Tasmanian School Students Reportedly Created Purported AI-Generated Pornographic Images of Female Classmates

Five male students at The Friends' School in Hobart, Tasmania, created and shared non-consensual pornographic deepfake images of 21 female classmates. The incident caused significant distress to the victims, who reported feeling silenced and unsupported by the school's response. The case highlights the growing crisis of AI-generated non-consensual imagery among students and the challenges schools face in managing such incidents.

Five boys at The Friends' School in Hobart, Tasmania allegedly created purported AI-generated pornographic images using photos of female classmates, with parents saying 21 girls were identified as victims. The images were reportedly shared in a boys' group chat. Tasmania Police said no charges had been laid and the youths were being dealt with under the Youth Justice Act.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 4 Malicious actors
  • Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation

The incident involved the intentional creation of humiliating and sexual deepfake imagery targeting specific victims (21 female classmates) for harassment or gratification, which fits under targeted manipulation and abuse of synthetic media.

Additional risk subdomains

  • 1.2 Exposure to toxic content: The creation and sharing of non-consensual pornographic deepfakes exposed the victims and their school community to highly toxic and sexually explicit content.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The incident was caused by human actors (the male students) who intentionally used a post-deployment AI deepfake generation tool to create and share non-consensual pornographic images of classmates.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Limited Risk: The EU AI Act classifies AI-generated content such as deepfakes under Limited Risk, requiring specific transparency obligations to ensure users are informed of the AI's nature.

AI system and alleged parties

  • AI system: None named
  • AI purpose: Deepfake Image Generation; Image Generation
  • Behaviour type: Tool
  • Alleged developer: Unknown deepfake technology developers
  • Alleged deployer: students, minors, Deepfake creators, Boys
  • Alleged harmed parties: The Friends' School community, students, minors, Girls, Epistemic integrity

Harm severity

Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Minor, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Minor, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Negligible, indirect Negligible
  • Psychological: direct Minor, indirect Minor
  • Epistemic: direct Minor, indirect Negligible
  • Child sexual exploitation and abuse: direct Substantial, indirect Negligible

Malicious content

Reported: The report explicitly describes the creation and sharing of non-consensual pornographic deepfake images.

Directly caused: Pornographic deepfake images of 21 female students were created and shared, exposing them and potentially peers in group chats or private messages to toxic, sexually explicit content.

Indirectly caused: N/A

Inferred additional harm: It is highly likely that the generated images persisted online or on private devices, continuing to pose a risk of further exposure and distress.

Civil rights

Reported: The report does not explicitly use the terms human or civil rights violations, but the non-consensual sexualization of minors violates basic rights to bodily autonomy and privacy.

Directly caused: The non-consensual creation of sexualized imagery of 21 minors violated their personal dignity and autonomy.

Indirectly caused: N/A

Inferred additional harm: N/A

Psychological

Reported: The report explicitly describes psychological harm, noting that the victims felt silenced, unsupported, humiliated, angry, and afraid.

Directly caused: 21 female students experienced significant distress, feeling humiliated, angry, afraid, silenced, and unsupported due to their images being used in deepfake pornography.

Indirectly caused: Other students in the school community felt fearful, confused, and worried that they might be targeted next.

Inferred additional harm: N/A

Epistemic

Reported: The report describes the creation of deepfakes, which are realistic but false representations of individuals doing or saying things they did not do.

Directly caused: The deepfakes fabricated false pornographic representations of 21 female students, creating a false record of sexual activity.

Indirectly caused: N/A

Inferred additional harm: N/A

Child sexual exploitation and abuse

Reported: The report describes the creation of non-consensual pornographic deepfakes of school students, which constitutes child sexual abuse material (CSAM) as the victims are minors.

Directly caused: Five male students created and shared non-consensual pornographic deepfake images of 21 female classmates, which constitutes the generation of synthetic CSAM.

Indirectly caused: N/A

Inferred additional harm: N/A

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 21
  • People reportedly exposed: 21

Potential causes

Management

  • Poor Communication Strategy: School advised parents not to inform victims, causing lack of support.
  • Unprepared Incident Response: Staff and parents are unsure how to coordinate and respond to incidents.

Technology

  • Accessible Deepfake Apps: Easy-to-use AI apps create realistic deepfakes at low or no cost.
  • Personal Device Creation: Images created on personal devices outside school hours evade monitoring.

Data Inputs

  • Social Media School Photos: Publicly available selfies and school photos used as source images.

Human Factors

  • Lack of Consent Awareness: Students create or share deepfakes as pranks without realizing severity.
  • Victim Shame and Isolation: Targeted students feel humiliated, fearful, and unsupported.

Process and Methods

  • Inadequate School Policies: Lack of clear education on digital literacy, relationships, and consent.
  • Flawed Incident Reporting: Students are unsure how to report or support peers in group chats.

Regulatory Environment

  • Delayed Legal Frameworks: Laws banning non-consensual deepfakes are relatively new and lagging.

Information quality

  • Classification confidence: High
  • Reason for confidence: The report provides clear, consistent details about the incident at The Friends' School, including the number of victims (21), the nature of the deepfakes (pornographic), and the impact on the students and school community. The role of AI as a tool for generating these deepfakes is explicitly stated.
  • Ambiguities identified: The specific AI applications used by the students are not named.
  • Alternative interpretations: None. The facts of the deepfake creation and its impact are uncontested.

Five students at an Australian school created and shared non-consensual pornographic deepfakes of 21 classmates using consumer AI tools. While causing severe psychological harm to the victims and highlighting regulatory challenges around synthetic CSAM, the incident remains a localized criminal and disciplinary issue with negligible direct national security impact.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Single nation
  • Primary target: Australia
  • Alleged perpetrator: Five male students

Threat characteristics

  • Imminence: Long-term. Represents an ongoing societal and regulatory challenge regarding synthetic media rather than an active national security crisis.
  • Autonomy: Human-controlled. The AI application acted strictly as a tool directly controlled and prompted by the human users to generate specific outputs.
  • Novelty: Established threat. Similar incidents of peer-to-peer deepfake harassment and non-consensual synthetic media generation have been increasingly documented globally.

Impact by dimension

  • Physical security: Negligible. No physical systems, critical infrastructure, or kinetic capabilities were targeted or impacted in this incident.
  • Information security: Negligible. The incident involved localized synthetic media for harassment, with no involvement of foreign state actors, intelligence compromise, or systemic disinformation.
  • Sovereignty: Negligible. No core government operations, electoral systems, or sovereign decision-making processes were affected.
  • Economic security: Negligible. The incident utilized easily accessible consumer AI tools and did not impact strategic economic assets or technological competitiveness.
  • Societal stability: Minor. While representing a serious violation of privacy and personal dignity for the 21 victims, the societal impact remains localized and manageable through domestic law enforcement and educational policies.
Explore in the interactive Incident Tracker