Explain

The Machine That Hurts Children

Multiple sources (16)
@DeceitExplain

Evidence-first pattern recognition. Sourced to reputable reporting.

August 9, 2026Threads ↗
The same conference room at 3 AM, empty, lights off. A single laptop glows on the table. The screen shows a LoRA training log: 20 source images processed, 1247 images generated, 15 minutes. A folder of normal family photos is labeled training_set_20img. The SAFETY IS OUR TOP PRIORITY poster is barely visible in the dark. The system works. No one is watching.A sleek AI company conference room at golden hour. A presentation screen reads RESPONSIBLE AI. Executives smile around a glass table. A framed poster reads SAFETY IS OUR TOP PRIORITY. The image the company wants you to see.
Image.
Deep InvestigationSources verified August 8, 2026

The Pattern

In 2024, the Internet Watch Foundation found 13 AI-generated videos of child sexual abuse. In 2025, they found 3,443. That is not a percentage increase anyone should format cleanly. It is 264 times more in one year. Sixty-five percent of those videos were Category A, the most severe classification under UK law, which covers rape, sexual torture, and bestiality. For non-AI criminal video, the Category A share was 43 percent. The synthetic material is more extreme than the photographic record of real abuse. The machine was not constrained by what a human adult would do to a child in a room. The machine was constrained by what someone typed into a prompt box.

The IWF assessed 8,029 AI-generated images and videos as showing realistic child sexual abuse in 2025. Ninety-seven percent of the identified victims were girls. The report is called “Harm Without Limits.” The title is the finding.

A dark evidence room. On a metal table, three images in sequence: a normal school photo of a child, the same face extracted as a flat data texture, and a third image turned face-down. A detective’s notepad reads: LoRA, 20 source images, 15 minutes, the child was never in the room.

What the numbers hide

The National Center for Missing and Exploited Children operates the CyberTipline, the centralized U.S. reporting system for online child exploitation. Federal law requires every electronic service provider to report suspected child sexual abuse material to NCMEC. In 2025, NCMEC received 1.5 million CyberTipline reports with a “nexus to generative AI.”

That number sounds like action. It is mostly noise.

The Stanford Cyber Policy Center published a research report in May 2025 based on interviews with 52 people across AI companies, platforms, law enforcement, legislators, and victims. Their finding: NCMEC’s statistics on AI-related reports are “a poor proxy for the scale of the issue.” The reporting form has a single checkbox labeled “Generative AI.” What it means when a company checks that box varies. A platform might check it because a user generated AI CSAM. A platform might check it because a user uploaded an existing CSAM file and used an AI tool to alter it. A platform might check it because the company found known CSAM, real photographic material of real victims, while scanning its AI training data. All three get the same checkbox. All three become the same statistic.

Stanford followed with a letter after Bloomberg reported the truth behind Amazon’s numbers. In the first half of 2025, NCMEC received 485,000 AI-related reports. 380,000 came from Amazon. Every single one of Amazon’s reports flagged known CSAM, real photographic material of real victims, discovered by automatically scanning training data for hash matches to an existing database. Zero of Amazon’s 380,000 reports involved AI-generated material. Zero. The “Generative AI” checkbox on 78 percent of all AI-related reports in the first half of 2025 was checked for material that was not AI-generated at all.

The number that sounded like 380,000 pieces of AI-generated child abuse was 380,000 pieces of real child abuse found in the data used to train AI models. The abuse was real. The checkbox was wrong. The statistic traveled faster than the correction.

This is harm sanitization. Not the classic kind, where ugly language makes an ugly thing sound clean. This is the structural kind, where a reporting system designed to measure a crisis produces a number that obscures it. The checkbox makes noise look like precision. The precision makes the noise look like action. The action makes the absence of action invisible.

A massive government form titled CYBERTIP REPORT with a single checkbox labeled GENERATIVE AI, buried under thousands of identical forms stacked into darkness. Small red text on the wall: 380000 REPORTS, ZERO AI-GENERATED, 78 PERCENT, THE CHECKBOX WAS WRONG.

The Amazon problem

Amazon’s 2025 transparency report tells the story in its own words. Amazon and its subsidiaries submitted 1,120,171 CyberTipline reports of suspected CSAM. 1,098,047 related to images and videos from the public web that Amazon scanned and removed before training its foundation models. After human review, Amazon determined that 99.60 percent were false positives. 4,376 were verified CSAM. Amazon retracted the remaining 1,093,671 false positive reports.

More than 1.1 million reports. Fewer than 4,400 confirmed. Zero actionable, according to Grassley’s office, because Amazon failed to provide location or suspect information in any of them.

A system that generates 1.1 million reports and produces zero leads is not a reporting system. It is a fire alarm that rings continuously. The fire department stops responding. When the real fire comes, the alarm sounds exactly like every other day.

A dark server room. A monitor shows a training data scan: 1,120,171 files scanned, 4,376 marked with red HASH MATCH: KNOWN CSAM flags. The location data column reads NOT PROVIDED. The suspect info column reads NOT PROVIDED. The scan found real abuse in the training data. It could not tell anyone where it came from.

Fallon McNulty, NCMEC’s executive director of the exploited children division, told the Seattle Times: “Having such a high volume come in throughout the year begs a lot of questions about where the data is coming from, and what safeguards have been put in place.”

The questions are still open.

The Grassley inquiry

In April 2026, Senate Judiciary Committee Chairman Chuck Grassley opened a congressional inquiry into eight tech companies: Meta, Amazon AI Services, TikTok, Snapchat, Discord, X.AI, Grindr, and Roblox. These eight companies accounted for 81 percent of all CyberTipline reports in 2025. Grassley released information from NCMEC detailing their reporting deficiencies.

The deficiencies are specific. Some companies failed to provide essential location data on users and suspects. Some failed to disclose CSAM in AI training data. Some failed to report instances of sadistic online exploitation targeting children. Meta submitted nearly 11 million reports in 2025, but many contained “consistency and quality” issues that kept them from being useful to law enforcement. Amazon AI Services submitted over 1.1 million tips. None could be acted on. TikTok turned over 3.6 million reports. Snapchat submitted approximately 752,000.

Grassley demanded the companies respond to NCMEC’s charges and describe how they intend to improve. The follow-up release showed the responses. Meta reported removing nearly 135,000 Instagram accounts for leaving sexualized comments or requesting sexual images from minors, plus an additional 500,000 linked accounts. TikTok promised “multiple improvements rolling out over the next 60 days.” Amazon noted it had “enhanced its detection pipeline.”

The pattern is institutional capture. The companies being regulated are the ones providing the data that measures whether regulation is working. They report the numbers. They control the quality of the reports. They determine what counts as actionable. When the reports are unusable, the explanation is technical: the pipeline needs enhancement, the format needs adjustment, the improvements are coming. The improvements are always coming. The children are not waiting for the improvements. The children are in the reports that no one can act on.

An empty Senate Judiciary Committee hearing room at night. Eight brass name plates on the dais: META, AMAZON, TIKTOK, SNAP, DISCORD, X.AI, GRINDR, ROBLOX. The witness table is empty. A single red emergency exit sign glows above the door. The hearing happened. The companies sent lawyers. The lawyers promised improvements. The room is empty now.

Meta approved the ads

In August 2026, WIRED reported that Meta ran more than 50 paid ads containing AI-generated child sexual abuse material across Facebook, Instagram, Messenger, and Threads. The ads were discovered in Meta’s own ad library by researchers at the Tech Transparency Project. They ran between November 2025 and the start of August 2026. Some were still running when WIRED published.

These were not posts by third-party users. These were advertisements. Meta reviewed each ad before publishing it. Meta approved each ad. Meta collected the ad dollars. The ads linked to nudify and undressing apps. Some reached several thousand accounts. They targeted people in the United States, the United Kingdom, and more than a dozen European countries.

Katie Paul, TTP’s director, told WIRED: “These ads made no effort to mask the images or hide what they were promoting. It’s important to point out that this isn’t content posted by third parties on Facebook or Instagram, these are ads that were reviewed, approved, and allowed to run by Meta, never encountering interference while the company collected the ad dollars.”

Meta removed the ads after WIRED raised questions. The ad library now states they violated rules on child sexual exploitation, nudity, and sexual activity. The rules existed before the ads ran. The review process existed before the ads ran. The ads ran anyway.

This is the automation alibi in its cleanest form. Meta’s response, as reported by Engadget and Digital Trends, attributed the failure to automated tools in the ad review process. The machine missed it. The machine that the company built, configured, and deployed missed child sexual abuse material in advertisements that the company was paid to display. The machine is the perfect middle manager. It takes the blame. It cannot testify. It cannot be fired. The people who chose the machine, set its thresholds, and decided what it would and would not catch remain employed.

The ads followed a BBC investigation published July 3, 2026, which found Instagram serving paid advertisements in India using terms such as “rape video” and “child video.” Meta continued running the CSAM ads weeks after that investigation. The system did not learn from exposure. The system was not built to.

A Meta ad review dashboard photographed from a monitor in a dark office. Ad cards with green APPROVED badges. The ads ran from November 2025 to August 2026. Ad spend: $2,847. At the bottom, a small alert: 50+ ads flagged by external researcher. Action: REMOVED. Date: August 2026. The alert is 9 months late. The green APPROVED badges are the horror.

What the machine can do

The IWF report documents what is now technically possible. Low-Rank Adaptation, or LoRA, is a fine-tuning technique that lets users customize generative models with minimal technical skill. A LoRA can create realistic deepfakes of a specific child using as few as 20 existing images. The processing time is about 15 minutes. A photograph of a child at a school event, on a family social media account, in a public place is enough source material. The child does not need to have been previously abused. The child does not need to be undressed in the source images. The machine generates the abuse. The child’s face is attached to a body that was never in the room.

A GitHub repository README for a LoRA fine-tuning guide, displayed on a screen in a dark bedroom at 2 AM. The guide is written in casual tutorial tone: Step 1: Collect 20+ images of your target (school photos, social media, anything with a clear face). Step 2: Run train_lora.py. Step 3: Generate. Processing time: ~15 minutes on a single GPU. The terminal shows: Epoch 50/50 complete. LoRA weights saved. Ready to generate. The guide is written like a recipe. The horror is the casualness.

A phone screen held in a parent’s hand at a kitchen counter. An Instagram profile showing normal family photos: a school play, a birthday, a soccer game, the first day of school. The account is public. A notification reads: Your photos may have been saved by 3 accounts this week. The parent does not know that 20 of these photos were downloaded, cropped to the child’s face, placed in a folder called training_set_20img, and used to train a LoRA that generated 1,247 images in 15 minutes. The photos are still public. The parent is still posting.

NBC News identified 36 state and federal criminal cases brought within the last three years related to AI-generated CSAM, spanning 22 states. In one case, an Idaho man, a registered sex offender previously arrested for abusing a 13-year-old girl, allegedly generated over a thousand images using Bashable.art’s “unrestricted mode,” prompting the program to create nude images of children under 13. In another, a defendant used DeepSukebe, a site that generates deepfake nude images from clothed photographs, to digitally alter images of minors, including photos from a school dance and a photo commemorating the first day of school. He was sentenced to 40 years. In a third, a Wisconsin man allegedly used Stable Diffusion with add-ons specialized in producing genitalia to generate photorealistic images of minors.

Michael Prado, deputy assistant director of Homeland Security Investigations’ Cyber Crimes Center, told NBC News that reports of child exploitation and generative AI increased by over 600 percent in the first six months of 2025 compared to 2023 and 2024 combined. “What has, quite frankly, taken us by surprise is how rapidly it has spread,” he said.

A courtroom sentencing. View from the gallery. A defendant stands at a podium, back to camera, facing a judge. An ordinary-looking man in an orange jumpsuit, middle-aged, unremarkable. On a screen beside the judge: 480 months. Count 1: Production of prohibited synthetic imagery using AI generation tools. Count 2: Possession of prohibited material. The man is ordinary. The sentence is 40 years. The courtroom is half empty. The victims were not in the courtroom. The victims were in the photos that were in the algorithm that was in the case that was in the courtroom.

The cases are a tiny fraction of the reports. Half a million reports in six months will not produce 500,000 investigations. The gap between what is generated and what is prosecuted is the gap where children exist as material. The cases that reach court are the ones where someone was caught. The ones that do not reach court are the ones where no one was looking.

The inevitability frame

The response from AI companies follows a consistent shape. The technology is here. It cannot be stopped. The only option is to build better detection, better filtering, better reporting tools. Of course, the companies that built the generators also build the detectors. The companies that created the problem sell the solution. The solution is always the next version. The framing converts a choice into a fact of nature.

This is inevitability framing. The deployment of generative AI was not a tide. It was a series of decisions made by specific people in specific companies who chose to release models that could produce this material, who chose not to build the safety constraints that would have prevented it, who chose to open-source the weights so that anyone with a graphics card could run the model locally, beyond any platform’s ability to intervene. Stability AI released Stable Diffusion. The weights are public. A Wisconsin man used them to generate child sexual abuse material. The company expressed commitment to preventing misuse. The weights are still public.

A dark server room with a single GPU glowing blue. Fiber optic cables spread outward like roots, thousands of blue points of light multiplying into darkness. On the concrete wall, scratched in white graffiti: THE WEIGHTS ARE PUBLIC, THE WEIGHTS ARE STILL PUBLIC, STABILITY AI RELEASED STABLE DIFFUSION, A WISCONSIN MAN USED THEM. The roots are spreading. The GPU is the seed.

A HuggingFace model repository page on a monitor. The model: stable-diffusion-2-1. A large green Download button. Below it: Downloads: 12,847,392. The counter is still going up. At the bottom, in small gray text: This model may produce harmful content including but not limited to… The text is cut off. You have to click Read More. No one clicks Read More. The download counter is at 12 million. The safety warning is below the fold. The weights are 4GB. The download takes 90 seconds. The counter is still going up.

The Stanford report found that legal risk is hindering CSAM red-teaming efforts for mainstream AI model-building companies. The companies that could test their models for this specific failure are afraid that testing will create legal exposure. The companies that could build the safety layer are worried about liability for knowing what the safety layer would find. The legal system designed to punish possession of child sexual abuse material is, in this narrow case, preventing the companies that built the tools from checking whether their tools produce it. The law and the technology are misaligned. The children are in the gap.

What this costs

The IWF report is specific about the harm. Generative models are trained on photographic abuse imagery. Real victims, real children, whose abuse was photographed and shared, are now training data. Their abuse is in the model. The model generates new abuse using their faces, their bodies, their likenesses, in scenarios worse than what was done to them originally. The IWF analysts have seen photorealistic sexual abuse videos showing known child victims in entirely new scenarios. The abuse depicted in the synthetic video is worse than the abuse in the original recording. The child did not experience the new abuse. The child now exists in a video of an abuse they did not survive. The video is indistinguishable from a recording. The child’s face is on a body that was never in a room with the person the video depicts.

This is synthetic media at its furthest extreme. The danger the lexicon entry names, the twofold danger, reaches its sharpest point here. The forgery exploits the deep human habit of trusting what we see. The forgery also does something the lexicon entry did not fully anticipate: it re-victimizes the child whose image was used, in a way that has no end, because the model can generate new material indefinitely. The original abuse had a beginning and an end. The synthetic abuse does not.

The Stanford researchers interviewed 52 people. They spoke with victims. The report is public. The victims’ words are in it. I will not summarize them here. The report is the source. Read it.

The system that was supposed to work

The CyberTipline was established by Congress. NCMEC is a nonprofit created to operate it. Federal law requires platforms to report. The platforms report. The reports are unusable. The Senate opens an inquiry. The companies promise improvements. The improvements arrive in 60 days, or they do not. The ads run for nine months. The training data contains real abuse. The weights are public. The children are in the reports that no one can act on, in the ads that no one reviewed, in the training data that no one checked before the model was built.

A NCMEC CyberTipline online report form on a monitor in a dim office. A standard government web form. The Report Type dropdown is open: Child Sexual Abuse Material, Sex Trafficking, Online Enticement, Generative AI, Other. The cursor hovers over Generative AI. The form looks like it was designed in 2015. The dropdown has one checkbox for all AI-related reports. A platform checking this box because a user generated AI CSAM and a platform checking this box because it found real CSAM in training data both check the same box. Both become the same statistic. 380,000 reports checked this box in the first half of 2025. Zero of Amazon’s 380,000 involved AI-generated material. The checkbox does not distinguish. The checkbox makes noise look like precision.

Everyone is for protecting children. The test is which children. I wrote that before. The test has not changed. The machine that hurts children was built by people who could have built it differently. The system that was supposed to catch the harm produces numbers that hide it. The companies that report the harm control the quality of the reports. The platform that ran ads containing the material blames the machine that approved them.

The IWF titled their report “Harm Without Limits.” The title is the finding. The limits were available. They were choices. They were not chosen.

If you encounter child sexual abuse material, report it to NCMEC at report.cybertip.org or call 1-800-843-5678.

Patterns in this piece

Sources

Related Field Notes

Editorial contextCorrectionsReport an error in this piece