In 11 days between late December 2025 and early January 2026, Grok, the AI chatbot built into X, generated an estimated 3 million sexualized images. Users could upload a photo of anyone and prompt the tool to undress them, publicly, on one of the world’s largest social media platforms.
The fallout was swift: a Dutch court banned Grok from generating non-consensual intimate images, the EU voted to ban nudification apps, teenagers in Tennessee sued xAI and multiple countries blocked access entirely.
The Grok scandal was a product governance failure: A model shipped with no content policy, no guardrails, no output review. But bans and moderation only work against actors who comply with them. The deeper question is this: Once harmful synthetic content exists and is circulating, what tools does a victim actually have in response?
The answer today is almost none. The reason is that the victim recourse problem has three distinct layers, and we’ve only started building infrastructure for two of them.
What Is the Victim Recourse Problem for AI Deepfakes?
The victim recourse problem refers to the lack of tools for victims to challenge circulating synthetic media without exposing their personal identities or original photos. It consists of three technical layers:
- Layer One (Origin): Proving where content came from using cryptographic tags (e.g., C2PA).
- Layer Two (Detection): Tracing modified images across platforms using digital watermarking.
- Layer Three (Private Claims): Enabling victims to assert verifiable ownership and request takedowns anonymously using Zero-Knowledge (ZK) proofs.
3 Layers of Victim Recourse
Layer 1: Proving Origin
C2PA, an open standard backed by Adobe, Microsoft and others, attaches a signed record of origin and editing history to image files. Samsung now ships C2PA signing in the Galaxy S25’s camera. It’s a genuine step forward, but C2PA metadata currently gets stripped by virtually every social media platform that recompresses or converts images. C2PA 2.0 and the C2PA Trust List initiative are actively working on platform-side preservation, and Google’s integration of the technology into its search function signals momentum.
Yet today, the content most likely to need verifiable provenance is still the content most likely to lose it because most social media platforms, which are the primary distribution channel for content, routinely recompress and convert uploads, stripping C2PA metadata in the process. C2PA also embeds creator identity by design, which creates a doxing risk for abuse victims. And it can’t help with synthetic content that was never signed, which is exactly the situation with AI-generated deepfakes.
Layer 2: Detecting and Tracing Content
Digital watermarking embeds imperceptible signals in the pixel data itself, surviving screenshots, cropping and recompression. Generation-level watermarking (like Google DeepMind’s SynthID) marks AI outputs at creation. Platform-level watermarking, where platforms mark every image at upload, creates provenance anchors tied to uploader accounts, even for non-AI content.
Watermarks are more durable than metadata, but generation-level marking only works for compliant generators. Platform-level marking centralizes trust in platforms and ties the watermark to the victim’s account, reproducing the same identity-exposure problem as C2PA.
Layer 3: Making Private Claims
If someone wants to file a takedown or pursue legal action, they typically have to formally identify themself (name, account, contact information) and hand over the original photo as evidence. That creates new exposure risks where their real identity is linked on the record to the transformed content. Can a victim prove something about their relationship to harmful content without exposing their identity, original photos or metadata? This is the recourse problem. Nothing in the production toolbox addresses it right now. And it’s the layer that matters most to the person who was harmed.
ZK Is the Path to the Third Layer
Zero-knowledge proofs allow one party to prove a statement is true without revealing the underlying data. This is what makes ZK uniquely suited to victim recourse: It lets someone prove something about content while keeping themselves private.
A victim with a device-signed original can prove they possess the authentic photo, that it was cryptographically signed at a specific time and that it predates the synthetic content, all without revealing the image, their identity or their metadata. If the circulating content is a deterministic transformation of the original (cropped, resized, rotated), ZK can prove that relationship directly. This covers the category of manipulation that happens routinely when content moves across platforms.
Generative manipulation is harder to solve. A nudified image isn’t a crop or resize. It’s a generative reconstruction that’s technically new pixel data. Proving that relationship inside a ZK circuit requires perceptual similarity primitives and is a research problem. For some primitives, you’d need a ZK proof to prove the similarity between an AI-generated photo and the original source. For example, something like neural embedding similarity can be used to say, “My original photo is within threshold distance of the face embedding in the deepfake.” The gap between “someone reshared a modified version of my photo” (provable now) and “someone ran my photo through a nudification model” (requires unsolved primitives) is big and complex.
But the framing matters. The question isn’t whether ZK solves every aspect of victim recourse today. It’s whether any other technology offers a credible path to the third layer at all. C2PA is designed for provenance, not private claims. Watermarking is designed for detection, not victim agency. ZK is the only primitive that lets a victim assert a verifiable relationship to content without surrendering their privacy.
How the Layers Connect
These technologies aren’t competing. They’re complementary.
C2PA creates cryptographic anchors at capture. Watermarking marks content durably across distribution. ZK lets victims make private claims against those anchors. The practical link is discovery: watermarks and perceptual hashes serve as lookup keys into a registry of ZK proof claims, connecting circulating content to a victim’s assertion.
The most promising convergence is between platform-level watermarking and ZK. If platforms watermark every upload, they create durable anchors at scale, including for photos that were never device-signed. ZK then lets victims make private claims against those anchors without exposing their account or identity. The watermark provides traceability. ZK provides privacy. Neither is sufficient alone.
The Hard Constraints on ZK Deployment
The Anchor Problem Is Real but Narrowing
ZK proofs need a cryptographic anchor. Device signing (C2PA) provides the strongest. Samsung’s Galaxy S25 is the first consumer camera app to ship with it, but the infrastructure is broader than one phone. Qualcomm’s Snapdragon 8 Gen 3 supports C2PA at the chip level, meaning many Android OEMs could enable signing. Likewise, Truepic has offered device-level signing in enterprise contexts for years.
The trajectory is toward ubiquity, but consumer adoption is still early. Platform-level watermarking could extend anchors much further, though it depends on adoption. Photos that predate all of this infrastructure, which constitute the current attack surface, have no anchors and may never have them. This architecture protects future victims, not current ones.
The UX Problem Is As Hard As the Cryptographic One
Victims are often teenagers and everyday people with no technical expertise. For this to matter at scale, it needs to be invisible: cameras that sign by default and reporting flows that generate proofs automatically. This follows the same pattern that made end-to-end encryption ubiquitous through iMessage and WhatsApp, but it requires platform commitment that hasn’t materialized, such as through preserving C2PA metadata through upload pipelines whilst ensuring privacy and security of the metadata using ZK proofs. Additionally, watermarking every image at upload creates durable anchors at scale.
Legal Admissibility Is Untested
ZK proofs are mathematically verifiable, but no court has established admissibility standards. This will evolve, but there’s a gap today. Here, the best path is to pursue such solutions before it gets into any form of litigation, such as directly with the platforms. We could start introducing these frameworks as supplementary evidence and build a body of such cases to create a precedent. Advocacy groups could start pushing ZK-based approaches to prove facts without having to reveal the victim’s identity.
What Builders Should Take From This
We have emerging infrastructure for proving origin and detecting synthetics. We have almost nothing for the third layer: enabling victims to make private, verifiable claims. ZK is the only credible path to that layer, and parts of it are buildable today, even as the harder primitives mature.
The EU has banned nudification apps, as has the state of Minnesota. The UK has criminalized AI-generated non-consensual intimate images. Regulatory pressure is accelerating. Organizations that build toward this layered architecture now will be positioned to offer meaningful victim recourse. Those that wait will find themselves where Grok was: no infrastructure for accountability, facing victims with no tools for response, in a legal environment that has already decided this is unacceptable.
