NEWS & ANALYSIS | SAFETY & HARM
Minnesota’s first-in-the-nation ban on AI “nudification” technology is now in force. The law was inspired by women whose ordinary family photographs were turned into fabricated sexual images. xAI says the ban goes too far. The court has allowed it to take effect, but the constitutional fight is only beginning.
By Andrew McDonald · Immortal AI
The Human Story
The photographs were not intimate. They were ordinary pictures taken from private Facebook pages: family moments, social occasions and familiar faces.
According to evidence presented to Minnesota lawmakers, a man known for years to Molly Kelley, Jessica Guistolise and Megan Hurley used photographs of them to create fabricated sexual images and videos. They were among about 80 women whose images were altered.
The abuse did not remain inside a computer. It followed the women into their homes, workplaces and relationships.
Minnesota House reporting records that Kelley stopped attending work in person because she did not know where the images had spread. Guistolise told her employer’s human resources team and feared having to explain the images again in future jobs. Hurley worried someone might connect the fabricated material to her workplace and use it to target her again.
The technology created something false. The consequences were real.
That distinction matters. A fabricated image does not become harmless because an event never occurred. Once an image carries a recognisable face, viewers may believe it, employers may encounter it and search engines may preserve it. The targeted person can be left proving a negative to strangers while the creator and the tool provider remain largely invisible.
A New Law Meets a New Technology
Minnesota has responded with what state officials describe as the first US law aimed directly at access to “nudification” technology.
The law defines nudification as altering or generating an image or video so that it realistically appears to show an intimate part of an identifiable person that was not present in the original. It prohibits an owner or controller of a website, application, software program or other service from allowing users to access or use that service to produce such material. It also prohibits advertising or promoting those services.
This is a significant change in legal responsibility. Many existing laws concentrate on the person who creates or distributes a fabricated intimate image. Minnesota’s law also looks upstream, towards the company that supplies the tool.
People depicted in material created in violation of the law may bring a civil action. Available remedies include compensation for mental anguish, punitive damages, injunctions and legal costs. The Minnesota attorney general may enforce the law, with civil penalties of up to US$500,000 for each violation.
The measure passed the Minnesota House 132 votes to one and the Senate 65 to zero. It was signed on 7 May and took effect on 1 August 2026.
The law does not ban every form of digital image-making. It includes an exemption where producing the result requires substantial, individualised technological or artistic skill and judgement from a person. That distinction appears intended to separate one-click or automated nudification services from conventional creative work, although courts may eventually have to decide how clear that boundary is.
Why Is xAI Challenging the Law?
xAI, the company behind Grok, filed a federal lawsuit against Minnesota Attorney General Keith Ellison on 27 July, only days before the law was due to begin.
The company says it does not dispute the state’s interest in stopping non-consensual fabricated sexual images. Its argument is that Minnesota has written the prohibition too broadly.
In its complaint, xAI argues that the law is based on the content of an image, restricts constitutionally protected expression and may cover images made with the depicted person’s consent or by the person themselves. It also objects that the statute does not expressly require a provider to know that its service has been misused and offers no safe harbour for companies making good-faith efforts to prevent abuse.
xAI says Grok’s terms prohibit illegal, harmful or abusive activity that violates privacy, including nudifying a person or placing them in a fabricated sexual image. The company says it can suspend or terminate accounts and report suspected child sexual abuse material. It also argues that determined users may evade safeguards and that a provider should not face a potentially enormous penalty for every output it failed to stop.
Those are allegations and legal arguments, not findings by a court.
xAI asked US District Judge Donovan Frank to stop the law from taking effect. On 31 July, the judge denied the request for an immediate temporary restraining order, pointing in particular to xAI’s delay in bringing the case. He did not decide whether the law is constitutional. The court will instead consider the request as a preliminary-injunction motion, with further submissions and a hearing scheduled for August.
The practical position is therefore clear but temporary: Minnesota’s law is in force; xAI’s challenge remains alive; and the most important legal questions are unresolved.
This Is Bigger Than Minnesota
The dispute exposes a wider regulatory choice.
Should responsibility begin only after a harmful image is created and shared? Or should a company that makes the creation easy be required to prevent the output in the first place?
The United States has already taken a national step through the TAKE IT DOWN Act, which requires covered platforms to provide a process for removing non-consensual intimate imagery, including certain digital forgeries. Removal mechanisms matter. They can reduce continuing exposure and give targeted people a route to action.
But removal begins after the harm exists.
Minnesota is testing a different proposition: some tools may be so closely designed around a foreseeable abusive output that the provider should be responsible at the point of creation. That approach could prevent harm earlier. It could also capture legitimate expression if definitions are imprecise or if providers respond by blocking broad categories of lawful images.
This tension is not unique to the United States. Australia already treats digitally altered or fabricated intimate material as image-based abuse in relevant circumstances. The eSafety Commissioner can assist eligible people to seek removal and advises them to preserve evidence, report the material and tighten account security. Yet the same underlying challenge remains: laws and reporting systems often respond to an image after a tool has made it effortless to produce.
When Technology Outpaces the Law
Traditional legal rules tend to divide responsibility into familiar roles: creator, publisher, distributor and victim. Generative AI complicates that model.
The user may supply the photograph and instruction. The model produces the image. The service controls the model, safety settings and access. A social platform may then distribute the result. Search engines, private groups and anonymous accounts may copy it beyond retrieval.
Each participant can point to someone else.
The user can say the machine created it. The provider can say a user misused a general-purpose tool. The platform can say it did not make the image. The targeted person is left locating copies, making reports and explaining that the image is false.
Effective law must decide where prevention is technically possible, who can bear the cost and which safeguards can operate without suppressing lawful expression. A rule aimed only at the final uploader may miss the company best placed to stop repeated generation. A rule that imposes absolute liability on a general-purpose provider may encourage excessive blocking.
That is why the Minnesota case matters. It is not simply a contest between safety and free speech. It is a test of how precisely a government can place responsibility on the systems that industrialise a particular form of abuse.
The Question Every Government Is Facing
Governments cannot assume that existing offences will automatically keep pace with tools that can create convincing abusive material in seconds.
Nor should every difficult output be answered with a sweeping ban.
The better question is narrower: when a service is capable of producing a predictable and severe form of non-consensual harm, what reasonable steps must its operator take before making that capability widely available?
That should include scrutiny of the service’s design, the specificity of the prohibited output, the quality of its safeguards, its response to known misuse, its reporting systems and whether targeted people can obtain rapid help. It should also include clear defences for legitimate artistic, medical, educational and investigative uses where consent and public interest can be established.
The law must be precise. Corporate responsibility must still be real.
What People Can Do Today
If you discover a fabricated intimate image of yourself, the first priority is not to prove to everyone that it is fake. It is to preserve evidence and obtain support.
Record where the material appeared, the account or service involved, dates, times, URLs and any messages or threats. Take screenshots where lawful, but do not save or redistribute illegal material, particularly any content involving a person under 18.
Report the content to the platform or service. Keep copies of the report and any response. Consider contacting police or a lawyer where threats, stalking, extortion, workplace harm or continued distribution are involved.
In Australia, the eSafety Commissioner accepts reports about image-based abuse that includes AI-generated deepfakes. eSafety advises that the abuse is not the targeted person’s fault and can work with services to seek removal or stop threats. Adults may also be able to use StopNCII.org to create a digital fingerprint that participating platforms can use to block re-uploading, while people under 18 can use Take It Down.
Tell someone you trust. The burden should not be carried alone, and the person targeted should not be made responsible for the conduct of the abuser or the design choices of a technology company.
Immortal AI Analysis
Minnesota’s law may prove too broad in parts. xAI may succeed in showing that some applications sweep in lawful, consensual or protected expression. The court has not yet answered that question.
But the constitutional uncertainty should not obscure the reason the law exists.
Ordinary photographs were taken from spaces people believed were private and converted into material capable of damaging health, employment, relationships and personal safety. The women affected were expected to explain, report and contain a harm they did not create.
For too long, technology policy has treated abuse as an unpredictable misuse that begins with one bad user. Sometimes it is. But when a capability is easy to access, repeatedly exploited and capable of foreseeable harm at scale, the design and distribution of the tool also deserve scrutiny.
The central question is not whether AI companies can stop every determined person. They cannot.
It is whether they should be able to release a capability, benefit from its use and place almost all responsibility on the people harmed when safeguards fail.
Minnesota has answered no. The courts will now decide whether it found a constitutional way to say it.
If You Have Been Affected
Australia: Report image-based abuse to the eSafety Commissioner at https://www.esafety.gov.au/key-topics/image-based-abuse/report-image-based-abuse
United States: Information about removal requests under the TAKE IT DOWN Act is available through participating platforms. People under 18 can use https://takeitdown.ncmec.org and adults can use https://stopncii.org where participating services are involved.
If you are in immediate danger, contact local emergency services.
Principal sources
- Minnesota House of Representatives, “Victims ask lawmakers to ban nudification technology for photos”, 19 February 2026: https://www.house.mn.gov/sessiondaily/Story/18880
- Minnesota Session Laws, Chapter 72, H.F. No. 1606: https://www.revisor.mn.gov/laws/2026/0/Session%2BLaw/Chapter/72/
- xAI LLC v. Keith Ellison, Complaint, US District Court for the District of Minnesota, filed 27 July 2026: https://kstp.com/wp-content/uploads/2026/07/gov.uscourts.mnd_.235231.1.0.pdf
- xAI LLC v. Keith Ellison, Order denying temporary restraining order, 31 July 2026: https://www.ag.state.mn.us/Office/Communications/2026/docs/03425_xAI_TRO-Order.pdf
- Associated Press, “Elon Musk’s xAI sues Minnesota over its first-in-the-nation law banning ‘nudification’ technology”, 29 July 2026: https://apnews.com/article/minnesota-artificial-intelligence-nudification-x-elon-musk-deepfake-131184be939d540de093b567b12c9e16
- Australian eSafety Commissioner, “Report image-based abuse”: https://www.esafety.gov.au/key-topics/image-based-abuse/report-image-based-abuse
This article was prepared with AI assistance for research organisation and drafting. Every material claim was checked against the cited sources, and the final framing, wording and publication decision were reviewed under the Immortal AI editorial process. The article distinguishes testimony, company claims, legal arguments and court findings. It will be updated if the court changes the law’s status or issues a substantive ruling.





