There is a sentence that gets said in almost every planning meeting at a platform that has not yet been burned. It goes: we're small, nobody has reported anything, the law doesn't make us scan, so we'll act on reports when they come.
Every clause of that is defensible on its own. Together they describe the exact position that the people who count this material have spent a decade documenting as the one that fails. What follows is the case for detecting content before anyone reports it — built not from a vendor's slide deck but from the 2025 figures published by the organisations that receive the reports, hunt the material, and fine the platforms.
The reports come from detection, not from users
Start with where the reports actually come from.
In 2025 the US National Center for Missing & Exploited Children (NCMEC) — the clearing house US providers are legally required to report to, and that most of the world's large platforms report to in practice — received 21.3 million CyberTipline reports containing 61.8 million images, videos and other files. Of those reports, 21,181,300 came from electronic service providers. 170,193 came from the public.
That is not a rounding error. More than 99% of the reports that identify abuse material — and, through it, the children in it — originate from a platform's own systems noticing something at upload. Fewer than one in a hundred comes from a person clicking "report".
It matters because the whole downstream machine — victim identification, law-enforcement referral, the hash databases that let the next platform block the same file — is fed almost entirely by detection. A platform that relies on notices is not participating in it. It also means that "nobody has reported anything" is a fact about your reporting channel, not about your uploads. NCMEC's own reading of its data attributes the jumps in several categories to enhanced industry reporting: the platforms that report the most are the ones that look the hardest.
The reasons users don't report are not mysterious. The victim usually cannot. The person who uploaded it will not. The people who deliberately seek it out are not going to press the flag button. That leaves the accidental encounter, which on most platforms is rare, brief, and unreported.
Meanwhile the Internet Watch Foundation (IWF) in the UK assessed 451,210 reports in 2025 and confirmed 311,610 of them as child sexual abuse material — one confirmed report every 101 seconds, all year.
Every hour it stays up is harm, not delay
The Digital Services Act measures your obligation from awareness: once you know, you must act expeditiously. The harm is measured from upload. The gap between the two is where detection lives, and it is worth being precise about what fills that gap.
The Canadian Centre for Child Protection surveyed 150 survivors whose abuse had been recorded. Almost 70% worried about being recognised by someone because of the imagery. Thirty of them had actually been identified by a person who had seen it. One respondent: "it feels like your abuser behind bars loosens their grip, but they'll always have a hold on you."
A file that is live for a week is not a week's delay to the same outcome. It is a week of copies.
Which is the other thing the takedown-only model gets wrong. Project Arachnid, C3P's crawler, reported in 2021 on 5.4 million verified images across more than 760 providers. 48% of the media it issued a removal notice for had previously been flagged to that same provider. In 10% of cases, removal took 42 days or more. Some providers had image recidivism rates above 80% — the same material, back up after every takedown.
Notice-and-takedown is a treadmill. The only place the loop breaks is the moment of upload, when the file is one file and has not yet become a hundred.
Small is not safe. Small is where it goes
The first clause — we're small — deserves the most scepticism, because it is the one that feels most like common sense.
The IWF actioned 310,437 URLs in 2025 across 7,268 distinct domains, a 20% increase in domains in a single year. 77% of the sites it actioned were image-hosting services — not because image hosts are run by bad people, but because forums embed images stored elsewhere, so one lightly moderated host serves many forums at once. The IWF's conclusion from the work is blunt: "every platform has the potential to be abused by bad actors and host child sexual abuse material." And 63% of what it found was hosted in EU member states. This is a European hosting problem before it is anyone else's.
The Stanford Internet Observatory made the point in miniature in 2023. Researchers ran hash matching over roughly 325,000 posts on the largest Mastodon servers for two days and found 112 matches for known abuse material, the first within five minutes. Nobody running those servers wanted it there. What they lacked, in the researchers' words, were the "technical measures" to see it.
Regulators have noticed the pattern. Ofcom, enforcing the UK Online Safety Act, opened a dedicated enforcement programme in March 2025 into file-sharing and storage services precisely because they are "particularly susceptible" to being used for distribution at scale. Two of them, 1Fichier and Gofile, deployed perceptual hash-matching after Ofcom raised concerns. Four others — Krakenfiles and the Nippyshare family — withdrew from the UK rather than answer. An image host, IM.GE, was fined £20,000 for not responding to Ofcom's statutory information requests, among them a request for its illegal-content risk assessment. None of these are household names. That is the point.
And then there is the case every founder of a small communications product should read once. Omegle shut down in November 2023, about a week after settling a suit brought by a woman the service had paired with a predator when she was eleven. Its founder's farewell letter said the part that usually goes unsaid: "virtually every online communication service has been subject to the same kinds of attack as Omegle … they all have their breaking point somewhere."
Offenders route around detection. A platform without it is not overlooked. It is selected.
The material is changing faster than the lists
The traditional answer to all of the above is hash matching: keep a list of fingerprints of known material, block on match. It works, it is cheap, and every platform that can run it should. It is also, on its own, increasingly insufficient, for a reason the 2025 numbers make unusually stark.
The IWF found 3,443 AI-generated videos of child sexual abuse in 2025. In 2024 it found 13. Sixty-five percent of those videos were Category A, the most severe classification — a higher share than for videos of real children. AI-generated imagery overall reached a record 8,029 items, and every one of them is, by definition, absent from every hash list at the moment it is created.
The same is true of self-generated material — the IWF classed a third of the imagery of 14-to-17-year-olds it saw as "self-generated", made on the child's own device under grooming or coercion — and of the enticement and extortion that produces it. NCMEC's online-enticement reports rose 158% to 1.4 million in 2025. Financial sextortion reports ran at 137 a day, up 37% on the year. This is new material, created this week, coerced from a child who is still on your platform.
The WeProtect Global Alliance's 2025 threat assessment puts it in one line: the scale and sophistication of technology-facilitated abuse are "outpacing current global safeguards."
This is where classifiers earn their keep — not instead of hash matching, but after it. A hash list tells you the file is known. A model tells you what it looks like. A platform with both catches the known material cheaply and has a chance at the novel material. A platform with only the first has decided, implicitly, that anything created after the list was compiled is not its problem.
Detection is how you protect your own people
There is a cost to the takedown-only model that never appears on the risk register: it is paid by whoever opens the queue.
Spence and colleagues, in a 2024 study in Cyberpsychology, Behavior, and Social Networking, found a dose–response relationship between how often content moderators were exposed to distressing material and their levels of psychological distress and secondary trauma. More exposure, more harm, in proportion. In 2020 Facebook paid $52 million to settle a class action brought on behalf of some 11,250 US moderators over exactly this.
Detection at upload changes what a human has to see. A pre-scored queue means the most severe material can be blocked and reported on a high-confidence threshold without a person ever opening it, and review effort goes to the genuinely ambiguous cases. At a small platform the moderator is often the founder, or the one support engineer. Deciding that they will personally look at everything a user chooses to upload is a decision, and it should be made knowingly.
The regulators have stopped waiting
The third clause — the law doesn't make us scan — is still true, and worth being exact about. The DSA contains no general monitoring obligation, and its Article 7 explicitly protects voluntary detection from costing you the liability shield. We wrote that guide and stand by it: nobody is ordering you to scan.
What has changed is what regulators do with the absence of detection.
The European Commission's first DSA non-compliance decision, in December 2025, fined X €120 million over transparency duties. Its second, in May 2026, fined Temu €200 million — and the reasoning is the instructive part. Temu had a risk assessment. The Commission found it was built on "general information about risks concerning the eCommerce sector as a whole, rather than on specific evidence about Temu's own service." Knowing your own traffic is now the standard, and the only way to know your own traffic is to look at it.
Ofcom, by its late-2025 count, had opened 21 investigations into the providers of 69 sites and apps since the UK's illegal-content duties took effect. Most of the services involved are small.
And the EU's CSA Regulation, in trilogue since December 2025, has settled almost everything except detection. In the meantime the interim regulation that gives communication services their legal basis for voluntary scanning lapsed in April 2026, was reinstated with effect from 1 August, and now runs to April 2028, with end-to-end-encrypted services carved out. Whatever the final text says about detection, the Council's position keeps the risk-assessment and mitigation duties mandatory, and that direction is not in dispute.
Detection remains a choice. It is no longer an unexamined one.
What "detect" actually needs to mean at your size
None of this requires a trust & safety department. At a platform with one engineer on the problem, detecting content nobody has reported means five things:
- A scanning step at upload, before the file is public — hash matching for known material, a classifier for the rest.
- A score, not a verdict, with a threshold you set. Usually two: one high enough to act on automatically, one lower that only queues for review. The base rate is why this cannot be a single global cut-off.
- Human review before anything irreversible happens to an account.
- A log of score, threshold, verdict and timestamp for every decision. This is what your Article 17 statements and transparency report are built from, and what shows a regulator that you looked.
- The paperwork: a lawful basis, an Article 28 agreement with the detection processor, and a decision about where the content is allowed to go. The GDPR guide covers all three.
Visork exists to be the first two items on that list — a detection API that takes the upload, returns a probability, processes in the EU and deletes by default, and leaves the decision where it belongs, with you. A pilot is 100 analyses on your own traffic before any commercial conversation, because a number measured on anyone else's data does not tell you what is in yours.
Reread the sentence
We're small, nobody has reported anything, the law doesn't make us scan.
Small is where the material goes. Nobody reports it anywhere — more than 99% of the reports that exist were made by software. And the law does not make you scan; it now asks what you knew about your own service, and how.
The honest version of the sentence is shorter: we have not looked.
Sources
Every figure above is taken from one of the following. Where a number is quoted, it is the publisher's own, not a derivation.
- National Center for Missing & Exploited Children, CyberTipline Data — 2025: report and file totals, provider versus public reports, online-enticement figures.
- National Center for Missing & Exploited Children, NCMEC Releases New Sextortion Data: Over 100 Reports Received Daily in 2025 (2026).
- Internet Watch Foundation, 2025 Annual Data & Insights Report — Executive Summary: reports assessed and confirmed, URLs and domains actioned, image-hosting share, self-generated imagery.
- Internet Watch Foundation, 2025 Annual Data & Insights Report — AI-generated child sexual abuse material.
- Internet Watch Foundation, 2025 Annual Data & Insights Report — Global geographic insights: share of actioned URLs hosted in EU member states.
- Canadian Centre for Child Protection, International Survivors' Survey — results (2017).
- Canadian Centre for Child Protection, Project Arachnid: Online Availability of Child Sexual Abuse Material (2021).
- David Thiel and Renée DiResta, Stanford Internet Observatory, Addressing Child Exploitation on Federated Social Media (July 2023).
- Ofcom, Enforcement programme into measures being taken by file-sharing and file-storage services to prevent users from encountering or sharing CSAM (opened March 2025).
- Ofcom, Enforcing the Online Safety Act: Ofcom fines file-sharing service £20,000.
- Ofcom, Ofcom issues update on Online Safety Act investigations: investigation and service counts.
- NPR, Omegle shuts down after 14 years, founder cites misuse and cost of fighting it (November 2023), quoting the founder's closing statement.
- WeProtect Global Alliance, Global Threat Assessment 2025 — Key findings.
- Ruth Spence, Antonia Bifulco, Paula Bradbury, Elena Martellozzo, and Jeffrey DeMarco, Content Moderator Mental Health, Secondary Trauma, and Well-being: A Cross-Sectional Study, Cyberpsychology, Behavior, and Social Networking (2024).
- NPR, In Settlement, Facebook To Pay $52 Million To Content Moderators With PTSD (May 2020).
- European Commission, Commission fines X €120 million under the Digital Services Act (December 2025).
- European Commission, Commission fines Temu €200 million for breaching the Digital Services Act (May 2026).
- Council of the European Union, Fighting child sexual abuse online: interim measure protecting children now reinstated (July 2026).
- European Parliament, Legislative Train Schedule, New legislation to fight child sexual abuse online (status as of August 2026).
Figures are as they stood in the sources above in September 2026. This is general information, not legal advice; obligations depend on your service, member state, and facts.