Analyzing AI’s Role in the Production and Proliferation of Child Sexual

Abuse Material and the Lack of Legal Safeguards

Abstract

This paper examines the growing phenomenon of AI-generated Child Sexual Abuse Material (CSAM) and its implications in India. It explores the technological mechanisms enabling the creation of synthetic sexually exploitative content, the challenges posed to existing legal frameworks, and the role of intermediaries in its proliferation. The study analyzes gaps in current Indian laws, such as the Information Technology Act, the Protection of Children from Sexual Offences Act, and the Digital Personal Data Protection Act, in addressing AI-generated abuse. It also reviews international regulatory approaches to highlight best practices. The paper concludes with recommendations for strengthening legislative measures and enforcement mechanisms to effectively combat AI-generated CSAM.

Introduction

From Pulitzer winning cartoonist Darrin Bell arrested for possessing AI generated Child pornography and the New Zealand MP Laura McClure showcasing a manipulated, nude image of herself in Parliament, to the search term “Taylor Swift” being temporarily disabled on the social media platform X (formerly Twitter) due to an overwhelming surge of pornographic AI-generated images of the celebrity triggered by the search, the use of AI in the creation of sexually exploitative images has been dominating headlines in recent times.

This alarming trend is not confined to celebrities or public figures; it also affects ordinary citizens and, according to reports, even minors and infants. The current legal infrastructure of India is equipped enough to bring the rising threat of AI generated Child Sexual Abuse Material (hereinafter CSAM) effectively under its purview. Even though the artificially created content has no real victims, it raises serious concerns about the human tendency to derive gratification from simulated suffering inflicted upon children.[1] Outdated laws, lack of specific provisions, evidentiary challenges, and insufficient regulatory obligations for intermediaries all contribute to the looming uncertainty regarding synthetic content.

This paper aims examine the rapidly evolving phenomenon of AI-generated sexually exploitative content targeting children, exploring the technological mechanisms that facilitate its creation, assess the effectiveness of existing legal and regulatory frameworks at both national and international levels and suggest potential policy interventions and preventive measures, for a stronger legislative and societal response.

Defining the Challenge

Child pornography or child sexual abuse material (CSAM) is defined as “imagery or videos which show a person who is a child and engaged in or is depicted as being engaged in explicit sexual activity.”[2] The term CSAM has been formally recognized as the preferred term , by an international working group, comprising a collection of countries and international organizations working to combat child exploitation in 2016 acknowledging the lack of consent in material involving children while pornography could be consensual and also highlighted that the term better reflects the abuse that is depicted in the images and videos and the resulting trauma to the child.

This definition, however, varies significantly across different nations, influenced by factors such as the age of consent, the nature and extent of activities involved, and so forth. Additionally, another area of legislative divergence pertains to whether an actual child must be depicted in the image or if artificially created images can also be classified as Child Sexual Abuse Material (CSAM). The legal penalties associated with the production, distribution, and possession of CSAM also differ from one country to another.

In the United Kingdom, the creation, possession, and distribution of child sexual abuse images, encompassing those generated through artificial intelligence are deemed illegal. Moreover, the legal framework recognizes the concept of “pseudo- photographs” defined as “an image, whether made by computer-graphics or otherwise howsoever, which appears to be a photograph including images made by Artificial Intelligence (AI).”[3]

In India, the term Child Sexual Abuse Material (CSAM) is not officially defined, despite recommendations from the NHRC in the Advisory for the Protection of the Rights of Children against the Production, Distribution, and Consumption of CSAM.[4] The POCSO Act under section 2(da) still uses the term Child pornography  defined as “any visual depiction of sexually explicit conduct involving a child which include photograph, video, digital or computer generated image indistinguishable from an actual child and image created, adapted, or modified, but appear to depict a child.”[5]  The NHRC  recognizes CSAM as one of the most terrible forms of sexual abuse and exploitation faced by children and, consequently, a grave violation of their human rights.

According to a report by the Daily Mail UK, child pornography constitutes one of the fastestgrowing illicit online enterprises, with India emerging as both a significant consumer and contributor with a pornographic video being recorded approximately every 40 seconds, of which an estimated 38% involve content linked to child sexual abuse.[6] The report identifies Kerala as a primary source of CSAM production while states such as Haryana, Assam, Bihar, Punjab, Delhi, and West Bengal report notably high rates of consumption and viewership of such exploitative content.

 

The Federal statutes of USA as well uses the term “child pornography” is used to refer to any visual depiction of sexually explicit conduct involving a person less than 18 years old.[7] Canada has a structured and expansive definition of the term. Canada’s definition of child pornography, as set out in Section 163.1(1) of the Criminal Code, is broad and comprehensive. It includes any photographic, film, video, or other visual representation, whether created by electronic or mechanical means—that depicts a person who is, or is represented as being, under the age of eighteen engaged in explicit sexual activity, or whose dominant characteristic is the sexualized depiction of a child’s sexual organ or anal region. Beyond visual material, the definition also covers written content, visual representations, and audio recordings that advocate, counsel, describe, or represent sexual activity with a person under eighteen in a manner that constitutes a criminal offence under Canadian law.[8]

 

Evolution and Extend of AI in CSAM

The term “deepfake,” coined in 2017, is a portmanteau of “deep learning,” which refers to the advanced algorithms employed to create artificial media, and “fake.”[9] Initially, deepfakes were produced by a limited group of individuals who manually gathered substantial amounts of source material, including images and videos of a person’s face. They then used deep learning models to convincingly superimpose this face onto the body of a pornographic performer. Deepfakes, however, do not require human labor to manually manipulate videos; instead, a computer’s processing power does all the work.[10]

Since 2018, significant advancements in technology have facilitated the automation of this production process through the development of various publicly accessible applications. Early instances of deepfakes predominantly featured renowned celebrities such as Gal Gadot, Emma Watson, and Scarlett Johansson.[11] Recently  AI powered ‘nudify’ apps have fueled a deadly wave of digital blackmail with the the FBI reporting a “horrific increase” in sextortion cases targeting U.S. minors, with victims typically males between the ages of 14 and 17.12

However, the application of this technology rapidly expanded into other territories, such as revenge pornography directed toward non-celebrities. In 2018 Rana Ayyub, an Indian investigative journalist, became the victim of an online hate campaign. This campaign was fueled by her outspoken condemnation of the rape of an eight-year-old girl in Kashmir. Ayyub faced an onslaught of rape and death threats, alongside the circulation of a doctored pornographic video featuring her image.[12]

Following 2018, the prevalence of deepfake incidents escalated significantly, encompassing instances involving minors. This increase became markedly pronounced in the aftermath of the COVID-19 lockdowns, reflecting a disturbing trend regarding the exploitation and harmful utilization of this technology. In 2023 alone the National Center for Missing & Exploited Children (NCMEC) of the USA reported a concerning surge in cases involving child sexual abuse material (CSAM) tied to Generative AI (GAI) technology. The NCMEC Cyber Tip line received approximately 4,700 reports related to GAI CSAM, highlighting the growing intersection of technology and child exploitation.[13]

A report from the Internet Watch Foundation (IWF) in October 2023 revealed the troubling presence of over 20,000 AI-generated images on a dark web forum within just a single month. Alarmingly, more than 3,000 of these images depicted criminal child sexual abuse activities. This indicates a significant and disturbing trend in the use of AI technology for creating exploitative content, with a total of 20,254 AI-generated images documented on that dark web CSAM forum during this period.[14] As the situation progressed into 2024, the IWF reported an even more alarming trend. Over 3,500 new AI-generated criminal child sexual abuse images were uploaded to the same dark web forum analyzed in the previous October. This marked a staggering 380% increase in AI-generated child sexual abuse imagery compared to the previous year, with the number of reports rising from 51 in 2023 to 245 in 2024. The content was described as even more severe, with a focus on hardcore abuse, underscoring the urgent need for intervention and monitoring in this area.[15]

In the UK, Hugh Nelson, a 28-year-old was sentenced to 20 years in prison last august for the production, distribution and possession of indecent images of children using AI assistants.[16] As horrific as it sounds he was commissioned to generate such images by the fathers, uncles, family friends, or neighbors of the victim over an 18-month period, making £5,000. What makes this situation even more alarming is that Nelson had no prior experience with software or a background in computer design, Anyone, regardless of technical skill, age, or background, can now access and wield AI tools to produce exploitative material with shocking ease. This unchecked accessibility doesn’t just democratize creation; it weaponizes it, vastly amplifying the availability and circulation of such content far beyond the limitations of traditional, labor or capital -intensive methods, eroding safeguards that once stood against this kind of abuse.

A 41-year-old child psychiatrist, David Tatum was sentenced on child pornography charges in North Carolina where one of the victims made her statement saying “It is a very strange and unsettling realization that, as an adult woman in her 40s, I became a victim of child pornography.”[17] Her picture from around two decades ago around the age of fifteen was manipulated using AI to generate a nude image.

India has also not stayed away from reporting related cases, while no reported instance of AI generated CSAM is in news Meta’s oversight board has invited comments into two cases involving facebook and Instagram posts of an undressed Indian public figure along with pictures of other AI generated Indian women.[18]

All of these developments underscore the pervasive extent of GAI in CSAM and highlight the urgent need for a comprehensive and robust legislative framework, and effective implementation mechanisms, both in India and globally.

Current Policy Approach under Indian Laws

Despite a range of laws aimed at curbing traditional child pornography and online exploitation, India’s policy framework remains fragmented and insufficient to effectively address the complex challenges posed by AI-generated CSAM.

        (i)         The Protection of Children from Sexual Offences Act, 2012 (POCSO Act)

The POCSO Act Criminalizes the sexual exploitation and abuse of minors, including aggravated forms of sexual assault and pornography involving children. The protections are extended to both physical and online threats to children.  Chapter III of the Act concerns “ Using child for pornographic purposes and punishment therefor”.

Section 13 reads, “Whoever, uses a child in any form of media (including programme or advertisement telecast by television channels or internet or any other electronic form or printed form, whether or not such programme or advertisement is intended for personal use or for distribution), for the purposes of sexual gratification, which includes—

  • representation of the sexual organs of a child;
  • usage of a child engaged in real or simulated sexual acts (with or without penetration);
  • the indecent or obscene representation of a child, shall be guilty of the offence of using a child for pornographic purposes. “

The explanation to the Section states that the expression ‘‘use a child’’ shall include involving a child through any medium like print, electronic, computer or any other technology for preparation, production, offering, transmitting, publishing, facilitation and distribution of the pornographic material.[19]

Section 14 provides for the punishment for offences under section 13, any person who employs a child for pornographic purposes is subject to a minimum imprisonment term of five years, along with a monetary fine. In cases of repeat offenses, the punishment increases to a minimum of seven years imprisonment, in addition to the fine. Furthermore, if the offender directly participates in the pornographic acts themselves, thereby committing related offenses specified in other sections of the Act (such as aggravated sexual assault or exploitation), they are subject to additional penalties as prescribed under the corresponding sections.[20]

Section 15 of the Protection of Children from Sexual Offences Act, 2012 (POCSO Act) specifically addresses the storage and possession of pornographic material involving children. Any individual who stores or possesses child pornography with the intent to share or transmit it, but fails to delete, destroy, or report it to the designated authority, is liable to a fine of at least five thousand rupees. For repeat offenses, the fine increases to a minimum of ten thousand rupees. If a person stores or possesses child pornographic material for the purpose of transmitting, displaying, propagating, or distributing it except when done for legitimate purposes such as reporting to authorities or presenting as evidence in court, they face imprisonment of up to three years, a fine, or both.

If such storage is for commercial purposes, on first conviction, the offender faces imprisonment ranging from a minimum of three years to a maximum of five years, in addition to a fine or both.

In cases of subsequent conviction, the punishment increases to a minimum of five years’ imprisonment, extendable up to seven years, along with a fine.[21]

Though Chapter IV of the Act, is with regards to abetment of an offence under the act, the liability of intermediary platforms are not yet brought under the purview of these sections.

        (ii)        The Information Technology Act, 2000 (IT Act)

Under the IT Act, Chapter XI deals with the offences committed with the aid of IT. While using deppfake technology to morph an existing person’s image into sexually explicit content maybe brought under Section 66C (Punishment for violation of privacy), there is no specific section addressing the use of GAI. Section 66C provides a maximum punishment of three years or with fine not exceeding two lakh rupees or both for “intentionally or knowingly captures, publishes or transmits the image of a private area of any person without his or her consent, under circumstances violating the privacy of that person”[22]

Before 2008, India lacked specific provisions against child pornography. However, amendments to the IT Act introduced Section 67B.[23] While Section 67 criminalizes publishing or transmitting obscene material in electronic form, Section 67 (B) of IT Act directly addresses CSAM. It states that “it is punishable for publishing or transmitting of material depicting children in sexually explicit act, etc. in electronic form. 25 Subsection (b) makes reference to “creation of text or digital images, in any electronic form depicting children in obscene or indecent or sexually explicit manner”. Further under (e) facilitation of abuse of children online is criminalized.

While this provision does not state whether such material includes AI generated content, however courts often adopt an interpretation in favour of the child, thereby extending the application of S.67(B) to AI generated CSAM.

Section 67C of the Act, prescribes the punishment for any intermediary who intentionally or knowingly contravenes the central government regulations as imprisonment for a term which may extend to three years and also be liable to fine.

        (iii)       The Bharatiya Nyaya Sanhita (BNS), 2023

Though BNS does not have a specific provision explicitly regulating AI-generated content or deepfakes, the general language of the law encompasses acts where the intention is to harm, exploit, or infringe upon the privacy and dignity of individuals which is applicable equally to real

and synthetically generated material. While chapter V of the act discusses in detail offences against women and child, there is still no mention of synthetically generated or modified content. Further the general language of the provisions tends to assume abuse to only affect women, no provision addresses generation and dissemination of sexually explicit content of a child or person of any other gender.

Section 294 deals with obscenity under Indian laws. The provision criminalizes “ book, pamphlet, paper, writing, drawing, painting, representation, figure or any other object, including display of any content in electronic form shall be deemed to be obscene if it is lascivious or appeals to the prurient interest or if its effect, or (where it comprises two or more distinct items) the effect of any one of its items, is, if taken as a whole, such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it.”[24][25]

Section 351, may extend to revenge porn generated using deepfake technologies of an existent person as it makes reference to any injury to his person, reputation or property, or to the person or reputation of any one in whom that person is interested.[26][27]

Section 356 regarding defamation again is only applicable to altering or modifying an existent person’s image or video to constitute sexually explicit material as it criminalizes making or publishing in any manner, visible representation intending to harm, or knowing or having reason to believe that such imputation will harm, the reputation of such person, is said, except in the cases hereinafter excepted, to defame that person.[28][29]

 

(iv)       Information Technology [Intermediaries Guidelines (Amendment) Rules] 2018

According to section 2(1)(w) of the IT Act, “Intermediary” with respect to any particular electronic records, means any person who on behalf of another person receives, stores or transmits that record or provides any service with respect to that record and includes telecom service providers, network service providers, internet service providers, web hosting service providers, search engines, online payment sites, online-auction sites, online market places and cyber cafes.[30]

The Intermediary guidelines of 2018, madates intermediaries to publish the rules and regulations, privacy policy and user agreement for access-or usage of the intermediary’s computer resource by any person and under rule 2 states that such publication shall inform the users of computer resource not to host, display, upload, modify, publish, transmit, update or share any information that:

  • belongs to another person and to which the user does not have any right to;
  • is grossly harmful, harassing, blasphemous, defamatory, obscene, pornographic, paedophilic, libellous, invasive of another’s privacy, hateful, or racially, ethnically objectionable, disparaging, relating or encouraging money laundering or gambling, or otherwise unlawful in any manner whatever;
  • harm minors in any way

(e) violates any law for the time being in force;

Under Rule 5, if legally required by the government intermediaries must provide information or assistance to government agencies within 72 hours. This includes aiding in matters related to state security, cyber security, investigation, prosecution, or prevention of offenses. Requests can be made in writing or electronically and must clearly state their purpose. Intermediaries are also obligated to help trace the originator of any information on their platform, as directed by authorized government agencies. This includes removal of materials including CSAM from their platforms at the behest of the government.

They are also obligated to report cyber security incidents and also share cyber security incidents related information with the Indian Computer Emergency Response Team (CERT).

 

(v) Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

Rule 3(b) of the code is a reproduction of rule 2 of the 2018 guidelines with added safeguards in the gaming sector. The IT Rules impose specific obligations on intermediaries, including social media platforms, requiring them to exercise due diligence. Failure to comply with these obligations results in the loss of legal immunity for third-party content or data hosted on their services. As part of this due diligence, intermediaries must remove, within 24 hours, any content that appears to expose an individual’s private areas, depicts full or partial nudity, or shows them engaged in sexual acts or conduct. Additionally, the rules mandate the formation of Grievance Appellate Committees, which allow users to challenge decisions made by Grievance Officers of social media intermediaries. The IT Rules, 2021, also establish a code of ethics for publishers of curated online content, such as OTT platforms.

 

(vi)       Digital Personal Data Protection Act, 2023

DPDPA creates a consent-centric regime for personal data processing. It establishes a rightsbased framework for processing personal data in India that significantly impacts the governance of generative artificial intelligence (“AI”). Section 9 of the Act requires verifiable parental consent before processing a child’s personal data and prohibits such processing if it is “likely to cause any detrimental effect on the well-being of a child.” It also prohibits behavioural tracking and targeted advertising directed at children. These provisions restrict the indiscriminate inclusion of children’s personal information in AI training datasets and impose heightened accountability on data fiduciaries to ensure purpose limitation, minimisation, and security. In the context of generative AI, this means developers must implement safeguards to prevent inadvertent disclosures of sensitive data and ensure that outputs do not re-identify or exploit minors, thereby embedding a statutory duty of care in technological design and deployment.

 

(vii)      Other governmental measures

Other governmental measures include the NHRC Advisory for the Protection of the Rights of Children against the Production, Distribution, and Consumption of Child Sexual Abuse Material (CSAM), issued to the Union and State Governments as well as Union Territory Administrations. This advisory aims to safeguard the human rights of children in the digital space. Additionally, the Ministry of Home Affairs has established the Indian Cyber Crime Coordination Centre (I4C), which is tasked with addressing all forms of cybercrime, including those specifically targeting children.

An MoU has been signed between the National Crimes Record Bureau (NCRB), Ministry of Home Affairs (MHA) and National Center for Missing and Exploited Children (NCMEC), USA regarding sharing of Tipline reports on online child explicit material and child sexual exploitation contents from NCMEC. The Tip lines, as received from NCMEC, are being shared with States/UTs online through the National Cybercrime Reporting Portal for taking further action.[31]

The Ministry of electronics, recommends that till a centralized mechanism is built in India to dynamically monitor websites/URLs containing online CSAM, the relevant ISP’s in India should adopt and disable/remove the online CSAM dynamically based on IWF list.

Further, India is a signatory to several key international conventions and treaties aimed at combating child sexual exploitation, including Child Sexual Abuse Material (CSAM) and emerging threats like AI-generated content.

Foremost among these is the United Nations Convention on the Rights of the Child (UNCRC), 1989, which obligates State Parties, including India, to protect children from all forms of sexual exploitation and abuse. India ratified the United Nations Convention on the Rights of the Child (UNCRC) on December 11, 1992, making the country legally bound to uphold and implement the rights of every child.[32] Article 34 of the UNCRC specifically mandates the prevention of the exploitation and abuse of children through prostitution, pornography, and any other harmful practices.[33]

Additionally, India signed the Optional Protocol on the Sale of Children, Child Prostitution, and Child Pornography (2000), on 15 novemver 2004 and ratified it on 16 August 2005. The protocol strengthens the obligation to criminalize and prosecute offenses related to child pornography, regardless of the medium used to produce or distribute the content. On a regional level, India The South Asian Association for Regional Cooperation (SAARC) Convention on Preventing and Combating Trafficking in Women and Children for Prostitution, 2002, which also imposes strict measures against child exploitation in any form, including digital media.

Although these treaties do not specifically address AI-generated content, their broad mandates to prevent child sexual exploitation and protect the dignity of children empower India to extend their interpretation to cover new technologies.

The Government has issued an order to Internet Service Providers, directing them to implement Internet Watch Foundation, UK or Project Arachnid, Canada list of CSAM websites/webpages on a dynamic basis and block access to such web pages or websites.[34]

Several private members’ bills were introduced in the Rajya Sabha recently, reflecting a focus on diverse and pressing issues. These included the Protection of Children from Sexual Offences (Amendment) Bill, 2024, aimed at strengthening victim-centric measures and addressing rising cases of child exploitation; the Artificial Intelligence (Protection of Rights of Employees) Bill, 2023, and the Deepfake Prevention and Criminalisation Bill, 2023, both introduced by Trinamool Congress MP Mausam B. Noor, which seek to safeguard employee rights in AI workplaces and criminalise non-consensual deepfake content, respectively; a bill to amend the Bharatiya Nyaya Sanhita, 2023, introduced by Derek O’Brien; and the Bill to Amend the Coaching Institutes (Accountability and Regulation) Bill, 2024, introduced by Congress MP Fauzia Khan, targeting oversight and regulation of coaching institutes nationwide.[35][36] However, no further updates or progress on the consideration or passing of these bills have been reported.

Furthermore, India actively collaborates with international law enforcement bodies such as INTERPOL and the WeProtect Global Alliance, which focus on cross-border cooperation, information sharing, and technological innovation to tackle the growing threat of online child exploitation, including that facilitated by AI. Nonetheless, the lack of AI-specific provisions at the international level reveals a significant gap in the regulatory architecture, calling for enhanced treaty frameworks to address synthetic media explicitly.

 

AROUND THE WORLD

Globally, the emergence of AI-generated Child Sexual Abuse Material (CSAM) has prompted a concerted response from governments, law enforcement, and civil society. Countries are increasingly recognizing the need for specialized legislation, enhanced detection technologies, and international cooperation to address this evolving threat. The International Centre for Missing & Exploited Children (ICMEC)’s  most recent assessment found that, out of 196 countries worldwide, 156 have introduced or strengthened laws specifically targeting CSAM. Of these, 111 countries meet four out of five key criteria considered essential for effective legislative frameworks, while only 27 countries fulfill all the criteria. Alarmingly, 10 countries still lack any legislation addressing CSAM.[37][38]

The United Kingdom has become the first country to criminalize AI child abuse tools, including criminalization of possession of pedophile manuals” which teach people how to use AI to sexually abuse children, punishable by up to three years in prison.[39] The new laws will also criminalize “predators who run websites designed for other pedophiles to share vile child sexual abuse content or advice on how to groom children”, punishable by up to 10 years in prison. It is also illegal to possess, create or distribute AI tools designed to generate child sexual abuse material (CSAM), punishable by up to 5 years in prison.[40]

The recently passed EU Artificial Intelligence Act (AI Act) has outlawed the worst cases of AIbased identity manipulation and mandated transparency for AI-generated content, establishing a risk-based AI classification system. AI systems that can be used in different applications are analysed and classified according to the risk they pose to users. The different risk levels mean more or less AI compliance requirements.38 The European Union has banned specific AI applications to protect individual rights and privacy. These include AI systems that manipulate behaviour, particularly targeting vulnerable groups, such as voice-activated toys encouraging harmful actions in children. Social scoring AI, which classifies individuals based on behaviour, socio-economic status, or personal traits, is also prohibited. Additionally, the use of biometric identification and categorisation of individuals is banned, along with real-time or remote biometric identification systems like facial recognition in public spaces.

In September 2024, South Korea amended the Act on Special Cases Concerning the Punishment of Sexual Crimes to criminalize the possession, viewing, purchase, and storage of non-consensual deepfake material.[41] The reforms also address the exploitation of minors through deepfakes, with penalties including imprisonment and fines. This was a result of an investigation launched against telegram and other encrypted platforms for abetting crimes due to public outcry over cases involving AI-generated porn, including depictions of teenagers.

Denmark’s copyright laws are proposed to be amended to address concerns regarding deepfakes. Under this amendment, any AI-generated realistic imitation of a person (face, voice, or body) shared without consent would violate the law. Danish citizens would have a clear legal right to demand takedown of such content, and platforms that fail to remove it would face severe fines.[42]

The federal government of the United States of America passed the TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act”) in May 2025, requiring platforms to remove non-consensual intimate visual deceptions, including AI-generated deepfakes. In general, the Act prohibits any person from “knowingly publishing“without consent intimate visual depictions of minors or non-consenting adults, or any deepfakes, whether intimate depictions or not, that are intended to cause harm. [43]

“Covered platforms“under the US law include public websites, online services and applications, and mobile applications that either (i) primarily provide a forum for user-generated content or (ii) are primarily designed to publish nonconsensual intimate visual depiction and do not include broadband Internet access providers, email services, or online services or websites with primarily preselected content where the content is not user-generated but curated by the provider.

The law not only punishes the original creators of explicit deepfake content but also places responsibilities on online platforms. Under the new legislation, if an individual discovers an explicit deepfake of themselves online, platforms are required by federal law to remove it within 48 hours of being notified. By May 2026, all platforms hosting user-generated content that could include intimate images must implement a clear notice-and-takedown procedure.

Australia has enacted an Online Safety Act (OSA) in 2021, which imposes certain duties on online service providers to protect Australians, in particular children and vulnerable adult users online. Under the OSA, enforceable codes and standards currently apply to AI-generated CSAM, including the “Designated Internet Service Standard” for generative AI and model distribution services, with civil penalties for non-compliance, while the Australian Government is consulting on mandatory AI guardrails to ensure training data excludes CSAM in high-risk settings.[44]

China has also recently updated its legislative framework to address emerging risks from generative AI. AI platforms are now regulated under the Interim Measures for the Management of Generative Artificial Intelligence Services and three cybersecurity standards issued on April 25, 2025:

  • Security Specification for Generative AI Pre-training and Fine-tuning Data,
  • Data Annotation Security Specification, and
  • Basic Security Requirements for Generative AI Services.

From September 1, 2025, new Labeling Rules require all AI-generated content to be labeled, explicitly where applicable, with clear guidelines and staff training for accurate labeling.[45] Additionally, the AI Measures mandate that generative AI providers uphold “socialist core values,” prohibiting content that incites subversion, threatens national security, undermines unity, or promotes terrorism, extremism, ethnic hatred, violence, pornography, or other harmful or false information.[46]

When it comes to France, Under the French Penal Code, the production, possession, and distribution of all forms of CSAM, including AI-generated or synthetic imagery are treated equivalently to material depicting real abuse. France actively supports the 2025 European Parliament Recast Directive, which explicitly criminalizes AI-generated CSAM across EU member states and addresses related offenses such as grooming and sextortion. Civil society and child protection organizations, notably the Fondation pour l’Enfance and the Children Online Protection Lab, play a central role in awareness-raising, victim identification, multi-stakeholder collaboration, and issuing concrete recommendations for prevention, detection, and enforcement. Law enforcement agencies employ sophisticated investigative tools and international cooperation to address the surge in AI-generated CSAM cases, while advocacy coalitions like the European Child Sexual Abuse Legislation Advocacy Group (ECLAG) lobby for legislative clarity and robust prosecution.

 

The use of AI for detecting and removing AI generated CSAM is also in discussion. The Ministry of Interior of the United Arab Emirates (UAE) launched the AI for Safer Children initiative. This initiative aims to build the capacities of law enforcement worldwide to leverage the positive potential of artificial intelligence (AI) and related technology to combat child sexual exploitation and abuse.[47] This initiative has established the AI for Safer Children Global Hub, an innovative online platform designed to support investigators tackling crimes against children. The platform provides access to detailed information on over 80 advanced AI tools, along with guidance on their responsible implementation to streamline investigative processes. Hundreds of law enforcement officers from more than half of the world’s countries have joined the Hub, promoting international cooperation and the practical application of AI technologies to prevent, detect, and prosecute cases of child sexual exploitation and abuse.[48]

These international approaches illustrate best practices in tackling AI-generated CSAM, combining targeted legislation, mandatory platform responsibilities, and technological safeguards. By examining measures such as the UK’s criminalization of AI child abuse tools, the EU’s risk-based AI framework, Australia’s Online Safety Act, and China’s regulatory standards, India could adapt and strengthen its own legal and regulatory mechanisms to more effectively prevent, detect, and respond to the growing threat of AI-facilitated sexual exploitation of children. Additionally, initiatives like the UAE’s AI for Safer Children Global Hub demonstrate the potential of leveraging AI positively, providing law enforcement worldwide with advanced tools and guidance to identify, remove, and prosecute cases of AI-generated CSAM, highlighting the value of combining legal measures with technological solutions and international cooperation.

 

POLICY RECOMMENDATIONS

In light of the findings of this study, various recommendations are being put forth:

Updating Terminology in Law: The term “Child Pornography” currently used in Section 2(1)(da) of the POCSO Act, 2012 should be replaced with “Child Sexual Abuse Material (CSAM).” This change will better reflect the range of offences, including both traditional and digital manifestations, and align Indian legislation with international best practices. Using precise terminology is crucial to ensure that legal provisions are inclusive of all forms of exploitative material, including those created synthetically through artificial intelligence.

Defining Deepfakes: It is necessary to introduce a clear definition of deepfakes in Indian law, specifying that these are AI-generated or digitally manipulated media, images, videos, or audio that misrepresent a person in a sexually explicit context. By legally defining deepfakes, law enforcement, courts, and platforms will have a clearer framework to identify and address AImanipulated content involving minors, closing gaps where current laws rely solely on the depiction of an actual child.

Need for an AI Classification Framework: The government should establish a comprehensive AI content classification framework to categorize digital media based on risk levels, particularly focusing on synthetic sexual content involving minors similar to china’s. Such a framework would provide standardized guidance to regulators, law enforcement, and technology platforms, ensuring consistent identification, monitoring, and restriction of harmful AI-generated content.

This framework could form part of a broader generative AI policy, outlining permissible and prohibited uses of AI technology in content creation.

Explicit Criminalization of Synthetic CSAM: Amendments should be made to the POCSO Act, 2012 and the IT Act, 2000 (or their replacements) to explicitly criminalize the creation, possession, distribution, or circulation of AI-generated sexual depictions of minors, even if no real child is involved. This is necessary because current provisions often leave loopholes: defence arguments can claim that synthetic media does not involve a “real child.” Following international practices, India should ensure that visual depictions appearing to involve minors, regardless of whether they are computer-generated, are punishable under law.

Comparative analysis of frameworks from jurisdictions like the UK highlights the effectiveness of combining explicit coverage of AI-generated content with mandatory platform accountability. India should adapt these practices through proactive moderation, robust technological interventions, and stringent enforcement, aligning domestic policy with global standards while accounting for local legal, cultural, and infrastructural realities.

Reassessment of Penal Provisions: The severity and societal impact of online CSAM offences necessitate a reassessment of the punitive framework under Indian law. The current maximum sentence of seven years under Section 14 of the POCSO Act, 2012, and Section 67B of the IT Act, 2000, may not adequately reflect the gravity of these offences or serve as a sufficient deterrent. The severity and societal impact of online CSAM offences necessitate a reassessment of the punitive framework under Indian law. The current maximum sentence of seven years under Section 14 of the POCSO Act, 2012, and Section 67B of the IT Act, 2000, may not adequately reflect the gravity of these offences or serve as a sufficient deterrent.

Creation of a National CSAM Database: A centralized repository containing hash values of verified CSAM content should be established and maintained by a Specialized Central Police Unit. This database would enable rapid identification and blocking of harmful content, disrupt distribution networks, and assist investigations of repeat offenders. Centralization would standardize detection protocols across platforms and support evidence-based policymaking.

Capacity Building and Specialized Training: Effective enforcement against AI-generated CSAM requires targeted capacity building for law enforcement. Officers should receive training to understand and investigate deepfakes, generative AI, and other digitally manipulated media. Integrating technical literacy with legal and investigative expertise ensures that prosecutions are both procedurally rigorous and technologically informed.

Stricter Platform Regulation: Intermediaries, including social media platforms, OTT services, and cloud providers, should be required to implement robust technological safeguards, such as automated content moderation algorithms, digital watermarking, and real-time detection tools. Platforms using end-to-end encryption must establish supplementary monitoring protocols that prevent circulation of illicit content without compromising user privacy. Compliance should be enforced through clear accountability mechanisms, including the potential withdrawal of safe harbor protections under Section 79 of the IT Act, 2000, to ensure that platforms are incentivized to proactively prevent the spread of harmful content.

 

Article by: Elizabeth Scaria, CHR, NUALS

Date: 30-09-2026

[1] https://www.ndtv.com/opinion/virtual–scars–real–harm–indias–legal–shift–on–child–abuse–in–the–digital–space8538786  

[2] https://www.inhope.org/EN/articles/child–sexual–abuse–material 

[3] https://www.gov.uk/government/publications/crime–and–policing–bill–2025–factsheets/crime–and–policing–billchild–sexual–abuse–material–factsheet  

[4] https://nhrc.nic.in/sites/default/files/Advisory%20on%20CSAM_Oct2023.pdf) 

[5] https://www.indiacode.nic.in/show–data?actid=AC_CEN_13_14_00005_201232_1517807323686&orderno=2  

[6] https://www.dailymail.co.uk/indiahome/indianews/article–4855694/India–world–s–worse–rates–online–childpornography.html

[7] https://www.justice.gov/criminal/criminal–ceos/child–pornography  

[8] https://laws–lois.justice.gc.ca/eng/acts/c–46/section–163.1.html  

[9] https://subvrsive.com/blog/deepfakes–what–how–why 

[10] Donie O’Sullivan, Deepfake Videos: Inside the Pentagon’s Race Against Disinformation, CNN (Jan. 28, 2019), https://www.cnn.com/interactive/ 2019/01/business/pentagons-race-against-deepfakes/ [https://perma.cc/ PQ2H-PK59]; Scott Ross, Why VFX House Lose Money on Big Movies, The Hollywood Reporter (Mar. 7, 2013, 5:00 AM), https://www .hollywoodreporter.com/news/why-life-pi-titanic-vfx-426182 [https://perma .cc/Z8KF-X2HZ].

[11] Cole, supra note 4; Alex Hern, AI Used to Face-Swap Hollywood Stars into Pornography Films, The Guardian (Jan. 25, 2018), https://www .theguardian.com/technology/2018/jan/25/ai-face-swap-pornography-emmawatsonscarlett-johansson-taylor-swift-daisy-ridley-sophie-turner-maisiewilliams [https://perma.cc/3VDX-A5ZB].   12 https://www.thehindu.com/sci–tech/technology/ai–powered–nudify–apps–fuel–deadly–wave–of–digitalblackmail/article69821623.ece 

[12] https://www.ohchr.org/en/stories/2018/07/nothing–they–can–do–will–stop–me  

[13] https://www.missingkids.org/blog/2025/spike–in–online–crimes–against–children–a–wake–up–call  

[14] https://www.iwf.org.uk/about–us/why–we–exist/our–research/how–ai–is–being–abused–to–create–child–sexualabuse–imagery/  

[15] https://www.iwf.org.uk/about–us/why–we–exist/our–research/how–ai–is–being–abused–to–create–child–sexualabuse–imagery/  

[16] https://www.bbc.com/news/articles/cq6l241z5mjo 

[17] https://www.fbi.gov/news/stories/charlotte–child–sexual–abuse–material–case–shows–unsettling–reach–of–aigenerated–imagery  

[18] https://www.thehindu.com/sci–tech/technology/meta–oversight–board–reviewing–two–cases–ai–generatednudity–targeting–women/article68074591.ece  

[19] https://www.indiacode.nic.in/show–

data?actid=AC_CEN_13_14_00005_201232_1517807323686&sectionId=12858&sectionno=9&orderno=13 

[20] https://www.indiacode.nic.in/show–

data?actid=AC_CEN_13_14_00005_201232_1517807323686&sectionId=12858&sectionno=9&orderno=14#:~:text

=%2D%2D%20(1)%20Whoever%20uses%20a,seven%20years%20and%20also%20be  

[21] https://www.indiacode.nic.in/show–data?actid=AC_CEN_13_14_00005_201232_1517807323686&orderno=15  

[22]

[23] https://www.sciencedirect.com/science/article/pii/S2950193824000883 

[24] https://www.indiacode.nic.in/show–

data?abv=CEN&statehandle=123456789/1362&actid=AC_CEN_5_23_00048_2023–

[25] _1719292564123&orderno=294&orgactid=AC_CEN_5_23_00048_2023–45_1719292564123  

[26] https://www.indiacode.nic.in/show–

data?abv=CEN&statehandle=123456789/1362&actid=AC_CEN_5_23_00048_2023–

[27] _1719292564123&sectionId=90716&sectionno=351&orderno=351&orgactid=AC_CEN_5_23_00048_202345_1719292564123  

[28] https://www.indiacode.nic.in/show–

data?abv=CEN&statehandle=123456789/1362&actid=AC_CEN_5_23_00048_2023–

[29] _1719292564123&sectionId=90721&sectionno=356&orderno=356&orgactid=AC_CEN_5_23_00048_202345_1719292564123  

[30] https://indiankanoon.org/doc/1752240/  

[31] https://www.pib.gov.in/PressReleasePage.aspx?PRID=2113098 

[32] https://nhrc.nic.in/sites/default/files/UNCRC_2020.pdf 

[33] https://www.unicef.org.uk/what–we–do/un–convention–child–rights/ 

[34] https://www.pib.gov.in/PressReleasePage.aspx?PRID=2113098 

[35] https://www.newsonair.gov.in/rajya–sabha–debates–pocso–amendment–bill–mps–introduce–ai–deepfakeregulationbills/#:~:text=She%20also%20introduced%20the%20Deepfake,the%20Bharatiya%20Nyaya%20Sanhita%2C%20202

[36] . 

[37] https://cdn.icmec.org/wp–content/uploads/2023/11/10th–Ed.–One–Pager–

[38] .pdf?_gl=1*rrmyq6*_ga*MTc1OTQ3Mzk0NS4xNzUzNDcyMTAx*_ga_8KQDFLQTCQ*czE3NTM0NzIxMDAkbzEkZzE kdDE3NTM0NzI2NzckajI3JGwwJGgw 

[39] https://www.aljazeera.com/news/2025/2/2/uk–to–become–first–country–to–criminalise–ai–child–abuse–tools  

[40] https://www.gov.uk/government/news/britains–leading–the–way–protecting–children–from–online–predators  38 https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu–ai–act–first–regulation–on–artificialintelligence  

[41] https://edition.cnn.com/2024/09/26/asia/south–korea–deepfake–bill–passed–intl–hnk  

[42] https://regulaforensics.com/blog/deepfake–regulations/ 

[43] https://www.skadden.com/insights/publications/2025/06/take–it–down–act  

[44] https://www.research.ed.ac.uk/en/publications/legal–challenges–in–tackling–ai–generated–child–sexual–abusemate–4 

[45] https://www.insideprivacy.com/international/china/china–releases–new–labeling–requirements–for–aigenerated–content/  

[46] https://www.whitecase.com/insight–our–thinking/ai–watch–global–regulatory–tracker–china  

[47] https://www.forbes.com/sites/markminevich/2023/12/26/revolutionizing–child–protection–the–un–and–uaesgroundbreaking–ai–for–safer–children–collaboration/  

[48] https://unicri.org/topics/AI–for–Safer–Children