A Pennsylvania State Police corporal was charged with felony unauthorized use of a computer after investigators discovered thousands of pornographic files on his work workstation. The cache included AI-generated deepfake media created using the likenesses of others. The officer has been suspended without pay pending the outcome of the investigation.
A Pennsylvania State Police corporal, Stephen Kamnik, was charged for allegedly using a work computer to store thousands of pornographic files, including content created with deepfake AI software.
Risk classification
- Primary risk domain: 1 Discrimination & Toxicity
- Primary risk subdomain: 1.2 Exposure to toxic content
The incident involves the creation and storage of AI-generated deepfake pornography, which constitutes toxic, inappropriate, and non-consensual sexual content violating community and legal norms.
Additional risk subdomains
- 4.3 Fraud, scams, and targeted manipulation: The deepfake software was used to create sexual imagery of individuals using their photos or videos without their consent.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by a human user intentionally utilizing deployed deepfake software to generate and store unauthorized pornographic media on a work computer.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The AI system is used to generate deepfakes, which are subject to transparency obligations under the EU AI Act.
AI system and alleged parties
- AI system: deepfake AI software
- AI purpose: Deepfake Image Generation; Deepfake Video Generation
- Behaviour type: Tool
- Alleged developer: Unknown deepfake technology developers
- Alleged deployer: Stephen Kamnik
- Alleged harmed parties: Victims whose images were manipulated, Pennsylvania State Police
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Malicious content
Reported: Yes, the report explicitly describes the storage of thousands of pornographic files, including AI-generated deepfakes.
Directly caused: The deepfake software was used to directly generate non-consensual pornographic images and videos using people's photos.
Indirectly caused: N/A
Inferred additional harm: It is likely that additional deepfake pornographic files were created or shared across other platforms or devices not captured in the seized workstation.
Privacy
Reported: Yes, the reports describe deepfakes created using a person's photo or video.
Directly caused: The incident directly involved using individuals' personal photos or videos to generate unauthorized pornographic media.
Indirectly caused: N/A
Inferred additional harm: It is likely that the personal data and likenesses of multiple individuals were harvested and processed without their consent to train or feed the deepfake generation software.
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Management
- Inadequate Workstation Oversight: Failure of management to enforce strict policies on work computer usage.
Technology
- Deepfake Generation Software: Software enabled creation of artificial pornographic media from photos.
- Unrestricted Workstation Storage: Work computer lacked restrictions to block storage of unauthorized files.
Data Inputs
- Target Photos and Videos: Deepfakes utilized real people's photos or videos to generate media.
Human Factors
- Employee Misconduct: Corporal intentionally stored thousands of pornographic files on work computer.
Process and Methods
- Inadequate Computer Auditing: Lack of proactive monitoring of work station hard drives for policy violations.
Information quality
- Classification confidence: High
- Reason for confidence: The reports are consistent across multiple sources regarding the charges, the seizure of the hard drive, and the presence of AI-generated deepfake pornography. The role of the AI as a tool for creating deepfakes is clear, though the specific software name and the identities/number of victims are not disclosed.
- Ambiguities identified: The reports do not specify the exact deepfake software used, how many individuals were depicted, or whether the deepfakes were distributed or solely stored.
- Alternative interpretations: None. The facts of the arrest and the nature of the files are clearly stated.
A Pennsylvania State Police corporal was arrested for storing AI-generated deepfakes on a work computer. While representing a serious breach of official conduct and individual privacy, the national security impact is minor and fully contained by local law enforcement and judicial processes.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: USA
- Alleged perpetrator: Stephen M. Kamnik
Threat characteristics
- Imminence: Long-term. The suspect has been suspended and the workstation seized, eliminating any immediate threat.
- Autonomy: Human-controlled. The AI software was operated as a tool under direct human input and control to generate specific media.
- Novelty: Established threat. The misuse of AI tools for generating non-consensual deepfake pornography is a well-documented and established threat.
Impact by dimension
- Physical security: Negligible. No threat to physical systems, critical infrastructure, or kinetic capabilities was identified in this incident.
- Information security: Negligible. No evidence of coordinated disinformation, intelligence compromise, or foreign influence operations.
- Sovereignty: Minor. Involves the unauthorized use of a state police workstation by an officer, but is fully manageable under standard domestic legal and disciplinary procedures.
- Economic security: Negligible. No threat to financial stability, strategic industries, or technological competitive advantage.
- Societal stability: Minor. The creation of non-consensual deepfake pornography violates individual privacy and dignity, but lacks population-scale societal disruption.