How everyday photos are being targeted by AI “Nudify” apps (and how to protect your family)
By Lucy Ramnought • Published: 01 Oct 2026 • 11:01 • 3 minutes read
One photo is all it takes Credit: Anastasiya_Rav/shutterstock
An innocent photo of your summer beach holiday eating ice cream, a selfies with pals, or a weekend family lunch snap from your uncles birthday is all a deepfake site needs to generate an explicit fake image in seconds. With ‘nudify’ web traffic now topping 40 million visits a month, security experts warn that ordinary profile photos are now prime targets. Here is how to lock down your accounts before it happens.
Why one photo is all they need
These tools are known as “nudify” services. They are websites and apps that use AI to strip the clothes from a photograph of a real person and produce a realistic but fake nude, a type of image called a deepfake.
A new investigation by the Institute for Strategic Dialogue (ISD), a research group backed by the UK’s AI Security Institute, found 181 websites selling this service, according to Spanish technology outlet EscudoDigital. Together they averaged more than 40 million unique visitors a month between December 2025 and March 2026, based on traffic estimates in the ISD report.
Social media is sending them customers. Between December and February, platforms referred more than 5.7 million visits to the ten busiest sites, with YouTube responsible for about 1.8 million and X for 1.3 million. YouTube has told Wired that its rules ban such content, including links to outside sites. Some tools charge as little as $1 per image.
Readers may be shocked by one finding. Out of the 163 sites that could be reached from the UK, only two checked that users were adults.
Josep Albors, head of research and awareness at ESET Spain, warns that a fake picture can still do real harm. He says it can become a tool for humiliation, harassment or pressure against the person shown.
Teenagers face the greatest danger
Common Sense Media, a US non-profit, surveyed 1,314 American teenagers aged 13 to 17 for research which was released in July. Some 44% had seen sexual content they believed was AI-generated, and almost a quarter of those said it showed themselves or someone they know. Nothing intimate is needed to start. A public profile picture, a family post or a shared album gives abusers enough raw material to create the image.
How to make your photos harder to steal
ESET cannot promise total protection, but it recommends steps that make life harder for abusers:
– Review the privacy settings on every social network and check who can see your posts.
– Search for your own name and photos now and then to see what is public.
– Use a different password for each account and switch on two-step verification.
– Keep phones and apps updated, and avoid uploading photos to apps with unclear privacy policies, even if they come from an official app store.
Parents should also talk openly with children about consent, digital manipulation and the consequences of sharing artificial images.
What to do if a fake image appears
Speed is crucial, as swift action can limit how far a fake spreads. Do not pay or negotiate if someone tries to blackmail you.
Save screenshots, messages, links, dates and usernames as evidence before you block the sender, then ask the platform to remove the image. Free tools can help. StopNCII.org creates a digital fingerprint of an image so participating platforms can spot it, while Take It Down, run by the US National Center for Missing & Exploited Children, is aimed at under-18s.
Residents of Spain can also use the Canal Prioritario (“priority channel”) run by the Spanish data protection agency, the AEPD. It handles urgent requests to remove sexual or violent material shared unlawfully. Search engines can be asked to delist results too, and threats, sextortion (blackmail using intimate images) or any involvement of children should go to the police.
Spain, Britain and the EU tighten the rules
Lawmakers are racing to catch up. On July 7, Spain’s cabinet gave final approval to rules replacing its 1982 law on the right to honour, privacy and one’s own image. It aims to rein in deepfakes made without consent, including the unauthorised commercial use of a person’s image or voice through AI, but MPs must still vote on it.
Brussels is moving too. An EU directive on violence against women covers the non-consensual sharing of digitally manipulated intimate material, including some sexual deepfakes, and member states have until June 14 2027 to turn it into national law.
Britain has made creating or requesting sexually explicit deepfakes of adults without consent a criminal offence since February 2026. The Crime and Policing Act, which received royal assent in April, adds an offence for supplying nudification tools.
Legislation will take time to bite, which leaves families to protect themselves in the meantime.
Follow Euro Weekly News on Google News
Get breaking news from Spain, travel updates, and expat stories directly on your Google News feed.
Follow on Google NewsSign up for personalised news
Subscribe to our Euro Weekly News alerts to get the latest stories into your inbox!
By signing up, you will create a Euro Weekly News account if you don't already have one. Review our Privacy Policy for more information about our privacy practices.
Lucy Ramnought
Lucy Ramnought is a local news writer and mother of 4 from the UK who has lived in the Costa Del Sol for just over 4 years. With a background in content writing and social media for various companies, and with vast experience in PA and project management, Lucy is committed to producing accurate, engaging and reliable stories to her work at Euro Weekly News.
Comments