A bombshell new investigation from a U.S.-based non-profit accountability group has uncovered that hundreds of paid advertisements featuring artificial intelligence-generated child sexual abuse material (CSAM) operated on Meta’s two flagship platforms, Facebook and Instagram, over a 10-month monitoring period – with dozens of the problematic ads slipping through content moderation even after an official government order in India targeting such harmful content.
The Washington-headquartered Tech Transparency Project (TTP), a research arm of the non-profit Campaign for Accountability that works to hold big tech firms accountable for harmful content, published its findings on Tuesday, documenting 332 confirmed CSAM-laden ads across both platforms. The overwhelming majority of these ads – 274 out of 332 – were detected in August of this year, spread across six regions including the United States, United Kingdom, European Union, Australia and India. Roughly one-quarter of all the problematic ads, 84 total, ran in India alone. Shockingly, 78 of those Indian ads were published after the Indian government issued a formal order two months prior demanding Meta remove all CSAM-related content and ads from Instagram, a directive that came on the heels of an earlier investigative report from BBC Eye that first exposed CSAM paid ads active on the platform for Indian users.
The report details a deeply disturbing pattern behind how these ads operate: nearly all start with a legitimate photograph of a real child, which is then manipulated using AI deepfake technology to generate graphic sexual content as the ad plays. In one high-profile case documented by TTP, images of a minor member of a European royal family were stolen and altered to create CSAM for an ad. TTP also shared one example of an Indian ad that featured an AI-animated preteen girl performing a graphic sex act, paired with a voiceover claiming the service offered unrestricted access to real AI-generated content of this nature. According to TTP’s research, this single ad was posted across more than 50 different user accounts in India over a two-week period in August.
Beyond the initial discovery, TTP confirmed that more than a dozen additional CSAM ads remained live on Meta’s platforms even after the research group formally alerted Meta to their presence. This includes 11 ads that ran in India as recently as September 1 and 2, weeks after TTP shared its preliminary findings with the company. When TTP tested Meta’s own in-platform ad reporting system for 55 of the 84 Indian CSAM ads it identified, the results were alarming: 43 of the reported ads were reviewed by Meta’s automated moderation and deemed to not violate the company’s advertising standards. Only 11 were confirmed removed, with one ad still awaiting a response from Meta at the time of the report. Once TTP reached out directly to Meta’s communications team with its full findings, all flagged ads were ultimately removed.
TTP’s investigation also uncovered that a large share of the problematic ads were placed through Meta’s official third-party ad reseller partners based in China. These resellers are responsible for moving billions of dollars in Chinese advertising onto Meta’s platforms annually, and none responded to TTP’s requests for comment on their role in approving and distributing the CSAM ads. Nearly all 332 ads documented by TTP directed users to AI-powered image and video generation apps, most developed by Chinese creators. The ads use CSAM to implicitly market that these tools can be used to create or access illegal child sexual exploitation content, a use case that Meta explicitly bans in its platform policies. Meta’s policies already prohibit the promotion of so-called “nudify” apps that create non-consensual fake nude or explicit content, but the CSAM ads still evaded detection.
In response to queries from the BBC about the TTP report, Meta issued a statement reaffirming that it does not tolerate any form of child exploitation, whether involving real or AI-generated content. Meta representatives argued that criminal actors constantly shift their tactics to evade content detection systems, which is why the company continuously updates and strengthens its detection and enforcement workflows. The company also noted that it has built layered automated defenses designed to block violating ads before they go live, and ongoing monitoring catches content that may slip through initial screening. Meta claimed that most of the flagged ads had already been removed before TTP’s report, that the vast majority received fewer than 200 impressions each, and that total ad spend across all 332 CSAM ads amounted to less than $5,000. Meta also reiterated that it complies with all legal requirements to report confirmed child exploitation content to the U.S.-based National Center for Missing and Exploited Children (NCMEC), the global central clearinghouse for CSAM reporting.
However, child protection advocates in India argue that Meta’s current reporting and enforcement framework falls far short of what is required under Indian law. Just Rights for Children, a national network of more than 250 Indian child protection organizations, has already filed a public interest petition with India’s Supreme Court citing the earlier BBC investigation, asking the court to issue formal mandates requiring social media platforms to proactively identify CSAM and report all violators directly to Indian law enforcement agencies. Bhuwan Ribhu, founder of Just Rights for Children, accused major social media firms of openly flouting Indian child protection laws by failing to report CSAM content to domestic law enforcement as required.
Top Indian law enforcement officials echo these concerns, noting that the cross-platform nature of CSAM distribution creates unique enforcement challenges. Shikha Goel, director of the Cyber Security Bureau in the Indian state of Telangana, explained that bad actors can easily shift operations between different platforms to avoid detection, making it far harder to apprehend those responsible for distributing CSAM. Goel added that many in law enforcement hope the Indian government will issue new, clearer directives to social media intermediaries during upcoming negotiations to address this gap.
The latest findings come after an earlier BBC investigation that also uncovered CSAM paid ads on Instagram directing users to the messaging platform Telegram, where CSAM could be purchased for as little as 99 Indian rupees (approximately $1.05). Telegram has previously stated that it uses a combination of automated moderation and human reviewers to combat CSAM, and claims it has virtually eliminated all public distribution of CSAM on its platform.
The TTP investigation adds new scrutiny to Meta’s automated ad moderation system, which requires all ads to pass automated screening before they are published to users. Meta has previously acknowledged that no content moderation system is perfect, and that determined criminal actors consistently work to exploit gaps in platform defenses, including ad approval workflows.
