The Anderegg prosecution and the model that was never deprecated

The first federal prosecution over AI-generated CSAM ran in parallel with four years of Stable Diffusion releases, takedowns and safety pledges. The courts could not reach private possession; every withdrawal that stuck landed somewhere other than the version named in the indictment. Civil liability is the one thing moving the other way.
Lane: Policy Stages: 11 Span: Oct 20, 2022 – Aug 25, 2026 Active

How it unfolded

1Release & provenanceOct 2022 – Aug 2024

Stable Diffusion 1.5 shipped from Runway rather than Stability, and the dataset beneath it was later shown to contain validated links to CSAM.

Note: The Stanford report does not claim the presence of CSAM in LAION-5B caused any specific model output, and does not address the Anderegg images.
  • Stable Diffusion 1.5 is released from Runway's repository The Stable Diffusion 1.5 weights were published to Hugging Face under Runway's account rather than Stability AI's. The original repository has since been deprecated; the weights remain available through community mirrors.
    Note: The cited page is a mirror, which states it is "a mirror of the now deprecated runwayml/stable-diffusion-v1-5" and "not affiliated in any way with RunwayML." It does not carry a release date; the date here is the widely reported one and is not confirmed by the cited source.
  • Stanford finds CSAM in the training data David Thiel of the Stanford Internet Observatory reported that the open LAION-5B dataset underlying Stable Diffusion contained links to suspected CSAM. The report's abstract states that its methodology "detected many hundreds of instances of known CSAM in the training set, as well as many new candidates that were subsequently verified by outside parties." The Associated Press reported that the study recommended anyone who built training sets from LAION-5B "delete them or work with intermediaries to clean the material," and that legitimate platforms "can stop offering versions of it for download." LAION told the AP it was temporarily removing its datasets on the eve of publication.
    Contested: The count differs between the two sources cited here. The report's own abstract says "many hundreds of instances of known CSAM" plus further candidates verified externally; the Associated Press account says "more than 3,200 images of suspected child sexual abuse." The Stanford Digital Repository landing page exposes metadata and the abstract only, so no table figure is cited.
    Note: The report's recommendation to deprecate affected models predates every industry action below it.
  • SD 1.5 is pulled from Hugging Face and re-hosted Runway removed the Stable Diffusion 1.5 weights from Hugging Face without explanation; the community re-uploaded them within days. The removal coincided with LAION's release of Re-LAION-5B, a version of the dataset it described as cleaned of known links to suspected CSAM.
    Reported by pressTechCrunch ↗ · LAION ↗
    Note: Runway gave no reason for the removal. The link to the Stanford findings is inference by reporters, not a stated cause. Re-LAION-5B is a new dataset, not a retraining of any released model.
2AThe criminal caseOct 2023 – Aug 2026

Detection to federal arrest took roughly seven months; the possession count then failed on precedent set twenty years before the technology existed.

Note: Only the possession count was dismissed. The production, distribution and transfer counts remain pending and are not resolved by either ruling.
  • Meta reports to the CyberTipline, and a search warrant follows Meta reported the online transmission of suspected CSAM to NCMEC's CyberTipline after an Instagram user sent apparent AI-generated material by direct message to an account belonging to a minor. The opinion states that "according to the government, in October 2023, Meta Platforms, Instagram's parent company, reported the online transmission of potential CSAM to the CyberTipline," and that "law enforcement then executed a search warrant of his home, his personal laptop, two other cell phones, and other devices."
    Note: The opinion gives the month of the report but no day, and gives no date for the search warrant.
  • Federal grand jury returns a four-count indictment The Justice Department announced that Steven Anderegg, 42, of Holmen, Wisconsin, had been charged on four counts: producing, distributing and possessing obscene visual depictions of minors engaged in sexually explicit conduct, and transferring obscene material to a minor under the age of 16. The release states the images were generated with Stable Diffusion and puts the maximum penalty at 70 years with a five-year mandatory minimum.
    Contested: The two sources characterise the counts differently. The Justice Department release describes all four as concerning obscene material; the Seventh Circuit opinion describes counts one to three as concerning "visual depictions of minors engaged in sexually explicit conduct" and only the fourth as "knowingly possessing obscene CSAM."
    Note: The release says the arrest occurred "last week" and gives no arrest date. It does not mention a search warrant date or any prior state arrest.
  • District court dismisses the possession count The Western District of Wisconsin held 18 U.S.C. § 1466A(b)(1) unconstitutional as applied to Anderegg's private, in-home possession of the AI-generated images, relying on Stanley v. Georgia and on Ashcroft v. Free Speech Coalition, which distinguishes virtual CSAM from material depicting an actual child. The court declined to extend Stanley to production, and declined to dismiss the distribution charge or the charge of transferring the images to a minor.
    Note: Neither cited source gives the day of the decision; both place it in February 2025. The Seventh Circuit appeal is numbered 25-1354.
  • Seventh Circuit affirms The Seventh Circuit upheld dismissal of the possession count, holding § 1466A(b)(1) unconstitutional as applied, "assuming for the sake of argument that obscene virtual CSAM is equivalent to other forms of obscenity." The court found the government's AI-specific arguments — grooming, normalisation and market effects — already rejected in Free Speech Coalition. The majority wrote: "Given the relentless advancement in artificial intelligence models, we have some concerns about the lines these cases draw, but we are not free to redraw them ourselves." A separate concurrence by Judge Lee, joined by Judge Kolar, went further and asked for Supreme Court guidance on the First Amendment and virtual CSAM.
    Note: The holding is as-applied and narrow: the statute was not struck down, and the ruling does not reach production, distribution or transfer. The “not free to redraw them” concession is the court's own, in the majority opinion — not the concurrence. The panel was Lee, Pryor and Kolar. The joinder is taken from the Volokh Conspiracy account, which reports the majority as written by Judge Lee and joined by Judges Pryor and Kolar, and the concurrence as “Judge Lee, joined by Judge Kolar”; on that reading the judge who wrote that the court was not free to redraw these lines also wrote separately to ask the Supreme Court to. The FindLaw transcription of the opinion carries the concurrence's signature line as “Lee, Circuit Judge.” alone and shows no joinder, which is a difference in what the two renderings print rather than a contradiction between them.
2BWithdrawals & commitmentsApr 2024 – Nov 2025

Three separate industry actions over nineteen months — a safety pledge, a policy restriction and a deprecation — none of which reached Stable Diffusion 1.5.

Note: No action in this act was framed by its author as a response to the prosecution, and none asserts a connection to it. A fourth action, the August 2024 removal of the 1.5 weights, renders in the Release & provenance panel above; it reached 1.5 but did not hold.
  • Stability AI adopts Safety by Design Stability AI was among the companies announcing adoption of Safety by Design principles developed with Thorn and All Tech Is Human, intended to prevent the misuse of generative AI to create or spread CSAM. The commitments applied to future development; no model already in circulation was withdrawn.
    On the recordThorn ↗
  • Acceptable Use Policy restricts explicit generation Stability AI updated its Acceptable Use Policy to prohibit the generation of sexually explicit content, effective July 31, 2025. Civitai removed Stability AI Core Models from its generator, deleted fewer than 6,000 R-rated images made with them, disabled 563 derivative resources and barred new R+ content generated with the affected models. Civitai stated that the restrictions “do not affect SD1.5, SDXL, or SDXL derivative models, which remain fully usable both for R+ (NSFW) generation and content hosting on Civitai.”
    On the recordCivitai ↗
    Note: This is a licensing restriction on hosted generation, not a withdrawal of weights, and the carve-out is Civitai's characterisation of the policy's scope rather than Stability AI's. The model named in the indictment was expressly outside it. Stability AI's live policy page now carries a later revision date and cannot be used to source the July 2025 change.
  • Stable Diffusion 2.0 and 2.1 are deprecated Stability AI removed Stable Diffusion 2.0 and 2.1 from Hugging Face. A user thread opened on November 13, 2025 asking why 2.1 had been deleted; on November 15 another user relayed a statement attributed to Stability AI saying the versions had been “outpaced by newer architectures that offer far stronger performance, safety, and alignment” and that deprecation was “part of our effort to clean up and consolidate our model offering and to get ahead of upcoming compliance requirements for the EU AI Act in 2026.” Versions 1.5 and SDXL were left in place.
    Note: No formal announcement appears to have been published. The quoted reason is twice removed — a forum user relaying a statement attributed to a Stability AI account on a different forum — and no Stability AI or Hugging Face staff member replied in the thread. The date here is when the removal was first publicly noticed, not a stated removal date. The repository URL now returns HTTP 401.
3Civil exposureJul 2026

Six weeks before the Seventh Circuit narrowed criminal exposure at the possessor end, a civil complaint advanced toward the supplier.

Note: Allegations in an amended pleading. Nothing here has been tested or decided, and no court has ruled on Stability AI's liability.
  • Stability AI added as a defendant An amended class-action complaint in the Northern District of California added Stability AI to a suit already pending against xAI, bringing the case to five plaintiffs — the three original Tennessee plaintiffs plus one from Wyoming and one from Wisconsin. NPR reports the complaint alleges Stability AI filtered not-safe-for-work content from its training data for one model version and later removed those safeguards, and that because its models are open-weight it is "much easier for users to remove restrictions that model makers have put in place."
    Note: Untested allegations in a pleading. The third source is plaintiffs' counsel and is not a neutral account; the complaint concerns models and downstream apps generally, not the Anderegg images.

Sources cited in this brief

  1. Stable Diffusion 1.5 is released from Runway's repository — Hugging Face (community mirror of the deprecated runwayml repository), Oct 20, 2022. huggingface.co ↗
  2. Meta reports to the CyberTipline, and a search warrant follows — United States v. Anderegg, 7th Cir. (opinion), Oct 1, 2023. caselaw.findlaw.com ↗
  3. Stanford finds CSAM in the training data — Stanford Internet Observatory / Stanford Digital Repository, Dec 20, 2023. purl.stanford.edu ↗
  4. Stanford finds CSAM in the training data — Fortune / Associated Press, Dec 20, 2023. fortune.com ↗
  5. Stability AI adopts Safety by Design — Thorn, Apr 23, 2024. thorn.org ↗
  6. Federal grand jury returns a four-count indictment — U.S. Department of Justice, Office of Public Affairs, May 20, 2024. justice.gov ↗
  7. SD 1.5 is pulled from Hugging Face and re-hosted — TechCrunch, Aug 30, 2024. techcrunch.com ↗
  8. SD 1.5 is pulled from Hugging Face and re-hosted — LAION, Aug 30, 2024. laion.ai ↗
  9. District court dismisses the possession count — Tech Policy Press (Riana Pfefferkorn), Feb 13, 2025. techpolicy.press ↗
  10. District court dismisses the possession count — Wisconsin Law Journal, Feb 13, 2025. wislawjournal.com ↗
  11. Acceptable Use Policy restricts explicit generation — Civitai, Jul 31, 2025. civitai.com ↗
  12. Stable Diffusion 2.0 and 2.1 are deprecated — Hugging Face (community discussion thread), Nov 13, 2025. huggingface.co ↗
  13. Stability AI added as a defendant — NPR, Jul 7, 2026. npr.org ↗
  14. Stability AI added as a defendant — CyberScoop, Jul 7, 2026. cyberscoop.com ↗
  15. Stability AI added as a defendant — Lieff Cabraser Heimann & Bernstein (plaintiffs' counsel), Jul 7, 2026. lieffcabraser.com ↗
  16. Seventh Circuit affirms — Reason (Volokh Conspiracy), Aug 25, 2026. reason.com ↗
  17. Seventh Circuit affirms — Krieg DeVault, Aug 25, 2026. kriegdevault.com ↗