When the Ad System Becomes the Threat: Meta Caught Monetizing Child-Abuse Ads
A BBC investigation found that Instagram ran and profited from paid ads promoting the sale of child sexual abuse material in India, funnelling users to off-platform channels.
- Privacy
- Trust & Safety

Bottom line. This is a systems failure, not a stray post. A BBC investigation found that Meta’s ad platform approved, delivered and earned money from paid adverts promoting child sexual abuse material (CSAM) in India, with the ads routing users to external messaging channels where illegal material was sold. The failure sits in the ad-review and monetization pipeline, and it coincides with Meta’s 2026 move to lean on AI in place of human moderators. Regulators and courts are now responding: India’s IT ministry issued a formal notice, and a US jury already found Meta misled users about child safety on its platforms. The lesson for every organization is blunt: automated-only trust-and-safety leaves gaps that adversaries and criminal networks monetize, and ‘report it after it runs’ is not a control.
Background
A BBC investigation reported that Instagram profited from paid advertisements promoting the sale of CSAM in India. Because these were paid ads, the platform did not merely fail to remove organic content, it accepted payment, ran the ads through its approval system, and algorithmically delivered them, before routing interested users to shadowy off-platform messaging channels where material was reportedly sold for as little as one dollar. To avoid amplifying harm, this advisory does not reproduce the ad wording or any of the mechanics involved.
The timing matters. Earlier in 2026 Meta said it would reduce reliance on third-party human moderators and shift toward AI-based review. The BBC findings suggest those automated systems did not catch clearly policy-violating, high-harm ads. Meta told the BBC it had disabled several adverts and suspended the associated accounts, adding that ‘no system is perfect and our review process may not detect all policy violations,’ that it runs proactive detection on ads once they are live, and that anyone can report an ad. Telegram, where much of the linked activity occurred, said it had removed more than 274,000 CSAM-related groups and channels in 2026.
Accountability is already landing. India’s Ministry of Electronics and Information Technology issued a notice ordering Meta to disable the offending ads and content and to provide a detailed explanation within days. Separately, a US jury in New Mexico found in March 2026 that Meta misled users about the safety of its platforms for children and allowed CSAM to proliferate. A former Facebook vice president testified that the platform’s algorithms were built to maximise profit. India, with roughly 1.9 million CSAM reports on a leading tipline, is second only to the United States, underlining the scale of the problem these ad systems intersect with.
What we observed
Why this is a security and privacy story, not just a moderation one:
- The monetization pipeline is the vulnerability: this was paid, reviewed and delivered advertising, so the breakdown is in ad approval and revenue systems, the part of the platform specifically designed to vet what runs.
- Automation replaced the safety net: the failure coincides with Meta’s shift from human moderators to AI review, and automated screening did not stop high-harm, clearly policy-violating ads, the exact edge cases where human judgment matters most.
- Detection lags publication: acting only after journalists flagged the ads, plus the admission that the review process ‘may not detect all policy violations’ and heavy reliance on user reporting, shows harm is caught after money and reach have already been delivered.
- Incentives are the root cause: testimony that the algorithms optimise for profit and engagement means safety competes with revenue by design, and under pressure the trade-off tilts toward revenue.
- Abuse networks weaponise mainstream reach: the ads used a trusted platform as top-of-funnel and pushed users to external channels for the actual transaction, a pattern that mirrors how scams and malware campaigns abuse ad networks for legitimacy and scale.
- Consequences are arriving from multiple directions: a government notice in India and a jury verdict in the US show regulatory and legal accountability is catching up to platform trust-and-safety failures.
How a harmful ad earns money before it is stopped
Every step before ‘flagged and removed’ is monetized and delivered at scale. Moving review earlier, and keeping humans in it, is the only place to break the chain.
Over time, the trade-off of revenue and user experience became a more core part of the conversation. – Brian Boland, former Facebook vice president, testifying about Meta’s algorithms.
Recommendations
- Report, do not engage or investigate: if you encounter suspected CSAM or an ad promoting it, do not click, share, screenshot or try to verify it. Use the in-app report tool and report to the authorities: the NCMEC CyberTipline (report.cybertip.org) in the US, the Internet Watch Foundation (iwf.org.uk) internationally, and India’s National Cyber Crime Reporting Portal (cybercrime.gov.in). Seeking or possessing this material is itself a crime.
- For parents and guardians: use the platforms’ supervision and restricted-account settings for minors, keep apps updated, talk with young users about not engaging with unknown accounts or off-platform links, and treat unsolicited links that push you to Telegram or other side channels as a red flag.
- For platforms and ad networks: keep human reviewers in the loop for high-risk paid-ad categories, review before publication rather than only after ads are live, run independent trust-and-safety audits, and do not treat AI-only moderation as a cost-saving replacement for judgment.
- For organizations and advertisers: audit where your ad spend and brand actually appear (brand-safety and placement transparency), demand accountability from ad platforms, and factor trust-and-safety track record into where you buy reach.
- Treat this as a model, not a one-off: the same pattern, mainstream ad platform as top-of-funnel plus off-platform execution, is used by fraud, malware and disinformation operators, so monitor advertising surfaces as an attack surface, not just an editorial one.



