Class Action Adds Stability AI as a Defendant Over Alleged AI-Generated CSAM

Class Action Adds Stability AI as a Defendant Over Alleged AI-Generated CSAM
An amended complaint filed July 7, 2026 in a federal class action over AI-generated child sexual abuse material adds Stability AI as a defendant alongside xAI and brings the number of plaintiffs to five. The suit, pending in the Northern District of California, invokes Masha's Law, 18 U.S.C. sec. 2255. Every allegation described below is a claim in a complaint, not a proven fact.
Information last verified on August 5, 2026. This is a developing story; the allegations described are claims in a complaint and have not been proven in court. We update it as the record changes.
Jurisdiction scope: This case is pending in federal court in the Northern District of California and applies federal statutes plus California state-law claims. See our deepfake laws hub for how states and Congress regulate AI-generated intimate imagery generally.
What Happened
The case is captioned Doe 1 v. X.AI Corp., No. 5:26-cv-02246, pending before U.S. District Judge P. Casey Pitts in the U.S. District Court for the Northern District of California. It began in March 2026 when plaintiffs connected to Tennessee sued xAI, alleging its Grok tool generated sexually explicit images of minors from ordinary photos. RecordingLaw covered that original filing separately; see our background report on the initial xAI/Grok suit.
On July 7, 2026, the plaintiffs' attorneys, including the firm Lieff Cabraser Heimann & Bernstein, filed an amended complaint naming Stability AI as a co-defendant for the first time and adding two new pseudonymous plaintiffs, bringing the total to five. One new plaintiff, identified as Jane Doe 4 and connected to Wyoming, alleges a family member used Grok to generate more than 7,000 sexually explicit images of her from a single photo taken when she was 11. A second, identified as Jane Doe 5 and connected to Wisconsin, alleges that an adult relative of one of her classmates used a photo of her taken when she was 14 to generate the images. Both are unproven claims pleaded in the complaint; neither has been tested at trial.
The amended complaint alleges that Stability AI released its Stable Diffusion 1.0 model as an open-weight model despite allegedly knowing the training data included CSAM, and that the company has declined to change its guardrails since, allegedly enabling third-party "nudify" apps built on top of the open model. The complaint separately alleges that xAI failed to adequately report Grok-generated CSAM to NCMEC's CyberTipline, alleging that roughly 90 percent of xAI's reports were not actionable by law enforcement because the reports allegedly omitted user-identifying information. Neither company has been found liable; these remain contested claims in an active complaint.
The addition of Stability AI is what makes the amendment notable. xAI operates Grok, a proprietary hosted tool it runs and can update. Stability AI, by contrast, is alleged to be liable not for operating a service but for having released model weights that third parties then used or adapted. That framing places a model maker, rather than only a service operator, in the defendant's chair.

What the Law Actually Says
The amended complaint invokes 18 U.S.C. sec. 2255, the federal civil remedy for child-exploitation victims sometimes called Masha's Law. That statute lets a person who was a minor victim of specified federal child-exploitation offenses, including production or distribution of child pornography under 18 U.S.C. sec. 2251 and sec. 2252, sue for actual damages or liquidated damages of at least $150,000, plus attorney's fees and costs. A claim under sec. 2255 generally must be brought within ten years after the plaintiff turns 18, or within ten years after the plaintiff reasonably discovers the violation and the resulting injury, whichever is later. Establishing a sec. 2255 claim requires proving the underlying conduct meets the elements of one of the referenced criminal statutes; that has not been established in this case.
The complaint also invokes federal CSAM and trafficking statutes and California state-law claims, including product-liability and negligence theories aimed at the model makers rather than only the individuals who allegedly generated the images. That framing is what makes the amended complaint notable: it asks whether a company that builds and distributes an image-generation model can be held liable when someone else uses that model, or a derivative built from its released weights, to produce CSAM. No court in this case has ruled on that theory's merits.
Separately, federal law imposes mandatory reporting duties on electronic service providers. Under 18 U.S.C. sec. 2258A, a provider that obtains actual knowledge of apparent CSAM on its service must report it to NCMEC's CyberTipline as soon as reasonably possible. The amended complaint's allegation is not that xAI failed to report at all, but that many of its reports allegedly lacked the user-identifying information law enforcement needs to act on them. Whether that allegation is accurate, and whether it supports a legal claim, is for the court to decide.
For general background on how U.S. law treats AI-generated intimate imagery, including state deepfake statutes, see our deepfake laws hub. California's own deepfake statute is discussed on our California deepfake laws page; this case proceeds in federal court under federal claims plus California state-law claims, not under that state statute directly.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Adding Stability AI raises a question not yet squarely tested against a model maker in this context: whether a company can be held liable for what a downstream user does with a model it released, particularly an open-weight model it does not directly operate after release. That differs from suing xAI over Grok, a proprietary, hosted tool xAI runs and can update. Once model weights are released publicly, as Stable Diffusion's were, the releasing company has limited ability to control how third parties fine-tune, strip guardrails from, or repackage the model into standalone apps.
That distinction is why the amendment has been described as testing new territory for generative AI liability. A hosted-model claim resembles product-liability theories courts already apply to software a company continues to operate. An open-weight claim asks a court to extend liability further upstream, to the release decision itself, without ongoing operational control over misuse. How a court will resolve that question here is not something we predict, and no ruling on either theory's merits has issued.
The reporting allegation is a second thread worth watching. Federal law already requires service providers to report apparent CSAM to NCMEC, but the complaint's theory is about the completeness of those reports, not their existence. If that distinction gains traction, it could matter for how any provider structures its CyberTipline submissions, though no court has adopted the theory here.
How This Affects You
This section describes general legal information, not advice for any individual situation.
Federal law provides a civil remedy, 18 U.S.C. sec. 2255, for people who were minors when victimized by conduct meeting the elements of specified federal child-exploitation offenses, including production of CSAM. It carries a $150,000 statutory-damages floor and generally must be brought within ten years of the victim turning 18, or within ten years of reasonably discovering the injury, whichever is later. Whether a particular set of facts qualifies is a legal determination that depends on the specific statute and evidence involved.
Anyone who has directly experienced AI-generated exploitative imagery, or is a parent or guardian of a minor who has, can report the material through NCMEC's CyberTipline (CyberTipline.org) and consult a licensed attorney about legal options. This case remains unresolved, including whether either defendant is found liable for anything. Readers should not treat any allegation described here as an established fact.
This is general legal information, not legal advice. This article describes federal litigation pending in California and general federal law; it is not a substitute for advice from a licensed attorney about any specific situation. Verified August 5, 2026. All allegations described are unproven claims in a complaint.
Related articles
- Deepfake laws in the United States: state-by-state overview
- Tennessee teens sue xAI over Grok-generated deepfake images (background)
- California deepfake laws
- DEFIANCE Act: a federal civil remedy for deepfake porn victims
Last updated: 2026-08-05. This is a developing story; details verified as of 2026-08-05.
Frequently Asked Questions
Who is being sued in the xAI/Grok CSAM lawsuit?
The amended complaint, filed July 7, 2026 in the Northern District of California, names xAI (which has publicly rebranded as SpaceXAI in 2026) and, newly, Stability AI as defendants. The suit is brought by five pseudonymous plaintiffs. These are allegations in a complaint; no defendant has been found liable.
Why was Stability AI added as a defendant?
The amended complaint alleges Stability AI released its Stable Diffusion 1.0 model as an open-weight model despite allegedly knowing it was trained on data that included CSAM, and has not changed its guardrails since, which the complaint alleges has enabled third-party deepfake apps built on the released model. This is an unproven allegation, not a finding by any court.
What is Masha's Law?
Masha's Law is the common name for 18 U.S.C. sec. 2255, a federal civil remedy that lets a person who was a minor victim of specified federal child-exploitation offenses sue for actual damages or a minimum of $150,000 in liquidated damages, plus attorney's fees. A claim generally must be filed within ten years after the victim turns 18, or within ten years after the victim reasonably discovers the injury, whichever is later. The amended complaint invokes this statute; whether it applies here has not been decided.
Can AI companies be sued for images their models generate?
They can be sued, meaning a complaint can be filed naming them as defendants, which is what has happened here. Whether a company that builds or releases an AI model can be held legally liable for what a user later generates with it, especially with an open-weight model the company does not directly operate after release, is an unresolved legal question this case may help test. No court has ruled on that question's merits in this case.
What does the lawsuit say about reporting to NCMEC?
The amended complaint alleges that a large share of xAI's reports to NCMEC's CyberTipline, roughly 90 percent according to the complaint, were not actionable by law enforcement because xAI allegedly did not include user-identifying information. This is an allegation in a complaint, not an established fact, and xAI has not been found to have violated federal reporting law in this case.
Is this related to the original Tennessee case against xAI?
Yes. The suit began in March 2026 when plaintiffs connected to Tennessee sued xAI over Grok-generated images. The July 7, 2026 amended complaint in that case adds Stability AI as a defendant and adds two new plaintiffs. See our background report on the original filing for that earlier history.
Sources and References
- Doe 1 v. X.AI Corp., No. 5:26-cv-02246-PCP (N.D. Cal.) docket, CourtListener (the case amended July 7, 2026 to add Stability AI)(courtlistener.com)
- Deepfake Victims Bolster Class Action Against xAI, Add Stability AI, Alleging Their AI Models Generated Child Sexual Abuse Material, Lieff Cabraser (plaintiffs' counsel), July 2026(lieffcabraser.com)
- Class action suit against AI makers over deepfake child sexual abuse material expands, NPR, July 9, 2026(npr.org)
- Tennessee teens sue Elon Musk's xAI over AI-generated child sexual abuse material, NPR, March 16, 2026 (background on original filing)(npr.org)
- 18 U.S.C. sec. 2255, Civil remedy for personal injuries (Masha's Law)(law.cornell.edu)
- 18 U.S.C. sec. 2258A, Reporting requirements of providers(uscode.house.gov).gov