The Info Web

Child sexual abuse material

Statutory and institutional record of child sexual abuse material: its definition in 18 U.S.C. 2256 and UK law, the provider reporting duty, NCMEC and the CyberTipline, hash matching, the IWF, and AI training data.

1978 · United States; United Kingdom

Federal law defines "child pornography" in 18 U.S.C. § 2256 as any visual depiction of sexually explicit conduct in which the production involves the use of a minor, which is a digital, computer or computer-generated image that is, or is indistinguishable from, that of a minor, or which has been created, adapted or modified to appear that an identifiable minor is engaged in the conduct; a "minor" is a person under eighteen.1 The term "child sexual abuse material" and its abbreviation CSAM are used by the National Center for Missing and Exploited Children (NCMEC) and by the Federal Bureau of Investigation, whose March 2025 public service announcement wrote it as "Child Sexual Abuse Material ( CSAM )," and by the 2023 text of the EARN IT Act, whose section 6 stated a sense of Congress that "child sexual abuse material" has the same legal meaning as "child pornography" in federal statutes and case law.23 The statute in Title 18 of the United States Code still uses "child pornography."1

The Federal Definition

The definition was first added to the Code by Public Law 95-225 of February 6, 1978 (92 Stat. 8) as section 2253, was renumbered section 2255 and amended by Public Law 98-292 of May 21, 1984, and became section 2256 in 1986. Later amendments came by Public Law 104-208 (September 30, 1996), Public Law 108-21 (April 30, 2003), Public Law 110-401 (October 13, 2008) and Public Law 115-299 (December 7, 2018). The section also defines "identifiable minor" and states that "indistinguishable" means "virtually indistinguishable, in that the depiction is such that an ordinary person viewing the depiction would conclude that the depiction is of an actual minor engaged in sexually explicit conduct," a definition that "does not apply to depictions that are drawings, cartoons, sculptures, or paintings."1

In New York v. Ferber, decided July 2, 1982, the Supreme Court of the United States upheld a New York statute against a First Amendment challenge as applied to distributors of films of children, and stated that the test for child pornography is separate from the obscenity standard of Miller v. California.4 In Ashcroft v. Free Speech Coalition, decided April 16, 2002, the Court held the "appears to be" and "conveys the impression" provisions of the Child Pornography Prevention Act of 1996, section 2256(8)(B) and (D), overbroad and unconstitutional.5 In United States v. Williams (No. 06-694), decided May 19, 2008, the Court held that the pandering and solicitation provision of 18 U.S.C. § 2252A(a)(3)(B), enacted after Ashcroft, was not overbroad.6

The Provider Reporting Duty

Section 2258A, added by Public Law 110-401 on October 13, 2008, requires a provider that obtains "actual knowledge" of facts showing an apparent violation involving child pornography to report them "as soon as reasonably possible" to the CyberTipline operated by NCMEC. Section 2258A(f) states that nothing in the section requires a provider to monitor any user or to "affirmatively search, screen, or scan" for the facts it describes. Section 2258B bars civil and criminal claims against a provider arising from its reporting and preservation duties, except for intentional misconduct, actual malice or reckless disregard. Section 2258C allows NCMEC to give providers hash values drawn from CyberTipline reports.7

The REPORT Act, Public Law 118-59, enacted May 7, 2024, added reports of child sex trafficking and enticement under 18 U.S.C. §§ 1591 and 2422(b), extended preservation of reported content from 90 days to one year, and set the maximum fine for a first knowing and willful failure to report at $850,000 for a provider with at least 100,000,000 monthly active users and $600,000 for a smaller provider, and for a later failure at $1,000,000 and $850,000. Public Law 119-60 of December 18, 2025 added "and all supplemental data included in the report" to the reports NCMEC makes available to law enforcement.7

In United States v. Ackerman, decided August 5, 2016, the United States Court of Appeals for the Tenth Circuit (opinion by Judge Neil Gorsuch, with Judge Gregory Phillips joining and Judge Harris Hartz joining in part) held that NCMEC is a "governmental entity or agent" for Fourth Amendment purposes, citing the "law enforcement powers" conferred by 18 U.S.C. § 2258A and 42 U.S.C. § 5773(b), and that its analyst's opening of an email and its attachments that AOL had flagged by hash match was a warrantless search that exceeded AOL's private search. The opinion lists NCMEC as amicus curiae, and Dropbox, Facebook, Google, Microsoft, Pinterest, Snapchat and Twitter as amici, in support of the government.8 The Stanford Internet Observatory reported in 2024 that in United States v. Wilson (9th Cir. 2021) the Ninth Circuit applied the private search doctrine in the same way, and that Ackerman and Wilson let NCMEC and law enforcement open without a warrant only files that platform personnel had already opened or that were publicly available.9

Reports and Their Volume

NCMEC created the CyberTipline in 1998.9 Its annual tables of reports by electronic service provider give a total of 16,836,694 for 2019, 21,447,786 for 2020, 29,157,083 for 2021, 31,802,525 for 2022 and 35,944,826 for 2023; NCMEC states that the CyberTipline received 36.2 million reports in 2023, 20.5 million in 2024 and 21.3 million in 2025.1011 NCMEC attributed part of the 2024 decline to a "bundling" feature adopted by Meta Platforms, and stated that the 20.5 million reports for 2024 correspond to 29.2 million separate incidents.11

By provider, the 2023 table lists 17,838,422 reports from Facebook, 11,430,007 from Instagram and 339,412 from Discord; the 2024 table lists 8,590,357 from Facebook, 3,320,008 from Instagram, 1,851,086 from WhatsApp, 1,359,806 from TikTok, 1,175,084 from Google, 1,174,698 from Snapchat, 686,176 from X Corp., 241,354 from Discord and 24,522 from Roblox; and the 2025 table lists 4,907,710 from Facebook, 3,673,045 from Instagram, 2,355,302 from WhatsApp, 3,623,177 from TikTok, 1,461,378 from Google, 816,611 from X Corp, 752,031 from Snapchat, 489,782 from Discord, 65,381 from Roblox and 1,105,405 from Amazon AI Services.10

On April 9, 2026, Senator Chuck Grassley, chair of the Senate Judiciary Committee, released data that NCMEC had given his office on March 16, 2026 concerning eight companies (Meta, Amazon AI Services, TikTok, Snapchat, Discord, X.AI, Grindr and Roblox), which together submitted over 17 million reports in 2025, 81 percent of the CyberTipline's total. The release stated that none of the 1.1 million Amazon AI Services reports was actionable because they lacked location or suspect information, that a representative of that company told NCMEC its "systems were intentionally designed not to collect or retain information about the underlying content or the associated user," and that NCMEC listed Amazon AI Services among "poor reporter" companies. It stated that NCMEC received 1.5 million CyberTipline reports in 2025 with a generative AI nexus, including over 12,000 reports of CSAM that companies indicated were identified in training data.12

The Stanford Internet Observatory's 2024 study, based on interviews with platforms, NCMEC and law enforcement, reported that in 2023 NCMEC received $41.4 million of federal funds under the Office of Juvenile Justice and Delinquency Prevention while the 61 Internet Crimes Against Children task forces received $40.8 million, and that in 2022 "Meta and Old Navy were the top corporate donors; each contributed over $1 million."9

The National Center for Missing and Exploited Children

NCMEC reported on its returns for 2024 and 2025 government grants of $48,907,021 against total revenue of $64,507,554, and $50,280,968 against $66,813,108. Its website lists corporate board seats held by representatives of Jones Day, The Walt Disney Company, LexisNexis Special Services, Amazon Web Services, Microsoft, Gap Inc., Adobe and Verisign; its return for 2025 lists Amazon Web Services among its largest independent contractors, at $291,871.13

Hash Matching

Microsoft announced on December 15, 2009 that it was donating PhotoDNA, a technology "created by Microsoft Research" and "further developed by leading digital imaging expert Dartmouth College professor of computer science Hany Farid," to NCMEC. The release quoted Brad Smith, Microsoft's general counsel, and Ernie Allen, then president and chief executive of NCMEC, who stated that NCMEC's Child Victim Identification Program reviewed 250,000 images and videos per week; it stated that NCMEC had reviewed almost 30 million photographs and videos since 2003.14 The hash of an image is compared with hashes of known material; the Ackerman opinion describes AOL's filter as matching hash values of images that its employees had previously viewed and deemed child pornography.8 NCMEC's Form 990 for 2025 states that its Exploited Children Division maintains a hash-sharing list to support industry detection of online child sexual abuse material.15

The Internet Watch Foundation

The Internet Watch Foundation is a company limited by guarantee registered in England on August 29, 1997 (number 03426366) and a charity (1112398). For the year to March 31, 2025 its income was £7,049,679, of which £526,315 was a government grant, and its expenditure £7,174,090.16 Its 2025 report states that it assessed 451,210 reports, confirmed 311,610 as containing or leading to child sexual abuse material, and added 317,101 new images and videos to its hash list.17 Its member list divides members by annual contribution: Amazon, Apple, Anthropic, Google (since May 2004), Meta (December 2009) and Microsoft (July 2001) are listed as contributing over £90,000; Roblox, X Corp, Pinterest and Epic Games over £50,000; and Discord (since November 2023) and Dropbox over £25,000. Telegram is listed as a member since November 2024 and OpenAI since April 2025.18 Companies House records list Peter Edward Thomas Robbins as company secretary from 2002 to 2011, Susan Elizabeth Hargreaves from 2013 to 2024, Roger Alessandro Darlington as a director from 2000 to 2005 and John Adam Carr as a director from 2001 to 2003; Dr Rebecca Sorla Portnoff, an American resident in the United States, is listed as a director from January 5, 2026.19

Thorn

Thorn (EIN 27-0943677) reported on its 2024 return revenue of $16,355,617, of which $8,015,412 was program service revenue described as software subscription and service revenue, contributions of $6,661,881, expenses of $21,769,314 and net assets of $30,462,580. Its board members listed on that return include Ernie Allen and Neelie Kroes; the return also lists a Rebecca Portnoff as vice president for data science. Its series of annual returns shows contributions of $61,728,173 in 2019, against $2,498,413 in 2015 and $7,254,172 in 2018.20

Training Data

In a report dated December 20, 2023, David Thiel of the Stanford Internet Observatory described the examination of the LAION-5B dataset, which contains URLs and captions rather than images. Of 32,138,129 items above a safety cutoff, 1,679 were matches in PhotoDNA, which were reported to NCMEC and to the Canadian Centre for Child Protection; of those still live, that organization classified 746 as CSAM or possible CSAM; the report identified 3,226 dataset entries of suspected CSAM in all. It stated that "an obvious gap during the compilation of LAION datasets was that images were not checked against known lists of CSAM," and that about 30 percent of the URLs passed to PhotoDNA in its initial approach were no longer active.21

Bills in Congress

S. 1207, the EARN IT Act of 2023, was introduced April 19, 2023 by Senators Lindsey Graham, Richard Blumenthal and others, and reported by Dick Durbin on May 15, 2023. It would establish a National Commission on Online Child Sexual Exploitation Prevention of nineteen members, including the Attorney General, the Secretary of Homeland Security and the Chair of the Federal Trade Commission; add subsections (6) and (7) to Section 230 of the Communications Decency Act preserving federal civil claims and state criminal and civil claims over child sexual abuse material that is intentionally, knowingly or recklessly promoted or distributed, while providing that the use of end-to-end encryption is not "an independent basis for liability"; and state that "child sexual abuse material" has the same legal meaning as "child pornography."3 The Senate Judiciary Committee's results of its May 4, 2023 executive business meeting list S. 1207 as "ORDERED REPORTED FAVORABLY AS AMENDED: VOICE VOTE" and list S. 1199, the STOP CSAM Act of 2023 (Durbin), as "HELD."22 Discord's chief executive wrote in answers to the committee in 2024 that the company was "aligned with the goals" of the EARN IT Act but "concerned that the imposition of broad liability could inadvertently result in the over-moderation of content."23

A Government-Operated Site

In United States v. Levin, decided October 27, 2017, the United States Court of Appeals for the First Circuit stated that in February 2015 FBI agents seized control of a Tor hidden service named Playpen, which more than 150,000 users had visited between August 2014 and February 2015, and ran it for two weeks from a government facility in the Eastern District of Virginia, while a magistrate judge of that district issued a warrant on February 20, 2015 for a network investigative technique that sent identifying information from the computers of users who logged in. The court vacated the district court's suppression order on good-faith grounds. Electronic Frontier Foundation, the American Civil Liberties Union of Massachusetts and Privacy International appeared as amici.24

United Kingdom

The Protection of Children Act 1978 makes it an offence to take, make, distribute or show, or to possess with a view to distributing, an indecent photograph or pseudo-photograph of a child; "pseudo-photograph" was added with effect from February 3, 1995 by the Criminal Justice and Public Order Act 1994, and "child" means a person under eighteen. Section 160 of the Criminal Justice Act 1988 covers possession, and section 62 of the Coroners and Justice Act 2009 covers possession of non-photographic "prohibited images of a child."25 The Crime and Policing Act 2026 (2026 c. 20, Royal Assent April 29, 2026) inserted section 46A into the Sexual Offences Act 2003, making it an offence to make, adapt, possess, supply or offer to supply a "CSA image-generator," punishable on indictment by up to five years; section 46B gives a defence to a member of the Security Service, the Secret Intelligence Service or GCHQ who acts for the purposes of a function of that body, and to Ofcom acting for its online safety functions.26

Extortion Networks

The FBI's alert of June 5, 2023 (I-060523-PSA) stated that the Bureau had observed since April 2023 an increase in sextortion victims reporting the use of fake images or videos made from content on their social media accounts.27 The alert of March 6, 2025 (I-030625-PSA) stated that 764 and other violent online networks "use threats, blackmail, and manipulation to coerce or extort victims" to produce material including CSAM, that victims are typically between 10 and 17 with some as young as 9, and that the networks exist on "publicly available online platforms, such as social media sites, gaming platforms, and mobile applications"; it names no platform.2 NCMEC stated that its 2025 CyberTipline data included more than 3,000 reports of sadistic online exploitation, an increase of more than 125 percent.11 The prosecutions of CVLT and 764 members are recorded on those pages and in United States v. Rane et al. (2-25-cr-00040).

  1. 18 U.S.C. § 2256(1), (8), (9), (11) and amendment history, Legal Information Institute. https://www.law.cornell.edu/uscode/text/18/2256 ↩
  2. Federal Bureau of Investigation, Internet Crime Complaint Center, Alert I-030625-PSA, "Violent Online Networks Target Vulnerable and Underage Populations Across the United States and Around the Globe," March 6, 2025. https://www.ic3.gov/PSA/2025/PSA250306 ↩
  3. EARN IT Act of 2023, S. 1207, 118th Cong., as reported in the Senate (Calendar No. 70), May 15, 2023, secs. 3, 5, 6. https://www.govinfo.gov/content/pkg/BILLS-118s1207rs/html/BILLS-118s1207rs.htm ↩
  4. New York v. Ferber, 458 U.S. 747 (1982). https://www.law.cornell.edu/supremecourt/text/458/747 ↩
  5. Ashcroft v. Free Speech Coalition, 535 U.S. 234 (2002). https://www.law.cornell.edu/supremecourt/text/535/234 ↩
  6. United States v. Williams, No. 06-694 (U.S. May 19, 2008). https://www.law.cornell.edu/supct/html/06-694.ZS.html ↩
  7. 18 U.S.C. §§ 2258A, 2258B, 2258C, Legal Information Institute, with amendment notes (Pub. L. 110-401, 115-395, 118-59, 119-60). https://www.law.cornell.edu/uscode/text/18/2258A ; https://www.law.cornell.edu/uscode/text/18/2258B ; https://www.law.cornell.edu/uscode/text/18/2258C ↩
  8. United States v. Ackerman, 831 F.3d 1292 (10th Cir. 2016), No. 14-3265 (Gorsuch, J.), paras. 1-6, 14-17, 55-57. https://openjurist.org/831/f3d/1292/united-states-v-ackerman ↩
  9. Stanford Internet Observatory, "The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It," April 22, 2024 (Shelby Grossman, Riana Pfefferkorn, David Thiel, Sara Shah, Alex Stamos, Renée DiResta, John Perrino, Elena Cryst and Jeffrey Hancock), sec. 2, sec. 2.1 and sec. 3.2.1. https://purl.stanford.edu/pr592kc5483 ↩
  10. National Center for Missing and Exploited Children, "CyberTipline Reports by Electronic Service Providers (ESPs)," annual tables for 2019 through 2025. https://www.missingkids.org/content/dam/missingkids/pdfs/2019-reports-by-esp.pdf (and files for 2020, 2021, 2022, 2023, 2025); 2024: http://ncmec.org/content/dam/missingkids/pdfs/cybertiplinedata2024/2024-reports-by-esp.pdf ↩
  11. National Center for Missing and Exploited Children, "CyberTipline Data," 2025 and 2024 summaries. https://www.missingkids.org/gethelpnow/cybertipline/cybertiplinedata ↩
  12. Senate Judiciary Committee, "Grassley Releases New and Disturbing Information on Online Child Exploitation, Presses Tech Giants for Answers," press release, April 9, 2026. https://www.judiciary.senate.gov/press/rep/releases/grassley-releases-new-and-disturbing-information-on-online-child-exploitation-presses-tech-giants-for-answers ↩
  13. The National Center for Missing and Exploited Children, IRS Forms 990 for the years ended December 31, 2024 and 2025 (IRS object IDs 202502169349301015 and 202611699349301126), Parts VII and VIII; "Leadership: Board of Directors," accessed October 2026. https://apps.irs.gov/pub/epostcard/990/xml/2026/2026_TEOS_XML_06A.zip ; https://www.missingkids.org/footer/about/leadership/leadership-profiles ↩
  14. Microsoft, "Microsoft and National Center for Missing & Exploited Children Push for Action to Fight Child Pornography," Microsoft Source, December 15, 2009. https://news.microsoft.com/source/2009/12/15/microsoft-and-national-center-for-missing-exploited-children-push-for-action-to-fight-child-pornography/ ↩
  15. The National Center for Missing and Exploited Children, IRS Form 990 for the year ended December 31, 2025 (IRS object ID 202611699349301126), Part III. https://apps.irs.gov/pub/epostcard/990/xml/2026/2026_TEOS_XML_06A.zip ↩
  16. Charity Commission for England and Wales, Register of Charities, "Internet Watch Foundation," charity 1112398, financial year ending March 31, 2025; Companies House, INTERNET WATCH FOUNDATION, company number 03426366, incorporated August 29, 1997. https://register-of-charities.charitycommission.gov.uk/en/charity-search/-/charity-details/4013804/full-print ; https://find-and-update.company-information.service.gov.uk/company/03426366 ↩
  17. Internet Watch Foundation, 2025 IWF Data & Insights Report. https://www.iwf.org.uk/annual-data-insights-report-2025 ↩
  18. Internet Watch Foundation, "Our Members," accessed October 2026. https://www.iwf.org.uk/membership/our-members/ ↩
  19. Companies House, INTERNET WATCH FOUNDATION (03426366), officers register, accessed October 2026. https://find-and-update.company-information.service.gov.uk/company/03426366/officers ↩
  20. Thorn, IRS Form 990 for the year ended December 31, 2024 (IRS object ID 202503189349315755), Parts I, III, VII and VIII; ProPublica Nonprofit Explorer API, organization 270943677. https://apps.irs.gov/pub/epostcard/990/xml/2025/2025_TEOS_XML_11A.zip ; https://projects.propublica.org/nonprofits/api/v2/organizations/270943677.json ↩
  21. David Thiel, "Identifying and Eliminating CSAM in Generative ML Training Data and Models," Stanford Internet Observatory, December 20, 2023 (revised December 23, 2023), sections 1, 2, 4 and 5.2. https://purl.stanford.edu/kh752sm9123 ↩
  22. Senate Committee on the Judiciary, Results of Executive Business Meeting, May 4, 2023. https://www.judiciary.senate.gov/imo/media/doc/2023-05-04%20-%20EBM%20-%20Results.pdf ↩
  23. Jason Citron, Responses to Questions for the Record, hearing of January 31, 2024, U.S. Senate Committee on the Judiciary. https://www.judiciary.senate.gov/download/2024-01-31-qfr-responses-citron ↩
  24. United States v. Levin, 874 F.3d 316 (1st Cir. 2017), No. 16-1567 (Oct. 27, 2017). http://media.ca1.uscourts.gov/pdf.opinions/16-1567P-01A.pdf ↩
  25. Protection of Children Act 1978 (c. 37), ss. 1 and 7; Criminal Justice Act 1988 (c. 33), s. 160; Coroners and Justice Act 2009 (c. 25), s. 62, legislation.gov.uk. https://www.legislation.gov.uk/ukpga/1978/37/section/1 ; https://www.legislation.gov.uk/ukpga/1978/37/section/7 ; https://www.legislation.gov.uk/ukpga/2009/25/section/62 ↩
  26. Crime and Policing Act 2026 (c. 20), s. 72 (inserting Sexual Offences Act 2003, ss. 46A and 46B), legislation.gov.uk. https://www.legislation.gov.uk/ukpga/2026/20/section/72 ↩
  27. Federal Bureau of Investigation, Internet Crime Complaint Center, Alert I-060523-PSA, "Malicious Actors Manipulating Photos and Videos to Create Explicit Content and Sextortion Schemes," June 5, 2023. https://www.ic3.gov/PSA/2023/PSA230605 ↩

Named without a link 4

Find a path

Full finder →

Find a chain of links from this entry to another.

FromChild sexual abuse material

    Local network

    Search or select an entry to see how it connects to Child sexual abuse material.

    Options

    An interactive diagram of Child sexual abuse material's connections, drawn on a canvas and explored with a pointer. The same connections are listed as links in the Connected and Mentioned-in sections below.

    Loading connections… Select to explore · double-click to open
    How to read the graph
    Colour shows the entry type or cluster
    • People
    • Organizations
    • Programs
    • Events
    • Concepts
    • Places
    Node size

    Larger = more mentions across the vault.

    Connections

    A link from one entry to another.

    A name mentioned in an entry without a direct link. Toggle these with “Inferred”.

    Highlights

    Gold rings mark entries mentioned across several clusters.

    Orange rings mark your selection.

    Tags