Meta has taken steps to address Child Sexual Abuse Material (CSAM) concerns following tough engagement with the Indian government, which has made clear that safe harbour protections under the Information Technology Act, 2000 (IT Act) will not extend to platforms if Indian laws are violated.
Senior sources in the Ministry of Electronics and Information Technology (MeitY) said the government’s firm stance has produced tangible results, with Meta demonstrating greater sensitivity and taking concrete action on the CSAM issue. Officials underlined that New Delhi’s position is simple: such content is illegal under Indian law, and platforms risk losing safe harbour protections if they do not prevent or remove it.
The developments follow a series of investigations that exposed gaps in Meta’s advertising and recommendation systems.
What the Investigations Found
In early July 2026, a BBC Eye investigation revealed that Instagram had been running paid advertisements promoting child sexual abuse material in India, with some linking users to Telegram channels where such material was sold. About 30 unique advertisements promoting child sexual abuse were identified across multiple accounts.
Critically, the BBC’s test demonstrated how recommendation systems contributed to the problem. Researchers set up an alias Instagram account in India and followed 10 profiles pushing sexually suggestive content. Within days, Instagram’s algorithm began showing the account paid advertisements featuring explicit adult content — and shortly after, advertisements promoting CSAM.
Meta says every advertisement is reviewed before publication through a system that relies primarily on automated technology, with cases escalating for human review when the software is uncertain. Yet in this instance, the offending advertisements passed through the review process.
On August 5, a WIRED investigation reported that Meta had run dozens of paid advertisements containing AI-generated CSAM across Facebook, Instagram, Messenger and Threads over a nine-month period. The Tech Transparency Project identified more than 50 such advertisements in Meta’s own public Ad Library, some reaching thousands of users across Europe and the United States before removal.
In the US, Senator Mark Warner wrote to Meta CEO Mark Zuckerberg citing both investigations, noting it “strains credulity” that Meta was unknowingly hosting and profiting from such content given its stated policy of reviewing all advertisements before publication.
India’s Response
In early July, the government directed Instagram to disable all advertisements and content promoting or facilitating access to CSAM, demanding a detailed explanation within seven days. The National Human Rights Commission directed Delhi Police to investigate whether Meta complied with mandatory reporting obligations under the Protection of Children from Sexual Offences Act, 2012, while the National Commission for Protection of Child Rights launched a separate inquiry.
Engagement intensified through early August, culminating in meetings between Meta officials and IT Secretary S. Krishnan on August 5, followed by discussions with IT Minister Ashwini Vaishnaw. According to reports, Meta CEO Mark Zuckerberg apologised for the presence of CSAM and other operational lapses on the company’s platforms.
Officials made clear that Meta cannot claim “intermediary” status under the IT Act if its systems actively determine what content users receive, and that safe harbour protections may not apply where algorithms recommend or amplify illegal content rather than merely host it.
The Broader Shift
The controversy reflects a global shift in how regulators approach online safety. While swift removal of illegal content remains a priority, increasing attention is being directed at whether recommendation and advertising systems are themselves contributing to its spread — a distinction with significant legal consequences. Earlier this month, a court in New Mexico found that Meta’s platforms created a public nuisance by exposing children to harm, ordering the company to pay $567 million — in addition to $375 million in civil penalties a jury had awarded in March for misleading users about platform safety. The court rejected Meta’s claim of immunity under Section 230 of the US Communications Decency Act (47 U.S.C. § 230) on the grounds that the case targeted Meta’s own product design and algorithmic choices, not third-party content it merely hosted. It also ordered extensive reforms that will remain in effect for five years, requiring enhanced protections against child sexual exploitation, including tougher enforcement against offending adult accounts.
In India, MeitY’s recent amendment to the IT Rules — reducing the content takedown window for intermediaries from 36 hours to 3 hours — signals a tightening regulatory posture. But the CSAM controversy suggests the debate may need to move further: beyond takedown timelines to greater scrutiny of the systems platforms use to review, approve, recommend and monetise content in the first place.