India's Digital Blind Spot: The Challenge of Reporting and Combating Child Abuse Material Online
A recent NHRC notice to Meta highlights the systemic difficulties in converting online child abuse reports into effective legal action and raises questions about platform liability in the age of AI.
Pre-requisite: Understanding the Landscape of Online Child Abuse Material
Combating online child abuse material (OCAM) in India involves a complex interplay of legal frameworks, technological challenges, and institutional coordination. A recent intervention by the National Human Rights Commission (NHRC) has brought these complexities into sharp focus, particularly concerning the reporting obligations of digital platforms and the evolving nature of their liability.
KEY TERMS
- Child Sexual Abuse Material (CSAM) / Child Sexual Exploitation Material (CSEAM) — Any visual depiction, whether actual or simulated, of a child engaging in sexually explicit conduct, or any material that exploits a child for sexual purposes.
- CyberTipline — An international reporting mechanism, operated by the National Center for Missing and Exploited Children (NCMEC) in the US, through which tech platforms report suspected child sexual abuse and exploitation material (CSEAM) detected on their services.
- Intermediary Liability — The legal principle that determines the extent to which online platforms (intermediaries) are responsible for content posted by third-party users on their services, often granting them certain protections from liability for such content.
- Hash Value — A unique digital fingerprint generated for a file, used by investigators to verify that different copies of a file are identical, particularly in identifying specific CSAM content.
BACKGROUND & TIMELINE
India's legal framework for protecting children from sexual offences is primarily anchored in the Protection of Children from Sexual Offences (POCSO) Act, 2012, which criminalises various forms of child sexual abuse and mandates reporting. Complementing this is the Information Technology (IT) Act, 2000, particularly Section 67B, which addresses the publication or transmission of sexually explicit material depicting children. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, further define the due diligence requirements for intermediaries. In a significant development, the Bharatiya Sakshya Adhiniyam, 2023, replaced the Indian Evidence Act, 1872, and includes provisions like Section 63 for documenting the chain of custody for digital evidence. On September 2, 2026, the NHRC issued notices to key ministries and the Delhi Police, highlighting concerns about the reporting and combating of online child abuse material, following allegations of Instagram advertisements directing users to CSAM. This action underscores persistent challenges despite India receiving approximately 1.9 million CyberTipline reports in 2025.
INSTITUTIONAL FRAMEWORK
The fight against online child abuse involves six key government bodies. The National Human Rights Commission (NHRC), established under the Protection of Human Rights Act, 1993, plays a crucial oversight role, issuing notices and recommendations to ensure human rights compliance. The Ministry of Electronics and Information Technology (MeitY) is responsible for policy formulation concerning information technology, including intermediary guidelines. The Ministry of Information and Broadcasting (MIB) oversees content regulation, particularly for online curated content. Law enforcement agencies, including the Delhi Police, are responsible for investigation and prosecution. At the national level, the National Crime Records Bureau (NCRB) and the Indian Cybercrime Coordination Centre (I4C), both functioning under the Union Ministry of Home Affairs, process and route CyberTipline reports to relevant state and district authorities, such as Delhi's Intelligence Fusion and Strategic Operations (IFSO) unit.
What is the immediate trigger for this discussion?
The current focus on India's challenges in combating online child abuse material (OCAM) stems from a recent notice issued by the National Human Rights Commission (NHRC) on September 2, 2026. The NHRC, acting under the Protection of Human Rights Act, 1993, issued notices to the Ministry of Electronics and Information Technology (MeitY), the Ministry of Information and Broadcasting (MIB), and the Delhi Police. These notices were prompted by allegations of paid Instagram advertisements that allegedly used search terms like “rape video” and “child video” to direct users to Telegram channels offering Child Sexual Abuse Material (CSAM). The NHRC's order specifically questioned whether statutory reporting obligations under the Protection of Children from Sexual Offences (POCSO) Act, 2012, were complied with by Meta, the parent company of Instagram, and whether platforms whose AI systems actively shape content can continue to claim the legal protections available to intermediaries (Source: Indian Express, September 5, 2026).
How does India receive and process reports of online child abuse material?
India's system for addressing online child abuse material largely relies on an international reporting mechanism known as the CyberTipline. These reports are generated when tech platforms detect suspected Child Sexual Exploitation and Abuse Material (CSEAM) on their services. The initial report is made to the National Center for Missing and Exploited Children (NCMEC) in the US, which operates the CyberTipline. When the activity appears linked to India, the report is then forwarded to Indian authorities for verification and investigation. India received approximately 1.9 million CyberTipline reports in 2025, indicating the scale of detected material (Source: Indian Express, September 5, 2026).
Upon receipt, these reports are processed by the National Crime Records Bureau (NCRB) and the Indian Cybercrime Coordination Centre (I4C), both operating under the Union Ministry of Home Affairs. The data is routed through a central system and assigned to the relevant state and district authorities. In Delhi, for instance, the Intelligence Fusion and Strategic Operations (IFSO) unit receives the report from the NCRB and I4C. The IFSO then verifies the district indicated in the report and forwards it to the appropriate local police station along with a tipline number. Investigators subsequently seek two categories of information from the platform: the identity of the sender and the recipient of the material (Source: Naresh Diwan, Delhi Police Cyber Cell, cited in Indian Express, September 5, 2026).
What challenges hinder the conversion of reports into prosecutions?
Despite the approximately 1.9 million CyberTipline reports, only a fraction of these translate into police action and subsequent prosecutions. The NCRB’s 2024 Crime in India report highlighted this disparity, noting that out of 1,238 cybercrime cases registered against children under the IT Act that year, 1,099 — nearly nine in ten — involved publishing or transmitting sexually explicit material depicting children (Source: NCRB 2024 Crime in India report, cited in Indian Express, September 5, 2026). This indicates a bottleneck in the investigative and judicial process.
One recurring difficulty lies in the preliminary verification exercise conducted before an FIR is registered. Investigators use information from the CyberTipline report, including account details, IP logs, email addresses, phone numbers, account creation records, and digital hash values, to identify the jurisdiction of content upload or sharing. However, experts note that the quality and completeness of these reports vary significantly; some provide enough information for immediate action, while others require extensive additional verification (Source: Indian Express, September 5, 2026).
A critical hurdle is verifying the age of the victim, as images and videos often lack clarity, making it difficult to definitively establish if the person depicted is a child. As Naresh Diwan of the Delhi Police Cyber Cell stated, “So usually when the background is blurred, and the images are not clear, we do not register a case either” (Source: Naresh Diwan, Delhi Police Cyber Cell, cited in Indian Express, September 5, 2026).
Furthermore, the digital nature of the reporting chain introduces delays. Bhuwan Ribhu, advocate and founder of Just Rights for Children, pointed out that even when the child, offender, and platform are all located in India, a report often travels through multiple entities before reaching the local police station, stating, “Every one of those extra steps is a delay a child cannot afford” (Source: Bhuwan Ribhu, cited in Indian Express, September 5, 2026). The challenge is compounded by offenders increasingly using encrypted platforms and AI-generated content, which makes detection and content verification through traditional methods like hash matching more difficult. Ribhu emphasized that “Law enforcement has to move at the same pace as the crime evolves, not catch up to where it was two years ago” (Source: Bhuwan Ribhu, cited in Indian Express, September 5, 2026).
What is the regulatory dilemma regarding platform liability?
The NHRC's notice to Meta also raises a fundamental regulatory question concerning the legal status of digital platforms, particularly those employing advanced AI-enabled systems. Traditionally, platforms like Instagram have claimed 'intermediary' status, which grants them legal protections from liability for third-party content hosted on their services, as outlined in the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. However, a supplementary representation filed before the NHRC argues that Meta’s AI-assisted tools now do more than merely host content; they can generate captions, recommend posting schedules, optimise engagement, and assist monetisation (Source: Indian Express, September 5, 2026).
The NHRC noted that this active involvement of AI systems in “generating, editing, transforming, recommending, assisting and disseminating content” raises a “significant regulatory question.” It has specifically asked the Ministry of Information and Broadcasting (MIB) to examine whether such functions remain consistent with intermediary status, or whether they resemble the role of a publisher of online curated content under the IT Rules, 2021. This frames the issue as whether the law adequately distinguishes between “mere hosting/transmission of third-party content” and “substantive platform involvement in its generation, modification, curation, recommendation, publication, amplification or monetisation” (Source: Indian Express, September 5, 2026). The outcome of this examination could redefine the legal responsibilities and liabilities of major tech platforms in India.
What legal frameworks govern the fight against online child abuse in India?
India's legal response to online child abuse is primarily governed by the Protection of Children from Sexual Offences (POCSO) Act, 2012, and the Information Technology (IT) Act, 2000. Under the POCSO Act, Section 19 mandates that any person “who has apprehension that an offence under this Act is likely to be committed or has knowledge that such an offence has been committed” shall report it to the Special Juvenile Police or the local police unit (Source: Section 19, POCSO Act, 2012). The NHRC has explicitly stated that this statutory obligation “cannot be substituted by internal correspondence, grievance redressal or regulatory engagement” (Source: NHRC notice, cited in Indian Express, September 5, 2026).
Cases involving online child sexual abuse material are generally tried before special courts designated under the POCSO Act. Section 28(3) of the POCSO Act grants these Special Courts jurisdiction to try offences under Section 67B of the IT Act, which specifically deals with the publication or transmission of sexually explicit material depicting children (Source: Section 28(3), POCSO Act, 2012; Section 67B, IT Act, 2000). Furthermore, the Bharatiya Sakshya Adhiniyam, 2023, plays a crucial role in the evidentiary process. Section 63 of this Act outlines the procedure for documenting the chain of custody for digital evidence, ensuring its integrity in court proceedings (Source: Section 63, Bharatiya Sakshya Adhiniyam, 2023). Convictions in these cases heavily rely on robust digital evidence, with defence arguments frequently focusing on attribution – proving that the accused was indeed the person using the device or account linked to the offence (Source: Indian Express, September 5, 2026).
Why This Topic Matters Right Now
The issue of reporting and combating child abuse material online is particularly salient due to the rapid evolution of technology, increasing digital penetration, and heightened regulatory scrutiny. The National Human Rights Commission's notice on September 2, 2026, to Meta, MeitY, MIB, and Delhi Police serves as a potent reminder of the persistent gaps in India's response mechanisms. It underscores that while legal frameworks exist, their effective implementation is challenged by the approximately 1.9 million CyberTipline reports in 2025 and the sophisticated methods employed by offenders. The debate over intermediary liability for AI-enabled platforms is particularly timely, as it seeks to adapt existing laws to the realities of generative AI and algorithmic content amplification.
Likely Trajectory in the Next 1-5 Years
In the coming 1-5 years, India is likely to see several key developments in this domain. The NHRC has directed an Action Taken Report (ATR) within two weeks of its September 2, 2026, notice, which will likely prompt a review of current reporting compliance mechanisms by platforms and ministries. This could lead to amendments or clearer interpretations of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, particularly concerning the definition of 'intermediary' versus 'publisher' for platforms with active AI involvement. There will likely be increased investment in enhancing the technical capabilities of law enforcement agencies like the NCRB and I4C to combat crimes involving encrypted platforms and AI-generated content, as highlighted by experts like Bhuwan Ribhu. Furthermore, inter-agency coordination is expected to be streamlined to reduce delays in converting reports into actionable investigations.
Governance, Policy, and Societal Implications
The implications of this challenge extend across governance, policy, and societal spheres. From a governance perspective, it necessitates a dynamic legal and policy framework that can keep pace with rapid technological advancements. The current debate on platform liability could redefine the responsibilities of tech giants, potentially shifting more onus onto them for proactive content moderation and reporting. Societally, the effective combatting of online child abuse is crucial for safeguarding the most vulnerable population and fostering a safer digital environment for children. India's ability to address this digital blind spot will be crucial for demonstrating its commitment to child protection in the digital age, balancing the imperatives of free speech and technological innovation with the fundamental right to safety and dignity for its children. The ongoing evolution of digital crime demands a continuous, adaptive, and multi-stakeholder approach to ensure that law enforcement and legal frameworks remain effective against an ever-changing threat landscape.