SF CITY ATTORNEY DEMANDS APPLE AND GOOGLE REMOVE 13+ NUDIFY APPS
David Chiu sent cease-and-desist letters accusing the platforms of “aiding and abetting” the spread of nonconsensual intimate images.
by editor5 min readcomments soon

San Francisco city attorney David Chiu ordered Apple and Google to pull 13 AI-powered nudify apps from their stores, warning that the companies are "aiding and abetting" the creation and distribution of nonconsensual intimate images. The letters, reviewed by Wired, target apps that let users upload a photo of any person and generate a nude version, often for harassment and humiliation.
The apps do not strain to find. Search terms like or return results on both platforms. Many carry a rating, meaning children can download them. One app passed a million downloads before Chiu's office moved, and its description advertised the ability to and create videos.
Chiu called the situation horrifying, adding that these images are used to bully, humiliate, and threaten women and girls, with devastating impacts on reputation, mental health, and autonomy, and that his office has seen victims who have been suicidal.
THE APPS HIDE IN PLAIN SIGHT
The 13 apps flagged in Chiu's letters are not a complete inventory. Researchers have warned for months that the real number is far larger. A preprint paper published in May identified 420 apps marketed as generic face-swapping tools. Of 155 tested, 70 per cent could be used to sexualize images. The apps pass moderation by advertising one feature (swapping faces into video, adding makeup) while hiding the nudification capability behind a paywall or a secondary interface.
Apple and Google both have policies that forbid sexual content. Google's Play Store prohibits pornographic material, and Apple's App Store guidelines are similarly strict. Yet the nudification apps were not just present: some were actively promoted through search and recommendations.
The Tech Transparency Project found that nudification apps frequently sailed through the review process. An app rated is a direct pathway to a child's phone. Chiu's office discovered that minors were being targeted by classmates who took a school photo and ran it through one of these tools.
GOOGLE ACTS, APPLE IS SUPER QUIET
Google responded to Chiu's letter by saying it had already removed "hundreds" of nudification apps from Google Play, including five that Chiu's office specifically flagged. A Google spokesperson said the company's policies forbid harmful content and that it takes "swift action" against violations. The company also said it had restricted search terms to make them harder to find.
Apple did not provide a comment for this story. The company has not addressed this issue. When researchers from the Tech Transparency Project reported similar findings earlier this year, Apple removed some apps but offered no public statement. The company also declined to comment when Ars Technica reached out.
The contrast matters. Google at least acknowledges the scale of the problem: it knows there are hundreds of these apps. Apple's silence suggests either a lack of enforcement in its store or a reluctance to acknowledge the failure.
THE MONEY BEHIND THE ABUSE
Chiu told Wired that Apple and Google have likely made millions from in-app payments flowing through the offending apps. Nudification tools are not free. They charge for credits, subscriptions, or per-generation fees. The app store cut (15 to 30 per cent) flows directly to the platform.
That financial incentive creates a perverse dynamic. As long as the apps are profitable and pass the initial review, the platform has little reason to look deeper. Chiu's letters argue that this amounts to supporting a service that violates California law. The state prohibits products that aid in creating deepfake pornography, and the letters warn that the app stores may be legally liable.
A PATTERN LARGER THAN THE STORE
The nudify app problem is a symptom of a broader failure across the industry. Meta's Oversight Board recently called on the company to strengthen protections for people targeted by deepfakes. Elon Musk's xAI has been sued multiple times over nonconsensual deepfakes generated by Grok, and the company itself filed a lawsuit against a user it accused of prompting the chatbot to produce child sexual abuse material.
That last case has direct relevance to the app store question. Apple told Senators in April that it had privately threatened to remove Grok from the App Store. The xAI app remains available. The same pattern emerges: threats are made, but the products stay.
Chiu is not asking for a policy change. He is asking Apple and Google to enforce the policies they already have. The letters name 13 apps, but the message is aimed at the platforms themselves. If they continue to host software whose only purpose is to generate intimate images without consent, the city attorney is prepared to escalate.
NO GAMES, NO SAFE HARBOUR
The letters do not name the apps. Wired and other outlets withheld the names to avoid driving traffic to them. That is a journalistic choice, not a legal one. The apps exist in a grey area where their descriptions say one thing, but their functionality is abusive.
Chiu's demand is simple: remove them and keep them removed. Google has shown it can find hundreds. The question is whether Apple will do the same, or whether the company will wait for a court order to act.
The cost of waiting is not abstract. Every week an app stays live, more photos are uploaded, more children are victimized, and more teenagers learn that they can humiliate a classmate with a few taps.
Chiu's letters are a warning shot. The industry should treat them as the start of something bigger.
what did you make of it?
more from cybersecurity
cybersecurity
TWO SCATTERED SPIDER HACKERS JAILED FOR 5.5 YEARS OVER TFL ATTACK
The attack cost London’s transport authority an estimated £29 million and forced 27,000 employees to reset passwords in person.
cybersecurity
ASSURANCEAMERICA DATA BREACH EXPOSES OVER 6.9MN DRIVER'S LICENSE NUMBERS
A targeted phishing attack on a single employee kicked off a breach that went undetected for months.
cybersecurity
OPERA DID WHAT CHROME AND EDGE STILL STRUGGLE WITH
Opera's paste protect screens every copied command before it runs. no other major browser does this natively.
cybersecurity
NEW GITHUB ATTACK USES PROMPT INJECTION TO TRICK AI CODING AGENTS
A repo with zero malicious code can silently own a developer's machine the moment an AI tool touches it.





