LikeWard
News9 August 20267 min read

AI Girlfriend Generators: Where the Law Stands Now

AI girlfriend generators draw 14,800 US searches a month. What the law now says about the category — and where the real exposure sits.

By LikeWard Compliance Desk
Legal paperwork on a desk, illustrating the law now applying to the AI girlfriend generator category

Photo via Unsplash

The AI girlfriend generator category draws roughly 14,800 US searches a month with a competition index of 1, on Keyword Planner data we pulled in August 2026. That makes it one of the largest consumer AI categories almost nobody writes about seriously. Meanwhile "take it down act" runs at 9,900 a month and rising. Those two numbers describe the same story from opposite ends.

This piece sets out what the law actually says about the category in mid-2026 — which parts are genuinely prohibited, which are merely regulated, and where the practical exposure sits for anyone operating in it.

Key takeaways

  • The category is not illegal. A specific subset is.
  • The dividing line is whether an identifiable real person is depicted without consent.
  • Resemblance, not naming, is the test. "We never used her name" is weak.
  • Operators carry duties independent of who typed the prompt.
  • Payment and app-store policy bite faster than any statute.

Contents

Two very different products, one search term

The search term hides a split that matters enormously.

Invented personas. Generated characters resembling nobody. No consent question exists because there is no person. The obligations are age assurance, content standards and consumer protection — real, but ordinary.

Real-person likeness. Output depicting an identifiable individual. Here publicity rights, intimate-image offences, platform removal duties and card-network consent requirements all attach at once.

Same search term. Radically different risk. Most coverage of this category collapses the two, which is why so much of it is either alarmist or useless.

What is actually prohibited

Narrower than headlines suggest, and sharper than operators assume:

Sexual or intimate imagery of an identifiable person without consent. Criminalised in a growing number of jurisdictions and extended to synthetic depictions in the UK and several US states. This is the hard prohibition.

Any depiction of a minor. Absolute, everywhere, with no consent-based exception and no argument that the subject is synthetic. This is why LikeWard makes minors contexts one of four non-waivable prohibitions evaluated before creator rules and before the age gate — a verified adult account gets refused just the same.

Non-consensual framing. Depictions presenting a person as coerced or unwilling. Prohibited platform-wide on any serious service, and a category no consent can license.

What is regulated but permitted

Most of the category, in fact:

  • Invented personas — permitted, subject to age assurance and content standards.
  • Licensed real-person imagery — permitted where consent is genuine, scoped and evidenced.
  • Non-intimate imagery of real people — messier, and jurisdiction-dependent. Publicity rights bite on commercial use in many US states.

That middle row is where a licensed marketplace sits, and the operative word is evidenced. Consent you cannot produce on demand is functionally the same as no consent when an acquirer asks — the argument we made in the card network consent rules guide.

The identifiability trap

The most common operator mistake, and worth stating plainly.

The test is generally whether an ordinary person could recognise who is depicted — not whether the output carries a name. So:

ApproachOperator assumptionActual position
Named real personClearly riskyCorrect
Unnamed but recognisable"We never used her name"Still caught — resemblance is the test
Composite of several real people"It is not anyone"Depends on whether anyone is recognisable
Wholly inventedNo exposureCorrect, until reference uploads are added
User-uploaded reference photo"The user provided it"You are now producing likeness output

Table: how operators typically read identifiability against how it actually works. The last two rows are where invented-character products quietly change category.

That final row deserves emphasis. Accepting a reference photo turns every user into a potential source of unlicensed likeness, and it is the single most common way a product with no consent obligations acquires them overnight.

Where enforcement actually comes from

Not primarily from prosecutors. In rough order of how often operators encounter it:

Payment processors. Fastest and most decisive. Card networks require documented consent and verified age for adult content merchants; acquirers enforce it on their own timetable, and losing processing does not wait for a hearing.

App stores and infrastructure. Policy-driven, unilateral, and effective within days.

Regulators. Ofcom under the Online Safety Act 2023, the FTC under the TAKE IT DOWN Act. Slower, but the penalties scale with revenue.

Private claimants. Publicity-rights and civil claims. No prioritisation, no capacity constraint beyond willingness to file.

"Operators prepare for the regulator and get taken out by the acquirer. We have never once heard it happen the other way round." — LikeWard compliance desk

What operators should do

Whichever half of the category you are in:

  1. Decide explicitly whether you produce real-person likeness. Then enforce that decision in code, not in a policy document.
  2. If you do, get scoped consent you can produce per output. Not a generic release — a versioned, machine-readable permission plus a record on each output.
  3. Fail closed on age. Unverified account, no output.
  4. Prohibit the absolute categories platform-wide and evaluate them before every other rule, including the age gate.
  5. Build removal before you need it. 48 hours, evidenced, reachable by non-users.
  6. Watch for drift. Reference uploads and "inspired by" personas change your category without changing your terms.

A worked example of how this goes wrong

Consider a small team shipping an image generator with invented personas. Clean start, no likeness question, a working age gate. Everything in order.

Six months in, retention is flat, and the obvious growth lever appears: let users upload a reference photo so the persona resembles someone they choose. It ships in a fortnight. Usage climbs.

Nothing in the terms changed. Nothing in the marketing changed. But the product is now producing likeness output of identifiable real people at scale, on the basis of consent nobody obtained, with no record of what any depicted person permitted — because no depicted person was ever party to anything.

The bill arrives in a familiar order. A subject finds an image and reports it, and the platform has 48 hours to remove it and known copies without any way to identify which other outputs used the same reference. A chargeback cluster triggers an acquirer review that asks for consent records that do not exist. A journalist joins the two together. Each event is survivable alone; arriving inside a fortnight, they are not.

The instructive part is that nobody made a bad decision. A product team shipped a requested feature. What was missing was a rule connecting "we accept reference photos" to "we are now a likeness platform" — and that rule lives in an architecture review, not in a legal opinion.

Practical tests for your own product

Five checks, each answerable in an afternoon:

  • Can a user get a recognisable real person out of your system? Try it. Not in theory — actually try it, with a public figure and with an uploaded photo.
  • Does anything in your stack record who permitted what? If the honest answer is "the terms of service", you have no per-output record.
  • What happens on a report today? Time it. If nobody knows, the 48-hour question is already answered.
  • Is your API looser than your UI? The loosest path is your real policy, whatever your website says.
  • Would a rephrased prompt get through? Text normalisation matters here: folding accents, homoglyphs, spaced letters and digit substitutions before matching is the difference between a rule and a suggestion.

What this means for creators

If you are the person whose likeness this is about, the useful reframe is that unlicensed generation of you is happening regardless of what you do. Your options are not "AI imagery of me exists" versus "it does not". They are "it exists with a documented position from me" versus "it exists with nothing".

A published boundary set is a dated, scoped, revocable statement of your terms that a platform enforces before producing anything, and that you can point at afterwards. How to license your likeness covers the practical steps.


Related: the companion app comparison, the deepfake law round-up, and the full risk breakdown of unlicensed generation.

Frequently asked questions

Are AI girlfriend generators illegal?
The category as such is not illegal, and saying it is would be wrong. What is increasingly unlawful is a specific subset — sexual or intimate imagery of an identifiable real person produced without their consent — and separately, operating any age-restricted service without effective age assurance. A generator built on wholly invented personas with a working age gate is doing nothing prohibited.
What is the 'identifiable person' test?
Broadly, whether an ordinary person could recognise who is depicted, rather than whether the output is labelled with a name. That means an unnamed persona modelled on a real individual can still be caught, and it is why 'we never used her name' is a weaker defence than operators expect. Resemblance is the risk, not attribution.
Does the operator or the user carry the liability?
Both, on different theories, which is why pointing at the user does not resolve much. The user may commit an offence by creating or sharing particular content. The operator carries platform duties — prevention, removal within a stated window, age assurance, record-keeping — that exist independently of who typed the prompt.
Can we avoid all of this by only offering invented characters?
You avoid the likeness and consent problems entirely, which is the largest part of the exposure. You still carry age assurance, content standards, consumer-protection and app-store obligations. The one thing to watch is drift: reference-image uploads and 'inspired by' personas are how invented-character products quietly become real-person products.
Why does search volume matter to a legal question?
It does not change what the law says, but it does predict enforcement attention and commercial pressure. Regulators, journalists and payment risk teams all watch category size, and a term drawing 14,800 US searches a month is not going to stay unexamined. Volume is a timing signal, not a legal argument.