In June 2026, the Canadian government passed a groundbreaking reform of the Criminal Code — the Protecting Victims Act (Bill C-16). This strengthened protections against gender-based violence and, for the first time, made it a crime to share sexual “deepfakes” of a person without their consent. That same month, Parliament amended the Elections Act to address political deepfakes in Bill C-25 and tabled the Safe Social Media Act (Bill C-34) — a major initiative looking to regulate social media and chatbot services. Despite these efforts, the issue of AI-generated, non-consensual intimate imagery remains inadequately addressed.The industry built around “nudifying” apps was valued at US$36 million per year in 2025. It has involved multiple large-scale scandals, such as the one in early 2026 when the social media platform X’s chatbot Grok generated up to 200 non-consensual sexualized deepfakes per minute, including 23,000 images that appeared to depict children.This is a rising form of abuse, and significant legal gaps remain. Correcting them is essential to protecting victims.The realism gapA new definition of “intimate imagery” emerged in the latest criminal reforms and in the proposed Safe Social Media Act. To count as illegal “intimate imagery,” a depiction has to be “likely to be mistaken for a visual recording of that person.” It has to be realistic enough to pass as a genuine photo or video. The Canadian Bar Association had already raised the issue this poses: when an image can easily be interpreted as synthetic, it can slip outside the law’s reach.Add elf ears to a person or set the scene in outer space, and the image’s distributor may have a ready-made legal defense, even though the victim’s face and the consent violation remain the same. This might even extend to AI-generated content that is labelled or watermarked as such. This conception mischaracterizes the harm of image-based abuse: people are not harmed because non-consensual sexualized deepfakes deceive viewers; they are harmed because their likeness is used in ways they did not consent to, thereby violating their sexual privacy. The law should depend on whether a victim is identifiable and has consented to the given use of their likeness, not on how realistic the forgery looks. This BBC World Service documentary explains the history, use and abuse of deepfake imagery. The accountability gapThe criminal reforms also focus solely on the person who distributes an illegal intimate image, leaving out a whole chain of entities who sustain a deepfake’s lifecycle online. The person who creates the image, the people who ask them to or who pay for it, the people who amplify the image by liking, resharing or leveraging it for extortion or other types of abuses all contribute to the problem of deepfake-based sexual abuse. All contribute to its normalization as a broader practice of gender-based violence. Researchers and victims alike agree that the harm begins at creation of an image, not distribution; and that both should therefore be prosecuted. Read more: Grok fallout: Tech giants must be held accountable for technology-assisted gender-based violence Fabricating a sexual image of an identifiable person without their consent is itself a violation of sexual privacy, regardless of whether it’s ever posted. Growing marketplaces now exist to facilitate creation, and the communities that support and serve as entry points for these ecosystems freely prosper online. These enablers of AI-generated non-consensual intimate imagery remain largely unaffected by current and proposed laws.Other countries have already moved past this narrow, distributor-centric approach. For example, under the United Kingdom’s 2025 Data (Use and Access) Act, it is an offence not just to share such images, but also to create them or request their creation, or to integrate specific features within them.South Korea has gone even further, criminalizing possession and consumption of AI-generated non-consensual intimate imagery as well as distribution and creation. And even in Canada, the Elections Act amendments criminalized solicitation and creation of politically deceptive deepfakes. All signs point to a global recognition of the wide variety of people who facilitate deepfake sexual abuse.The prevention gapThe third gap is in the timing of responses. Canada’s criminal reforms and proposed Safe Social Media Act are both built to respond after damage is done. An image is created, shared, reported and eventually taken down after a victim signals it, by which point it may reasonably have already spread online.Bill C-34 even explicitly states: “Nothing in this Act requires an operator to proactively search content on a regulated service that it operates in order to identify harmful content.”This is, again, misaligned with the nature of deepfake-based sexual abuse. This form of gender-based violence is a preventable harm of generative AI, that is now well-documented and has been for years.The growing consensus among researchers and the public is that companies providing critical infrastructure for this abuse foreseeably amplify this harm and should play an active role in avoiding it. There are numerous avenues, both technical and legal, that could help us move in this direction. We could strengthen model safeguards of image generators before release. We could take down “nudifier” apps and other tools. We could moderate these ecosystems. Laws that only act post-hoc accept that the crux of the harm will have already occurred before coming into play.Systematic gender-based violenceCanada is one of the few countries to have moved forward on AI-generated non-consensual intimate imagery.Still, the current framework treats deepfake-based sexual abuse as isolated criminal behaviour, rather than what the evidence shows it to be: a systematic and increasingly normalized form of gender-based violence. We need to close these gaps — grounding the law in identifiability rather than realism, reaching everyone involved in a deepfake’s lifecycle rather than just the distributor, working towards preventive measures instead of reactive mitigations. This is how Canada can turn these landmark reforms into a framework that actually protects victims of technology-facilitated gender-based violence.Anne Imouza receives funding from the FRQSC and the Tomlison Doctoral Fellowship. Catherine Régis receives funding from CIFAR AI Chair Program, Fonds de recherche du Québec, IVADO and Canadian Institutes of Health ResearchReihaneh Rabbany receives funding from CIFAR AI Chair program, IVADO, MITACS, NSERC, and FLI. She is affiliated with Mila and CSDC. Emma Kondrup does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.