Wednesday, 19 August 2026 Fearless, independent journalism

The Indie Leaks

Sophie Editorial
The Grooming Files

When the Abuser Is a Piece of Software

When the Abuser Is a Piece of Software

For as long as child sexual abuse material has existed, it has needed something the law could point to: a real child, harmed in a real moment, captured and shared. That single fact has anchored almost every safeguarding response for decades. It no longer holds.

In 2025, the Internet Watch Foundation identified 3,443 AI generated child sexual abuse videos. The year before, it found thirteen. That is a 26,385% increase in a single year. Sixty five per cent of those videos were classified as Category A, the most extreme classification the IWF uses. This is not a fringe technical curiosity. This is an industrial scale abuse economy that did not exist three years ago.

The Tools

A fine tuning technique called Low Rank Adaptation, or LoRA, allows someone with minimal technical skill and little money to customise generative AI models. Using as few as twenty photographs of a real child, someone can produce a realistic deepfake of that specific child in as little as fifteen minutes. Twenty photographs is a school photo, a sports day picture, a handful of social media posts. It is what most parents have already, unknowingly, made public.

This is not theoretical. By November 2025, IWF reports of AI generated CSAM had more than doubled year over year, rising from 199 to 426. Girls accounted for 94% of the victims, and reported cases included children ranging from newborns to two year olds. In the government’s own figures, cases involving infants aged 0 to 2 rose from five to ninety two in a single year.

In April 2025, a researcher found an exposed cloud storage bucket belonging to a South Korean nudify app containing over 93,000 AI generated images alongside the prompts used to create them. An entire production line, sitting exposed on the open internet, generating this material at a scale that has nothing to do with individual predatory acts and everything to do with automated infrastructure.

The School That Got a Ransom Demand

Late last year, cybercriminals contacted an unnamed UK secondary school demanding payment to keep AI generated abuse images offline. Blackmailers had scraped ordinary school photographs, fed them through deepfake tools, and manufactured CSAM from children’s own class and sports day pictures. The IWF classified 150 of the resulting images as CSAM under UK law and does not believe this was an isolated incident.

Safeguarding minister Jess Phillips called it a deeply worrying emerging threat. Safeguarding experts are now telling schools to reconsider two decades of standard practice: photos from trips, prize days, sports fixtures, all captioned with a name and a year group, uploaded without a second thought. That entire archive is now raw material.

This is the same pattern this publication keeps returning to. Nobody needed to target a specific eight year old when these systems were built. Once the capability existed, any child with a publicly available photograph became a potential target. Harm stops requiring intent at the point of creation. It only requires access, and access is now nearly frictionless.

Children Doing It to Each Other

The uncomfortable extension of this story, the one that mirrors what we’ve written about pornography sharing among peers, is that adults are not the only ones using these tools. Schools are facing a growing problem of students creating and spreading AI generated CSAM among their own classmates. A twelve year old does not need technical skill or malicious sophistication to cause devastating harm to a classmate now. They need an app, a photo already public, and about fifteen minutes.

A UNICEF, ECPAT and INTERPOL study across eleven countries found that at least 1.2 million children disclosed having had their images manipulated into sexually explicit deepfakes in the past year, in some countries representing as many as one in twenty five children, roughly one child in a typical classroom.

The Legal Loophole That Protects Real Offenders

There is a second order harm here that gets far less attention. Offenders are exploiting what’s known as the liars’ dividend: claiming that genuine evidence of contact abuse was actually AI generated and therefore does not depict a real child. The existence of convincing synthetic abuse material does not just create new victims. It gives cover to people who abused real ones, muddying evidence that used to be unambiguous.

What This Tells Us

In February 2025, the UK became the first country to introduce a specific criminal offence for making, adapting, possessing, or supplying a CSA image generator, and has since proposed powers allowing designated authorities to test AI models before deployment to ensure they cannot be misused this way. That is a genuinely significant step. It is also, by definition, reactive. The law is responding to a capability that already exists and is already industrial in scale.

This is the same environment we’ve described before, just moved one stage further along the chain. Exposure. Sharing. Desensitisation. Escalation. Now: fabrication. A predator no longer needs access to a child at all to produce material of that child being abused. The photograph a proud parent posted, the class photo a school uploaded in good faith, the video a teenager shared with friends, all of it is now raw input for a system that turns ordinary images into abuse material without anyone in the chain intending that outcome.

Safeguarding has spent years learning to look for grooming, for access, for opportunity. None of those concepts fully apply here.

The offender doesn’t need to get near the child anymore. They simply need the child to have existed online at all.

Do you think the law can realistically keep pace with this, or are we already permanently behind?

If you value investigations like this, follow The Grooming Files for more court verified, safeguarding led journalism.

© Sophie Lewis. All rights reserved.

More from The Grooming Files