Public Policy Is Moving Too Slowly to Protect Children from AI

Technology advances exponentially while public policy advances … glacially.

While Congress continues to debate how best to regulate an industry that has been allowed to run amok for nearly two decades, technologists continue to push ahead with increasingly powerful AI systems, even as the executives and engineers who built them worry they “could kill us all by the end of the decade.”

Are our public institutions prepared to meet the moment? Or will they remain trapped in regulatory frameworks built for a technological era that no longer exists? The answer matters because the greatest threat these technologies pose might not be to our survival, but to our humanity.

Consider recent reports that Meta failed to stop hundreds of paid advertisements containing suspected AI-generated child sexual abuse imagery from running across its platforms.

According to the Tech Transparency Project (TTP), “Meta says it reviews ads before they run to ensure they meet the company’s advertising standards, which prohibit ‘content that sexually exploits or endangers children.’ These reviews can encompass images, videos, and text as well as advertising link destinations, Meta says. But TTP found 332 CSAM [child sex abuse material] ads that made it through Meta’s review process.”

Many of those AI-generated CSAM images involved real children, including a member of a European royal family, and were used to promote AI image and video tools capable of creating nonconsensual intimate imagery.

Bear in mind, this reporting comes just weeks after Meta settled a $16.7 billion lawsuit brought by several state attorneys general over alleged harms to children and less than a month after a New Mexico court ordered Meta to pay $567 million in civil penalties and implement extensive youth-safety measures, in addition to a separate $375 million jury penalty in the same case. So Meta was already facing intense scrutiny for business practices that resulted in harm to minors.

This is where the conflict really lies. Whatever their public posture, these tech companies have consistently prioritized profit over child safety, and the public policy response has been, “Well, we don’t want to hamper innovation and growth with burdensome regulations.”

Why on earth not? Meta’s current market valuation is $1.6 trillion. When the settlement was announced, the stock rose roughly 2%, adding about $30 billion in market value, nearly twice the cost of the settlement itself. Meta came out ahead. Can we really say the company was meaningfully punished?

With Congress dragging its feet on a Kids Online Safety bill, states are looking to the courts to restore balance, but that too has its limits, especially in the area of AI-generated intimate images.

The U.S. Court of Appeals for the Seventh Circuit ruled in August that the First Amendment protects the private possession of AI-generated child sexual abuse images that do not depict real people, citing as precedent Ashcroft v. Free Speech Coalition (2002), which found that virtual CSAM not depicting a real person is not “child pornography” and cannot be prohibited on the same basis as real‑child abuse material, and Stanley v. Georgia (1969), which found that individuals have a constitutional right to possess obscene material in the privacy of their home.

In his ruling, Judge John Z. Lee acknowledged that technological advances complicate existing legal precedent, stating, “Given the ever-accelerating march of imaging-generation technology, we have some misgivings about applying Free Speech Coalition here, but ‘unless we wish anarchy to prevail within the federal judicial system,’ we are dutybound to follow it,” and urged the Supreme Court to reconsider the issue of virtual abuse material of children in the age of AI.

These stories highlight problems created by the widening gap between our public policy and technological advancement.

We are entering a new era in which horrific images of exploitation and abuse have never been easier to create, customize, and distribute. The argument that no “real” child is harmed by a synthetic image collapses under the weight of what these tools actually do: normalize the sexualization of children, provide predators with endless material tailored to their preferences, and make it harder for law enforcement, parents, and platforms to distinguish fabricated images from images documenting real abuse.

Nor should AI-generated abuse material be treated as some sort of ethical substitute for pornography involving real victims. Pornography use, like other compulsive behaviors, can be progressive in nature: repeated exposure can dull the user’s response and drive some users toward increasingly extreme or transgressive content. AI does not interrupt that cycle, it pours fuel on the fire by removing risk, expanding supply, and giving users the ability to generate precisely the kind of material that existing law and social norms have long sought to suppress.

Ashcroft v Free Speech Coalition was decided in a world where “virtual” imagery was relatively crude, costly, and easy to distinguish from the real thing. Today, generative AI can produce realistic images on demand and at scale. The Supreme Court should revisit that precedent, recognizing that the courts cannot keep applying twentieth-century precedents to twenty-first-century tools as if nothing material has changed.

But courts alone cannot solve this. Congress also needs to put strict guardrails around the use of AI in the creation of explicit images, especially where minors, real people’s likenesses, or nonconsensual intimate imagery are involved. At minimum, companies that build and distribute these tools should be required to maintain robust safeguards, prevent known abuse cases, preserve evidence for law enforcement, and face meaningful consequences when they knowingly or recklessly enable illegal uses.

We should want American entrepreneurs to build, compete, and lead in the next generation of technology. But innovation is not a license to externalize foreseeable harms onto children, families, and society at large. Nor should companies be allowed to hide behind blanket immunity when their own products generate the harmful content at issue. Section 230 was designed to protect platforms from being treated as the publisher of material created by third parties. It was not designed to immunize companies from responsibility for products they design, deploy, and monetize.

A product-liability approach offers a reasonable middle ground: if it is foreseeable that a tool can be used to create illegal or devastatingly harmful explicit material, then the company offering that tool should be expected to build reasonable safeguards into it.

Unfortunately, many companies appear to be moving in the opposite direction, loosening restrictions on explicit content, marketing flirtatious or sexualized chatbots, and prioritizing engagement over safety. That is precisely why voluntary promises are not enough.

If technology continues to advance exponentially while public policy moves glacially, the costs will be borne by the most vulnerable people that those technologies make easier to exploit.

Related