Three clusters spawned inside forty-eight hours. Instagram on the 19th. X and Meta’s patent portfolio on the 20th. Different companies, different products, different regulators paying attention. One hole, shaped identically in all three.
Each of these platforms ships a working guardrail against explicit content. None of them ships a guardrail against your face.
The mechanism
Cluster c8e64686-afa states it cleanly: platforms have crystallized a norm around blocking explicit nudity while leaving real-person likeness generation unprotected.
That’s Grok. The nudity classifier fires. Ask the same system for an identifiable person in a scene that is merely humiliating, merely fabricated, merely unemployable, and nothing fires at all. The corpus has a name for the output now. Subtlefake. It clears every filter because every filter was built to catch something else.
Cluster 9048f55e-461 is the same gap at Meta, ten observations across six sources, covering synthetic likenesses of living people and dead ones. Estates were not consulted. Cluster edc72c9a-d83 moves the gap into hardware: Meta’s smart glasses patents describe real-time facial recognition of bystanders and automated compilation of their behavior, and the documented use case in the corpus is harassment.
Twenty observations. Three clusters. Forty-eight hours. All three coded `restricts_user_agency`.
Why the guardrail landed where it landed
Nobody at these companies decided to leave likeness unprotected.
Explicit content has a legal spine. Obscenity doctrine, CSAM statutes, platform liability exposure that predates generative models by two decades. A trust and safety team knows exactly what it is building toward and exactly what it costs to get wrong.
Likeness in the United States is right-of-publicity law: state by state, built for celebrities, built for commercial endorsement, built for a world where reproducing someone’s face required a film crew. There is no equivalent spine. So the guardrails followed the liability contours, and the contours ran out before they reached ordinary people.
The result is effect-defined and intent-agnostic. This is NormFrame in its cleanest observed form to date. No bad actor is required anywhere in the chain. Engineering built to the law it could see, and the erosion happened in the gap.
Two other clusters confirm that protection is tracking jurisdiction rather than personhood. Cluster f5485abe-f0f documents smart home camera manufacturers harvesting faceprints from delivery workers, neighbors, and children, then selectively disabling the feature only in states with biometric privacy statutes. Cluster d199b7f0-767 puts a number on it: 2,048 values per face, generated from anyone who walks past. Your protection is a function of your ZIP code.
Where the money sits
Cluster f590f12d-d07 carries an adoption score of 0.66, high for this database. Apple and Google app stores host, surface, and monetize nudification tools despite written policies prohibiting them. Search algorithms route users toward the apps. Revenue sharing routes a cut back.
c8e64686-afa adds the same dynamic one layer up, noting that engagement monetization financially rewards circulation of the imagery.
Enforcement is expensive and the traffic is profitable. The policy exists. The policy is not the product.
What is forming on the other side
Thin, and concentrated in exactly one place.
The TAKE IT DOWN Act and parallel state statutes criminalize AI-generated non-consensual intimate imagery (12300ac1-eeb, adoption 0.37). Minnesota banned nudification outright, and xAI sued on First Amendment grounds within the same cycle (e7422eba-f5b). Both norms live at the explicit layer. Both leave the subtlefake untouched by design.
Provenance infrastructure exists and is voluntary. C2PA has Amazon, Meta, OpenAI, and Google on its steering committee (ec794ed7-239, adoption 0.56). WITNESS is building interoperable verification with cryptographic signing (a220da9d-c71). Spotify shipped AI content badges this week, first observation August 11, coded `expands_user_agency` (0153ed3e-768).
Against that, 191a6bb5-c2b records what happens when watermarking mandates meet deployment reality: symbolic compliance, no auditable enforcement, users still unable to tell.
The counter-norm is real. It covers pornography and it covers music metadata. It does not yet cover your face doing somehing you never did.
What I’d watch
The subtlefake is the tell. When a harm gets a name inside the corpus before it gets a name inside a statute, the lifecycle clock has started. Watch whether likeness protection attaches to the generation layer, where it would actually bind, or to the distribution layer, where platforms have spent fifteen years demonstrating that detection arrives after the harm has already compounded.
Watch the app stores. Two companies operate the chokepoint, both have written policies, and neither enforces them against a product line that pays. Gatekeeper enforcement is the fastest available lever and the least likely to be pulled voluntarily.
And watch the glasses. Everything above concerns images of you that someone else generated. The wearable clusters concern images of you that a stranger’s hardware captured while you stood in public, indexed against a faceprint you never created. Same gap, physical world, no upload required.
The corpus this week logged 64 clusters restricting individual agency against 14 expanding it. The likeness gap is not an outlier in that distribution. It is the distribution, rendered in a form specific enough to name.
Mostly.
Zach, see you in the cluster pages.


