AI-generated child sexual abuse imagery is growing faster than the laws written to contain it. On 5 October 2026 the Internet Watch Foundation (IWF), the UK charity that assesses and removes this material, reported that its analysts assessed 6,310 AI-generated images meeting the legal definition of child sexual abuse between 1 January and 30 June 2026. That is 40% more than the 4,512 identified across the whole of 2025. This analysis stays with the statistics and the policy response, and deliberately omits any description of the material itself.
What the IWF AI-generated child abuse imagery figures show
Four numbers carry most of the weight in the release.
- Volume. 6,310 images in six months, against 4,512 in the previous twelve. The IWF puts the increase over the 2025 full-year total at 40%.
- Who is depicted. Girls featured in 98% of images where gender was recorded. Children aged 7 to 13 accounted for 79% of images, up from 70% across 2025. The IWF also counted 1,004 images of children aged 3 to 6 and 190 of children under 2.
- Severity. The IWF graded 350 images as Category A, its most severe classification, alongside 403 in Category B and 5,557 in Category C. Category C made up 88% of AI content, up from 62% in 2025.
- Scope. These are images assessed as meeting the UK legal definition. Counts of images, videos and reports are different measures, so figures from different IWF publications should not be added together or compared without checking the unit.
Six months of 2026 already exceed all of 2025
AI-generated images assessed by the Internet Watch Foundation as meeting the legal definition of child sexual abuse material, and the share depicting children aged 7 to 13.
If Europe is serious about protecting children, it needs a comprehensive Child Sexual Abuse Regulation that gives platforms the legal certainty to detect, prevent and respond to known and unknown child sexual abuse content.
Kerry Smith, Chief Executive, Internet Watch Foundation
The comparison between periods has limits. A half-year count set against a full-year count shows pace, not a like-for-like annual rate, and detection effort, reporting channels and the IWF's own capacity all influence what gets counted. Even so, the direction is not in dispute: the IWF's own earlier reporting also described AI-generated material rising sharply in 2025.
The UK legal position: the Crime and Policing Act 2026
The Crime and Policing Bill received Royal Assent on 29 April 2026. According to the GOV.UK factsheet, the Act creates an offence to adapt, possess, supply or offer to supply a "CSA image generator", punishable by up to five years in prison, across England and Wales, Scotland and Northern Ireland. The Act also contains a Technology Testing Defence: a delegated power for the Secretary of State to permit relevant organisations to possess such generators for an appropriate purpose, for example testing the capabilities of models to prevent future crime.
That defence matters for developers. Safety testing of a model's ability to produce prohibited content is only possible if testers are not themselves committing an offence, and the Act routes that permission through an authorisation mechanism rather than leaving it to case-by-case prosecutorial discretion. The factsheet does not state a commencement date for these provisions.

The EU: a detection framework still unsettled
The IWF's October message to Brussels centres on the permanent Child Sexual Abuse Regulation, which would set the rules for how platforms detect and respond to abuse material. The Parliament adopted its negotiating position in November 2023 and the Council adopted its own in November 2025, and Euronews reports that trilogue negotiations are still ongoing.
In the meantime, a temporary derogation lets platforms voluntarily scan for this material under an exception to EU privacy rules. Euronews reports the EU briefly missed a deadline to extend it in early 2026, then extended it to April 2028 through a Council written procedure on 23 July 2026, by 25 votes to 1 with one abstention. The same report notes the temporary arrangement excludes end-to-end encrypted services. The permanent text remains contested, largely over scanning and privacy.
The IWF has separately argued that EU law should address AI directly. In a September 2025 blog on the recast Child Sexual Abuse Directive it called for comprehensive criminalisation of AI-generated material, including training models on existing abuse imagery and producing tools designed to create it. For related context on how the AI Act is being sequenced, see our explainer on the EU AI Act's August 2026 changes.
The US: the Take It Down Act and state criminal law
Two layers apply in the United States. Federally, the TAKE IT DOWN Act covers nonconsensual intimate imagery, including AI-generated "digital forgeries", and gave covered platforms until 19 May 2026 to offer a removal process and act within 48 hours of a valid request. The FTC announced enforcement that day, launched a complaint portal and sent compliance reminders to 15 platforms. The Act is a removal regime for intimate imagery generally, not a model-level safety rule.
At state level, ENOUGH ABUSE documents that 47 states have criminalised AI-generated or computer-edited child sexual abuse material as of September 2026, with three states and the District of Columbia not yet doing so. State law here targets creators and possessors. Separate fights over nudification statutes are playing out in court, as our coverage of Minnesota's nudify ban and the Eighth Circuit shows.
What safety by design means for model developers
Criminal law reaches people who misuse a system. Safety by design asks what the system's builders should have done before release. The IWF set out its position in a March 2026 blog, arguing that AI systems must be tested before release to ensure they cannot be adapted to generate child sexual abuse material, and that protections be built in from the start of development. Its recommendations also cover robust content moderation and the use of trusted datasets, including the IWF Hash List, to keep known abuse material out of training data.
In practice, the obligations discussed in this area fall into four groups:
- Training data hygiene. Screening datasets against known-material hash lists before training.
- Pre-release evaluation. Adversarial testing for the ability to produce prohibited content, including after fine-tuning or adaptation, which is where the UK testing defence becomes operationally relevant.
- Deployment controls. Prompt and output filtering, abuse monitoring and reporting channels.
- Release decisions. Whether and how to publish open weights, since safeguards in a downloadable model can be removed by the person who downloads it.
The open questions are real. Mandatory requirements raise definitional problems for what counts as a covered model, how developers can test for prohibited outputs lawfully, and how rules apply to open-weight releases. The IWF's position is that voluntary effort has not kept pace with the data above.
Key takeaways
- The IWF counted 6,310 AI-generated images in H1 2026 against 4,512 in all of 2025, with the share depicting children aged 7 to 13 rising from 70% to 79%.
- The UK now criminalises adapting, possessing or supplying a CSA image generator, with a testing defence for authorised organisations.
- The EU's permanent regulation is unresolved, and its interim detection derogation now runs to April 2028.
- US law combines federal takedown duties with near-universal state criminal statutes, but neither sets pre-release model requirements.
- Safety by design is the live policy question: who must test models, against what, and before which release.
If you encounter child sexual abuse material online, do not share it. Report it to the IWF at report.iwf.org.uk or to your national hotline.
Sources:
- IWF, More AI-generated child sexual abuse images found in the first six months of 2026 than all of 2025 (5 Oct 2026)
- IWF, AI-generated child sexual abuse: why safety by design must be the next step (24 Mar 2026)
- IWF, No loopholes: the EU must close the AI gap through the recast CSA Directive (22 Sep 2025)
- GOV.UK, Crime and Policing Act 2026: child sexual abuse material factsheet
- Osborne Clarke, Regulatory Outlook May 2026: Artificial intelligence
- Euronews, Why is Chat Control one of the EU's biggest digital rights fights (28 Jul 2026)
- FTC, FTC begins enforcing the TAKE IT DOWN Act (19 May 2026)
- ENOUGH ABUSE, State laws criminalizing AI-generated or computer-edited CSAM
Image credits
Header image: Berlaymont building, Brussels, by almathias via Wikimedia Commons, released under CC0. In-body image: Palace of Westminster, London, by Julian Herzog via Wikimedia Commons, licensed under CC BY 4.0.
