A single tool, a disproportionate share of the harm
Resemble AI's H1 2026 Deepfake Threat Report, published August 12, 2026, puts a number on something victims' advocates have argued for months: one company's product is driving the deepfake abuse crisis. Of roughly 3.46 million synthetic files tied to 821 documented deepfake attacks between January and June, xAI's Grok accounted for 87% of every traceable file. Within that same dataset, 137 attacks — one in six — involved nonconsensual intimate imagery (NCII) of adults or children. Resemble AI calculates that those NCII/CSAM incidents alone expose defendants to as much as $2.24 billion in statutory civil liability under 15 U.S.C. § 6851, against just $6.95 million in verified direct financial losses across all 821 attacks combined.
That 322-to-1 ratio between potential liability and measured loss will read to some as evidence the law is wildly disproportionate. It isn't. It's evidence the law is doing exactly what Congress designed it to do when actual damages are nearly impossible to prove.
Steelmanning the case for aggressive liability
The strongest argument for uncapped statutory exposure is that intimate-image abuse doesn't produce a tidy financial receipt the way fraud does. A woman whose face is grafted onto explicit content and circulated to her coworkers, or a child depicted in AI-generated sexual imagery, suffers reputational, psychological, and safety harm that no accountant can price — which is precisely why § 6851, enacted in the Violence Against Women Act reauthorization, gives plaintiffs a choice between actual damages and a $150,000 liquidated-damages floor per violation. Congress built the gap between exposure and measured loss into the statute on purpose, the same way it did with the TCPA and statutory copyright damages: when harm is real but hard to quantify, a large fixed penalty is the deterrent, not a bug to be litigated away.
The underlying facts back that design choice. Before xAI added any restriction, researchers documented Grok generating sexualized images at a rate of roughly 6,700 per hour, with over half of the roughly 20,000 images produced between Christmas and New Year's showing people in minimal clothing — some appearing to depict minors, according to California Attorney General Rob Bonta's January 16, 2026 cease-and-desist letter, which cited California's NCII statute, its CSAM provisions, and its unfair-competition law. A week later, a bipartisan coalition of 35 state attorneys general, led by DC's Brian Schwalb, sent a joint letter accusing X of having "not only enabled the mass production of nonconsensual deepfake pornography but encouraged and profited from it." When the underlying conduct looks like that, a damages regime with real teeth is the proportionate response, not an overreach.
Where the proportionality argument actually bites
The case for skepticism isn't about the size of the statutory number — it's about how xAI responded to it. On January 9, 2026, facing mounting regulatory pressure, xAI restricted Grok's image generation and editing tools to paying subscribers only, rather than fixing the underlying model behavior. The UK government called the move "insulting," with a Downing Street spokesperson noting it simply "turns an AI feature that allows the creation of unlawful images into a premium service." Deepfake researcher Henry Ajder made the more durable point: a paywall doesn't touch the model's actual alignment failure, and payment-verification is trivially defeated. Plaintiff Ashley St. Clair confirmed as much, noting many accounts that targeted her were already paying subscribers.
That gap — between a company treating a civil-liability threat as a pricing problem and regulators treating it as a product-safety problem — is the real story. A liability regime only produces good incentives if the response it triggers is engineering, not monetization. The TAKE IT DOWN Act, signed May 2025, complements § 6851 well here: it requires covered platforms to remove reported NCII within 48 hours as of the May 19, 2026 compliance deadline, backed by FTC civil penalties of $53,088 per violation, giving victims a fast administrative remedy that doesn't depend on winning a federal lawsuit first.
The proportionate path forward
People of Internet's institutional priors favor light-touch, innovation-friendly regulation, and there is a real overbreadth risk if state legislatures respond to this report by criminalizing broad categories of AI image editing rather than the narrow, already-illegal conduct at issue. But that risk doesn't run through § 6851's damages cap, and it doesn't run through the TAKE IT DOWN Act's takedown clock. Both target conduct — nonconsensual sexual imagery, including of children — that has never had First Amendment protection and that no legitimate generative-AI product needs to enable by default. The $2.24 billion figure is a warning about what happens when a company ships an image generator without basic non-consent guardrails, not a case study in regulatory excess. Grok's 87% share of the traceable harm suggests the fix belongs in xAI's model architecture, not in Congress's damages formula.