Apple reports more than 800 million weekly visitors to its App Store. That looks like a distribution number. It is becoming an enforcement number.
Key takeaways
- App-store control is being repriced: the same power antitrust authorities view as a potential tool of exclusion gives regulators a fast, centralized way to restrict AI-enabled abuse.
- San Francisco’s demand that Apple and Google remove 13 nudification apps shows why authorities target distribution layers: stores provide identifiable operators, review systems, and revocation mechanisms.
- Removing an app can reduce mainstream exposure but cannot eliminate access through websites, messaging platforms, or other distribution channels.
- Effective policy must preserve narrowly defined emergency-removal authority while imposing transparent evidence standards, timely appeals, and safeguards against commercial exclusion.
- As generative tools increase submission volume and blur the line between legitimate and abusive software, verification and judgment—not software creation—become the scarce resources.
San Francisco’s City Attorney sent Apple and Google legal notices demanding that they remove 13 apps used to create deepfake nude images.
The disparity explains a regulator’s leverage. It does not need to identify every download, payment, developer account, or victim before acting against distribution. It can address the operator that controls admission and revocation for a consumer surface visited by more than 800 million people each week.
The store is not the whole system, but it is an unusually legible control point inside a system becoming harder to see.
AI abuse turns review into revocation
For years, Apple set the rules, developers submitted software, and Apple accepted or rejected it. Public fights centered on quality, security, competition, and commissions.
Generative abuse turns rejection into an enforcement tool. When developers package a harmful capability as a consumer app, the store operator can interrupt its distribution without first finding every user. That is deployment-layer control: the ability to reduce reach at the boundary where software becomes broadly available.
In April 2024, Apple removed three AI image-generation apps after reporting found that they advertised the creation of nonconsensual nude images. In July 2026, a city attorney demanded removal of 13.
The episodes moved from three apps removed after media reporting to 13 apps named in a legal demand. By 2026, a city attorney—not only a newsroom—was initiating action through legal notice.
The record does not establish how many apps the stores ultimately removed. Parallel coverage disagreed on whether Google had deleted five apps or all 13, leaving no comparable takedown count. The enforcement demand is established; the completion rate is not.
Nor is an app-store takedown a complete remedy. More than 1.4 million Telegram accounts had signed up to 39 deepfake-creation bots. Web services and messaging systems remain available after a store removes an app, giving developers and users alternate routes around the rule.
A store takedown need not eliminate access to matter. Like a fire door, it can still reduce exposure at a boundary millions already use.
Safety depends on discretion antitrust constrains
That same week, Apple and the U.S. Department of Justice were reportedly in early settlement discussions over the DOJ’s 2024 antitrust lawsuit. Unnamed sources described preliminary talks, not a confirmed agreement.
Together, the antitrust case and San Francisco’s letters expose the same mechanism from opposite sides. The DOJ’s case treats unilateral control over iPhone software distribution as a potential source of exclusion. San Francisco treats that control as a source of speed. The DOJ asks why Apple may remove an app; San Francisco asks why it has not. Both turn on the same act, with the legal valence determined by its target.
Apple cannot resolve the conflict by relabeling gatekeeping as safety. Developers in the European Union reported that Apple was denying or delaying notarization for some apps intended for alternative stores, including emulators. Apple later approved the Epic Games Store only after Epic said it had been blocked over buttons and labels resembling those in Apple’s own store.
Those disputes show why broad discretion is not an uncomplicated public good. Apple can remove abusive software quickly, but it can also delay a rival. Speed serves the public only when transparent standards constrain it.
Apple’s distribution control already has a commercial price, visible in the broader structure of one ecosystem with many tollbooths. AI harms add a second price. Public authorities now have reason to preserve some of the intervention capacity they have spent years trying to limit.
Because Apple already holds this power, policymakers must decide which uses remain legitimate when competition policy and public safety issue opposing orders.
Cheap creation makes judgment scarce
Generative tools change both sides of the review queue. They lower the effort required to produce software while blurring the line between a legitimate image tool and a product designed, marketed, or easily repurposed for abuse.
Developers reported in March that an influx of vibe-coded apps was pushing App Store review waits to multiple weeks. More submissions were entering the system as consequential decisions became less mechanical.
In 2023, Apple said developers would need to explain their use of certain APIs to prevent fingerprinting misuse. In 2026, it said apps in saturated categories could be removed if they were not updated, improved, or attracting customers.
Reviewers must now weigh safety, privacy, quality, maintenance, and commercial judgment in the same queue. Each rule can look reasonable while the combined system becomes slower and less predictable.
Reviewers can classify a plainly malicious app. A general image generator with abusive prompts, suggestive marketing, weak safeguards, or an evasive developer is harder. Reviewers must infer intended use from incomplete evidence, and revocation must survive appeal.
When generative tools make creation cheap, reviewers spend more on verification and judgment; volume and ambiguity multiply that burden.
As submissions multiply, simple admission matters less. Apple faces the harder task of identifying the small set of apps that warrant removal without turning every uncertain case into a discretionary veto.
Liability follows the layers that create scale
Lawmakers first targeted the creation of deepfakes. They have widened the perimeter toward the systems that host, distribute, and amplify the result.
California enacted election-deepfake laws that include liability for large platforms that fail to remove reported content. Across the United States, states enacted more than 120 deepfake-related laws from 2023 onward, including 26 in 2025. Legal experts have also argued that Section 230 is unlikely to shield companies from liability for generative-AI outputs.
None of those facts automatically makes an app store liable for every output generated by software it distributes. Model makers, app developers, hosts, marketplaces, and operating-system providers perform different functions, and law rarely maps neatly onto a stack diagram.
Regulators are nevertheless moving toward each layer that makes synthetic abuse scalable. They now look beyond the person who pressed “generate” to the institution that can reduce reach after receiving notice.
When regulators impose a removal duty, they shift some of the cost of abuse from victims, schools, employers, police, and courts toward the operator that controls distribution.
Regulators target app stores not because they caused every harmful image, but because they offer named counterparties, review processes, and revocation mechanisms. Synthetic-abuse networks offer few of those things.
Open distribution still requires an accountable boundary
Apple has said its proposed iOS and App Store changes seek to preserve as much control as possible while complying with Europe’s Digital Markets Act. Phil Schiller has separately described the risk that mandated third-party stores could expose iPhone users to harm.
Apple has an economic interest in making that argument, but it can still be right about the security mechanism; motive does not settle function.
Opening distribution reduces one company’s ability to exclude rivals, but it also fragments enforcement across marketplaces, developers, payment systems, notarization, and operating-system controls.
The meaningful policy variables are scope, trigger, evidence, appeal latency, and emergency authority. Who may revoke access? On what showing? For how long? Which decision can be challenged, and before whom? Policy must provide both appeal and emergency intervention; without the first, removal becomes arbitrary, and without the second, review becomes ceremonial.
Policymakers therefore need contestable interoperability rather than frictionless openness. Alternative distribution can coexist with narrowly defined removal authority. The hard part is preventing safety authority from becoming commercial exclusion while preventing due process from becoming delay by another name.
Apple’s store is still a market. It sells access, discovery, and convenience. But the 13-app demand reveals another asset embedded in the same machinery: the ability to revoke distribution across a vast consumer boundary.
That is what the opening number measures now—not merely weekly visitors, but the reach of a public control point. Eight hundred million reasons the gate cannot be valued only as a tollbooth.
The scale behind the enforcement leverage
| Measure | Evidence | Why it matters |
|---|---|---|
| Apps named in San Francisco’s removal demand | 13 AI apps | A regulator can direct a limited legal demand at the stores controlling distribution. |
| App Store reach reported by Apple | More than 800 million weekly visitors | One store-level decision can affect access across a vast consumer boundary. |
| Date the legal notices were recorded | July 18, 2026 | By 2026, a city attorney was using formal notice to seek app-store enforcement. |
Frequently asked questions
Why are regulators targeting Apple and Google instead of individual AI-app users or developers?
App stores are legible control points with named operators and the ability to revoke distribution at scale. Regulators can act through those mechanisms without first identifying every user, download, payment, or victim.
Did Apple and Google remove all 13 apps named by San Francisco?
The legal demand is established, but the final removal count is not. Parallel reporting disagreed about Google’s actions, so the piece does not claim a complete takedown.
Can an App Store takedown stop deepfake abuse?
Not completely: web services, messaging systems, and alternative distribution can remain available. A takedown can still reduce exposure at a major consumer boundary even when it does not eliminate the underlying capability.
How does AI-safety enforcement conflict with antitrust policy?
Safety enforcement assumes Apple can quickly remove harmful software, while antitrust scrutiny questions whether its unilateral distribution control can exclude competitors. The same discretion can serve public protection or commercial foreclosure depending on its target and constraints.
What rules could balance safety with competition?
The piece argues for contestable interoperability: alternative distribution combined with narrowly scoped removal powers. Rules should define the trigger, required evidence, duration, emergency authority, and appeal process for revocation decisions.