GenNomis Said No to CSAM. Its Leaked Database of 94,000 Files Said Otherwise.
What happened
In March 2025, a security researcher discovered that GenNomis, a South Korean AI image generation platform, had left a database publicly accessible without any authentication. The exposed archive contained nearly 94,000 files, including AI-generated images that violated the most basic legal and ethical thresholds. Among them was material constituting child sexual abuse material, generated by tools the platform offered to any user willing to sign up.
GenNomis published guidelines that explicitly prohibited the creation of illegal content, including CSAM. The prohibition did not extend to the platform's actual tooling. The service gave users unrestricted access to image generation features, face-swapping capabilities, and deepfake creation without apparent technical controls preventing the production of content the guidelines nominally banned. The gap between what the terms of service said and what the product made possible was not a design accident; it describes a platform that published a rule and never built enforcement for it.
The database also contained non-consensual deepfake imagery targeting adults, placing GenNomis inside a pattern that has been escalating across South Korea. Incidents operating under the label associated with earlier coercive abuse networks have involved AI nudification tools and distribution chains across messaging platforms. For individuals depicted in the material without their consent, the harm is not hypothetical: the images exist, were stored in an unsecured system accessible to anyone who knew where to look, and may have circulated before discovery.
Generative AI image platforms operating in the consumer market face a straightforward structural choice: build technical enforcement for stated prohibitions, or publish the prohibition as cover. GenNomis chose the latter, whether by negligence or intent. The exposure of the database did not create the problem. It revealed one that had been running. Every file in that archive was produced by the platform's own tools, stored on the platform's own infrastructure, and accessible because the platform had not secured it.
What this incident lacks, beyond regulatory consequences that remain unclear at the time of publication, is a verifiable record of who authorized the tooling decisions that made unrestricted generation possible, and when. Platform policies are assertions; they become meaningful only when something produces a provable record of what a system did, who reviewed it, and what it was actually capable of generating before it reached users. Without that record, a terms-of-service prohibition is a liability shield that dissolves on first inspection.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.