Product1 publisher3 min readPublished
Meta's new AI ad screening let more than 250 CSAM ads run since August
The Tech Transparency Project says some of those ads were identical to ones Meta had already deleted, which makes this a repeat-upload failure in the review queue rather than a hard problem in spotting novel material.
The Product Desk · Product desk

What happened
- Meta deleted around 50 ads containing child sexual abuse material from Facebook, Instagram and Threads early last month after WIRED asked about them.
- The Tech Transparency Project told WIRED it has since found more than 250 further CSAM ads running on Meta's platforms since the start of August, some of them identical to ads Meta had just taken down.
- TTP's running total is more than 350 abusive video ads published since the end of last year, many of them linking to "nudification" apps tied to Chinese developers.
- The newer ads used images of real children, including an officially released photograph of a minor in a European royal family turned into a video of a graphic sex act.
- TTP says Meta took a week to review some live ads reported through Meta's own tools, and those ads gathered hundreds more views while they waited.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Meta's explanation that the bad ads predated its new AI screening cannot cover creative that was removed and then ran again, which takes the legacy-inventory argument off the table for the next round of questions.
- exposure The source material for these ads includes public accounts of teenagers on Meta's own platforms, so a child's ordinary use of Instagram is now an input to somebody else's ad campaign.
- decision Any team that has promised automated review as a remedy now has to decide whether it can produce a repeat-asset rate and a report-to-removal time, because blocked-volume totals no longer answer the question.
- precedent The only public audit of this remedy is a nonprofit's ad count, which sets the pattern that outside researchers, not company dashboards, grade whether AI review works.
A researcher at the Tech Transparency Project reports an ad that is live and serving, using Meta's own in-product reporting tool. A week later, TTP says, the ad is still up and has collected hundreds more views, with screenshots shown to WIRED to back the timeline [10]. No classifier reviews the ad during that week; the report sits in a human queue behind the report button.
Meta's defence last month was chronological: most of the abusive ads went up before it rolled out new AI tools to "better detect and block" harmful ads [2]. That argument holds until the same creative runs twice. TTP says some of the ads it found from August onward were identical to ones Meta had just removed [3][4]. Matching an asset against the set you deleted weeks ago is the cheapest check in ad review, far cheaper than judging a video nobody has seen before. TTP calls the repeats identical, and the reporting does not separate a re-uploaded file from a re-encoded copy [19]. That gap matters because it separates two different failures: a hash list that was never populated with the asset, versus a matcher that had the asset but was evaded.
The numbers work against Meta's timeline explanation. TTP counts more than 350 of these video ads published since the end of last year [7], and more than 250 of them ran from the start of August [3], so on the order of seven in ten arrived in the window the new tooling was supposed to cover [16]. Both figures are floors, so read the ratio as approximate. The August-onward count is roughly 4.7 times the 53 ads that started this [17][5].
The demand side is ordinary performance marketing. The click goes to an AI face-swapping or video app in Apple's or Google's store, under copy that reads "This is the AI that men actually use" [12]. Meta's targeting was doing the thing it is good at while Meta's written policy says every ad on the platform is reviewed [9]. When some of the ads did come down, they carried no disclosure that they had breached the child sexual abuse policy until WIRED asked about it [11], so even the public record an outside auditor works from was incomplete.
For anyone who runs a review queue, two axes are worth drawing. First, was the content novel or already removed once. Second, was it stopped before it served or only after someone outside the company reported it. Three of those quadrants are normal operations. The fourth, already-removed content that comes down only on an external report, is the one that tells you the remedy is not working, and it is the one internal dashboards are least likely to surface, because blocked-volume metrics count what you caught rather than what ran.
Safety teams present classifier precision on a labelled set, but the child in one of these videos experiences queue latency and the repeat-upload rate instead. Automated review counts as a fix only once three figures are public: the share of takedowns that are assets removed before, the median hours from an outside report to removal in the highest-severity queue, and the impressions delivered after that report landed. TTP has produced its own version of the third [10]. The tool shipped without that measurement in place.</body_markdown> </invoke>
What to watch
- Whether the next TTP count after this reporting shows a decline rather than another few hundred ads.
- Whether officials in the country TTP contacted over the royal family image open an inquiry.
- Whether any regulator asks Meta for its repeat-asset takedown rate rather than a blocked-ads total.