The Internet Watch Foundation identified 6,310 AI-generated images meeting the legal definition of child sexual abuse material in the first half of 2026—a 40 percent jump from 4,512 images across all of 2025.

The findings expose a critical mismatch between detection capability and content velocity. Among 6,221 images where both age and gender were recorded, girls appeared in 98 percent of the identified material. The breakdown: 2,534 images depicted children aged seven to 10, 2,369 showed children aged 11 to 13, 1,004 depicted children three to six, and 190 featured infants under two.

Children aged seven to 13 collectively represented 79 percent of all AI-generated material identified in H1 2026, up from 70 percent in 2025.

The current detection infrastructure relies on hash-matching—converting confirmed criminal images into unique digital fingerprints that platforms and law enforcement use to block known content. The problem is obvious: hash-matching only works for material already cataloged. New AI-generated content has no hash until someone detects it first. At current production rates, offenders generate new material faster than systems can fingerprint it.

The IWF is pressing the EU to finalize long-delayed Child Sexual Abuse Regulation that would mandate detection of both known and previously unseen content. Tech companies say they need legal certainty—and likely liability protection—before investing in detection systems that flag material they haven't yet seen. Right now, platforms lack clear legal cover to implement such tools, creating a regulatory vacuum that content moderation lags behind.

The IWF notes that existing frameworks leave gaps where online services simply aren't required to detect or remove this material. A regulation focused solely on known content would allow offenders to operate in a cycle where they outproduce detection faster than platforms can respond.