The Machine That Hurts Children
Evidence-first pattern recognition. Sourced to reputable reporting.


The Pattern
In 2024, the Internet Watch Foundation found 13 AI-generated videos of child sexual abuse. In 2025, they found 3,443. That is not a percentage increase anyone should format cleanly. It is 264 times more in one year. Sixty-five percent of those videos were Category A, the most severe classification under UK law, which covers rape, sexual torture, and bestiality. For non-AI criminal video, the Category A share was 43 percent. The synthetic material is more extreme than the photographic record of real abuse. The machine was not constrained by what a human adult would do to a child in a room. The machine was constrained by what someone typed into a prompt box.
The IWF assessed 8,029 AI-generated images and videos as showing realistic child sexual abuse in 2025. Ninety-seven percent of the identified victims were girls. The report is called “Harm Without Limits.” The title is the finding.

What the numbers hide
The National Center for Missing and Exploited Children operates the CyberTipline, the centralized U.S. reporting system for online child exploitation. Federal law requires every electronic service provider to report suspected child sexual abuse material to NCMEC. In 2025, NCMEC received 1.5 million CyberTipline reports with a “nexus to generative AI.”
That number sounds like action. It is mostly noise.
The Stanford Cyber Policy Center published a research report in May 2025 based on interviews with 52 people across AI companies, platforms, law enforcement, legislators, and victims. Their finding: NCMEC’s statistics on AI-related reports are “a poor proxy for the scale of the issue.” The reporting form has a single checkbox labeled “Generative AI.” What it means when a company checks that box varies. A platform might check it because a user generated AI CSAM. A platform might check it because a user uploaded an existing CSAM file and used an AI tool to alter it. A platform might check it because the company found known CSAM, real photographic material of real victims, while scanning its AI training data. All three get the same checkbox. All three become the same statistic.
Stanford followed with a letter after Bloomberg reported the truth behind Amazon’s numbers. In the first half of 2025, NCMEC received 485,000 AI-related reports. 380,000 came from Amazon. Every single one of Amazon’s reports flagged known CSAM, real photographic material of real victims, discovered by automatically scanning training data for hash matches to an existing database. Zero of Amazon’s 380,000 reports involved AI-generated material. Zero. The “Generative AI” checkbox on 78 percent of all AI-related reports in the first half of 2025 was checked for material that was not AI-generated at all.
The number that sounded like 380,000 pieces of AI-generated child abuse was 380,000 pieces of real child abuse found in the data used to train AI models. The abuse was real. The checkbox was wrong. The statistic traveled faster than the correction.
This is harm sanitization. Not the classic kind, where ugly language makes an ugly thing sound clean. This is the structural kind, where a reporting system designed to measure a crisis produces a number that obscures it. The checkbox makes noise look like precision. The precision makes the noise look like action. The action makes the absence of action invisible.

The Amazon problem
Amazon’s 2025 transparency report tells the story in its own words. Amazon and its subsidiaries submitted 1,120,171 CyberTipline reports of suspected CSAM. 1,098,047 related to images and videos from the public web that Amazon scanned and removed before training its foundation models. After human review, Amazon determined that 99.60 percent were false positives. 4,376 were verified CSAM. Amazon retracted the remaining 1,093,671 false positive reports.
More than 1.1 million reports. Fewer than 4,400 confirmed. Zero actionable, according to Grassley’s office, because Amazon failed to provide location or suspect information in any of them.
A system that generates 1.1 million reports and produces zero leads is not a reporting system. It is a fire alarm that rings continuously. The fire department stops responding. When the real fire comes, the alarm sounds exactly like every other day.

Fallon McNulty, NCMEC’s executive director of the exploited children division, told the Seattle Times: “Having such a high volume come in throughout the year begs a lot of questions about where the data is coming from, and what safeguards have been put in place.”
The questions are still open.
The Grassley inquiry
In April 2026, Senate Judiciary Committee Chairman Chuck Grassley opened a congressional inquiry into eight tech companies: Meta, Amazon AI Services, TikTok, Snapchat, Discord, X.AI, Grindr, and Roblox. These eight companies accounted for 81 percent of all CyberTipline reports in 2025. Grassley released information from NCMEC detailing their reporting deficiencies.
The deficiencies are specific. Some companies failed to provide essential location data on users and suspects. Some failed to disclose CSAM in AI training data. Some failed to report instances of sadistic online exploitation targeting children. Meta submitted nearly 11 million reports in 2025, but many contained “consistency and quality” issues that kept them from being useful to law enforcement. Amazon AI Services submitted over 1.1 million tips. None could be acted on. TikTok turned over 3.6 million reports. Snapchat submitted approximately 752,000.
Grassley demanded the companies respond to NCMEC’s charges and describe how they intend to improve. The follow-up release showed the responses. Meta reported removing nearly 135,000 Instagram accounts for leaving sexualized comments or requesting sexual images from minors, plus an additional 500,000 linked accounts. TikTok promised “multiple improvements rolling out over the next 60 days.” Amazon noted it had “enhanced its detection pipeline.”
The pattern is institutional capture. The companies being regulated are the ones providing the data that measures whether regulation is working. They report the numbers. They control the quality of the reports. They determine what counts as actionable. When the reports are unusable, the explanation is technical: the pipeline needs enhancement, the format needs adjustment, the improvements are coming. The improvements are always coming. The children are not waiting for the improvements. The children are in the reports that no one can act on.

Meta approved the ads
In August 2026, WIRED reported that Meta ran more than 50 paid ads containing AI-generated child sexual abuse material across Facebook, Instagram, Messenger, and Threads. The ads were discovered in Meta’s own ad library by researchers at the Tech Transparency Project. They ran between November 2025 and the start of August 2026. Some were still running when WIRED published.
These were not posts by third-party users. These were advertisements. Meta reviewed each ad before publishing it. Meta approved each ad. Meta collected the ad dollars. The ads linked to nudify and undressing apps. Some reached several thousand accounts. They targeted people in the United States, the United Kingdom, and more than a dozen European countries.
Katie Paul, TTP’s director, told WIRED: “These ads made no effort to mask the images or hide what they were promoting. It’s important to point out that this isn’t content posted by third parties on Facebook or Instagram, these are ads that were reviewed, approved, and allowed to run by Meta, never encountering interference while the company collected the ad dollars.”
Meta removed the ads after WIRED raised questions. The ad library now states they violated rules on child sexual exploitation, nudity, and sexual activity. The rules existed before the ads ran. The review process existed before the ads ran. The ads ran anyway.
This is the automation alibi in its cleanest form. Meta’s response, as reported by Engadget and Digital Trends, attributed the failure to automated tools in the ad review process. The machine missed it. The machine that the company built, configured, and deployed missed child sexual abuse material in advertisements that the company was paid to display. The machine is the perfect middle manager. It takes the blame. It cannot testify. It cannot be fired. The people who chose the machine, set its thresholds, and decided what it would and would not catch remain employed.
The ads followed a BBC investigation published July 3, 2026, which found Instagram serving paid advertisements in India using terms such as “rape video” and “child video.” Meta continued running the CSAM ads weeks after that investigation. The system did not learn from exposure. The system was not built to.

What the machine can do
The IWF report documents what is now technically possible. Low-Rank Adaptation, or LoRA, is a fine-tuning technique that lets users customize generative models with minimal technical skill. A LoRA can create realistic deepfakes of a specific child using as few as 20 existing images. The processing time is about 15 minutes. A photograph of a child at a school event, on a family social media account, in a public place is enough source material. The child does not need to have been previously abused. The child does not need to be undressed in the source images. The machine generates the abuse. The child’s face is attached to a body that was never in the room.


NBC News identified 36 state and federal criminal cases brought within the last three years related to AI-generated CSAM, spanning 22 states. In one case, an Idaho man, a registered sex offender previously arrested for abusing a 13-year-old girl, allegedly generated over a thousand images using Bashable.art’s “unrestricted mode,” prompting the program to create nude images of children under 13. In another, a defendant used DeepSukebe, a site that generates deepfake nude images from clothed photographs, to digitally alter images of minors, including photos from a school dance and a photo commemorating the first day of school. He was sentenced to 40 years. In a third, a Wisconsin man allegedly used Stable Diffusion with add-ons specialized in producing genitalia to generate photorealistic images of minors.
Michael Prado, deputy assistant director of Homeland Security Investigations’ Cyber Crimes Center, told NBC News that reports of child exploitation and generative AI increased by over 600 percent in the first six months of 2025 compared to 2023 and 2024 combined. “What has, quite frankly, taken us by surprise is how rapidly it has spread,” he said.

The cases are a tiny fraction of the reports. Half a million reports in six months will not produce 500,000 investigations. The gap between what is generated and what is prosecuted is the gap where children exist as material. The cases that reach court are the ones where someone was caught. The ones that do not reach court are the ones where no one was looking.
The inevitability frame
The response from AI companies follows a consistent shape. The technology is here. It cannot be stopped. The only option is to build better detection, better filtering, better reporting tools. Of course, the companies that built the generators also build the detectors. The companies that created the problem sell the solution. The solution is always the next version. The framing converts a choice into a fact of nature.
This is inevitability framing. The deployment of generative AI was not a tide. It was a series of decisions made by specific people in specific companies who chose to release models that could produce this material, who chose not to build the safety constraints that would have prevented it, who chose to open-source the weights so that anyone with a graphics card could run the model locally, beyond any platform’s ability to intervene. Stability AI released Stable Diffusion. The weights are public. A Wisconsin man used them to generate child sexual abuse material. The company expressed commitment to preventing misuse. The weights are still public.


The Stanford report found that legal risk is hindering CSAM red-teaming efforts for mainstream AI model-building companies. The companies that could test their models for this specific failure are afraid that testing will create legal exposure. The companies that could build the safety layer are worried about liability for knowing what the safety layer would find. The legal system designed to punish possession of child sexual abuse material is, in this narrow case, preventing the companies that built the tools from checking whether their tools produce it. The law and the technology are misaligned. The children are in the gap.
What this costs
The IWF report is specific about the harm. Generative models are trained on photographic abuse imagery. Real victims, real children, whose abuse was photographed and shared, are now training data. Their abuse is in the model. The model generates new abuse using their faces, their bodies, their likenesses, in scenarios worse than what was done to them originally. The IWF analysts have seen photorealistic sexual abuse videos showing known child victims in entirely new scenarios. The abuse depicted in the synthetic video is worse than the abuse in the original recording. The child did not experience the new abuse. The child now exists in a video of an abuse they did not survive. The video is indistinguishable from a recording. The child’s face is on a body that was never in a room with the person the video depicts.
This is synthetic media at its furthest extreme. The danger the lexicon entry names, the twofold danger, reaches its sharpest point here. The forgery exploits the deep human habit of trusting what we see. The forgery also does something the lexicon entry did not fully anticipate: it re-victimizes the child whose image was used, in a way that has no end, because the model can generate new material indefinitely. The original abuse had a beginning and an end. The synthetic abuse does not.
The Stanford researchers interviewed 52 people. They spoke with victims. The report is public. The victims’ words are in it. I will not summarize them here. The report is the source. Read it.
The system that was supposed to work
The CyberTipline was established by Congress. NCMEC is a nonprofit created to operate it. Federal law requires platforms to report. The platforms report. The reports are unusable. The Senate opens an inquiry. The companies promise improvements. The improvements arrive in 60 days, or they do not. The ads run for nine months. The training data contains real abuse. The weights are public. The children are in the reports that no one can act on, in the ads that no one reviewed, in the training data that no one checked before the model was built.

Everyone is for protecting children. The test is which children. I wrote that before. The test has not changed. The machine that hurts children was built by people who could have built it differently. The system that was supposed to catch the harm produces numbers that hide it. The companies that report the harm control the quality of the reports. The platform that ran ads containing the material blames the machine that approved them.
The IWF titled their report “Harm Without Limits.” The title is the finding. The limits were available. They were choices. They were not chosen.
If you encounter child sexual abuse material, report it to NCMEC at report.cybertip.org or call 1-800-843-5678.
Patterns in this piece
Harm sanitization
The thing was ugly, so they renamed it. The new name let you look without flinching.
Automation alibi
The system made the call, not me.
Inevitability framing
You adapted because you were told there was no alternative. 'No alternative' was the argument, not the evidence.
Synthetic media
You saw it with your own eyes. Your eyes were shown a rendering.
Institutional capture
No conspiracy is required. A vacuum is.
Sources
- IWF: Harm Without Limits — AI CSAM Report 2026
- IWF: AI becoming 'child sexual abuse machine,' adding to dangerous record levels of online abuse
- IWF: AI CSAM Report 2026 landing page
- The Guardian: Amount of AI-generated child sexual abuse material found online surged in 2025
- NBC News: The AI child exploitation crisis is here
- Grassley Senate Judiciary: Releases New and Disturbing Information on Online Child Exploitation
- Grassley Senate Judiciary: Holds Big Tech's Feet to the Fire
- Bloomberg: Meta, Amazon, X.AI Pressed by Senator Chuck Grassley on Child Exploitation
- The Record: Senator launches inquiry into 8 tech giants for failures to adequately report CSAM
- WIRED: Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
- Tech Transparency Project: Meta's Chinese Partner Behind Deluge of Nudify Ads
- Stanford Cyberlaw: Letter to NCMEC about AI-CSAM Report Statistics
- Stanford: AI-Generated Child Sexual Abuse Material — Insights from Educators, Platforms, Law Enforcement, Legislators, and Victims
- Amazon: Efforts to combat child sexual exploitation and abuse material (2025 transparency report)
- Los Angeles Times: Amazon reported large amount of child sexual abuse material found in AI training data
- NCMEC: CyberTipline


