What the report found
The Tech Transparency Project, a non-profit that audits large platforms, published research on 8 September finding 332 advertisements containing suspected child sexual abuse material that ran on Facebook and Instagram.
Bloomberg, which reported the findings, said the ads ran between November 2025 and early August 2026 and reached more than 29,000 accounts across the United States, the United Kingdom and more than a dozen European countries. The bulk of them — 274 — ran in August alone. At least one ad reached over 2,500 accounts in Europe.
The group says most of the ads promoted so-called nudify apps, which generate images of real people without clothes. TTP identified photographs of real children among the images used, including one of a member of a European royal family, altered with AI.
Why ads are different from posts
The distinction that makes this a story about Meta rather than about its users is that these were paid advertisements. Katie Paul, who directs TTP, told Engadget that the material was reviewed, approved and allowed to run by Meta, and that the company collected the advertising revenue while it ran.

Every ad on Meta’s platforms passes through an automated review before it is served, and the ad library that TTP used to find them is a public tool Meta built for transparency. The failure being described is not moderation at scale on user-generated content; it is a paid pipeline with a review step that took money and approved the placement.
The commercial scale was small. Bloomberg reported total spend of under $5,000 and most individual ads registering fewer than 200 impressions. That is the difference between a revenue problem and a controls problem, and it is the controls problem that matters.
What Meta says
Meta told Engadget that sexual exploitation is horrific and that it works aggressively to keep it off its platform. The company said most of the ads had minimal reach, that many had already been disabled before it was contacted, and that several predated AI detection technology it launched recently. It says it removes 36 million pieces of child sexual exploitation content a year and has taken legal action against developers of nudify apps.

Two of those points are checkable and one is not. Reach and spend are in the ad library. The claim that new detection technology postdates the ads is harder to square with the timeline: TTP puts 274 of the 332 in August 2026, the last full month before publication. The group also says more than a dozen ads appeared after it had already notified Meta of its findings.
The upstream problem
Nudify apps are the demand side here, and they advertise because advertising works. TTP’s earlier work traced the apps to developers and to a Meta advertising partner in China — the reseller layer that buys placements on behalf of clients, and which sits between the advertiser and Meta’s review.
That layer is where enforcement is weakest across the industry, not only at Meta. It is also where a platform has the most leverage, because a partner account can be terminated in a way that individual advertiser accounts cannot.
What to watch next
Whether regulators move. The ads ran in the European Union, where the Digital Services Act obliges very large platforms to assess and mitigate exactly this category of systemic risk, and in the UK under the Online Safety Act. Both regimes can compel an audit of the ad review pipeline rather than a takedown of individual ads, which is the level at which this failure sits.