If a Child Is the Target of an AI Deepfake: A First-Response Plan
Beginner9 min readParenting & Education

If a Child Is the Target of an AI Deepfake: A First-Response Plan

What to do in the first hours if a child has been targeted by an AI-generated image or video: preserve evidence the right way, reduce spread, involve the child, and notify the platform, school, or authorities — without ever downloading or forwarding illegal content.

What you should be able to do

If the material is sexual imagery of a minor, it is illegal content regardless of who made it or how realistic it looks — do not save it, view it repeatedly, or forward it to anyone, including to 'prove' it exists. Use the reporting paths built for exactly this, and get a person with legal authority involved immediately.

AI Expert TeamPublished: Jul 30, 2026
Saved only in this browser.
In this article

If the content in question is a sexual or nude image or video of a minor, generated by AI or not, it is illegal content in most jurisdictions and treated as child sexual abuse material regardless of how it was produced. Do not download, screenshot, save, or forward it — including to a friend, a spouse, or “to show the school” — beyond what is strictly required by the official reporting tools described below. Viewing or sharing it further, even with protective intent, can itself carry legal risk and adds to the harm. Report through the channels in this article and let the relevant platform or authority handle the material directly. This article is practical first-response guidance, not legal advice; reporting routes and criminal definitions depend on your jurisdiction and the specific harm.

Finding out that a child has been the target of an AI-generated image or video — sexual or not — is one of the more frightening moments a parent can face, and the instinct to act immediately is correct. The specific actions matter, though, because some natural first reactions (saving copies, forwarding it to warn others, confronting the person who made it directly) can make the situation worse, destroy evidence in a form investigators need, or put the child through the material again unnecessarily. This is a first-response sequence, not a full recovery plan — the goal is doing the right things in the first hours, calmly, before deciding what happens next.

Step 1: preserve evidence the right way — without downloading illegal content

If the deepfake is sexual in nature, do not save, screenshot, download, or forward the actual image or video yourself. Prefer reporting paths that work from a URL or platform report without requiring you to hold a local copy.

NCMEC’s Take It Down creates a digital fingerprint (a hash) of an image already on your device — the image itself is not uploaded — and shares only that fingerprint with participating platforms. NCMEC’s own instructions say not to download or share imagery in order to submit to Take It Down. So:

  • If the file is already on a device you control (for example the child received it directly): use Take It Down from that device without copying it elsewhere.
  • If you only saw it on someone else’s feed, a group chat you do not control, or a public page: do not download it just to hash it. Record the URL, platform, username, date/time, and a text description; report that URL to the platform’s abuse tool and to NCMEC’s CyberTipline (US) or your national equivalent. Let the platform and investigators retrieve the material.

Take It Down currently works with a defined set of participating platforms; it will not reach every site, but it is the correct hash-based option when you already have a local file. CyberTipline reporting is the correct path when you do not.

If the deepfake is not sexual — a bullying face-swap, a fabricated quote, a fake video making it look like the child said or did something they didn’t — evidence preservation is more straightforward: record the URL, the platform, the date and time, and a text description, and take a screenshot only of non-sexual material if you need it for a report. Do not screenshot or save sexual content under any circumstance, even for this kind of documentation purpose.

Step 2: reduce spread through the platform, not through your own network

Report the content directly to the platform it appeared on, using its dedicated abuse or safety reporting tool rather than a general contact form — most major platforms have a specific reporting category for non-consensual or sexualized imagery of minors, which routes to a faster, specialized review path. Resist the instinct to warn a wide circle of contacts by sharing a link or description “so people know to watch for it” — this increases the number of people who have seen or can find the content, which is the opposite of the goal, and it removes a decision that belongs to the child and your family about who is told and when.

The Internet Watch Foundation’s 2026 research on AI-generated child sexual abuse material found this content is often deliberately made to look imperfect, like amateur photography, specifically so it is harder to identify as synthetic — meaning you should not spend time trying to determine whether an image is “real enough” to be worth reporting, or hold off reporting while you try to verify authenticity yourself (IWF, “Harm Without Limits,” 2026). Treat any sexualized image or video that appears to depict your child as reportable regardless of how convincing or crude it looks.

Step 3: involve the child — supportively, not as an interrogation

If the child is old enough to be aware of the situation, involve them directly in what happens next rather than managing it entirely around them. Lead with reassurance before any questions: they did nothing wrong, this is not their fault, and you are handling it together. Ask what they already know and who else has seen it, gently and without pressing for details beyond what’s needed to act. A child who feels blamed or interrogated in this moment is less likely to disclose the next problem early, which is the opposite of what you need going forward — the same principle behind the help-seeking clause in the family AI agreement.

Do not have the child view the material again to “confirm” it or describe it in detail unless a professional handling the report specifically needs that from them. Repeated exposure to the content, even to help you assess it, adds harm without adding much useful information beyond what the platform report and evidence hash already capture.

Step 4: notify the right platform, school, or authority

Match the notification to what happened:

  • Sexual imagery of a minor, anywhere: report to NCMEC’s CyberTipline (US) or your national equivalent — the UK’s Internet Watch Foundation accepts reports of child sexual abuse imagery hosted anywhere — and to local law enforcement. This is not optional or “only if it escalates”; sexual content depicting a minor is a matter for authorities by default. If you already have a local file, also submit a hash via Take It Down — that is a separate hash-sharing step, not a substitute for a CyberTipline report.
  • Someone is threatening or extorting the child over the material (sextortion): do not pay, do not delete the child’s account or the threatening messages, preserve the offender’s profile URL and the conversation as text/URL evidence, and report the threat specifically to the CyberTipline / national equivalent and to local law enforcement in addition to the platform. Threats change the priority from content removal alone to immediate protective response.
  • Non-sexual but harmful or defamatory deepfakes involving classmates or school context: notify the school directly, in addition to the platform. Many schools now have specific policies for AI-generated harassment content precisely because it has become common enough to require one.
  • Content that also involves another child (as creator, target, or both): treat this as needing both a platform report and a conversation with the other child’s parents or the school, handled by an adult, not peer-to-peer.

The EU Digital Services Act requires platforms accessible to minors to take appropriate and proportionate measures for minors’ privacy, safety, and security (Article 28). Separate notice-and-action obligations for illegal content sit under Article 16. If a platform’s report tool is unresponsive or clearly inadequate, escalate through that platform’s compliance channels or a relevant regulator — do not abandon the report — but treat regulator escalation as a follow-on step after you have already used CyberTipline / national CSAM reporting and the platform abuse tool.

Do not rely on detection tools to settle the question

There is no reliable, publicly available tool that definitively tells you whether a given image or video was AI-generated, and spending time trying to “prove” synthetic origin before reporting is a wasted step in most cases — the legal and platform response to sexualized imagery of a minor does not depend on establishing how it was made. AI-detection tools for images, like AI-detection tools for text, produce both false positives and false negatives and should not be the basis for deciding whether to act. Report first; let the platform, investigators, or forensic specialists make the technical determination if one is ever needed.

After the immediate response

Once evidence is preserved, the platform is notified, and the right authority is involved, the ongoing work shifts toward the child’s wellbeing — this is a moment where a school counselor or mental health professional is a reasonable, proactive step, not only a response to visible distress. AI is not therapy is relevant here in a specific way: do not let the child process this event primarily through conversations with an AI chatbot, however available and non-judgmental it might feel in the moment. This needs a person, ideally one with actual training in supporting a child through this specific kind of harm.

If the deepfake originated from within a peer group — a classmate, a friend, someone in the child’s own social circle — the situation also needs the school involved as a matter of course, separate from any legal reporting, because it will likely resurface in the child’s daily environment regardless of what happens with the platform report.

Try it today, before you need it

The single most useful thing to do before any of this happens is know where the reporting tools are in advance: bookmark Take It Down and your national reporting body’s page now, not during a crisis when you are least able to search calmly. Talk through the broad shape of this response plan with any child old enough to understand it, framed the same way you’d explain a fire escape route — not because you expect to need it, but because knowing the steps in advance changes how calmly they can be followed if you ever do.

The child deepfake first-response checklist puts the four steps above into an immediate-action format you can follow directly in the moment, with the reporting links already listed.

Read next

Continue through the same learning path with the next practical articles.