If content appears to sexualize a child, do not forward it, repeatedly view it, or download a new copy to investigate. Whether synthetic content meets a criminal definition, what evidence should be retained, and who must report vary by jurisdiction and facts. Use the platform’s dedicated safety report and the official child-exploitation reporting route for your location, and follow their instructions. None of this is legal advice or a substitute for a safeguarding professional or law-enforcement direction.
Finding out that a child has been targeted by an AI-generated image or video calls for a prompt, calm response through the appropriate platform and safeguarding channels. Saving copies, forwarding links, or confronting a suspected creator can increase spread, risk or evidence problems. This is a first-response orientation, not a jurisdiction-specific evidence protocol or full recovery plan.
Step 1: preserve evidence the right way — without downloading illegal content
If the deepfake is sexual in nature, do not save, screenshot, download, or forward the actual image or video yourself. Prefer reporting paths that work from a URL or platform report without requiring you to hold a local copy.
NCMEC’s Take It Down creates a hash of eligible nude, partially nude or sexually explicit material already on the eligible person’s device; the file is not uploaded. Eligibility and platform coverage are defined by NCMEC and may not cover every synthetic deepfake. Read the current FAQ or use CyberTipline/national guidance rather than assuming this article can classify the file. Never download or share imagery in order to use the service.
- If an apparently eligible file is already on the child’s device: follow NCMEC’s current instructions on that same device without copying it elsewhere. If eligibility is unclear or the image is wholly synthetic, use CyberTipline or the applicable national hotline for direction.
- If you only saw it on someone else’s feed, a group chat you do not control, or a public page: do not download it just to hash it. Record the URL, platform, username, date/time, and a text description; report that URL to the platform’s abuse tool and to NCMEC’s CyberTipline (US) or your national equivalent. Let the platform and investigators retrieve the material.
Take It Down works only with participating public or unencrypted services and eligible material. Having a local file alone does not establish eligibility. CyberTipline or the applicable national hotline is the route for uncertainty and for reports outside the hash service’s scope.
If the deepfake is not sexual — a bullying face-swap, a fabricated quote, a fake video making it look like the child said or did something they didn’t — evidence preservation is more straightforward: record the URL, the platform, the date and time, and a text description, and take a screenshot only of non-sexual material if you need it for a report. Do not screenshot or save sexual content under any circumstance, even for this kind of documentation purpose.
Step 2: reduce spread through the platform, not through your own network
Report the content directly to the platform it appeared on, using its dedicated abuse or safety reporting tool rather than a general contact form — most major platforms have a specific reporting category for non-consensual or sexualized imagery of minors, which routes to a faster, specialized review path. Resist the instinct to warn a wide circle of contacts by sharing a link or description “so people know to watch for it” — this increases the number of people who have seen or can find the content, which is the opposite of the goal, and it removes a decision that belongs to the child and your family about who is told and when.
The Internet Watch Foundation’s 2026 research on AI-generated child sexual abuse material found this content is often deliberately made to look imperfect, like amateur photography, specifically so it is harder to identify as synthetic — meaning you should not spend time trying to determine whether an image is “real enough” to be worth reporting, or hold off reporting while you try to verify authenticity yourself (IWF, “Harm Without Limits,” 2026). Treat any sexualized image or video that appears to depict your child as reportable regardless of how convincing or crude it looks.
Step 3: involve the child — supportively, not as an interrogation
If the child is old enough to be aware of the situation, involve them directly in what happens next rather than managing it entirely around them. Lead with reassurance before any questions: they did nothing wrong, this is not their fault, and you are handling it together. Ask what they already know and who else has seen it, gently and without pressing for details beyond what’s needed to act. A child who feels blamed or interrogated in this moment is less likely to disclose the next problem early, which is the opposite of what you need going forward — the same principle behind the help-seeking clause in the family AI agreement.
Do not have the child view the material again to “confirm” it or describe it in detail unless a professional handling the report specifically needs that from them. Repeated exposure to the content, even to help you assess it, adds harm without adding much useful information beyond what the platform report and evidence hash already capture.
Step 4: notify the right platform, school, or authority
Match the notification to what happened:
- Content that appears to sexualize a child: use NCMEC’s CyberTipline in the United States, the UK’s Internet Watch Foundation where applicable, or an official national hotline found through INHOPE. Contact local law enforcement or a qualified safeguarding professional when the reporting body, immediate danger, threats, or local rules direct you to do so. If a file is already on the child’s device, Take It Down may create a hash without uploading the image; follow NCMEC’s instructions and never download a copy just to use the service.
- Someone is threatening or extorting the child over the material: do not pay or negotiate. Preserve non-content identifiers and messages only as official guidance for your jurisdiction allows; do not expose the child to the material again to collect evidence. Report the threat to the platform, the relevant national reporting body, and emergency or law-enforcement services if there is immediate danger or the official route instructs you to do so.
- Non-sexual harmful deepfakes involving classmates or school context: use the school’s safeguarding or harassment route in addition to the platform, while obtaining legal advice before making a defamation allegation.
- Content that also involves another child (as creator, target, or both): report through the platform and the school’s designated safeguarding lead or the official authority. Do not contact another child or family directly when that could increase spread, retaliation, evidence loss or risk; follow the safeguarding professional’s direction.
The EU Digital Services Act requires platforms accessible to minors to take appropriate and proportionate measures for minors’ privacy, safety, and security (Article 28). Separate notice-and-action obligations for illegal content sit under Article 16. If a platform’s report tool is unresponsive or clearly inadequate, escalate through that platform’s compliance channels or a relevant regulator — do not abandon the report — but treat regulator escalation as a follow-on step after you have already used CyberTipline / national CSAM reporting and the platform abuse tool.
Do not rely on detection tools to settle the question
There is no public detector that can definitively establish synthetic origin in every case. Do not delay a safety report while trying to prove how the content was made. Legal classification and platform handling vary, but the reporter’s first task is describing the apparent harm and location accurately, not conducting a forensic analysis. Detection tools can produce false positives and false negatives and should not determine whether you seek help.
After the immediate response
Once evidence is preserved, the platform is notified, and the right authority is involved, the ongoing work shifts toward the child’s wellbeing — this is a moment where a school counselor or mental health professional is a reasonable, proactive step, not only a response to visible distress. AI is not therapy is relevant here in a specific way: do not let the child process this event primarily through conversations with an AI chatbot, however available and non-judgmental the replies may sound in the moment. This needs a person, ideally one with actual training in supporting a child through this specific kind of harm.
If the deepfake originated from within a peer group — a classmate, a friend, someone in the child’s own social circle — the situation also needs the school involved as a matter of course, separate from any legal reporting, because it will likely resurface in the child’s daily environment regardless of what happens with the platform report.
Try it today, before you need it
The single most useful thing to do before any of this happens is know where the reporting tools are in advance: bookmark Take It Down and your national reporting body’s page now, not during a crisis when you are least able to search calmly. Talk through the broad shape of this response plan with any child old enough to understand it, framed the same way you’d explain a fire escape route — not because you expect to need it, but because knowing the steps in advance changes how calmly they can be followed if you ever do.
The child deepfake first-response checklist puts the four steps above into an immediate-action format you can follow directly in the moment, with the reporting links already listed.



