A nonprofit research team found more than 350 video advertisements containing child sexual abuse material running across Meta’s platforms since the end of last year. The ads were not buried in obscure corners of the internet. They ran on Facebook, Instagram, Messenger, Threads, and Meta’s broader advertising network, in some cases accumulating hundreds of views while awaiting review after being reported. This is not a story about a fringe exploit. It is a story about what happens when automated content moderation meets a determined, systematic abuse campaign, and loses.
How the Ads Were Built, and What They Did
The pattern researchers at the Tech Transparency Project identified was consistent across the cache of ads. Most began with an image of a preteen or teenage girl, overlaid with text suggesting the image could be manipulated without restriction. Within seconds, the video would morph the child’s face into graphic sexual content. When clicked, the ads directed users to download AI face-swapping or video applications from Apple and Google’s app stores.
This is what makes the mechanism particularly significant: the ads were not simply distributing illegal material. They were functioning as a commercial pipeline, driving downloads of applications linked to what researchers describe as “nudification” apps, many connected to Chinese developers. The phrase repeated across many ads, “This is the AI that men actually use,” signals that the content was designed to normalize and market these tools.
Researchers were able to identify the real-world identities of four minors whose images appeared in the ads. Three were from the United States, including two teenage social media influencers with public accounts on Meta’s own platforms. One was a stock photo model whose image had been labeled as depicting a preteen on the stock photo websites where it was sourced. The fourth was a minor belonging to a European royal family, whose official photograph was transformed into a graphic video. WIRED confirmed the source image came from the official website of a royal family.
The Gap Between Policy and Practice
Meta’s advertising policies state that the company reviews all ads before they run. The ads in question were published anyway. In some instances, after researchers reported live ads through Meta’s own reporting tools, it took the company a week to act. During that window, those ads continued to accumulate views.
When Meta eventually removed some of the ads, the removal notices did not initially specify that the content violated child sexual abuse policies. That detail was only added after WIRED asked Meta about the discrepancy.
Meta had previously announced new AI tools designed to better detect and block harmful ads. The scale of what researchers found after that announcement suggests those tools did not perform as intended. Meta’s spokesperson stated that many of the ads had already been removed and that most had fewer than 200 impressions, with the company receiving under $5,000 in ad payments from the campaign. Researchers counter that the ads were shown to more than 29,000 accounts across the European Union and around 7,000 in the United Kingdom, according to data from Meta’s own ad library. Significant additional exposure occurred in the United States, Australia, and India, where Meta does not publish granular performance data.
The findings arrived as Meta is paying up to $16.7 billion to settle lawsuits related to alleged harm to children on its platforms. The company is also appealing a New Mexico court decision that would require it to improve its child sexual abuse material reporting processes and include human review.
What This Reveals About AI Moderation at Scale
Here is what most coverage of this story underemphasizes: the failure is not simply that bad actors found a loophole. The failure is structural. Automated systems, however sophisticated, operate on pattern recognition. Adversarial actors learn those patterns and adapt. The researchers noted that some ads used brief or blurred clips of minors, which Meta cited as a reason detection was more difficult. That explanation describes exactly how evasion works: the abuse material is present, but engineered to fall below the threshold that triggers automated flags.
This dynamic has broad implications for how platforms govern AI-generated content. When the volume of ads running across a network is vast, human review becomes impractical at scale. Automated systems fill that gap. But automated systems can be gamed, and the cost of gaming them, for the people who produce and distribute child sexual abuse material, is low. The cost to the children whose images are used is not.
Regulatory attention is now arriving from multiple directions. Virginia senator Mark Warner sent a letter to Meta’s CEO. Michigan’s attorney general stated the office is actively looking into the matter. Florida’s attorney general announced an investigation. Australia’s eSafety regulator said it is assessing Meta’s compliance with its rules and has requested information from the company at a senior level.
The Tech Transparency Project reported all ads to the National Center for Missing and Exploited Children’s CyberTipline and says it is consulting on how to disclose findings to those affected.
In Short
Automated content moderation, even when reinforced by AI tools, can be systematically evaded by actors who understand how detection thresholds work. More than 350 ads containing child sexual abuse material ran on Meta’s platforms over several months, some featuring identifiable real children, some removed only after external reporting, and some generating revenue for the platform in the process. The gap between a company’s stated policies and what its systems actually catch is not a technical footnote. It is where the harm lives.
Based on reporting from Wired.