Social Suit / Online safety

AI Deepfake Images of a Child: Removal, Reporting, and Family Support

A practical guide for families responding to fake explicit images of a child, including evidence, platform removal, FTC complaints, NCMEC reporting, and school support.

Read the guide ↓
A hand holds a smartphone displaying a gallery of photographs against a blue background.
Illustrative stock photograph · Tomáš Hustoles / Burst
Published by Social Suit · Updated October 11, 2026 · 23 minute read

Educational information, not individual medical or legal advice. Practical examples are hypothetical and do not describe clients or study participants. This article is not represented as reviewed by a clinician or attorney. How we prepare our guides.

Treat a fake image as a real safety problem

An AI-generated or digitally altered intimate image can depict a real child in a scene that never occurred. A creator may place the child's face onto another body, alter an ordinary photograph, generate an entirely synthetic image resembling the child, or use a so-called nudify tool. The image can be false while the harassment, humiliation, threats, and circulation are real. A family does not need to prove how the file was made before asking a platform to remove it and reporting suspected child sexual exploitation.

Begin by telling the child that the image does not become true because it looks convincing or because other people repeat a claim about it. Do not interrogate them about whether they secretly created or sent an original. Ask what they know, what they have seen, who contacted them, and whether anyone made a threat or demand. A calm first response helps the child continue sharing new information. Blame can push the problem into hidden accounts and private conversations where support is harder to provide.

NCMEC's generative-AI guidance says altered nude or sexually exploitative images of children should be taken seriously and reported. Its examples include fake imagery used for bullying, peer victimization, online enticement, and sextortion. These are different situations that may require different steps. Describe the conduct precisely: creation, possession, posting, private sharing, impersonation, a money demand, a request for more images, or an offline threat. Avoid assuming that every person who saw the file created it.

If the child is in immediate physical danger or says they may hurt themselves, stay with them and prioritize emergency or crisis support over account work. In the United States, call emergency services for imminent danger or use the 988 Suicide & Crisis Lifeline for suicidal or emotional crisis support. Platform reports and evidence notes can wait while immediate safety is protected. No image, rumor, or threat is more urgent than keeping the child alive and connected to a trusted person.

Use the first hour to stop unnecessary spread

Ask the child not to reply publicly, argue about whether the image is fake, pay anyone, send another photograph, or click a removal link supplied by the harasser. Put the device on silent if messages are arriving rapidly. A pause prevents an anxious response from exposing more personal information or drawing a larger audience to the post. The family can preserve essential identifiers and use official reporting routes without debating the creator in a comment thread.

Record the account name, profile link, post URL, platform, date, approximate time, caption, threats, payment instructions, and names of people who reported receiving it. Capture enough surrounding context to show where the material appeared. Do not ask friends to forward the explicit file or create multiple screenshots containing it. The URL, non-explicit messages, account identifiers, and a factual description may preserve useful information without creating additional copies. Ask NCMEC or law enforcement how to handle the file itself.

Report the content through the platform's route for child sexual exploitation, nonconsensual intimate imagery, or intimate-image abuse. Use the category that fits the conduct rather than a general dislike or spam option. Save the confirmation number and a screenshot of the completed report when safe. If the platform has a dedicated removal form that does not require an account, use it from the platform's official help center rather than a link sent by an unknown person.

Tell one trusted adult who can coordinate the response. That adult can make the CyberTipline report, track platform requests, contact the school, and keep the child informed. The child should not have to tell the complete story to every relative or staff member. A single factual timeline and one point of contact reduce repeated disclosure while keeping responsibilities clear.

A woman holds a smartphone in front of her face.
Pause before replying so the next action protects privacy and preserves useful identifiers.Illustrative stock photograph · Matthew Henry / Burst

Separate evidence from redistribution

Evidence preservation does not mean saving the image everywhere. Write a factual incident log that identifies where the file appeared and what happened around it. Include exact usernames, URLs, dates, messages, threats, and report numbers. Label uncertain information as uncertain. For example, write 'a student said the image was posted in a private group' rather than recording the statement as confirmed publication. This distinction helps platforms, schools, and investigators understand what each person directly observed.

Avoid emailing the image to yourself, uploading it to a shared drive, placing it in a family group chat, or asking another student to send it. Explicit material depicting a child requires careful handling even when it is synthetic. If the original post can be documented without saving the image, preserve the location and context. If authorities need the file, ask them for a lawful, secure transfer method and why it is required. Do not assume an ordinary email attachment is appropriate.

A screenshot that includes the image creates another copy. When possible, capture the username, URL, caption, and surrounding messages without the explicit area. Some apps notify a sender when screenshots are taken, and some content disappears. If capture may alert the person or increase danger, note the details manually and ask authorities for instructions. A perfect technical record is less important than the child's safety and avoiding unnecessary possession or distribution.

Keep the incident log in a place the harasser cannot access. If an account or email may be compromised, use a secure record controlled by the assisting adult or a paper timeline. Limit access to people with a role in the response. Later, ask the investigating agency what material must be retained and what can be deleted. The goal is useful documentation, not a permanent family archive of the child's most private experience.

Request platform removal under current federal rules

The federal TAKE IT DOWN Act applies to certain nonconsensual intimate visual depictions, including qualifying digitally altered and AI-generated material. The FTC's current consumer guidance says covered platforms must offer a process for removal requests and remove covered material, plus known identical copies, within 48 hours after receiving a valid request. The FTC enforces the notice-and-removal requirements. This guide cannot decide whether a particular file, requester, or service meets every legal definition.

Start with the platform that hosts the content. Log in when appropriate and use the report option near the post, or locate the official help-center removal form if no account is available. State that the image depicts a child, is intimate or explicit, was shared without consent, and is AI-generated or altered if known. Provide the direct location and requested information without adding speculation. Save the exact submission time because the federal complaint route asks whether the platform responded within the required period.

A removal request is not the same as a general content complaint. If the first interface offers only broad categories, search the official help center for nonconsensual intimate imagery, child exploitation, or TAKE IT DOWN requests. Keep a record of broken forms, missing options, error messages, or an inability to submit without an account. The FTC says people can report a covered platform when its removal process cannot be found or does not work, as well as when content remains after a valid request.

Do not represent the 48-hour requirement as a promise that every copy everywhere will disappear. A platform can act on material located on its service and known identical copies within its systems. Altered versions, private encrypted transfers, reuploads on another service, or content outside a covered platform may require separate action. File a specific request for each known hosting location and use additional reporting and hash tools where appropriate.

Report a platform problem to the FTC

If a covered platform does not remove the reported intimate image and known identical copies within 48 hours of a valid request, the FTC directs people to TakeItDown.ftc.gov. The FTC also accepts reports when the platform lacks an easy removal process or the process is broken. Record the original removal request, submission time, confirmation, direct URL, platform response, and status after 48 hours. Those facts make the complaint more useful than a general statement that the service failed.

The FTC's October 7, 2026 alert tells parents to report the perpetrator to criminal law enforcement, request platform removal, report a noncompliant covered platform to the FTC, and use NCMEC's Take It Down service to help suppress further sharing. These actions have different purposes. An FTC complaint about platform compliance does not replace a CyberTipline or police report about the person who created or distributed the image.

Give the FTC accurate information about what the family knows. Do not claim the platform created the image unless there is evidence. Do not state that a person is identified when only a username is known. The issue for the complaint is the platform's process and response to a removal request. Keep allegations about the creator in the separate law-enforcement or CyberTipline report, supported by the messages and identifiers available.

Continue using the platform's appeal or safety escalation route while the FTC complaint is pending. Save new confirmation numbers and do not repeatedly submit identical reports every hour. A scheduled follow-up reduces confusion and creates a clear chronology. If the image appears at a new URL or under a new account, treat that as a new location and report it while connecting it to the existing incident record.

Report suspected child exploitation to NCMEC and law enforcement

Families in the United States can report suspected online child sexual exploitation to NCMEC's CyberTipline. NCMEC reviews reports and makes information available to the appropriate law-enforcement agency. State that the content is believed to be AI-generated or altered, identify the child depicted, describe where it appeared, and include threats or demands. Save the CyberTipline confirmation so follow-up information can be connected without rebuilding the report from memory.

Contact local police when the creator or distributor may be local, the incident involves classmates, or there are offline threats. The FBI accepts information at tips.fbi.gov, through local field offices, or at 1-800-CALL-FBI. Explain that the matter involves an explicit synthetic or altered depiction of a minor. Do not minimize it as a joke or school drama merely because the image is fake. The conduct may still involve child exploitation, harassment, coercion, or other offenses.

Provide identifiers and context, not unsupported conclusions. A familiar photograph may have been taken from a public account, a school page, a hacked device, or another source. The person who first sent the image to the child may not be the creator. Record what each account did and what each witness observed. Investigators can determine how identities, devices, and files connect; the family should not impersonate others or access someone else's account to solve the case.

A platform report, FTC complaint, CyberTipline report, and police report can coexist. Keep a single table with the destination, date, confirmation number, requested follow-up, and current status. This prevents the teenager from becoming the case manager and helps adults provide new facts to the right place. It also shows when a task is complete so the family can step away from constant monitoring.

Use Take It Down without obtaining another copy

NCMEC's Take It Down service can create a digital fingerprint, or hash, of an eligible nude, partially nude, or sexually explicit image or video depicting someone when they were under eighteen. The image remains on the user's device; only the hash is sent to NCMEC. Participating public or unencrypted platforms can compare content against the hash and act under their policies. NCMEC says its support can apply to real or generative-AI-created explicit imagery.

Use only a file that is already on the device. Take It Down explicitly says not to send, share, or download an image merely to submit it. If the synthetic image exists only on another person's account or a remote post, do not ask them to forward it. Report the location to the platform and CyberTipline instead, and ask NCMEC for further help. Preventing another transfer is more important than forcing every tool into the response.

Hash matching has limits. A participating platform must use the system, and a substantially modified version may not match the original fingerprint. Private or encrypted communications may not be scanned in the same way as public content. A hash submission therefore supports suppression but does not guarantee universal deletion. Continue reporting known locations and record reuploads without repeatedly searching for the image.

For an adult who was eighteen or older in the image, NCMEC directs people toward StopNCII.org rather than the child-focused Take It Down service. Age is based on the person depicted and the relevant image, not only their age when reporting. When eligibility is unclear, use official support channels and do not send the file to an unofficial removal company for evaluation.

Respond to threats and deepfake sextortion

An offender can threaten to publish a fake explicit image unless the child sends money, real images, account credentials, or additional personal information. NCMEC reports that generative AI has been used in sextortion even when a child refused to send a nude image. The falsity of the image does not make the blackmail harmless. Stop responding, preserve the threat and identifiers, involve a trusted adult, and report through the CyberTipline and appropriate law enforcement.

Do not pay or negotiate privately. Payment does not create a reliable agreement and can lead to repeated demands. If money was already sent, save receipts, transaction IDs, payment handles, wallet addresses, gift-card details, and related messages. Contact the provider promptly and explain that the payment was connected to extortion. Ask whether it can be stopped or flagged, but do not promise recovery to the child.

Do not hire an online service promising guaranteed deletion, retaliation, or identification of the creator. A family in crisis can be targeted by a second scammer. Verify help through official domains and published numbers. Never give an unknown fixer the image, an account password, remote access to a device, or another payment. The FBI warns sextortion victims about for-profit companies that charge for supposed help and directs minor victims to NCMEC resources.

Avoid threatening the offender or pretending to continue the conversation unless law enforcement specifically asks for cooperation. A parent message can expose another account, escalate threats, or interfere with an investigation. Preserve what already exists and shift the work to official reporting routes. Ending the private negotiation removes the offender's ability to dictate the timetable.

Secure the child's accounts and source photographs

Change passwords for affected social-media and email accounts after preserving necessary messages. Use unique passwords and enable multi-factor authentication. Review logged-in devices, recovery email addresses, recovery phone numbers, connected apps, and backup codes. Remove sessions or connections the child does not recognize. These steps reduce the chance that the harasser can impersonate the child, delete evidence, or obtain more photographs.

Review where the source photograph may have been available. It could come from a public profile, a relative's account, a team roster, a school site, a shared album, or a compromised device. Reduce unnecessary exposure by changing audiences, removing public tags, asking an account owner to limit a post, or replacing a public image when practical. Do not assume the child caused the incident by having an ordinary photograph online. The creator is responsible for transforming or abusing it.

Check whether the harasser created impersonation accounts. Search the child's name and common username variations at a planned time, not continuously. Ask close contacts to report new accounts without following, commenting, or requesting the image. A small coordinated check is more useful than a public call for everyone to investigate. Public attention can lead more people to look for the content.

Preserve necessary access to school, trusted friends, and safety contacts. Temporary message restrictions or account deactivation may help, but explain the purpose and review date. Removing every device indefinitely can isolate the child and discourage future disclosure. The security plan should block the harmful route while keeping useful communication available.

Create a careful school response

Contact the school's counselor, principal, safeguarding lead, or other designated official when students created, shared, requested, or received the image, or when circulation affects attendance and safety. Provide a concise written summary without attaching the explicit file. Include known accounts, dates, platforms, threats, and the reports already made. Ask what the school must report, who will receive the information, and how it will protect the child's privacy.

Request specific supports for the next school day: a named adult, a private place to regroup, a plan for leaving class without a public explanation, separation from a suspected student when appropriate, and a route for reporting new distribution. Decide what teachers need to know about attendance or assignments without disclosing unnecessary details. The child should not have to retell the incident to multiple staff members to receive support.

Ask the school to instruct students not to open, save, forward, request, or joke about the image. Recipients can report the account or message and tell an adult while preserving the sender's identifier without copying the explicit content. A broad assembly or parent email can accidentally identify the child through context. Use general prevention education unless a narrower disclosure is necessary and authorized.

Keep discipline questions separate from immediate support. The family may not be entitled to details about another student's consequences, but it can ask what safety measures protect the affected child and how new reports will be handled. Set a follow-up date and document agreed actions. If the plan fails, record the specific new incident or missed support step rather than relying only on general frustration.

A child sits at a white table and looks toward a smartphone.
A school plan should give the child one trusted contact without requiring repeated disclosure.Illustrative stock photograph · Farah / Burst

Guide friends and bystanders not to amplify it

A friend who receives the image should not forward it to prove that it exists, show it to a group, or send it back to the depicted child. They can record the sender's username, the time, and the non-explicit surrounding message, then report it and tell a trusted adult. If the platform allows reporting without downloading, use that route. The helpful action is to stop the chain, not become another keeper of the file.

Friends should avoid public defenses that repeat the rumor, tag the account, or direct people to search for the image. A private message can be enough: 'I received abusive fake content, reported it, and will not share it.' Do not ask the child to prove that the image is fake. Support does not depend on a technical demonstration or a public statement from the child.

If classmates are unsure whether a file is real, the answer is still not to possess or circulate explicit content depicting a child. Authenticity is not a permission test. Report it and allow appropriate adults and authorities to handle the facts. This rule is easier to remember than asking students to inspect pixels, metadata, or visual artifacts in a harmful image.

Follow up with the child through ordinary friendship. Invite them to a normal activity, sit with them at lunch, or help them reach a counselor if requested. Do not make every interaction about the incident or repeatedly ask for updates. Quiet support can reduce isolation without creating another audience for the content.

Avoid unreliable deepfake detection claims

A family may want software to prove instantly that an image is fake. Detection tools can produce uncertain or conflicting results, and a file may have been resized, compressed, edited, or photographed from another screen. Do not delay removal and reporting while searching for a perfect technical verdict. Tell platforms and authorities what is known: the child says the depicted event did not occur, the image appears altered, and the content is being used or shared in a specific way.

Visual clues such as distorted hands, inconsistent lighting, or unusual edges can support a suspicion but are not a universal test. Modern generated images may lack obvious errors, and genuine photographs can contain compression artifacts. Avoid posting a detailed public analysis that republishes the image. An investigator or qualified forensic professional can examine original files and metadata when that is necessary.

Do not use an unfamiliar online detector that requires uploading the explicit image. The upload may create another copy, expose the child to a new service's data practices, or violate the site's terms. Ask law enforcement or counsel whether technical analysis is needed and how the file should be transferred. Removal and safety decisions do not require the family to submit the image to multiple commercial tools.

The key distinction is between factual identity and practical response. A platform can receive a notice about a nonconsensual intimate depiction; NCMEC can receive a report about suspected AI-generated child exploitation; a school can address circulation and harassment. Each can act on documented conduct while technical questions are investigated.

Support the child's emotional recovery and privacy

The child may fear that everyone believes the image, that it will remain online forever, or that ordinary photographs are no longer safe. Do not promise complete deletion or say that nobody saw it. Offer truthful updates: which posts were reported, which were removed, who is handling new messages, and when the next review will occur. Clear facts are more stabilizing than guarantees the family cannot control.

Give the child choices within the response. They may choose which trusted adult attends a school meeting, whether a parent or another adult submits a report, and which close friend is told. Adults still need to act when safety requires it, but explaining each step prevents the process from becoming another loss of control. Ask before taking the device or opening a private conversation whenever possible.

Offer professional support when distress persists, sleep or school participation changes, the child withdraws from valued activities, or they ask to speak with someone outside the family. A pediatrician, licensed mental-health professional, school counselor, or victim advocate may help assess individual needs. Ask about confidentiality, mandatory reporting, experience with online sexual exploitation, and how records are stored. This guide cannot diagnose a condition or select treatment.

Keep ordinary routines available. Meals, sleep, exercise, school accommodations, time with safe friends, and activities unrelated to the incident provide structure. Recovery does not require the child to discuss the image all day or perform reassurance for adults. Schedule case updates so the rest of family life can continue.

Talk about deepfakes before a crisis

Explain in age-appropriate language that software can create convincing fake images or videos of real people. A false image can still be used for bullying, blackmail, or humiliation. The family rule should be simple: do not create or share an intimate fake, even as a joke; do not pay or comply with a threat; and tell a trusted adult immediately if one appears.

Practice a disclosure sentence: 'Someone made or shared a fake sexual image and I need help before I answer.' A child may prefer to text that sentence or show an adult a non-explicit part of the message. Identify more than one trusted adult in case a parent is unavailable or not the easiest first person to approach. The plan works only when the child expects support rather than automatic punishment.

Discuss consent around ordinary photographs. Ask before posting another person's image, use audience settings thoughtfully, and avoid public details that are not needed. These practices may reduce source material and impersonation opportunities, but they cannot eliminate the risk of synthetic content. Prevention education should not imply that a victim failed by having a face online.

Review the difference between reporting and investigating. A child who sees exploitative content should stop, report it, and tell an adult rather than downloading it to identify the creator. Friends should not conduct polls about whether an image looks real. Adults and authorities can handle the evidence through appropriate routes.

Build a school prevention plan that protects victims

Schools can include AI-altered sexual imagery in digital-safety and harassment policies. The policy should address creation, requests, possession, redistribution, threats, and retaliation. It should tell students exactly which adult or reporting channel to use. A rule that only bans phones may miss content created off campus and shared into the school community.

Staff training should distinguish urgent child-safety reporting from ordinary device discipline. A teacher who receives a disclosure should not ask the student to email the file or display it to a room of administrators. The school needs a process for preserving identifiers, limiting access, contacting guardians and authorities when required, and supporting the depicted child during the school day.

Prevention messages should avoid suggesting that careful children cannot be targeted. A creator may use a yearbook image, team photo, public profile, or synthetic resemblance. Teach students that fake explicit material is not harmless entertainment and that receiving it does not create permission to keep or share it. Bystanders need a safe reporting route that does not require redistribution.

After an incident, review whether the policy worked without naming the child publicly. Ask whether staff knew the reporting route, whether the victim had a single point of contact, whether students received a clear stop-sharing instruction, and whether online and offline retaliation were addressed. Correct the process rather than treating one disciplinary decision as the complete response.

Understand what current reporting data means

NCMEC reports that generative AI is being used to create exploitative imagery of children, support fake accounts for enticement, facilitate sextortion, and enable peer victimization. It has also described a gap between material it identifies as AI-generated and files that electronic service providers label that way in CyberTipline reports. These observations show an active child-safety problem and a classification challenge; they do not provide an individual probability that a particular child will be targeted.

The FTC began enforcing the TAKE IT DOWN Act's platform obligations in May 2026. In a May 2026 enforcement announcement, it said covered services must provide a removal process and act within 48 hours after a valid request. The FTC also sent warning letters to companies offering nudify tools. These dated actions describe federal enforcement as of October 2026. Families should use the FTC's current pages because forms, guidance, and enforcement information can change.

Do not combine CyberTipline statistics, platform moderation totals, police reports, and school incidents as though they count the same event. One case may appear in several systems, while another may never be reported. Use agency figures to understand scale and improve procedures, not to claim an exact prevalence without matching definitions and periods.

Statistics belong after immediate support. A child in crisis needs a clear next action and reassurance that adults will help. Trend information can later support prevention education, school policy, and resource planning without turning the child's experience into a data point during disclosure.

Prepare legal questions without making public accusations

AI-generated intimate imagery can involve federal, state, school, and civil legal issues. The family does not need to classify every possible violation before reporting. Give authorities the facts: the child's age, how the image depicts them, where it appeared, what was threatened, who distributed it, and what removal requests were made. Laws and procedures vary, and this guide cannot determine charges, liability, deadlines, or available damages.

If legal advice is needed, seek an attorney licensed in the relevant jurisdiction. Ask about confidentiality, evidence handling, school communications, platform notices, protective options, costs, and what documents are needed. Do not upload the explicit file to a general intake form unless the attorney explains a lawful, secure process and why the file is required. A consultation does not guarantee representation or a result.

Use Social Suit's guide to documenting online harm and questions for a possible legal review to organize a factual timeline. For serious harm potentially connected to social-media products or conduct, the legal options explainer describes an independent eligibility enquiry. An ordinary rumor or single moderation disagreement does not automatically establish a legal claim.

Avoid posting names, accusations, or the image publicly to pressure a suspected creator. A public campaign can identify the child, spread the material, alert the offender, and accuse the wrong person. Preserve facts privately for platforms, schools, authorities, and qualified advisers. A careful record is more useful than a viral thread created during a crisis.

A hypothetical family response

Consider a hypothetical case: a fifteen-year-old learns that an altered explicit image using a school photograph is circulating in a private student chat. Another account threatens to post it publicly unless the student sends money. The student tells an older cousin, who brings in a parent. This example is illustrative and does not describe a client, victim, or study participant.

The parent says the student is not in trouble and asks about immediate safety. They silence the threatening account, record the username, chat name, threat, payment handle, dates, and names of two students who reported seeing the file. They do not ask anyone to forward the image. They secure the student's email and social accounts, save report confirmations, and block new contact after preserving identifiers.

They report the hosting location through the platform's child-safety removal form, submit a CyberTipline report, and contact local police because students at the school are involved. The image is already on the student's device, so they review Take It Down's instructions without uploading the file elsewhere. They record the 48-hour platform deadline and use the FTC route if the covered service fails to comply.

The school assigns one counselor, tells students not to open or forward the image, and gives the student a private support plan. The family shares factual updates at planned times and arranges professional support when requested. They do not promise universal deletion, but they replace the harasser's deadline with coordinated reporting, removal requests, account security, and human support.

A person works on a laptop with a phone and notebook nearby.
One adult can track reports and deadlines so the child does not manage the response alone.Illustrative stock photograph · Sarah Pflug / Burst

Keep a one-page action checklist

First, check immediate safety and stay with the child if there is a crisis. Second, stop replies, payments, downloads, and public arguments. Third, preserve usernames, URLs, threats, dates, and report confirmations without redistributing the explicit file. Fourth, secure affected accounts and review public source photographs. Fifth, submit platform, CyberTipline, and law-enforcement reports suited to the facts.

Sixth, use Take It Down only for an eligible file already on the device. Seventh, record the platform's removal-request time and use the FTC complaint route when a covered platform fails to provide or follow the required process. Eighth, create a focused school plan if students or school participation are involved. Ninth, give close contacts a no-forwarding instruction. Tenth, schedule emotional and procedural follow-up.

Assign each task to one person. A parent might track platform and FTC reports, another adult might handle school communication, and the child might choose which trusted friend receives a short explanation. Roles prevent duplicate submissions and repeated questioning. Keep confirmation numbers in one table and close completed tasks.

The core message remains simple: a synthetic image is not evidence that the depicted event happened, but its abusive use deserves a real response. Do not spread it to prove it exists. Protect the child, record the location, report through official channels, request removal, secure accounts, and keep support available after the visible post is gone.

Sources and further reading

These primary resources provide context. Our practical examples and planning suggestions are original educational material, not validated treatment protocols. Linked organizations do not endorse Social Suit.