The Tech Transparency Project published an investigation on Tuesday showing that Meta failed to detect 332 advertisements containing AI-generated child sexual abuse material on Facebook and Instagram this year. Many of the ads used photos of real children, including images of a young member of a European royal family and a preteen Instagram influencer, to promote AI "nudify" applications. The findings arrived weeks after Meta agreed to an $18 billion multistate settlement that required the company to make changes to enhance child safety on its platforms.

How the Ads Used Real Children's Photos

TTP matched multiple CSAM ads to photos of real children that appeared online. In one case, an image of a young royal was animated into a video depicting a graphic sex act. Another ad took a photo of a 14-year-old Instagram influencer showing off a sports club uniform and transformed it into explicit content. A third victim, a preteen in stock photos wearing a pink athletic outfit, was morphed into a video depicting abuse. The ads overwhelmingly depicted preteen girls, and captions enticed users with lines like "there are no restrictions" and "this is the AI men actually use."

The vast majority of the 332 ads promoted AI apps made in China. Many specifically advertised nudify applications that use AI to digitally alter images of children. TTP's findings built on an earlier batch of 53 ads the group flagged in August alongside Wired, after which Meta claimed to have rolled out new detection systems. Hundreds of new CSAM ads appeared after that announcement.

Delayed Removals and Inconsistent Enforcement

Meta removed the ads after TTP and Wired flagged them, but the response was slow and inconsistent. In the hours after TTP reported more than 300 ads, Meta quickly removed about half from its archived ad library. Many of those were not marked as violating Meta's child exploitation policy until TTP pointed out the discrepancy. One ad featuring a child in stock photos was reported on the day it started running, but Meta delayed removal for days while impressions grew from four to 330. In another case, Meta removed one ad depicting a child in a graphic sex act but refused to remove an identical ad with the same image and text, claiming it did not violate ad standards.

When TTP reported ads as involving someone under 18 or as potential sexual exploitation, Meta often took at least a week to review and frequently took no action. The delay matters because ads continued running and accumulating impressions during that window.

Meta's Financial Incentive

TTP cited a Reuters report finding that Meta does not always act immediately when Chinese resellers post violating ads, because the company depends on those resellers for billions in revenue from the Chinese ad market, where its platforms are banned. Three of Meta's ad reseller partners in China ran ads containing the same CSAM content without detection. Other ads were linked to clearly fraudulent business pages with no content or followers beyond a stock profile photo. One Facebook page claiming to represent the Church of Jesus Christ of Latter-day Saints ran a CSAM ad that escaped notice until TTP flagged it.

The ads collectively reached more than 29,000 people in the EU and 6,800 in the UK, with roughly 80 percent served in the US. Meta told Wired that the flagged ads averaged fewer than 200 impressions each with total ad spend under $5,000, but TTP suggested Meta's potential undercount means it profited more than it acknowledged.

Regulatory Pressure Mounts

Attorneys general in Michigan and Florida said they are investigating the CSAM ads. Senator Mark Warner sent a letter demanding Meta end the illegal ads following the August report. Australia's eSafety regulator, which recently banned under-16s from social media, requested information from Meta at a senior level. The Internet Watch Foundation noted that AI apps are making it far too easy to create realistic criminal imagery of child sexual abuse, creating a new risk where everyday photos of children can be transformed into explicit content. For developers building or integrating AI tools, the case is a stark reminder that image generation capabilities have direct abuse vectors that platform operators are not yet catching at scale.