Security1 publisher3 min readPublished
Meta's ad review passed more than 300 AI-altered CSAM ads promoting Chinese nudify apps
The Tech Transparency Project counted the ads on Facebook and Instagram this year, several of them placed by Meta's own top-tier ad partners in China, and Meta pulled about 150 within hours of seeing the list.
The Watch · Security desk

What happened
- The Tech Transparency Project identified more than 300 paid ads run on Facebook and Instagram this year containing child sexual abuse material, most of it a real child's photo altered with AI.
- The vast majority of the ads pointed to AI apps from China, many of them able to nudify people, and one ad promoting such an app was targeted at adult male users.
- TTP found dozens of CSAM ads still running in the days after the cleanup, including the one animating a minor from a European royal family into a graphic sex act.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The material sat in ads Meta approved and was paid for, which moves the legal question off user-generated content and onto the platform's own conduct under statutes Section 230 does not cover.
- constraint Meta's Ad Library is the public evidence base for what it enforces, and rewriting a hundred-plus violation records after being shown the ads means outside counts built on it were low by an unknown margin.
- capability A template that survives paid review gives an operator audience targeting and delivery that organic posting does not, at the price of ad spend.
- precedent If hashes only reach platforms after the AI derivative has been submitted, pre-publication blocking of novel edits of public photos of children stays out of reach for whoever is next in the queue.
The creative was reused. TTP describes one recurring format: a snippet of adult pornography, then a photo of a real child manipulated with AI into a sex act, carried by a shared set of captions, voiceovers and background music [7]. The source photos came from social media posts and websites [8]. Duplicate creative is the cheapest thing an automated review stack catches. By TTP's count, this one cleared more than 300 times [1], on children the investigation places from toddlers through young teenagers [6].
Hash matching does not help here on the timeline that matters. TTP reported the ads it found to NCMEC, which distributes hashes to tech companies so they can identify and block known abuse images [14]. A fresh AI derivative of a public photograph has no hash until someone submits it. In this chain, the hash exists because the ads already ran.
Meta's response arrived in hours, after TTP shared its findings: about 150 ads still visible in the Ad Library were removed, and the records of more than a hundred already-removed ads were revised to show a child exploitation violation [11][12]. That is roughly 250 of the 300-plus TTP counted, leaving about 50 unaccounted for in the cleanup [21]. TTP then found dozens more still running in the following days, including the ad animating a minor from a European royal family, which promoted a Chinese AI app and was targeted at adult male users [13][9].
The reclassification is the part worth holding onto. Those hundred-plus records previously showed violations of Meta's adult-oriented policies with no mention of children, which TTP reads as evidence Meta may be undercounting child sexual abuse in its own advertising data [12]. Anyone auditing Meta against its published enforcement numbers is auditing a category that Meta relabeled after being shown the ads.
Section 230 protects platforms from liability over user-generated content, and does not extend to federal criminal violations, including the child sexual exploitation statutes [15]. Federal law covers advertisement and distribution, not just production and possession [16], and the FBI has said CSAM built from AI-generated images is illegal too [18]. These were ads Meta approved, ran, and took money for [17], which puts the conduct on the platform's side of that line rather than a user's.
The buy side failed as well. Several of the ads show placement by Meta's own "top tier" ad partners [20], among them partners in China including a state-controlled company [4], and the vast majority of the ads pointed at Chinese AI apps, many of them capable of nudifying people [5]. Meta did not answer TTP's request for comment [10]. The channel is a vetted advertiser account and an approved creative, and as of TTP's follow-up it was still open.
What to watch
- Whether the NCMEC referrals produce a federal inquiry into how the ads were approved, or charges against the advertisers.
- Whether Meta publishes a child-exploitation enforcement count that reconciles with the Ad Library records it relabeled.
- Whether Meta's China ad partner program, including the state-controlled company named by TTP, is suspended or re-vetted.