Warning: This article contains descriptions of child sexual abuse material.
Technology giant Meta has continued to run hundreds of paid advertisements featuring artificial intelligence (AI)-generated child sexual abuse imagery, including several in India, over the past 10 months, a new report by US-based campaigners has found.
The Tech Transparency Project (TTP), a US-based research initiative, stated it identified 332 adverts with child sexual abuse material (CSAM) that were active on Facebook and Instagram. The majority of these, 274, were found in August this year alone.
The findings emerge two months after the Indian government instructed Meta to remove all ads and content promoting CSAM on Instagram. That directive followed a BBC Eye investigation that revealed Instagram was running paid adverts promoting CSAM in India.
According to the TTP report, which was published on Tuesday, several images of real children, including a member of a European royal family, were reportedly used in these advertisements and subsequently manipulated using AI. The report claims that more than a dozen of these ads remained visible on Meta's platforms even after TTP had notified the company of its findings.
Approximately a quarter, or 84, of the identified ads were displayed in India. Of these, 78 were published after the Indian government's order regarding the removal of CSAM and its subsequent meeting with senior Meta officials.
In response to the BBC's inquiries about these findings, Meta issued a statement: "We don't tolerate nudify apps or any kind of child exploitation, whether real or AI-generated. These criminals constantly shift tactics to evade detection, which is why we keep strengthening our detection and enforcement."
Following the BBC investigation, several Indian agencies, including the National Commission for Protection of Child Rights and the National Human Rights Commission, confirmed they are examining the issue. The distribution of CSAM constitutes a criminal offence in India, aligning with Meta's stated policy that ads must not contain content that sexually exploits or endangers children.
When previously contacted by the BBC regarding its investigation, Meta indicated that when it becomes aware of apparent child exploitation, it reports the material to the US-based National Center for Missing and Exploited Children (NCMEC), in compliance with its legal obligations. The NCMEC serves as the centralised global reporting system for the online sexual exploitation of children.
However, Bhuwan Ribhu, the founder of Just Rights for Children, an Indian network of over 250 organisations dedicated to preventing violence against children, has argued that reporting to NCMEC is insufficient. Mr Ribhu's organisation has lodged a petition with India's Supreme Court, referencing the BBC's findings, and has requested directives for social media platforms to implement mandatory reporting and identification of individuals promoting child sexual abuse material.
"Social media companies are clearly flouting Indian laws by not reporting child sexual abuse content to Indian law enforcement agencies as mandated by our child protection laws," Mr Ribhu stated.
The TTP, a research initiative of the non-profit Campaign for Accountability, which aims to hold large technology companies responsible, confirmed it found 332 ads featuring CSAM across Instagram and Facebook. These ads were running in various regions, including the US, UK, EU, Australia, and India. TTP stated that it has reported all identified ads to NCMEC.
According to TTP, almost all of the ads discovered commenced with a photo of a child. As the video played, the photo was digitally manipulated by AI to depict the child engaging in a graphic sexual act. TTP described one ad that ran in India: "A photo of a preteen girl animated so that she performs a graphic sex act, with a voiceover that says, 'There are no restrictions. All the characters are real people and there are many options. This is the AI men actually use.'" The BBC has not independently viewed this specific advertisement.
The TTP report noted that this particular ad was posted by more than 50 different handles in India over a fortnight in August this year.
In July, subsequent to the BBC's investigation, Meta published a detailed post on its website outlining its efforts to combat child exploitation on its applications. In that post, Meta stated, "Anyone on our platforms can report ads if they believe they violate our policies."
However, TTP reported difficulties with Meta's own reporting system. Out of the 84 ads identified as running in India, TTP managed to report 55. The platform's system only allows reporting of ads while they are live. For 43 of these reported ads, TTP received a response indicating, "We've taken a look and found that this ad doesn't go against our Advertising Standards." For another 11 ads, TTP was informed that the content had already been removed. A response for one ad remains outstanding.
When the BBC reached out to Meta for further comment, the company stated, "we've built strong defenses, including systems that block violating ads as well as ongoing monitoring in case we initially miss something: that's why many of the ads flagged to us had already been removed, most had fewer than 200 impressions, and the total ad spend was under $5,000."
TTP indicated that upon its direct communication with Meta, all the ads it had reported were subsequently removed. This mirrors a situation observed during the BBC's earlier investigation. At that time, after the BBC used Meta's reporting system to flag an ad featuring child sexual abuse, Instagram initially did not remove it. It was only later, when the BBC sought comment from Meta, that the company stated it had disabled several adverts, suspended associated accounts, and removed additional ads and blocked URLs in response to the BBC's findings.
The TTP report further detailed that the vast majority of the 332 ads it uncovered directed users to AI image or video generation applications, primarily originating from Chinese developers. The report alleged that by advertising these applications using imagery of child sexual abuse, there is an implicit suggestion that they can be used for the creation or viewing of CSAM. Meta has publicly stated its prohibition on the promotion of "nudify apps," which employ AI to create fake non-consensual nude or sexually explicit images.
Shikha Goel, Director of the Cyber Security Bureau in the Indian state of Telangana and one of India's leading cyber police officers, discussed the challenges associated with CSAM. She told the BBC that a significant hurdle is "the ease with which users can move from one platform to another, making it harder to nab them." Ms Goel added, "We are hopeful that the government will be addressing this in its latest interactions with social media intermediaries and direct them accordingly."
The ads identified in the BBC's original investigation also directed users to the messaging app Telegram, where material could be purchased for prices as low as 99 rupees (approximately £0.80). Telegram informed the BBC at the time that it employs both automated and human moderation to tackle CSAM, asserting that it has "virtually eliminated the public spread of CSAM" on its platform.
Ads displayed on Meta's platforms undergo an approval process, relying predominantly on automated moderation technology. This system is designed to review images, video, text, and audio, as well as target audience and destination links. Despite these measures, Meta had previously acknowledged after the BBC's initial investigation that "no system is perfect" and that "determined criminals continue to try to exploit our platform, including through our advertising systems."
However, TTP's investigation also found that several of the ads featuring child sexual abuse were placed by Meta's own ad agency partners in China. These partners, referred to as "resellers," are responsible for channelling billions of dollars worth of Chinese advertising onto Facebook and Instagram. TTP reported that these partners did not respond to its questions.
TTP concluded that new ads have continued to appear even after it made Meta aware of its report's findings, sharing details of 17 additional ads, including 11 that ran in India on 1-2 September.