AI Undresser Risk Report
An AI undresser is a class of online service or mobile application that takes an ordinary photograph of a clothed person and synthesises an image of a nude body attached to that person's recognisable face. Nothing is uncovered: the body in the output was never photographed, which is precisely why every such image is a fabrication about a real, identifiable human being.
What this page is and is not
This report does not provide, host, link to or recommend any tool that undresses people or produces deepfakes. There is no software here, no service directory, no filter-bypass guidance and no example imagery. Every outbound link goes to research, legislation, a regulator or a victim support service.
Creating or sharing intimate imagery of a person without their consent causes documented harm and is now a criminal offence in a growing number of jurisdictions. If the person depicted may be under 18, the material is child sexual abuse material: report it to the police and a dedicated hotline, and do not forward or store it. Nothing here is legal advice.
- 705M+downloads across nudify apps found in the two main app storesTech Transparency Project, 27 Jan 2026
- 120+undresser services traced through payment analysisElliptic
- 48 hoursUS legal deadline for a platform to remove NCII on valid requestPub. L. 119-12
- 8,029child sexual abuse items assessed for 2025, of which 3,443 videosInternet Watch Foundation, 2026
What an AI undresser actually is
An AI undresser does not remove clothing and does not reveal anything concealed by it. It generates a body that never existed in the source photograph and joins it to a recognisable face, hair, pose and background. The output is false by construction in one hundred per cent of cases.
That mechanical detail carries the whole argument of this report. Because the face, setting and lighting are real, the composite reads to other people as a photograph — and it is that gap between technical fiction and social credibility that converts these images into instruments of harassment, blackmail and reputational damage. A victim cannot disprove a body that was invented, and an audience rarely stops to ask whether one was.
The same class of harm appears under several names. Nudify apps and undress apps describe the consumer-facing product; AI undressing and ai undresser describe the operation; deepfake porn and face swap porn describe the related technique of transplanting a real face into an existing explicit scene rather than building a body around it. In legislation and in victim support these outputs share one operative category: NCII, non-consensual intimate images. The related terms revenge porn and sextortion describe motive and method rather than the artefact itself.
One consequence deserves stating plainly, because it drives most of the practical advice below. Since the input is any ordinary clothed photograph, no behaviour on the victim's part creates the exposure. There is no intimate image to have leaked, no message to regret sending, and therefore no version of "be more careful" that would have prevented it. Responsibility sits entirely with the person who produced or circulated the material.
How widespread nudify apps and undress apps became
These services are not confined to the dark web. In January 2026 the Tech Transparency Project found 55 nudify apps in the Google Play Store and 47 in the Apple App Store, 38 of them listed in both, with more than 705 million downloads and roughly $117 million in lifetime revenue between them.
The distribution failure was compounded by classification. Several of these apps shipped with age ratings suitable for children and teenagers, including all-ages, 9+, 12+ and 13+ labels. Store policy already prohibited them: Google Play's rules name apps that "claim to undress people or see through clothing, even if labeled as prank or entertainment", and Apple's guidelines bar overtly sexual or pornographic material. Enforcement was reactive rather than preventive — Apple removed 28 apps and Google removed 31 only after publication, by which point the installs had already happened.
A second market never touched the app stores at all. Elliptic, a blockchain analytics firm, examined more than 120 "undresser" services operating through Telegram bots and standalone websites, some with over 3 million monthly active users. Pricing is trivial: roughly one dollar buys two to four generations, sold as credits. More than half of the surveyed tools accepted cryptocurrency, often at a discount to cards and e-wallets, and individual operator revenues ranged from under $1,000 to more than $200,000.
| Channel | What research documented | Source |
|---|---|---|
| App stores | 55 apps on Google Play, 47 on the App Store, 38 in both; 705M+ downloads; ~$117M lifetime revenue; child-friendly age ratings; 28 and 31 apps respectively removed after publication | Tech Transparency Project |
| Telegram bots | Part of 120+ services surveyed; some tools with 3M+ monthly active users; credit-based pricing at ~$1 for 2–4 generations; bots resurfaced on backup channels after removal | Elliptic |
| Standalone websites | Where removed bots migrated; over half of surveyed services accept cryptocurrency, frequently discounted against card payment | Elliptic |
| Payment rails | ~80% of operator funds eventually reached centralised exchanges with KYC procedures; links identified to Huione Pay and Haowang Guarantee merchants | Elliptic |
That last row is the one operators would rather their customers did not read. The assumption of anonymity is mistaken in both directions: around 80% of the money flowing to these services eventually landed at exchanges that perform identity checks, which makes the payment trail traceable, and Elliptic additionally described "crime displacement" — when Telegram removed popular bots, the same services reappeared on bespoke sites and backup channels rather than disappearing.
The severity end of the picture comes from the Internet Watch Foundation. Its 2026 report, Harm without limits: AI child sexual abuse material through the eyes of our Analysts, records 8,029 such images and videos assessed for 2025, including 3,443 videos against just 13 the previous year. Sixty-five per cent of those videos fell into Category A, the most severe classification, and 97% of the images depicted girls. The FBI has clarified that synthetic material depicting children meets the legal definition of CSAM, and Europol's 2024 IOCTA assessment named it a distinct investigative challenge. Elliptic separately confirmed these tools being used for sextortion, harassment and romance scams, while noting that the terms of service nominally prohibiting non-consensual use are largely unenforceable — operators state they retain no access to outputs, and only one surveyed service described prompt filtering at all.
Where an AI undresser is now illegal
The legal position changed materially in 2025 and 2026. The United Kingdom now criminalises the act of creation itself, not merely distribution, and the United States imposes a hard 48-hour takedown duty on platforms enforced by the Federal Trade Commission.
| Jurisdiction | Instrument | What it does | In force |
|---|---|---|---|
| United Kingdom | Data (Use and Access) Act 2025, section 138 | Makes it an offence to create, or to request another person to create, a "purported intimate image" of an adult without consent or reasonable belief in consent. Covers digitally altered images as well as wholly fabricated ones. Potentially unlimited fine. | 6 Feb 2026 |
| United States (federal) | TAKE IT DOWN Act, Pub. L. No. 119-12 | Covered platforms must remove NCII, including deepfakes, within 48 hours of a valid request by the depicted person, with reasonable efforts to remove known identical copies. Enforced by the FTC; civil penalties above $53,000 per violation. | Signed 19 May 2025; platform duties 19 May 2026 |
| United States (states) | State statutes on synthetic intimate imagery | Around thirty states had enacted or proposed their own legislation at the time of Elliptic's review. | Varies |
| Any jurisdiction, minors | CSAM law | The FBI has clarified that synthetic material depicting children falls under the existing definition of child sexual abuse material. | Existing law |
Three practical consequences follow. First, "I made it but never shared it" has stopped being a defence under UK law — section 138 reaches the creation and the commissioning of the image, closing a gap that had been exploited for years. Second, a platform receiving a properly formed request now carries direct regulatory exposure for ignoring it, which is why the official reporting form is a far stronger lever than arguing in a comment thread. Third, app store policy operates independently of statute: a complaint about an app that breaches Google Play or Apple rules runs in parallel and, as the 2026 removals showed, does produce results.
The persistent weakness is cross-border operation. An operator may sit in one country while its payment infrastructure sits in another, which is precisely why the traceable money trail into KYC-compliant exchanges has proved more useful to investigators than attempts to block individual domains. This section reviews published sources and is not legal advice; for a specific situation, consult a qualified lawyer in the relevant jurisdiction.
Spotting an AI nude or deepfake porn video
Visual inspection helps but cannot be relied on. Output quality keeps improving, and the absence of visible artefacts proves nothing about authenticity. Provenance — where the image came from and what preceded it — is consistently stronger evidence than pixels.
The recurring visual signals are worth knowing anyway, because they still catch a large share of low-effort material:
- Seams at the joinThe neck and shoulder line, where a synthesised body meets a real head, is the most common failure point.
- Interrupted objectsStraps, collars, necklaces, ties and drawstrings that terminate abruptly or change geometry mid-run.
- Hands and fingersStill a persistent weakness: extra digits, fused knuckles, implausible joint angles.
- Implausibly uniform skinNo moles, scars, tan lines or texture variation across large areas.
- Lighting that disagreesThe direction and colour temperature on the body do not match the face and background.
Non-visual checks are more decisive. A reverse image search frequently surfaces the original clothed photograph on a public profile, which settles the question outright. Posting history shows whether the "photograph" appeared later than the original with no chain of provenance. And the account distributing it — an anonymous channel, a freshly created profile, an aggregator with no history — often tells you more than any amount of pixel-peering.
The working rule for an ordinary reader is therefore not "learn to spot the seam". It is to refuse to treat intimate imagery of unknown provenance as fact, and never to forward it. Forwarding is what converts a single fabricated file into a distribution event, and under the US statute it is also what places a person within reach of the law rather than merely adjacent to it.
What to do if an AI undresser image of you appears
Work several channels at once, and do it in a fixed order: preserve evidence first, refuse payment, then file through official routes rather than negotiating with whoever posted the material. In the United States a valid request starts a 48-hour removal clock.
- Preserve the evidence before anything elseSave links, screenshots showing the URL and the date, account names and message identifiers. Both the platform and the police will need them. Do not delete a blackmailer's messages — that conversation is evidence.
- Do not payPayment does not end the pressure; it establishes that the victim can pay, and demands typically escalate. Cut contact and keep the thread intact.
- File through the platform's official NCII formThis is what triggers the legal response window. Arguing publicly under the post only widens the material's reach and does not start any clock.
- Submit a hash to StopNCII.orgThe service computes a digital fingerprint on your own device and transmits only that hash; the file never leaves your phone or computer. Participating platforms match it on their side. You must be over 18, the image must depict you and be in your possession, and it must be intimate in nature. Deepfakes and synthetic images explicitly qualify.
- Report to the policeParticularly where there is extortion, a named perpetrator or repeated distribution. The traceability of crypto payments through KYC exchanges means the financial trail is often the most productive line of enquiry.
- If the person depicted is under 18, stop and escalateThe StopNCII route is not available. Contact the police and a dedicated child protection hotline immediately. Do not forward the material and do not store it on anyone else's device "as evidence".
For parents, schools and workplaces the sequence is the same, with one addition: the common institutional mistakes are punishing or isolating the victim, demanding they "just delete it and move on", or circulating the material in a group chat to identify who is depicted. Each of those multiplies the distribution. Cut off access, preserve evidence, report, and provide support — in that order.
Reducing your exposure to nudify apps in advance
There is no complete defence, because the input is an ordinary photograph rather than anything private. The realistic objective is to shrink the attack surface and shorten the time between publication and discovery. These six measures do that.
- Shrink the public photo footprintRestrict profile visibility and remove public archives of high-resolution, head-on portraits — school, corporate, sports and event galleries are the usual sources.
- Vet anything you upload a face toCheck who develops a photo editor or avatar app and what its retention policy says. Tech Transparency Project noted developers based in jurisdictions with mandatory data disclosure to the state. An uploaded image has left your control.
- Set up early detectionOnce a month, search your own name and run a reverse image search on your public photographs. Early discovery is the single biggest factor in how easily material can be removed, before mirrors appear.
- Harden the accounts, not just the photosUnique passwords and two-factor authentication on email and social accounts. A compromised account hands an attacker both source material and a ready-made distribution channel.
- Have the conversation before an incidentFor teenagers the essential points are that any ordinary photo is a usable input, that "I never sent anything explicit" is therefore not protection, and that the victim is never at fault.
- Know the reporting route in advanceBookmark the platform NCII forms and StopNCII.org now. Under pressure, in the first hour after discovery, is the worst time to be researching where to file.
Terminology: nudify, undress app, deepfake porn
One phenomenon travels under a dozen names, and the inconsistency causes real problems — for victims filing reports, for parents, and for moderators classifying material. These are the terms as research, legislation and support services use them.
- nudify · nudify app · nudify ai
- The collective name for applications that take a photograph of a clothed person and output an image of a nude body. This is the class the Tech Transparency Project located in both app stores, and the wording now appears in Google Play policy.
- undress · undress app · ai undress · ai undress app · undress ai app
- Synonyms for the same product category. The word "undress" is itself misleading: no clothing is removed, a body is generated, so the result is a fabrication wearing a real person's face rather than a disclosure about them.
- ai undresser · undresser ai · ai undressing
- The term "undresser", used by Elliptic throughout its payment analysis, more often refers to services operating outside the app stores — Telegram bots and standalone sites running on a paid credits model.
- deepfake porn · deepfake porn video
- Explicit images or video in which a real person's face is combined with another body. It differs from nudify in the source material: nudify builds a body around a photo, whereas this transplants a face into footage that already exists.
- face swap porn · porn face swap · faceswap porn
- The same category named after the technique. The Tech Transparency Project documented apps that marketed face swapping as an entertainment feature while explicit output remained reachable.
- ai nude · ai nude video · undress ai nude
- Search terms describing the output rather than the tool. Legal status turns on the consent and the age of the person depicted, never on the method of production.
- ai porn generator · ai porn video generator
- A broader category spanning services built around fictional characters and tools applied to photographs of real people. Consent is the dividing line: material depicting a recognisable real person without consent is NCII, with the legal consequences set out in section 03.
- NCII · revenge porn · sextortion
- NCII — non-consensual intimate images — is the operative term in US legislation and in support services. Revenge porn describes distribution out of spite. Sextortion is extortion under threat of publication, one of the abuse patterns Elliptic confirmed in practice.
- CSAM
- Child sexual abuse material. The FBI has clarified that synthetic material depicting children meets the same definition, and the Internet Watch Foundation assessed 8,029 such items for 2025.
- hash · digital fingerprint
- A short irreversible value computed from a file. StopNCII.org computes it on the victim's device so that participating platforms can match the image without the image itself ever being transmitted.
On product names. A large share of search demand in this area consists of specific brand names and "alternative to X" queries. This report answers none of them with a review, a ranking or a link, because any such page functions as a storefront regardless of the warnings wrapped around it — and because no verified public research exists on most individual services, so writing about them would mean inventing facts. If a product name brought you here, the answer is in sections 03 and 05, and it is the same for the entire category.
Devices, browsers and accessibility
This report is a single self-contained HTML page with no external libraries, fonts, trackers or third-party requests. It renders identically on any device, works offline from a saved file, and transmits nothing about the reader anywhere.
The layout is built on CSS Grid and Flexbox with relative units and fluid type, and reflows correctly from 320-pixel phone screens up to wide desktop monitors, where a sticky contents rail appears alongside the text. Line length is capped at roughly 68 characters so that long-form reading stays comfortable. Current versions of Chrome, Edge, Firefox and Safari, and the mobile browsers built on their engines, are fully supported; older browsers may skip a few progressive properties such as color-mix() or the translucent header blur without any effect on the text or navigation. The page also declares color-scheme, so native scrollbars and form controls follow the chosen theme rather than staying stubbornly light. With JavaScript disabled the entire report remains readable, the contents links still work, and the FAQ still opens — the accordion is native <details> markup, not scripted.
Accessibility was treated as a requirement rather than a checklist. The markup uses one h1, an unbroken heading hierarchy, semantic landmarks and a skip link as the first focusable element. Every control is a real button or link, reachable by keyboard in a logical order, with a visible focus ring and a minimum target size. Colour pairings were chosen to clear WCAG AA contrast in both light and dark themes, and no meaning is carried by colour alone — a text label always accompanies it. The page respects system preferences: reduced-motion settings disable smooth scrolling and transitions, forced-colors mode takes borders and text from the system palette, and browser zoom to 200% does not break the layout or introduce horizontal scrolling. The report prints and exports to PDF cleanly, with controls hidden, every FAQ answer expanded and link destinations printed alongside the text so that a paper copy remains verifiable.
AI undresser and nudify app FAQ
Does an AI undresser show what someone actually looks like undressed?
No. The tool does not reveal anything hidden by clothing. It generates a body that was never in the photograph and attaches it to a recognisable face. The output is a fabrication in every case, which is why the law treats it as a false depiction of a real person rather than as a photograph of them.
Is using an AI undresser illegal?
In the United Kingdom, since 6 February 2026, section 138 of the Data (Use and Access) Act 2025 makes it an offence to create — or to ask someone else to create — a "purported intimate image" of an adult without consent, carrying a potentially unlimited fine. In the United States the federal TAKE IT DOWN Act targets distribution and platform duties, and around thirty states have their own statutes. Where the person depicted is a minor, the output is child sexual abuse material under existing law.
How fast must a platform remove a nudify image of me?
In the United States, covered platforms must remove the material within 48 hours of a valid request from the person depicted, and make reasonable efforts to remove known identical copies. Those duties took effect on 19 May 2026 and are enforced by the Federal Trade Commission, with civil penalties above $53,000 per violation. Outside the United States, timelines depend on local law and the platform's own policy.
Do I have to hand over the image to have it blocked?
No. StopNCII.org computes a hash — a digital fingerprint — on your own device and transmits only that hash; the file never leaves your phone or computer. Participating platforms match the hash on their side. You must be over 18, the image must depict you and be in your possession, and it must be intimate in nature. The service FAQ confirms that deepfakes and synthetic images qualify. Its limitation is that it reaches participating partners only, not the whole internet.
Can I tell a deepfake nude from a real photograph by looking at it?
Not reliably. Seams at the neck and shoulders, straps and jewellery that terminate abruptly, malformed hands, unnaturally even skin and mismatched lighting are common signals, but output quality keeps improving and the absence of artefacts proves nothing. Provenance is stronger evidence than pixels: a reverse image search that surfaces the original clothed photograph, the posting history, and the credibility of the account that published it.
Publisher, method and limitations of this report
This report is published by a registered company whose details can be verified independently, and it makes no claim to in-house expertise. Its authority rests entirely on named primary sources, each linked below, and on being explicit about what those sources do and do not establish.
- Publisher
- GOSSIP NAILS PORTSMOUTH LTD
- Company number
- 17148150
- Type
- Private limited company
- Incorporated
- 10 April 2026
- Registered office
- 92 Mayes Road, London, England, N22 6SY
- Register entry
- Companies House record for 17148150
Method. Every quantitative claim on this page is traceable to one of the six sources in section 11 and is attributed inline at the point of use. Where a figure comes from a single study, it is presented as that study's finding rather than as an established fact. No statistic here was estimated, rounded for effect, aggregated across sources or carried over from secondary reporting. Where research names specific applications, this report deliberately does not reproduce those names, because a list of products is a directory regardless of framing.
Limitations, stated openly. Three matter. Research on this subject captures a snapshot: the Tech Transparency Project counts reflect January 2026 and the app store position has changed since. Elliptic's payment analysis covers services it was able to trace on-chain, so the true market is larger than 120 and unmeasured in its tail. And legal status is moving quickly — the UK offence is only months old, US state legislation is still being enacted, and nothing here covers jurisdictions outside the UK and US. Readers outside those two countries should treat sections 03 and 05 as orientation, not as a statement of their local law.
Corrections. Factual corrections are welcome via the publisher named above. This page carries a review date, and any material change to the underlying law or research will be reflected there.
Sources
Six primary sources support every figure and legal statement above. All are linked directly and none of the source text has been reproduced; the wording throughout this report is original.
- Tech Transparency Project — Nudify Apps Widely Available in Apple and Google App Stores 27 January 2026. App counts across both stores, download and revenue totals, age ratings, verbatim Google Play and Apple policy wording, and the removals that followed publication.
- Elliptic — AI deepfake undresser tools are becoming illegal 120+ services surveyed, audience size, credit pricing, share accepting cryptocurrency, the ~80% of funds reaching KYC exchanges, payment infrastructure links, confirmed abuse patterns, and the legislative overview including the count of US states.
- legislation.gov.uk — Data (Use and Access) Act 2025, explanatory notes to section 138 The offence of making, or requesting the making of, a purported intimate image without consent, and its coverage of digitally altered as well as fabricated images.
- Federal Trade Commission — What will the FTC's enforcement of the TAKE IT DOWN Act mean for you? The regulator's own explanation of the rights of depicted persons and the duties placed on covered platforms under the US federal statute.
- Internet Watch Foundation — Harm without limits: AI child sexual abuse material through the eyes of our Analysts 2026 report covering 2025 data: 8,029 items assessed, 3,443 videos against 13 the previous year, 65% of videos in Category A, 97% of images depicting girls.
- StopNCII.org — How StopNCII.org Works On-device hashing mechanics, eligibility rules, the limitation to participating partner platforms, and the explicit confirmation that deepfake and synthetic images qualify.