Meta carried hundreds of ads with AI-generated child abuse imagery over nine months
The Tech Transparency Project documented the ads for WIRED. Some manipulated photographs of real children. The failure is in the automated systems Meta is now selling as agents.
An investigation by WIRED and the Tech Transparency Project has documented hundreds of advertisements carrying AI-generated child sexual abuse imagery on Meta's platforms over a nine-month period. Some of the material manipulated photographs of real children.
The finding is about the advertising system specifically, which makes it worse rather than better. Advertising is the part of Meta that is reviewed before publication, because someone is paying and the company has a commercial reason to know who.
The review that was supposed to catch it
Meta's ad review is automated at volume, with human review on escalation. Nine months of hundreds of ads is not a gap of hours between publication and takedown; it is a sustained failure of both layers, in a category where the company has stated zero tolerance and where detection technology is more mature than for almost any other class of prohibited content.
Hash-matching systems like PhotoDNA identify known material by comparing against databases of previously identified images. Generated material has no hash to match, which is precisely why this category defeats the industry's primary tool — and why classifier-based detection was supposed to have been built for it.
That some of the imagery manipulated photographs of real children removes the last remaining defence anyone offers for synthetic material, which is that no child was involved.
The context Meta launched into this week
On the same day the investigation was published, Meta launched Muse — a consumer AI agent connected to email, calendars, payment systems, health apps, smart home controls and shopping platforms, free at entry with tiers at $20 and $100 a month.
Meta's pitch for Muse rests on an architectural safety claim: a dedicated "Muse Secure VM" with browser isolation, an agent that cannot reach passwords or payment methods, and conversations not shared with advertising systems.
The question the investigation raises is not whether that architecture is well designed. It is whether Meta can operate automated systems at scale and detect when they are failing — and the answer, in the one area where it has the strongest incentive, the most mature detection technology and a pre-publication review process, is that it did not for nine months.
The launch also comes less than two weeks after Meta settled multistate litigation over social media harms to children for $18 billion.
What regulators can actually do
The European position is the more consequential one. Under the Digital Services Act, very large online platforms must assess and mitigate systemic risks including harms to minors, submit to independent audits, and give vetted researchers access to platform data.
That researcher access provision is what makes investigations like this reproducible rather than dependent on an NGO's own sampling. The European Commission designated ChatGPT a very large online platform on 31 August with 159.1 million monthly EU users; Meta's platforms have been designated since the regime began.
The EU's AI transparency rules, in force since 2 August, require disclosure when content is AI-generated. That obligation does not help here — an advertiser breaking the law about child abuse imagery is not going to comply with a labelling requirement.
Meta has not said how the ads passed review, whether the accounts were connected, or what has changed. The Tech Transparency Project's method was targeted discovery rather than a platform-wide sample, so the documented count is a floor rather than an estimate.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters