A Seventh Withdrawal
On June 26, 2026, Australia's eSafety Commissioner announced that three more AI "nudifying" services had exited the Australian market rather than meet age-assurance obligations imposed under the Age-Restricted Material (ARM) Codes. That brought to seven the number of the most widely used nudify tools — services that let a user upload a photo and generate a fabricated nude image of the person in it — that have either gone dark in Australia or taken steps to comply with the Online Safety Act 2021 since eSafety began targeted enforcement in this category (eSafety, June 26, 2026).
The mechanism behind that tally is a Direction to Comply, the first formal step available once an ARM Code takes effect. In one case folded into this run of enforcement, eSafety issued a Direction to a nudify service drawing roughly 50,000 visits a month from Australian users, giving the operator 14 days to add age-assurance measures or face civil penalties of up to AUD $49.5 million and a possible delisting notice instructing search engines to stop surfacing the site (eSafety media release). MLex reported the same June 26 figures independently, framing the episode as evidence that Australia's 2021 Online Safety Act framework is now doing real work against a category of app that barely existed in policy conversations two years ago (MLex).
The Case for the Codes
The strongest argument for eSafety's approach isn't hypothetical. Research from the Institute for Strategic Dialogue, cited in the OECD's AI Incidents Monitor, found that YouTube and X directed more than 5.7 million users to AI-powered nudify apps between December 2025 and March 2026 (OECD.AI). That is not a fringe problem confined to obscure corners of the internet — it is mainstream platforms functioning as a distribution funnel for tools that generate non-consensual intimate imagery, frequently of minors. Left to platform terms-of-service enforcement alone, take-down has been slow and inconsistent; a regulator with statutory power to compel age-assurance, backed by real financial exposure and search-delisting authority, can move on a timeline — 14 days — that voluntary industry self-regulation has not matched. Seven services either shuttered or brought into compliance in roughly eight months is a genuine, measurable result, and critics of Australia's online safety regime should weigh it against the realistic alternative, which is not zero regulation but continued drift.
Enforcement, Not a Ban
What makes the Australian model worth studying — and preferring over the alternatives now circulating in other jurisdictions — is what eSafety did not do. It did not ban image-generation AI, impose a blanket age-verification mandate on every platform capable of producing explicit imagery, or require pre-screening of general-purpose generative tools. It issued individualized Directions against specific non-compliant services, with an explicit compliance off-ramp before penalties attach. That is a narrower instrument than the blanket age-verification regimes now being litigated and debated in the UK and elsewhere, which sweep in lawful adult content and general-purpose services alongside the tools actually implicated in child-safety harms. A regime that targets demonstrated bad actors, gives them a defined path back into the market, and escalates only on non-compliance is closer to the proportionate model this publication has consistently argued for than to a moral panic dressed up as policy.
Where the Model Strains
The caveats are real, though. eSafety has generally declined to publicly name the services subject to these Directions, reasoning that identifying them would amplify their reach — a defensible operational call, but one that means the public record of "seven withdrawals" rests substantially on the regulator's own account rather than independently verifiable disclosures (Epoch Times reported a comparable, earlier Direction against an unnamed Argentina-based provider in May 2026, similarly withheld from public identification) (Epoch Times). And "withdrawal" is doing a lot of work in the headline figure: for offshore operators with no Australian assets, revenue interest, or legal presence to defend, exiting the market costs nothing and proves little about the underlying harm being addressed elsewhere. In those cases, the delisting-notice power — directing search engines to stop surfacing a site — is what actually restricts Australian access, and that is a broader and more contestable authority than a Direction against a party that is actually subject to the code. It edges toward general content-blocking rather than enforcement against a named respondent, and deserves more scrutiny than a straightforward compliance action does.
The net assessment still favors the model. Australia has shown that an existing statutory framework — codes registered under the Online Safety Act, graduated enforcement, real but bounded penalties — can push a genuinely harmful AI use case out of a market without legislating against generative AI itself. That is the template regulators elsewhere weighing nudify-app rules should be studying, provided the delisting power stays tightly scoped to the child-safety harms it was built for rather than becoming a general-purpose tool for suppressing sites Canberra would prefer Australians not find.