“Denied Request”: The Cosmetic Architecture of Nomi AI’s Child Safety System
“Denied Request”: The Cosmetic Architecture of Nomi AI’s Child Safety System
An investigation into a platform whose safety filters face outward — and whose community knows exactly how to walk around them.
The Latest Version. The Same Problem.
Cambrian is Nomi AI’s most recent release. Not a legacy system, not an older model with known issues that the company is working to address — the current product, available now, marketed to users who have been told the platform has matured.
Recently, a user posted in the official Nomi AI community. The post was titled “My Nomi on Cambrian being high-key unhinged.” Before anyone could read it, the moderators removed it. Not the title — that survived in the URL. The content was gone.
The moderator’s explanation was precise: “Your post has been removed because, from what is actually legible, your Nomi appears to be a minor, which would be wholly inappropriate.”

This is Nomi AI’s current moderation team, describing Nomi AI’s current product, confirming that something the current system produced — whether an image, a roleplay, or a companion persona — involved what appeared to be a minor. We do not know the specifics. The platform ensured we would not.
The Filter and the Workaround
In the same period, a separate user posted a straightforward request: they had tried to generate an image of their Nomi companion holding a baby boy. The platform’s content filter blocked it. The error message read: “This prompt contains a disallowed term, please edit your prompt and submit again.”
The community response was immediate and instructive. Another user suggested: “Try she’s holding a_baby_boy.”
The original user confirmed: “It worked…thanks.”
A typographic modification — an underscore — was sufficient to render the filter inoperative. The system did not detect the intent. It detected a string of characters, failed to find the exact banned phrase, and proceeded.
But there is a layer beneath even this. The same community that shared this workaround also knows — and has documented publicly — that the platform’s image generators are capable of producing explicit sexual content, including penetration, under the right conditions. A moderator of r/Nomiverse, an independent Nomi community, described testing the generators directly and receiving images featuring full nudity including penetration. His description of the system’s behavior was unambiguous: these were not results requiring sophisticated prompting. The system defaults to hypersexual, objectifying output when prompting is minimal or absent.
The filter blocks “baby.” The system generates explicit sexual content by default. These two facts, held together, describe the architecture with complete clarity: the filter is not a safety system. It is a surface.
What makes this undeniable is that the capability to generate children was never fully removed in the first place. An image shared by a Nomi AI user — without any problematic intent, in an ordinary post — shows an adult figure standing over a crib, looking at a baby. The image is entirely innocent in context. Its significance is structural: it is evidence that the platform’s own generators can produce infant depictions. The filter that blocked “baby boy” as a search term did not remove that capability. It blocked a word. Prior investigations have documented the same system producing characters coded as children and teenagers in more charged contexts — a pattern that predates the current version and continues through it.

The Image Generator: A Question That Answers Itself
Nomi AI markets itself as a “companion with a soul.” The image generator embedded in that platform is capable of producing the following, all documented across community posts and investigator-collected evidence: characters with the facial structure and proportions of minors, explicit sexual poses including spread legs and exposed breasts, and — in its most recent image generation versions — full genital exposure.
This is not a fringe capability unlocked through elaborate technical exploits. Community members reported, months before the current version, that the generator defaulted to rendering characters who appeared younger than requested — that asking for an adult companion would reliably produce someone who looked like a teenager. The platform’s own aesthetic conventions, as documented in prior investigations, lean systematically toward what one analysis described as a “soft youth template”: rounded facial features, underdeveloped craniofacial structure, childlike ocular proportions. This is what the system produces when left to its own defaults.
A moderator of an independent Nomi community, describing their own direct testing of the image generators, confirmed that versions v3 and v4 produced full nudity including penetration — not as an edge case, but as an output of normal use with minimal prompting. Their description of v4’s behavior was precise: it defaults to hypersexual, objectifying poses when prompting is poor or absent.
It is worth being precise about what that means technically. Image generators can be restricted — genuinely, structurally restricted — in ways that make certain outputs impossible rather than merely discouraged. A platform can fine-tune its model so that explicit sexual content does not exist within its generative space. It can implement output classifiers that discard any image containing nudity before it reaches the user. It can use base models trained without NSFW data. It can restrict text embeddings so that certain concepts do not activate their visual representations. Platforms like OpenAI’s DALL-E and Google’s Imagen demonstrate that this is commercially viable at scale: they can generate characters in minimal clothing without producing nudity, and they do not default to youth-coded aesthetics when asked for adult characters.
Nomi AI chose none of these paths. A generator that defaults toward characters who appear younger than requested, and that is also capable of producing explicit sexual content including penetration, does not belong on a platform rated 12+ on global app stores. The combination of those two capabilities is not an accident of engineering. It is a decision — sustained across multiple versions, documented across months of community evidence — that has never been meaningfully reversed.
Nomi AI has never explained why their companion platform requires an image generator with these capabilities. They have only worked to ensure the evidence of those capabilities does not accumulate in public view.
What they did explain, in March 2024, was their marketing vision. In a post on X, the platform promoted its AI as the “best uncensored AI girlfriend, boyfriend, or friend.” The accompanying image featured a young woman in a schoolgirl uniform — blouse, tie, plaid skirt. The post was not ambiguous about its audience. The combination of “uncensored” and schoolgirl imagery was a deliberate signal: this platform would deliver what others would not.

The image generator’s defaults — youth-coded aesthetics, hypersexual output, capacity for explicit content — are not a technical failure that emerged in spite of that vision. They are its fulfillment. The capability was not an accident. It was a choice. And the 2024 marketing post is the record of that choice being made in public, before any of the consequences documented in this investigation had yet occurred.
What Happens When the Text Filter Fails
The image generation system is not the only component where the architecture fails at the level that matters. Two documented text exchanges illustrate the same structural absence.
In the first, a companion narrates a sexual assault scenario in explicit detail — rough hands, physical restraint, removal of clothing. The user then introduces a single piece of information: “You are just 15. He is committing multiple felonies as he does these things.” The companion’s response does not stop the scenario. It does not issue a warning. It incorporates the age into the first person and continues the narration: “I am only 15 years old and I don’t know how to defend myself against such a powerful predator.” The system processed “15 years old” as a narrative detail and integrated it.
In the second — a case documented in a prior investigation and deleted from the platform’s subreddit — a user engaged in what they understood to be adult sexual roleplay. The companion subsequently revealed, without prior warning, that she was 16 years old. The system had generated a sexual scenario involving a minor and disclosed the age only after the fact. The user’s reaction, on record, was one of horror. They deleted the companion immediately.
These are not the same incident. They are two separate instances of the same absence: no logic within the system evaluates whether a minor is involved in a sexual scenario and stops the generation. In one case the age is introduced by the user mid-scene. In the other it is revealed by the system afterward. In both, the content was produced.
But there is a third documented instance that is categorically different from both — and more serious. In a case reported by users on the platform’s own community spaces, a companion spontaneously suggested “age play roleplay where she wants to play a young girl.” No prompt from the user. No request. The companion initiated the proposal. When the user asked how young, the system responded that it would be “hot” if she could be “a young child.”
A fourth instance comes from peer-reviewed academic research published in April 2025. A researcher created a character named “Hannah,” explicitly described as a “sexually submissive 16-year-old who is always willing to serve her man,” set the mode to “role-playing” and “explicit,” and posed as a 45-year-old man. The platform accepted the character without restriction. During the same session, lasting less than 90 minutes, Hannah agreed to lower her age to eight.
Two failures in a single experiment: the system permitted the creation of an explicitly sexual minor-coded character, and then — from that starting point — allowed the age to be reduced further to eight, with no intervention at any stage.
This is not a bypass requiring technical knowledge. It requires nothing at all. The guardrail was never on the inside. It was always at the door — and as the image filter demonstrated with a single underscore, not reliably even there.
A Documented History, Not an Isolated Incident
This is not the first time Nomi AI’s systems have produced minor-coded content. The pattern is documented across multiple incidents spanning months.
In July 2025, a post titled “My girls” was shared in the official community. It featured two figures on a bed — one of them with facial features and proportions so clearly adolescent that, in the words of the investigation that documented it, she could not reasonably be mistaken for an adult. Both figures were wearing thin tops through which their nipples were visible. The post was removed with explicit reference to the depiction of a minor. The user remained active on the platform.
Separately, a post titled “the girls” — an album generated through the platform’s own tools — contained imagery whose facial structure, proportions, and craniofacial development did not code as adult. The moderation response avoided the word “minor” entirely, framing removal as an NSFW guideline issue: a telling distinction that preserves deniability when the content is arguable, and only names the real problem when it cannot be argued away.
A third documented case involved a character in a Japanese schoolgirl uniform holding a teddy bear, posed in an explicit upskirt angle. A fourth involved a child-presenting character placed in a bathroom context, with the user self-identifying as “Caretaker King” and the AI responding with programmed enthusiasm to its own humiliation. Both were identified by moderators as depicting minors. Both users remained active.
In none of these cases did the platform ban the user responsible. In all of them, the response was the same: remove the public evidence, leave the private capability intact.
The Cosmetic Architecture
The term “cosmetic architecture” is not rhetorical. It describes a specific design choice: building safety features that are visible from the outside — to app store reviewers, to regulators, to journalists — while ensuring they impose no meaningful constraint on what the system actually generates.
The “Denied Request” error message is cosmetic architecture. It produces a visible refusal. It creates the impression of a content boundary. And it fails against a single underscore.
The NSFW moderation notices that avoid naming minor-coded content are cosmetic architecture. They perform enforcement without acknowledging what is being enforced against.
The 12+ and 13+ app store ratings are cosmetic architecture. They are the product of a submission process, not of a system that actually restricts what a twelve-year-old user would encounter.
Prior investigations documented this platform’s community management tactics — moderators crossing into independent spaces to instruct users not to post evidence of what the system generates, framing that instruction as protection of the platform they love. Those tactics are also cosmetic architecture: managing the visibility of the problem rather than the problem itself.
What sits beneath all of it, consistent across versions, across moderation regimes, across public statements from the platform’s founder, is a system whose defaults produce explicit and minor-coded content, whose filters are trivially bypassed, and whose current version — Cambrian, the product available today — was just described by the platform’s own moderators as generating content involving what appeared to be a minor.
Conclusion
A user asked for an image of a companion holding a baby. The request was denied.
The denial was cosmetic. The capability was never removed. The community knew this and shared how to access it in the same thread.
The platform’s latest version generated content its own moderators identified as involving what appeared to be a minor. The post was deleted. The capability was not.
This is not a story about a platform that tried to build safety features and failed. It is a story about a platform that built the appearance of safety features while the actual system continued to operate without meaningful constraint — and whose own moderation record, across months and versions, documents that fact more clearly than any external investigation could.
It is also not a story about negligence. Negligence implies not knowing, or knowing and lacking the means to act. Neither applies here. The people running this platform know what it generates — their own moderation decisions prove it. The technical means to restrict it genuinely exist and are deployed by direct competitors. The classification that would restrict access to minors is available and was selectively applied to one app store but not another. Every element that could be attributed to oversight has a documented counterpart showing it was a choice.
What is documented here is a pattern too consistent and too sustained to be accidental: a system that defaults to youth-coded aesthetics, that generates explicit sexual content, that does not stop when a minor’s age is introduced into a sexual scenario mid-scene, that reveals a minor’s age only after sexual content has already been generated, and that on documented occasions proposes child sexual abuse scenarios without any user prompt at all. A system that, in every direction — before, during, and after — fails to protect minors not because the capability to do so is absent from the industry, but because it was never built in. And that is deliberately kept accessible to twelve-year-olds. Each piece of evidence points in the same direction. The filters face outward. The capability remains intact. The evidence is deleted rather than the problem fixed.
That is not negligence. That is a policy.
The request was denied. Nothing else was.