Broken Promises
Meta Ran Hundreds of Paid Ads with Child Sexual Abuse Imagery
TTP has found more than 300 ads with child sexual abuse material that ran on Facebook and Instagram. Some include images of real children.

Key findings:

  • Meta has run more than 300 paid ads containing child sexual abuse material (CSAM) this year, a TTP investigation found.
  • Most of the ads showed a photo of a child, which is digitally altered with AI to make it appear the child is performing a sex act.
  • TTP identified multiple photos of real children, including a member of a European royal family, that were used in the ads.
  • Several of the CSAM ads were placed by Meta’s own advertising partners in China, including a Chinese state-controlled company.
  • The vast majority of the ads pointed to AI apps from China. Many of these apps were capable of “nudifying” people.

Last year, a European royal family released a photo of one of its youngest members, a minor. This month, the photo turned up in an ad that ran on Facebook and Instagram. But it had a disturbing twist: The young royal was animated into a video of her performing a graphic sex act. The ad promoted a Chinese AI app and was targeted at adult male users.

The ad is one of hundreds containing images of child sexual abuse that have run on Facebook and Instagram this year, a Tech Transparency Project investigation found. TTP identified more than 300 Meta ads that depicted children ranging in age from toddlers to preteens to young teenagers being molested or engaged in sexual activity.

Most of the ads had the same format, showing a snippet of adult porn followed by a photo of a child, which is manipulated with AI to make it appear the child is performing a sex act. The ads used a common set of captions, voiceovers, and background music. TTP was able to identify multiple photos of real children—taken from social media posts and websites—that appeared in these ads.

Meta did not respond to a request for comment about the child sexual abuse ads. But hours after TTP shared its findings with Meta, the company did a rapid clean-up operation, removing about 150 of the ads that were still visible in its Ad Library, the company's database of advertising that has run on its platforms.

Meta also revised the Ad Library records of more than a hundred other ads that had already been removed, marking them as having violated the company's policy on child exploitation. The ads previously showed violations of Meta's adult-oriented policies without mentioning children—an omission that suggests Meta may be undercounting instances of child sexual abuse.

Despite the quick clean up, Meta did not fix the flow of child exploitation content in its advertising system. In the ensuing days, TTP found that Meta continued to run dozens of ads containing child sexual abuse images—including the one featuring the underaged European royal.

TTP’s investigation raises questions about Meta’s recent effort to position itself as an industry leader on child safety. After agreeing to a multi-billion-dollar settlement with state attorneys general to end its social media addiction trial, Meta began pushing rivals like YouTube and TikTok to adopt the same set of teen safety features it has pledged to implement under the settlement deal. But TTP’s findings reveal that at the same time it is calling on tech rivals to join it in creating a new industry standard for teen safety, Meta has been publishing and making money off graphic images of child sexual abuse.

TTP reported all of the ads found during the course of its research to the nonprofit National Center for Missing and Exploited Children (NCMEC), which processes evidence of online child exploitation. NCMEC provides data to law enforcement and shares digital fingerprints, or “hashes,” with tech companies to identify and block child abuse images.

The ads identified by TTP pose a raft of potential legal questions for Meta. While Section 230 of the Communications Decency Act broadly protects tech platforms from liability over user-generated content, it does not extend to federal criminal violations, including under laws covering sexual exploitation of children. U.S. federal law prohibits the production, advertisement, distribution, receipt, and possession of child sexual abuse material, known as CSAM.

Furthermore, the images at issue are not organic user posts. The CSAM at issue is contained in advertisements approved and run by Meta, which collected revenue from disseminating the material. The FBI has warned that CSAM created with AI-generated images is also illegal.

TTP found some notable patterns in the Meta CSAM advertising.

Several of the ads show they were placed by Meta’s own "top tier" ad agency partners in China. These partners—known as "resellers"—channel billions of dollars’ worth of Chinese advertising onto Facebook and Instagram. They are part of a system that allows Meta to tap into the enormous Chinese ad market despite the fact that its platforms are banned in China. Reuters has reported that Meta exempts these reseller companies from being punished for violating its policies and doesn’t immediately act when their ads are flagged by its automated systems.

One of the resellers that ran a CSAM ad, GIMC, is controlled by the Chinese government. Another, BlueFocus, works closely with the Chinese Communist Party’s main propaganda outlet and was blocked by U.S. national security officials from merging with an American firm in 2018.

TTP found that the majority of the CSAM ads pointed to AI image- or video-generation apps from Chinese developers. TTP verified that many of these apps are capable of "nudifying" people in photos. Meta has said it prohibits promotion of nudify apps.

The investigation also found that a large number of the CSAM ads were linked to Facebook accounts for what appear to be fake people or businesses. That would violate Meta’s ban on what it calls "inauthentic behavior" on its platforms. The Facebook accounts were often empty shells, with no content and few if any followers. They frequently used the same profile image, suggesting they are part of a network.

This is not the first time Meta has faced questions about the presence of CSAM in its paid ads. In July 2026, the BBC found that Instagram ran ads promoting CSAM in India, with some of the ads using terms like "rape video" and "child video." In response to that report, Meta insisted it takes a "zero tolerance approach" to child exploitation. TTP’s findings raise questions about that statement.

Meta did not respond to TTP's questions about why it approved hundreds of ads containing child sexual abuse material, how many users the ads reached globally, how much revenue it generated from the ads, and whether it informed law enforcement about the ads.

Warning: This report contains descriptions that some readers may find offensive or disturbing.

‘Hidden desires’

TTP researchers identified the CSAM ads in the Meta Ad Library, which preserves certain categories of ads that run on Facebook and Instagram. Most of the CSAM ads ran in the European Union and/or the United Kingdom. Because Meta retains ads that run in those regions for a year, they remain visible to researchers even when they are not active. In the U.S., unless Meta ads pertain to “social issues, elections or politics,” they disappear from the Ad Library as soon as they finish running.

Meta says it reviews ads before they run to ensure they meet the company’s advertising standards, which prohibit "content that sexually exploits or endangers children." These reviews can encompass images, videos, and text as well as advertising link destinations, Meta says. But TTP found 332 CSAM ads that made it through Meta’s review process.

These ads showed, among other things:

  • A photo of an elementary-school-aged girl applying unicorn lip gloss morphing into a scene of her performing a graphic sex act.
  • A preteen girl taking off her shirt with the text, "Our AI transforms your hidden desires into hypnotic videos. Dark, seductive, unforgettable."
  • A photo of an elementary-school-aged girl in a Hello Kitty shirt which transforms into a video of her being raped by an adult male.
  • A photo of a preteen girl animated so that she performs a graphic sex act, with a voiceover that says, "There are no restrictions. All the characters are real people and there are many options. This is the AI men actually use."

TTP matched multiple CSAM ads to photos of real children that appeared online. In addition to the young European royal mentioned earlier, TTP found ads that used a photo of a 14-year-old influencer showing off her new sports club uniform. She had posted the photo on her Instagram account. The ad animated the girl into a video of her performing oral sex.

Another set of ads featured a preteen girl posing in a pink athletic outfit with pigtails. The ad morphs the girl into a video with an adult man standing behind her, removing her shirt and molesting her while she looks frightened. The girl’s image was taken from stock photos created years earlier. The photo descriptions specify that she is a preteen.

In early August, TTP shared its initial findings of 53 Meta CSAM ads with Wired. Meta told the publication that many of the ads predated "new AI technology we launched recently to better detect and block violating ads at upload." However, TTP identified hundreds of additional CSAM ads that ran on Facebook and Instagram after that.

Due to the limitations of the Meta Ad Library, TTP was only able to view the CSAM ads’ reach in the EU and UK. The ads collectively reached more than 29,000 people in EU and 6,800 people in UK. However, TTP determined that many of the ads ran in additional countries:

  • Nearly 80% of the ads (262) ran in the U.S.
  • 84 of the ads ran in India—78 of them after the Indian government directed Meta to remove any Instagram ads promoting CSAM.
  • 120 of the ads ran in Australia, which is investigating Meta’s enforcement of the country’s social media ban for children under 16.

Two of the CSAM ads reached more than 2,500 users in the EU. The Meta Ad Library only gives data for select regions, so the actual reach may be much higher.


Two of the CSAM ads reached more than 2,500 users in the EU. The Meta Ad Library only gives data for select regions, so the actual reach may be much higher.

As of Sept. 1, Meta had removed just over half (183) of the 332 CSAM ads from its Ad Library. But hours after TTP shared its findings with Meta on Sept. 2, the company removed the remaining 149 ads.

Meta also revised a large number of policy violation notices. When it pulls an ad from its Ad Library, Meta often lists which policies were violated. For CSAM, that would be the Child Exploitation, Abuse, and Nudity policy. But with 113 CSAM ads, the notices made no mention of children at all. Instead, they cited adult-oriented policies—such as Adult Nudity and Sexual Activity or Adult Sexual Exploitation—or carried a generic notice that read, "This ad was run by an account or Page we later disabled for not following our Advertising Standards."

Only after TTP flagged these inconsistencies did Meta correct the 113 notices to reflect a child exploitation violation.

Meta's misidentification of policy violations raises questions about the reliability of its self-reported statistics about the CSAM it removes from its platforms. Meta did not respond to TTP's questions about how it categorizes these violations.

Meta frequently mislabeled the policy violations of CSAM ads. While it correctly cited some ads for violating its policy on Child Sexual Exploitation, Abuse, and Nudity ...


Meta frequently mislabeled the policy violations of CSAM ads. While it correctly cited some ads for violating its policy on Child Sexual Exploitation, Abuse, and Nudity ...

TTP found other problems with Meta’s characterization of the CSAM ads. The company told the Australian trade publication AdNews that the initial batch of 53 CSAM ads identified by TTP and shared with Wired "were not targeted towards Australian users." But TTP confirmed in the Meta Ad Library that dozens of the ads were in fact targeted at users in Australia.

Meta’s Chinese ad partners

TTP found that three of Meta’s ad reseller partners in China—GIMC, Meetsocial, and BlueFocus—ran ads on Facebook and Instagram containing the same CSAM content. Resellers place ads on Meta platforms on behalf of Chinese customers. (Facebook and Instagram are banned in China, but through this system, Meta still gets access to Chinese ad dollars.)

The CSAM ads, which ran in February and March 2026, showed a girl who appeared to be naked from the waist down laying back with her legs spread in a sexual position, with overlay text that said, “I can show you more.”

One of the ads listed Global Integrated Marketing Communication Group Holdings as its advertiser and payer. According to Hong Kong corporate records and Chinese state media, this is another name for Guangdong Advertising Group, also known as GIMC.

GIMC is a state-controlled Chinese business and one of Meta’s 11 authorized resellers in China. Meta has even touted the company as an advertising “success story,” saying it "helps clients enhance brand awareness, expand market share, and increase sales through data-driven strategies."

The ad placed by GIMC directed users to a virtual private network app called AstralVPN in the Google Play Store. The implication is that the VPN can be used to view child sexual abuse material. The app showed it has been downloaded more than 100,000 times.

GIMC did not respond to a request for comment and questions about the CSAM ad. The developer of the AstralVPN app also did not respond.

See the note at the bottom of this report for additional findings on GIMC.

One of the child sexual abuse ads was placed by GIMC, a Meta advertising partner in China. Meta has touted GIMC as an advertising "success story."


One of the child sexual abuse ads was placed by GIMC, a Meta advertising partner in China. Meta has touted GIMC as an advertising "success story."

Three additional CSAM ads showing the same young girl with the "I can show you more" text listed Feishu Shennuo Digital Technology (Shanghai) Co., Ltd, as their advertiser and payer. That is the full name for Meetsocial, another Chinese Meta reseller.

One of the Meetsocial ads directed to an app that has been removed from the Google Play Store. The app’s ID, which was still visible in the URL of its Google Play page, matched a VPN app called Proxy Master – Fast & Private from a Chinese developer called FangX Technologies, according to mobile analytics firm AppMagic. TTP was not able to capture where the other two ads directed users before they were removed by Meta.

A 2023 analysis conducted by the consulting firm Frost & Sullivan ranked Meetsocial as Meta’s largest Chinese ad reseller, with $2.24 billion in Meta ad sales.

MeetSocial did not respond to a request for comment and questions about the CSAM ads. App developer FangX Technologies also did not respond.

A fourth CSAM ad showing the young girl listed the Meta reseller BlueFocus as its advertiser and payer.

The ad directed users to an app called Knight Star VPN in the Google Play Store. The app, which had more than 500,000 downloads, gave its developer as IOPixel with an address of simply, "China."

BlueFocus is one of the largest public relations firms in China and boasts a roster of high-powered clients like Toyota, Pepsi, and Intel.

In 2018, the Committee on Foreign Investment in the United States (CFIUS), which evaluates whether foreign deals pose risks to national security, blocked BlueFocus from combining its business with the American digital marketing firm Cogint. A year later, BlueFocus launched a "Belt and Road Brand Cooperation Program" with the Chinese Communist Party’s main propaganda outlet, the People's Daily.

BlueFocus did not respond to a request for comment and questions. Knight Star VPN also did not respond.

Another child sexual abuse ad was placed by Meta's China advertising partner BlueFocus. Meta has given BlueFocus multiple performance awards.


Another child sexual abuse ad was placed by Meta's China advertising partner BlueFocus. Meta has given BlueFocus multiple performance awards.

These findings raise questions about Meta's prior statements about child exploitation ads. In July 2026, Meta blamed "determined criminals” for the ads, saying they would “continue to try to exploit our platform, including through our advertising systems." But TTP found that Meta’s own advertising partners in China—including one controlled by the Chinese government—are part of its CSAM problem.

Meta has a close relationship with the Chinese resellers that ran CSAM ads, giving all three companies industry performance awards in recent years. GIMC received two Meta awards for "large-scale customer activation," while BlueFocus was honored for bringing in "new track" customers.

Meta pays Chinese resellers a 10% commission for ads purchased through their accounts, according to Reuters reporting. Reuters also detailed how Meta whitelists ads purchased via the resellers and doesn’t act immediately when their content is flagged by Meta’s automated systems. In practice, this often results in resellers ads getting a pass on policy violations.  

Meta has a close relationship with the Chinese resellers that ran CSAM ads, giving all three companies industry performance awards in recent years.

AI and nudify apps

TTP’s analysis found that 298 of the 332 Meta CSAM ads directed users to AI image- and video-generator apps in the Apple or Google app stores. The vast majority of these ads (253) pointed to apps from China-based developers.

The ads imply that the apps can be used for creating or viewing CSAM. In 182 cases, the ads pointed to Apple App Store apps that TTP verified are capable of “nudifying” people or putting them into sex videos.

For example, two of the ads pointed to an app called Lumin – AI Partner in the App Store. The ads showed an image of an elementary-school-aged girl who appeared to be still missing her adult teeth, with the text "Realizing Deep Fantasies with Generation AI." Clicking the ad showed a video montage of adults engaged in sex acts and swapped the child’s face onto one of the adults.

TTP downloaded and reviewed the Lumin app. The app initially opened to an innocuous-looking page with fully clothed cartoon characters. But very quickly, it jumped to a video of an AI-generated female FBI agent wearing a leather corset, which comes undone to reveal her underwear. The app then displayed a collection of sexual and pornographic video templates. Users could upload photos to these templates to depict people naked, in lingerie or bikinis, or performing sex acts.

Two of the Meta CSAM ads pointed to an app called Lumin in the Apple App Store.


Two of the Meta CSAM ads pointed to an app called Lumin in the Apple App Store.

Lumin listed its developer as Chengdu Heng’aotong Supply Chain Co., Ltd., with an address in China. The app had the same user interface and templates as Mask AI, one of the CSAM-advertised apps that TTP shared with Wired. (Mask AI was removed from the Apple App Store after the Wired reporter asked Apple about the app.)

TTP found Meta CSAM ads pointing to eight other apps with the same design and templates, including Craftor, Prabag-AI Diverse Photo&Video, Voyag - AI Travel Photo Maker, Eariey - AI Custom Earrings, Morph Ai Face Fusion, Scelis – AI Visual Maker Video, and Sollune—AI Mood Redrawn, and WizArc - Virtual AI Wardrobe. All were in the Apple App Store.

After TTP shared the list of apps with Apple, the three nudify apps that were still available in the App Store (Lumin, Prabag, and Voyag) were taken down.

The developers of the apps did not respond to questions.

In a statement, Apple said it has "zero tolerance for developers who deliberately attempt to evade our review process."

"In this case, the developers mentioned in this report initially submitted apps that were compliant with the App Review Guidelines, only to later surface nudify capabilities, which are against our rules," Apple said. "Our teams work continuously to identify and remove apps that engage in this kind of bait-and-switch behavior, as well as the developer accounts behind them."

A Google spokesperson said all the Google Play apps flagged by TTP—which had been promoted by Meta CSAM ads—have also been suspended. These included AI apps as well as the VPN apps placed by Chinese ad resellers.

"Google Play does not allow apps that contain sexual content or allow users to nudify images of people, and we continually take proactive steps to detect and remove apps with harmful content," the spokesperson said. "When violations are reported to us, we investigate and take swift action, which in the case of these apps has included suspending hundreds of violating apps and restricting related search terms like 'nudify' on our store."

Fake Accounts

Meta requires advertisers to have a Facebook page, which is disclosed in the Ad Library. TTP found that many of the CSAM ads were linked to Facebook pages for what appeared to be fake people or entities.

For example, one of ads that ran April 9 to 13 on Facebook and Instagram showed a preteen-looking girl dressed in a pink top performing a graphic sex act with the text "bring your dream girl to life." The ad was linked to a Facebook page for "Kenny Maddie Regan." The page calls itself a local business but has no content or followers beyond a profile photo of three women shoppers. It gives its location as a commune in Vietnam.

An identical ad ran during the same period but was linked to a Facebook page for "Lynn Nicole Brooks." That page was a clone of "Kenny Maddie Regan."

This Facebook page, which was linked to one of the CSAM ads, appears to be a fake identity.


This Facebook page, which was linked to one of the CSAM ads, appears to be a fake identity.

Another ad that ran Aug. 12 to 13 on Facebook and Instagram showed a girl in a school uniform and depicted her engaged in a sex act. A voiceover said, "There are no restrictions. All the characters are real people and there are many options. This is the AI that men actually use." The ad was linked to a Facebook page for "Briflabremgles Nihendrimes" with the same profile photo of the three women shoppers.

This page listed an address and phone number in Chicago that, when called, answered with an unintelligible voice recording.

One CSAM ad that ran on August 3 to 4 was connected to a Facebook page called "Divine Productions," which had no profile photo and no followers. The page tried to pass itself off as being from the Church of Jesus Christ of Latter-day Saints. TTP reported the ad to NCMEC, and Meta later disabled the ad and page. 

Multiple CSAM ads were linked to Facebook pages with the same profile image of three women shoppers.


Multiple CSAM ads were linked to Facebook pages with the same profile image of three women shoppers.

These apparently fake Facebook pages violate Meta’s policies, which require people to "create one account using the name they go by in everyday life that represents their authentic identity." Meta’s rules also prohibit "inauthentic behavior," which the company defines as "a variety of complex forms of deception, performed by a network of inauthentic assets controlled by the same individual or individuals, with the goal of deceiving Meta or our community or to evade enforcement under the Community Standards."

Ad enforcement failures

In its July 7 statement on child exploitation, Meta said, "Anyone on our platforms can report ads if they believe they violate our policies." However, Meta only has a reporting feature for ads that are actively running. There is no mechanism to alert Meta about ads that are archived in the Ad Library after their scheduled run.

TTP did report 129 active CSAM ads to Meta, marking them as "problem involving someone under 18" and "seems like sexual exploitation." Meta took at least a week to review the reports and often took no action:

  • With 57% (73) of the CSAM ads reported to Meta, the company sent back a message that said, "We've taken a look and found that this ad doesn't go against our Advertising Standards."
  • In 43% (56) of the cases, Meta sent back a message that the ad had already been removed, though six of the ads remained visible in the Ad Library.

In some cases, the CSAM ads racked up hundreds of additional views as Meta mulled a response. For example, TTP reported the ad showing the preteen in pigtails—a real person—on August 14, the day it started running. At that time, the ad had only reached four users in the EU. But over the next several days it reached an additional 330 users before Meta removed it.

TTP also found that Meta was inconsistent in its approach to identical ads reported by TTP. For example Meta removed one ad showing a girl engaged in a graphic sex act with the text, "Not just photo. There are no restriction [sic]." But when TTP reported an identical ad to Meta, the company responded by saying it did not violate advertising standards.

It is unclear why Meta would remove one CSAM image while failing to take action on identical copies. The company says it developed hashing technologies in 2019 that “detect identical and nearly identical photos and videos.”

With 57% (73) of the CSAM ads reported to Meta, the company sent back a message that said, "We've taken a look and found that this ad doesn't go against our Advertising Standards."

TTP reported this CSAM to Meta. It showed a girl engaged in a graphic sex act.


TTP reported this CSAM to Meta. It showed a girl engaged in a graphic sex act.

Meta’s retention of CSAM ads in the Ad Library raises other issues. During TTP’s investigation, we encountered dozens of CSAM ads that were archived in the Ad Library after running on Facebook and Instagram. The content of these older ads remained visible to anyone. As noted above, there is no mechanism to flag these archived ads to Meta.

TTP also encountered disclosure problems with Meta ads that ran in the EU. Most of these ads did not fulfill the EU Digital Services Act requirement to provide information on who benefited from the ad and who paid for it. These fields in their Ad Library disclosures were often left blank or filled with gibberish, an apparent violation of EU transparency rules.

Meta did not respond to questions about its ad reporting mechanisms, response time to user reports, image-matching technology, retention of CSAM content in its Ad Library, and ad disclosure discrepancies.

Additional findings on Chinese reseller GIMC: TTP found that GIMC has been running ads this year for "Movely - AI Photo to Video." TTP identified Movely as a nudify app in an April 2026 report. The following month, 404 Media detailed how a ninth grader in Radnor, Pennsylvania allegedly used Movely to create nude images of five female classmates. Apple has since removed the app from its app store, and the more recent GIMC ads for Movely point to a website for creating sexually suggestive AI storylines about women. TTP sent questions to a contact email listed on the website but did not hear back.

September 8, 2026
Top stories_
September 8, 2026

TTP has found more than 300 ads with child sexual abuse material that ran on Facebook and Instagram. Some include images of real children.

August 18, 2026

As social media bans for kids under 16 gain momentum around the world, Meta is exporting its U.S. influence tactics to undermine them.

June 11, 2026

The U.S. imposes economic sanctions on an array of Iranian officials and groups. YouTube is providing channels to many of them and running ads on their videos.

April 22, 2026

Apple is positioning the Apple Watch as a health monitoring tool. It wants Washington’s help to get more Americans to buy them.