Hong Kong university's AI deepfake porn scandal ignites debate
HONG KONG – The potential dangers of using generative AI made the headlines in Hong Kong, after a student from a top local university allegedly used artificial intelligence tools to create hundreds of pornographic images of dozens of his female classmates and teachers.
The incident has sparked calls for the government to update its laws to regulate use of the technology, as Hong Kong prepares to launch its first ChatGPT-style AI service this year.
The case involving the University of Hong Kong (HKU) quickly gained public attention over the past week, after three victims took to social media anonymously to convey their unhappiness with the university's handling of the matter.
According to what the victims shared on an Instagram post on July 12, pornographic images of around 20 women were found in February on the personal laptop of the HKU law student, whom they referred to only as X.
The more than 700 photos discovered included original innocuous screenshots and digitally manipulated indecent images of women who were the student's 'friends, university classmates, seniors, primary school classmates and even secondary school teachers'.
'Upon questioning, X admitted to using photos of the victims… as material to generate these pornographic images using free online AI software,' the Instagram post read. 'It is understood that none of the victims authorised X's actions.'
It was not clear how the images were discovered or whether he had distributed them.
Top stories
Swipe. Select. Stay informed.
Singapore Judge asks prosecution for more information on Kpods in first case involving etomidate-laced vapes
Singapore Male victim of fatal Toa Payoh fire was known to keep many things, say residents
Singapore 5 teens arrested for threatening boy with knife, 2 charged with causing hurt
Singapore HDB launches 10,209 BTO and balance flats, as priority scheme for singles kicks in
Sport Saka the difference as Arsenal beat AC Milan at National Stadium
Singapore Cyclist charged after allegedly hitting elderly pedestrian, killing him
Singapore Over 1.15 million Singaporeans aged 21 to 59 have claimed SG60 vouchers
Singapore Singapore Oceanarium will enhance tourism while supporting sustainability: Grace Fu
The victims alleged that after the case was brought to HKU's attention in March, the university proposed only written and verbal reprimands for the student and cited legal advice that he was unlikely to have committed any legal offence.
'Most victims felt that the university's response was insufficient to hold X accountable,' the post said.
It added that those affected considered existing legislation inadequate to address the incident, leaving them 'unable to seek punishment for X through Hong Kong's criminal justice system'.
The three victims told The Straits Times that they filed a complaint to the city's equality watchdog, but did not make a police report as they believed that 'deepfakes, which represent a relatively new form of sexual violence, fall outside the scope of existing laws'.
'However, we hope this incident will raise public awareness about deepfakes and push for legislative reforms,' they said.
They also expressed disappointment in online opinions, which have been split along gender lines.
'We call on the public to recognise the seriousness of sexual violence issues,' they said.
'Voicing out personal stories of injustice should never be framed as the promotion of patriarchalism or feminism; it should be understood as a basic right in a law-based society.
'The perpetrators should be the only ones condemned,' they added.
In the wake of the scandal, the authorities have warned the public on the severity of such misconduct and said they would carefully consider how best to manage such cases.
Chief Executive John Lee addressed the issue directly on July 15, placing the onus on the university to 'deal seriously' with the matter and to report it to law enforcement agencies if it constitutes a legal offence.
'The government will… examine global regulatory trends, and conduct in-depth research into international best practices to see what we should do,' Mr Lee added.
Currently , there is no dedicated legislation in Hong Kong that governs the use of generative AI.
It is an emerging field, and countries are still grappling with the regulatory aspects of the new technology's impact on employment, productivity, the economy and society.
Following Mr Lee's comments, the city's privacy watchdog, the Office of the Privacy Commissioner for Personal Data said it had opened a criminal investigation into the incident.
HKU, meanwhile, said it had issued the student with a warning letter and instructed him to apologise to his victims. It also clarified that the university's investigation was still ongoing.
Technology minister Sun Dong cautioned users of AI tools that they would have to ' bear the legal responsibilities' for how they choose to use them.
His ministry, the Innovation, Technology and Industry Bureau, said separately that the government would 'review existing legislation (governing the application of AI) if necessary'.
'The use of AI is a double-edged sword... The key is to have proper guidance and a comprehensive legal framework,' Mr Sun told local broadcaster RTHK on July 19.
The minister's remarks came as he shared details on Hong Kong's first home-grown ChatGPT-style AI service, which is slated to be launched within the year.
The DeepSeek-powered chatbot, called HKGAI V1, has already been tested in 13 government departments, and can generate content ranging from translations, meeting minutes and travel itineraries, to videos.
'It is an all-round working platform that can handle all kinds of tasks, like help you compose a report, lyrics, or even a song,' Mr Sun said.
The service is free for all Hong Kong residents, who will be able to download it via the government's iAM Smart digital identity app, which is similar to Singapore's SingPass.
DeepSeek is China's answer to the United States' ChatGPT, which is inaccessible in Hong Kong except through a virtual private network. OpenAI, the US firm behind ChatGPT, has blocked the AI chatbot's use in the city, mainland China, and Macau since July 2024.
The confluence of HKGAI V1's upcoming launch and the recent HKU scandal has called to question whether Hong Kong is adequately equipped to regulate the burgeoning use of generative AI tools in the city.
Professor Benedict Chan , director of Hong Kong Baptist University's (HKBU) Centre for Applied Ethics, said the ease of misusing the increasingly sophisticated generative AI technology has raised 'serious concerns about privacy, consent, and social trust'.
'The key challenge is to ensure that these powerful tools are used responsibly, with safeguards in place to prevent misuse,' Prof Chan, who is also associate dean at HKBU's faculty of arts and social sciences, told The Straits Times.
As AI technology advances and its range of applications widen in scope, new laws should be made to fill any gaps, said Mr Alex Liu , managing partner at law firm Boase Cohen & Collins.
'Law reform in this area has been overdue,' Mr Liu told ST.
'There are fundamental issues that need to be addressed by the legal system, legislature and executive with regard to AI. For example, data privacy, intellectual property, liability in the event of accidents, and many other areas in which AI impacts our daily lives.'
In the HKU case involving deepfake porn images, however, Mr Liu suggested that existing laws may already be sufficient to address the misconduct.
The student could have violated laws in Hong Kong's crimes and personal data privacy ordinances 'if he used a computer dishonestly to create or distribute the images (or) if the AI-generated images were based on real photos of classmates or teachers (that) were used without consent', the lawyer said.
The three victims suggested that legislation against deepfakes should cover their creation, distribution, as well as the potential risks that the fabricated content pose s.
'The non-consensual creation of these indecent photos have undermined our personal autonomy and dignity, and inflicted psychological damage on us, the victims,' they told ST .

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

Straits Times
3 hours ago
- Straits Times
Casualties reported in active shooter incident at US Army base in state of Georgia
Sign up now: Get ST's newsletters delivered to your inbox ATLANTA - An active shooter incident at the Fort Stewart US Army base in Georgia has resulted in casualties, authorities said, and the base has been put on lockdown. 'The installation was locked down at 11.04am and law enforcement is on the scene,' Fort Stewart said in a Facebook post, adding the incident happened in the 2nd Armoured Brigade Combat Team area and that casualties had been reported. No further information was immediately available, including the number of casualties and their severity. A spokesperson for the Liberty County Sheriff's Office said the agency was assisting in the response at Fort Stewart but referred all questions to the US Army. Governor Brian Kemp wrote on X that he and his family were 'saddened by today's tragedy' at the base. 'We are keeping the victims, their families, and all those who answer the call to serve in our hearts and prayers, and we ask that Georgians everywhere do the same,' he added. Fort Stewart is about 360km south-east of Atlanta and 60km south-west of Savannah. REUTERS Top stories Swipe. Select. Stay informed. Singapore MRT track issue causes 5-hour delay; Jeffrey Siow says 'we can and will do better' Singapore ST Explains: What is a track point fault and why does it cause lengthy train disruptions? Singapore Three people taken to hospital after fire in Punggol executive condominium Singapore Elderly man found dead in SingPost Centre stairwell could have been in confused state: Coroner Singapore 81 primary schools to hold ballot for Phase 2C of Primary 1 registration Singapore S'pore and Indonesia have discussed jointly developing military training facilities: Chan Chun Sing Singapore Two workers died after being hit by flying gas cylinders in separate incidents in 2025 Sport Young Lions and distance runner Soh Rui Yong out of SEA Games contingent

Straits Times
3 hours ago
- Straits Times
US jury deadlocks on Tornado Cash founder's money laundering charge
Sign up now: Get ST's newsletters delivered to your inbox NEW YORK, August 6 - A U.S. jury deadlocked on Wednesday on money laundering and sanctions evasion charges against the founder of Tornado Cash, a firm that makes cryptocurrency transactions harder to track. The jury in Manhattan federal court could not reach a verdict on charges Roman Storm conspired to launder the proceeds of hacks, including by a sanctioned North Korean government-backed group. But the jury found him guilty of the less serious charge of conspiracy to operate an unlicensed money transmitting business. He faces up to five years in prison when he is sentenced by U.S. District Judge Katherine Failla at a later date. The money laundering and sanctions evasion conspiracy charges each carried possible 20-year sentences. Storm was arrested in 2023 on charges that the so-called mixer he founded helped hide more than $1 billion, including hundreds of millions of dollars for Pyongyang-backed hacking group Lazarus Group, which is blacklisted by the U.S. Treasury over its alleged financial support of North Korea. Storm, 36, had pleaded not guilty to all three felony charges he faced. In his closing argument on July 30 after a two-week trial in Manhattan federal court, defense lawyer David Patton said even though Tornado Cash's privacy tools may have been useful to criminals, Storm's intent was not to help conceal illicit funds. "There is nothing unlawful about the software that he built," Patton said. "The evidence here shows that Roman very much did not want hackers and scammers to use Tornado Cash." Top stories Swipe. Select. Stay informed. Singapore MRT track issue causes 5-hour delay; Jeffrey Siow says 'we can and will do better' Singapore ST Explains: What is a track point fault and why does it cause lengthy train disruptions? Singapore Three people taken to hospital after fire in Punggol executive condominium Singapore Elderly man found dead in SingPost Centre stairwell could have been in confused state: Coroner Singapore 81 primary schools to hold ballot for Phase 2C of Primary 1 registration Singapore S'pore and Indonesia have discussed jointly developing military training facilities: Chan Chun Sing Singapore Two workers died after being hit by flying gas cylinders in separate incidents in 2025 Sport Young Lions and distance runner Soh Rui Yong out of SEA Games contingent Prosecutor Benjamin Gianforti said Storm had been informed multiple times between 2020 and 2022 that Tornado Cash was helping criminals hide dirty money, but kept running the business out of greed. Gianforti said Tornado Cash's emphasis on user privacy was a "cover story." "The real money wasn't in protecting privacy for regular folks, it was in providing privacy for big time crypto criminals," Gianforti said. "Hackers were his best customers." Tornado Cash had itself been sanctioned by the U.S. Treasury under then-President Joe Biden's Democratic administration over its alleged support of North Korea. The Treasury lifted those sanctions in March, two months into Republican President Donald Trump's administration, saying it had reviewed legal and policy issues raised by the sanctions within "evolving technology and legal environments." Last year, one of Tornado Cash's developers, Alexey Pertsev, was sentenced to five years and four months in prison in the Netherlands for money laundering. REUTERS

Straits Times
3 hours ago
- Straits Times
Casualties reported in active shooter incident at U.S. Army base in state of Georgia
Sign up now: Get ST's newsletters delivered to your inbox An active shooter incident at the Fort Stewart U.S. Army base in Georgia has resulted in casualties, authorities said, and the base has been put on lockdown. "The installation was locked down at 11:04 a.m. and law enforcement is on the scene," Fort Stewart said in a Facebook post, adding the incident happened in the 2nd Armored Brigade Combat Team area and that casualties had been reported. No further information was immediately available, including the number of casualties and their severity. A spokesperson for the Liberty County Sheriff's Office said the agency was assisting in the response at Fort Stewart but referred all questions to the U.S. Army. Governor Brian Kemp wrote on X that he and his family were "saddened by today's tragedy" at the base. "We are keeping the victims, their families, and all those who answer the call to serve in our hearts and prayers, and we ask that Georgians everywhere do the same," he added. Fort Stewart is about 225 miles (362 km) southeast of Atlanta and 40 miles (64 km) southwest of Savannah. REUTERS