If a child is the target of an AI deepfake: a first-response plan
Beginner9 min readParenting & Education

If a child is the target of an AI deepfake: a first-response plan

A first-response plan for harmful synthetic images involving a child: protect the child, avoid copying suspected sexual material, preserve non-content details, and use official platform and national reporting routes.

What you should be able to do

If material appears to sexualize a child, do not forward it or download a new copy to investigate. Use the platform and official child-exploitation reporting route for your jurisdiction, preserve non-content details where safe, and obtain qualified local advice.

Saved only in this browser.
In this article

If content appears to sexualize a child, do not forward it, repeatedly view it, or download a new copy to investigate. Whether synthetic content meets a criminal definition, what evidence should be retained, and who must report vary by jurisdiction and facts. Use the platform’s dedicated safety report and the official child-exploitation reporting route for your location, and follow their instructions. None of this is legal advice or a substitute for a safeguarding professional or law-enforcement direction.

Finding out that a child has been targeted by an AI-generated image or video calls for a prompt, calm response through the appropriate platform and safeguarding channels. Saving copies, forwarding links, or confronting a suspected creator can increase spread, risk or evidence problems. This is a first-response orientation, not a jurisdiction-specific evidence protocol or full recovery plan.

Step 1: preserve evidence the right way — without downloading illegal content

If the deepfake is sexual in nature, do not save, screenshot, download, or forward the actual image or video yourself. Prefer reporting paths that work from a URL or platform report without requiring you to hold a local copy.

NCMEC’s Take It Down creates a hash on the device for eligible nude, partially nude or sexually explicit images or videos taken of the person while they were under 18; the file itself is not uploaded. NCMEC says submissions should be made on the device where the material was originally taken and explicitly says not to download or ask someone to send material in order to use the service. A wholly synthetic deepfake may therefore fall outside this stated eligibility. Check the current FAQ and use the official national reporting route when eligibility is uncertain.

  • If apparently eligible original material is already on the device where it was taken: read and follow NCMEC’s current instructions on that device without copying it elsewhere. If it is synthetic, altered, on another device or otherwise uncertain, use the official reporting route for direction instead of forcing the file into the hash workflow.
  • If you saw suspected sexual material on a feed, message or public page: do not download, save, screenshot, forward or email it. Keep the page open only if safe to do so, copy the URL and submit that URL once through the national hotline. INHOPE says you do not need to decide whether it is illegal; trained hotline analysts do that assessment (INHOPE reporting instructions).

Take It Down works only with participating public or unencrypted services and eligible material. It does not guarantee removal everywhere. CyberTipline in the United States or the applicable national hotline is the route for threats, uncertainty and reports outside the hash service’s scope.

If the deepfake is non-sexual, such as a bullying face-swap, fabricated quote or fake video, record the URL, platform, account, date/time and a text description. A screenshot may be appropriate for a platform or school report if it is clearly non-sexual and local guidance permits it. If classification is uncertain, do not create another copy; ask the official reporting route what to preserve.

Step 2: reduce spread through the platform, not through your own network

Report the content directly through the platform’s dedicated abuse or safety tool and use the closest accurate category. Do not promise how quickly or through which internal team a platform will handle the report. Resist the instinct to warn a wide circle of contacts by sharing a link or description “so people know to watch for it”; that can increase exposure and spread.

NCMEC says generative-AI exploitative imagery involving a child should be reported and taken seriously. Do not spend time trying to determine whether an image is sufficiently convincing or whether it was wholly synthetic before seeking help. Report the apparent harm and location accurately; let the platform, hotline or authority make the classification (NCMEC: generative AI).

Step 3: involve the child — supportively, not as an interrogation

If the child is old enough to be aware of the situation, involve them in what happens next in an age-appropriate way rather than managing it entirely around them. Lead with reassurance before questions: they did nothing wrong, this is not their fault, and you are handling it together. Ask what they already know and who else has seen it, gently and without pressing for detail beyond what the official report or immediate support requires. Do not blame or interrogate the child.

Do not have the child view the material again to “confirm” it or describe it in detail unless a professional handling the report specifically needs that from them. Repeated exposure to the content, even to help you assess it, adds harm without adding much useful information beyond what the platform report and evidence hash already capture.

Step 4: notify the right platform, school, or authority

Match the notification to what happened. In Estonia, use Vihjeliin to report suspected online child sexual abuse material; it assesses reports and passes material it considers illegal through police or INHOPE channels. Use the free, round-the-clock Child Helpline 116111 for any concern about a child or online harm. If anyone’s life or health is in danger or immediate help may be needed, call 112.

  • Content that appears to sexualize a child: submit the URL once through Vihjeliin in Estonia, NCMEC’s CyberTipline in the United States, the Internet Watch Foundation where its route applies, or the national hotline found through INHOPE. Do not attach or email files. Contact law enforcement or a qualified safeguarding professional when the official route, immediate danger, threats or local rules direct you to do so.
  • Someone is threatening or extorting the child over the material: do not pay or negotiate. Preserve non-content identifiers and messages only as official guidance for your jurisdiction allows; do not expose the child to the material again to collect evidence. Report the threat to the platform, the relevant national reporting body, and emergency or law-enforcement services if there is immediate danger or the official route instructs you to do so.
  • Non-sexual harmful deepfakes involving classmates or school context: use the school’s safeguarding or harassment route in addition to the platform, while obtaining legal advice before making a defamation allegation.
  • Content that also involves another child (as creator, target, or both): report through the platform and the school’s designated safeguarding lead or the official authority. Do not contact another child or family directly when that could increase spread, retaliation, evidence loss or risk; follow the safeguarding professional’s direction.

The EU Digital Services Act requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures for a high level of minors’ privacy, safety and security. Article 16 separately requires a notice-and-action mechanism for information alleged to be illegal. These duties do not guarantee a particular result or replace the national hotline and immediate safeguarding route.

A woman reaches for a telephone beside a folder and a blank page.
Prepare to contact a person who can help with the response. AI-generated illustration.

Do not rely on detection tools to settle the question

There is no public detector that can definitively establish synthetic origin in every case. Do not delay a safety report while trying to prove how the content was made. Legal classification and platform handling vary, but the reporter’s first task is describing the apparent harm and location accurately, not conducting a forensic analysis. Detection tools can produce false positives and false negatives and should not determine whether you seek help.

After the immediate response

Once the immediate reports are made, keep checking the child’s safety and wellbeing and offer an accountable human support route appropriate to the incident and the child’s needs. Child Helpline 116111 or the applicable local safeguarding service can help identify the next route. AI is not therapy is relevant here in a specific way: do not leave the child to process the event primarily with an AI chatbot.

If the incident involves classmates, a school account or circulation in a school setting, use the school’s designated safeguarding or harassment route when doing so is safe and appropriate. Keep that report separate from the platform and national-hotline reports; one does not replace the others.

Try it today, before you need it

Before an incident, bookmark your national reporting body and child-support route. In Estonia, that means Vihjeliin, Child Helpline 116111 and emergency number 112. Take It Down is a separate option only when its current eligibility rules fit; do not treat it as the default for a synthetic deepfake.

The child deepfake first-response checklist puts the four steps above into an immediate-action format you can follow directly in the moment, with the reporting links already listed.

Read next

Continue through the same learning path with the next practical articles.