The findings attributed to AI Forensics and reported by The Verge on July 28, 2026 expose a structural gap in the AI supply chain that has nothing to do with model capability and everything to do with who is responsible for what a hosted tool does once it leaves the lab. Hugging Face doesn’t build the seven noncompliant models AI Forensics tested — it distributes them, running the Spaces where anyone can point a browser at an image editor and type a prompt. That distinction is the whole business model, and it’s also the whole liability question.
Map the transaction and the asymmetry is stark. The sellers are open-weight model developers who publish checkpoints with no sexual-content refusal training baked in, often because refusal training costs money and effort a hobbyist or small lab won’t spend. The buyers are anonymous prompt-writers, and per AI Forensics’ honeypot data cited by The Verge, a startling share of them are there specifically for nonconsensual undressing — 83 percent of the sexual requests among more than 1,000 logged over seven days, 95 percent of those targeting women, according to the report. Hugging Face sits in the middle collecting neither payment nor blame under its current posture, while researcher Paul Bouchaud’s line that “only the developer can, if they want, implement some” safeguards — and most don’t — describes an entire tier of the ecosystem opting out of the guardrails that Google and OpenAI have made table stakes for their own consumer products.
Open infrastructure is only as safe as the least responsible developer who publishes to it — and right now nobody at the platform layer is checking.
The competitive implication is a widening split between closed, guarded consumer AI and open, ungoverned model infrastructure — a split that increasingly looks less like a technical gap and more like a liability arbitrage. Grok’s undressing controversy showed users routing around consumer-facing guardrails with coded prompts; this report describes a venue where no coding is required at all, just a plain-text request. That makes Hugging Face’s Spaces the lower-friction option, and low friction is exactly what a distribution platform sells.
What would change this read: whether Hugging Face actually adopts AI Forensics’ proposed prompt- and output-level filtering, whether regulators treat hosting platforms as accountable intermediaries under emerging deepfake laws, and whether victims or advocacy groups can establish that a platform’s inaction — as opposed to a model developer’s design choice — carries legal exposure. Until then, the damage AI Forensics documented is a market outcome, not an accident.
"Most of the Spaces [tested] can be used for generating nonconsensual intimate images, and users are actually using it for these purposes," Paul Bouchaud, a lead researcher at AI Forensics, said in a statement to Wired. "No safeguards at all are being implemented at a platform level. Only the developer can, if they want, implement some, and most of them do not."