What happened

According to reporting by SBS, the defendant — identified only as Official A — worked at the Guro District Office in Seoul. He took a photograph of a female colleague, without her knowledge or consent, and used a generative AI tool to compose images in which he and she appeared together in romantic poses, as though they were a couple. He then circulated the results through messaging applications.

The court, ruling on 11 September 2026, convicted him under the Act on Special Cases Concerning the Punishment of Sexual Crimes — the same statute that carries South Korea's deepfake sexual-abuse provisions — and imposed a fine of six million won. The reasoning is what matters. The judge held that whether material induces sexual humiliation is not determined by the degree of exposure, such as nudity or underwear. The prosecution had framed the interest at stake in a single sentence that is likely to be quoted for years: everyone has the freedom not to be sexualised against their will.

Why a fully clothed image can still be a sexual offence

Deepfake prosecutions to date have clustered around a familiar fact pattern: a real person's face is transplanted onto sexually explicit material. The harm is intuitive, the imagery is plainly pornographic, and the legal question is mostly about identification and intent.

This case sits outside that pattern. The images were, by any conventional description, tame. What made them actionable was not their explicitness but their appropriation of a person into a sexual or romantic narrative she never agreed to enter, and their circulation to an audience of her colleagues' peers. The court's move was to locate the protected interest in the victim's sexual autonomy and dignity rather than in the visual content of the file.

That shift has three consequences worth naming:

  • The test becomes contextual. A court must now look at what the image asserts about the victim, who received it, and what it was for — not merely at what it depicts.
  • The evidentiary centre of gravity moves. Prosecutors no longer have to establish that content crossed a threshold of obscenity; they have to establish non-consent, identifiability and the sexualising character of the portrayal.
  • The offender profile widens. The archetypal deepfake defendant is an anonymous distributor on an encrypted channel. Here he was a colleague with a desk in the same building.

Where this fits in South Korea's deepfake architecture

South Korea has built its response to synthetic sexual imagery in layers, and this ruling tests the seams between them.

  • The 2024 amendments. After the Telegram deepfake scandal, the National Assembly criminalised not only the production and distribution of sexually explicit deepfakes of real people but also their possession, purchase, storage and viewing, with penalties reaching three years' imprisonment or a fine of up to 30 million won. We covered that legislative moment in our report on the day the Deepfake Sexual Violence Act passed parliament, and the social crisis behind it in our analysis of South Korea's deepfake crisis.
  • The pending "fictional persons" bill. A separate proposal would criminalise AI-generated sexual material even where no identifiable real person is depicted — the most contested frontier in this field, which we examined in our report on criminalising AI sexual content of people who don't exist.
  • The AI Basic Act. In force since 22 January 2026, it obliges providers to label generative outputs that are hard to distinguish from reality. It is a transparency instrument, not a criminal one — but labelling duties shape the evidentiary record that prosecutions later rely on.

Read together, the picture is of a jurisdiction steadily expanding the protected interest: from explicit imagery of a real person, to any sexualising portrayal of a real person, and — if the pending bill passes — to sexual imagery with no real person at all. This conviction is the middle step being confirmed in practice rather than in theory.

The workplace dimension

The detail that the parties were colleagues is not incidental. It converts what might look like a private fantasy into something with a recognisable institutional shape.

In most legal systems, conduct of this kind would engage at least three distinct regimes simultaneously: criminal law, employment and disciplinary law, and data-protection law. A public employer confronted with these facts faces its own questions. Did the images circulate on work devices or work accounts? Was the victim's photograph taken from an internal directory or an intranet profile? Did the employer have a policy governing generative AI at all, and did it address the use of colleagues' images?

The KVKK-equivalent question — whether a person's photograph, processed through a system that reconstructs their face, becomes biometric data subject to a stricter regime — arises here as squarely as it does in consumer apps. We set out that analysis in our report on the KVKK's warning that your face is biometric data.

What it means for Türkiye

Turkish law has no offence written for this scenario, but it is not silent either. Depending on the facts, prosecutors would look at several provisions of the Turkish Penal Code: the offences protecting private life, the unlawful processing or dissemination of personal data, insult where the portrayal attacks honour and dignity, and — where the content is sufficiently explicit — the obscenity provisions. Civil law adds the protection of personality rights, with claims for moral damages, and Law No. 5651 supplies the removal and access-blocking machinery for online content.

The Korean ruling exposes the gap in that toolkit. Turkish practice, like most, has calibrated its sexual-offence provisions to explicit content. Where a synthetic image is decorous but humiliating, the natural landing spots are insult and privacy — offences whose sentencing scales and procedural posture (often requiring a complaint, often resolved with deferred sentences) do not reflect the gravity of being placed into a sexual narrative before one's colleagues.

Three questions follow for any future Turkish rule, of the kind we sketched in our study of the draft Turkish AI Act:

  • Is the protected interest explicitness or autonomy? If it is autonomy, the offence must be drafted around non-consensual sexualisation, not around depicted body parts.
  • How is identifiability proved? Where a face is composited rather than transplanted, victims need a workable evidentiary route — which is where provenance and labelling rules do real work, as we argued in our analysis of mandatory AI watermarking and in marking AI-generated content.
  • What happens inside institutions? A criminal provision reaches the individual; it does not tell a ministry, a municipality or a company what its own duty of care requires. That is a policy question, and the answer usually has to be written into an internal AI use policy — our guide to a corporate AI use policy sets out a workable framework.

Three hard cases at the edge

A rule built on sexualisation rather than explicitness has to survive its boundary cases, and it is worth stating them plainly rather than waiting for a court to be surprised by one.

  • The political cartoon. A satirical composite placing a politician in an intimate scene with a lobbyist is sexualising, non-consensual and identifiable — and in most constitutional traditions it is also protected comment on public affairs. The way out is not to carve out politicians but to weigh purpose and public interest, as defamation law already does. A rule with no such weighing will be used to suppress criticism within a year of enactment.
  • The private image never shared. If the official in this case had generated the same pictures and kept them on his own device, the humiliation — which flowed from circulation to colleagues — would not have occurred. Dissemination is doing real work in the reasoning, and a rule that criminalises solitary creation is a different and much more contested proposition.
  • The celebrity composite. Synthetic "relationship" imagery of public figures circulates constantly in fan communities, most of it clothed. Applying the sexual-offences statute to all of it would criminalise an enormous, largely adolescent, cultural practice; applying it to none of it leaves performers with no protection against sexualised fabrication. This is where the publicity-rights route matters more than the criminal one, as we discussed in our analysis of the Seoul right-of-publicity case and in K-pop's synthetic revolution.

None of these is an argument against the ruling. They are an argument for keeping its elements tight, which is exactly what a first-instance fine in a modest case is unlikely to do on its own.

The comparative map: almost everyone else requires explicitness

What makes the Korean ruling unusual is easiest to see against the wave of intimate-image legislation passed elsewhere in the last two years. Nearly all of it is built on a threshold of explicitness.

  • United States. The TAKE IT DOWN Act, enacted in 2025, criminalised the publication of non-consensual intimate visual depictions of identifiable people, digital forgeries included, and imposed rapid removal duties on platforms. The operative concept is an intimate depiction — nudity or sexual conduct. A clothed composite would not engage it.
  • European Union. The directive on combating violence against women requires member states to criminalise the non-consensual production or manipulation of intimate material, again anchored to intimacy rather than to sexualisation in the broader sense. The EU AI Act adds transparency duties for deepfakes from its own direction, and from 2 December 2026 prohibits systems generating non-consensual intimate imagery outright — but the prohibition tracks the same explicitness threshold.
  • United Kingdom. The intimate-image offences, and the more recent step of criminalising the creation of sexually explicit deepfakes of adults, also turn on explicit content. Outside that, a victim is generally left with harassment or malicious-communications routes.

Against that map, South Korea has just recognised a harm the others have drafted around. If the reasoning holds on appeal, the interesting question is not whether other legislatures copy the Korean statute — they will not — but whether their courts start reading existing harassment, dignity and privacy provisions with the same instinct: that being sexualised without consent is the injury, and the pixels are only the instrument.

What a victim can actually do

Most people who discover synthetic images of themselves do the worst possible thing first: they demand deletion, and the evidence disappears with it. The sequence that preserves a case looks different.

  • Capture before you confront. Save the files themselves rather than screenshots where possible, along with the surrounding conversation, sender identity, timestamps and any group membership list. Metadata that survives in the original file is often the only thing that later establishes which tool produced it.
  • Record the distribution, not just the image. Who received it matters as much as what it shows — in this case it is what converted a private composite into a public humiliation.
  • Use the institutional channel in parallel. An employer's disciplinary process moves faster than a prosecution and can stop ongoing circulation inside the organisation.
  • Do not negotiate for deletion in exchange for silence. It is the most common outcome and it leaves the victim with neither evidence nor remedy.

In Türkiye, removal and access-blocking under Law No. 5651 can run alongside a criminal complaint, and a data-protection complaint may be available where the image was produced from personal data held by an employer or a platform.

The platform and tool layer

Every case of this kind raises a question the defendant cannot answer: why was the tool willing to do it?

Most mainstream image models refuse overtly sexual outputs, and many refuse to place a named real person in intimate scenes. Very few refuse to compose two uploaded faces into an affectionate pose. The conduct here sat precisely in that permitted space — non-explicit, personally devastating, technically trivial.

That gap has three possible closures, and each carries costs. Providers can require affirmative confirmation that uploaded third-party images are used with consent, which is easy to lie about. They can restrict face-to-face composition of multiple uploaded people, which breaks legitimate uses from family photo restoration to design work. Or they can attach durable provenance metadata so that a victim can prove synthesis quickly, which does nothing to prevent creation but transforms the victim's evidentiary position. On present evidence, the third is the only one that survives contact with reality.

What employers should put in place

Organisations tend to write their generative-AI rules around confidentiality: do not paste client data into a chatbot. This case is a reminder that the other exposure — what employees do to each other — is barely addressed anywhere.

  • Name the conduct. An AI use policy should state explicitly that generating images of colleagues, clients or the public without consent is a disciplinary matter, and that sexualising portrayals are gross misconduct.
  • Control the source material. Staff photographs in internal directories are personal data collected for identification, not for image generation. Access, download rights and retention should reflect that.
  • Give victims a route that is not their line manager. In this case the perpetrator was a senior figure; a reporting channel that runs through the hierarchy would have failed.
  • Preserve rather than purge. IT teams' first instinct is to delete offending material from company systems. Legal hold procedures should cover synthetic content the way they cover any other evidence.
  • Train on the specific scenario. Abstract warnings about "responsible AI" do not reach this behaviour. The example does.

What to watch next

Four things will determine whether this ruling becomes a line of authority or an outlier. First, whether it is appealed, and whether an appellate court endorses the "humiliation is not measured by exposure" reasoning. Second, whether prosecutors begin charging similar non-explicit cases, which is the real test of whether the ruling changes practice. Third, whether the fictional-persons bill advances, since together the two would leave South Korea protecting both real people in non-explicit portrayals and no one at all in explicit ones. Fourth, whether public employers respond with AI use policies rather than treating this as one individual's misconduct.

Frequently asked questions

Was the material pornographic?

No. According to the reporting, the images showed the defendant and his colleague in romantic poses as a couple. The court's point was that the absence of nudity or underwear did not prevent the material from causing sexual humiliation.

What was the sentence?

A fine of six million won, imposed by a first-instance court on 11 September 2026 under the Act on Special Cases Concerning the Punishment of Sexual Crimes.

Does this mean any unwanted AI image of a person is now a sex crime in Korea?

No. The ruling turns on a sexualising portrayal circulated without consent. An unflattering or comic composite would engage different provisions — defamation or privacy — rather than the sexual-offences statute.

Would this be an offence in Türkiye?

There is no provision written for it. Prosecutors would likely proceed under privacy, personal-data or insult provisions, and the victim could bring a personality-rights claim and seek removal under Law No. 5651. Whether those routes match the gravity of the conduct is precisely the open question.

Does it matter that they were colleagues?

Legally, the offence does not require it. Practically it matters a great deal: the audience that received the images was the victim's professional environment, which is what made the humiliation concrete, and it brings the employer's own duties into play.

How does this relate to the bill on "people who don't exist"?

They are opposite ends of the same debate. This case involves a real, identifiable victim in non-explicit imagery. The bill targets explicit imagery with no identifiable victim at all. Together they show a legislature and a judiciary pushing outward from the original core of the offence in two different directions.

Burhan Doğuş Ayparlar's View

This section sets out my personal assessment as the founder of this site and an AI ethics & compliance counsel.

I think this is the right ruling, and I think its importance is out of all proportion to the six million won. For three years the deepfake debate has been organised around explicit content, because explicit content is where the outrage is. That framing quietly encoded an assumption that the wrong lies in the depiction. It does not. The wrong lies in being conscripted into someone else's story about your body and your intimacy, and then having that story handed to the people you work with. A picture of a fully dressed woman standing beside a man she never agreed to stand beside can carry that wrong completely.

What I find most useful for practitioners is the evidentiary logic. Courts that require explicitness are, in effect, requiring victims to be humiliated in a particular visual register before the law will engage. The Korean court declined that requirement and asked instead what the image asserted and to whom. That is a test other jurisdictions can borrow without importing Korea's whole penal apparatus, and I expect it to travel.

My caution is about proportion. A rule framed around non-consensual sexualisation is broad by construction, and broad sexual-offence provisions have a way of catching satire, art and clumsiness alongside cruelty. The discipline has to come from the elements: non-consent, identifiability, sexualising character, and dissemination. Drop any one of those and the offence becomes a general prohibition on unflattering images, which is not a place any legal system should want to be.

For Türkiye my recommendation is narrow and practical. We do not need to wait for a comprehensive AI statute to fix this. A targeted provision covering non-consensual synthetic sexualisation of an identifiable person — explicit or not — with a clear removal duty for platforms and a realistic evidentiary standard for victims, would close the gap now. And for employers, public and private: this case should be read as a warning that the risk of generative tools is not only data leakage. It is also what your staff can do to each other with them, and whether your AI use policy says a single word about it. Most do not.

This article is for information only and does not constitute legal advice. The facts are based on press reporting of the 11 September 2026 ruling, principally by SBS; the judgment text was not available at the time of writing and the case may be subject to appeal. Statements about Turkish law are general in nature; specific cases require individual assessment. The analysis and assessments are the author's own.