← All posts / Policy

Six Months Beats Twelve: IWF Finds More AI Child Abuse Images in H1 2026 Than All of 2025

IWF analysts assessed 6,310 AI-generated child sexual abuse images in H1 2026 — 40% more than all of 2025 — as the charity urges the EU to finally pass its stalled Child Sexual Abuse Regulation.

Six Months Beats Twelve: IWF Finds More AI Child Abuse Images in H1 2026 Than All of 2025

The Internet Watch Foundation (IWF), Europe’s largest hotline for finding and removing child sexual abuse imagery online, published new figures on October 5, 2026 that read like a warning shot to policymakers. In the first six months of 2026, the charity’s analysts assessed 6,310 AI-generated images that met the legal definition of child sexual abuse — already 40% more than the 4,512 images identified across the entirety of 2025. The first half of a year has overtaken a full previous year, and the trend line is steepening rather than flattening.

What the data shows

The IWF’s half-year figures are drawn from reports processed by its expert analysts, who grade confirmed criminal imagery under UK law. The headline numbers:

  • 6,310 AI-generated child sexual abuse images assessed between January 1 and June 30, 2026, versus 4,512 in all of 2025 (+40%).
  • Of the 6,221 images where both age and gender were recorded, girls appeared in 98% of the AI-generated imagery. Unique images depicting girls rose from 4,259 across 2025 to 6,094 by the end of June 2026.
  • The imagery is skewing younger: 2,534 images depicted children aged 7–10; 2,369 depicted children aged 11–13; 1,004 depicted children aged 3–6; and 190 depicted infants and toddlers under the age of two.
  • Children aged 7–13 accounted for 79% of AI-generated images in H1 2026, up from 70% across 2025.
  • Under UK grading, 5,557 images (88%) were Category C — which can include sexualised posing and nude imagery — compared with 2,842 (62%) in 2025. The remainder included 350 Category A images (the most severe, including depictions of rape or sexual torture) and 403 Category B images.

The proportions matter as much as the totals. The category mix shows generative tools being used to produce a broader range of abusive content, not merely more of the least severe kind, and the age distribution is drifting downward — both indicators that offenders are exploring the capability rather than repeating a fixed pattern.

Why this keeps getting worse

The IWF has been tracking AI-generated child sexual abuse material since early 2023, when the first photorealistic outputs began appearing in reports. What was then a trickle — a few hundred images a year — has compounded into an industrial-scale problem. Uncensored open-weight image models, fine-tuned “nudify” variants, and jailbreak communities have lowered the technical barrier to near zero, while the distribution side has migrated to services that either cannot or will not detect the material.

The report’s darker observation is about re-victimisation: in some cases offenders use AI tools to manipulate genuine photographs of real victims, creating new abuse material that further traumatises survivors. The imagery is synthetic; the harm is not.

The detection gap — and the EU fight

The IWF’s core policy argument is technical as much as moral. Its main disruption tool today is hash-matching: confirmed criminal images are converted into unique digital fingerprints that law enforcement and tech companies can use to detect and block known material automatically, without storing or re-viewing the original. But a hash only exists after an image has been identified. Generative AI produces effectively unlimited novel images, each of which has no hash until a human analyst somewhere finds it first. A defence built purely on known-content detection is structurally outpaced by a technology whose defining feature is infinite variation.

That is why the charity is pressing the EU to agree on the long-delayed Child Sexual Abuse Regulation (CSAR), proposed in 2022 and stuck in negotiations ever since. The IWF argues the final text must let platforms detect both known and previously unseen abuse content, with legal certainty for the companies that do so voluntarily — a framing aimed at the encryption and privacy fight that has stalled the file, particularly resistance from Germany, Italy, and Poland over client-side scanning in encrypted messaging.

IWF Chief Executive Kerry Smith put it bluntly: “If Europe is serious about protecting children, it needs a comprehensive Child Sexual Abuse Regulation that gives platforms the legal certainty to detect, prevent and respond to known and unknown child sexual abuse content. At a time when technology is making it easier than ever to create and distribute abusive images and videos at scale, Europe cannot afford to delay.”

The regulatory backdrop

The numbers land on unusually fertile legislative ground. The UK’s Crime and Policing Act 2026 already created dedicated offences around AI-generated abuse material — including criminalising AI models optimised to produce CSAM, owning such models, and taking/modifying/distribising such imagery — making Britain the testbed for supply-side enforcement. The EU strengthened its criminal framework through the recent Child Sexual Abuse Directive, and the IWF launched a public campaign ahead of the resumed CSAR negotiations in Brussels in September. Public opinion polling cited by the charity has consistently shown strong majorities in member states favouring detection mandates, which proponents argue contradicts the hold-out governments’ positions.

The unresolved question is the one that has haunted this file for four years: can detection of unseen content be made proportionate and privacy-preserving inside end-to-end encrypted services? Privacy campaigners maintain that client-side scanning is a structural vulnerability in every conversation; child safety organisations counter that the alternative is simply ceding the territory. The IWF’s H1 2026 data is, in effect, the latest bid to force that trade-off into the open with numbers attached.

Why it matters beyond this report

For the AI industry, the report is a reminder that the most severe misuse of generative models is not a hypothetical tail risk — it is measurable, compounding at 40%-plus per half-year, and increasingly infant-directed. Model providers’ safety filters are the first choke point, but fine-tuning, LoRA swaps, and uncensored derivatives mean the frontier labs’ guarantees degrade quickly outside their own APIs. The enforcement question is shifting from “was this image generated?” toward “who built and distributed the tool that generates it” — the UK’s model-level offences point at exactly that layer.

For policymakers, the IWF data reframes the CSAR debate: every month of delay now corresponds to a measurable volume of novel material that no hash list will ever catch. Whether that argument finally breaks the Brussels deadlock — or hardens it — will be one of the defining AI governance outcomes of the coming year.