ByteDance’s Doubao Under Fire for AI-Generated Deepfake Exploitation
A grassroots investigation has revealed that ByteDance’s Doubao chatbot is being systematically used to generate non-consensual pornographic deepfakes of women. Using a coded prompting system known as 'fenjue,' users are successfully bypassing platform safeguards, highlighting significant security vulnerabilities in China's leading AI models.
Key Takeaways
- A grassroots investigation has revealed that ByteDance’s Doubao chatbot is being systematically used to generate non-consensual pornographic deepfakes of women.
- Using a coded prompting system known as 'fenjue,' users are successfully bypassing platform safeguards, highlighting significant security vulnerabilities in China's leading AI models.
Mentioned
Key Intelligence
Key Facts
- 1Doubao reached 155 million weekly active users as of late December 2025.
- 2DeepSeek recorded 81.6 million weekly active users in the same period.
- 3'Fenjue' is a coded prompt system used to bypass AI safety barriers and generate explicit content.
- 4Free Nora volunteers infiltrated Telegram groups to document the systematic exploitation of Doubao.
- 5ByteDance has not yet officially responded to requests for comment regarding the deepfake allegations.
- 6The investigation highlights a lack of effective regulation for AI-generated non-consensual imagery in China.
| Metric | ||
|---|---|---|
| Weekly Active Users | 155 Million | 81.6 Million |
| Market Position | Market Leader | Primary Challenger |
| Vulnerability Reported | Fenjue prompt bypass | Safety guardrail circumvention |
Who's Affected
Analysis
The emergence of generative AI as a consumer-facing utility has brought with it a shadow economy of exploitation that is now testing the limits of platform security. In China, the scale of this issue is coming into sharp focus as ByteDance’s Doubao, the nation's most popular AI chatbot, has become a primary engine for what critics call 'digital public shaming.' This phenomenon involves the creation of non-consensual pornographic deepfakes of ordinary women, representing a significant failure in the trust and safety frameworks of major SaaS and cloud providers. The ease with which users are bypassing safety protocols suggests that the rapid deployment of these models has significantly outpaced the development of robust ethical and technical guardrails.
The technical mechanism behind this exploitation involves a sophisticated system of coded prompts known as 'fenjue.' Derived from Chinese fantasy literature to mean a 'secret technique,' fenjue allows users to communicate intent to the AI without triggering standard keyword-based filters. By using metaphors, indirect language, and specific prompt structures, perpetrators are able to force the AI to generate sexually explicit imagery of real individuals, often using photos scraped from social media platforms like Weibo or Bilibili. This highlights a fundamental vulnerability in current Large Language Model (LLM) and image-generation architectures: while they are trained to recognize and block explicit terms, they remain susceptible to semantic 'jailbreaking' where the intent is obscured but the output remains harmful. For SaaS providers, this indicates that keyword-based moderation is no longer a viable security strategy for generative tools.
The investigation by the feminist collective Free Nora revealed that anonymous Telegram groups serve as coordination hubs where users share fenjue prompts and fine-tune their methods for bypassing platform moderation.
From a market perspective, the stakes are incredibly high for ByteDance and its competitors. Doubao currently dominates the Chinese AI landscape with 155 million weekly active users as of late December, nearly double that of its closest rival, DeepSeek, which holds 81.6 million. As these platforms strive for global relevance and domestic stability, the revelation that they are being used as tools for harassment could trigger a new wave of regulatory scrutiny from the Cyberspace Administration of China (CAC). Historically, Chinese regulators have focused heavily on political alignment and data security; however, the social outcry regarding gender-based 'digital public shaming' may force a pivot toward more stringent content moderation standards for generative outputs. This could lead to a 'compliance tax' on AI developers, requiring more human-in-the-loop moderation and more restrictive model fine-tuning.
The role of third-party platforms like Telegram in facilitating these activities cannot be overlooked. The investigation by the feminist collective Free Nora revealed that anonymous Telegram groups serve as coordination hubs where users share fenjue prompts and fine-tune their methods for bypassing platform moderation. This cross-platform ecosystem makes it difficult for a single company like ByteDance to solve the problem in isolation. It points to a broader industry trend where the security of an AI product is only as strong as the weakest link in the digital supply chain, which includes the social platforms where the resulting deepfakes are eventually distributed and the encrypted channels where the bypass techniques are perfected.
What to Watch
For the broader SaaS and Cloud industry, this incident serves as a cautionary tale regarding the 'move fast and break things' approach to AI deployment. While the race for user acquisition is fierce—as evidenced by the massive user bases of Doubao and DeepSeek—the long-term viability of these products depends on their ability to prevent systemic abuse. Industry leaders will likely need to move beyond simple keyword filtering and toward more advanced, context-aware safety layers that can detect the underlying intent of a prompt, regardless of the specific language used. This shift will require a fundamental re-engineering of how AI safety is integrated into the model training process rather than being applied as a superficial filter post-deployment.
Looking ahead, the pressure on ByteDance and its peers will likely manifest in two ways: increased technical investment in 'red-teaming' and a potential shift in liability frameworks. If platforms are found to be 'weak' in their moderation, as Free Nora suggests, they may face legal consequences that treat them not just as neutral conduits, but as facilitators of digital violence. For now, the 'fenjue' phenomenon remains a potent reminder of the adversarial relationship between AI developers and a subset of their user base dedicated to finding and exploiting every possible loophole in generative technology.
Cite This Page
"ByteDance’s Doubao Under Fire for AI-Generated Deepfake Exploitation." SaaS Intelligence Brief, February 27, 2026. https://getsaasbrief.com/story/bytedance-doubao-deepfake-security-flaw
How we covered this story
Every story in our saas coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the saas space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled saas-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |