I can see how it'd be trivial to block known celebrities, but how do you handle everyone else?
Do you need to? It doesn't know everyone else. Or at least it shouldn't.
I mean a realistic take is to simply not use source images containing people at all.
AIs have been able to invent fictional people longer then they've been able to modify existing images.
> trivial to block known celebrities
see here for one example: https://news.ycombinator.com/item?id=47370100