WASHINGTON — The claim before lawmakers was direct: artificial intelligence tools are taking ordinary images from everyday life and using them to generate child sexual abuse material. The statement, made by a woman whose identity was not specified in the available material, captures a legal and technical problem that prosecutors, platform operators and legislators have struggled to address as image-synthesis models became widely available.
The core mechanism is well documented in law enforcement reports. Generative AI models trained on large image datasets can produce photorealistic synthetic images, including images depicting minors in sexually explicit contexts. The National Center for Missing and Exploited Children flagged a rise in AI-generated CSAM reports starting in 2023, though exact annual counts vary by reporting period.
U.S. federal law under 18 U.S.C. § 2256 criminalizes the production, distribution and possession of child sexual abuse material, and courts have ruled that the prohibition covers computer-generated images that are sufficiently realistic. The PROTECT Act of 2003 closed an earlier loophole by making obscene visual depictions of minors illegal even when no real child was used. The question that has resurfaced with generative AI is enforcement at scale: models capable of producing this content are downloadable, run locally on consumer hardware and require no platform intermediary.
That last point is where legislative pressure is building. Open-weight models released by companies including Meta, Mistral and others can be downloaded and run without any content filter or terms-of-service enforcement. Closed commercial platforms such as OpenAI's DALL-E and Stability AI's hosted products implement classifiers designed to block explicit outputs, but researchers have repeatedly demonstrated jailbreak techniques that bypass those filters. The gap between a closed API and a locally run open-weight model is where enforcement becomes practically impossible without hardware-level or internet-level intervention.
Congress has moved on this front, though slowly. The Kids Online Safety Act passed the Senate in July 2024 with a 91-to-3 vote but stalled in the House. Legislators have separately introduced bills targeting AI-generated CSAM specifically, including proposals that would require platforms to proactively scan for synthetic material using hash-matching technology similar to PhotoDNA, the Microsoft-developed tool the tech industry already uses for known CSAM. PhotoDNA works by comparing cryptographic hashes of known illegal images against uploaded content; applying an equivalent system to AI-generated material is harder because each generated image is unique and produces a different hash.
The technical asymmetry is real. A human-produced CSAM image generates a fixed hash that can be flagged across every platform that runs PhotoDNA. A generative model can produce millions of unique images depicting the same content, none of which matches a known hash. Detection then requires a classifier trained to identify explicit content involving minors, and those classifiers produce both false positives and false negatives. Google, Microsoft and Meta each operate internal trust-and-safety teams that work on these classifiers, but the specifics of their accuracy rates are not public.
The liability question under Section 230 of the Communications Decency Act adds another layer. Section 230 generally shields platforms from civil liability for user-generated content, but Congress carved out an exception for CSAM under the FOSTA-SESTA legislation signed in 2018. Whether that exception applies when a platform's own AI tool generates the content—rather than a user uploading it—is a question courts have not yet resolved at the federal appellate level.
For the companies building and distributing these models, the business exposure is not abstract. Stability AI has faced multiple civil lawsuits over training data; a ruling that extends CSAM liability to model developers or distributors would create a different order of legal risk than copyright claims. Investors in open-weight model companies have largely priced that risk as manageable, but a high-profile prosecution or a successful civil suit against a model distributor would reprice it quickly.
The woman's testimony, whatever the specific venue, reflects a pattern: survivors and advocacy organizations have become the primary drivers of legislative momentum on this issue, ahead of both the technology industry and most regulatory agencies. The National Center for Missing and Exploited Children received 36.2 million reports of suspected child sexual exploitation in 2023, a record. The agency has said AI-generated content is a growing share of that volume, though it has not broken out a precise percentage in publicly available reports.