Italy launches an investigation into Telegram bots that make fake nudes from women's photos, after researchers found 100K+ images shared on its public channels
The bots were found to be generating fake nude images of unsuspecting women — The Italian Data Protection Authority has started …
Context & Ripple Effects
Days after researchers documented a bot that turns photos of women into fake nudes — with 100K+ images already shared in public Telegram channels by July — Italy's Data Protection Authority has opened a formal investigation. The probe converts a researcher disclosure into a regulatory case against Telegram itself, not just the bot's anonymous operators.
The timing matters: a month after discovery, researchers reported the bot was still operating and Telegram had done little to stop it, and later reviews found the problem had scaled to 50+ bots claiming 4M+ monthly users by 2024. Italy has form here — it previously fined Cloudflare €14.2M for refusing to block pirate sites on its DNS resolver, so the DPA's willingness to act against infrastructure-level refusals is established.
First-order effects
- Telegram is now a named subject of an Italian data-protection investigation, with the researchers' 100K+ image findings serving as the evidentiary basis — its moderation of bot-generated nonconsensual imagery becomes a formal compliance question rather than a public-relations one.
- The bot's operators face exposure of the kind that previously led Telegram to remove CSAM and ban a responsible user, but at the scale of a tool rather than a single account.
Second-order effects
- If Telegram's response stays as limited as researchers documented in the month after discovery, Italy's DPA has a template — the Cloudflare €14.2M fine — for monetary penalties against platforms that decline to act, and other EU regulators can replicate the case file.
- The later finding that Italian and Spanish Telegram groups were trading nonconsensual images alongside spyware sales and doxing means the investigation's scope could expand from one bot to the ecosystem of paid tools around it.
Third-order effects
- The structural shift is from policing individual images after they spread to assigning liability for the AI tools that mass-produce them — the 50+ bot ecosystem documented by 2024 shows that takedowns of single bots do not dent the supply.
- For platforms hosting user-created automation, the pattern points toward a duty to vet what bots can generate before distribution, not just react to reports — a compliance burden that favors platforms with proactive moderation infrastructure.
The trend: Regulators are moving from removing nonconsensual AI imagery after it spreads to investigating the platforms and bot ecosystems that mass-produce it, with Italy's data-protection authority as the test case.