Free webinar: 7 Rules That Protect Your Pupils from AI Deepfakes — 4pm, Tuesday 20th October Register now

AI Generated Child Sexual Abuse Material Photos

Written by a human

4 minutes estimated read time

Author: Gareth de Beer Last updated: 1st June 2026

Introduction

Child Sexual Abuse Material generated by artificial intelligent models (AI CSAM) poses a real threat primarily to the welfare of children and secondly to the reputation of education institutions. AI can now create super realistic ‘deep fake’ photos and videos based on images of real children. These images can be used for blackmail, ransom attacks and selling for profit.

Scope of the problem

The AI landscape is changing daily. This is our analysis as of ‘June 2026’. If you’re reading this after it may have changed.

We don’t want to fear monger, but we don’t want to understate either. Here’s the stats.

The stats

All stats are based in the UK.

Of 13–17-year-olds: 1 in 8 have seen peers use AI to make sexual images of others

source: UK Safer Internet Centre

The idea of taking teenage boys taking images and manipulating them is not new. However, AI has meant the resulting images are much more realistic. It would appear that the majority of the specific and targeted deepfakes are between known peers.

97% Of illegal AI-generated images depicted girls

source: IWF 2026

26,385% Rise in AI child abuse videos, 2024→2025

source: IWF report 2026

In absolute numbers that’s 13 videos discovered in 2024, and 3,443 in 2025. For now, that number is relatively small, we have individual websites with more photos and videos than that.

Reports indicate that in many of these videos, AI is being used:

  1. to generate new CSAM that is based on existing CSAM (taking existing material and creating new situations or making them more extreme), or
  2. to create deepfakes of child celebrities.

20–30 Photos needed to build a realistic deepfake model of a specific child, using LoRA fine-tuning

source: IWF report 2026

A ‘LoRA’ is a set of data used to train AI models for a specific purpose. Its reported that a standard consumer laptop can now take 20-30 images of a child and generated realistic deep fakes within 15 minutes. This used to take an advanced machine hours only a year ago.

The potential issues

Peer-to-peer

It seems the largest threat is peer-to-peer. This would largely be an internal school safeguarding issue, rather than a marketing one.

AI Blackmail

There has already been an incident of a malicious actor taking a photograph from a school and turning it into CSAM. The malicious actor then sent a ransom request to schools with the threat of releasing the images if the ransom was not paid (source The Guardian).

As the seed is now planted, we can expect more of these kinds of attacks to take place.

As news of these issues become more mainstream, it will become harder for schools to get photo consent from pupils and parents.

How to protect children at your school

We understand a complete overhaul might be too much work for an individual school. But steps can be taken now to ensure that we minimise risk.

We have two options:

  1. Take real, but AI-aware photographs
  2. Use AI to generate images

7 AI-Aware School Photography Rules

  • Focus on the activity, not the children
  • Take group shots, never single shots
  • Don’t have the same child more than 15 times on the website
  • Limit face-on, take side and over-the-shoulder shots
  • Remove old photographs, consent is not always perpetual
  • Scrub meta-data, (TinyPNG is our favourite tool for this)
  • Don’t link names to photos

Focus on the activity, not the children

The subject of every photograph should be what is happening, not who is in it. A science experiment, a sports day race, or a drama rehearsal tells the school's story just as effectively as a close portrait — and keeps individual children from becoming the focal point of publicly accessible imagery. This approach also produces more authentic, engaging marketing content, and significantly reduces the utility of any image as source material for AI misuse.

Take group shots, never single shots

Isolating a single child in a photograph creates a clearly identifiable subject with no surrounding context to obscure them. Group shots distribute attention across multiple people, making any individual far harder to extract, identify, or use as training data for AI fine-tuning tools. As a rule of thumb: if only one child is in the frame, don't take the shot.

Don't have the same child more than 15 times on the website

Research published in the IWF's 2026 AI CSAM report found that a realistic deepfake model of a specific child can be built using as few as 20 to 30 existing images. Limiting any individual child's appearances across the website to 15 keeps them meaningfully below that threshold, reducing the risk of a viable training dataset being assembled from publicly accessible school images alone.

Limit face-on, take side and over-the-shoulder shots

Full face-on photographs are the most useful type of image for AI face recognition, fine-tuning, and nudification tools. Profile shots, over-the-shoulder angles, and images where children are looking away from the camera or partially obscured retain the authenticity and warmth of genuine school photography while being significantly less exploitable. The EWWG guidance (Image guidance for education settings - UK Safer Internet Centre) specifically recommends these angles as best practice.

Remove old photographs — consent is not always perpetual

According to the ICO's guidance on UK GDPR, consent does not last indefinitely. While the UK GDPR sets no specific time limit, the ICO is clear that consent is likely to degrade over time, and that its duration depends on the context, the scope of the original consent, and the individual's reasonable expectations at the time they gave it. A consent form signed by a parent at school admission in 2019 was given in a very different context to the one that exists today — before AI deepfake tools were accessible to teenagers on a standard laptop. It is therefore reasonable to conclude that the scope of that original consent did not extend to the current risk environment. Schools should conduct a minimum annual audit of published imagery, refresh consent at key transition points, and remove images of any child who has left the school. Where there is doubt about whether original consent still reflects current expectations, the image should come down.

Scrub metadata — TinyPNG is our favourite tool for this

Every photograph taken on a modern camera or smartphone contains embedded EXIF metadata: the date and time the photo was taken, the GPS location, the device used, and sometimes even the photographer's name. When school images are published online with this data intact, it can inadvertently reveal school timetables, routines, and locations to anyone who looks. The EWWG guidance specifically flags metadata as a safeguarding risk. Running images through a tool such as TinyPNG before publication strips this data automatically as part of the compression process, at no extra cost or effort.

Don't link names to photos

A photograph of an unidentified child is significantly less exploitable than one captioned with their full name. Name and face together create a searchable, identifiable profile that can be used to target a specific individual — whether by a malicious peer using a nudify app, or by an offender building a fine-tuned AI model. If identification is needed for internal school records, keep it in a separate document that is never published. On the website, images should speak for themselves.

AI Generated Photography

Fighting fire with fire – or using AI generated photographs in the first place.

Real images are still preferred, since AI images tend to produce a ‘uncanny value effect’ – where the images feel ‘weird’. However, AI models are increasingly more sophisticated.

We can take photographs of empty classrooms and then insert children into the photographs using AI.

This ensures that real children are protected, even in the event of a blackmail attack.

It also means we can continue having the ‘old-style’ of face on photography.

Example website

The SLT at Olga Primary School were concerned about the AI deepfakes (before this report even came out). So, we organised a ‘faceless’ photoshoot for them. We (us and them) are glad in hindsight. See how it’s possible to create an attractive website without the use of faces:

  • Teacher supporting two pupils during a religious education lesson at Olga Primary School
  • Child working on an edible garden art project at a desk, photographed over the shoulder at Olga Primary School
  • Classroom of children at desks, photographed from behind at Olga Primary School
  • Children learning in a classroom, photographed from behind at Olga Primary School
  • Child drawing at a desk, photographed over the shoulder at Olga Primary School
  • Child playing violin in the playground, photographed over the shoulder at Olga Primary School
  • Children doing a classroom craft activity with a teacher, photographed from the side at Olga Primary School
  • Pupils in the school playground, photographed from behind at Olga Primary School
  • Pupils walking through the school garden, photographed from behind at Olga Primary School