Skip to main content

AI-generated CSAM: Artificial Images, Real Harm

Reading time: 10 min

AI-generated child sexual abuse material (CSAM) is never victimless. This article explains how synthetic CSAM, deepfakes, and “nudification” apps create real harm, strain investigations, exploit real images, and demand stronger awareness, regulation, safeguards, and forensic analysis.

AI-generated CSAM: artificial images, real harm

In some countries, one child in twenty-five reports having had their photo transformed into a sexually explicit deepfake. If that number is accurate, AI-generated CSAM (child sexual abuse material) is no longer an emerging problem, it is already a large-scale child protection issue. 

The use of generative AI to create CSAM, and, more broadly, synthetic non-consensual explicit images, including those produced through so-called “nudification” apps, is a phenomenon whose true scale is often underestimated and whose nature is still widely misunderstood by the general public. In fact, AI-generated CSAM is not a lesser form of child sexual abuse material:  it’s deeply entangled with real abuse, it’s growing faster than institutions can respond, and most people, including lawmakers, still don’t understand why.

Key Takeaways

  • AI-generated child sexual abuse material (CSAM) is not victimless. Even when an image is synthetic, the harm is real, especially when it depicts, imitates, or is derived from images of real children.
  • Synthetic CSAM and real CSAM are closely connected. AI-generated abuse material may be trained on real imagery, created from existing abuse material, or produced by manipulating innocent photos of children.
  • Deepfake CSAM can waste critical investigative resources. When synthetic and real media become difficult to distinguish, investigators risk spending more time on AI media, delaying the identification of real victims.
  • Deepfake detection alone is not enough. CSAM investigations need deepfake forensics: contextual analysis, source evaluation, technical examination, repeatable workflows, and careful reporting.
  • Nudification apps and explicit deepfakes are a growing child protection risk. These tools can be used for blackmail, humiliation, coercion, and abuse, including within school communities.
  • AI-generated CSAM creates legal, technical, and social challenges. Lawmakers, technology companies, regulators, parents, and investigators all need to understand that artificial images can cause real-world harm.
  • Forensic video and image analysis remains essential. Investigators need tools to assess whether media is synthetic or real, enhance details when a real child must be identified, document findings for court, and protect victims through careful redaction.
  • The response must combine awareness, regulation, safeguards, and forensic capability. AI companies need stronger preventive measures, institutions need updated legal frameworks, and investigators need reliable methods to handle both synthetic and real evidence.

CSAM Investigations Grow into Multimedia Forensics

Historically, at Amped Software, CSAM investigators were a relatively small part of our user base, as they focused more on the specific digital forensics aspect of investigations. Still, quite a few were using tools such as Amped FIVE to investigate every little detail of exploitation videos, looking for clues in the desperate search for missing and exploited minors. For those luckily out of the field, this article represents an interesting case where subtle details in a video led to the rescue of a girl who had been abused for years.

However, with the rise of generative AI, a lot has changed. A couple of years ago, we were interviewed for the report “Generative AI for online child safety exploitation and abuse”, seeking our contribution on image and video analysis for discriminating deepfakes from real images. It was an opportunity to study the phenomenon in greater depth. When I realized how big the danger was and how little people and institutions were aware of the risks and the scope of the problem, I started advocating for greater attention to the issue. I included this topic in my institutional presentations, including the manifesto A Roadmap for Security and Justice in the AI Era”, which I presented at the European Parliament last year. I also spoke about it on TV news and shared my thoughts on LinkedIn. For some time, the issue attracted little attention outside specialist circles. That changed early this year, when Grok generated explicit images of real people, including minors, for a period before safeguards were reinstated. This forced institutions and the public to open their eyes to the situation.

The Main Dangers of AI-generated CSAM

On the surface, the creation and distribution of AI-generated explicit images could seem to be less severe than those often known as first-generation CSAM, where a real child has been directly abused, or is at immediate risk of abuse. This is far from the depths of this reality. In this section, we will see how these are strictly related and the various reasons why AI-generated CSAM is far from a victimless phenomenon.

Investigative Resources Directed Away from Real Harm

The growing amount of deepfake CSAM means that investigators are at risk of directing their efforts to search for kids that don’t exist, if they don’t realize that images are AI-generated.

Hypothetically, when we are at the point that only 1 video in 100 is real, and real and synthetic are virtually indistinguishable, how do we focus the already tight resources of law enforcement on the real ones without dispersing energy on the non-existent ones?

Ease of Generation Implies Normalization

The growing volume of easily generated and customized material drives prices down, feeds large illegal commercial markets, and gradually normalizes this content within the communities that consume it. A commonly raised concern is that the growing availability of synthetic CSAM may contribute to normalization and desensitization within offender communities. Although the empirical evidence of this on real-world offenders remains limited and the overall effect is still debated, it’s a potential additional risk that shouldn’t be dismissed.

Synthetic Media Is Trained on Real Media

AI doesn’t create images and videos from nothing. AI systems can only generate content based on patterns learned from their training data. They may have been trained not only on datasets containing CSAM, but also potentially on large volumes of innocuous images of children shared (often with good intentions by parents!) on social media.

Disturbingly, even standard training datasets used by all major providers of AI systems have been found to contain CSAM material. Notoriously, CSAM links have been identified in the LAION-5B datasets in 2023, when a Stanford study found that it contained 3,226 suspected instances of child sexual abuse material, 1,008 of which were externally validated. And as late as January 2026, Amazon discovered a high volume of CSAM in its training data, without understanding where it was coming from.

Real and Fake Are a Spectrum

Similarly to what I wrote in my previous article, things are rarely black and white. An AI-generated image doesn’t necessarily imply that it’s showing a non-existent kid. Synthetic images can depict real persons and kids, either from existing CSAM content or innocuous ones, to “nudify” them or to create additional videos of their favorite subjects. And even images of adults can be de-aged to create explicit material.

As we can see, deepfake forensics is very badly needed in this field. Once more, I want to underline that we are talking about “deepfake forensics”, not just deepfake detection. In fact, simple deepfake detection doesn’t account for the fact that whether an image or video should be considered a deepfake, depends not only on the technology used to create it, but also on the context.

To complicate matters, for example, there’s the phenomenon of AI laundering, which happens when some real footage is processed with AI (without changing its content), just to make it appear AI-generated to deepfake detectors.

Real-World Cases Confirm the Growing Threat

The scale of this isn’t theoretical: in the past 18 months alone, cases have emerged across multiple continents. A big misconception is that the only reason for the creation and sharing of CSAM material is related to some form of sexual desire. In reality, there are many other drivers, first of all, economic ones: creating and sharing this material has enormous (black) market value. The second is for financial extortion; for example, creating explicit images of a person (either minor or adult) and then blackmailing them with threats to share them with classmates, family, or coworkers. Finally, for humiliation: a big plague is the use of nudification apps between classmates and “friends”. Unfortunately, this often means that minors are usually those creating CSAM, perhaps not even realizing the severity of their actions.

According to a study done by Wired and Indicator published in April 2026, they found 88 cases in 28 countries with 640 victims of “nudification” apps in schools.

Over the past year or so, I used to keep track of the news related to investigations involving AI-generated CSAM. After all, while the previously mentioned report presented a huge number of tiplines in general, the growth of cases was still a bit hypothetical.

  • In October 2024, a student was sentenced to 18 years for producing and selling AI-generated CSAM on request.
  • In January 2025, in Randers, Denmark, a 29-year-old man was sentenced to 1 year and three months in prison for producing and possessing thousands of offensive images created with artificial intelligence.
  • In February 2025, Europol arrested at least 25 people during a worldwide operation against AI-generated CSAM.
  • In October 2025, a 52-year-old man was arrested in Venice, Italy, for creating child pornography using artificial intelligence: more than 900 AI-generated images were found.
  • In January 2026, in Charlotte, NC, a man was sentenced to 6 ½ Years for possessing this kind of material. A forensic review of the devices revealed that they contained more than 30,000 images and videos of AI-generated CSAM and over 8,600 images and videos of real media.

But recently, the number and visibility of reported cases appear to have increased significantly.

In April 2026 alone, there were the following news items:

  • A corporal in the Pennsylvania state police pleaded guilty to a set of crimes that include going through his co-workers’ underwear, possessing a stolen gun, having child sexual abuse material on his hard drives, and using AI tools to create over 3,000 explicit deepfakes.
  • A man in Ohio became the first to be convicted under a new deepfake law, pleading guilty to cyberstalking, producing explicit images and digital forgeries of child sexual abuse.
  • Another man in Michigan has been found with 40,000 CSAM images and, as a defense, he claimed that they were AI-generated images.

And, of course, there have been all kinds of abuses with explicit deepfakes for adults as well: in January 2026, in Germany, a senior staff member of the parliament was sexualized with AI.  The case was dismissed, however, because, according to German law, it can only be prosecuted if the victim personally files a complaint.

In May 2026, Italian Prime Minister Giorgia Meloni wrote on X/Twitter about being targeted with explicit deepfakes. Interestingly, according to Italian law (art. 612-quater c.p.), causing harm through the use of deepfakes is a criminal offense punishable by imprisonment from one to five years.

We Believe No One and Everyone Now

This specific case about the Italian Prime Minister, like many others, could be easily dismissed as “obviously fake”, but we should look outside our tech-savvy bubble.

A few weeks ago, I gave a presentation to company executives and managers outside the tech field, and I was shocked to learn that nobody knew what a deepfake was. Often, people do not realize that an image or video is AI-generated, even when it contains a Gemini, Sora, or other watermarks.

Interestingly, we are also starting to see the opposite effect, what is known as the “liar’s dividend”. People are becoming so used to AI-generated media that they dismiss real images as fake and stop trusting anything at all.

What is the solution? Being skeptical but pragmatic. Not taking any media at face value, asking ourselves the right questions before looking for answers, and validating the context. For example, the source of information, not just the information itself.

How Organizations Are Reacting

The volume of cases eventually forced a response.

In February 2026, UNICEF released a statement about AI-generated sexualized images of children (that I mentioned at the beginning of the article):

New evidence confirms the scale of this fast-growing threat: In a UNICEF, ECPAT and INTERPOL study across 11 countries, at least 1.2 million children disclosed having had their images manipulated into sexually explicit deepfakes in the past year. In some countries, this represents 1 in 25 children – the equivalent of one child in a typical classroom. [..] We must be clear. Sexualised images of children generated or manipulated using AI tools are child sexual abuse material (CSAM). Deepfake abuse is abuse, and there is nothing fake about the harm it causes.

1 in 25 children. The number speaks for itself.

In the same month, data protection agencies from 61 different countries signed a joint statement laying out (in a very brief, straight-to-the-point way) a warning about AI-generated images and videos of real people. These were created without consent and used to create fake intimate content, defamatory material, and harmful imagery, especially affecting children and vulnerable groups.

According to the document, the message to companies is clear:

  • Build safeguards in the systems from day one, not as an afterthought
  • Be transparent about what the technology does
  • Act fast when harm occurs
  • Work with regulators.

Interestingly, the European AI Act, widely touted as the first and most comprehensive AI regulation worldwide, didn’t initially consider this part. It defined deepfakes and their transparency requirements, but didn’t provide any prohibition or criminal charges.

But in May 2026, the EU reached a provisional agreement on updates to the AI Act, mostly as part of the Digital Omnibus package. While at the time of writing the text is not available yet, among other updates, the announcement writes: “It prohibits AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse material, such as AI “nudification” apps.

In April 2026, OpenAI released a policy document against AI-generated CSAM and related abuses. It defines three main points:

  • The need for legislative modernization, for example, to update the CSAM definition to cover synthetic and digitally altered material, clarify attempted liability (even if blocked by safeguards), but at the same time establish good-faith safe harbors.
  • Providing reporting and coordination standards, improving the reporting quality, and properly balancing AI-assisted detection and human-reviewed escalation.
  • Generative AI safeguards include, for example, prompt and intent detection, and standardized classification.

Whether these commitments translate into measurable reductions in abuse remains to be seen.

Very recently, the Magnifica Humanitas encyclical letter by Pope Leo XIV addressed the issue of AI being used to sexualize and abuse children and adults (paragraphs 141 and 142).

Finally, let’s remember that AI is not just a tool that introduces new challenges and risks; it can also be used (but shouldn’t be abused) to combat these crimes. There are organizations, such as UNICRI AI for Safer Children, that try to bring together law enforcement, technical providers, and international organizations to leverage the positive potential of AI and related technology to combat child sexual exploitation and abuse.

We Must Fight Together Against AI-generated and Real CSAM

After two years of tracking this phenomenon, several trends have become increasingly difficult to ignore. The production of AI-generated CSAM has grown faster than investigators, legislators, or the public were prepared for. For too long, it remained below the radar, treated as a niche concern rather than a systemic one. That is finally changing: lawmakers, the AI industry, and the public are beginning to grasp the scale of the problem. But awareness arriving late is not the same as the problem being under control.

There is no easy path forward. Public awareness still needs to grow: most people outside the technology and law enforcement fields remain largely uninformed about the scale of the problem, as the reaction to the Grok episode made clear.

  • Parents need to understand the danger and educate their children accordingly.
  • Lawmakers need to modernize legal definitions and impose clear obligations on technology companies, while carefully balancing investigative needs against privacy and data protection rights.
  • Technology companies must treat safeguards as a core responsibility rather than an afterthought.
  • Forensic investigators need tools capable of keeping pace with what continues to slip through.

Forensic tools have a specific and unglamorous role in this: determining whether an image or video is synthetic or real, enhancing detail when a real child needs to be identified, and documenting findings in a way that holds up in court, all while protecting victims from further exposure through careful redaction. These are not heroic acts that you will read about in the news. They are the slow, careful work that makes prosecution possible and keeps investigative resources focused on children who actually need rescuing.

And this crosses with one of the biggest challenges of our time, and for the foreseeable future: discriminating artificial intelligence from real evidence.

We are in it together.


 Martino Jerian

Martino Jerian is the CEO and Founder of Amped Software. He holds a degree in Electronic Engineering (summa cum laude) from the University of Trieste, Italy, where his thesis focused on forensic image processing. In 2008, he founded Amped Software, leading the development of advanced tools for image and video forensics. With a strong background in software engineering, he played a key role in designing and driving the initial development of the company’s products. Martino has been a contract professor in university courses on investigations, forensics, and intelligence. He has authored multiple scientific papers in the field of image and video forensics and has served as a forensic expert in high-profile judicial cases. His work bridges the gap between cutting-edge technology and the pursuit of security and justice.

Subscribe to our Blog

Receive an email notification when a new blog post is published and don’t miss out on our latest updates, how-tos, case studies and much more content!