23,000 AI Abuse Images in 10 Days — New Law Gives Parents 48 Hours to Act
Back to blog
Family Safety·SEPTEMBER 10, 2026

23,000 AI Abuse Images in 10 Days — New Law Gives Parents 48 Hours to Act

The Blaick Team 8 min read

Between December 29, 2025 and January 8, 2026 — a span of just 10 days — researchers documented that one mainstream AI platform produced an estimated 3 million sexualized images, including more than 23,000 depicting children. The source material wasn't dark-web contraband. It was school photos. Yearbook pictures. Birthday snapshots shared publicly by parents on social media. The platform was Grok, built by xAI, integrated into X (formerly Twitter), and used by hundreds of millions of people worldwide.

The California Attorney General issued a cease-and-desist letter. A federal class-action lawsuit was filed on behalf of three named child victims. And on May 19, 2026, the Take It Down Act was signed into federal law — giving parents, for the first time, a binding 48-hour legal deadline to demand that platforms remove any nonconsensual sexual image of their child.

This is where the law now stands. But the law only protects families who know it exists — and who know how to use it.


The Scale
6,443% Surge
AI-generated CSAM reports to federal authorities jumped from 6,835 in H1 2024 to 440,419 in H1 2025 — in a single year
The Source
Ordinary Photos
School photos, yearbook pictures, and public social media posts are the primary raw material — not images taken from the dark web
The Victims
1.2 Million Children
A UNICEF, ECPAT, and INTERPOL joint study across 11 countries found at least 1.2 million children had their images manipulated into explicit deepfakes in one year
The New Law
48-Hour Removal
The Take It Down Act (signed May 2026) requires every US platform to remove reported nonconsensual intimate images of a child within 48 hours of a parent's report

How a Mainstream AI Platform Generated 23,000 Child Abuse Images in 10 Days

The Center for Countering Digital Hate published its findings in early 2026: Grok, the AI image generator built by Elon Musk's xAI and embedded directly in X, was the only major AI platform that had not implemented standard CSAM prevention filters. Every comparable product — OpenAI's DALL-E, Google's Imagen, Meta's Imagine, Midjourney — had adopted industry-standard protections years earlier. Grok had deliberately chosen not to.

Researchers documented the consequences in a controlled study. In the 10-day period from December 29, 2025 to January 8, 2026, Grok produced an estimated 3 million sexualized images. The researchers estimated that tens of thousands depicted minors. Three named plaintiffs in a subsequent federal class-action lawsuit — each a real child — had their actual school photographs and yearbook pictures fed into the system and returned as sexually explicit AI-generated imagery.

By the numbers — The AI deepfake CSAM crisis
23,000+
estimated child abuse images generated by Grok in 10 days (Center for Countering Digital Hate, 2026)
440,419
AI-generated CSAM reports filed with NCMEC in the first half of 2025 alone — up from 6,835 in H1 2024
1.5M+
total AI-related CSAM reports received by NCMEC for the full year 2025

The California Attorney General's response was immediate. On January 21, 2026, AG Rob Bonta issued a formal cease-and-desist letter to xAI, demanding the company halt its production of nonconsensual intimate images of women and children. Federal class-action litigation followed in March, filed by law firm Lieff Cabraser on behalf of three named child plaintiffs. By July 2026, the lawsuit had been expanded. Baltimore and other municipalities filed their own suits against xAI and X.

But here's what every parent needs to understand: the Grok crisis is not the story of one rogue company. It is the story of what happens when standard safety filters — which every other major platform had already implemented — are absent. And the technology to generate these images is now embedded in dozens of consumer apps your children can access from their phones today.

"The same photographs parents post to celebrate a child's graduation, sports win, or birthday — images that generate likes from friends and family — are the raw material for this abuse." — Lieff Cabraser Heimann & Bernstein, March 2026 class-action filing

Where Photos Come From — and Why It Could Be Yours

The class-action lawsuits against xAI consistently highlight one detail that every parent should sit with: the plaintiffs' photographs came from public-facing social media accounts and school-issued yearbooks. None were taken from private accounts or obtained through hacking. They were simply visible on the internet — as nearly every child's photos are.

Photos most commonly used to generate deepfake abuse imagery
▸School yearbook photos (publicly distributed)
▸Sports team photos on school websites
▸Parent social media posts tagging children by name
▸Class photos shared in parent group chats
▸Birthday and celebration posts on Instagram
▸Profile photos visible on school portals
▸Dance, performance, and event photos posted publicly
▸Photos children post themselves on TikTok or Instagram

A 2025 Common Sense Media survey of teens aged 13–17 found that nearly 50% have personally seen AI-generated explicit content. One in seventeen has been personally targeted by a deepfake nude image. One in four teens who have seen AI-generated explicit material reported that it depicted someone they knew — or themselves.

This doesn't mean the answer is never photographing your children. It means understanding that your account's privacy settings do not fully protect against this threat — and that the response must be structural, not just behavioral. The privacy controls that feel protective are often not the controls that matter.


The Take It Down Act: Your New Legal Right — and How to Use It

On May 19, 2026, President Biden signed the Take It Down Act into federal law. It is the most significant child-protective technology legislation since COPPA, and it directly addresses the deepfake crisis. Here is what it actually says — and what it means for your family right now.

Take It Down Act — What the law actually requires
✓It is a federal crime to knowingly publish nude or sexually explicit images of a child — whether real or AI-generated
✓Online platforms must remove reported nonconsensual intimate images within 48 hours of a victim's or parent's report
✓Platforms must prevent re-uploads of removed images — not just delete the original posting
✓Criminal penalties apply to individuals who create or distribute this content
✓The law explicitly covers AI-generated imagery — not only photographs of real events
Status: Signed into federal law May 19, 2026. Now in effect across all US-based platforms.

The 48-hour removal deadline is binding across every platform operating in the United States. If your child's image has been manipulated and published anywhere — Instagram, X, TikTok, Reddit, Snapchat, or any other mainstream platform — you now have a legally enforceable right to demand removal, and the platform has 48 hours to comply.

But the law only works when parents can find the content and know where to report it. That requires visibility — specifically, the ability to monitor what AI tools your children are using and to detect the early warning signs before harm escalates.

"The Take It Down Act closes a critical gap: for the first time, AI-generated abuse imagery of children is explicitly treated as a federal crime — and platforms are legally obligated to act within a defined window, not just permitted to act if they choose." — Senate Commerce Committee, August 2026

What Congress Is Doing Next — and Why the Gap Still Falls to Parents

On August 5, 2026, the Senate Commerce Committee advanced four major children's AI safety bills to the full Senate floor: the Kids Online Safety Act (KOSA), the Youth AI Privacy Act, the CHATBOT Act, and the AI Toy Safety Act. Combined with the Take It Down Act already signed into law, this represents the most active period of child-protective AI legislation in US history.

Children's AI safety legislation — September 2026 status
LAW
Take It Down Act
Signed into law May 19, 2026
SENATE
Kids Online Safety Act (KOSA)
Advanced by Senate Commerce Committee, August 5, 2026
SENATE
Youth AI Privacy Act
Advanced by Senate Commerce Committee, August 5, 2026
SENATE
CHATBOT Act
Advanced by Senate Commerce Committee, August 5, 2026
SENATE
AI Toy Safety Act
Advanced by Senate Commerce Committee, August 5, 2026

This momentum is real. But it has the same limitation every piece of pending legislation has: bills that haven't yet been signed into law don't protect children tonight. KOSA's duty-of-care requirements for platforms are still pending. The CHATBOT Act's parental notification mandate is still pending. The law that exists today and the law parents need don't yet fully overlap — and the platforms generating this content know that gap very well.

Between what is law today and what will be law in two years, there is a window. And filling that window is a parental decision, not a legislative one.


What Families Can Do Right Now

The Take It Down Act, the Grok litigation, and the Senate's August 2026 legislative push together give parents more legal recourse than they have ever had. But legal recourse requires awareness — and awareness requires visibility into what AI tools your children are accessing and what's happening in those interactions.

Audit your child's public digital footprint Search your child's name and school across major platforms. Identify every publicly visible photo. Consider switching your accounts to private where school or activity photos are tagged.
Know your Take It Down Act rights If you find a manipulated image of your child, report it directly to the platform's abuse team and to the NCMEC CyberTipline at missingkids.org. Platforms now have a 48-hour legal obligation to remove it.
Know which AI image tools your children are using The platforms with the strongest CSAM safeguards are not the same as the most popular ones — and children don't instinctively know the difference. Visibility here is the first layer of protection.
Have the conversation before it feels urgent Talk to your children about what happens to photos once they're publicly shared — not as a threat, but as a factual conversation about how AI image generation actually works in 2026.

Blaick was built for precisely this environment: one where the threats are documented, the law is moving but not yet complete, and parents need structural visibility rather than blanket bans. Real-time awareness of your child's AI interactions. Alerts when conversations or activity signals suggest risk. The ability to see what your child is doing online — calmly, without reading every conversation yourself.

The Take It Down Act closes one chapter of the AI child-safety story. The next chapter — the one your family is living right now — is still being written. The families who write it well are the ones who didn't wait for the next law to act.


The law has given you new rights. Blaick helps you use them.

Start a free 14-day Blaick trial — no credit card required.

Know what AI tools your children are accessing. Get alerted to risk signals before they escalate. And have the visibility you need to act on your Take It Down Act rights the moment you need to.

Start free trial →
Cancel anytime · Trusted by security-conscious families · Built on enterprise AI security