For decades, law enforcement agencies relied on one basic assumption while investigating child sexual abuse material: that an image or video could be evidence of something that had happened to a child somewhere. However, with generative artificial intelligence, things have become extremely complicated.
An abusive-looking image can now emerge from very different situations. It may be existing material involving a known victim that has been altered using AI. It may use an ordinary photograph of a real child which has been fabricated into something that never happened. It may depict a completely synthetic child who does not even exist in the real world. Or it may be a fabricated image used to threaten, humiliate or blackmail an identifiable child.
When investigating CSEAM cases, these are not the same problems for law enforcement agencies. In one case, the victim is already known, in another, the child exists but the act shown in the image never happened, and in the third, investigators first have to establish whether there is a real child to find at all. The applicable law differs in each case.
This issue involving images of children generated using artificial intelligence (AI) has become a serious problem for all law enforcement agencies involved in such cases. According to the National Centre for Missing and Exploited Children, or NCMEC, of the US, its CyberTipline received over 4,00,000 reports in 2025 alone which involved child exploitation with a generative-AI nexus.
Over 1,82,000 reports involved possession, generation or attempted generation of generative-AI CSEAM. Since NCMEC began tracking the issue in 2023, over 1,58,000 images and videos have been categorised as generative-AI CSEAM and more than 275 victims have been identified.
While similar figures for India are not currently available, the question therefore is not whether AI can be misused in this way in the country. It is what Indian law already covers, where interpretation is still required, and whether police, forensic laboratories and technology platforms can establish what actually happened behind the image.
AI-generated abuse material is not one category
AI-generated abuse material is not merely a single category and has a number of factors that distinguish one type of material from another. The first category of such content involves the abuse of a real child and is subsequently altered using AI. According to NCMEC, known CSEAM victims are being re-victimised when offenders manipulate existing abusive imagery to create new material.
The second category covers cases where an ordinary photograph of a real child is transformed into sexual imagery using AI. The act shown may never have happened, but the child being targeted is real. Such images or videos can then be circulated among peers or used for humiliation, harassment, coercion or sextortion.
According to NCMEC, it is tracking cases in which people, including classmates and peers, use so-called “nudify” applications to create and circulate fabricated images. It has also documented generative AI being used as part of child sextortion rackets.
The third category covers cases where everything is synthetic. A model can generate a photorealistic person who appears to be a child even though investigators cannot immediately establish that anybody resembling the person shown actually exists. The first question then changes from “Who is this victim?” to “Does this child exist?”
The fourth category concerns how the fabricated material is used. A synthetic image may become a tool for threatening a child, grooming, impersonation, blackmail or coercion into producing real material. Here, the image may be only one part of a broader offence.
All these categories fall under different sections of the applicable laws, as there is no one standalone offence called “AI-generated CSEAM”. Different provisions become relevant according to what was created, whether a real child was involved and what was subsequently done with the material.
Indian law anticipated computer-generated imagery before the generative-AI boom
One of the most important aspects of Indian law predates the current AI wave. The Protection of Children from Sexual Offences Act, or POCSO, was amended in 2019 to insert Section 2(1)(da). Its statutory definition covers a visual depiction of sexually explicit conduct involving a child and expressly includes a “digital or computer-generated image indistinguishable from an actual child”. It also includes an image that has been created, adapted or modified but appears to depict a child.
Interestingly, the language entered Indian law years before consumer generative-AI image tools became widespread. It would therefore be inaccurate to say POCSO deals only with photographs or videos recording actual physical abuse and contains nothing relevant to synthetic imagery. Parliament had already brought computer-generated and modified depictions into the statutory definition.
But defining the law alone is not enough. The next question is which offence applies to a particular set of facts.
A broad definition does not make every AI case identical
Section 13 of POCSO deals with using a child in any form of media for sexual gratification. It covers representation of the sexual organs of a child, real or simulated sexual acts and indecent or obscene representation. Its explanation says “use a child” includes involvement through electronic, computer or other technology in preparation, production, transmission, publication, facilitation and distribution. Section 14 provides punishment for such use.
Section 15 separately deals with storage or possession of such material involving a child. Its different sub-sections distinguish between circumstances such as failure to delete or report material with an intention to share it, possession for transmission or display, and storage for commercial purposes.
Understanding how the sections have been written is essential to understanding how they create an important distinction for AI cases. If an identifiable child’s photograph has been manipulated, the connection with a real child is clear. If known CSEAM has been altered, a real victim and underlying abuse already exist.
A fully synthetic image is different. Section 2(1)(da) expressly recognises a computer-generated image indistinguishable from an actual child, but provisions such as Sections 13 and 15 also use phrases including “uses a child” and material “involving a child”.
That does not mean completely synthetic imagery is automatically outside POCSO. But unless courts directly interpret these provisions in such a case, it would also be premature to describe every possible application as settled.
The legal question is therefore narrower: how should the broad definition covering computer-generated images be read with offence provisions framed around the involvement or use of “a child”?
POCSO specifically recognises fabricated depictions used to threaten children
Section 11 of POCSO defines sexual harassment of a child. Clause (v) covers threatening to use, through electronic, film, digital or other means, a “real or fabricated depiction” of any part of the child’s body or the child’s involvement in a sexual act. Whether sexual intent exists is treated as a question of fact.
This is directly relevant to an AI-era situation in which an ordinary image of a child is manipulated, and the resulting fabricated image is used to threaten the child with circulation.
The act depicted does not have to be real for the threat itself to be real. The statute expressly recognises a fabricated depiction. That makes Section 11(v) particularly relevant to AI-assisted sextortion, bullying and coercion using fake imagery.
Section 67B of the IT Act goes beyond uploading existing material
Another important layer of legal ammunition against such content is provided by the IT Act. Section 67B covers publication or transmission of electronic material depicting children in sexually explicit conduct, but its wording is broader. Clause (b) refers to a person who “creates text or digital images”, collects, seeks, browses, downloads, advertises, promotes, exchanges or distributes electronic material depicting children in an obscene, indecent or sexually explicit manner.
The words “creates text or digital images” make the provision particularly relevant to generative AI. It is not framed only around receiving an existing file and uploading it elsewhere.
However, the wholly synthetic scenario again raises an interpretive question. Section 67B speaks of images depicting “children”, and its explanation defines children as persons who have not completed 18 years of age.
If the depicted person was generated entirely by software and never existed, a court may eventually have to decide how this wording applies. The issue is therefore not whether Section 67B addresses digital creation, as it plainly does. The question is how its reference to children will apply where the apparent child is completely synthetic.
The Supreme Court changed how India talks about such material
On 23rd September 2024, the Supreme Court delivered its judgment in Just Rights for Children Alliance and another vs S Harish and others. The court examined the scope of Section 15 of POCSO and rejected a narrow understanding of possession and storage of child sexual abuse material.
It also recommended replacing the expression “child pornography” with “child sexual exploitative and abuse material”, or CSEAM, saying the latter better reflects the exploitation and abuse involved.
When it comes to generative AI, it adds another layer to the term. In one case, the image may derive directly from the recorded abuse of a real child. In another, the depicted act never happened but a real child has been targeted. In a wholly synthetic case, investigators may not find a child corresponding to the person depicted at all.
The label attached to the file cannot answer these questions. The facts behind its creation have to do that.
How amendments in rules brought AI-generation services into the regulatory framework
India changed its intermediary rules in February 2026 to specifically address synthetically generated information. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 were notified on 10th February, with the relevant provisions coming into force on 20th February 2026.
The rules define “synthetically generated information”, or SGI, broadly to cover specified audio, visual or audio-visual information artificially or algorithmically generated or materially altered using a computer resource so that it appears real or authentic.
More importantly for child safety, services enabling the creation or modification of synthetic information must deploy reasonable and appropriate technical measures to prevent their computer resources from being used for unlawful SGI. The prohibited category expressly includes “child sexual exploitative and abuse material”.
This means regulation no longer begins only when an unlawful image is uploaded to a social-media platform. It also reaches services capable of generating the material.
The changes came after AI chatbot Grok was used extensively to remove clothes from images of women and children. Grok, which was under minimal restrictions at that time, published the results in public view on social media platform X. Initially, Elon Musk, founder of Grok and owner of X, hinted that Grok would not be censored, but later a major update restricted the AI chatbot from generating such images.
While X and Grok stopped fulfilling such requests, there are a lot of apps available that do the job, no questions asked. Such apps are still a major issue for law enforcement agencies.
An AI label does not make unlawful material permissible
The same amendments introduced labelling and provenance requirements for permissible synthetic information. Significant social-media intermediaries also have obligations relating to user declarations and technical verification of whether certain uploaded content is synthetic.
But these requirements should not be confused with permission to publish unlawful material. An AI-generated image does not become lawful CSEAM merely because it carries an AI label or provenance marker. The rules separately identify CSEAM as unlawful synthetic information against which generation services must deploy preventive measures.
The distinction is straightforward: permissible synthetic media may require labelling. Unlawful synthetic material remains unlawful.
Regulation now begins before the image is created
The February 2026 rules effectively place obligations at different points in the lifecycle of synthetic content. At the generation stage, services enabling SGI are expected to use technical measures against unlawful creation. At the distribution stage, intermediary due-diligence requirements apply. Significant social-media intermediaries are also required to deploy appropriate technical measures, including automated tools or other mechanisms, to proactively identify information depicting or simulating child sexual abuse, subject to safeguards in the rules.
The amendments also tighten response times in specified cases. Complaints relating to certain intimate material, sexual imagery, impersonation or artificially morphed images are subject to a two-hour response requirement. Material covered by a valid court order or reasoned government intimation under Rule 3(1)(d) is subject to a three-hour removal or access-disabling requirement.
The regulatory chain can therefore begin with preventing generation, move to detection and removal, and eventually lead to preservation of evidence, reporting and investigation.
A newly generated image presents a different detection problem
Known CSEAM can often be detected through hash matching, where a digital fingerprint of an image or video is compared with fingerprints of previously identified material. A newly generated image may have no known hash.
Google says it uses hash matching for known CSEAM and machine-learning classifiers to identify previously unseen suspected material, followed by specialist human review. Its policies and systems also cover modified imagery of identifiable minors and computer-generated imagery indistinguishable from an actual minor engaging in prohibited conduct.
This makes detection more complex than comparing every suspicious file against a known database. A platform may have to assess whether a newly generated person appears to be a child, whether an identifiable real person has been manipulated and whether existing abusive imagery has contributed to the output.
Once law enforcement becomes involved, another question follows: what exactly does the image represent?
Investigators may first have to establish whether the child exists
In a conventional victim-identification investigation, analysts study an unknown image for clues that may help identify the child and locate where the abuse occurred.
AI can add another question before that process begins: is there a real child in the image who can be found?
The image may depict a victim already known from existing material. An identifiable child’s photograph may have been supplied to an AI system and manipulated. A composite image may incorporate features from real people. Or the apparent child may have been generated entirely by software.
The absence of a physical event corresponding to the image does not necessarily mean there is no victim or offence. An identifiable child may have been threatened or humiliated, their photograph may have been misused, synthetic imagery may have facilitated blackmail or grooming, or the new file may derive from existing abuse material.
NCMEC says offenders are using AI to manipulate existing abusive imagery involving known CSEAM victims, creating new material and re-victimising those children.
One victim can therefore appear in an expanding number of derivative files. Raw file counts cannot be treated as equivalent to the number of children involved.
‘Nudify’ tools create a real victim even when the depicted act is fake
Manipulated photographs sit between recordings of actual abuse and wholly synthetic imagery. An ordinary photograph of an identifiable child can be altered into fabricated sexual imagery even though the act depicted never happened. The child can still face humiliation, bullying, threats or coercion when the image is circulated.
NCMEC says it is tracking cases involving so-called “nudify” applications used to create and circulate fabricated images, including among peers and classmates.
Indian investigators may then have to examine several provisions according to the facts. Section 2(1)(da) covers computer-generated and modified depictions. Section 11(v) specifically addresses threats involving real or fabricated depictions. Sections 13 to 15 address use and storage of prohibited material, while Section 67B of the IT Act covers a range of conduct involving prohibited electronic content.
That does not mean every manipulated-image case attracts every provision. Police still have to establish what was created, why, whether it was stored or circulated and whether it was used against a child.
The hardest question is the child who never existed
The most difficult legal scenario can be stated simply: what happens if an adult in India generates a photorealistic sexual image of a completely fictional child created entirely by software? There are strong reasons not to describe this as a clear statutory void.
POCSO expressly includes a computer-generated image indistinguishable from an actual child. Section 67B expressly refers to creating digital images depicting children. The February 2026 IT Rules expressly place CSEAM within the category of unlawful synthetic material against which generation services must deploy technical measures.
At the same time, some substantive provisions use phrases such as “a child”, “uses a child” or material “involving a child”. Section 67B defines children as persons who have not completed 18 years of age.
That leaves a specific interpretive question: when the person depicted was generated entirely by software and never existed, how should the broad computer-generated-image language be reconciled with offence provisions framed around an actual child?
Until a directly applicable Indian judgment answers that question, it would be wrong to describe the law either as completely silent or conclusively settled.
What if the platform blocks the request before an image is produced?
Generative AI creates another problem that traditional file-based investigations rarely faced. A user can attempt to generate prohibited material only for the service to block the request before an image is produced.
The February 2026 rules require intermediaries offering synthetic-generation capabilities to deploy reasonable and appropriate technical measures to prevent their resources from being used to create unlawful SGI, including CSEAM.
For law enforcement, a blocked attempt raises different questions. Was the request retained? Can the account be attributed to a person? Did the user upload an image of a real child or existing abuse material as an input? Were there repeated attempts? Was anything ultimately generated, stored or transmitted?
Whether such conduct by itself becomes a prosecutable attempt will depend on the offence alleged, the steps taken and the evidence available. A rejected request cannot automatically be equated with possession or distribution of an unlawful file.
But prevention at the generation stage has now become part of India’s regulatory architecture.
India still lacks a public AI-CSEAM enforcement funnel
NCMEC can separately show that more than 400,000 CyberTipline reports in 2025 had a generative-AI nexus, more than 182,000 involved possession, generation or attempted generation of GAI CSEAM, and more than 158,000 images and videos have been categorised as GAI CSEAM since 2023.
India does not yet have a comparable publicly available national breakdown separating AI-generated CSEAM from broader CSEAM and cybercrime data.
That leaves basic questions unanswered publicly: How many India-linked CyberTips involve generative AI? How many complaints involve manipulated photographs of real children? How many concern fully synthetic material? How many involve AI-assisted sextortion? How many became FIRs, arrests, chargesheets and convictions?
Without those numbers, international data can demonstrate the emergence of the problem but cannot establish its scale in India.
The February 2026 rules provide a useful point from which to start measuring. Data on complaints, blocked generation, platform action, takedowns and cases involving synthetic CSEAM after 20th February 2026 could show whether the new regulatory obligations are translating into an identifiable enforcement trail.
AI changes what police have to establish
An AI-related investigation may require police to answer considerably more than whether a suspicious file exists on a device.
They may have to identify who generated it, which service and account were used, whether a real child’s image was supplied as input, whether the material derives from known CSEAM, and whether it was merely generated or subsequently stored and shared.
Where a real child is identifiable, investigators also need to establish whether the synthetic image was used to threaten, harass, blackmail or coerce them.
Where no real person can immediately be identified, investigators may have to determine whether the apparent child is entirely synthetic, a composite or derived from real material.
Only after those factual questions are answered can investigators determine which provision most closely fits what the accused actually did.
AI-generated CSEAM is therefore not merely a new-content problem. It is also an attribution and classification problem.
The image may be synthetic, but the investigation cannot be
Generative AI has broken the assumption that every abusive-looking image must be a direct visual record of an event that happened exactly as shown.
Investigators can now encounter an image of something that never happened involving a child who nevertheless exists. They can encounter newly created material derived from the recorded abuse of a known victim. They can also encounter an apparently realistic child who may never have existed.
Indian law is more prepared for this change than the claim of a complete “AI loophole” would suggest. POCSO has included computer-generated and modified depictions since 2019. Section 11 expressly recognises threats involving fabricated depictions. Section 67B of the IT Act includes creation of digital images. Since 20th February 2026, India’s intermediary rules have expressly placed CSEAM within obligations concerning unlawful synthetic content.
The unresolved question is not simply whether Indian law mentions computer-generated imagery. It clearly does.
The harder task is establishing what produced a particular image, whether a real child is connected to it, what the accused actually did, what evidence the platform retained and which provision applies to those facts.
Indian courts may eventually have to draw some of those boundaries, particularly when the apparent child is entirely synthetic. Until then, the enforcement challenge is whether police, forensic systems, courts and technology platforms can make those factual distinctions quickly and accurately enough for the existing laws to work.
Note: While CSAM is the term commonly used internationally, the Supreme Court of India has directed the use of CSEAM in the Indian context. Accordingly, CSEAM has been used as the standard term throughout.





