Report Remove, the IWF/NSPCC service that helps under 18s get intimate images taken down, logged 420 AI made sexual images of under 18s in H1 2026, already above 2025's 397. That is the early receipt for a regulatory gap the statute has not closed.
UK children reported 420 AI-made sexual images of themselves in the first six months of 2026, exceeding the 397 they reported in all of 2025 to Report Remove, the Internet Watch Foundation and NSPCC service that helps under-18s get intimate images removed from the internet. The number crossed the prior full-year total inside six months, and the IWF says the majority of the manipulated-image reports made to Report Remove in 2025 and 2026 were severe enough to meet the UK legal threshold for child sexual abuse material (CSAM).
The service added a dedicated "deepfaked" checkbox to its submission form because tagging became a practical necessity. Volumes no longer fit inside the existing taxonomy of "manipulated image" reports. The checkbox is a small receipt for a much larger shift: most of what is arriving is not a touched-up photo of an adult. It is AI-generated sexual abuse material of a real child, and Report Remove is now flagging it as such by default.
Dan Sexton, the IWF's chief technology officer, put the stakes in plain terms: "everyone in the world is at risk," because any photo of a child that has ever appeared online can be fed into a nudification tool and turned into explicit material. Nudification tools are AI apps that digitally remove clothing from a real photograph.
UK law already addresses part of the pipeline. It is illegal to possess, make, or distribute AI-generated CSAM, and it is also illegal to adapt an AI model to produce abuse material or to distribute such a model. The offence sits at the output and at the weights. What the statute has not yet reached is the generation step inside the commercial products the public uses. Training a general-purpose image model on CSAM, fine-tuning an open-weights model for nudification, or shipping a chat product that will produce the imagery on request are upstream acts the criminal law still treats as a downstream concern. Report Remove is the downstream receipt, and the 420 H1 2026 reports are the leading indicator for that gap.
The constructive move, which Rani Govender, the NSPCC's online safety lead, has been pressing for, is to push the obligation up the stack. A child-safe AI pipeline has three layers, and each one calls for a specific intervention.
At the model layer, training-data filters and fine-tune prohibitions should make it impossible to build a foundation or specialist model on CSAM or on a nudification dataset, and the obligation should sit with the developer that publishes the model. At the platform layer, deployed generative products need generation filters that block the request and upload filters that reject the prompt, with a logged refusal the regulator can audit. At the distribution layer, the platforms that host and share model weights should carry liability when those weights are purpose-built or fine-tuned for abuse, and that liability should attach before the model is used to generate a single image.
These are not new ideas. The IWF's own AI CSAM research has been warning that reactive takedowns arrive after the harm is already done, when a child has to ask for an image of themselves to be removed. The 420 H1 2026 reports are what "too late" looks like at volume. The next regulatory move is to put the duty on the products that mint the imagery, not on the child who has to ask for it back.