Posted on 20 Jul 2026
A teenager uploads an ordinary photograph to social media. Minutes later, someone they have never met downloads it, alters it and turns it into sexual abuse material – without their knowledge or consent. Artificial intelligence (AI) has made it easier than ever for criminals to generate abusive content, creating challenges that existing laws and detection tools were never designed to address.
Once the domain of individual offenders and closed online communities, child sexual exploitation has now become a low-risk, highly scalable source of profit for organized criminal networks. The Internet Watch Foundation’s 2026 report found that the volume of AI-generated child sexual abuse material (CSAM) on both the dark web and mainstream platforms had ‘increased exponentially’ over the past two years. It is now estimated that at least 1.2 million children have had their likeness used to generate CSAM.
With the market flooded with AI-generated images and videos, the illusion could be created that synthetic material will replace real child exploitation. However, evidence suggests the opposite. Synthetic CSAM has the potential to attract new offenders, enabling criminal groups to profit from both synthetic material and real abuse. Higher demand could also drive up recruitment, trafficking and exploitation.
Recent global law enforcement operations, led by Europol, demonstrate the scale of the threat. In 2025, Operation Cumberland, a joint effort involving authorities from 19 countries, dismantled one of the first transnational networks distributing AI-generated CSAM, identifying nearly 300 users worldwide. In July 2026, Operation Torch resulted in 28 arrests across seven European countries.
However, the production and distribution of CSAM now share operational methods with other forms of cybercrime, and the use of social media, encrypted communications and anonymous payment systems makes the market increasingly difficult to disrupt. Although AI can also help investigators identify victims, criminal actors continue to adapt faster than legislation. Integrating safety-by-design and child protection measures into AI systems will be crucial to minimizing opportunities for abuse.
AI is creating a new criminal market
AI is now being used throughout the cycle of child sexual exploitation. Offenders can create fake identities and even automate the grooming of victims, allowing them to scale up exploitation across languages and platforms. While many commercial AI platforms incorporate safeguards to prevent the creation of harmful content, researchers and law enforcement agencies have repeatedly shown that these protections can be bypassed.
Open-source AI models, which allow users to access and modify their source code, present an even greater challenge. Offenders can use these models to develop tools such as ‘nudification’ and ‘de-aging’ applications that can transform ordinary photographs into synthetic CSAM.
Moreover, the platform identified in Operation Cumberland displayed characteristics commonly associated with ‘crime-as-a-service’ models. Criminal groups could purchase AI-generated CSAM without needing the technical expertise to produce it themselves. This ability to buy rather than create abusive material risks broadening participation in offending and expediting the commercialization of child exploitation.
This reflects the broader shift identified in a recent Europol report on the current threats posed by criminal networks. While technologies such as AI are not creating entirely new criminal markets, they are accelerating existing ones by increasing their scope, efficiency and resilience, and by making them more difficult to detect and disrupt.
Research also suggests that the financial infrastructure enabling CSAM has become more sophisticated. While around half of the identified transactions are below US$100 – with costs kept low by the ease and scale of production – operators are increasingly relying on subscription-based business models to secure ongoing revenue streams. Although Bitcoin is still widely used for payments, networks also convert proceeds into privacy-focused cryptocurrencies such as Monero, which enable the rapid conversion of assets with minimal customer verification requirements. These financial practices resemble those used by other cybercriminals and illicit online marketplaces, and make it more difficult to trace and disrupt illicit financial flows.
In addition, as payments increasingly move through cryptocurrencies and online payment platforms, opportunities arise for organized criminal actors to combine child sexual exploitation with fraud, identity theft, sextortion and money laundering.
Regulatory gaps and their consequences
The success of the Europol-led enforcement operations shows that cross-border law enforcement cooperation can still be effective. However, the investigations also exposed a critical enforcement gap. The difficulty of establishing the origins or veracity of the material seized was a significant barrier to identifying both offenders and victims. Furthermore, the legal framework governing AI-generated CSAM remains underdeveloped, and Europol noted that coordinating the operation across 19 countries in the absence of national legislation was ‘exceptionally challenging for investigators’.
While criminal actors are rapidly integrating artificial intelligence into their operations, policymakers and law enforcement agencies around the world are struggling to address the implications. A temporary EU legal framework, known as the derogation from the e-Privacy Regulation, which permitted tech companies to scan certain communications for CSAM on a voluntary basis, expired in April 2026. The issue was brought back before the European Parliament in July 2026, however, and the temporary regime was allowed to continue, subject to amendments including protections for end-to-end encrypted communications. Negotiations on a permanent legal framework are ongoing. In 2021, a similar period of legal uncertainty was associated with a 58% decline in CSAM reports, as detection efforts were severely hampered.
Some governments have begun to respond to the rise in AI-generated CSAM by proposing targeted legislation, signalling that there is political will to address the issue. Australia, the United States, the United Kingdom and the European Union have proposed or introduced measures criminalizing AI-generated child sexual abuse material or restricting the use of AI systems for such abuse. However, progress has been slow. The Council of Europe has taken concrete steps by criminalizing the creation, alteration and distribution of AI-generated child sexual abuse material under its conventions. However, aside from recent amendments to the EU AI Act introducing transparency requirements for AI-generated content, due to take effect in December 2026, most legislation is still under development. Law enforcement agencies are still working within legal frameworks that were not designed with synthetic abuse material in mind.
Ultimately, while AI is changing the methods of child sexual exploitation, the victims remain the same. To ensure that innovation does not further enable organized crime, the systems to protect children must be as proactive as the criminal networks exploiting these new technologies.