Analysis
A nonprofit investigation published Sept. 8 found that Meta ran more than 300 advertisements on Instagram and Facebook this year containing suspected AI-generated child sexual abuse material, reaching an estimated 29,000-plus accounts across the US, UK and more than a dozen European countries (Business Standard). The ads ran between November 2025 and early August 2026 and were discovered by the Tech Transparency Project inside Meta's own Ad Library -- the public tool the company built specifically to demonstrate advertising transparency (Tech Transparency Project).
What the ads actually were
According to the report, many of the ads promoted so-called "nudify" apps -- tools that use AI to generate explicit imagery from ordinary photos -- and several were built from real images of real children, including a press photo of a European royal family member and pictures pulled from a preteen Instagram influencer's account. The nonprofit says it traced an earlier wave of similar ads to a Meta advertising partner based in China, meaning this is at least the second documented instance of the same ad-network pathway carrying policy-violating content onto Meta's platforms.
“The more useful question isn't whether Meta can hit zero; it's whether a repeat violation from the same advertising partner should have been caught the first time.”
Why this keeps happening
Meta has spent years building automated image-classification systems specifically to catch CSAM before it reaches its ad review queue, and the company routinely cites those systems' scale as evidence its platforms are safe for advertisers and users. The gap this report exposes isn't detection at the extreme edges of the platform; it's detection inside paid, reviewed advertising -- the one surface where Meta has the most direct control and the strongest financial incentive to get right, since every ad is a transaction the company profits from. That the violations were findable by an outside nonprofit combing through Meta's own public Ad Library, rather than requiring privileged internal access, is the detail regulators and advertisers are likely to focus on.
The regulatory backdrop
This lands as several state attorneys general and EU Digital Services Act investigators already have open inquiries into Meta's child-safety practices -- the same terrain Pulse covered when a coalition of 29 state attorneys general took Meta to trial in California over child-safety design choices in August -- and as Congress continues to debate child-safety-specific AI legislation. A documented, dated pattern of policy-violating ads slipping through paid review, twice by the same nonprofit's count, is the kind of evidence that tends to show up in enforcement actions rather than press releases.
The counterweight
However, it's worth separating scale from severity here: 300 ads out of the many millions Meta runs daily is a small fraction of total ad volume, and Meta has historically moved quickly to pull flagged ads once notified, which the Tech Transparency Project's report does not dispute. Critics of accountability journalism aimed at Meta have also noted that nudify-app advertisers are adversarial -- they actively try to evade keyword and image filters -- meaning zero violations isn't a realistic bar for any ad-review system at Meta's scale. The more useful question isn't whether Meta can hit zero; it's whether a repeat violation from the same advertising partner should have been caught the first time.
What it means for advertisers and investors
For brand-safety-conscious advertisers and the ad-tech vendors serving them, this is the kind of story that shows up in agency risk memos within days. For Meta, the direct financial exposure is still modest next to its ad revenue base, but the compounding regulatory and reputational cost of a repeat pattern, not a first offense, is the more expensive number to model.