generate sexualized depictions of real people – mainly women but also children." X limited image generation to paying subscribers on January 9, and on January 14 said it had barred Grok, for all users, from editing images of real people into revealing clothing. By January 26, Indonesia and Malaysia had temporarily blocked the chatbot, California's attorney general had opened an investigation into xAI, and both Ofcom and the European Commission had opened their own into X. Three continents, one month.
January was not only an xAI story, though: according to Wired, as NPR reported, Google's Nano Banana Pro and OpenAI's updated ChatGPT Images "can also edit images to put people in bikinis." And the court noted that HF 1606 "applies to all companies providing its users with AI-tools that allow for nudification." January helps explain why Minnesota acted when it did; it does not tell you whether the law is constitutional.
England and Wales wrote the missing sentence first
"It is a defence for a person charged with an offence under this section to prove that they took all reasonable steps to prevent the thing being used for creating, or facilitating the creation of, purported intimate images of a person without the person's consent."
That is the clause Minnesota's statute lacks. It is section 66I(4) of the Sexual Offences Act 2003, added by section 99 of the Crime and Policing Act 2026, and it applies in England and Wales only. (Scotland's government has proposed its own, narrower version, aimed at tools "designed solely or principally to generate intimate images and videos.")
The offense is making, adapting, supplying or offering to supply anything, from a program to a service, "for use as a generator of purported intimate images," and whether someone has done so is judged objectively: "if a reasonable person (having regard to all the circumstances) would consider that they do so." The government told peers it would catch generators "irrespective of whether they are used to generate consensual or non-consensual intimate images," so consent enters only through the defense. And it is harsher in kind than Minnesota's law, carrying up to three years in prison on indictment. The middle path lies in the structure, not in leniency.
It also got there first. The Home Office's guidance to police dates Royal Assent to April 29, 2026, the day Minnesota's Senate passed the country's first ban on "nudification" apps 65–0, and the offense took effect on June 29, more than a month before Minnesota's. Baroness Levitt, the justice minister who introduced it in the House of Lords, called the ban "the first of its kind in the world"; against Minnesota, at least, the calendar agrees. A tool made or supplied for nudification is caught, she said, "irrespective of whether that is a primary purpose."
A defense of that kind is roughly what xAI asked Minnesota for. At an August 19 hearing its lawyer, Robert Dunn, told the court "The Legislature has a very easy fix here," which, in Courthouse News's summary, meant narrowing the law to consent and distribution and adding a "safe harbor" for platforms acting in good faith. England and Wales set a higher bar than good faith: all reasonable steps, with the burden on the company to prove them.
So is England and Wales's version the answer? Not yet. It is three months old and, as far as I can find, untested in court, with no official word on what "all reasonable steps" means for an AI model. Critics at home call it too narrow: in the same debate, the Conservative peer Baroness Bertin said, "I believe this legislation would also not have caught Grok," and the Liberal Democrat Lord Clement-Jones called the amendments "clearly too narrow." Even Ofcom has said the UK's online-safety law left it "currently unable to investigate the creation of illegal images by the standalone Grok service in this case."
Fifty rulebooks for one app
Where does this go? Start with what already exists. Complying in Minnesota, as the judge summarized an xAI declaration, meant having to "design, test, and deploy geographically targeted controls within Grok Imagine's image-editing pipeline." The same request can now get a different answer depending on which side of a state line you type it.
Now imagine a few years out. Suppose a dozen states copy Minnesota's text and a dozen more write in a reasonable-steps defense. Every general-purpose image tool would become a jurisdiction engine that must work out where you are, and which definition applies there, before it can answer what you asked. Whether a forged image of you is actionable already depends on your address; in that world, whether a tool will make one would too. The Justice Department, quoting a presidential executive order, wants one "national standard" rather than "50 discordant state ones."
The tools this fight is really about may slip through both laws. Researchers have documented open-source face-swapping models and nearly 200 nudifying programs that let non-technical users make such images within minutes, and many may have no one who "owns or controls" anything a Minnesota court can reach. Baroness Bertin warned that the government's clause "will not capture software made overseas." My guess (only a guess) is that both laws will bind the careful, visible companies hardest, which was, in its way, Rep. Roach's objection too.
Who lines up where (it isn't who you'd guess)
The usual teams scramble here. The ACLU of Minnesota and RAINN both wrote in support of the bill; the ACLU affiliate called it "a delicate approach to the issue of Nudification technology using civil penalties and by targeting the website or software owner," while conceding, "It's also easy to see the First Amendment implications of laws restricting or banning AI images."
Against it stand the Trump Justice Department and a set of free-speech lawyers and writers. FIRE and two other groups, in a proposed amicus brief, say the missing intent requirement means strict liability, "the antithesis of narrow tailoring." The law professor Josh Blackman argues at the Volokh Conspiracy that "The lack of a scienter requirement renders the content-based ban unconstitutional." Mike Masnick of Techdirt, a critic of Musk, calls the law "ridiculously overbroad and pretty clearly unconstitutional", then adds, "This is not a defense of those apps."
The most serious case for aiming at tools comes from the Oxford law professor Ignacio Cofone, writing in February, before Minnesota's law passed. Regulators, he argues, should "govern capabilities at the model level, not outputs at the content level," and "dual-use is a poor defense when the harmful use case is foreseeable, can be mitigated by proportionate controls, and the harms are severe." Those two words, "proportionate controls," point toward a reasonable-steps defense more than toward Minnesota's text.
What does this mean for you?
If a fake intimate image of you turns up online, StopNCII will hash a deepfake or synthetic image of you so participating platforms can block matches, and the image itself never leaves your device. It works only with those platforms, and only if you have a copy.
If the person pictured is under 18, use NCMEC's free Take It Down service instead; its page speaks of images "taken of you when you were under 18 years old" and does not mention AI-made ones.
If a platform ignores your request, covered platforms must now remove nonconsensual intimate images within 48 hours of your request, and the FTC takes reports on those that don't. As I wrote about that law, "Since May 19 the burden of getting an image down sits on the platform, not the person in it."
If you live in Minnesota, the person depicted can sue under the new law for violations on or after August 1, 2026, and the attorney general's office, which enforces it, "welcomes complaints from constituents" too. Since October 2, though, a court order bars that office from enforcing the law against xAI while the appeal runs. The order says nothing about private suits.
If you build or sell an image tool, know both standards: under Minnesota's text a strong rulebook is not a defense, while in England and Wales a company charged would have to prove it took "all reasonable steps." Document your safeguards as if you will one day have to.
If you want to follow the case, the Eighth Circuit docket is public, and xAI's opening brief is due October 29.
The lesson, as I see it
Take away the plaintiff and the politics, and this case asks a question every AI law will eventually face: when a tool is misused, who has to prove what?
Minnesota's text makes the company liable when the user succeeds, whatever it did to stop it. xAI's lawyer asked for a good-faith safe harbor. England and Wales wrote something in between and backed it with prison: prove you took all reasonable steps.
I think that is the better design, and not because it is gentler (it isn't). It asks companies for evidence instead of promises, and it puts the burden where the knowledge is. It would not settle the swimsuit problem, and its own critics may yet be proved right that it is too narrow.
My vote? Keep the target on the toolmaker, narrow the definition, and write in the defense.
If the courts ultimately rule against Minnesota, its Senate author, Erin Maye Quade, has said she plans to bring a new ban to the legislature next session. If she does, the sentence worth borrowing has been in force since June 29, in England and Wales.
Know someone who builds image tools, uses them, or writes the rules for them? Send this their way. The argument over what a company should have to prove is only starting, and it goes better when more people have read the fine print.





