AI Deepfakes: How Your Child's Photos Can Be Misused
Your Child's Photo. 20 Images. 15 Minutes.
“The thought of people taking photos of my kids and using AI software to create content off of them. The thought of either of them growing up and going to college only to find that she has an AI-built fictional record of being in that world.”
That was a comment left on my Substack recently. A dad with a specific fear, not a vague worry about the internet being dangerous.
He wasn’t being paranoid. AI deepfake technology can now take as few as 20 ordinary photos of a child, the kind sat in every parent’s camera roll, and use them to generate illegal images in around 15 minutes on a normal home computer. The Internet Watch Foundation (IWF), the UK charity that finds and removes this material, confirms this is already happening at scale.1 What scares me more is the number of parents regularly posting photos of their children on social media profiles open to anyone who follows them.
I’m going to explain exactly how, what UK law now says, and what you can actually do about it.
How AI Deepfakes Are Made From a Child’s Photo
There’s a technique called LoRA, short for Low-Rank Adaptation. It lets someone take an existing AI image generator and fine-tune it using a small set of photos of one specific person. The result is a personalised model that can generate new images of that child in any scenario the user chooses.
The barrier to doing this is lower than most people believe. As few as 20 images, on a bog-standard home computer, in around 15 minutes. Those 20 images don’t need to be explicit and they don’t need to come from anywhere unusual. Birthday photos, sports day, school trip, family holiday snaps posted publicly, or even just to a wide friends list, by a parent who had no reason to think there was any risk.
That’s all it takes.
How Much AI-Generated Child Sexual Abuse Material Is There in the UK?
In 2025, the IWF assessed 8,029 AI-generated images and videos as showing realistic child sexual abuse, a 14% rise on the year before.2 I’m going to stop there for a second, not to shock, but because it’s easy to read a figure and not register what it means. Each one depicts a child. Each one is criminal, 8,029 images.
Video is where the growth is sharpest. AI-generated child sexual abuse videos rose from 13 in 2024 to 3,443 in 2025, a 26,385% increase. 65% of that video content is classified as Category A under UK law, the most severe classification and believe me when I say they do not get any worse. The IWF also reports that 94% of illegal AI-generated content targets girls,3 and that material depicting infants aged 0 to 2 rose sharply year on year.4
I’m not including these figures to shock or frighten you. I’m including them because the scale of what’s happening bears no resemblance to the public conversation about it. Most parents I speak to have never heard the term AI CSAM. Most assume their child is safe because they’re not on adult sites, or screen time is monitored, or age restrictions are in place. None of those things are protection against this.
Where Do Offenders Get the Photos?
The IWF has confirmed offenders are actively using images of real, known children found online. Not from dark corners of the internet I have written about before. From the same places every parent posts family photographs, Instagram, Facebook, school WhatsApp groups, a class photo on the school’s own website or even a profile the parent thought was visible only to friends.
The content those images get used to create is not private and once it exists, it doesn’t go away. That dad on my Substack put it best. A fictional record, a file that says his daughter did something she never did.
Is AI-Generated Child Sexual Abuse Material Illegal in the UK?
Yes and it has been for longer than most parents assume. The Protection of Children Act 1978 already covers pseudo-photographs, which is the legal term for exactly this kind of AI-generated image, so creating, possessing or distributing it has always carried the same weight as real content.5
What’s changed is that the law has finally caught up with the tools themselves. The Crime and Policing Act 2026 received Royal Assent on 29 April 2026, until then, the AI tool used to make this material could sit in a legal grey area even when the output was obviously illegal. Now it’s a specific offence to make, adapt, possess or supply an AI model built to generate child sexual abuse material, and it carries up to five years in prison.6 AI-generated CSAM also counts as priority illegal content under the Online Safety Act, so platforms are legally obliged to be actively stopping it, not just removing it when someone complains.
Whether that gets properly enforced is a different question, and one I’ll come back to. But for the first time, the legislation actually matches the technology.
⚡Please don’t forget to react & restack if you appreciate my work. More engagement means more people might see it. ⚡
Why Aren’t Tech Platforms Doing More to Stop AI Deepfakes?
Researchers at the Oxford Internet Institute investigated two of the largest AI model repositories in 2025, and what they found should worry you more than it probably will. Almost 35,000 publicly downloadable deepfake models, downloaded close to 15 million times since November 2022.7 That particular study is about non-consensual deepfakes broadly, not children specifically, ranging from global celebrities down to Instagram accounts with under 10,000 followers. But the pattern it exposes is the same one running through everything above.
Most of those models carried tags that made their intended use obvious. Most broke the hosting platform’s own terms of service. Somehow, they managed to stay up anyway. I’ve spent enough years in DFIR to know the difference between a company that can’t catch something and a company that hasn’t been made to look hard enough. The detection tools exist. In a lot of cases now, so does the legal duty to use them. What’s missing isn’t capability. It’s whether anyone’s enforcing it.
How Can Parents Protect Their Child’s Photos From AI Misuse?
None of what follows is a guarantee, and none of it makes your child completely safe from a threat that’s partly being enabled at platform level. That responsibility sits with platforms and regulators, not with parents navigating a risk they were never warned about. That said, there are things that are worth you knowing about and doing because you cannot rely on the platforms to protect your children.
Review what’s publicly visible. A public Instagram account, an open Facebook profile, a school website that publishes class photos- all of these are potential sources. Check what’s actually visible to anyone, not just your friends list.
Understand the difference between private and public. Photos on a private account are still stored on that platform’s servers. Private means fewer people can see them, not that they can’t be found or misused. Still meaningfully better than public, but not a complete solution.
Talk to older children about their own accounts. Teenagers are posting photos of themselves, their friends, their siblings. They’re unlikely to have thought about this specific risk. A calm, factual conversation goes a long way.
Report to the IWF. If you or your child finds AI-generated content of any child online, report it at iwf.org.uk. They’re the UK body responsible for finding and removing this material, and they act quickly.
Knowledge is the protection here. The fact you are still here reading this means that you care and that really matters. Remember the first parental control is something you already possess, open & honest communication with your child and the knowledge that you are a safe space for them.
As always, thank you for your support. Please share this across your social media, and if you do have any comments, questions, or concerns, then feel free to reach out to me via the Social page, as I am always happy to spend some time helping to protect children online.
Remember that becoming a paid subscriber means supporting a charity very close to my heart and helping it do amazing things for people. Childline, I will donate 100% of paid subscriptions collected every six months, as I don’t do any of this for financial gain. Or to make a one-off donation, go to my Just Giving page.
If you or a child you know needs support:
Childline: 0800 1111 | childline.org.uk
Available 24/7, 365 days a year. Free, confidential, and here for every child.
Internet Watch Foundation, “AI CSAM Report 2026: Harm Without Limits,” iwf.org.uk, accessed 1 August 2026. IWF states LoRA models can be created from as few as 20 images in around 15 minutes.
Internet Watch Foundation, “Harm without limits: AI child sexual abuse material through the eyes of our Analysts,” published 24 March 2026, iwf.org.uk, accessed 1 August 2026. Covers full-year 2025 data.
Internet Watch Foundation news release, 12 November 2025, iwf.org.uk, accessed 1 August 2026. The 94% girls figure covers January-October 2025 reporting, a different data window to the March 2026 full-year report.
Figures for AI-generated content depicting infants aged 0-2 vary slightly by IWF release (reported as both 92 and 96 in different 2025/2026 publications). Worth citing as “a sharp rise from 5 the year before” rather than a single precise figure until IWF’s own site confirms one.
Protection of Children Act 1978 (pseudo-photographs) and Online Safety Act 2023 (priority illegal content), legislation.gov.uk, accessed 1 August 2026.
Crime and Policing Act 2026, received Royal Assent 29 April 2026, bills.parliament.uk / gov.uk factsheet, accessed 1 August 2026. Five-year maximum sentence applies to the AI CSAM-generator offence (clause 36).
Hawkins et al., “Deepfakes on Demand: the rise of accessible non-consensual deepfake image generators,” Oxford Internet Institute / FAccT 2025, oii.ox.ac.uk, accessed 1 August 2026. This study covers non-consensual deepfakes generally, not a child-specific dataset.






