News

Meta’s Safe Harbour Shield Under Scrutiny Over CSAM Concerns

Meta has taken steps to address Child Sexual Abuse Material (“CSAM”) concerns following tough engagement with the Indian government, which has made clear that safe harbour protections under the Information Technology Act, 2000 (“IT Act”) will not extend to platforms if Indian laws are violated.

Senior sources in the Ministry of Electronics and Information Technology (“MeitY”) said the government’s firm stance has produced tangible results, with Meta demonstrating greater sensitivity and taking concrete action on the CSAM issue. Officials underlined that New Delhi’s position is simple: such content is illegal under Indian law, and platforms risk losing safe harbour protections if they do not prevent or remove it.

The developments follow a series of investigations that exposed gaps in Meta’s advertising and recommendation systems.

What the Investigations Found

In early July 2026, a BBC Eye investigation revealed that Instagram had been running paid advertisements promoting child sexual abuse material in India, with some linking users to Telegram channels where such material was sold. About 30 unique advertisements promoting child sexual abuse were identified across multiple accounts.

Critically, the BBC’s test demonstrated how recommendation systems contributed to the problem. Researchers set up an alias Instagram account in India and followed 10 profiles pushing sexually suggestive content. Within days, Instagram’s algorithm began showing the account paid advertisements featuring explicit adult content — and shortly after, advertisements promoting CSAM.

Meta says every advertisement is reviewed before publication through a system that relies primarily on automated technology, with cases escalating for human review when the software is uncertain. Yet in this instance, the offending advertisements passed through the review process.

On August 5, a WIRED investigation reported that Meta had run dozens of paid advertisements containing AI-generated CSAM across Facebook, Instagram, Messenger and Threads over a nine-month period. The Tech Transparency Project identified more than 50 such advertisements in Meta’s own public Ad Library, some reaching thousands of users across Europe and the United States before removal.

In the US, Senator Mark Warner wrote to Meta CEO Mark Zuckerberg citing both investigations, noting it “strains credulity” that Meta was unknowingly hosting and profiting from such content given its stated policy of reviewing all advertisements before publication.

India’s Response

In early July, the government directed Instagram to disable all advertisements and content promoting or facilitating access to CSAM, demanding a detailed explanation within seven days. The National Human Rights Commission directed Delhi Police to investigate whether Meta complied with mandatory reporting obligations under the Protection of Children from Sexual Offences Act, 2012 (“POCSO Act”), while the National Commission for Protection of Child Rights launched a separate inquiry.

Engagement intensified through early August, culminating in meetings between Meta officials and IT Secretary S. Krishnan on August 5, followed by discussions with IT Minister Ashwini Vaishnaw. According to reports, Meta’s CEO apologised for the presence of CSAM and other operational lapses on the company’s platforms.

Safe Harbour: Conditional by Design

Safe harbour under Section 79 of the IT Act is not unconditional — it is subject to a set of requirements under the provision, including that the intermediary’s function remains limited to providing access to a communication system, or that it does not select the receiver of the transmission or modify the information.[1] It must also observe due diligence,[2] which includes compliance with the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“IT Rules”). Under the IT Rules, intermediaries are required to make reasonable efforts to ensure that content that is obscene, pornographic, paedophilic, or harmful to children is not hosted, displayed, or transmitted on its platform.[3] The February 2026 amendments to the IT Rules now extend these obligations to AI-generated content — requiring all intermediaries to deploy reasonable and appropriate technical measures to prevent unlawful synthetically generated information.[4] Significant social media intermediaries (“SSMIs”) face additional obligations, including obtaining user declarations and undertaking technical verification before publishing SGI, and ensuring its prominent labelling.[5] This is particularly relevant given the WIRED investigation’s finding that Meta ran paid advertisements containing AI-generated CSAM across its platforms. In its judgment dated 23 September 2024, the Supreme Court further held that safe harbour is unavailable unless the intermediary also complies with the mandatory reporting obligations under the POCSO Act — treating such compliance as integral to the due diligence requirement.[6]

Instagram’s recommendation engine and its algorithmic targeting of advertisements to specific user profiles involve active decisions about content distribution — a role that may be difficult to reconcile with the functional conditions of the safe harbour framework. Where CSAM advertisements cleared Meta’s review system and reports of such content were dismissed as not violating community standards, questions arise as to whether the platform has met its obligations under Section 79.

The Broader Shift

The controversy reflects a global shift in how regulators approach online safety. While swift removal of illegal content remains a priority, increasing attention is being directed at whether recommendation and advertising systems are themselves contributing to its spread — a distinction with significant legal consequences. Earlier this month, a court in New Mexico found that Meta’s platforms created a public nuisance by exposing children to harm, ordering the company to pay $567 million — in addition to $375 million in civil penalties a jury had awarded in March for misleading users about platform safety. The court rejected Meta’s claim of immunity under Section 230 of the US Communications Decency Act (47 U.S.C. § 230) on the grounds that the case targeted Meta’s own product design and algorithmic choices, not third-party content it merely hosted. It also ordered extensive reforms that will remain in effect for five years, requiring enhanced protections against child sexual exploitation, including tougher enforcement against offending adult accounts.

In India, MeitY’s recent amendment to the IT Rules — reducing the content takedown window for intermediaries from 36 hours to 3 hours — signals a tightening regulatory posture. But the CSAM controversy suggests the debate may need to move further: beyond takedown timelines to greater scrutiny of the systems platforms use to review, approve, recommend and monetise content in the first place.

 


References:

[1] Section 79(2)(a) and (b), Information Technology Act, 2000.

[2] Section 79(2)(c), Information Technology Act, 2000.

[3] Rule 3(1)(b)(ii), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

[4] Rule 3(3)(a)(i), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

[5]  Rule 4(1A), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

[6] Just Rights for Children Alliance & Anr. v. S. Harish & Ors., Criminal Appeal Nos. 2161-2162 of 2024, Supreme Court of India, decided on 23 September 2024.