TTP’s September 8 report alleged that Meta’s advertising systems distributed 332 paid ads on Facebook and Instagram containing suspected AI-generated child sexual abuse material (CSAM) from November 2025 through August 2026. The reported ads reached more than 29,000 users across several regions, but TTP cautioned that public Ad Library data do not provide a complete measure of delivery, particularly outside regional disclosures.
6
9
What the investigation found
According to TTP, the ads used AI-generated or AI-manipulated imagery to sexualize children and frequently promoted “nudify” or deepfake-style applications. TTP said some images appeared to be derived from photographs of real children, including a member of a European royal family.
9
10
The ads appeared across the European Union and United Kingdom, the United States, India, and Australia. Reporting on the investigation said TTP identified 84 ads in India and 120 targeted to Australia; the majority were reported to have run in the EU and UK.
1
12
TTP linked many of the ads to AI app developers and to Meta’s Chinese advertising-reseller network. Its report identified resellers including GIMC and BlueFocus, while other coverage described many ads as promoting deepfake “nudify” apps.
9
6
Why paid distribution matters
The central issue is not simply that harmful content appeared on a social platform. These were paid ads: material that, according to TTP’s findings, passed through Meta’s advertising intake and review processes before being delivered to users.
TTP argued that the ads exposed failures in both review and advertiser oversight. It reported that much of the imagery was overt, rather than hidden behind subtle wording or ambiguous visual cues. The group also said Meta initially categorized 113 removed ads under adult-sexual-content or generic policy labels, then changed those notices to child-exploitation classifications after TTP raised the issue.
9
That distinction matters for transparency and enforcement. If prohibited ads are not consistently classified as child-exploitation content, public removal data may not clearly show the scale or nature of the problem, as TTP noted.
9
Meta’s response and removals
Meta spokesperson Andy Stone said the company prohibits nudify apps and all child exploitation, “whether real or AI-generated.” He said those seeking to evade enforcement continually change tactics and that Meta must keep improving detection and enforcement.
3
Meta also said many of the ads had limited reach, that some were disabled before outside reporting, and that some preceded newer tools intended to detect and block violating AI-related ads during upload.
11
TTP reported that Meta had removed 183 of the 332 ads by September 1. After TTP shared its findings on September 2, Meta removed the remaining 149 ads and reclassified 113 others under child-exploitation rules, according to the group.
9
TTP nevertheless said similar ads continued to appear in the following days, including one involving the European royal minor. That means the removals addressed the identified ads but did not, on their own, establish that the underlying review problem had been solved.
9
Broader regulatory and political pressure
The report arrived amid broader scrutiny of Meta’s approach to young users and platform safety. TTP connected the findings to a potential $18 billion settlement with U.S. state attorneys general over allegations that Meta’s products harmed young people.
9
Senator Mark Warner had previously asked Meta how exploitative ads could pass its systems and noted that Meta’s public Ad Library did not provide users a way to report offending ads.
17
In India, the National Human Rights Commission sought responses from government ministries and police after reports that paid Instagram advertisements promoted or facilitated access to CSAM.
22
18
How TTP reported the ads
TTP said it reported each ad it identified to the National Center for Missing & Exploited Children, including through its CyberTipline. The reporting route is significant because suspected online child exploitation can then be assessed and, where appropriate, referred to law enforcement.
9
3
The report’s broader takeaway is that AI abuse prevention cannot be limited to content moderation after publication. For paid advertising, the key control point is earlier: advertiser vetting, creative review, automated detection, accurate policy classification, and rapid action when abuse is identified.