Skip to main content
LATEST What Happens When a City’s Data Center Battle Leaves the Council Chamber The Strange Sea Journey of a Crab Stuck in a Bottle Explicit Deepfakes of Children Put UK Schools, Platforms and Regulators on the Same Clock The First Virus Built by AI Exposes a New Biosecurity Problem Mythos Tightens Defenses After a Social Engineering Push Exposes an AI Policy Weak Spot
Tech

Explicit Deepfakes of Children Put UK Schools, Platforms and Regulators on the Same Clock

Alex Raeburn
Alex Raeburn Staff Writer ·
10 min read
Explicit Deepfakes of Children Put UK Schools, Platforms and Regulators on the Same Clock

The deepfake threat has reached the school gate

What used to sound like a grim corner of AI policy’s pushed into ordinary life. A photo from a school website, a weekend football snap, a birthday picture shared in a family group chat. Any of those can now be run through mainstream AI tools or “nudification” apps and turned into explicit fake images in a few clicks. That’s the unsettling part: the input doesn’t need to be secret, stolen from a hard drive, or taken by a malicious insider. It can be public, banal and taken for granted.

The result is no longer theoretical. UK children under 18 are already reporting that they’ve seen sexualised deepfakes of themselves. Once that sentence moves from a hypothetical to a complaint made by a child, the tone changes. Fast. This stops being a debate about whether the software exists and becomes a child-safety problem with a very real paper trail.

The danger isn’t that AI can invent a fake person. It’s that it can now corrupt a real child’s ordinary photo with almost no friction.

That’s why schools, tech platforms and regulators have all been pulled into the same mess at once. Schools are caught on the front line because they publish the easiest raw material: class photos, sports day shots, prize-giving images, staff-pupil event posts. In a lot of cases, those images are uploaded with decent intentions and very little thought about how useful they might be to someone looking for a target. A face, a uniform, a name tag, a caption. That’s enough to make a child identifiable, which is all a bad actor really needs.

Tech platforms sit in the middle. They host the photos, distribute the apps and decide how quickly abuse reports are handled once a fake image starts circulating. Some platforms can detect re-uploads with reasonable speed. Others move at the pace of a broken printer (and that’s no small thing). When explicit deepfakes spread through social apps, group chats and image-sharing sites, the delay between reporting and removal can matter as much as the original upload. A fake can do its damage long before anyone’s finished filling out the complaint form.

Then there are the UK’s safety regulators, who are now dealing with a problem that sits awkwardly between existing child-protection rules and fast-moving AI policy. The law has been trying to catch up with adult deepfake porn, child sexual abuse material, and platform duties all at once. It’s a messy overlap, and not the fun kind of overlap that makes a product manager smile in a meeting. Regulators have to decide where the line sits when a child’s face’s copied, altered and distributed by software that was widely available to anyone with an internet connection.

What makes this story hard to shrug off is its plainness. The technology isn’t rare, the victims aren’t imaginary, and the harm isn’t staying inside a lab. It’s showing up in real reports from children, in school inboxes and in the kind of tech news that nobody wants to see repeated. “ is already obsolete. The live question is who steps in first, and whether they can move before the next photo does.

A reporting spike that has already outgrown last year

A reporting spike that has already outgrown last year

By the time a problem turns up in a child-reporting service with a dedicated deepfake option, the alarm bell has usually stopped being polite. It’s started shouting.

The anonymous Report Remove service, run by the Internet Watch Foundation with the NSPCC, logged a little over four hundred child reports in the first half of 2026. That already puts it ahead of the total for all of 2025, when the figure sat just under four hundred. For a service built to help remove intimate images from circulation, that kind of jump is hard to dismiss as a blip. It looks more like a queue.

When the first six months beat the whole of the previous year, the problem has already moved past the “early warning” stage.

Report Remove exists for a grimly practical reason. Children and young people can use it to flag sexual images or videos of themselves so the material can be taken down and, where possible, stopped from spreading further. The service is anonymous, which matters. A lot of victims aren’t ready to attach their name to a report when they’re still trying to work out whether the image’s real, altered or both. Some are also trying to decide whether telling a parent, a school or the police will make the mess bigger. That hesitation buys time for whoever posted the image in the first place.

The clearest sign that the complaints are changing is the reporting pipeline itself. And the form now includes a specific option for deepfaked material, which is a fairly blunt admission that manipulated images are no longer some awkward edge case. They’re common enough to need their own box. That’s how a reporting system evolves when a new type of abuse starts arriving in volume, not as a one-off novelty.

A lot of the material being flagged is also serious enough to cross the line into child sexual abuse material. That’s the part many people miss when they hear the word “deepfake” and picture a crude prank or a nasty bit of schoolyard humiliation. Some of these images aren’t just embarrassing. They are illegal sexual abuse imagery, created from ordinary photos and then weaponised. In AI safety terms, this is not a future policy headache. It’s a present-day criminal workflow.

The complaints that come through Report Remove also seem to arrive with a nasty bonus feature: sextortion. In some cases, the child who reports the fake image is also being pressured by the same or a separate offender, with demands for money or for more explicit images. That makes the whole thing uglier and more coercive. The fake image isn’t the end point. It’s the lever.

The UK government has already started tightening the legal and safeguarding response, with a new law aimed at AI child-abuse images at source and a separate push on protecting children from online predators. Those moves do not erase the fact that the reports are already piling up. They do, however, show that this is no longer being treated as a niche tech nuisance tucked away in the lifestyle tech corner of the internet.

Schools are feeling the pressure too, because the complaints do not stay neatly inside one platform or one household. The 2026 safeguarding guidance in Keeping Children Safe in Education is part of the backdrop now, not a side note. Once reports are landing with this much frequency, schools, parents and platforms are all being pulled into the same response cycle, often before anyone has had time to work out where the image came from in the first place.

The pace matters. So does the type of harm. A reporting service that once dealt mostly with takedowns is now handling complaints that can involve sexual abuse imagery, deepfaked school photos and extortion in one chain of events. That’s a bigger administrative headache, yes, but it’s also a clearer sign of what this wave of UK deepfakes looks like in practice: faster, meaner and already outpacing last year’s totals.

How a normal school photo turns into blackmail fuel

The ugly trick here’s that the original picture doesn’t need to be anything scandalous. A normal classroom snap, a football-day team photo, a leavers’ montage on a school site, even the sort of cheerful image parents post after assembly can be enough. Once a child’s face’s out in public, it can be copied, cropped and fed into nudification tools or other generative systems that spit out explicit fabrications. The process is mundane. The outcome isn’t.

Once a child’s face is public, an attacker doesn’t need a camera. They only need a file, a cheap tool and a willingness to be vile.

That’s what makes this such a hard problem to shut down after the fact. The Internet Watch Foundation has been blunt about the logic of it: if you wanted to prevent this kind of abuse completely, the only guaranteed method would be to keep children out of photographs altogether. That’s obviously not how schools, families or ordinary life work. Parents want birthday photos. Teachers want a record of trips and sports days. Schools use images to show what pupils are doing and to make their communities feel, well, like communities. None of that’s remotely sinister. It just means the raw material is already everywhere.

The advice now being pushed out by the National Crime Agency and the Internet Watch Foundation is therefore very practical and a bit unromantic. Keep children’s pictures off public feeds where you can. Tighten privacy settings. Share in smaller, limited groups instead of broadcasting to the world. It’s not about panic or suspicion of every upload. It’s about reducing how easy it’s for strangers to scrape images from open profiles and school pages, then feed them into tools built to create sexualised fakes. The advice isn’t glamorous, but neither’s blackmail.

Another thing: Schools have their own version of the same problem. A single school website can hold a surprising amount of useful material for an offender: class photos, achievement posts, sports teams, performance shots, house events, trips, the lot. If faces are visible and names are attached, the image becomes a ready-made target sheet. In recent cases, criminals have scraped pupil photos from school and family accounts, used AI to generate abuse imagery, then threatened to leak the material unless the child complied or paid. It’s grimly efficient, which is why schools are being urged to strip identifiable faces from websites and social posts whenever they can. A blurred crowd shot’s boring. A clear child portrait is ammunition.

The threat also scales in a way that older forms of image abuse didn’t. This isn’t just one child, one image, one blackmailer in a basement somewhere. Any visible, identifiable school image can be used as raw material for a broader extortion run. A single year-group photo can become dozens of synthetic files. A school newsletter picture can be turned into a threat against one family, then reused against another. Once the image exists online, the attacker can come back to it again and again, which is part of what makes the whole thing so nasty. The picture doesn’t age out. It waits.

The Internet Watch Foundation’s own annual data on AI-generated child sexual abuse shows how quickly this material has moved from a hypothetical to something people are actually reporting. That shift matters for schools because it changes the default assumption. A photo on a public page is no longer just a photo on a public page. In the wrong hands, it can be turned into a threat with very little effort and even less shame.

Report Remove sits in the middle of this mess as a cleanup tool after harm has happened, but the prevention message is the same one repeated by child-safety teams again and again: if you can keep a child’s image off open feeds, do it. If you can make a school site less searchable, do that too. And if you can stop posting faces where strangers can scrape them, even better. The tech’s moving fast. And the abuse’s moving faster. That leaves families and schools doing a very unglamorous bit of digital housekeeping, because the alternative is letting someone else decide what a child’s picture gets turned into next.

The accountability test for platforms and policymakers

Once a child’s photo has been turned into explicit material, the cleanup job stops being a family problem and becomes a system test. That’s where the UK’s legal position starts to matter. The law already treats AI-generated child sexual abuse material as illegal, and it also makes it unlawful to tamper with an AI model for abuse or pass those tools to other people. So this isn’t one of those airy AI policy debates where everyone nods politely and then gets on with shipping the product anyway.

If a tool can make abuse easier, the law cannot wait for the abuse to become common before it reacts.

That sounds obvious, which is usually a sign that the industry has managed to complicate something simple. The NSPCC’s warning goes straight at that problem. Tech companies, it says in effect, can’t keep pushing out AI products and hope child safety can be patched in later with a few settings and a trust-and-safety blog post. Then the protection needs to be built into the thing itself, before launch, not added after a school has already spent a week handling complaints and a parent’s spent a sleepless night trying to find out where the image spread, if a system can produce synthetic abuse imagery.

For platforms, that means more than a generic abuse-reporting button hidden three menus deep. It means detection that catches manipulated child sexual abuse material quickly, removal systems that can act before the image ricochets around the internet and guardrails around creation tools so people can’t so easily make the material in the first place. Some of that’ll rely on policy, some on product design, and some on old-fashioned enforcement. None of it works if the response time is measured in days while the abuse’s moving in minutes.

Report Remove sits in the middle of that clean-up pipeline. The service does more than forward a complaint, when a child or parent reports an intimate image. It turns the image into a digital fingerprint, often called a hash, which can then be shared with major platforms so they can spot the same file again, take it down, or block fresh uploads of it. That matters because the internet’s memory isn’t sentimental. Once a file exists, it tends to pop back up in odd corners, copied by people who may not even know what they’re sharing.

The practical value here’s plain enough. One report can help stop repeated re-uploads across multiple services, which is a lot better than making families file the same complaint five times and hope the image eventually gets tired and disappears. It probably won’t. The same file can keep turning up under a slightly different account name, on a different site, with a different caption. And the fingerprint system gives platforms a way to recognise the image even when the human eye has not yet seen it.

What follows from all this isn’t subtle. The burden’s moving away from families trying to hide every school photo or strip every face from a birthday post. That advice still matters, because the internet has never been especially wise with children’s pictures. Makes sense. But it can’t be the whole answer. Schools now have to think about what appears on websites and social feeds. Platforms have to detect and remove synthetic abuse faster. Regulators have to keep pressure on the companies building and selling the tools. And AI policy has to stop treating child safety as a side issue that can be dealt with after the next model update.

The race here’s awkward but simple. Technology’s moving at one speed, the law has already chosen its line and the child-safety response has to catch up on the same clock. Not later. Not after another round of public shock. All at once, or not nearly fast enough.

Newsletter

Stay in the loop

Join our newsletter and get resources, curated content, and inspiration delivered straight to your inbox.