Meta Approved and Ran Ads Showing AI-Generated Child Sexual Abuse Images for Nine Months
More than 50 paid advertisements containing child sexual abuse material ran across Facebook, Instagram, Messenger and Threads. Some reached thousands of accounts in Europe and the United States before researchers forced Meta's hand.

Key points
- Researchers at the Tech Transparency Project found more than 50 paid ads containing child sexual abuse material in Meta's own public ad library between November 2024 and August 2025.
- At least one ad reached 2,563 accounts across eight European countries, including the UK, France and Germany.
- Meta's automated ad-review system approved the ads before they ran; some reappeared after Meta had already removed identical versions for policy violations.
- Several ads linked to an app called MaskAI, which Apple has since removed from the App Store.
- Meta says it removed over 36 million pieces of child sexual exploitation content last year, but critics say the repeated approvals reveal a deeper failure in paid-ad screening.
For nine months, Meta's advertising systems reviewed, approved, and collected payment for ads that contained child sexual abuse material, or CSAM, images or video that show the sexual abuse of children. The Tech Transparency Project (TTP), an independent watchdog group, found more than 50 such ads sitting in Meta's own public ad transparency library, a searchable database Meta created so anyone can see what ads run on its platforms.
WIRED first reported the findings.
What did the ads actually show?
The content was explicit and deliberate. One video ad used a thumbnail of a child, added a caption about "deep fantasies," and when clicked, played adult sexual footage before inserting the child's face into it using AI. Another ad, repeatedly reposted, showed a young girl in a sexual position with the caption "I can show you more."
A third video started with a clip of a girl applying lip gloss and morphed into the child performing a sex act. These were not borderline cases.
"These ads made no effort to mask the images or hide what they were promoting," Katie Paul, TTP's director, told WIRED. She stressed that this was paid advertising, content Meta actively reviewed and charged for, not posts uploaded by ordinary users that slipped through.
How did Meta's systems miss this?
Meta says all ads go through review before they run, primarily using automated tools, software that checks content against the company's rules. Those rules explicitly ban child sexual exploitation material and any sexually suggestive imagery.
The automated screening failed repeatedly. Some of the ads found in the second batch, discovered hours before publication, had been posted after WIRED first contacted Meta about the problem. A few were actively reaching accounts at the moment researchers spotted them.
Worse, Paul says some of the reposted ads were identical to ones Meta had already removed for policy violations. If the system could flag one copy, the fact that duplicates kept running raises serious questions about whether the removal process triggers any broader block.
Most ads came from Meta accounts with few or no followers. Where paying advertisers were identified, they traced back to Chinese companies. One ad, showing a girl reclining, listed the advertiser as a Chinese firm called Meet Social, formerly one of Meta's authorised ad resellers in China, where Meta's own platforms are blocked. Meet Social did not respond to requests for comment.
Several ads directed users to an app called MaskAI, available on Apple's App Store. The app showed nothing explicit on its store listing, but once opened it contained AI-generated pornography and a face-swap feature that let users drop any uploaded photo into sexual imagery. Apple removed MaskAI after WIRED contacted the company.
What does this mean for ordinary people?
If you or your children use Facebook, Instagram, Messenger or Threads, paid ads in your feed go through the same automated system that approved these. Meta's ad library showed the ads reaching real accounts in France, Germany, Ireland, Italy, the Netherlands, Spain, Sweden and the United Kingdom. US reach figures are not disclosed in the library, so the total audience is unknown.
The TTP reported its findings directly to the National Center for Missing and Exploited Children's CyberTipline, the US body that processes reports of online child sexual abuse material. The NCMEC did not comment on the specific reports.
Meta's response acknowledged the failure in measured terms. "Sexual exploitation is horrific, and we work aggressively to keep it off our platform," a spokesperson said, noting that the company recently launched new AI detection technology for ads and removed over 36 million pieces of child exploitation content in the past year. The company also said many of the ads had minimal reach and some were disabled before WIRED's inquiry.
Paul's counter-point is blunt: Meta's ad library has no way for the public to report a violating ad once it has stopped running. You can see the evidence of the crime; you cannot flag it.
Common questions
Can I report a suspicious Meta ad myself?
You can report an ad while it is actively running on Facebook or Instagram by tapping the three dots on the ad and selecting "Report ad." Meta's public ad library, where you browse historical ads, currently has no built-in reporting tool for ads that are no longer live.
Were any charges filed?
No criminal charges or regulatory actions have been publicly announced as a result of these specific ads. The TTP reported the material to the NCMEC CyberTipline, which can refer cases to law enforcement, but the NCMEC has not commented on what steps it is taking.
Did Apple's removal of MaskAI stop the harm?
Removing the app from the App Store stops new downloads. Anyone who already installed MaskAI still has it on their device unless they delete it manually.



