Is AI Porn Legal? Deepfakes, Minors, Copyright and Age Rules in 2026

Where AI porn stands with the law in 2026: the federal deepfake crime, why AI minors are prosecuted, the copyright you cannot claim, labels, and age checks.

Is AI Porn Legal? Deepfakes, Minors, Copyright and Age Rules in 2026 - Make A Porn Site

Short answer: AI porn of made-up adults is legal in the United States. AI porn of a real person without consent is a federal crime since May 2025 and a crime in at least 45 states. AI porn of anyone who looks under 18 is prosecuted as child sexual abuse material even though no child exists. You do not own a copyright in a raw AI image. The EU requires deepfake labels from August 2026, the platforms that allow AI adult content require labels now, and age verification laws apply to your site exactly as they apply to a shot site. Nothing on this page is legal advice; the laws are new and change monthly, so read the sources and talk to a lawyer who works in adult before you launch. The AI overview links the rest of the section.

Age of the subject: the line you never test

Is AI porn of someone who looks underage illegal if nobody is real?

Legal Consequences
Pornsite Law Gavel

Pornsite Law Gavel

Yes. This is the one part of AI porn law with no gray area, and it is the one that puts people in prison.

What the law says

Federal law, 18 U.S.C. 1466A, bans obscene visual depictions of minors and says in the text that it is not required "that the minor depicted actually exist." That is the statute used against fully synthetic images. A second statute, 2252A, applies when the image depicts a real, identifiable child, which includes an AI image made from a real child's face. The Department of Justice put it plainly in May 2024 when it charged a man for making explicit images of children with Stable Diffusion: "CSAM generated by AI is still CSAM."

That case, United States v. Anderegg, is still going. The one count the courts threw out was private possession inside his own home, first in February 2025 and again on appeal in August 2026. The production and distribution counts stand. Another federal court in Florida ruled in January 2026 that there is no protection for AI material stored anywhere outside the home. A bill to equalize penalties for AI-generated material, the ENFORCE Act, passed the Senate unanimously in December 2025. Outside the US, the UK passed a law in 2026 that makes it a crime to make, possess or supply a tool built to generate this material, with up to five years in prison.

A porn site does not store images at home. It publishes them. There is no version of this that is legal for you.

What that means in practice

  • Write the age down. Every performer's character sheet states an adult age, and every image has to look it. "Probably over 18" is not a standard. "A stranger would say adult without thinking" is.
  • Ban the cues, not just the number. School uniforms, classrooms, braces, pigtails, stuffed animals, childlike rooms, small frames, age words in prompts or captions. A model can drift young from a single word. Keep a list of words that never go in a prompt.
  • Prompt text proves nothing. Fanvue's rules say it directly: the prompt cannot prove the subject's age. Only the image can. If it reads young, it is gone, whatever the prompt said.
  • Review every image before it is public. Not a sample. Every one. Log who approved it.
  • Do not train on anything you would not publish. Training images are possession too.

This is also the first thing a payment processor checks, and the fastest way to lose the account and get reported. The AI Processor page covers that side.

Consent and real faces: deepfake law

Can I make AI porn of a real person?

Porn Legal Issues
Pornsite Law GDP

Pornsite Law GDP

Not without a signed license from that person for exactly that use, and even then only on platforms that allow it. Without one, it is a federal crime, a crime in at least 45 states, and a civil suit waiting to happen.

Federal law

The TAKE IT DOWN Act was signed on May 19, 2025. It makes it a federal crime to knowingly publish a sexual image of an identifiable person without consent. It covers AI directly: a "digital forgery" is an intimate image made with software, machine learning or AI that a reasonable person could not tell from a real one. Penalties run to three years in prison. The second half of the law took effect on May 19, 2026: any site that primarily hosts user content must remove a reported image, and every known copy, within 48 hours of a valid request. The Federal Trade Commission enforces that and cites a civil penalty of $53,088 per violation.

A civil law, the DEFIANCE Act, passed the Senate in January 2026. It would let victims sue for up to $150,000 per image, or $250,000 when tied to stalking, harassment or assault, with ten years to file. It was still waiting on the House when this page was written. The NO FAKES Act, which would create a licensable right in a person's voice and face with its own takedown process, cleared the Senate Judiciary Committee in June 2026 and is also still a bill.

State law

At least 45 states had a sexual deepfake law by August 2026. A few examples of how they look: Texas made deepfake video a crime in 2023 and added still images in September 2025. California allows a civil suit for digitized sexual images with damages of $1,500 to $30,000, or up to $150,000 for malice, and made it a crime in January 2025. Louisiana punishes distributing a sexual deepfake without consent with ten to thirty years. Tennessee's ELVIS Act, in force since July 2024, covers voice as well as face. It also makes it illegal to distribute a tool whose main purpose is producing a person's likeness without permission. New York, Virginia and Minnesota have their own versions.

Civil suits and the card networks

Even where the criminal law does not reach, the right of publicity does. In July 2025 a New York federal court let two voice actors' claims proceed against a company that cloned their voices with AI, and a 2026 New York case over a model's face placed in AI ads she never shot is ongoing. Mastercard's brand damage rule, revised in February 2026, names "unauthorised AI-generated depictions of real people" as content a merchant may not sell. The AI Processor page explains what that does to your account.

What to do

  • No real person's face, ever. No celebrities, no other sites' performers, no one you know. No real photo as a reference, and no real name in a prompt.
  • If a real performer wants an AI version of herself, get a written license that names AI, names the uses, and names the end date. Platforms like Fanvue allow that only for the account owner's own likeness, with the real person verified.
  • Put a removal request form on the site that reaches a person, and answer within 48 hours whether or not the law technically covers you. Google also demotes whole sites that draw a volume of these requests.
  • Keep the generation log for every image, so you can show that no real person was used.

Copyright: what you own and what you don't

Do I own the AI porn I generate?

You own the files, but you probably do not own a copyright in a raw AI image, which means anyone can copy it and you have no takedown to file. What you can protect is everything you add around it.

The rule

The US Copyright Office's January 2025 report on AI says that expression "determined by a machine" is not protectable, and that writing a prompt, even a long one, does not give you enough control over the result to make you the author. The courts agree. In March 2025 the D.C. Circuit held in Thaler v. Perlmutter that a copyright needs a human author, and the Supreme Court declined to review that in March 2026. That is the law for now.

What you can protect

The same report says protection is available for the human parts: elements you drew or edited by hand, a creative selection and arrangement of AI images, and creative changes you made to them. In practice:

  • A raw generated image: not protectable.
  • That image after real editing, compositing and retouching by you: the parts you did may be.
  • Your site, its layout, its written text, its performer bios and captions: protectable, if you wrote them.
  • Your performer names and your site name: protect those with trademarks, which do not care who made the pictures. For an AI site the brand is the only asset the law reliably protects, so register it.

When someone reposts your set, your DMCA notice will rest on the edits, the watermark, the text and the trademark, not on the image itself. Build with that in mind.

The models themselves

The lawsuits over how the models were trained have mostly gone the model makers' way so far. Getty's case against Stability AI in the UK ended in November 2025 with Getty dropping its training claims mid-trial and the court rejecting the argument that the model is itself an infringing copy. The main US case, Andersen v. Stability AI, is still heading toward a 2027 trial. Nothing in either case has made a user of the models liable for using them. That could change, so keep a note of which model made what.

Read the license before you sell

Owning nothing in the output does not mean the model's license does not bind you. FLUX.1 dev licenses the model for non-commercial use even though the images it makes may be sold. The Pony Diffusion license bars running the model on a site that charges for generation. Illustrious bars selling closed fine-tuned versions. The original Stable Diffusion license and FLUX.1 schnell allow commercial use outright. Check every base model and every LoRA you use, write the license version down, and check again when you upgrade.

Disclosure: labeling AI content

Do I have to label AI porn as AI?

Allowed Content
Adult Content host

Adult Content host

In the EU, yes, by law, from August 2026. In the US there is no general federal labeling law for adult AI content yet, but every platform that allows it requires a label, at least one adult processor asks for one, and California's new rules reach the tools you use. Label everything. It costs nothing and it settles arguments before they start.

Where it is the law

  • European Union. Article 50 of the EU AI Act applies from August 2, 2026. Anyone who deploys a deepfake, meaning AI content that looks like a real person, place or event, must disclose it "in a clear and distinguishable manner" the first time a viewer sees it. The companies that make the models must mark their output in a machine-readable way, with a grace period to December 2, 2026 for systems already on the market. Fines run to 15 million euros or 3 percent of worldwide turnover. If you sell to EU customers, this reaches you.
  • California. The AI Transparency Act became operative on August 2, 2026. It requires generative AI providers with more than a million monthly users to embed hidden provenance data, offer a visible label option, and provide a free detection tool. That is aimed at the model makers, not at you, but it means the tools you use will increasingly stamp their output whether you ask or not. Platform duties follow in 2027.
  • Federal. The TAKE IT DOWN Act is about nonconsensual images, not labels. There is no federal rule that says "mark AI porn as AI." Do not read that as permission to skip it.

Where it is the rule

OnlyFans requires AI content to be "clearly and conspicuously captioned" with something like "#ai." Fanvue requires disclosure in the bio, the caption or a watermark. Segpay, one of the adult processors that has approved AI sites, tells merchants to "disclose when AI has been used in content creation." Meta, TikTok and Google all read the AI flag in image metadata and act on it.

How to label

  • A visible line on the performer page, the set page and the join page.
  • The IPTC Digital Source Type field in every image file set to "trained algorithmic media," and any content credentials the tool attaches left in place. The AI Marketing page explains what Google does with those.
  • A sentence in your terms of service that says the performers are not real people.
  • If you run chat, the bot says it is AI when asked, every time.

Every record to keep for AI content

Does 2257 apply to AI porn?

Legal Docs
Adult Content Legal Issues DriversLicenses

Adult Content Legal Issues DriversLicenses

By its own words, 2257 applies to real people, so a fully made-up performer has no 2257 record to keep. That reading has never been tested in court, the government has published nothing about AI, and the moment a real person touches the content the whole law applies. So you keep a different set of records, and you keep them just as carefully.

What the statute says

18 U.S.C. 2257 covers producers of a "digital image, digitally- or computer-manipulated image of an actual human being" that shows "actual sexually explicit conduct," and it defines a performer as a person portrayed. The regulations that implement it, 28 CFR part 75, repeat "actual human being" throughout and contain nothing about synthetic content. The Department of Justice has issued no guidance on AI-only depictions. The only sources that say 2257 "does not apply" to AI are vendors, not the government. Our 2257 guide covers the law itself and our AI porn legal guide goes deeper on the open question.

When it does apply

  • A real performer's face or body, from any source, in any amount.
  • A face swap onto real footage, or real footage into an AI scene.
  • A LoRA trained on a real person's photos, even with permission.
  • Real reference photos used to steer a "fictional" performer.

In every one of those cases the real person is a performer, 2257 applies in full, and you need the consent and ID records a shot scene would need, plus a license that names AI. Do not let "it is mostly AI" talk you out of that.

What to keep for a fully synthetic performer

  • A generation log for every published image and clip: model and version, LoRA, prompt, seed, date, who approved it. This is the AI site's 2257 file. It shows what was used and, more importantly, what was not.
  • The character sheet for each performer, with the stated adult age.
  • Model and LoRA licenses, saved as files, with the version you used.
  • Your written policies: no real faces, no minors, no nonconsensual scenarios, human review before publishing, labeling. Processors ask for these by name.
  • The removal request log: every request, what you did, when.
  • Chat logs and the bot's rules, if you run chat.

Keep a 2257 statement page on the site anyway. Say plainly that the performers are computer generated, that no real person is depicted, and where records are kept for any real performer you do use. The AI Processor page shows how the same folder gets you through underwriting.

Facing age verification laws

Do age verification laws apply to an AI porn site?

Government ID
Adult Website Lawyer GreenCard

Adult Website Lawyer GreenCard

Yes. Age verification laws are about what the visitor sees, not how it was made. An AI porn site is a porn site to every one of them.

The United States

On June 27, 2025 the Supreme Court decided Free Speech Coalition v. Paxton, 6 to 3, and upheld the Texas law that requires sites with a substantial share of content harmful to minors to verify that every visitor is an adult. The Court held that adults have no First Amendment right to avoid an age check. That settled the question for every state law like it. Most of those laws apply once a third or more of a site's content is harmful to minors, which describes any porn site. Twenty-five states had such a law in effect by February 2026, and later counts put it at 27, with West Virginia, Missouri and Illinois joining in 2026. Our state age verification table tracks them one by one.

The United Kingdom

Since July 25, 2025, the Online Safety Act requires any service that publishes or hosts pornography to use "highly effective" age assurance, with fines up to 18 million pounds or 10 percent of global turnover. The regulator, Ofcom, said in January 2025 that services publishing their own explicit content, "including certain generative AI tools," should start age checks at once. A UK visitor to your site puts you inside that law.

What to do

  • Pick an age verification vendor and turn it on for visitors from the states and countries that require it. Turning it on everywhere is simpler and costs conversions; the table above helps you decide.
  • Keep the age gate on every entry point, including deep links from search and social.
  • Do not collect or store more than the vendor gives you back. Several state laws punish keeping identity data.
  • If you run chat, the same rule applies to the chat: no one under 18, verified, not promised.

One last point. Nothing on this page is legal advice. The laws here are new, they change monthly, and the penalties are the kind that end a business. Read the sources, then pay a lawyer who works in adult for an hour before you launch. Our lawyer directory lists a few who do.

Checklist

  • A generation log for every published image: model, LoRA, prompt, seed, date, approver.
  • A removal request form that reaches a person, answered within 48 hours.
  • Age verification turned on where the law requires it, with the vendor named.
  • Every performer is written down as an adult and looks it in every image. Ban the cues that read young.
  • Labels: on the page, in the image metadata, and in your terms.
  • Model and LoRA licenses saved, with the version you used.
  • No real person's face, name or photo in any prompt, reference or training set, ever.
  • One hour with an adult industry lawyer before launch.
  • Trademark the site and performer names. Copyright will not protect the images.