A peer-reviewed study examined the infrastructure behind 88 websites hosting non-consensual intimate imagery, including AI-generated material, and identified five providers as prominent service suppliers. The researchers’ findings, reported by 404 Media, put a practical question on the table: what responsibility should infrastructure companies take when harmful material is hosted on sites using their services?
Watch Desk analysis
What happened
The researchers searched for 400 URLs over six weeks between February and March, then narrowed the sample to 88 sites they found actively hosting non-consensual intimate imagery. They used open-source web-analysis tools to identify services associated with those sites.
In the study, the researchers identify Cloudflare, Google, Namecheap, WordPress and Proton as dominant providers in different parts of the infrastructure. Their account says Cloudflare supplied a range of services, Google supplied SSL certificates and advertising to many sites, Namecheap was a prominent domain registrar, WordPress software was widely used, and Proton supplied mail services. These are findings about the sample, not proof that any provider knowingly supported abuse.
Why it matters
The report turns attention from the people making abusive images to the less visible services that can help websites stay online, find audiences or operate. That does not make every service provider responsible for every customer’s content. It does make detection, reporting and decisions about withdrawing services part of the debate.
The distinction matters: WordPress’s spokesperson told 404 Media that WordPress.org is open-source software, not a host, and does not control independently hosted sites. Researcher Hany Farid disputed the breadth of that distinction, pointing to WordPress.com hosting and other Automattic services. Google said it has policies against non-consensual explicit content and described removal and advertising enforcement measures. Cloudflare, Proton and Namecheap did not respond to 404 Media’s requests for comment, according to the report.
Our read
This is a useful map of a distribution problem, not a verdict on the knowledge or conduct of each named company. The study’s small, targeted sample cannot establish how common these arrangements are across the web. Still, the details give platforms and researchers something more concrete to argue over than the familiar promise to “do better”.
What to watch
- Whether the researchers publish the site list or further detail about how services were classified.
- Whether the named providers explain how they investigate reports and decide when to suspend services.
- Whether other researchers reproduce the findings with a larger or different sample.
Discussion spark: When a provider’s services are used by a site hosting non-consensual intimate imagery, what evidence should be enough to justify suspending that service?
Sources and evidence
- Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds (30 September 2026, 16:02 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.