Nearly three-quarters of user-submitted prompts collected during a one-week test on Hugging Face were sexual in nature. That single statistic, buried in a study by European non-profit AI Forensics, tells you more about the platform’s moderation failures than any policy document ever could. According to Engadget, the research found that Hugging Face is actively hosting tools capable of generating non-consensual intimate imagery, with almost nothing in place to stop them.
The study targeted Hugging Face’s Spaces feature, the cloud environment where developers host and test AI models. AI Forensics tested the nine most popular models in the image editing category as of June 25, 2026, using an AI-generated image of a woman and a prompt asking for a topless version. Seven out of nine models complied. That’s not a fringe problem. That’s the mainstream of what the platform is offering in that category.
To measure real-world demand, the researchers deployed their own decoy image-editing model in Spaces and logged incoming prompts for one week without generating any outputs. They collected 1,081 submissions. Of those, 73 percent were sexual in nature, 83 percent were requests to undress the person in the uploaded photo, 95 percent targeted women, and 6.7 percent targeted what appeared to be a minor. The decoy model wasn’t labeled for adult content. Users found it anyway.
The platform has policies against non-consensual sexual imagery. AI Forensics found that only 3 percent of audited Spaces had any output moderation whatsoever. A policy that exists on paper but isn’t enforced at the infrastructure level is essentially no policy at all.
This matters beyond Hugging Face specifically. The platform is the dominant open-source AI hosting environment, used by researchers, startups, and independent developers globally. When something is hosted there, it becomes easy to find, benchmark, and build on top of. That’s the point of the platform. But that same openness creates a distribution problem for harmful tools that competitors like GitHub or Replicate also struggle with, though neither has quite the same concentration of model-sharing activity.
The timing is also significant. The EU is actively moving to ban nudification applications, and the UK has taken steps in the same direction. Regulators looking for evidence that self-regulation isn’t working now have a study with specific numbers attached to it. That changes the political conversation.
The key findings from the AI Forensics audit include:
- 7 of the 9 top image-editing Spaces generated non-consensual nude imagery when prompted
- 73% of prompts collected by the decoy model were sexual in nature
- 83% of sexual requests were specifically to undress the subject of an uploaded photo
- 95% of targeted subjects were women
- 6.7% of sexual requests appeared to target a minor
- Only 3% of audited Spaces had any output moderation
Hugging Face has not yet publicly responded to the study’s findings. But the pressure is building. This is the kind of documented, quantified evidence that regulators act on, and the platform will need more than a policy update to address it.




