_An update to the September 2024 post on AI-generated harm against children. The last of five 2026 updates to the children-focused posts in the privacy series._
When I wrote the AI-deepfake post in September 2024, the situation was that the technical capability was new enough to be alarming, the legal framework was unclear, and the school-level operational response was patchy. Two years later, the technical capability has matured into a commodity, the legal framework has tightened, schools have policies, and the practical experience of managing the incident when it happens is — sadly — more developed. This update covers what is genuinely different in 2026.
What is now legally clear
Three changes of consequence.
Creation of intimate deepfakes of any person became a criminal offence in England and Wales under provisions of the Crime and Policing Bill that came into force in 2025. Possession of AI-generated child sexual abuse material has been a criminal offence for longer; the new provision criminalises the creation with intent to cause alarm or distress, regardless of whether the image is then distributed. This is a meaningful tightening from 2024. Several prosecutions have resulted.
Police and CPS have published practical guidance for handling AI-generated image cases. CEOP has refreshed its guidance and is actively running prevention campaigns aimed at adolescent boys, who are over-represented as creators of school-friend deepfake material. The CPS guidance on revenge pornography offences now explicitly covers AI-generated material.
Schools have safeguarding policies that cover AI image abuse. What in 2024 was a pattern many schools had encountered but few had policies for is, in 2026, named explicitly in most schools' safeguarding policies, with the route to disclosure, the route to police involvement, and the route to platform takedown all written down. The quality of these policies varies; their existence is now near-universal.
The scale of AI-generated harm
The Internet Watch Foundation publishes regular reports on AI-generated child sexual abuse material. The volume has grown sharply since 2024. The IWF's analysts now spend a meaningful proportion of their working time on AI-generated material; the most recent reports document the emergence of full deepfake CSAM marketplaces on the dark web, with subscription models and on-demand generation services. The technical pipeline is mature. The defensive pipeline is catching up.
This is sobering. It does not mean every child is at heightened risk. It means the industrial version of the harm exists in a way it did not in 2024. The protections that work — limiting public exposure of children's faces, the conversations with children about reporting, the platform takedown routes — remain the right protections. They are simply more important than they were.
What is genuinely working
Three things that have made real progress.
Apple and Google's on-device nudity detection. Both platforms now ship — and default-enable for accounts owned by under-18s — on-device detection of nude images in messages. When such an image is detected, the platform warns the child before they send or open it, provides links to support resources, and does not surface the image to the parent unless the child reports it. The protection is real, the parent is not surveilling, and the child has a moment to reconsider. This is the closest thing to an unalloyed win in this space.
The Take It Down and Report Remove services. NCMEC Take It Down and Childline Report Remove are now mature, well-tested, and supported by the major platforms. A child or parent who reports an image through either service can usually expect rapid takedown across the main platforms. The system is not perfect; the friction is much lower than it was.
Family code-words against voice clone scams. The grandparent-on-the-phone voice clone scam has matured. The defence — a short family code-word agreed in advance — is now widely-enough known to be standard advice from banks and police. Take Five to Stop Fraud covers the framing. If you have not set one, do it this month.
AI safeguarding tools in schools have improved. The keyword-monitoring platforms of 2023 have been augmented with image-detection systems that flag AI-generated explicit content among files on school devices. This is not a panacea; it is meaningful infrastructure.
What is harder than in 2024
Three things have got harder.
The volume of AI-generated material. As above, the IWF reports are sobering. The defenders' systems are working harder.
The school-friend deepfake pattern at scale. The pattern of teenage boy creates AI-generated intimate image of a female classmate that I described in 2024 has, in 2026, become disturbingly common — common enough that most large UK secondaries have handled at least one case. The harm to depicted children is severe and the prosecutorial response is increasing. The conversations adolescent boys need to be having about this — that creating these images is a crime, that distribution is a crime, that the image of the depicted classmate will haunt her — are conversations a meaningful fraction are not having until after the fact.
AI companions for children. Covered in last month's gaming post. Character.ai's documented harms, the lawsuits, the regulatory inquiries. The category is a real concern, especially for vulnerable adolescents.
The conversation, updated
The three-part conversation from 2024 still works. The thresholds have shifted.
The image-of-you part. People can now make images of you doing things you have not done. If you see one or a friend sees one, come to us. You will not be in trouble. We will deal with it. Same conversation. Worth having again.
The voice-of-someone-you-know part. If you get a call from someone in the family asking for something unusual, even if the voice sounds right, the rule is the family code-word. Set the code-word. Use it normally so it is not weird when it matters.
The friend-of-yours part. If a friend of yours is the target of an AI image, the action is to support them and stop the spread. Not share, not save for evidence. Tell a parent, a teacher, or the platform. Take It Down works.
A fourth conversation, new since 2024.
The you-might-be-tempted-to-make-one-of-these part. The conversation specifically with adolescent boys, before they get to the point of trying. Creating intimate images of someone using AI is now a crime, regardless of distribution. It will be prosecuted. The girl will remember it for the rest of her life. The technology makes it easy. Do not do it. This is the conversation parents most flinch from; it is the conversation most worth having in 2026.
What this month looks like
Four pieces of work, none of which takes more than half an hour.
One: confirm on-device nudity detection is enabled on every device used by every child in the household.
Two: set the family code-word if not already set. Have grandparents practice using it.
Three: the conversation. All four parts. With each child where appropriate.
Four: know the reporting routes — Take It Down, Childline Report Remove, CEOP, IWF. Have the URLs bookmarked before you need them.
A note to end on
I closed the 2024 post by saying parents who have had this conversation in advance handle the actual incident, when it arrives, dramatically better than parents who have not. Two years on, that is still the most important thing I have to say. The case for the conversation has only grown stronger.
This is the last of the five children-focused update posts. The original eighteen-post privacy series will continue to be updated when the world shifts enough to warrant it. The children posts will likely be revisited again in a couple of years, because this is the corner of the field that moves fastest.
For now: see you in the school newsletter, the safeguarding panel, the family kitchen. The conversations remain the work.