digital forensics
Source: Canva

The UK's laws on sexually explicit AI deepfakes have moved faster than the systems investigators need to enforce them.

That gap is becoming increasingly visible as police investigate cases involving AI-generated intimate images. A recent investigation reported by IBTimes UK found that several cases involving Grok-generated deepfakes have stalled because investigators were unable to identify suspects, obtain information from X or pursue people believed to be outside the UK.

The problem is not necessarily that the law is unclear. In many cases, the problem is proving who was behind the keyboard.

Since February 2026, UK law has made it an offence to intentionally create or request the creation of a purported intimate image of an adult without consent. The Crown Prosecution Service confirms that the offence covers both the creation and the request for creation of such images.

That is a significant legal change. But legislation can only establish that conduct is criminal. It cannot automatically reveal the identity of an anonymous account.

This is where the technology creates a difficult enforcement problem.

A person can operate through an anonymous account. The relevant platform may hold information that could help identify them. The information may sit across different jurisdictions. Investigators may need cooperation from a technology company, telecommunications provider or foreign authority before they can establish who was responsible.

If one link in that chain fails, an investigation can stall.

'The law can define the conduct as criminal, but enforcement depends on evidence,' said Isvari Maranwe, founder of Yuvoice.

'If investigators cannot connect an anonymous digital action to a real person, accountability is hard, but with too much surveillance, we lose freedom, privacy, and human connection online. Plus, platforms collecting data on individuals can mean authoritarian and nefarious government requests overseas, not just the UK government catching predators.'

The problem is particularly complicated when AI systems sit between the user and the resulting content.

A conventional investigation might examine who uploaded a photograph or sent a message. With generative AI, investigators may instead need to establish who prompted the system, what account was used, what the platform recorded and how the resulting material was distributed.

IBTimes UK reported that police investigating several Grok cases encountered precisely these difficulties.

In one case involving presenter Jess Davies, police were unable to identify the person behind an anonymous X account. In another involving MP Jess Asato, the suspect was reportedly identified but was outside the UK, creating another barrier to prosecution.

For victims, the distinction can be frustrating. The harm occurs in a matter of minutes. Identifying the person responsible can take months, or may not happen at all.

'The speed of generative AI creates a mismatch with traditional investigations,' Maranwe said. 'A harmful image can be created instantly, but establishing the evidence trail behind that image may require multiple companies, systems, and jurisdictions to cooperate and a lot of data being collected.'

The UK is also putting greater pressure on platforms themselves.

Ofcom's deadline for platforms to implement measures designed to detect and prevent the spread of illegal intimate images, including AI-generated deepfakes, fell on 30 September. Platforms that fail to comply with applicable legal duties can face fines of up to 10% of global annual revenue.

The new requirements could improve prevention and removal, but they do not solve every investigative problem.

Stopping an illegal image from spreading is different from identifying the person who created it. Removing content can reduce additional harm, while criminal investigations require evidence capable of connecting conduct to an individual.

That distinction matters as social platforms increasingly incorporate generative AI directly into their products.

Yuvoice is developing a social platform built around AI-assisted fact-checking and healthier engagement. Its approach reflects a broader question facing the industry: whether AI should simply moderate content after it appears or be designed into the architecture of a social platform from the beginning.

'The safety conversation has to include the evidence layer,' Maranwe said. 'Platforms need to think not only about whether illegal content can be detected and removed, but also about balancing that with supporting investigations and genuine privacy. The focus should be on the impact to real people, not outrage.'

That does not mean creating an environment where every user is subjected to unrestricted surveillance. Privacy, due process, and proportionality remain important considerations. Nor does every piece of platform data automatically establish criminal responsibility.

But the Grok cases illustrate a practical reality of AI-enabled abuse: accountability can become fragmented between the person making a request, the AI system processing it, and the platform distributing the resulting content.

The UK's legal framework is continuing to evolve. The Crime and Policing Act 2026 also creates offences relating to making or supplying tools designed to generate purported intimate images, expanding the legal response beyond individual users.

The next challenge is making sure enforcement evolves alongside it.

'Technology companies need to consider harm to users from the get go, not just because law enforcement makes them,' Maranwe said. 'It is better to stop the ongoing harm to victims immediately than wait for the government to force it.'

The UK has taken a significant step by criminalising conduct that was previously difficult to prosecute directly. The harder question now is whether investigators will have the technical access, platform cooperation, and cross-border mechanisms needed to turn those laws into cases that can actually be brought before a court.