AI & Emerging Tech

X.AI Challenges Minnesota’s AI “Nudification” Ban on First Amendment Grounds

By Arnold D. Lee · August 11, 2026 · Updated August 21, 2026

State legislatures have spent the past two years racing to regulate specific applications of artificial intelligence, and few targets have drawn as much bipartisan urgency as “nudification” tools — AI image editors that let a user upload an ordinary photograph and generate a version depicting the subject nude or partially undressed. Minnesota became the first state in the country to ban that capability outright, rather than simply punishing the people who misuse it, and the company behind one of the most widely used AI image tools on the market has now asked a federal court to strike the law down before it can be enforced. The resulting case is an early and closely watched test of a question that will recur across dozens of statehouses: how far can a state go in regulating what an AI system is permitted to generate before it runs into the First Amendment?

On July 27, 2026, X.AI LLC — the Elon Musk-owned company that develops the Grok chatbot and its Grok Imagine image-generation tool — sued Minnesota Attorney General Keith Ellison in the U.S. District Court for the District of Minnesota, seeking to enjoin the state’s new nudification law before its August 1 effective date.1 X.AI does not dispute that Minnesota has a legitimate, even compelling, interest in stopping the nonconsensual creation of AI-generated nude images of real people. Its argument is narrower, and more consequential for the broader AI industry: that the statute Minnesota actually enacted reaches so much further than that interest that it functions as a content-based restriction on a wide range of ordinary, protected image editing.

Minnesota’s Nudification Law

Minnesota Gov. Tim Walz signed House File 1606 on May 7, 2026, after it passed the House 132 to 1 and the Senate 65 to 0 — a lopsided vote reflecting how little political disagreement exists over the underlying harm the law targets.2 The statute, now codified at Minn. Stat. § 325E.91,3 prohibits any person who owns or controls a website, application, software program, or other service from allowing a user to access, download, or use that service to “nudify” an image or video of a real person, or from nudifying an image on a user’s behalf. A separate provision bars advertising or promoting a nudification service. Unlike most existing state deepfake statutes, which impose liability on the individual who creates or distributes a nonconsensual image, HF 1606 places the entire enforcement weight on the platform or tool that made the image possible in the first place; the person who actually generates and shares the image is not directly reached by the statute at all.

The statute defines “nudify” as altering or generating an image so that it depicts “an intimate part not depicted in an original unaltered image or video of an identifiable individual,” where the result is realistic enough that a reasonable viewer would believe the depicted body part belongs to that person. For “intimate part,” the law borrows a definition from Minnesota’s criminal sexual conduct statute — the primary genital area, groin, inner thigh, buttocks, or breast of a human being — a list drafted to define unwanted physical touching, not photographic content.4 The law contains no consent defense and no scienter or knowledge requirement: liability attaches whenever a covered service is used to produce a qualifying image, regardless of whether the subject consented, whether the platform prohibited the conduct in its terms of service, or whether the platform took reasonable steps to prevent it.

The statute does, however, contain one carve-out that has drawn little attention outside the litigation and that shapes the entire constitutional question. Subdivision 3 provides that the prohibition does not apply “when the website, application, software, program, or other service requires the technical skill of a user to nudify an image or video,” and subdivision 1(e) defines “technical skill” as the “substantial application of individualized technological or artistic skill and judgment by a human creator in directing, shaping, or controlling the output.”5 The practical consequence is that a conventional photo editor is outside the ban while a generative tool that produces the identical image from a short prompt is inside it. Minnesota has embraced that reading rather than resisted it: in its brief opposing a preliminary injunction, the state argues that the law does not prohibit expressive conduct at all because it preserves the ability of a “human creator” to engage in a “substantial application of individualized technological or artistic skill and judgment” by, for example, photoshopping an image.6

The bill’s own drafting history shows that the broad “intimate part” definition was a choice rather than an oversight. As introduced, HF 1606 defined “intimate part” by reference to Minn. Stat. § 604.32, subd. 1(d) — the definition used in Minnesota’s civil deepfake statute, which lists discrete anatomical features. The enacted version replaced that cross-reference with the criminal sexual conduct definition, which describes general regions of the body.7

The remedies are more layered than early coverage of the law suggested, and they are not interchangeable. Subdivision 5(a) authorizes the attorney general to enforce the statute under Minn. Stat. § 8.31 and creates a civil penalty of up to $500,000 “for each unlawful access, download, or use.” That penalty belongs to the state alone; the proceeds are deposited in the general fund and appropriated each year to the commissioner of public safety for victim-services grants. The private right of action in subdivision 4 is separate and differently calibrated: a depicted individual may recover compensatory damages, including for mental anguish or suffering, “in an amount up to three times the actual damages sustained,” plus punitive damages, injunctive relief, and reasonable attorney fees, costs, and disbursements. The statute does not give private plaintiffs access to the $500,000 penalty, and its damages provision is a capped multiplier of actual damages rather than a separate award of treble damages on top of compensatory damages.8

One further provision cuts against the common description of HF 1606 as a pure no-fault regime. Subdivision 7 states that the section “does not alter or amend the liabilities and protections granted by” 47 U.S.C. § 230 and “shall be construed in a manner consistent with federal law.”9 How much work that savings clause does is genuinely unsettled. Section 230 ordinarily prevents an interactive computer service from being treated as the publisher or speaker of content supplied by someone else, but no court has yet decided how that immunity applies to a provider whose own model generates the image in response to a user’s prompt. A platform facing a Minnesota enforcement action will have a statutory-construction argument that the drafters themselves supplied, and the strength of that argument will depend on how courts eventually resolve the Section 230 question for generative outputs.

X.AI’s Constitutional Challenge

X.AI’s complaint frames HF 1606 as a content-based restriction on speech subject to strict scrutiny under the Supreme Court’s decision in Reed v. Town of Gilbert, which held that a law is content-based, and therefore subject to strict scrutiny, whenever applying it requires examining what a piece of expression says or depicts, and that content-based laws are presumptively unconstitutional unless the government proves they are narrowly tailored to serve compelling state interests.10 X.AI’s complaint states the standard more demandingly, describing strict scrutiny as requiring the government to prove narrow tailoring “through the least restrictive means”; Reed itself speaks only of narrow tailoring to a compelling interest, and practitioners should be careful not to import the least-restrictive-means formulation into a citation of Reed. Because enforcing HF 1606 requires determining what an image depicts, X.AI argues the law is content-based on its face, and that Minnesota cannot satisfy strict scrutiny because far less restrictive alternatives exist, including the distribution-based nonconsensual-imagery statutes that most other states have already enacted.

The complaint argues the statute’s borrowed “intimate part” definition sweeps in a large volume of protected expression that has nothing to do with image-based sexual abuse, photographs of men without shirts, people in shorts or swimwear, and other body parts that are ordinarily and lawfully depicted in public.11 Because the statute does not distinguish a nonconsensual sexual deepfake from a satirical image, a restored family photograph, or an otherwise innocuous edit made with Grok Imagine, X.AI contends the law is substantially overbroad relative to the legitimate sweep of conduct it could otherwise reach.

The technical-skill exemption sharpens that problem rather than solving it, and it is the feature of the statute most likely to decide the case. Subdivision 3 sorts services by how much human effort they demand, not by what the resulting image depicts, whether the subject consented, or whether the image is ever shared. The same picture of the same person is lawful when a skilled user assembles it by hand in a conventional photo editor and unlawful when a generative tool produces it from a prompt. Minnesota defends that line as a regulation of technology rather than of content, but the line does not track any of the harms the state invokes; it tracks ease of use. That gives X.AI a strong argument on both of its theories. On the content-based theory, a statute whose exemption turns on the quality of a “human creator’s” artistic judgment requires an enforcing official to evaluate expression rather than conduct. On the overbreadth theory, the exemption confirms that Minnesota does not regard the depiction itself as the evil to be prevented — if it did, the Photoshop version would be banned too.

X.AI’s second major argument targets the statute’s strict-liability structure. The complaint asserts that because the law imposes liability regardless of a platform’s content-moderation efforts, and because no image-generation system can filter every possible attempt to circumvent its safeguards with perfect accuracy, HF 1606 effectively forces providers to either withdraw general-purpose image-editing functionality altogether or accept unlimited financial exposure. X.AI has already restricted Grok Imagine’s editing features for users located in Minnesota, which its complaint describes as leaving it “no practical choice” when confronted with $500,000-per-image strict liability and no safe harbor.12 The absence of any safe harbor for platforms that prohibit and actively police nudification, X.AI argues, is itself evidence that the law is not narrowly tailored, since a law that treats a compliant platform the same as a bad actor cannot be the least restrictive means of achieving the state’s interest. That argument echoes the Supreme Court’s reasoning in Counterman v. Colorado, which held that even categories of speech that receive no First Amendment protection at all, such as true threats, generally require some showing of the speaker’s mental state before liability can attach.13

Where the Case Stands

X.AI moved for a temporary restraining order on July 29, 2026, two days after filing suit and just three days before the law’s effective date. U.S. District Judge Donovan Frank denied that motion on July 31, but on narrow procedural grounds that did not reach the constitutional merits. Judge Frank found that X.AI’s own delay undercut its claim of irreparable harm, writing that the company “filed the motion on July 29, 2026, nearly three months after the law was signed, and only three days before the law is set to take effect,” and that “such a delay in bringing the action and the motion suggests that harm is not immediate.”14 HF 1606 accordingly took effect as scheduled on August 1, 2026. Rather than dismissing X.AI’s request outright, Judge Frank converted the motion into one for a preliminary injunction and set an expedited briefing schedule. Attorney General Ellison filed his opposition brief on August 14, arguing that X.AI had shown no irreparable harm, that its delay undercut the request, and that a pre-enforcement facial challenge fails because the statute has substantial constitutional applications.15 Ellison has also defended the law publicly, stating that nudification tools “have been used to generate child sexual abuse materials and harass people in the vilest ways imaginable.”16

The federal government then entered the case on the company’s side of the argument. On August 18, 2026, the United States filed a statement of interest under 28 U.S.C. § 517, signed by Associate Attorney General Stanley E. Woodward, Jr. The filing does not take a position on whether the injunction should issue. It argues instead that HF 1606 “sweeps more broadly than federal law” in four specific respects: its borrowed “intimate part” definition is broader than the definition of “intimate visual depiction” used in the TAKE IT DOWN Act; it imposes strict liability where federal law requires knowledge or at least affords a notice-and-removal opportunity; it applies even where an adult consents, including where a user generates an image of himself; and it contains no exemption for matters of public concern. The United States offers a concrete illustration — an artificially generated image of a shirtless man in a swimming pool would fall within HF 1606 but outside federal law — and describes subdivision 3 as a “nebulous savings clause.” The filing also ties the case to the administration’s stated preference for one national AI standard rather than “50 discordant state ones.”17 A statement of interest is not a ruling and carries no formal weight, but the participation of the Justice Department on the challenger’s side of a state AI statute is itself a signal to other legislatures.

Judge Frank heard argument on the preliminary injunction on August 19, 2026. X.AI’s counsel argued that the legislature never weighed the First Amendment problems and that the statute could be fixed by keying liability to consent and distribution and adding a good-faith safe harbor. Assistant Attorney General Janine Kimble responded that terms of service are not enough, noting that X.AI is still reporting tens of thousands of users who create such images, and that after-the-fact remedies require someone to see the image, report it, and locate a user within a court’s reach. The court took the motion under advisement without ruling and said it would issue a decision as soon as possible.18 As of this writing no ruling has issued, and HF 1606 remains in force, including against X.AI.

A Broader Pattern in State AI Regulation

Minnesota’s approach did not emerge in a vacuum. Nearly every state has now enacted some form of law addressing nonconsensual intimate imagery or AI-generated sexual content involving minors, and by one recent count roughly 48 states have some statute on the books addressing nonconsensual deepfakes, AI-generated child sexual abuse material, or both.19 Most of those laws target the creation or distribution of specific images after the fact, leaving platforms exposed only when they knowingly host or fail to remove offending content. Texas is the closest analog. S.B. 441, effective September 1, 2025, added Tex. Civ. Prac. & Rem. Code § 98B.0022, which makes liable a person who owns “a publicly accessible nudification application from which the material is produced,” along with website owners who recklessly facilitate production and payment processors who recklessly process payment for it. The same act added an affirmative defense in Tex. Penal Code § 21.165(c-5) for an AI provider that prohibits the conduct in its terms and takes affirmative technological steps — training, filtering, and reporting tools — to prevent it.20 California’s AB 621, enacted the same year, expanded an existing civil cause of action (originally enacted in 2019) to reach “deepfake pornography services” and those who knowingly facilitate them, raising statutory damages to up to $250,000 for malicious violations.21 At the federal level, the TAKE IT DOWN Act criminalizes the knowing publication of nonconsensual intimate images and digital forgeries and requires covered online platforms to establish a notice-and-removal process, but does not ban the underlying editing technology.22

Minnesota is therefore not the only state to point its statute at the tool rather than at the person who misuses it; Texas and California both reach operators of nudification services. What sets HF 1606 apart is the combination of three features. It carries a $500,000 penalty per unlawful access, download, or use, an order of magnitude above California’s $250,000 ceiling. It contains no scienter element at all, where Texas requires recklessness, California requires knowledge, and the federal statute requires knowledge. And it provides no good-faith safe harbor for a platform that prohibits and actively polices the conduct, where Texas provides exactly that defense. Those differences, not the fact that the law is aimed at a tool, are what X.AI has put at the center of its constitutional challenge.

What This Means for Businesses and Other States

Judge Frank’s forthcoming ruling will matter well beyond Minnesota. First, AI companies that offer general-purpose image or video editing tools should assume that any state considering nudification legislation may look to Minnesota’s tool-based model rather than the distribution-based approach that has prevailed until now, and should evaluate now whether their existing content-moderation architecture could survive a strict-liability standard with no safe harbor. Second, companies operating in Minnesota should treat the current statute as fully enforceable while the litigation proceeds; a TRO denial on timing grounds is not a ruling on the law’s validity, and businesses cannot rely on the pending challenge to excuse noncompliance in the interim. Third, in-house counsel advising clients on AI product design should document content-moderation efforts, filtering architecture, and enforcement statistics now, since those facts will be directly relevant if a company later needs to argue that a strict-liability regime is not narrowly tailored to the state’s interest. Fourth, businesses and trade associations that want a voice in how these statutes are drafted should engage during the legislative process rather than after enactment, since HF 1606’s own drafting history shows that the definition now under attack replaced a narrower one that appeared in the bill as introduced. Fifth, counsel reviewing a client’s exposure under a statute of this kind should read the exemptions as carefully as the prohibition; HF 1606’s technical-skill carve-out and its Section 230 savings clause are both doing real work in the litigation and would be easy to miss in a summary of the law. Sixth, companies should watch not only Judge Frank’s ruling but also how courts and legislatures in other states treat similar proposals, since a ruling either upholding or enjoining HF 1606 is likely to shape how California, New York, and other states drafting their own nudification bills approach the same content-based line-drawing problem.

Conclusion

The Minnesota case is unlikely to be the last word on how far states can go in regulating specific AI capabilities, but it will be an important early data point. X.AI has conceded that the state’s underlying interest is legitimate and even compelling; the entire dispute is about tailoring — whether a strict-liability statute with no safe harbor, no consent defense, and an exemption keyed to how much skill a tool demands is narrowly drawn to prevent AI-generated image-based abuse, or whether it reaches so much ordinary, protected image editing that it cannot survive strict scrutiny. Judge Frank has the preliminary-injunction motion under advisement, and the Justice Department has now told him the statute sweeps past federal law. Whenever the ruling comes, businesses that build or deploy generative AI image tools, and the states drafting the next generation of AI-specific legislation, will be studying the result closely.

This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.

The views expressed are those of the author alone and do not represent the views of Spencer Fane LLP or its clients. This article is for general informational purposes only and is not legal advice.

  1. Compl., X.AI LLC v. Ellison, No. 0:26-cv-03425 (DWF/DTS) (D. Minn. filed July 27, 2026), available at source. ↑
  2. H.F. 1606, 2026 Minn. Laws ch. 72 (signed May 7, 2026); House vote 132–1 and Senate vote 65–0 reported in Off. of Minn. Att’y Gen., Press Release (Aug. 18, 2026), available at source. ↑
  3. Minn. Stat. § 325E.91, enacted by 2026 Minn. Laws ch. 72, § 1; full enacted text available at source. ↑
  4. Minn. Stat. § 609.341, subd. 5, available at source. ↑
  5. Minn. Stat. § 325E.91, subds. 1(e), 3, supra note 3. ↑
  6. Def.’s Mem. of Law in Opp’n to X.AI’s Mot. for a Prelim. Inj. at 31, X.AI LLC v. Ellison, No. 26-cv-03425 (DWF/DTS) (D. Minn. Aug. 14, 2026) (Doc. 38), available at source. ↑
  7. Compare H.F. 1606, 94th Leg., § 1, subd. 1(b) (Minn., as introduced Feb. 25, 2025) (defining “intimate part” by reference to Minn. Stat. § 604.32, subd. 1(d)), available at source, with H.F. 1606, 2d engrossment, § 1, subd. 1(c), supra note 3 (substituting Minn. Stat. § 609.341, subd. 5). ↑
  8. Minn. Stat. § 325E.91, subds. 4, 5, supra note 3. ↑
  9. Minn. Stat. § 325E.91, subd. 7, supra note 3. ↑
  10. Reed v. Town of Gilbert, 576 U.S. 155, 163–64 (2015), available at source. ↑
  11. Compl., supra note 1. ↑
  12. Compl. ¶ 7, supra note 1. ↑
  13. Counterman v. Colorado, 600 U.S. 66 (2023), available at source. ↑
  14. Order Denying Mot. for Temporary Restraining Order, X.AI LLC v. Ellison, No. 26-cv-03425 (DWF/DTS) (D. Minn. July 31, 2026), available at source. ↑
  15. Def.’s Mem. of Law in Opp’n to X.AI’s Mot. for a Prelim. Inj., supra note 6, at 1–2. ↑
  16. Off. of Minn. Att’y Gen., Press Release (July 31, 2026) (quoting Att’y Gen. Keith Ellison), available at source. ↑
  17. Statement of Interest of the United States of America, X.AI LLC v. Ellison, No. 0:26-cv-03425 (DWF/DTS) (D. Minn. Aug. 18, 2026) (Doc. 42), available at source. ↑
  18. Ryan Luetkemeyer, Elon Musk’s xAI battles Minnesota over AI ‘nudification’ ban, Courthouse News Serv. (Aug. 19, 2026), available at source. ↑
  19. MultiState.ai, Minnesota Bans Nudification Technology in First-of-Its-Kind AI Law (June 2026), available at source. ↑
  20. Tex. S.B. 441, 89th Leg., R.S. (2025) (enrolled) (adding Tex. Civ. Prac. & Rem. Code § 98B.0022 and amending Tex. Penal Code § 21.165), available at source. ↑
  21. Cal. Civ. Code § 1708.86, as amended by A.B. 621, ch. 673, 2025 Stats., available at source. ↑
  22. TAKE IT DOWN Act, Pub. L. No. 119-12 (May 19, 2025) (criminal provisions codified at 47 U.S.C. § 223(h); notice-and-removal duty codified at 47 U.S.C. § 223a; incorporating the definition of “intimate visual depiction” from 15 U.S.C. § 6851(a)(5)(A)), available at source; see also Statement of Interest of the United States, supra note 17, at 7–8. ↑