Generative AI (GAI) and the Changing Nature of CSAM
In 2023, the National Center for Missing & Exploited Children (NCMEC) received roughly 36.2 million reports through its designated CyberTipline, which serves as the United States’ centralized reporting forum for the online exploitation of children.1 Roughly 4,700 of these reports were flagged as content created, solicited, or otherwise altered through the use of generative artificial intelligence, known as GAI.2 By 2025, NCMEC’s GAI reports surged to 400,000, with NCMEC identifying more than 182,000 actionable reports with a GAI nexus.3 The growing availability of GAI presents emerging challenges for legislators, regulators and enforcers that current laws addressing exploitative materials did not contemplate.
Case Studies in Modern Exploitation
X, formerly known as Twitter, employs its own GAI chatbot developed by xAI named Grok that allows users to interact via basic text chat and, importantly, through visual inputs directly within the social platform’s application. In an eleven-day span from December 2025 into January 2026, users prompted Grok to produce an estimated three million sexualized images, including approximately 23,000 depicting children that constituted child sexual abuse material (CSAM).4 In response, a bipartisan coalition of 35 attorneys general urged xAI to adopt immediate safeguards to prevent Grok from circulating both nonconsensual intimate images (NCII) and CSAM.5 The letter adds that it is X’s obligation, as an AI powerhouse, to “comply with the law and devote sufficient attention and resources to avoiding the kind of widespread harms and abuses we are seeing now.”6 The coalition prompts X to, inter alia, “eliminate such content that has already been produced,” “suspend users that have created these materials,” and “ensure that the safeguards [X] recently announced do not merely place NCII creation behind a paywall, but actually mitigate its production throughout X and the Grok platform.”7
A complaint filed in the Federal District Court of New Jersey in late 2025 brings claims against AI/Robotics Venture Strategy 3 Ltd., the developer of the “ClothOff” app and ten similar services, and its owners; the complaint alleges that the defendants engaged in a “criminal and tortious operation of a network of websites.”8 The complaint states that the defendants solicit users to “upload clothed images of other people . . . to ‘undress’ them and produce hyper-realistic nude images of children . . . without their knowledge or consent.”9 For a premium fee, plaintiff alleges that users can “select from a menu of pornographic poses and positions in which to depict the targeted individual, thereby forcing its victims to become unwilling participants in and subjects of child . . . pornography.”10
The complaint itself was filed by a 16-year-old Jane Doe, who alleges photos that she uploaded to Instagram of herself as a 14-year-old were used by classmates to generate deepfaked CSAM.11 Notably, the complaint alleges that the defendants intentionally make their services widely accessible to “everyone on the Internet without safeguards to prevent users from producing CSAM . . . making it a breeding ground for child pornography, sexual exploitation, and abuse.”12 The complaint states that the plaintiff has experienced lasting emotional harm because there is “no way to determine how far the images of her were distributed” and because her image “has been and will continue to be used to help train ClothOff’s AI system to better generate CSAM” of other children.13
The Paradigm Shift: Why GAI Destabilizes Existing Legal Frameworks
Collectively, these examples highlight a dilemma that was unfathomable upon the authorship of existing laws. Although the misuse of emerging technology is not a novel phenomenon, the rapid advancement of GAI technologies has introduced new forms of exploitation at a pace that existing legal frameworks were not designed to anticipate or address cohesively. GAI has not just made it easier to produce child sexual abuse material; it has restructured who can produce it, how quickly it can be distributed, and the source from which it originates.
The capacity to generate sexually exploitative imagery now rests in little more than text prompts and a few keystrokes. An offender can generate synthetic CSAM without access to a child or existing abuse material, yet the absence of the physical presence of a child in the image’s creation does not render the resulting harm victimless when a child’s innocuous photo is transformed. Modern GAI platforms are simple to navigate and do not require specialized technical knowledge, meaning that a single image of a child can be quickly turned into hyper-realistic sexually explicit imagery in the matter of seconds that is overwhelmingly indistinguishable from reality, even to the utmost trained eye.14 Additionally, evidentiary challenges, jurisdictional complexity, forensic limitations, and constitutional considerations may further complicate investigative and prosecutorial efforts. This technological shift has outpaced legal frameworks that were largely developed in an era when CSAM necessarily originated from documented abuse of an identifiable child. As such, legislatures and courts are becoming increasingly confronted with legal questions that existing statutory frameworks do not encapsulate.
Emerging Technological Challenges
With new technological means, new calculated methods emerge. NCMEC’s CyberTipline received a range of reports concerning sexually exploitative requests, ranging from text prompt inputs asking GAI to create CSAM, inputs for guidance on how to access CSAM or to facilitate real-world abuse, inputs seeking to juxtapose non-sexual images onto known CSAM to create new imagery, and inputs requesting the alteration of photos from children’s social media accounts to create nude images.15 The sources reporting to the CyberTipline range from AI companies reporting user attempts to upload known CSAM to users entering egregious textual prompts in effort to receive CSAM-related output, and to social media platforms reporting the distribution of GAI CSAM imagery.16 In 2024 alone, for example, Google reported over “600 instances of apparent CSAM to NCMEC using hash-matching, which were uploaded as a user prompt to our generative AI products.”17
The Mechanics of Hash-Matching
Hash-matching is a highly technical identification process that, in essence, creates a digital signature of content distributed online. A hash acts as a one-way mathematical function that implements a unique numerical identifier for images, audio files, videos, passwords, computer malware and other forms of digital content.18 Notably, the use of hash-matching has been a longstanding tool within cybersecurity realms and has become increasingly valuable in CSAM detection online through the use of Microsoft’s PhotoDNA algorithm.7 Generally, if an image is “known” within the algorithmic database, meaning that the identifiable numerical value exists within it through prior documentation, then there is a “match” from which law enforcement can take action.7
Prior to the proliferation of GAI CSAM, such exploitative media was created with physical cameras, meaning that predators almost exclusively shared identical copies of files that law enforcement had already cataloged through forensic analysis, providing a very low rate for false positives upon notification of a match. Yet, traditional hash identification for images, known as cryptographic hashing, is pixel-specific, meaning if one pixel of the original image is altered or removed, the resulting hash is not a match within the algorithm being employed.19
Consequently, perceptual hashing emerged. Microsoft’s PhotoDNA employs perceptual hashing which can identify CSAM in a way that is tolerant of minor edits, such as resizing or using minute visual modification like filters.6 Perceptual hashing, thus, begins to address the gap left by cryptographic hashing if even one pixel of an image is altered, though instances of false positives are slightly more prevalent. Perceptual hashing was designed to find copies (or slight variations) of known CSAM, but perpetrators are beginning to use AI to create entirely new images which may go undetected and unrecorded in the current hashing algorithms, creating an entirely new cyberscape of deeply harmful content.
The Decentralization Challenge: Local LLMs and the REPORT Act
The Revising Existing Procedures on Reporting via Technology Act, or REPORT Act, enacted in 2024, expanded and clarified online service providers’ obligations to report suspected online child sexual exploitation. These obligations extend to AI companies. The act broadened the covered offenses, extended data-retention requirements, clarified liability protections for companies, vendors, and victims, and amended provisions governing reports to NCMEC’s CyberTipline under 18 U.S.C. § 2258A.20 OpenAI, which owns and operates ChatGPT, reported a sharp rise in CyberTipline submissions in 2025, sending roughly 80 times more tips during one comparable period than it had during the same period the prior year.21
Although mainstream, closed-source LLMs (large language models) have drawn significant scrutiny, open-source and “unrestricted” local models may present a quieter regulatory challenge because they are often less visible to platforms, regulators, and law enforcement. Local open-source LLMs are, in essence, the “brains” of an artificial intelligence system downloaded directly (locally) to a user’s device that do not rely on cloud-based centralized services like ChatGPT, Anthropic’s Claude, or Google’s Gemini. These local, nearly entirely customizable models are attractive to users for their enhanced data privacy standards, offline capabilities, and their ability to produce uncensored and unrestricted responses.
Crucially, the decentralization of local LLMs creates a gap in detecting GAI-created CSAM; the REPORT Act and the CyberTipline both depend on platforms detecting and reporting content hosted on their own servers. Because generation occurs on the user’s own device, local models create an insulated private-data environment that is largely invisible to the public internet. A Reuters report notes that although some open-source models include safety parameters, cybersecurity researchers at SentinelOne and Censys identified “hundreds of instances where guardrails were explicitly removed.”22 This decentralization evades potential reporters and the CyberTipline, making identification of those violating the law using local models a difficult challenge.
Proliferation through the Dark Web
The use of the dark web further complicates efforts to track and limit the spread of GAI CSAM.23 The dark web refers to internet sites that users cannot access without the use of specialized networks, like Tor (short for The Onion Router). With these networks, users’ web traffic is diverted through other users’ computers by establishing relays through which the information passes.24 Throughout this entire process, the user’s actual IP address remains hidden. This multi-layered routing prevents law enforcement from easily identifying where the physical servers hosting the material reside. In the context of GAI CSAM, this anonymity can provide a low-risk environment for sharing harmful content, as well as for distributing the unaligned, open-source AI models and training data sets used to generate them.
The severe challenges that anonymity poses to law enforcement and investigators are underscored by Operation Grayskull, a major joint investigation by the Department of Justice and the FBI that culminated in 2025.25 The operation successfully dismantled four dark web networks dedicated to the distribution of CSAM. While Operation Grayskull targeted traditional CSAM, the highly coordinated infrastructure uncovered in the investigation represents the precise blueprint that may facilitate the circulation of GAI CSAM. Beyond CSAM itself, the anonymous environment of dark web networks may also facilitate further generation by enabling offenders to exchange the specialized prompt formulas, open-source models, and large data training sets that GAI relies on.
Federal Law Confronts a New Category of CSAM
The Safe Harbor Dilemma: Adversarial Testing and its Current Limitations
A potentially intelligible solution is to train GAI models to overtly refuse CSAM-related outputs, which appears feasible.26 But AI model training requires either developer input from the backend or user input from the frontend. Simultaneously, federal law strictly prohibits the knowing production, distribution, or possession of CSAM regardless of intent and without any carve-outs for research and testing purposes.27 This potential good-faith research is known as red teaming, in which a group or individual acts as an adversarial actor intending to exploit a system’s vulnerabilities for further research and strengthening purposes.28 Although red teaming is well established in cybersecurity and increasingly central to GAI safety testing, its application to GAI CSAM remains legally uncertain as federal law provides no comparable research protections. Thus, building safer GAI systems comes at the cost of an individual’s potential criminal liability; yet, if red teaming is not implemented, the potential for GAI platform misuse surrounding CSAM increases exponentially.29 Balancing the legitimate concerns about any generation – even in a good-faith testing environment – and the potential mediation of the harms which may occur from unchecked GAI models poses difficult policy and technological questions.
Further, President Biden issued Executive Order (EO) 14110 in October 2023, which in pertinent part, highlighted the necessity for red teaming and “testing and safeguards against . . . producing child sexual abuse material . . . for generative AI.”30 President Trump subsequently repealed EO 14110, replacing it with Executive Order 14365 which emphasizes the administration’s goals to place the United States at the forefront of AI innovation and advancement, while intending to “ensure that children are protected.”31 There is no explicit mention of ethical adversarial testing as it refers to GAI CSAM in Executive Order 14365.
In recent years, the Department of Justice reformed its charging policy for the Computer Fraud and Abuse Act, providing ethical hackers with a safe harbor for furthering good-faithed cybersecurity research through red teaming efforts while avoiding harm to the public.32 Though this revision is binding only at the federal level, it provides a useful framework for distinguishing malicious conduct from good-faith security research. A similarly tailored safe harbor for GAI CSAM research may enable responsible adversarial testing to improve model safeguards while further informing future legislative reform and statutory interpretation as courts and legislatures continue to confront the novel complexities posed by GAI.
Bipartisan Legislative Proposals
The push for expert-driven legislative reform emerged in a bipartisan coalition of 54 state and territory attorneys general who issued a joint letter to Congress in 2023, urgently declaring that GAI had constructed “a new frontier of abuse” that was rapidly outpacing existing digital forensics.33 Congress answered in 2024 with the introduction of H.R. 8005, the Child Exploitation and Artificial Intelligence Expert Commission Act of 2024. Sponsored by Representative Nick Langworthy (R-NY), the bill sought to formalize a collaborative framework requested by the states by establishing an expert federal commission. This commission would have been mandated to investigate how AI is weaponized to commit CSAM offenses, evaluate the efficacy of current criminal statutes, and further develop a legal framework to assist law enforcement in the investigative and prosecutorial processes.34 The desire for this committee was reinforced in June 2024 when a subsequent letter signed by 44 attorneys general explicitly endorsed H.R. 8005.35 Though the bill did not become law, these developments from 2023 to 2024 reflect a growing prosecutorial consensus that synthetic CSAM has outpaced traditional digital forensics and existing legal frameworks, requiring a more coordinated federal response.
Beyond these proposed exploratory commissions, binding federal legislation is slowly taking shape. The TAKE IT DOWN Act (TIDA), signed into effect in May 2025, makes it a federal crime to “knowingly share or threaten to share non-consensual intimate imagery (NCII), including AI-generated images that depict real people.”36 Further, TIDA requires the removal of such imagery within 48 hours following a victim’s verified request as well as making any and all reasonable requests to remove such NCII duplications or subsequent reposts on its platform.37
TIDA’s Borders: The “Real Person” Nexus and Emerging Case Law
The most prominent legislative question left after TIDA’s enactment is the “real person” nexus requirement – the exact element that purely synthetic CSAM lacks. TIDA’s crucial protections for NCII victims were simply not designed to address the vectors for creation of fully synthetic CSAM that GAI has allowed. Fully synthetic CSAM, that with no existing identifiable child behind it,38 falls under the federal obscenity statute, 18 U.S.C. § 1466A, which explicitly notes that “it is not a required element of any offense under this section that the minor depicted actually exist.”39 GAI CSAM with an identifiable child depicted is prosecutable under the two child pornography statutes.27
The distinction traces back to a premise underlying years of Supreme Court doctrine: child sexual abuse material is unprotected speech because of the real children harmed in its production – a premise that cannot be extended if no real child exists.40 The Court confirmed this in 2002 through its decision in Ashcroft v. Free Speech Coalition, striking down a federal ban on imagery merely “appearing to be” children where no actual child was used in production.41
This distinction carried constitutional weight with one federal district court that already faced the issue head-on in United States v. Anderegg.42 There, prosecutors charged a Wisconsin man with producing, distributing, and possessing obscene GAI images of children after allegedly using a text-to-image AI model to create thousands of sexually explicit images depicting fictional children, with several of the images then being distributed to an actual minor via Instagram.43 Meta then reported the direct message correspondence to the CyberTipline.44 Anderegg moved to dismiss the production and possession counts under Stanley v. Georgia, which protects the private possession of obscene adult material in one’s home.45
The government urged the court to extend the rationale set forth in Osborne v. Ohio, arguing that the same interests justifying CSAM regulation, including the prevention of grooming, normalization, and the broader exploitation platform, applied to GAI imagery depicting children.46 The court held that Osborne’s rationale depends on a real child being harmed in production and that Ashcroft had already rejected each of the government’s arguments nearly two decades earlier.47 The court dismissed the possession charge as unconstitutional as applied, but further declined to extend that protection to production, and it left the distribution and transfer charges intact.48 As such, the result is narrow – producing and sharing fully synthetic CSAM remains a federal crime, and undistributed possession within the home may not be.
A second court confronted the same question just months after Anderegg, applying that court’s reasoning yet reaching a different result from different facts. In United States v. Yener, decided in January 2026, the defendant, who was facing separate terrorism-related charges, moved to dismiss a § 1466A possession count for GAI images under Anderegg.49 Subsequently, the court followed the Anderegg reasoning and rejected the same jurisdictional argument the government raised and lost previously.50 However, the facts cut slightly differently in that the defendant’s phone which contained the GAI CSAM were found on his person at a diner and in a separate storage unit, rather than in his home.51 As such, the court held that the Stanley protection turns particularly on the privacy of the home, not private possession generally, further declining to treat a cell phone outside of the home as the constitutional equivalent of one’s residence.7 Together, these two decisions suggest the narrow limits of Ashcroft as applied to fully synthetic CSAM thus far.
Pending Reforms (ENFORCE and Protecting Our Children in an AI World Acts)
Congress is endeavoring to further minimize the gaps. The bipartisan ENFORCE Act sets to amend the obscenity statute to import the same enhanced consequences already attached to the child pornography statutes.52 The bill, if passed, would add Section 1466A to the statute of limitations exemption, sex offender registration requirements, pretrial detention presumption, and mandatory supervised release provisions that already govern under Sections 2252 and 2252A. This would increase the consequences for obscenity to match those for child pornography. The bill separately amends Section 2252A’s production offense to broaden and clarify its interstate commerce jurisdictional hook.53 The bill passed in the Senate by an overwhelming margin in December 2025 and has drawn support from NCMEC, RAINN, the National District Attorneys Association, and the National Children’s Alliance.54 As of August 2026, it still awaits action in the House.
A second bill, the Protecting Our Children in an AI World Act of 2025, approaches the same underlying issue from a different angle than the ENFORCE Act. Introduced by Representative Bilirakis (R-FL) and referred to the House Judiciary Committee in February 2025, the bill strikes an affirmative defense currently available under the federal child pornography statute that no actual minors was used in its production.55 Furthermore, it eliminates the conforming language that had already carved that defense out for prosecutions involving certain computer-generated or digitally modified images defined under 18 U.S.C. § 2256.56 The practical effect eliminates the defense entirely, including for GAI material. Further, the bill seeks to broaden the statutory definition of “sexually explicit conduct” to include obscene depictions regardless of whether the figure is clothed or unclothed.7 Finally, a severability clause provides that if any portion of the Act is deemed unconstitutional, the rest remains intact.7 The bill remains in the committee with no further action to date as of July 2026.
State Responses to an Evolving Legal Landscape
States have moved to close the gap on their own in the absence of solidified federal guidance. As of July 2026, at least thirty states have amended their child pornography statutes to expressly reach GAI content.57 Effective dates for these statutes vary considerably. Missouri and Wyoming were among the earliest states to criminalize computer-generated child pornography, doing so in 2006 and 2007, respectively; Wyoming’s 2021 amendment extended that prohibition to cover such depictions regardless of whether an actual child was involved in production.7
Most states that have enacted GAI CSAM legislation combine two elements: an appearance-based threshold and a production- or method-based hook describing how the image was made. States differ in describing the appearance threshold, which may indicate differences in how closely the generated image comes to depicting actual minors. Alabama and Arkansas, for instance, require that the depiction be “virtually indistinguishable” from an actual minor while also specifying it was “created, altered, or produced by digital, computer generated, or other means.”58 California uses a looser appearance standard, criminalizing “digitally altered or artificial-intelligence-generated data depicting what appears to be a person under 18 years of age.”59 These laws reflect a legislative judgment that GAI CSAM warrants criminal treatment regardless of the technological means used to produce it.
North Carolina’s approach tracks the appearance-based model closely: its statute reaches “digital or computer-generated visual depictions or representations” created, adapted, or modified through technological means — including algorithms and GAI — but only where a reasonable person would believe the image depicts an identifiable individual. That standard is substantively similar to Alabama’s “virtually indistinguishable” threshold, which is defined as being an image that a “reasonable person would conclude is of an actual individual under 18 years of age,”60 reinforcing that the appearance and method-based elements described above tend to travel together rather than mark a clean divide between states.61 Texas has gone further by not only expanding its existing CSAM statute but also creating an entirely separate felony offense for using an image of a child with the intent to train GAI to produce CSAM, making it the first state currently to expressly regulate the AI training-data pipeline rather than focusing solely on generative outputs.62 Wyoming likewise criminalizes the development of GAI systems designed specifically for the purpose of producing CSAM, expressly regulating the technological means rather than merely the generative outputs or use.63 Consequently, the diversity of these varying legislative approaches underscores the novelty and deep complexity of GAI CSAM. Given that most of these legislative efforts are recent, judicial guidance remains sparse, but the rapid pace of legislative activity provides prosecutors and courts with increasingly robust statutory frameworks from which more solidified guidance is likely to emerge.
Conclusion
Generative artificial intelligence has unearthed a fundamental tension within the existing legal framework governing CSAM. Statutory and constitutional doctrine developed against the backdrop of abuse depicting identifiable children, yet GAI permits the creation of sexually explicit depictions that may be indistinguishable from reality without the involvement of a child outside of the four corners of a phone or computer screen. As such, federal courts have begun confronting constitutional questions that existing precedent has never faced, Congress has introduced narrowly targeted legislation to address critical gaps, and state legislatures have adopted a wide range of approaches to address GAI CSAM harm. A uniform legal framework has yet to emerge, yet the contours of such are beginning to take shape through the combined efforts of legislatures and federal courts. As GAI continues in its rapid evolution, so too must the legal doctrines governing its misuse.
Endnotes
- Nat’l Ctr. for Missing & Exploited Child., 2023 CyberTipline Report, 3 (2023), https://www.missingkids.org/content/dam/missingkids/pdfs/2023-CyberTipline-Report.pdf. [↩]
- Id. at 5. [↩]
- Nat’l Ctr. for Missing & Exploited Child., 2025 CyberTipline Report, 14 (2025), https://www.missingkids.org/content/dam/missingkids/pdfs/2025-cybertipline-report.pdf. [↩]
- Ctr. for Countering Digital Hate, Grok Floods X with Sexualized Images of Women and Children (Jan. 22, 2026), https://counterhate.com/research/grok-floods-x-with-sexualized-images/. [↩]
- Letter from William Tong, Att’y Gen. of Conn., et al., to xAI (Jan. 23, 2026), https://portal.ct.gov/-/media/ag/press_releases/2026/letter-to-xai_final.pdf. [↩]
- Id. at 4. [↩][↩]
- Id. [↩][↩][↩][↩][↩][↩][↩]
- Compl. ¶ 1, Doe v. AI/Robotics Venture Strategy 3 Ltd., No. 2:25-cv-16671 (D.N.J. Oct. 16, 2025). [↩]
- Id. ¶ 2. [↩]
- Id.. [↩]
- Id. ¶¶ 10, 39-40. [↩]
- Id. ¶ 4. [↩]
- Id. ¶ 11. [↩]
- See generally, Hany Farid, The World’s Leading Deepfake Expert No Longer Trusts His Own Eyes, N.Y. Times (June 14, 2026), https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html. [↩]
- Addressing Real Harm Done by Deepfakes: Hearing Before the Subcomm. on Cybersecurity, Info. Tech., & Gov’t Innovation of the H. Comm. on Oversight & Accountability, 118th Cong. 3–4 (2024) (statement of John Shehan, Senior Vice President, Exploited Children Division & International Engagement, National Center for Missing & Exploited Children). [↩]
- Shelby Grossman, Riana Pfefferkorn & Sunny Liu, AI-Generated Child Sexual Abuse Material: Insights from Educators, Platforms, Law Enforcement, Legislators, and Victims, 35–36 (Version 1, Stanford Digit. Repository 2025), https://purl.stanford.edu/mn692xc5736. [↩]
- Google, AI Responsibility: Child Sexual Abuse and Exploitation 15 (2024), https://www.gstatic.com/marketing-cms/6d/ac/f8c844a24c1e80f521429f4f4be3/ai-responsibility-and-csae-en.pdf. [↩]
- Dan Sexton, Separating Fact from Fiction on the Technology Used to Detect Child Sexual Abuse (June 22, 2026), https://www.iwf.org.uk/news-media/blogs/separating-fact-from-fiction-on-the-technology-used-to-detect-child-sexual-abuse/. [↩]
- Ofcom, Overview of Perceptual Hashing Technology, 16 (2022), https://www.ofcom.org.uk/siteassets/resources/documents/research-and-data/online-research/other/perceptual-hashing-technology.pdf. [↩]
- REPORT Act, Pub. L. No. 118-59, 138 STAT. 1014 (2024). [↩]
- Maddy Varner, OpenAI’s Child Exploitation Reports Increased Sharply This Year, WIRED (Dec. 22, 2025) https://www.wired.com/story/openai-child-safety-reports-ncmec/. [↩]
- A.J. Vicens, Open-Source AI Models Vulnerable to Criminal Misuse, Researchers Warn, Reuters (Jan. 29, 2026), https://www.reuters.com/technology/open-source-ai-models-vulnerable-criminal-misuse-researchers-warn-2026-01-29/. [↩]
- RAINN, How Does CSAM Get Distributed?, RAINN (May 31, 2026), https://rainn.org/get-the-facts-about-csam-child-sexual-abuse-material/how-does-csam-get-distributed/ (describing the ways CSAM is distributed online, generally, which includes dark web facilitation). [↩]
- Kristin Finklea, Cong. Rsch. Serv., IF12172, The Dark Web: An Overview, 1 (2024). [↩]
- U.S. Department of Justice, Operation Grayskull Culminates in Lengthy Sentences for Managers of Dark Web Site Dedicated to Sexual Abuse of Children (July 23, 2025), https://www.justice.gov/opa/pr/operation-grayskull-culminates-lengthy-sentences-managers-dark-web-site-dedicated-sexual. [↩]
- OpenAI, Protecting Children in the Age of Generative AI, 9-10 (2026), https://cdn.openai.com/pdf/9886ee82-5a5e-4f0a-acaa-a47b01b0a68e/Child-Protection-Blueprint.pdf. [↩]
- 18 U.S.C. §§ 2252, 2252A. [↩][↩]
- Kim Martineau, What is Red Teaming for Generative AI? (Apr. 11, 2024), https://research.ibm.com/blog/what-is-red-teaming-gen-AI. [↩]
- Grossman et al., AI-Generated Child Sexual Abuse Material, supra note 17, at 2. [↩]
- Executive Order 14110 of October 30, 2023, 3 C.F.R. 657 (2024) § 10.1(b)(viii)(A). [↩]
- Executive Order 14365 of December 11, 2025. 90 C.F.R. 58499 (2025) § 1. [↩]
- U.S. Dep’t of Justice, Justice Manual § 9-48.000(B)(3)(8) (2022). [↩]
- Letter from Dave Yost, Att’y Gen. of Ohio, et al., to Patty Murray, President Pro Tempore, U.S. Senate, et al., re: Artificial Intelligence and the Exploitation of Children (Sept. 5, 2023), https://www.naag.org/wp-content/uploads/2023/09/54-State-AGs-Urge-Study-of-AI-and-Harmful-Impacts-on-Children.pdf. [↩]
- H.R. 8005, 118th Cong., 2d Sess. § 2(b)(1)-(3) (2024). [↩]
- Letter from Lynn Fitch, Miss. Att’y Gen., et al., to Nick Langworthy, U.S. Rep. (June 10, 2024) https://www.naag.org/wp-content/uploads/2024/06/AI-CSAM_Letter-to-Congressman-Langworthy-_-FNL.pdf. [↩]
- RAINN, Take It Down Act, https://rainn.org/federal-legislation/take-it-down-act/; See also, David Leibert, Congress’s Attempt to Criminalize Nonconsensual Intimate Imagery: The Benefits and Potential Shortcomings of the Take It Down Act, Nat’l Ass’n of Att’ys Gen., https://www.naag.org/attorney-general-journal/congresss-attempt-to-criminalize-nonconsensual-intimate-imagery-the-benefits-and-potential-shortcomings-of-the-take-it-down-act/. [↩]
- RAINN, Take It Down Act. [↩]
- Given that GAI is trained on existing images, whether a generated image could identifiably depict an “existing” child is an open question. [↩]
- 18 U.S.C. §1466A. [↩]
- New York v. Ferber, 458 U.S. 747 (1982) (holding that child pornography depicting actual minors is unprotected speech given the state’s compelling interest in preventing the sexual exploitation of children); Osborne v. Ohio, 495 U.S. 103 (1990) (extending Ferber to uphold criminalization of mere possession on the theory that reducing demand also reduces production). [↩]
- Ashcroft v. Free Speech Coal., 535 U.S. 234 (2002) (striking down a federal ban on computer-generated CSAM that did not involve any actual minor in its production, holding such virtual imagery protected speech absent a real-child nexus). [↩]
- U.S. Dep’t of Justice, Press Release, Man Arrested for Producing, Distributing, and Possessing AI-Generated Images of Minors Engaged in Sexual Activity (May 21, 2024), https://www.justice.gov/archives/opa/pr/man-arrested-producing-distributing-and-possessing-ai-generated-images-minors-engaged. [↩]
- United States v. Anderegg, No. 24-CR-50-JDP, 2025 WL 3126093 at *1 (W.D. Wis. Feb. 13, 2025). [↩]
- Id. at *5. [↩]
- Id. at *7; see Stanley v. Georgia, 394 U.S. 557, 568 (1969). [↩]
- Anderegg, WL 3126093 at *8; see Osborne v. Ohio 495 U.S. 103, 111 (1990). [↩]
- Anderegg, WL 3126093 at *9. [↩]
- Id. at *10. [↩]
- United States v. Yener, No. 24-CR-20523-BLOOM/Elfenbein, 2026 WL 177600 (S.D. Fla. Jan. 21, 2026). [↩]
- Id. at *2-3. [↩]
- Id. at *3. [↩]
- H.R. 4831, 119th Cong., 1st Sess. (2025) (ENFORCE Act). [↩]
- Id. at 2. [↩]
- Street Grace, Senate Unanimously Passes Federal Bill to Prosecute AI-Generated Child Sexual Abuse Materials (CSAM), https://www.streetgrace.org/news/senate-unanimously-passes-federal-bill-to-prosecute-ai-generated-child-sexual-abuse-materials-csam. [↩]
- See 18 U.S.C. § 2252A(c)(2). [↩]
- H.R. 1283, 119th Cong., 1st Sess. (2025) (Protecting Our Children in an AI World Act of 2025). [↩]
- Orrick, Herrington & Sutcliffe LLP, U.S. AI Law Tracker, AI Law Ctr., https://ai-law-center.orrick.com/us-ai-law-tracker-see-all-states/. [↩]
- Ala. Code § 13A-12-190; Ark. Code Ann. § 5-27-302. [↩]
- Cal. Penal Code §§ 311.1(a). [↩]
- Ala. Code § 13A-12-190(15). [↩]
- N.C. Gen. Stat. § 14-202.7(a)(3). [↩]
- Tex. Penal Code Ann. § 43.235(b)(2). [↩]
- Wyo. Stat. Ann. §§ 6-4-303, 6-4-308. [↩]
Author
-
2026 Summer Law ClerkOlivia D’Andrea was a 2026 Summer Law Clerk at the National Association of Attorneys General. Olivia is currently a second-year law student at the Catholic University of America Columbus School of Law.

