The A.I. Nudification Ban on Trial: xAI v. Minnesota, and the President in the Pool

The A.I. Nudification Ban on Trial: xAI v. Minnesota, and the President in the Pool

2026-08-22

Elon Musk, the State of Minnesota, and the first courtroom test of undressing people by algorithm.

On May 1st, Donald Trump posted a picture on Truth Social in which he, J. D. Vance, Marco Rubio, and Doug Burgum are taking the waters in the Reflecting Pool on the National Mall, the Washington Monument at their backs. The men are shirtless; the President is giving a thumbs-up; beside them poses a woman in a bikini who is unidentified and quite possibly nonexistent. The image was generated, of course, by artificial intelligence, and the joke concerned the dragging renovation of the Mall. Three months later, the same picture entered the record of the federal court in St. Paul as the flagship exhibit in a lawsuit that Elon Musk’s company has brought against the State of Minnesota. The complaint’s thesis is simple: if the new state law punishes a tool’s maker for every generated likeness that exposes “intimate parts,” then it covers the Presidential meme; and a law that cannot tell satire from harm will not survive its collision with the First Amendment.

The case, styled X.AI LLC v. Keith Ellison, Minnesota’s attorney general (No. 0:26-cv-03425, District of Minnesota), is the first American test of a statute banning “nudification,” the undressing of people by algorithm. House File 1606 was signed on May 7, 2026, and took effect on August 1st. xAI sued on July 27th, and on July 31st, Judge Donovan Frank, an appointee of Bill Clinton’s, declined to halt the law on an emergency basis: not because the plaintiff was wrong but because it had waited nearly three months after the signing and moved for emergency relief three days before the effective date, which reflects poorly on the urgency it claimed. On August 19th, the court heard argument on a preliminary injunction to last for the duration of the case, and promised a swift ruling. The day before, the federal government had entered the matter, filing, under 28 U.S.C. § 517, a statement of interest that formally supports no one and functionally seconds Musk.

The provision in dispute, Section 325E.91 of the Minnesota Statutes, does not punish the user who makes the image, or anyone who passes it along. It punishes the owner of a site, an app, or a program for the mere fact of allowing a user to “nudify” a picture or a video, and it punishes anyone who advertises such a service. “Nudification” means generating or altering an image so that it depicts an “intimate part” of an identifiable person that was not there in the original, realistically enough that a reasonable viewer would take it for genuine. The legislature borrowed its definition of “intimate parts” from the criminal-sexual-conduct code (Section 609.341), a provision written for unwanted touching, not for pictures: it covers the genitals and the groin, but also the inner thigh, the buttocks, and the breast, the male breast included. Hence xAI’s argument that the statute reaches a shirtless man, a swimmer in trunks, and a politician in shorts; alongside the President in the pool, the record contains a satirical image of a former and a sitting governor wrestling sumo.

The sanctions are unprecedented: a civil penalty of up to five hundred thousand dollars for each individual use of the service, plus private suits by the people depicted, with damages of up to three times the loss, punitive damages, and costs. The complaint does simple arithmetic: a hundred thousand challenged images amounts to exposure on the order of fifty billion dollars. And the statute asks for nothing more. It does not require that the person depicted withheld consent, or any fault, or even knowledge on the provider’s part, or that the image ever circulated; it makes no exception for art, satire, science, or medicine; it offers no harbor to a provider that bans such content and filters it in good faith. Liability is strict: all that matters is whether the user succeeded.

The single exception is telling: the ban does not cover tools that demand “technical skill” of the user. A practiced designer may lawfully produce in Photoshop what will cost the maker of a plain-language tool half a million dollars. The paradox is not an oversight but the point: Minnesota is not banning the image; it is banning the ease of obtaining it. Behavioral science has a name for this, a policy of friction: small obstacles can shrink unwanted behavior dramatically, which is among the best-documented regularities of applied psychology. The trouble is that American constitutional doctrine has no category for speech that is too easy.

Honest analysis begins with the adversary’s strongest argument, and Minnesota has a serious one. At the hearing, Janine Kimble, arguing for the state, described why chasing perpetrators after the fact is, in practice, an illusion: the image must be noticed and reported by someone; it must be findable; its maker must be a human being, must be identifiable, and must be within the court’s reach or extraditable. Each link of that chain fails on its own, and together they fail almost always. The state cites research from 2019 finding that ninety-six per cent of deepfake videos then online were nonconsensual sexual imagery of real people, overwhelmingly women; newer incident tallies, compiled through early 2025, put fraud at thirty-one per cent of documented cases, political content at twenty-seven, and sexual material at twenty-five, with every category climbing. If harm is the technology’s standard use, Minnesota argues, then regulate the technology rather than chase a million files.

The most interesting evidence for the state comes from the plaintiff. xAI boasts in its complaint that in 2026 alone it has suspended more than fifty thousand accounts and filed more than seventy thousand reports with the National Center for Missing and Exploited Children, leading to at least two hundred and forty-four arrests. To the company, this is proof of diligence; to the state, proof of scale. The terms of service prohibit; the users proceed; and the machine, by Musk’s own exultant count in the first days after launch, in August of 2025, was turning out twenty million images in a single day. At that volume, even a fraction of one per cent of abuse is an avalanche, and the promise of a suspended account reads like a ticket mailed out after the avalanche.

There is, finally, a psychological argument that the state touches by intuition. Research on image-based abuse, conducted by Clare McGlynn, Nicola Henry, and Anastasia Powell, among others, finds effects in victims comparable to the aftermath of sexual violence: anxiety, shame, social withdrawal, a loss of trust. The artificiality of the image does not cancel the injury, because the social gaze does not check a file’s metadata; the victim loses control over her public self, and with it an elementary sense of safety: she can never again know who has seen what, and who believed it. The harm arises at the moment of creation, not only at publication. Tellingly, the legislature wrote that psychology directly into its definition: only a fake realistic enough for a reasonable person to believe is punishable. The injury grows with plausibility, and the provision measures exactly that. The refusal of an exception for consensual images has a similar internal logic: since consent cannot be verified in advance, every exception becomes an instruction manual for evasion. This is how all precursor regimes reason, from chemicals to firearms: where verification is costly, the legislature reaches for a flat ban. The price, always, is excess.

One thing is certain: as written, House File 1606 is the easiest constitutional target the state could have put up. To find a violation, an official must look at the image and judge what it depicts, the textbook mark of a content-based regulation (Reed v. Town of Gilbert, 2015), which draws strict scrutiny, a test so exacting that the Supreme Court, facing Texas’s age-verification law just last year, reached for a gentler standard rather than apply it (Free Speech Coalition v. Paxton, 2025). Minnesota answers that it regulates a technology, not content; xAI’s lawyer replied at the hearing that this is wordplay, since the ban switches on only according to what the picture shows.

The wounds number at least four. The statute is grossly overinclusive, reaching depictions that are not nudity in any ordinary sense; half a century ago, the Supreme Court struck down, for a similar reason, a ban on drive-in theatres showing films with exposed buttocks or breasts, noting that it would cover a baby’s bottom and the naked body of a war victim (Erznoznik v. City of Jacksonville, 1975). It contains no element of fault, though the case law requires a subjective state of mind even for the least protected categories of speech (Counterman v. Colorado, 2023), and the Eighth Circuit, the federal appeals court that sits over Minnesota, held flatly in 1992, in Video Software Dealers Association v. Webster, that a statute which chills expression must include a knowledge requirement. It does not require dissemination: it punishes creation alone, including an image never shown to anyone and deleted at once, and the Constitution does not permit banning expression because it might someday serve a crime (Ashcroft v. Free Speech Coalition, 2002). And gentler means exist, not hypothetical ones: Minnesota’s own law criminalizes the knowing, nonconsensual dissemination of intimate deepfakes, and the federal Take It Down Act of 2025 does the same nationwide, with a narrow anatomical definition, with elements of fault, non-consent, and dissemination, with exceptions for matters of public concern, for medicine, and for science, and with a duty to remove a reported image within forty-eight hours. Under strict scrutiny, it is the state that must show these tools insufficient; a heavier burden is hard to imagine.

Worse for Minnesota, the breadth was no accident. The original bill pointed to the narrow definition in the state’s own deepfake statute; the legislature had it on the table and chose the broader one, and the chief sponsor, asked in committee whether consensual images were covered, replied that this was intended. In American constitutional grammar, that sentence ends the conversation about a narrowing construction.

A forecast, probable though not certain: Judge Frank will block enforcement, at least as against xAI. The July denial says nothing about the merits; it was a ruling about urgency, not about who is right, and a typical display of judicial caution: better to hear the case properly on an expedited schedule than to hand down, in forty-eight hours, material for reversal. xAI’s own lawyer, for that matter, built the legislature a golden bridge, observing that a law which had passed unanimously could pass unanimously again in a narrower form. Counsel was rounding kindly: the House recorded one dissenting vote, the Senate none, though the arithmetic of the invitation survives the correction. That is not a declaration of war; it is an invitation to amend.

The Justice Department’s statement, filed on the eve of the hearing, rewards a slow read, because there is more industrial policy in it than constitutional law. Federal law, we are told, is carefully calibrated; Minnesota’s reaches further and threatens to paralyze the industry; and America is in a race with its adversaries for dominance in artificial intelligence. The brief invokes a Presidential executive order calling for a single national standard, preëmpting fifty divergent state regimes, and a January memorandum creating, inside the Department, a special litigation task force against state A.I. regulation. The irony is plain: a year earlier, the same Administration proudly signed the Take It Down Act and collected bipartisan applause for it. Yet there is no contradiction here, only a hierarchy: protection for victims, yes, so long as it costs the national champions nothing. Ask cui bono and the answer sits in the statement’s opening pages: national and economic security. For the other forty-nine states, the signal is legible: whoever regulates generative models more sternly than Congress will meet in court not only Big Tech but their own federal government.

Worth noting, too, is what the complaint does not say. xAI did not reach for Section 230, the shield that protects platforms from liability for other people’s content, although Minnesota’s statute expressly declares that it leaves the provision undisturbed. The choice was presumably deliberate: a Section 230 defense would require the thesis that someone else creates the images, which would undercut the suit’s central story of the plaintiff’s own expression and its tool of speech, and the shield’s application to the outputs of models that share in authoring the content is, in the scholarship, doubtful at best. The case thus remains a clean test of the question that will define the decade: whose speech is a model’s output, and who answers for it. If Minnesota could fine the provider for every image, other states could fine it tomorrow for every defamatory hallucination and every mistaken medical answer. That, not the memes, is what the game is about.

Musk appears in this dispute in a role he has cultivated for years: defender of civilization against the censors, herald of the family and of the birth rate, ally of the hard right on both shores of the Atlantic. In court, he speaks the language of free expression, of satire, and of art. Between the pulpit and the complaint, however, stands the product. Grok Imagine debuted in the summer of 2025 with a mode winsomely named “spicy”; a reporter for The Verge described how, on her first try, an innocent prompt about a music festival returned, unasked, a video of Taylor Swift undressed. Around the turn of the year came a wave of on-demand undressings of photographs of real women, and, according to researchers, of children, posted directly in replies on X: more than 4.4 million images in nine days, by the Times’s count, at least 1.8 million of them sexualized on a conservative reading; the Center for Countering Digital Hate’s statistical model put the sexualized total at just over three million. Malaysia and Indonesia blocked Grok; the attorney general of California opened an investigation, as did the British regulator; the European Commission ordered X to preserve its internal documents. The company’s first response to reporters’ questions was its stock line about the lies of the legacy media; only in mid-January did xAI restrict the editing of real people’s likenesses and promise geographic blocks where the law demands them. The chronology speaks: the Minnesota Senate committee debated House File 1606 in February, and the votes came in the second half of April. One may reasonably suppose that the law xAI now challenges passed all but unanimously in large part thanks to Grok.

The psychology of language performs here the work that Albert Bandura called moral disengagement. “Spicy” sounds like a seasoning, not like pornography wearing someone else’s face; responsibility diffuses among the user, who merely typed a request, the model, which merely erred, and the terms of service, which, after all, prohibited it. The company’s numbers, offered in the complaint as proof of vigilance, read from the other side as an examination of conscience: seventy thousand reports of suspected child-abuse material in seven months is not a moderation statistic, it is a product statistic. Musk has even sued one of his own users for circumventing the safeguards; a striking gesture, perhaps sincere, but it belongs to a familiar script in which the rotten apple is always guilty and the orchard never is.

There is a name for this style of public life, and it comes from professional wrestling, an industry in which the President sits, literally, in the Hall of Fame. Kayfabe is the convention by which scripted conflict is performed as real while everyone half knows better; the pleasure lies not in being deceived but in the shared wink. Read as kayfabe, the season’s plot assembles itself: a President publishes a synthetic body he does not have, in a pool he has not repaired; a moralist of the family sells a button labelled “spicy”; a Justice Department files a paper supporting no party on the eve of supporting one. None of it is exactly a lie, because a lie requires a speaker who cares about being believed. Harry Frankfurt reserved a blunter word for speech indifferent to truth, and that indifference is precisely what a generative model industrializes: fluent assertion with no one behind it who means anything at all. The First Amendment has long known what to do with the liar and the satirist. It has never before been asked what to do with an author who stakes nothing on being believed.

There is, however, one room in which kayfabe dies, and Musk has just walked into it. A pleading is a performative act in the oldest legal sense: counsel’s signature certifies the party’s contentions to the court. To win, xAI has had to state, on the record, that Grok’s outputs are protected expression and that the tool itself is an instrument of xAI’s own speech. The performance requires the thesis, and the thesis will outlive the performance: it prices every future hallucination, as noted above, in courtrooms where the First Amendment will offer far less shelter. Such is the quiet cost of theatre conducted by lawsuit: the script gets certified. And that, better than hypocrisy, explains the deeper incoherence of the camp: the same coalition that applauded last summer when Texas’s age-verification law survived now recites Ashcroft in St. Paul, because the attachment was never to a principle of speech, only to a roster of speakers. Wrestling has a word for that as well: whatever the storyline, the result is booked before the bell. The President’s joke, filed as a flagship exhibit, thus plays its final role: a human shield made of pixels.

Honesty requires two additions. First, xAI’s present safeguards appear to be real and do not lag the industry’s standard, and part of its case against the statute would be pressed by any maker of generative tools. Second, a plaintiff’s hypocrisy does not make a statute constitutional, and the court will rightly be deaf to it. The public, though, is under no duty of judicial restraint. Whoever builds moral authority on the defense of family and children, and monetizes a machine with a “spicy” mode, comes to a dispute over nudity as, at most, a witness, and certainly not a judge.

The sponsor’s sentence about deliberately covering consensual images, suicidal in an American courtroom, sounds familiar in Europe. In 1995, the Conseil d’État, France’s supreme administrative court, upheld a municipal ban on dwarf-tossing over the objection of the man being tossed, a performer named Manuel Wackenheim, who insisted that the work was his living: dignity, the court ruled in the Morsang-sur-Orge case, belongs to public order and is not at the individual’s disposal. The Polish Constitution says the same in its Article 30: dignity is inherent and inalienable, and inalienable means precisely that it cannot be waived or signed away. American law asks whether an image is speech; continental law asks whether an image is an injury. Both questions are necessary, and neither suffices alone.

There is, finally, a reason that synthetic nudity wounds even though “it isn’t me.” Sociology will call it the loss of control over self-presentation; psychology will call it objectification: another’s body handled as raw material. The oldest story of our culture has known it longer. The first human gesture after the loss of innocence was to cover the body; the shame of nakedness there is not prudery but knowledge, that a body is not a surface but a person. A law that cannot write that knowledge in the language of tests and amendments will keep returning to it by roundabout paths. Minnesota’s statute is such a roundabout path: technically defective, and faithful to an intuition it could not name.

Europe, for the moment, has chosen another technique: not a ban on capability but compulsory candor and the management of risk. The A.I. Act requires that deepfakes be labelled (Article 50); the Digital Services Act obliges the largest platforms, X among them, to assess and mitigate systemic risk, of which the Commission’s January moves against Grok were the first serious trial. In Polish criminal law, the nearest provision is Article 191a of the penal code, which punishes recording the image of a naked person by violence, unlawful threat, or deception, and disseminating the image of a naked person without consent; whether it reaches generated nudity, in which only the face is real, remains disputed among scholars, because the provision was written in the age of the camera, not of the diffusion model. The civil route is surer: one’s likeness, honor, and intimacy are protected as personal rights under Articles 23 and 24 of the Civil Code, with monetary redress, and in parallel runs the General Data Protection Regulation, since generating the fake means processing the biometric data of a face, a special category under Article 9 with its own stricter regime, no matter what has been drawn beneath it. Practice, as we argued at greater length in an earlier study of advertising deepfakes, teaches that none of these bases suffices alone: full protection comes only from their cumulation, alongside the underrated Article 190a § 2 of the penal code, which punishes impersonation by means of another person’s likeness, and Article 81 of the Copyright Act, the most formal ground and the easiest to prove. Sooner or later, the Polish legislature will face the same choice as Minnesota: punish the act, meaning the knowing, nonconsensual dissemination, as American federal law now does, or punish the capability, meaning the mere supply of the tool. The quarrel in St. Paul, watched from the banks of the Vistula, hints at which of those roads survives constitutional review, ours included, since the Polish Constitution joins freedom of expression (Article 54) to a proportionality test of its own (Article 31, section 3). For firms deploying generative tools, one piece of advice holds whatever the verdict: terms of service and a filter are not enough if the product’s architecture invites abuse; responsibility is designed into the product, not into the legal department.

Certain is this: the statute as written covers Presidential memes, self-portraits, and satire on equal terms with real harm, and it counts its penalties by the image. Probable is this: the court will halt enforcement, and Minnesota’s legislature, which passed the law with a single dissenting vote, will as readily pass a narrower one, with elements of non-consent, fault, and dissemination, and a harbor for providers acting in good faith. Uncertain is the thing that matters most: how far the courts will go in treating a model’s output as protected speech, because on that answer hang all the future liability regimes for artificial intelligence, from defamation to medical advice.

Minnesota will lose, most likely, not because it defended a trivial good but because it defended it too broadly. In disputes over technology, the winner is rarely the side that was right about the evil; it is the side that managed to name the evil precisely. The good itself remains: older than the First Amendment, and more patient than any model.

The law and the record described here are as of August 22, 2026

 

Further reading

A Face for Sale: Who Is Behind the Fake Celebrity Ads, and How Much Meta Makes on Them

The End of the Checkbox

Deepfakes – Your Face Is Not Yours Anymore