P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

IWF: 6,310 AI child sexual abuse images assessed in six months, 40% above all of 2025

The Internet Watch Foundation assessed 6,310 AI-generated child sexual abuse images between 1 January and 30 June 2026, against 4,512 in all of 2025. It is a count of what analysts assessed, not of what exists, and the UK offence for abuse-image generators is enacted but not yet in force.

By Parminder Kumar Sharma · · 21 min read

A dark desk with a monitor showing a blank statistics dashboard of empty rounded tiles and two plain bars beside one hollow amber outline, and a closed navy statute book with blank paper page flags in front of it. No people and no writing.

Six months set against twelve

On 5 October 2026 the Internet Watch Foundation (IWF) said its analysts assessed 6,310 AI-generated images that met the legal definition of child sexual abuse between 1 January and 30 June 2026. For all of 2025 the same release gives 4,512. The difference is 1,798 images, or 39.8 per cent (derived: 6,310 divided by 4,512 is 1.398). The IWF rounds that to 40 per cent, and the arithmetic holds.

The detail that matters is the clock. The 6,310 covers 181 days and the 4,512 covers 365. Per day that is 34.9 images against 12.4, about 2.8 times the pace (derived, and it assumes images were assessed evenly through each period, which the IWF does not state). The Guardian's standfirst and picture caption say "this year". The IWF's own release says the first half. Nothing after 30 June is in the number, and the release came 97 days later.

What the number does not establish is what most readers will take from it. It is not how much of this material exists, because it counts what analysts assessed. It is not how many children are affected: the IWF says of its 2025 data that some children appear repeatedly, so the figures do not necessarily represent unique individuals. And it does not say whether the rise reflects more material, better detection, or more searching and reporting. The IWF said of its 2025 video total that it is influenced by where its analysts look and what the public reports. The 5 October release makes no such statement about the 2026 image count. Silence is not evidence either way. This briefing applies the same caution to images, as an inference.

What each number counts

The IWF's unit in this release is the image, not the web page, the report or the child. Its methodology page says hash-level data allows more precise trend analysis than URL-level data, where a single web page may hold hundreds or thousands of images. It also says identical files share a hash and need not be assessed again, and that changing one pixel produces a different hash. Inference: re-edited variants of one picture can each count as a new image. How the 2026 count treats near-duplicates is not stated, and it matters most for a technology that makes variants cheaply.

What each figure in this story counts, from the IWF's own pages

  1. Figure
    6,310
    What it counts
    AI-generated images assessed by IWF analysts as meeting the legal definition of child sexual abuse. Still images only.
    Period and source
    1 Jan to 30 Jun 2026. IWF release, 5 Oct 2026
  2. Figure
    4,512
    What it counts
    The release's total for the same description across all of 2025.
    Period and source
    2025. Same release
  3. Figure
    4,586 and 81
    What it counts
    The annual report's total of AI-generated images assessed as realistic abuse, plus 81 assessed as prohibited (non-photographic). 180 of the 4,586 were grid images.
    Period and source
    2025. IWF annual report
  4. Figure
    6,221
    What it counts
    Images where both age and sex were recorded. The base for the 98 per cent girls and 79 per cent aged seven to 13.
    Period and source
    1 Jan to 30 Jun 2026. Release
  5. Figure
    5,557, 403, 350
    What it counts
    Images graded Category C, B and A. They sum to 6,310.
    Period and source
    1 Jan to 30 Jun 2026. Release
  6. Figure
    3,443
    What it counts
    AI-generated videos in 2025, against 13 in 2024. A separate series, not inside the 6,310.
    Period and source
    2025. IWF annual report
  7. Figure
    420
    What it counts
    Report Remove reports in which a child believed some imagery had been faked, criminal or not. Reports, not images, and the child's belief is not verified. 268 were actioned.
    Period and source
    Jan to Jun 2026. IWF release, 10 Aug 2026
A chart drawn to scale. Images assessed: 4,512 in all of 2025 (365 days), with the annual report's 4,586 marked, and 6,310 from 1 January to 30 June 2026 (181 days). Images per day, derived: 12.4 and 34.9, about 2.8 times. Four caveats: it counts what analysts assessed, the cause of the rise is not stated, videos are a separate series, and the data stops 97 days before publication.
Drawn from the IWF release of 5 October 2026 and its 2025 annual report. Per-day figures are derived by this briefing and assume an even spread, which the IWF does not state.

Two points on where the Guardian's pieces come from. First, the release is addressed to Brussels: it urges EU policymakers to agree the Child Sexual Abuse Regulation so that platforms can detect known and previously unseen material. It does not ask for UK legislation on AI. The call for "binding legislation on AI" is a quote the Guardian attributes to the IWF's head of policy, so it rests on that report. It is consistent with the IWF's annual report, which calls for a "regulatory requirement to ensure AI products are safe by design". Second, the Guardian's Report Remove figures (420 against 397) are from a different IWF release, of 10 August, and count children's reports, not images.

Reconciling the time frames, and the IWF's two totals for 2025

The Guardian's two time frames. Its body text says the first half of 2026, which is correct. Its standfirst and caption say "this year", and the standfirst says the number is "already" 40 per cent above last year's total. Read against the release, "this year" means 1 January to 30 June. So the comparison is half a year against a whole one. That does not weaken the finding, since the first-half total already exceeds the full-year total. It does mean the pace is faster than the 40 per cent suggests, and that the three months from 1 July to the release are not covered at all.

The IWF's two totals for 2025. The release says analysts identified 4,512 images in 2025. The annual report, read on 5 October 2026, says 4,586. They are 74 apart, 1.6 per cent of the larger. The release does not say why. The annual report says 180 of its 4,586 were grid images (single images made of several), and whether the 4,512 leaves anything out is not stated. The choice moves the headline: against 4,586 the rise is 37.6 per cent, not 39.8. The release's own 2025 Category C share points the same way. It says 2,842 images, 62 per cent. That is 61.97 per cent of 4,586 and 62.99 per cent of 4,512, which would round to 63. Inference: the release's percentage appears to use the annual report's total while its headline uses another. The Guardian's "more than 4,500" fits both.

The arithmetic, checked against the IWF's published figures

  1. Check
    6,310 / 4,512
    Result
    1.398, so +39.8 per cent
    Reading
    The IWF's 40 per cent, correctly rounded
  2. Check
    6,310 / 4,586
    Result
    1.376, so +37.6 per cent
    Reading
    If the annual report total is the baseline
  3. Check
    6,310 / 181 days
    Result
    34.9 a day, 1,052 a month
    Reading
    Derived. 1 Jan to 30 Jun 2026 is 181 days
  4. Check
    4,512 / 365 days
    Result
    12.4 a day, 376 a month
    Reading
    Derived
  5. Check
    34.9 / 12.4
    Result
    2.82 times
    Reading
    Derived. Assumes an even spread, not stated
  6. Check
    350 + 403 + 5,557
    Result
    6,310
    Reading
    Categories sum to the headline count
  7. Check
    6,094 / 6,221
    Result
    97.96 per cent
    Reading
    The IWF says 98 per cent girls
  8. Check
    (2,534 + 2,369) / 6,221
    Result
    78.8 per cent
    Reading
    The IWF says 79 per cent aged seven to 13
  9. Check
    5,557 / 6,310
    Result
    88.07 per cent
    Reading
    The IWF says 88 per cent Category C
  10. Check
    2,842 / 4,512 or 4,586
    Result
    62.99 or 61.97 per cent
    Reading
    The IWF says 62 per cent, matching 4,586

What changed inside the count, and why synthetic is not victimless

The release's breakdown does not show the rise concentrated at the most severe end. Category C, the lowest of the three gradings in the Sentencing Council's guidelines and still criminal, was 5,557 of the 6,310 images, 88 per cent. In all of 2025 it was 2,842. Categories A and B together were 753 images in the half year. For all of 2025 they were about 1,670 (derived: 4,512 less 2,842, or 1,744 on the 4,586 total). The annual report put Category A at 23 per cent of AI images in 2025; in the first half of 2026 it is 350 of 6,310, or 5.5 per cent (derived).

That does not show the worst material fell. In 2025 the IWF found that 65 per cent of AI-generated videos were Category A, and the 2026 video figures are not in this release. The release does not say whether severe material moved out of still images, whether analysts' priorities changed, or whether the mix reflects what is being made or what is being found.

Age and sex moved in one direction. Images of children aged seven to 13 were 79 per cent of those with both recorded, up from 70 per cent across 2025. The IWF reports 1,004 images depicting children aged three to six and 190 aged under two in the half year. Girls were 98 per cent of the 6,221 with both recorded, against 97 per cent in 2025, and the number of unique images depicting girls rose from 4,259 to 6,094.

"AI-generated" is not a safe word. It suggests no victim and no offence. The sources say otherwise. The IWF's release states that AI-generated child sexual abuse imagery "causes real harm", and that in some cases offenders use AI tools to manipulate genuine images of victims. Its annual report says images of real children are often used to train models. UK law does not treat the label as a defence. A realistic AI image falls within the pseudo-photograph definition in section 7(7) of the Protection of Children Act 1978, an image which "appears to be a photograph", and the government's factsheet says such images are most likely treated as pseudo-photographs. The 1978 Act makes it an offence to make, distribute or possess one with a view to distributing it, with up to ten years on conviction on indictment. Non-photographic images fall under section 62 of the Coroners and Justice Act 2009. The government's own factsheet says the law is clear that creating, possessing or distributing such images, AI-generated or not, is already illegal.

Stated and not stated

What the IWF release and its supporting pages state, set against what they do not

  1. Question
    Period covered
    Stated
    1 Jan to 30 Jun 2026
    Not stated
    Anything about 1 Jul to 5 Oct
  2. Question
    Unit
    Stated
    Images meeting the legal definition. 'Unique images' for the girls figure
    Not stated
    Treatment of near-duplicates. Whether grids or non-photographic images are in the 6,310
  3. Question
    2025 baseline
    Stated
    4,512 in the release
    Not stated
    Why the annual report says 4,586
  4. Question
    Cause of the rise
    Stated
    A sharp rise, with no cause given
    Not stated
    More material, better detection, more reporting or more searching
  5. Question
    Prevalence
    Stated
    Nothing. The IWF counts what it assessed
    Not stated
    How much exists, and how much is new rather than re-shared
  6. Question
    Children affected
    Stated
    Age and sex recorded for children in each image
    Not stated
    How many individual children. The IWF says some appear repeatedly
  7. Question
    Videos
    Stated
    A separate series. 3,443 in 2025
    Not stated
    Any 2026 video figure in this release
  8. Question
    Link to real children
    Stated
    Offenders sometimes manipulate genuine images of victims
    Not stated
    What share of the 6,310 involves an identifiable real child
  9. Question
    Legal tools working
    Stated
    Nothing
    Not stated
    Whether any enacted measure has changed the count. The image-generator offence is not in force

Method, not accusation. The IWF is a charity that assesses this material, and its numbers come from trained analysts, not from a model. It is also funded in part by its members, who buy its services, including a hash list it markets to generative AI model providers, and it campaigns on legislation. This release is one part of a push on the EU Child Sexual Abuse Regulation: the IWF launched a campaign to EU citizens and MEPs on 14 September 2026, ahead of negotiations. None of that is a reason to doubt that analysts assessed 6,310 images. It is a reason to read each figure for what it counts, and to note that no independent audit of the 2026 count was found.

What UK law does today, and what is enacted but not in force

The Guardian says the government "has also made it illegal to adapt an AI model" to create abuse material, with up to five years for developing a model designed to produce hyper-realistic material. The Crime and Policing Act 2026, which received Royal Assent on 29 April 2026, does create an offence of that kind. On legislation.gov.uk at 08:00 BST on 5 October 2026, section 72 is marked prospective, with the note that it was "not in force at Royal Assent". Most of the Act starts on a day the Secretary of State appoints (section 255). Three sets of commencement regulations have been made, on 25 June, 25 August and 2 September 2026. None lists section 72. Nobody can be charged under it today, on the evidence of those pages. A commencement order could change that at any time, so check before relying on this.

Legal tools relevant to AI-generated abuse imagery, status at 08:00 BST on 5 October 2026

  1. Provision
    Protection of Children Act 1978, s.1 and s.6
    Status
    In force. Section 7 stated up to date to 5 Oct 2026
    What it does
    Making, distributing or possessing with a view to distributing indecent photographs or pseudo-photographs of a child. Up to 10 years on indictment
  2. Provision
    Coroners and Justice Act 2009, s.62
    Status
    In force
    What it does
    Possession of prohibited (non-photographic) images of children
  3. Provision
    Crime and Policing Act 2026, s.72 (Sexual Offences Act 2003, s.46A)
    Status
    Enacted 29 Apr 2026. Prospective. No commencement regulation found
    What it does
    Offence to make or adapt, or to possess, supply or offer to supply, a thing made or adapted for creating such images. Up to 5 years on indictment
  4. Provision
    Same Act, s.73 and s.74
    Status
    Northern Ireland and Scotland versions, started by separate orders
    What it does
    Equivalent offences. Devolved start dates not checked
  5. Provision
    Same Act, s.99
    Status
    In force 29 Jun 2026
    What it does
    Offence to make or supply a thing for creating purported intimate images of a person. The Explanatory Notes say it does not cover children
  6. Provision
    Same Act, s.111 and s.112
    Status
    In force 29 Jun 2026, but only a power
    What it does
    Lets the Secretary of State authorise technology testers and give them a defence, by regulations. No regulations found
  7. Provision
    Online Safety Act 2023, s.66 and SI 2026/268
    Status
    In force 7 Apr 2026
    What it does
    Regulated user-to-user services must report child sexual exploitation and abuse content to the NCA, with a retention rule
  8. Provision
    Ofcom Illegal Content Code, ICU C9 and C10
    Status
    In force 17 Mar 2025
    What it does
    Perceptual hash matching and URL matching for services in scope
  9. Provision
    Same Act, s.248 (Online Safety Act s.216A) and s.249
    Status
    In force 29 Apr 2026. Power not yet used
    What it does
    Lets the Secretary of State extend illegal content duties to AI services. Progress report or draft regulations due by 31 Dec 2026
A status board of UK legal tools at 08:00 BST on 5 October 2026 in three columns. In force: Protection of Children Act 1978 offences, Online Safety Act reporting to the NCA from 7 April 2026, Ofcom hash matching code from 17 March 2025, and section 99 from 29 June 2026. Enacted, not in force: the section 72 image-generator offence. Powers not yet used: the section 111 testing defence and the section 248 AI services power. Three dated markers follow.
Drawn from legislation.gov.uk, the three Crime and Policing Act 2026 commencement regulations, Ofcom's pages and the EU Digital Omnibus text, as read on 5 October 2026.

Three phrases in the Guardian's paragraph need care. First, "has made it illegal": enacted, not commenced. The offences that apply to images today are the 1978 and 2009 provisions, and the 1978 Act carries up to ten years against up to five for the model offence. Second, "a model designed to produce hyper-realistic" material: the statute does not use those words. Section 46A catches a thing "made or adapted for use for creating, or facilitating the creation of" such images, and "thing" includes "a program, information in electronic form and a service". The Explanatory Notes say this captures models optimised to create abuse material and also "wider technologies that can be used to create this content, such as CGI programmes". The government's factsheet says the offence "will not criminalise AI developers" and is aimed at offenders who optimise models for this purpose. Whether a general-purpose image tool is caught turns on whether it was made or adapted for that use. An online safety commentator calls that unclear, and no court has tested it. Third, "up to five years": that is on conviction on indictment. A director or manager who consents to or connives at an offence by a company also commits it (section 46C).

The government's own route for AI services is separate. Section 248 inserted a power into the Online Safety Act so that the Secretary of State can, by regulations, impose illegal content duties and the NCA reporting duty on AI services. GOV.UK's press release of 15 February 2026, filed under the 2024 to 2026 Labour government, promised to "move fast to shut a legal loophole". The IWF's 10 August release refers to "a new Government". The Guardian reports that the current government has not signalled an AI bill, and that the AI minister said nothing is off the table. A bill is not the only route. Section 249 requires a progress report by 31 December 2026, 87 days from 5 October, unless draft regulations are laid first. No draft regulations were found.

What Ofcom expects, and where its reach stops

Ofcom said on 3 February 2026 that chatbots are outside the Online Safety Act if they only let a person interact with the chatbot and no other users, do not search multiple websites or databases, and cannot generate pornographic content. Images a chatbot creates without searching are not generally in scope, unless they are pornographic, in which case they must be age-gated, or can be shared with other users. Ofcom added that it was "currently unable to investigate the creation of illegal images by the standalone Grok service in this case". That is the gap the section 248 power is meant to close, and it is open today.

If your service has UK links and lets users share what a tool creates, or is a search service, the illegal content duties apply. In practice that means an illegal content risk assessment, updated before a significant change, and the Illegal Content Codes of Practice in force since 17 March 2025. Measure ICU A2 asks every service to name an individual accountable for illegal content safety duties. Measure ICU C9 recommends perceptual hash matching of images communicated publicly, for services at high risk of image-based abuse material that have more than 700,000 monthly UK users or are file-storage and file-sharing services, and for large services (more than 7 million monthly UK users) at medium or high risk. The hash set must come from an expert source that identifies material correctly and keeps its database up to date. ICU C10 does the same for listed URLs. Ofcom can fine up to 18 million pounds or 10 per cent of qualifying worldwide revenue, whichever is greater.

Ofcom has used this. On 13 October 2025 it reported that two file-sharing services it had identified as concerning deployed perceptual hash-matching after its enforcement programme, and it took no further action against them at that time. It opened a formal investigation into X on 12 January 2026 over sexualised imagery made through Grok. At the last Ofcom update I read, of 3 February 2026, that investigation was ongoing, and I found no published outcome.

Hash matching only stops what has already been identified. The IWF's release says so itself: new content has no existing hash until someone has assessed it. Ofcom proposed in June 2025 that services at the applicable risk level deploy proactive technology to detect unknown image-based material as well. That consultation is marked Pending Statement. In its statement of 18 May 2026, updated 9 September, Ofcom said it expects to publish its decision on those other measures in autumn 2026. Until then, detecting new AI-generated material is not a measure in Ofcom's Codes, so a service that meets ICU C9 has met the Code and still has no recommended measure aimed at new AI-generated images that no hash list has seen.

The EU adds a date. Regulation (EU) 2026/1744 inserts Article 5(1)(bb) into the AI Act from 2 December 2026, 58 days from 5 October. It prohibits placing on the market, putting into service or using an AI system that generates or manipulates child sexual abuse material, where that is the intended purpose or where it is a reasonably foreseeable and reproducible outcome and the system lacks reasonable and adequate safeguards. The recital lists safeguard types: data cleaning, refusal training, safe prompt design, output controls, content classification and filtering, usage restrictions, abuse detection and notice and action. It also says the prohibition should not prevent legitimate red-teaming and evaluation. An earlier briefing on the AI Act sets out the application dates. A UK organisation placing a system on the EU market is in scope of that date.

What a UK organisation that builds, hosts or deploys image tools should have in place

This is general advice, not legal advice, in the order worth doing. It assumes you run or supply a tool that can generate or host images. Which of the legal duties above reach you depends on the design of your service, and the dividing lines are set out in the Ofcom section. One principle runs through all of it, and an earlier briefing on an Ofcom age-assurance case makes the point: a vendor's tool does not move the legal duty. It stays with you.

Take this with you

Six things to have, in order

  • Safety-by-design evidence, written before launch and kept current: what keeps abuse material out of training data and out of outputs, what filters, refusals and usage limits exist, who signed it, and what changed since. Do not test by trying to generate the material yourselves. Creating such an image is itself within section 1 of the 1978 Act, and no testing defence for developers was found in force. The section 111 power needs regulations that were not found. Take legal advice on an authorised route.
  • Hash matching for known material, and a plan for the unknown. Use a hash list from an expert source on uploads and inputs, such as the IWF Image Hash List through IWF membership. The IWF sells that service, so weigh its interest; Ofcom's Code requires an expert source, not a particular one. The Code expects this of services in scope. Hash lists cannot see a new image, so test a classifier, record its false-positive rate, and watch for Ofcom's autumn 2026 decision. The duty stays with you, not the vendor.
  • Reporting routes, tested. A report route for users, a monitored address for outsiders, the IWF's anonymous report page and the police. If you run a regulated user-to-user service, register with the NCA before you need to report: a senior manager or equivalent as organisation administrator, current contacts, and a response to NCA requests within 7 days.
  • Retention and legal hold, written down before an incident. The rule for staff is do not copy it, do not forward it, report it to the IWF and the police. If section 66 applies to you, regulation 8 of the 2026 regulations sets one year for the reported content and related data and five years for the report reference. Take legal advice on how that sits with data protection before anyone builds a store for it.
  • Staff welfare and escalation: a named owner, a clear route from the first person who sees something to that owner, and occupational health support arranged before it is needed. List who could be exposed, including moderators, support staff and engineers on call. The IWF's methodology page says it limits what it records on videos to protect its assessors, which shows the principle.
  • Contact made before the incident: an IWF membership enquiry, NCA registration if section 66 applies, your own counsel, and a named person who can reach each of them. Keep contact details current.

What could not be verified

The question this leaves

A hash list stops what someone has already seen, and the IWF's count is of images that a person had to see first. The first six months of 2026 already sit 40 per cent above all of 2025. So when the first image your service produces or hosts is one that no list has ever fingerprinted, what in your service catches it, and who has signed the evidence that it works?

Key facts

Sources

  1. PrimaryIWF news release of 5 October 2026, read in full: the 6,310 count for 1 January to 30 June 2026, the 4,512 figure for 2025, the age, sex and category breakdowns, the statement that hashes only stop known material, and the call for the EU Child Sexual Abuse RegulationInternet Watch Foundationaccessed 2026-10-05
  2. Primary2025 Data and Insights Report, AI-generated images page: the 4,586 total for 2025, the 81 prohibited images, the 180 grid images, the category and age shares, and the statement that figures may not represent unique individualsInternet Watch Foundationaccessed 2026-10-05
  3. Primary2025 Data and Insights Report, emerging harms page: 8,029 AI images and videos in 2025, 3,443 AI videos against 13 in 2024, the statement that the video total is influenced by where analysts look and what the public reports, and the IWF policy position on safe-by-design requirementsInternet Watch Foundationaccessed 2026-10-05
  4. Primary2025 report methodology: what a report, URL, image and hash are, the statement that one changed pixel gives a new hash, the Sentencing Council categories, and the definition of assessedInternet Watch Foundationaccessed 2026-10-05
  5. PrimaryIWF 2026 AI report page: the 8,029 total for 2025 and the IWF statement of the February 2025 introduction of the image-generator offence in the Crime and Policing BillInternet Watch Foundationaccessed 2026-10-05
  6. PrimaryIWF news release of 10 August 2026 on the Report Remove helpline: 420 reports in the first six months of 2026 against 397 in 2025, 268 actioned against 221, and the reference to a new GovernmentInternet Watch Foundationaccessed 2026-10-05
  7. PrimaryIWF news index read on 5 October 2026: the release is the only item that day, and the 14 September 2026 campaign to EU citizens and MEPs ahead of Child Sexual Abuse Regulation negotiationsInternet Watch Foundationaccessed 2026-10-05
  8. PrimaryIWF membership page for generative AI model providers: the Image Hash List and the stated use of it to stop known images being uploaded to AI tools; read as a commercial offer from the IWFInternet Watch Foundationaccessed 2026-10-05
  9. PrimaryIWF services page: the Image Hash List, Keywords List, URL List and Takedown Notices offered to membersInternet Watch Foundationaccessed 2026-10-05
  10. PrimaryIWF anonymous reporting page, which states that AI-generated and drawn child sexual abuse images can be reportedInternet Watch Foundationaccessed 2026-10-05
  11. PrimaryCrime and Policing Act 2026 section 72, read in full on 5 October 2026: new Sexual Offences Act 2003 sections 46A to 46C, the make or adapt offence, the possess, supply or offer offence, the defences, the 5 year maximum, and the status marked prospective with 'not in force at Royal Assent'legislation.gov.ukaccessed 2026-10-05
  12. PrimaryCrime and Policing Act 2026 section 255 on commencement, read in full: most provisions start on a day the Secretary of State appoints, with sections 108 to 112 starting two months after Royal Assent, and section 248 starting at Royal Assentlegislation.gov.ukaccessed 2026-10-05
  13. PrimaryCrime and Policing Act 2026 (Commencement No.1 and Saving Provision) Regulations 2026, SI 2026/689, made 25 June 2026: section 99 and others from 29 June 2026; sections 72, 75 and 77 are not listedlegislation.gov.ukaccessed 2026-10-05
  14. PrimaryCrime and Policing Act 2026 (Commencement No. 2) Regulations 2026, SI 2026/939, made 25 August 2026: section 139 onlylegislation.gov.ukaccessed 2026-10-05
  15. PrimaryCrime and Policing Act 2026 (Commencement No. 3 and Saving Provisions) Regulations 2026, SI 2026/960, made 2 September 2026: provisions from 21 September, 29 September, 26 October and 29 October 2026; sections 72, 75 and 77 are not listedlegislation.gov.ukaccessed 2026-10-05
  16. PrimaryCrime and Policing Act 2026 section 111, the technology testing defence: a power for the Secretary of State to make regulations authorising testers, in force at 29 June 2026 per its commencement notelegislation.gov.ukaccessed 2026-10-05
  17. PrimaryCrime and Policing Act 2026 section 112, the list of relevant offences for the technology testing defence, including Sexual Offences Act 2003 section 46A and Protection of Children Act 1978 section 1legislation.gov.ukaccessed 2026-10-05
  18. PrimaryCrime and Policing Act 2026 section 248, inserting Online Safety Act 2023 section 216A: the Secretary of State's power to extend illegal content duties and CSEA reporting to AI services by regulations; in force at Royal Assentlegislation.gov.ukaccessed 2026-10-05
  19. PrimaryCrime and Policing Act 2026 section 249: a progress report on section 216A regulations by 31 December 2026, unless a draft statutory instrument is laid firstlegislation.gov.ukaccessed 2026-10-05
  20. PrimaryExplanatory Notes to the Crime and Policing Act 2026, sections 72, 99, 111 and 112: the reading that the definition captures models optimised to create abuse material and wider technologies such as CGI programmeslegislation.gov.ukaccessed 2026-10-05
  21. PrimaryProtection of Children Act 1978 section 1: offences of taking, making, distributing or possessing with a view to distributing indecent photographs or pseudo-photographs of a childlegislation.gov.ukaccessed 2026-10-05
  22. PrimaryProtection of Children Act 1978 section 7, stated up to date to 5 October 2026: the definition of a pseudo-photograph as an image which appears to be a photographlegislation.gov.ukaccessed 2026-10-05
  23. PrimaryProtection of Children Act 1978 section 6: up to ten years on conviction on indictmentlegislation.gov.ukaccessed 2026-10-05
  24. PrimaryCoroners and Justice Act 2009 section 62, possession of prohibited images of children, the framework for non-photographic images; the explicit definition is not reproduced in this briefinglegislation.gov.ukaccessed 2026-10-05
  25. PrimaryOnline Safety (CSEA Content Reporting by Regulated User-to-User Service Providers) Regulations 2026, SI 2026/268, in force 7 April 2026: registration with the NCA, the senior manager as organisation administrator, priority levels and time frames, the 7 day response rule and the retention rule in regulation 8legislation.gov.ukaccessed 2026-10-05
  26. PrimaryOnline Safety Act 2023 (Commencement No. 7) Regulations 2026, SI 2026/262: section 66 reporting duty in force on 7 April 2026 for regulated user-to-user serviceslegislation.gov.ukaccessed 2026-10-05
  27. PrimaryCrime and Policing Act 2026 child sexual abuse material factsheet, published 11 May 2026 and last modified 30 September 2026: the government's description of the image-generator offence, its statement that the offence will not criminalise AI developers, and the technology testing defenceHome Office and Ministry of Justice (GOV.UK)accessed 2026-10-05
  28. PrimaryPress release of 15 February 2026, filed under the 2024 to 2026 Labour government: the commitment to move fast to bring AI chatbot providers under the illegal content duties and the amendment to the Crime and Policing BillGOV.UKaccessed 2026-10-05
  29. PrimaryOfcom update of 3 February 2026 on its investigation into X and the limits of the Online Safety Act for chatbots: which chatbots and which generated images are outside the Act, and Ofcom's statement that it could not investigate creation of illegal images by the standalone serviceOfcomaccessed 2026-10-05
  30. PrimaryOfcom explainer of 18 December 2025 on AI chatbots and the Online Safety Act: the three service types in scope and the conditions under which a chatbot is not regulatedOfcomaccessed 2026-10-05
  31. PrimaryOfcom release of 12 January 2026, updated 15 January: the formal investigation into X, the duties under examination, and the maximum penalty of 18 million pounds or 10 per cent of qualifying worldwide revenueOfcomaccessed 2026-10-05
  32. PrimaryIllegal Content Codes of Practice for user-to-user services, issued 24 February 2025 and in force 17 March 2025: measures ICU A2, C9 and C10, and the definition of a large service as more than 7 million monthly active UK usersOfcomaccessed 2026-10-05
  33. PrimaryOfcom enforcement update of 13 October 2025: two file-sharing services deployed perceptual hash-matching after Ofcom's programme, and the 20,000 pound fine on 4chan for ignoring information requestsOfcomaccessed 2026-10-05
  34. PrimaryOfcom consultation page on additional safety measures, published 30 June 2025, closed 20 October 2025, status Pending Statement, last updated 12 May 2026Ofcomaccessed 2026-10-05
  35. PrimaryAdditional Safety Measures consultation document: paragraph 9.22 proposing proactive technology to detect unknown image-based child sexual abuse material that hash matching does not captureOfcomaccessed 2026-10-05
  36. PrimaryOfcom statement on detecting intimate image abuse, published 18 May 2026 and updated 9 September 2026: the statement that Ofcom expects to publish its decision on the other additional safety measures in autumn 2026Ofcomaccessed 2026-10-05
  37. PrimaryOfcom discussion paper page, Red Teaming for GenAI Harms, 23 July 2024: it states that it does not constitute official guidanceOfcomaccessed 2026-10-05
  38. PrimaryRegulation (EU) 2026/1744, the Digital Omnibus on AI: new Article 5(1)(bb) and Article 5(1a), the 2 December 2026 application date, and the recital listing safeguard types and the red-teaming carve-outFuture of Life Institute, reproducing the Official Journal textaccessed 2026-10-05
  39. Reported byNews report of 5 October 2026 (06.00 BST, last modified 06.01) used as the pointer for the story: the 'this year' and 'first half of 2026' time frames, the quotes attributed to the IWF head of policy, the AI minister and a government spokesperson, and the offence descriptionThe Guardianaccessed 2026-10-05
  40. Reported byCommentary on the Crime and Policing Act 2026 from an online safety perspective: used only for its observation that it is unclear whether the image-generator offence reaches tools not designed or adapted for the purposeOnline Safety Networkaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.