a Podcast supported by Global Emancipation network
Hello everybody. Welcome to our podcast. We're very excited for this to be our episode one
of this podcast that is supported by Global Emancipation Network. Here, you've got here
three of us speaking today, all supporting Global Emancipation Network. This is Melanie Duzyj here,
and I'll turn it to Sherrie Bosisto, our executive director, to introduce herself.
Hi everyone. As Mel just pointed out, I'm the executive director at Global Emancipation
Network. We're really excited to be starting this podcast and bring you all along for the journey.
Megan. Hi all. Megan Anderson, currently supporting GEN as a senior advisor for Government Affairs.
Thank you too for joining our first podcast. And of course, we've got Jonathan in the back end
as our producer, so I feel like we're really doing this the right way today. So thank you,
Jonathan. Well, so first, because this is episode one, I'd like to just set the stage with what the
heck this podcast is all about, who the heck we are, and what our careabouts are. I could certainly
certainly go on and on about what Global Emancipation Network, or GEN as we call it for
short, why it's special to me. But I would love to just hear a little bit from you, Sherrie,
as the founder and executive director. Tell us what this organization is and what we're all about.
Yeah, I started this organization 10 years ago. This is a huge year for us. We've been
leaning in and celebrating our 10th anniversary. And what we really do is dismantle exploitation,
all of its forms all over the world, using three main approaches, technology, community, and policy.
Today, we're going to be really leaning in on that latter one, policy. But what we really do
is we build technology for our main stakeholders, whether that's law enforcement agencies somewhere
in the world, or if it's a private sector company that we're working with, or fellow
nonprofits. So we really just like to come alongside and use technology as a way of scaling
effort and being more efficient. But I would love to hear, Mel, how did that come up? Does that
embody everything that you think that we do? I think it does. Sherrie is very humble. I think
Megan and I have talked about this often. Sherrie is a known voice within the anti-exploitation
community. And Sherrie and I actually met each other more than a decade ago when she had first
founded Global Emancipation Network. And she was reaching out to different technology partners,
including Splunk, the data analytics company where I was employed for many, many years.
And over the years, Sherrie and I got really close through storytelling and doing media
relations together. I was on the corporate communications team at Splunk for a number of
years. And Sherrie and I just always really clicked, not only from the mission perspective,
but I've always really admired the community aspect of this work that Sherrie took quite
seriously. GEN has always been a small but mighty team, up until recently two people officially.
But the number of supporters and volunteers that you've got are worldwide in the hundreds and the
thousands even. And so I'm very excited to be a part of this mission. I've joined on officially
in 2026 as head of strategy and growth. And I'm just over the moon to be here. Now, Megan,
I'd love to hear your point of view. When you first met Sherrie and heard about GEN,
I think you had that strong reaction that I felt too. Can you tell us about that?
Yeah. So I come from, vast majority of my career is in federal government,
federal US government, working in international human rights. But a career field I almost went
into was sex education. And so now that I'm doing a career pivot, I have been wanting to get into
spaces where I can bring together this passion for sex education and keeping kids safe from sexual
predators and my international human rights background. And just understanding how there's
the space where these two things really come together are in places like what GEN has been
doing in terms of keeping kids who are victimized, especially through the internet, on keeping
families aware of what child sexual exploitation online looks like. And then obviously, how do you
get our policymakers to really understand what the issues are and what are the solutions?
And so of course, when I meet a problem solver like Sherrie, it was just pismat thinking,
okay, how can we get this problem solver in front of the policymakers, the US government?
Megan, I want so badly to make a bunch of jokes about sex education and how you need to,
the next time we all hang out together, pull out the bananas and the condoms for us to-
I almost-
That was almost my career. I almost got an MPH. I got an MPP, but I almost got an MPH. I was gonna
focus on these issues.
That's a really fun fact. I did not know that. My dream pre-Silicon Valley was to actually be a
nonprofit lobbyist. So here we are. Things come full circle. It's funny how things work.
And now you have the dream?
Now I'm living the dream. This is the dream. Well, so let's get into the conversation today.
We spend a lot of time in the weeds of technology. We're going to cover a lot of that in future
episodes. What's working, what's not working, and what's coming. Today, I really wanted to zoom out
because something really extraordinary is happening right now in the halls of Congress
and in Brussels. And most people in child safety aren't really paying close enough attention to
this. The three of us here have spent time not on this podcast, really talking about the changes
that we want to see in the main topics that we want to see legislators worldwide really cover.
So we have five federal bills active in Congress right now, all touching child protection and
platform accountability. This is a very interesting moment in history given all that is happening
with AI and generative AI and now generative AI created child abuse material, which we'll get into.
Also, it's an interesting moment here in America right before the midterms because you've got a lot
of legislators trying to show an interest in child safety. And a big reason for that is third, the
Epstein files is very much on the mind and child safety is now in the mainstream consciousness to
a degree I had never seen before. So while we are really focused today on U.S. legislation,
I also just want to point out these conversations are happening worldwide. The EU just faced down a
deadline that could have wiped out all voluntary child sexual abuse material detection across an
entire continent. So I asked Sherrie and Megan to join us today to help make sense of it because
these laws written now are going to have cascading effects for a really long time, for many years to
come. So let's just start with a moment of context. Stepping back, Megan, I just want to hear your
overall impression on how you see child safety on the minds of legislators. Now, is it I perceive
that it's relevant to a higher degree right now, but what's your perception? Certainly. I mean,
think about just in the last month, you have these two big meta trials. So issues that for us are
day to day, we're steeped in tech and child safety. This is now something that's in the forefront of
Americans' minds because it's been splashed on the newspapers for weeks. But I come from an internet
freedom background primarily. And so I've been really confronted with the tension in this space
of freedom of expression and privacy and child safety, because these are where the conversations
have been getting stuck for the past several years. Like right now, the Kids Online Safety Act in the
Senate has over 75 co-sponsors. This is possibly a record, but still the House version, we have a
majority, Republican majority. They're never going to get consensus because you've got
too many voices who are not willing to play in the space of freedom of expression. And so the
Democrats aren't going for it. And so where are those little pieces of legislation that are going
to be narrow enough to be palatable to both sides? But this is going to take time. And as you said,
Mel, we're in election year. We could have Democrat majority in the House easily in January,
and we're going to have to start over. So in the meantime, in this space, what I think is so crucial
is how do we keep the momentum of the average American now seeing the meta trials and obviously
seeing all the state level policies and phones in schools? People are having these conversations
more and more about what does it mean when my kid has a phone and they're alone? And I think it's
just becoming organic that at the constituent level, more and more people are having these
conversations. But I still, let's be realistic. The average American is not tracking what's
happening in Congress, and they're not tracking what's happening at the state level. Maybe they're
tracking what's happening at the county level. But so how do we, as part of a bigger network,
get of other advocacy groups and people who care so passionately about these issues, how do we talk
to the average American in a way that would make them see this from the freedom of expression side?
So certainly protecting data privacy, protecting end-to-end encryption. Maybe that means we need
to talk to someone about what end-to-end encryption means. And then how do we talk to the child
advocates about how do we protect end-to-end encryption while also allowing the tech at hand
to actually do the scrubbing of anything that is illegal content? And this is where I'd love
Sherrie to talk. I think we should actually do a breakdown of the kind of tech that Sherrie and her
team have been building for years in a way that, you know, how would you explain, Sherrie, the tech
that you have been building to an average American voter? Yeah. And I think it's important for us to
think even beyond the American voter. Yes, that we are rooting this conversation in American
legislation. But kicking it off really with this idea of this EU derogation, that is the issue that
we're talking about, the e-privacy derogation, which gave cover to these companies who were
doing voluntary scanning for child sexual abuse material. We're going to use the term CSAM here.
And I think what's important though is that this isn't an issue that's global. It's worldwide.
It's affecting all of us. Yes, a lot of these companies are actually based in America.
And that's why these laws have such a large overreach. But when we're talking about the
public, we need to think about the American, but then we also need to think about the family in
Costa Rica or the technology provider in Japan. So beyond that, though, yes, what Global Emancipation
Network does is really try to provide tools that can help those frontline investigators that we
talked about, whether that is somebody sitting in content moderation at a private sector company,
maybe it's a job board, maybe it's a social media company, to law enforcement all over the world or
to academia even. We have some research projects that we do. A lot of the tools that we do sit
really under the protection or prosecution umbrellas of that, which really it means that we're
looking at tools that do victim identification. We are looking at tools that triage content,
and that can just be out of a whole set of reviews on the internet. How can we figure out
which businesses might be engaging in human trafficking or engaging in exploitative processes?
So we would put that in this triage and classification bucket for it. And then there
are others that really just make life better for the people who are doing this sort of work.
And I know that this is something that we're going to talk a little bit more about now,
but it really ranges the entire gamut here. We're talking about end-to-end encryption,
and I think that this is actually one of the issues is that most people don't really know
about the tech that we're discussing. They don't know exactly what that is. And because we've
already called it out, these are the chats that are like signals that we're talking about.
And we're also talking about the apps that are like signal or some of the other encrypted
messaging apps where nobody can actually get in and see those communications, whether that is the
company who provided the tools or it's law enforcement. That's part of the appeal is it
has safety for say a journalist who is conveying sensitive information or for a distance somewhere
who are trying to organize. Unfortunately, though, sometimes that also means that these are spaces
that we can't really think about. And so we're trying to balance security and privacy,
but the issue is whose security and whose privacy are we centering in it? And I argue that these
aren't even two separate things. We can do both at the same time with the right technology.
Now, you guys, as we're talking about encryption here,
this is really bringing me back to the many cybersecurity events where Sherrie and I have
met up together over the years. We love our black hat. We love our deaf con even more. Sherrie,
can you tell us a bit about how your experience with the cybersecurity community has really
inspired a lot of the tactics and strategies that you're bringing over here through not only GEN's
technology, but the way that you are approaching community. For instance, Megan was just talking
about the very narrow legislation that's needed here and the education we have to provide to
legislators. I see such parallels between exploitation work and cybersecurity work.
How do you think about the parallels and how has that inspired you?
Yeah, I actually got into the counter human trafficking space, you know, at risk of aging
myself just over 20 years ago. And there we were actually just drafting legislation.
You're just 21 now, Sherrie.
Exactly. I was a baby. But in between doing that policy work at Johns Hopkins University,
I was working for another nonprofit where we were actually doing rescue operations. And this was
founded by a couple of people who came out of the intelligence community out of the US
and the special forces. From that background and other people that I knew, we were really applying
cybersecurity techniques and open source intelligence techniques that came from the
military and again from the cybersecurity domain and applying it to the counter human trafficking
space. And in particular there, we were focusing on trafficking within orphanages and how can we
secure those spaces and protect those innocent children. So that's really where I learned
how both we can use the internet to find offenders and protect children, but also how the
internet and tools and technology were being used by those bad guys, the organized criminal elements
and others in order to do this. So that is really what spurred Global Emancipation Network, how we
started 10 years ago. And I thought, gosh, if we are having so much success as a single small
organization, what could be possible if we were to equip the broader community with these same
skills and the same data for it. And all of actually our initial contacts and companies
that we were working with really came from the cybersecurity domain. All of our volunteers,
all of the tech companies who are working with us, some of the members of our board even,
really came from that community. So it's really been the seed of it. And the people who come
from that space, I think have this really cool aha moment when they realize it's absolutely the
same methodology, the same tools that we are using. And we're just replacing the domain. We're
just swapping out malware and viruses and state actor threats to organize criminal elements and
human trafficking and survivors. So it's cool for me to see those moments when they understand.
And I think that we really carry that on. The other piece of that, Mel, I think that you're
also talking about is that there is a concept in the cybersecurity space that was originally
borrowed from the military that is called the cyber kill chain. And we have extended that into
what we call, I mean, originally we called it the human trafficking kill chain working title,
because I cringe whenever I say those words. And really what we're talking about though,
is the exploitation life cycle. What are the stages and phases that are present in, if not,
every single exploitation experience, but the majority of them, from recruitment to harboring
and transportation and brokering to exploitation. And then what do the offenders use in order to
have that happen? Are they taking airplanes? Are they using one of the major social media companies?
What are those individual assets that they're being used? And then how can we as defenders
and protectors actually use those same points to interdict those efforts? So again, totally
borrowed from the cybersecurity domain. She borrowed it and you heard it here first,
that Sherrie wrote the paper about this, what, 10 plus years ago. So you were ahead on that curve.
Now, the exploitation life cycle is a really important place to start in framing how we think
about child sexual abuse material within the human trafficking umbrella. I think of child sexual abuse
material, or again, CSAM, we'll be saying CSAM a lot in this podcast. CSAM appears on one point
of the exploitation life cycle. That's the way that I think about it. Sherrie, do you agree,
disagree? How do you think about child safety within the broader umbrella of human trafficking?
That's a really good question. I mean, there's even the question, it really comes about how do
you define human trafficking or modern slavery? At its root, really what it is, is the exploitation
of one person to benefit another. And that doesn't have to be financial. There's all kinds
of different ways. And this is very broad strokes in terms of using that definition there. But when
we are talking about child sexual abuse material and online child sexual exploitation abuse,
there are sometimes financial elements to it. And sometimes there's not. Sometimes this is just for
the, I apologize for being so dark in this conversation, but for the gratification of
one person. This can be actually a family member who is assaulting another family member, a child,
and then taking photographs, which are really just evidence of those offenses, for their own
use, and then trading so that they can get additional material. That additional material
exposure and that trade still counts as benefit and they receive something from it. So we do
think of it as one term. And then as for your particular question about, is CSAM one point on
the exploitation chain? I think I'd have to think a little bit more about that. I think that moment
that you're seeing is the moment of exploitation, which is a dot on that chain or in that cycle,
for sure. This is evidence of the crime. But there are pieces that came before that. Again,
there are assets that were used. The offender needed to have a camera. Probably it was their
phone, right? The exploitation took place in a location that could have been outside, but more
likely it was a bedroom or a bathroom or a hotel room, something like that. So those are individual
assets. They probably were trading the material or it was stored on the cloud or maybe on a hard
drive somewhere. So there are pieces like that for some of this content, unfortunately, that we're
going to talk into about, particularly like coerced abuse where someone is remotely actually
sent to somebody on the other side of a computer, maybe even on the other side of the world.
You need to send me these photos, or I will tell your family, I will expose this to the school,
or you need to pay me money to not share these photos that you've already shared.
Then you are looking further upstream. You're beginning to look at grooming patterns. And so
this is earlier in the exploitation cycle. I'm not sure that this fully
covers your point. What do you think, Megan? I mean, all of all you're talking and just
the scourge that this issue is right now, so much of it is CCM is exploding. We just saw these stats
that the National Center for Missing and Exploited Children, NICMC, also I think an acronym you'll
hear a ton on this podcast, or the Internet Watch Foundation, which is the UK's,
really for global collection of CCM, 2025 highest rates ever of reported CCM. And that's because
we're seeing so much synthetic CCM, which is tech created, either starting from scratch or adjusting
an existing image using technology. And so it puts even more pressure on groups like GEN,
who are familiar with the tech, who've been building tech tools, to then say,
but it's like an encouraging challenge too, because you're going to use tech to push back
against all the evil that tech is doing. We're going to meet the moment because there's so much
good that we can also do with technology. And this is again, why I think you're in such a unique
place, because you're not saying, oh, maybe we should use tech. This is pretty bad. You were
saying that years ago. I mean, I think in my background in the governance space,
I love this example of Estonia is a leader in e-government. And this started over two decades
ago. I mean, okay, it's a tiny country, but still. That's because they looked at the question is,
how do we make our government better? And they said, oh, we'll use technology. And so many
countries now are saying, how do we use technology to make our government better? And that it's like,
we've already missed the boat. And Sherrie, you created this organization because you were
so horrified by trial trafficking. And you said, how can we help this problem? Oh, we're going to
use tech to help address this problem. And now obviously the network has exploded and so many
other groups are doing it. But it's just so crucial in this moment more than ever when we
see these increase in numbers of millions and millions and millions of reports of CSAM and so
many of them are synthetic, that the way we can take these down is by having tools that are going
to help go through all those images and help them be removed. Megan's bringing up synthetic CSAM.
And I want to get into that. Sherrie, you and I have talked about your thoughts on maybe some
misconceptions out there around AI generated CSAM. I would love for you to just explain your
viewpoint of, okay, AI is out there. Grok is helping people generate some really horrible content.
Not now. They said they won't anymore. Thankfully, there's some healthy litigation
happening out there to keep different AI providers essentially more accountable.
How much AI generated CSAM is there out there really? Is this explosion in CSAM reports from
commercial platforms? Is that really all because of AI generated CSAM? What's actually going on
there? Ah, such a good question. You're right. You have hit one of my current soap boxes. I'm
glad we're getting right into the meat and potatoes of this. I know your soap boxes, Sherrie.
This is obviously a very important topic. This is something that we should be paying attention to.
Megan is right. There has been a drastic increase in reports right now that there are,
I think that there's something like over a million AI related CSAM reports in the last
nine months. Some figures, if you're looking, it depends on if you're looking at the 2024 numbers
coming from NICMEC, the National Center for Missing and Exploited Children, or you're looking at the
first half of 25. They just released their numbers for that. It might be a 1300% increase. It might
be a 600% increase, but part of the issue is actually in how we're defining that term and what
the reporting mechanisms actually look like. There was a great New York Times article that came out,
it was probably about a month ago now, I think, Mel, that was actually detailing breaking down
those numbers. There are a couple of different ways that AI generated CSAM can be produced.
There can be fully synthetic. This was created using Grok or some other tool. There's lots of
them out there that we won't get into. Or you can actually have bits where there was actually an
original abuse image and you can use AI to generate new content from it. Or you can take
an existing picture of a real person, and this is when we get into these nudifying apps that are
unfortunately really common right now that are causing a lot of issues, to nudify a person who
was clothed in an image or to take my face and then generate illicit material from that that would
be nonconsensual, intimate imagery since I'm an adult, but if it was a tile, it would be CSAM.
Then there's places where it's just like a new face has been swapped into another existing piece
of material. There's even this challenge where it's not just fully synthetic or it is real.
There's really this blend that complicates the issue. But the New York Times article got into,
in particular, the AWS reports, Amazon's web services reports. What they were actually doing
was in the process of training their models, obviously they were going out to the internet
and using images on it. It's a very simple thing to do, right? That's a normal part of the process,
training your models. That is, yep. There's obviously debate as to the permissions to use
some of that data, but setting that aside, obviously all AI models require training material.
In this case, we're talking about images for any of these vision language models.
They realized that they had accidentally hoovered up in this bunch some CSAM because that's what
exists on the internet, is taking a slice of the internet and it exists there. They did the right
thing, the thing that they are required to do under law, which is to report it to NICMIC.
Then using their form, one of the options, if we're to get into it, and the public can do this,
we can do that, it actually says AI related or just AI, I can't remember the exact words for it.
This is what they used. What NICMIC's intent for that is to say that this is actually AI
generated CSAM, that this is either wholly generated or it's inpainted. It's some of the
swapping that we're talking about, but it actually was created using some AI tools.
The figures that were included, unfortunately, were just like, ah, in the process of creating AI,
we use the CSAM that was reported under the same umbrella. There are some issues that are known.
We're trying to sort all of this out, but in general right now, I still think that the
reports that I'm hearing from the field are that this is less than 1% of the reports that are
coming through, or actually some form of AI. That's not to discount it. We do expect that
it will get worse. I don't want to get too much into the technology that's used right now to
combat it, because I'm very sensitive to burning tactics and techniques for investigators.
It is something that we are working on. We are on the forefront. There are some incredibly
smart people, people I respect, including one of our former students and generous, Bella White,
that is on the forefront of that issue. Go Bella! Yeah, go Bella! Friends at Camera Forensics,
or at Thorne, IWF, there are lots of people who have come out with statements and been a little
bit public on their work there, and all let them speak for themselves. But I'm not sure that it is
the emergency that people thought that it might be, and it is, I think, smaller than the numbers
currently suggest. Controversial hot take, Mel. I love your hot take, Sheri. Thank you. We're
building a whole podcast around this after all. This is where I want to bring it a little bit
closer to some of these pieces of legislation that we've teed up to talk about. The Enforce
Act was passed the Senate unanimously in December of 25, and it's got no committee referral yet on
the House. The Enforce Act closes sentencing gaps for AI-generated CSAM and ensures deep fake
penalties match traditional CSAM penalties and removes a statute of limitation. Sheri or Megan,
what aspects of those stand out to you, and why do you think those are important details?
Megan, do you want to take it? You want me to take this one on? I mean, just because we are seeing
an increase now in AI-generated, this is how we address this problem is you
impact the demand side, and the demand side are the people seeking CSAM, the people creating CSAM.
If people think there's a workaround, they're going to exploit it. This is closing a crucial gap.
We were talking earlier, we just saw under the Take It Down Act, which went into force almost a year
ago, which passed incredibly quickly, which is non-consensual intimate imagery, whether it's AI-generated
or not. And whether it's child-related or not, correct. Right. And that is huge because we need
to demonstrate that if you play in this space, you're going to get burned. And this is where,
when we have legislation like this, that law enforcement and local judiciaries can point to
it's huge, but it takes time. But it's like I was saying, it needs to be these narrower
pieces of legislation if we're going to get through this Congress. Sheri?
Yeah, I completely agree with everything that you said here. I think what is important about this
is that in the US, there was this loophole basically around this, that if it was
AI-generated, CSAM, using AI was prosecuted differently. It fell under the obscenity statute.
And so the penalties were different. Sentencing guidelines were different. Supervision
requirements differed. Registration on a sex offender registry differed as a result of whether
it was a hands-on offense or not. And part of the issue is what I talked about. It's not just all
or nothing. There's this in-painting issue. And so there's a little bit of a legal vacuum there.
I think it's also important to note that this brings it a little bit more in line with some
of the other countries and their current statutes and legislative efforts around AI-generated CSAM
as well. So I always like to see standards come across the board that's really helpful for
companies who are trying to protect against this and shield themselves from liability
and do the right thing. And it's easier for investigators and prosecutors, frankly.
I think the other piece that's important behind this is that there's something that is actually
missing from this bill in this conversation. It needs to be part of the broader conversation.
And that this enforce really tells us what happens after an offender is caught creating
material using AI. It doesn't do anything to actually address the detection problem.
And again, I said, I'm not really going to get into how this is currently done or what research
exists in this space right now. But it is difficult to identify, is what I'll say.
And you can't actually prosecute what you can't find right now. And not only that, this is still
really in the action of what happens after the bad thing. We need to go further upstream. And to
your point, Mel, that these are sometimes these are individuals, just really smart offenders who
are really great smart technologists. And then sometimes these are tools that are actually being
created by companies who aren't intending it to be used this way. But unfortunately, this is how
it is shaping out to be. And so by going further upstream and working with these companies, helping
them understand this particular use case and addressing the guardrail issue for it, this is
how we're going to actually limit the amount of this is actually being used. And so I think
this is actually happening at that point. Thanks, Sheri. Now, so now we're starting
to talk about the platforms where CSAM may occur. And that could include, as I understand any
entity that includes file sharing, right? That could include images or video. One piece of
legislation that we're really excited to support is the STOP CSAM Act. This piece of legislation
extends platform liability to include reckless hosting and promotion of CSAM, strengthens the
cyber tip line, which I would love for us to talk more about what the heck is the cyber tip line.
How does that relate to NICMIC? But the STOP CSAM Act also requires transparency reports,
which gets me really excited. So Sheri, could you put the STOP CSAM Act in context of
existing legislation, say, SESTA FOSTA, which was put in place in 2018?
What does the STOP CSAM Act do as far as logical incentives for organizations?
To better safeguard, I'll say, safeguard our children.
Yeah. I mean, this is another one of those bills that has a really catchy name,
STOP CSAM, strengthening transparency and obligations to protect children suffering
from abuse and mistreatment act. We love an acronym, and this is a fantastic example of that.
It's actually a really broad bill. The point of it is to extend platform liability to include
reckless hosting and promotion of CSAM. And the challenge for me in understanding this is
actually what does it mean for it to be reckless? How does this differ from the
current knowing standards? And then in terms of promotion of CSAM, but then also,
where is it that it is either solving or adding to the paradox that we already see, where
detecting CSAM creating legal exposure for companies, particularly under the SESTA FOSTA Act,
which was, again, that bill that came out in 2018. I think SESTA stands for Stop Enabling Sex
Trafficking Act, and FOSTA was the other version, the House version of that bill. But it really
just ended up shifting liability. So this is my biggest concern, and the thing that I'm waiting
to see if this compounds the issue or if it helps solve the issue. The debate is interesting in that
I think that we all agree that platforms need to be responsible, and they need to be searching for
this sort of illicit material. What is less clear or available right now is an understanding of
best practices. What actually does good content moderation look like? And you have a human element,
there need to be tools which detect known material, things like hash matching algorithms,
photo DNA or whatnot. And there need to be things that identify first generation CSAM.
And that means for those listening who aren't sure what I'm talking about exactly, there are
really two different spheres here that we are talking about that platforms use or organizations
like ours use. Hash matching is basically a collection of numbers that says we know this
number. There's this color here, this outline here, and it's really just converting an image to
computer language that says this. A hash is not something that's easily reversible or possible to
reverse, but it's really just a unique identifier for that image. And some of them are a little bit
more rigid or some of them can stand out too, like if you change it to black and white or crop
the image or whatnot. But basically these are collections that are held by Nick Mick or Megan
mentioned the IWF. Interpol has a collection of these hashes called ICSA, UK has the child abuse
image database, CAID. Lots of these hash databases exist. These are known images. These are the ones
that are traded over and over again. They get reported and added to these. The real challenge
is in first generation material. When an offender takes a new abuse image and documents that crime
and then shares that, but it hasn't actually been turned into law enforcement yet. It hasn't been
added to any of these hash catalogs. What tools do we have that exist right now that help us
see, ah, this is actually CSAM and not just a human like you or I, who if we saw these images,
we'd be able to say, absolutely, this is bad. But a computer to do it because we're talking about
massive volumes of data that are really difficult for companies and law enforcement and everybody
to actually manage the flow of this information. It's a literal fire hose. And so we need to be
using tools to do that. But there is sort of a fundamental misunderstanding, I think,
by policymakers of where best practice is actually at, you know, the best detection tools. And then
even that we're not really even talking about moving from pure detection into intelligence.
We need to go beyond just, is this bad or is this good? It's if this is bad, tell me everything we
need to know about it. Who did it? What other material have they been using on it? Can you tell
me where in the world this was taken? There's so much more that needs to be wrapped around that.
And part of that that I'm excited about because it does mention the cyber tip line, which is
actually the program out of the National Center for Missing and Exploited Children, where
electronic service providers and the general public are actually making reports of sea salmon
exploitation to them. And from that, they're actually referring out all of these tips to the
rest of the world. You know, they'll say, this looks like it belongs in Romania, this one goes
to Costa Rica, this one goes to Estonia, and so on. So this all goes through the cyber tip line.
It is a huge, huge, massive program. I'm lucky enough to know the people who run it.
They're doing a phenomenal job. But again, this is actually another nonprofit who are running
this for them. This is the world's clearinghouse for this sort of material. So right now, it's
really difficult. It's really complex for us to say, everybody is required to report to them.
Good luck now. Thank you for your service. So we have a lot of material that's submitted to them
that's actually inactionable. I hesitate to give a number, but it's really high. It's in their
transparency reports that you can find online. Maybe we can link to that. Of companies who are
providing reports and saying, hey, we saw a thing, but not actually providing enough material for
law enforcement to do a thing about it. So really exciting.
And by a thing, you mean investigate and perhaps launch activity to identify and or safeguard
people with- Exactly. Yes, yes, exactly. To identify the victims who oftentimes aren't
actually known. We're going to talk about another bill later on that is really entirely focused on
victim identification or for law enforcement to actually investigate those crimes. For example,
I was in a country in January embedded as part of a mission where we were helping them build
technology to manage the flow of these cyber tip reports coming into this country. And they were
receiving about 250,000 of these reports per year. And there was a team of nine people whose job it
is to actually investigate and action these reports. Nine people.
So there is, yeah, there's no way that humans can scale to that amount. So this is why you're
going to keep hearing us talk about intelligence beyond detection and why we're excited to see
some of the improvements to the cyber tip line and some platform accountability. So that is so
much hearing from me, but I want to hear a little bit more, Megan and Mel, what you think about this,
this distinction between knowing and reckless and what we need to do to shift to a better policy here.
This is Sherrie trying to get a moment to drink a sip of water between her.
She can keep going. I mean, so much about why I'm excited for this moment, even though it will be
challenging because we see there is deadlock on the Hill in so many ways, is how do we get average
Americans to know what the tech companies are currently liable for and how there's still so much
bad stuff and what they could be liable for with some not too crazy legislation that gets pushed
through. And it's these things that like someone like Sherrie and hopefully all of us can explain
to our neighbor, like what the difference between knowing and reckless. What does it mean when it's
hashed CSAM? What does it mean when it's a novel CSAM or first generation CSAM? What does it mean
when it's synthetic and when it's not? But we've all been talking about the volume.
And so this is why stop CSAM is so important because it extends the statute of limitations.
Because once a victim, always a victim. It doesn't matter if it was 10 years ago. It doesn't matter
if it was 20 years ago. These victims deserve to have that CSAM removed. And who's going to
disagree, disagree with that. And so we have to live with the realities that we're in. And that
means, and we just need more time. And some of the other legislation we're talking about too,
is getting more law enforcement in place to go through all these images that are being reported.
Oh, you just made a good point as well, Megan. This is one cool thing about this bill is that
it actually put in place a 60 day removal window, a time limit from which these companies have to
act to remove material. Most companies are really good once they receive a takedown notice from
NICMC or another company. When somebody flags it as being CSAM or illicit material,
or contrary to their terms of service, most are really very good about it. But sometimes it slips
through the cracks and sometimes there are companies who aren't as responsive to that.
So this is the first time that we're actually seeing a removal deadline for it. Companies already
have an existing requirement to quarantine and hold material for 90 days. And we're seeing
efforts to try to extend that as well, particularly given the challenges responding to disclosure
requests. Stepping back, I just want to make it totally clear for listeners that those folks that
are conducting investigations not only exist on the law enforcement side, once these tips have been
passed over to law enforcement, like this nine person agency that Sheri was saying she was
recently working with, but these teams also exist within commercial entities, within social media
platforms, within content sharing businesses. At Splunk, we used to say every company is a data
company. And this is really true now. So what we're seeing at Global Emancipation Network is this
evolution where trust and safety teams internally are really looking at content moderation in new
ways. And something that I'm excited about is the conversation around the standards needed.
What we're hearing in the industry right now is that there's a lot of, do it yourself, build your
own on the trust and safety team side, as far as CSAM detection and standards used either by team
or by organization to do this. At GEN, we're very passionate about creating standards, not only for
better operational efficiency across teams, but also so that we can set expectations for technologies
that are created to help solve this problem and so that we can influence legislative expectations
on how to solve this problem. So that's something I want to come back to in future episodes.
I also want to note we're talking about these analysts and investigators to a better degree
than ever before. Just in the last week, we brought up New York Times. They've been doing great
coverage on the human trafficking contours, and one of those aspects includes the investigators
around the world that do have to take a look at this material that has been flagged. This potentially
has criminal material within. We need a human to take a look. If you take a look at the latest
OpDocs video from the New York Times this week, there's a great video interviewing a fellow out
of the Netherlands that does this as his day job, day in and out. It was hard for me to watch,
Mel. Wonderful piece, so hard to watch. Because you've worked with these people,
right, Sheri, for years and years. Now, as we're seeing, these folks exist both on the
corporate commercial side and the law enforcement side. I really want to bring up the Renewed Hope
Act of 2026. We at GEN are so excited about this bill. It mandates the creation of more than 200
new HSI analyst and investigator specialist positions dedicated specifically to victim
identification. They're also focused on deconfliction coordination, and this bill really mandates
better and more advanced training on AI assisted victim identification. I would love for either of
you to comment on this one because we're excited to watch this from the GEN side, and we're
actively talking with congressional offices about this one. Yeah, and real quick acronym, HSI,
Homeland Security Investigations. These are officers in the United States, and then also HSI
is the entity of the Department of Homeland Security that sends investigators overseas.
Because, again, when we're thinking about the demand of CSAM, of course, there's offenders
in every country in the world, but America is the biggest offender. Netherlands being number two,
which is why I think that OpDoc was from the Netherlands. This is so exciting because, again,
thinking about the supply and demand of CSAM is the way that we can get at, hopefully, getting
people to make it less and seek it out less is when they see that there will be people convicted
with very harsh penalties when they create or view or store or share CSAM, certainly in the United
States. And really, I think this could have an impact globally as well. And when we're talking
about the goal of being law enforcement, so not even funding law enforcement, but also
supporting those officers because of the mental health effects of when you are looking at this
kind of imaging all day long, it's really a holistic bill, and it's such an incredible
complement to the other legislation, which is more focused working on the tech companies.
Yeah. This bill is really personal to me. I want to start framing this conversation in particular
with a number that Tim Tebow himself calls out. Tim Tebow was an American football player. That's
how he became famous. And he ended up starting his own foundation, the Tim Tebow Foundation,
which is really focused on human trafficking and child sexual exploitation and just the most
vulnerable people is the way he calls them. But they are huge advocates and have been really the
primary drivers behind this particular act. So Tim Tebow was testifying before Congress on the
3rd of March. I think it was the Senate Judiciary Committee. And he shared some really cool numbers.
We are partners of Tim Tebow Foundation, and he was really focused on some data that came
from another one of their partners and mutual friends of ours at the Child Rescue Coalition.
And what he was showing actually was this map of the United States that was covered in dots,
some red and some blue. Each red dot was unique IP address. And those were people who were trading
child sexual abuse material. There were hundreds of thousands of dots that were on this screen.
It was such a moving visual for it. But the number that he shared was 89,000. And that is the
number of children who appear in known child sexual abuse imagery that law enforcement know
about. These are faces that they have seen. These are children that we know exist. And trust me when
I say that victim identification specialists live and breathe this work. They are some of the most
skilled and compassionate investigators and people that I have the privilege of knowing.
And these are the faces that haunt them. That number grew by 32,000 children in just two years.
So the number that he's pointing out and that you said, Melanie, that there are currently 10
people whose job it is to identify those 89,000 children in the U.S. right now. There are very
few victim identification specialists around the world. And I am lucky enough to know so many of
them. There are some incredible people at Task Force Argos in Australia. I want to give a special
shout out to this really skilled team of four people in at Police Scotland who identified over
600 children last year. But again, this is barely touching the dot. How is it that 10 people are
supposed to identify 89,000? The scale doesn't work. So this is why we're so excited about
Operation Renewed Hope, which is the victim identification task force that happens internationally.
There's another one happening next month. And again, the Renewed Hope Act for it.
Our position is really unequivocal. We really support this bill. There are things that it does
to support the Cybercrime Center at HSI in Virginia, just here down the road from me.
There are things that it does to strengthen NCMEC itself, who we've already talked a lot
about in some of the challenges there. And it really funds some of the Internet Crimes
Against Children Task Forces, the ICACs, as we call them, whose job it is to end up investigating
this to identify the 89,000 and more. So we really want to see, I think, those new 200 specialists
who are going to be there. I think that we're seeing some great traction behind this act.
Those 200 specialists need some additional help, don't they? Because we already talked about 200
specialists aren't probably going to be able to identify 89,000 in a year. They certainly
aren't going to be able to investigate 250,000 cyber tips per year, let alone the rest of the
firehose that's coming down the line. Those specialists still need the technology infrastructure,
not just the headcount. They need the intelligence tools that GEN and other of our partners and
other people in the community are providing. They can help them triage those image series,
surface those behavioral and geographic patterns, connect material, do some of the
deconfliction work that we know that needs to happen. So this renewed HOPE Act will create
the workforce and arm them with some things, but this is really just opening the door to more.
Thanks, Sheri. Now, listeners heard again another acronym that we'll use often on this podcast,
the ICAC. ICAC. Again, it stands for what? Remind me.
Internet Crimes Against Children. These are the task forces that are organized across the country
and there are versions of this around the world as well. Thank you, Sheri. So I'll quickly say
two more bills that we are following, one of which addresses ICAC task forces. One is
Protect Our Children Act, which would reauthorize ICAC task force funding, which would be more than
$240 million over three years and would add limited liability for cyber tip prioritization
decisions. That kind of prioritization is something we're going to be talking a lot about
in future episodes, so stay tuned. And I'll also plug one more piece of legislation, the Safe
Cloud Storage Act. I'm so excited about that one, Mel. Tell us why, Sheri.
It almost sounds nerdy because it is very technical. The material that we're talking about
is so tightly regulated, right? This is sort of the worst of the worst. There is the child sexual
abuse material, but there are also some really sadistic trends that are happening, coercing
harm to both individuals and to, say, animals around. And this is the data that we're talking
about. It is so terrible that the government has said, we can never put this in the cloud. These are
things like your Microsoft Azure cloud storage, your AWS, your Apple iCloud, I think it's called
Dropbox. All of the places where we're currently storing all of our data exists in the cloud.
These are those data center storage racks, right? In contrast, what they say is it's so bad it can't
go there. So all of these law enforcement agencies and companies whose job it is to deal with this
material stores this on premise in these giant computers or server rooms that they have to manage,
that they have to own and know what to do with. And we've already talked about the volumes of
data that a national center has or IWF or CAID. There's so many of these images. But beyond that,
what this bill would allow then is for them to actually store that material in the cloud by
providing a liability shield for those companies who have cloud hosting. So this doesn't sound
super, this sounds just like a rubber stand bill, I think in many ways. It's like, oh,
we understand that this is needed. But what excites me about it actually is that it opens
the door, I think, because it's beginning to have the conversation where it's saying,
we recognize that this material can and probably should be hosted securely in the clouds. And
there's rules around it. It has to be CJIS compliant or comply with NIST. But more than that
is that the best tools that we have right now to combat this sort of material, to understand where
in the world this material is coming from, to help with victim identification, help with triaging
and processing this content. All of these are cloud based tools. What we have to do with the
things that are on premise, as we say, is create almost like lesser versions of those with small
and scrappy organizations with our tiny team of like 10 people, we have to build something that
is somehow equivalent to, you know, Claude. You can guess how well that goes. It's just,
it can't stack up to the same quality or security, honestly. So what I am really hoping happens with
this is that it enables us to do more triage and processing and enables AI related tools
to be able to manage the flow of this information. And then secondly, I think that it also potentially
opens the door to recognize that there are other organizations who have a role to play
in this fight. Organizations like ours and other nonprofits who are adjacent and touch these sorts
of crimes and technologies and material that also right now exists in the liability vacuum.
That when we are working with this, we are in some ways treading very carefully around the our own
legal issues around it. And I'm really hopeful that this begins to identify paths forward for
third parties to be able to be more directly involved in this. Thanks, Sheri. Well, I'm going
to acknowledge that Jonathan, our producer, has given us the flag to wrap things up, which we
stormed past quite a while ago. So I will set us up to wrap up. But Megan and Sheri, any last
comments before we close for today? I mean, I'd love to share the last word. I think,
look how we can keep talking for hours. This issue is complex. And there's so many players
in this space that should be in this space. And there's legislation that is needed to empower
groups like GEN and its law enforcement partners to keep doing the really nuanced, hard work safely,
securely, impactfully. And I'm so excited to just continue the conversation with various experts
in future episodes. There's so much to unpack and to educate people about.
You took the words right out of my mouth. This is just the beginning of the conversation.
And it is so in the weeds, isn't it? Like the specifics here. And there's so many conversations
that we are looking forward to having with other stakeholders. Thanks so much, Mel.
Thanks, everybody. We'll see you on episode number two.
You've been listening to Exploitation Intelligence, a podcast supported by Global Emancipation
Network. To learn more about our mission, please visit www.globalemancipation.org.
If you or someone you know is being directly affected by trafficking or exploitation,
please reach out immediately. Contact the National Human Trafficking Hotline, available 24 hours a
day, seven days a week. Call or text 1-888-373-7888. You can also text the word HELP to 233733.
You are not alone. Help is available.