Where, exactly, should intervention begin when someone is moving towards child sexual abuse material online?

The immediate answer is to remove illegal material, identify offenders and support law enforcement.

Obviously...

Nevertheless, a new report commissioned by Ofcom points to earlier stages where intervention may still change what happens next.

Protect Children surveyed 20,592 adults who were actively searching for child sexual abuse material, or CSAM, on the dark web. The findings cover first exposure, search behaviour, platform use, AI-generated material and reactions to warning messages.

The findings are pretty disturbing. They also give policymakers, platforms and safeguarding leaders a clearer view of where controls could act before the behaviour escalates further.

TL;DR

  • Nearly half of respondents said their first exposure to CSAM was unintentional.
  • Respondents reported searching on open-web and dark-web platforms at similar levels.
  • AI tools appear to be lowering the effort needed to create abusive material, while making synthetic and real imagery harder to distinguish.
  • Warning messages were far from universally effective, but some respondents said they stopped, reflected or looked for help after seeing one.
  • Controls need to appear throughout the pathway to harm, including before an offence has been detected and formally recorded.

What the research can and cannot tell us

Before drawing conclusions, the limits of the study need to be clear.

This was an anonymous, self-reported survey shown to people using known search terms on a dark-web search engine. Participants selected themselves into the study. The findings should not be treated as representative of the general population, nor do they establish that one behaviour caused another.

The platform figures also describe where respondents said they searched. They do not prove that illegal material was hosted on a named platform, or that every search succeeded.

Those limitations define how the findings should be used. The report gives us rare insight into the reported behaviour of a large group of people actively seeking CSAM. It also identifies several points where intervention deserves serious consideration.

First exposure can happen before deliberate searching

According to the report, 46% of respondents said their first exposure to CSAM was unintentional. They either encountered it online without searching for it, or somebody showed or sent it to them.

Three in five respondents also reported first seeing CSAM before the age of 18.

Accidental exposure does not inevitably lead to offending. Nevertheless, the finding challenges a neat model in which a person simply decides to enter a hidden part of the internet and begins searching.

For some respondents, the pathway began earlier, in ordinary digital environments, with exposure they did not initially seek.

As I see it, this creates an intervention window. Education, reporting routes, moderation, age-appropriate design and access to confidential help may all have a role before repeated viewing or intentional searching becomes established behaviour.

If our controls only appear after material has been downloaded, shared or reported to law enforcement, we are acting at the far end of the pathway.

The open web is part of the problem

The report also weakens the assumption that CSAM is predominantly a dark-web issue.

Among respondents, 63% said they tended to search for CSAM on dark-web platforms and 61% said they tended to search on open-web platforms. More specifically, 27% reported using open-web search engines, 22% adult pornography sites and 16% social media platforms.

The open web gives policymakers and providers more visible points of control.

Search engines can interrupt queries. Social and content platforms can change discovery and recommendation systems. Messaging services can strengthen detection and reporting processes within the boundaries of the law. AI providers can introduce safeguards at the point of generation. Cloud services can act against the storage and distribution of illegal material.

Platform design is therefore part of the safeguarding architecture. Features that make content easy to discover, generate, move or store can increase exposure. Friction, warnings, reporting routes and effective enforcement can reduce it.

I do not think this transfers responsibility away from perpetrators. It tells us that responsibility is not exhausted by prosecuting them. The systems through which harm is discovered and distributed also have decisions to make.

AI makes abusive material easier to create

Three in ten respondents, 29%, said they had viewed AI-generated CSAM. One in ten said they had created it.

The report warns that the viewing figure may be understated because 61% of respondents said they could not, or were unsure whether they could, distinguish AI-generated imagery from real imagery.

Creation was reportedly learned through trial and error using tools that were often open and easy to use. The material described by respondents included fully synthetic images, altered images of real children and existing abuse material modified for particular preferences.

My opinion is that the AI discussion needs to be far less ‘general’ on this matter.

Synthetic imagery does not make the safeguarding issue victimless. Images of real children can be manipulated. Existing abuse can be repurposed. Demand, normalisation and escalation still carry consequences. The report also records respondents describing AI-generated material as a possible gateway towards seeking real material, although that is a reported perception rather than proof of a causal pathway.

Providers should be able to answer: where will they create friction, identify prohibited use, preserve evidence, issue a warning or direct somebody towards help?

When a tool lowers the human effort needed to act on harmful intent, the design decisions by the creator of said tool have a fair bit of consequence.

What warning messages can do

Only 34% of respondents recalled encountering a warning message while searching for CSAM. Those warnings were most commonly recalled on open-web search engines and browsers. They were less commonly recalled on social media, messaging services, AI applications and cloud storage, despite respondents reporting that they used those environments to find, create or store material.

Reactions were mixed. Many ignored the warnings. Others described fear, shame or indifference.

Yet a notable subset said a warning prompted them to leave a site, stop searching, reflect on their behaviour or look for help. More than 2,200 respondents clicked through to Protect Children’s ReDirection programme after completing the survey.

We should be cautious here. A self-reported reaction is not the same as verified long-term behaviour change. Even so, it suggests that timely interventions may reach some people at a point when interruption is still possible.

Warning messages have a limited role within a wider control system that includes detection, removal, reporting, law enforcement, offender prevention services and victim support.

Placement also affects whether the control is seen. A warning that appears on a search engine but disappears when the same person moves to an AI tool, messaging app or storage service leaves an obvious gap.

What this means beyond platform policy

This report is principally about online services and perpetration prevention. It should not be misused to claim that an employer can predict who will offend, or that a digital screening result proves somebody is safe or unsafe.

Nevertheless, the broader lesson is relevant to any organisation making high-trust access decisions.

Formal checks generally show recorded outcomes. They remain essential, particularly where they are legally required. But the Ofcom research shows how harmful behaviour can develop across digital environments before it produces the sort of formal record that a traditional background check can reveal.

For organisations granting access to children, vulnerable people, sensitive systems or positions of authority, that creates a difficult but necessary question: does the available evidence match the consequence of the access being granted?

Digital Risk Screening can add structured visibility into relevant digital signals that traditional checks were not designed to reach. It cannot predict future behaviour, replace statutory vetting or make the decision automatically. The scope must be lawful and proportionate, findings must be validated by a human analyst, and the organisation remains accountable for the judgement.

That boundary needs to remain explicit. Better visibility should improve the quality of the decision without becoming another unofficial badge of safety.

Three decisions for leaders

For policy, platform, safeguarding, HR and risk leaders, I would take three practical questions from the report:

1️⃣ Where can we intervene earlier?

Map the pathway from exposure to intentional search, creation, storage and distribution. Do not wait until the final stage to introduce a control.

2️⃣ Are controls present where the behaviour has moved to?

Warnings and detection concentrated on traditional search surfaces will miss activity that shifts into social platforms, (anonymous) messaging, AI tools and cloud storage.

3️⃣ Does the evidence match the access decision?

For high-trust roles, combine required checks with proportionate, human-reviewed digital risk intelligence where the exposure justifies it. Record the scope, evidence, limitations and decision pathway.

Having read this report, I am cautiously optimistic.

The pathway to harm contains points where technical controls, regulation, education, specialist help and human judgement can interrupt what may happen next. Each measure covers a different point in that pathway, and each has limitations.

Leaders now need to decide where intervention can still alter the outcome, then make sure an effective control actually exists there.

If your organisation is reviewing how it makes high-trust access decisions, Safehire.ai provides Digital Risk Screening as an additional, human-validated layer alongside traditional checks. It supports clearer, more defensible decisions without replacing statutory vetting or human judgement.

Sources

Continue reading