What may an image generator do with the face of a real person?
Image-generation models can now create realistic images of identifiable people in situations that never occurred. For one of the world’s largest technology companies, the question was which prohibitions were missing from policy, and why.
We combined policy research with scenario-based testing. First, we reviewed academic literature across law, philosophy, socio-technical studies, and computer science; current and draft regulation in more than a dozen jurisdictions; public debate; expert judgment; and frontline harm documentation.
Second, we used that research to generate a harms taxonomy and corresponding test prompts. We tested these on the image-generation model to identify where existing policy did not prevent harmful outputs. This gave the client a map of policy gaps grounded in observed model behaviour.
We gave the client a map of where its image-generation policy fell short. Each of more than twenty recommendations specified the gap it addressed, the harm it was meant to prevent, the evidence behind it, and the strongest argument against adopting it, so the policy team could decide what to change and say why.



