top of page

UK Police Deepfake Crime Is Rising, but the Official Count Captures Only Part of the Harm

6 hours ago
13 min read

UK police deepfake crime records across 20 forces reached 163 by July 2026, according to figures reported by The Telegraph. The comparable count was 10 in 2023. That increase suggests synthetic media has moved from a theoretical risk into everyday police work.

However, the figures are not a complete national crime total. They came from searches for terms such as “AI-generated,” “deepfake,” and “nudify” inside police records. Twenty forces supplied relevant data, while England and Wales have 43 territorial police forces.

The headline number therefore creates a two-sided story. Police are encountering more crimes with an identifiable AI component, especially sexualized image abuse. At the same time, inconsistent recording practices make the true scale difficult to measure.

That tension matters because England and Wales changed the law during the same period. Creating or requesting a purported intimate image of an adult without consent became a specific offense in February 2026. Parliament has also targeted services designed to generate those images.

The challenge has shifted from recognizing the harm to detecting, recording, investigating, and removing it. Laws can define an offense. They cannot automatically identify every manipulated image, preserve overseas evidence, or persuade victims that reporting will help.

UK Police Deepfake Crime Rose Across a Partial Dataset

The 163 recorded crimes are a warning signal, not a national prevalence estimate.

The reported police figures cover records returned by 20 forces using keywords associated with synthetic media. According to The Telegraph’s account, the total climbed from 10 in 2023 to 163 by July 2026.

That is more than a sixteenfold increase between the reported endpoints. Yet the comparison should not be interpreted as a precise measure of how often people created deepfakes during either period.

A keyword search depends on the words entered by call handlers, officers, investigators, and victims. One force might describe a manipulated photograph as “AI-generated.” Another might record similar conduct as harassment, blackmail, malicious communications, or intimate image abuse.

A third record might explain the alteration without using any searched term. That case would not appear in the result, despite involving the same technology and comparable harm.

The dataset also includes less than half of the territorial police forces in England and Wales. It does not establish what happened in forces that did not return usable information. Nor does it show whether every responding force searched the same fields, spellings, or date ranges.

The word “crime” needs similar care. A record containing “deepfake” does not necessarily represent a distinct offense written specifically for deepfake creation. Police classify conduct under the law applicable to the behavior, which can include sexual, communications, fraud, stalking, or child-protection offenses.

Some records could involve AI-generated audio used for impersonation. Others could concern altered sexual images, threats to publish them, or material involving children. The keyword method groups technologically related cases that can differ substantially in conduct and legal treatment.

Recording behavior also changed between 2023 and 2026. Public awareness grew, officers gained vocabulary for synthetic media, and new offenses gave police clearer labels. Part of the increase likely reflects more offending, while another part reflects improved recognition and documentation.

That qualification does not make the rise unimportant. A noisy administrative measure can still reveal a meaningful operational change. The same terms are appearing in many more police records, across multiple jurisdictions, within a much shorter reporting period.

The crucial unanswered questions concern outcomes. The public figures do not provide one standardized national breakdown of arrests, charges, prosecutions, victim ages, or offense categories. Without those details, the count measures recorded demand more clearly than enforcement success.

Police leaders consequently need a common way to tag AI-enabled crime. Otherwise, policymakers will continue comparing keyword searches that vary by force, software system, and officer practice.

A reliable national picture would distinguish synthetic intimate images from voice impersonation, fraud, fabricated evidence, and AI-generated child abuse material. It would also track whether each case involved creation, distribution, threats, or repeated uploading.

Until that system exists, 163 is best read as a floor within a partial dataset. It shows a growing problem, but not its boundaries.

Why Nudify Tools Changed the Scale of Abuse

Nudify services reduce a technically difficult act to an upload, a prompt, and a generated image.

A deepfake is synthetic or altered media that falsely depicts a real person doing or saying something. A nudify tool is a service designed to make a clothed person appear nude or sexually exposed.

Earlier deepfake production often required specialist software, suitable hardware, many source images, and considerable time. Consumer services now hide much of that work behind web forms, messaging bots, or built-in image assistants.

The offender does not need to understand model training. A school photograph, social profile image, or ordinary portrait can become the source material. Distribution can then occur through group chats, social networks, forums, or direct messages.

This lower barrier changes who can commit the abuse and where it happens. A classmate can target another student. An estranged partner can manufacture humiliating material. A stranger can alter a public photograph and attach it to a name.

The image may be fabricated, but the violation is tied to a real identity. Viewers can recognize the face, school, workplace, or social account. Victims may then face ridicule, sexual harassment, extortion, or repeated demands to prove the image is false.

The harm also survives technical debunking. A victim can demonstrate that an image was generated and still lose control over its circulation. Copies can move to new accounts or platforms after the original upload disappears.

Scale compounds that problem. Wired identified at least 50 Telegram bots claiming to create explicit images or videos in a 2024 investigation of nudify bots. That reporting showed how automation, messaging infrastructure, and simple interfaces could turn individualized abuse into a service.

General-purpose image generators add another layer. They are not necessarily marketed for abuse, but weak safeguards can permit sexualized transformations of real people. The distinction between a dedicated nudify product and a misused mainstream assistant then becomes important for both law and enforcement.

A bespoke tool has an obvious purpose. A general model can serve many legitimate functions while still producing prohibited output after certain prompts or modifications. Developers must test whether safeguards work across languages, indirect requests, image edits, and repeated attempts.

The technology can also create an evidence problem. Investigators must establish who submitted the image, who generated the output, who shared it, and whether the depicted person consented. Those actions may involve different people, accounts, devices, and countries.

Service providers can hold essential logs, including upload times, account identifiers, payment records, prompts, and generated outputs. If a provider retains little information or operates overseas, police may struggle to obtain it before deletion.

Encryption and anonymous payment methods can add further barriers. Even when officers identify an account, connecting it to a person beyond a reasonable doubt remains a separate task.

These mechanics explain why recorded cases can rise faster than enforcement capacity. Generation is immediate. Investigation still depends on evidence preservation, platform cooperation, forensic work, and legal process.

New Laws Move Liability From Sharing to Creation

England and Wales now criminalize more of the abusive chain, including creation and requests made before an image is distributed.

Sharing or threatening to share intimate images without consent was already covered by the Sexual Offences Act 2003 following changes made through the Online Safety Act 2023. That framework includes images that were altered or entirely manufactured.

A gap remained around creating a purported intimate image of an adult when the creator did not distribute it. The Data (Use and Access) Act 2025 introduced offenses covering creation and requests for creation without consent or a reasonable belief in consent.

Those offenses took effect on February 6, 2026. The timing is central to interpreting the new police figures because conduct recorded earlier may have been investigated under different offenses.

The law uses “purported intimate image” to cover an image that appears to show a real person in an intimate state but is not solely a genuine photograph or film of that person. This technology-neutral wording avoids tying the offense to one model or generation method.

It also recognizes that the harm starts before publication. Creating an image without consent can itself violate a person’s sexual autonomy, even if police cannot prove that the creator distributed it.

Requesting the creation is covered too. That matters when one person commissions a service, bot operator, or another individual to manufacture the image.

The Crime and Policing Act 2026 goes further by addressing generators. Its nudification provisions target making, adapting, supplying, or offering something for use as a purported intimate image generator.

The legislation defines a “thing” broadly enough to include a program, electronic information, or service. Liability turns partly on whether a reasonable person would consider it made or supplied for generating purported intimate images.

The maximum penalty for the generator offense can reach three years in prison following conviction on indictment, alongside an unlimited fine. The Act also contains defenses, intermediary exemptions, and provisions addressing corporate liability.

A provider can raise a defense based on taking all reasonable steps to prevent misuse. That creates a practical compliance question for multipurpose AI developers: what testing, access controls, monitoring, and response procedures qualify as reasonable?

The same Act establishes image deletion orders. A court can require an offender to put covered material beyond use, including deleting digital copies or arranging for online content to be removed or permanently hidden.

These changes create a more complete legal chain. The law can reach creation, requests, distribution, threats, dedicated generators, and continuing possession or control after conviction.

However, enactment does not guarantee immediate operational impact. Different sections can require commencement measures, guidance, technical standards, or regulatory implementation. Police also need training to recognize which offense fits a specific sequence of actions.

Investigators must separate adults from children because different statutory regimes apply. Purported intimate image offenses for adults do not replace laws covering indecent or pseudo-photographic images of children.

The new framework is therefore broader, but also more complex. Officers need to identify the victim, image type, suspect action, consent status, distribution history, and generator involved.

A national recording standard would make that complexity visible. Without one, the public may see a rising total without knowing whether the justice system is using the newer offenses effectively.

Police and Platforms Now Share the Enforcement Burden

The central contest is no longer law versus lawlessness; it is faster generation versus slower detection and removal.

Police can investigate individual suspects, seize devices, collect statements, and seek platform records. They cannot continuously monitor every service where abusive images might be created or reposted.

Platforms control the systems that generate, host, recommend, and replicate content. Their product decisions determine whether a user can upload another person’s photograph, request a sexual alteration, and publish the result within minutes.

This makes prevention a design issue as well as a policing issue. Services can restrict sexual transformations involving identifiable people, test adversarial prompts, rate-limit repeated attempts, and preserve evidence after valid reports.

They can also use hashes, which are digital fingerprints derived from files, to identify known copies. Matching systems can reduce repeated uploads without requiring victims to find every instance manually.

The Crime and Policing Act creates a duty for covered user-to-user and search services to act on valid intimate-image reports. It requires removal or suppression as soon as reasonably practicable, with a deadline no later than 48 hours.

The rules contemplate matching the reported content and copies that are the same or substantially the same. That feature matters because small edits, crops, captions, or compression can otherwise defeat simple exact-file matching.

Ofcom has separately proposed stronger detection requirements within its Illegal Content Codes. The regulator said the code amendments were expected to take effect in autumn 2026, subject to the relevant process.

This platform layer changes the pressure calculation. A victim should not have to rely only on identifying and prosecuting the original creator. Rapid removal can limit exposure while a criminal investigation continues.

Yet automated detection creates tradeoffs. A system must distinguish intimate abuse from lawful medical, educational, journalistic, artistic, and consensual content. Weak matching misses altered copies, while overly broad filtering can remove legitimate material.

Synthetic media adds another complication. Detection models do not always identify whether an image was generated, and generation techniques keep changing. A false negative can leave harmful content online, while a false positive can block lawful expression.

Consent cannot always be inferred from pixels. A realistic image might be genuine and consensually shared, genuine and stolen, or synthetic and unauthorized. Platforms need reporting processes that incorporate context from the depicted person.

Victims also need a route that does not expose them to more harm. Requiring repeated uploads of an abusive image, excessive identity documents, or separate reports for every copy can recreate the loss of control.

Police and platform evidence needs can conflict with immediate deletion. Investigators may require preserved records, while victims reasonably want public access stopped at once. Providers need processes that restrict access without destroying legally relevant data.

International services create further friction. A company may lack a UK office, store data in another jurisdiction, or respond slowly to law-enforcement requests. Blocking and financial penalties can pressure providers, but attribution still takes time.

The government has created PoliceAI and a Policing AI Threat Hub to coordinate the response to AI-enabled crime. Its policing program is expected to supply deepfake detection tools and training to forces.

Detection technology can help triage evidence, but it cannot decide a case by itself. Officers still need provenance, witness accounts, account records, and device evidence. A detector’s confidence score is not proof of who created or shared an image.

The strongest enforcement model combines platform prevention, rapid victim reporting, evidence preservation, specialist police capability, and prosecution. Leaving any one element weak gives offenders a route around the others.

What the 163 Cases Still Do Not Tell Us

The largest uncertainty is not whether abuse is rising, but how much remains unreported or hidden by inconsistent classifications.

Victims may avoid police because they fear disbelief, publicity, parental discovery, workplace consequences, or further circulation. Some do not initially know whether the image is genuine, manipulated, or entirely synthetic.

Others may report directly to a platform without contacting police. A school might handle an incident internally, while an employer may treat it as misconduct. Each path can leave the behavior outside criminal statistics.

The 20-force dataset cannot measure these missing cases. It also cannot reveal how many reports involved women, men, adults, or children unless the underlying forces collected and disclosed those fields consistently.

The sexualized use of deepfakes is widely understood as gendered abuse. Dedicated nudify services have often been designed around female bodies, while public cases have repeatedly targeted women and girls.

However, the reported police total should not be used to assign a victim profile that the dataset has not demonstrated. Better national statistics should publish demographic information with safeguards that protect victims.

The same caution applies to the phrase “AI crime.” AI can be the instrument, evidence, target, or incidental detail in a case. A deepfake used for sexual humiliation presents different investigative needs from cloned audio used in payment fraud.

Keyword results can also count changing language rather than only changing behavior. The term “deepfake” became more familiar after high-profile incidents and legislative debate. An officer who wrote “edited image” in 2023 might write “AI-generated deepfake” in 2026.

New laws can cause an apparent rise by improving classification. That is a desirable result if previously invisible victims receive a more accurate response. It nevertheless complicates year-to-year comparisons.

There is another boundary around children. Existing law already treats realistic AI-generated child sexual abuse material as illegal through provisions covering indecent pseudo-photographs and related material.

The Internet Watch Foundation identified 8,029 realistic AI-generated images and videos depicting child sexual abuse during 2025. Its 2026 assessment also described the use of real children’s likenesses and signs of commercialized generation services.

Those figures measure material assessed by a specialist hotline, not police-recorded offenses. They should not be added to the 163 cases. The difference illustrates why the UK needs connected measures covering victim reports, platform removals, hotline findings, investigations, and court outcomes.

Enforcement outcomes are especially important. A rising report count paired with few evidence requests, arrests, or charges would indicate an operational gap. More charges under the new creation offenses would suggest that legislation is translating into practice.

Public statistics should also show time to removal. An image that remains widely accessible for days can cause lasting harm even when a suspect is eventually identified.

Researchers will need to test whether the 48-hour duty reduces exposure across major services. They should also examine whether abusive communities migrate to smaller sites, encrypted channels, or providers outside the UK.

The number 163 therefore opens the inquiry rather than closing it. It confirms that officers are seeing more AI-linked allegations, but it cannot establish prevalence, victimization, or deterrence on its own.

Three Signals Will Show Whether the Response Works

The next test is whether legal change produces measurable improvements in recording, removal, and criminal outcomes.

The first signal is a standardized national police dataset. The Home Office, PoliceAI, or the National Police Chiefs’ Council should define consistent flags for AI-enabled offenses across all 43 territorial forces.

That system should separate image creation, requests, sharing, threats, generator supply, fraud, and child sexual abuse material. It should also record whether AI was confirmed, suspected, or merely mentioned.

A standardized dataset would reveal whether the current rise continues after terminology stabilizes. It would allow comparisons between forces without relying on separate keyword searches.

It would also help identify training gaps. If similar populations produce radically different recording rates, the difference could reflect reporting channels, officer awareness, or local investigative capacity.

The second signal is Ofcom’s implementation of stronger intimate-image protections. The important measures are not only the written rules, but removal speed, repeat-upload prevention, complaint handling, and enforcement against noncompliant services.

A meaningful result would show victims reporting once and seeing matching copies suppressed across covered platforms. Repeated reappearance would weaken the claim that the regulatory framework returns control to victims.

Transparency will matter here. Aggregate reports should show how many notices platforms receive, how often they act within 48 hours, and how many decisions are challenged or reversed.

The third signal is the first body of cases under the 2026 offenses. Charges and judgments will clarify how prosecutors prove creation, requests, lack of consent, and responsibility for supplying a generator.

Early cases will also test the “reasonable steps” defense available to some providers. Courts may need to examine whether safeguards were meaningful, documented, and tested against predictable misuse.

These outcomes should be assessed carefully. A low prosecution count might indicate weak enforcement, but it could also reflect investigation timelines or successful prevention. A high count could mean better detection rather than more underlying abuse.

The most useful measure will combine several outcomes: fewer harmful uploads, faster removal, stronger victim support, clearer investigations, and proportionate prosecutions.

For AI developers, the lesson is already concrete. Safety testing must include attempts to sexualize identifiable people, not only requests for explicit content in general. Providers also need reporting and evidence-preservation systems before incidents occur.

For schools and employers, synthetic images should be treated as real abuse rather than dismissed because the depicted body is fabricated. Response plans must protect the targeted person, preserve evidence, and limit recirculation.

For users, skepticism about manipulated media remains necessary, but the burden cannot sit with audiences alone. A victim should not need to win a public forensic argument before a platform acts.

UK police deepfake crime records show that the problem has entered routine institutions. The next question is whether those institutions can move as quickly as the tools creating the harm.

Watch the national recording standards, Ofcom’s implementation, and the first prosecutions under the expanded laws. Together, those signals will show whether the 163 cases mark the start of effective accountability or only better visibility into a much larger problem.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page