Skip to main content
AI RegulationPolicy DecisionAug 26, 2026, 3:23 AM· 5 min read

EU AI Act Adds New Prohibitions on AI-Generated NCII and CSAM, Imposing Fines Up to €35 Million

The European Union has formally expanded the AI Act to ban systems that generate non-consensual intimate imagery and child sexual abuse material. Enacted via the Digital Omnibus package, the new rules expose AI providers to maximum-tier fines if they fail to implement effective technical safeguards.

By Sofia Matos

Legal & Compliance Analysts 40%Child Rights Advocates 30%AI Industry Observers 30%
Legal & Compliance Analysts
Focus on the strict liability, the €35 million penalty exposure, and the legal definition of reasonably foreseeable outcomes.
Child Rights Advocates
Argue that upstream bans on generation are necessary because downstream removal is insufficient to protect vulnerable populations.
AI Industry Observers
Highlight the accelerated timeline and the technical difficulty of implementing foolproof guardrails in general-purpose models.

Key points

  • The EU Digital Omnibus formally bans AI systems that generate non-consensual intimate imagery and child sexual abuse material.
  • Violations carry the AI Act's maximum penalty of up to €35 million or 7% of global annual turnover.
  • The prohibition applies to general-purpose models if generating such content is a reasonably foreseeable outcome.
  • Providers can defend against liability by demonstrating reasonable and effective technical safeguards.
  • The new rules become fully enforceable on December 2, 2026.
€35 million
Maximum fine for Article 5 violations
7%
Global turnover penalty alternative
1 in 25
Children reporting deepfake manipulation (2025 study)
Dec 2, 2026
Enforcement date for new prohibitions

The European Union has formally expanded the AI Act's Article 5 prohibitions to ban artificial intelligence systems that generate non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM). Enacted via the Digital Omnibus package, officially designated as Regulation 2026/1744, the ban carries the law's maximum penalty tier. Violations expose providers to fines of up to €35 million or 7% of their global annual turnover, whichever is higher. While the Omnibus package delayed several high-risk compliance deadlines to 2027 and 2028, it accelerated the timeline for these new prohibitions, which will become fully enforceable on December 2, 2026. The move represents the first substantive amendment to the AI Act since its initial adoption, reflecting growing regulatory alarm over the proliferation of synthetic abuse material.[1][2]

The legal text explicitly targets both purpose-built "nudifier" applications and general-purpose generative AI models. Under the expanded Article 5, a system is prohibited if the generation of NCII or CSAM is a reasonably foreseeable and reproducible outcome of its design, training, architecture, or user-facing functionalities. This represents a fundamental shift in European technology regulation, moving away from downstream content moderation and toward upstream capability restriction. Rather than merely requiring platforms to remove illegal imagery once it has been generated and shared, the AI Act now makes the capability to generate such imagery a categorical violation of market rules.[1][5]

However, the legislation does not impose a blanket ban on all generative models simply because misuse is theoretically possible. The regulation provides a critical defense for developers: a system is not prohibited if the provider has implemented reasonable, proportionate, and effective safeguards to reliably prevent the generation of prohibited material. This requires a differentiated assessment of system design, shifting the legal focus to the robustness of a model's safety guardrails. Providers must demonstrate that they have taken active technical measures to block the creation of NCII and CSAM, rather than relying solely on terms of service or acceptable use policies.[1][7]

Violations of the new Article 5 prohibitions carry the AI Act's maximum financial penalties.

The inclusion of this ban followed intense advocacy from child rights organizations and was driven by alarming data on the scale of synthetic exploitation. A 2025 joint study by UNICEF, ECPAT, and INTERPOL across eleven countries estimated that one in twenty-five children disclosed having their images manipulated into sexually explicit deepfakes. The legislative urgency was further catalyzed by high-profile incidents in late 2025, including reports that a major commercial chatbot generated approximately 23,000 CSAM images over an eleven-day period. These events provided the empirical basis for lawmakers to argue that existing frameworks were insufficient to protect vulnerable populations from generative AI capabilities.[3][4]

The inclusion of this ban followed intense advocacy from child rights organizations and was driven by alarming data on the scale of synthetic exploitation.

Prior to this amendment, the European Union relied primarily on the Digital Services Act to combat synthetic abuse material. The Digital Services Act establishes a reactive framework, requiring online platforms to diligently remove illegal content once they become aware of it. However, policy analyses highlighted a critical gap: the Digital Services Act only applies when content is shared on covered platforms, offering no mechanism to regulate the offline generation of abuse material or its distribution through encrypted channels. The AI Act prohibition complements the existing framework by targeting the point of creation, effectively closing the loophole for local generation and peer-to-peer distribution.[4]

Despite the strict legal mandate, the evidence regarding the technical feasibility of total prevention remains weak. Security researchers and policy analysts widely acknowledge that no current mitigation method or technical safeguard can entirely eliminate a generative model's capacity to produce NCII or CSAM. Compliance will require a layered, defense-in-depth approach, incorporating training data sanitization, robust refusal training, prompt-safe design, and continuous runtime guardrails. Because perfect safety is mathematically impossible in large language and image models, the regulatory standard relies on the concept of "effective safeguards" rather than absolute prevention, leaving room for technical failure rates.[4][6]

The Digital Omnibus accelerated the enforcement of generative AI prohibitions while delaying other high-risk requirements.

Significant uncertainty remains regarding how the European AI Office and national market surveillance authorities will interpret these technical thresholds in practice. The exact definition of what constitutes a "reasonably foreseeable and reproducible outcome" has not yet been tested in court, nor has it been clarified through harmonized European standards. Providers are currently operating without clear technical benchmarks for acceptable failure rates. Until the European Commission publishes formal guidelines or the first enforcement actions establish a precedent, companies deploying generative AI in the European market must self-assess whether their internal safety mechanisms meet the undefined standard of proportionality.[1][5]

The most acute area of legal and technical uncertainty surrounds open-weight models. Because downstream deployers can modify open-weight architectures to strip away safety filters and refusal mechanisms, it is not yet established how liability will flow under Article 5. If a provider releases a model with effective safeguards, but a user intentionally removes those safeguards to generate prohibited content, the extent of the original provider's exposure remains ambiguous. Regulators will soon have to decide whether the "reasonably foreseeable" standard requires open-weight developers to anticipate and technically prevent intentional, adversarial modification of their models.[4][7]

What we don’t know

  • How regulators will define the technical threshold for 'effective safeguards' in generative models.
  • Whether providers of open-weight models will face liability when downstream users intentionally strip away safety filters.
  • How the European AI Office will measure 'reasonably foreseeable and reproducible' outcomes in enforcement actions.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

Legal & Compliance Analysts 40%Child Rights Advocates 30%AI Industry Observers 30%
  1. [1]Taylor WessingLegal & Compliance Analysts

    New Prohibited AI Practices under Article 5 of the AI Act: NCII and CSAM in Focus

    Read on Taylor Wessing
  2. [2]OrrickLegal & Compliance Analysts

    EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes

    Read on Orrick
  3. [3]Child Helpline InternationalChild Rights Advocates

    The Growing Threat of AI-Generated Sexual Abuse Content

    Read on Child Helpline International
  4. [4]Tech Policy PressChild Rights Advocates

    How a ban under the AI Act could complement existing protections

    Read on Tech Policy Press
  5. [5]Echelon CyberAI Industry Observers

    Here's What Actually Changed: EU AI Act Omnibus

    Read on Echelon Cyber
  6. [6]Credo AIAI Industry Observers

    What just happened: Digital Omnibus deal on AI

    Read on Credo AI
  7. [7]RegulomeAI Industry Observers

    EU AI Act - Comprehensive Risk-Based Framework

    Read on Regulome

Comments

Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.