A deep investigative look at years of documented failures
A deep investigative look at years of documented failures
Here is a simple question that Meta has now been asked, in one form or another, by a state attorney general, a nonprofit research group, a major newspaper, an international broadcaster, and the Indian government.
How do dangerous, sexually exploitative, and sometimes outright illegal ads keep making it through a company’s own paid ad system, a system that Meta reviews and approves before a single ad goes live?
Meta has given some version of the same answer every time. It has a zero tolerance policy. It works aggressively against this kind of abuse. Its systems are not perfect. What has been much harder to find, across several years of reporting, is evidence that any of that has actually fixed the problem.
Meta’s adult nudity and sexual activity advertising policy
This is not a story about a single scandal. It’s a story about a pattern, one that stretches across at least three years, multiple countries, a state lawsuit, an independent research group, a major European newspaper, a British broadcaster, and a national government. Each of these investigations found something slightly different. Together, they describe the same basic failure, repeating itself in almost exactly the same way, each time.
Walmart and Match Group learn the hard way
Start with what happened to Walmart and Match Group, the company behind Tinder and Hinge, in late 2023. Both companies are big spenders on Meta advertising, the kind of customers a platform is supposed to protect above almost anyone else, since they represent the direct revenue Meta depends on. According to a lawsuit filed by New Mexico’s attorney general, Match noticed its dating app ads showing up next to short videos on Facebook and Instagram that appeared to promote illegal and exploitative activity, including troubling imagery involving young girls. This wasn’t a fringe corner of the platform. Reels, the short video feature at the center of the complaint, is one of Meta’s most heavily promoted products, the one the company has spent years pushing users and advertisers toward.
When Meta did not fix the problem after being notified, Match’s CEO wrote directly to Mark Zuckerberg, describing the situation in blunt terms and noting the company was paying millions of dollars to have its ads shown next to exactly the kind of content it was trying to escape. According to the lawsuit, Zuckerberg never responded personally.
Walmart had a similar experience around the same time, telling Meta that the company’s attention to brand safety had all but disappeared. Meta’s own reply, quoted in the legal filing, was that there was some minimal exposure to ad placements Walmart hadn’t approved, a description that understated the problem badly enough that Walmart’s own marketing team called the response unacceptable. One Walmart representative said, according to the complaint, that they were disappointed Meta’s team seemed more focused on getting a press statement right than on fixing what was actually happening. That’s a telling detail. Two of the biggest advertisers on the planet were essentially describing a company more concerned with managing the story than solving the underlying issue.
The lawsuit didn’t stop at ads placement. Investigators working for the New Mexico attorney general’s office ran their own test, searching Instagram and finding accounts and posts depicting or promoting abuse of young girls. They reported everything they found directly to Meta, through the company’s own reporting tools. According to the complaint, Meta removed only about half of what was reported. Content that was taken down would often reappear under a new account soon after, or Meta’s own recommendation system would suggest similar material to replace whatever had just been removed. The lawsuit’s conclusion was blunt: Meta clearly has the technical ability to identify this kind of content. What it appears to lack is the ability, or perhaps the institutional will, to actually deal with it once it’s found, especially at the volume and speed the problem demands.
Also Read: A New Cold War Is Coming
A former Instagram employee added a personal dimension to this same case, testifying before Congress that his own daughter had received unwanted advances from an adult online, and that when he raised the issue with senior Meta leadership directly, he says he was ignored. Whatever the full context of that exchange, it underscores the same theme running through the entire lawsuit: warnings reaching the company through multiple channels, informal and formal, corporate and personal, without producing a fix that stuck.
A different kind of ad problem, hiding in plain sight
A little over a year later, a separate investigation turned up a related but distinct problem, one that had nothing to do with organic posts or Reels and everything to do with paid advertising specifically. The nonprofit research group AI Forensics, working with the French newspaper Le Monde, published a report in January 2025 documenting thousands of explicit pornographic ads running on Facebook and Instagram, something both platforms explicitly and unambiguously ban in their advertising policies.
Thousands of pornographic ads go unmoderated on Facebook and Instagram — Le Monde
What made this report especially damning was how easy the ads were to find. Researchers didn’t need special access or insider information. They located the ads using simple, everyday search terms inside Meta’s own public ad library, a transparency tool the company built specifically so anyone, researchers, journalists, or regulators, could see what’s being advertised across its platforms. In other words, Meta had already published the evidence of its own failure in a searchable public database, and nobody at the company had apparently checked.
The numbers were not small. The ads had reportedly generated more than eight million views across Europe over the course of roughly a year, reaching mostly men in their forties living in Germany and France. Some of the videos involved deepfakes, digitally manipulated footage using the faces and voices of real, identifiable public figures, including a well known French actor, a prominent television doctor, and a media personality, to falsely promote the products being sold. That detail matters beyond the obvious ick factor. It means Meta’s ad review system failed on two counts simultaneously: it missed sexually explicit content that its own written policies clearly prohibit, and it missed a form of manipulated media using real people’s identities without consent, a separate category of harm the company also claims to take seriously. A system built to catch either problem should have caught ads that violated both at once. It caught neither, for over a year, at a scale in the thousands.

The BBC investigation and India’s response
Then, this past July, came the most serious version of this pattern yet. A BBC Eye investigation found that Instagram was running paid advertisements in India that referenced child sexual abuse material, some of which pointed users toward Telegram channels where that material was reportedly being sold. The methodology behind this investigation is worth sitting with, because it shows just how little effort was required to expose the problem. Reporters created a brand new Instagram account, essentially a blank slate with no search history. They followed ten profiles that Instagram’s own algorithm was actively suggesting to that new account. Within less than a week, without the account searching for anything remotely related, Instagram began serving it paid ads for adult pornography. Days after that, the same account started receiving ads connected to child sexual abuse material.
Read that sequence again. The platform’s own recommendation and advertising systems escalated a brand new account toward increasingly extreme and illegal content entirely on their own initiative, based on nothing more than which accounts it followed. No searches. No explicit signals of intent. Just the platform’s own machinery, working exactly as it was built to keep people engaged, pulling a user progressively further into darker territory with each passing day.
India’s technology ministry responded quickly once the investigation aired, issuing a formal notice ordering Meta to immediately disable the ads and content in question and demanding a full written explanation within seven days. This wasn’t a symbolic gesture. India is Meta’s single largest market by user count, with hundreds of millions of Instagram and Facebook users in the country, giving the government real leverage that smaller markets typically lack.
Meta’s response followed a script that, by this point in the story, should sound familiar. It called child exploitation a horrific crime. It said it uses advanced technology to detect this material proactively. It said it was in a constant fight against criminals hiding among its billions of users. And it repeated, almost word for word, language it had used in prior incidents involving entirely different companies and different years, calling it categorically inaccurate to suggest the company knowingly targeted such ads to people with an inappropriate interest in children. Separately, Meta noted it had removed roughly 13 million pieces of child sexual exploitation content across its platforms in a recent three month period, with well over 90 percent of it caught proactively before any user reported it. Those numbers are genuinely large, and they reflect real investment in detection technology. They also don’t explain how a brand new test account, followed by BBC reporters, was pushed toward the exact category of content those systems are supposedly built to intercept.
What happened when I reported one myself
This isn’t only something that shows up in lawsuits and investigative documentaries filed by other people. Last month, I came across an ad on Facebook that I believe showed actual child sexual abuse material, and I reported it directly through Meta’s own reporting tool.

I wish I could share the ad with you but it was a video of a girl in her teens, stripping down and using asymmetrical objects on herself. The quality of the video made it seem as if it was from a webcam.
That response, on its own, tells you most of what you need to know about how seriously an individual report like this is actually handled once it reaches Meta’s review queue.
A pattern, not a series of accidents
Reading these episodes side by side, spanning late 2023 through the middle of 2026, a pattern becomes hard to miss. Different investigators. Different countries. Different types of illegal or dangerous content, ranging from brand safety violations involving major retailers, to explicit deepfakes of real public figures, to child exploitation material connected to criminal networks. And in every single case, the same basic result: outside researchers, journalists, corporate advertisers, or a foreign government did the work of finding the problem, and Meta’s own review systems, the ones built and paid for specifically to catch this before it reaches anyone, did not.
Alongside the reporting already documented by others, additional ad placements matching this same pattern have been independently observed and archived over recent months, adding further weight to what the existing investigations already describe. Taken together, this isn’t a story about one bad actor slipping past a system once. It’s a story about a system that keeps getting beaten in the same basic way, by different categories of harmful content, across multiple years and multiple countries, while the company running it keeps offering nearly identical reassurances each time it happens.
It’s also worth noting that Meta is not the only platform facing this exact criticism. YouTube received a similar government notice around the same period as Meta’s most recent scandal, and gave a very different answer, stating flatly that it had not detected child sexual abuse material on its platform and had not received evidence of it from regulators. That denial sits somewhat awkwardly next to YouTube’s own history with this issue, including a 2017 episode where several major global advertisers pulled their campaigns after reporting found ads running next to videos of children that were attracting sexualized comments from viewers, and a UK government inquiry years later that documented a similar problem with the platform’s recommendation system pushing viewers toward more of the same content. The specifics differ from Meta’s case, and it would be inaccurate to claim the exact same evidence exists against both companies. But the broader dynamic, a platform’s core recommendation and advertising machinery inadvertently amplifying harmful content faster than its safety systems can catch it, is not unique to any single company. It appears to be a structural feature of how these platforms are built.
Also Read: Sexual Assault Is Being Reduced to a Joke and We’re Letting It Happen
Why this keeps happening
There’s a structural reason this keeps happening, and it’s worth naming plainly rather than treating each incident as an isolated failure. Automated ad review exists primarily to approve content quickly, because speed of approval is directly tied to advertising revenue. Every day an ad sits in review instead of running is money the platform isn’t making yet. That system tends to be genuinely good at catching material that has already been flagged, hashed, and cataloged somewhere in a database of known violations, the digital equivalent of a most wanted list. It is much weaker against novel, coded, or context dependent material, exactly the kind that determined bad actors learn to produce specifically because it slips past automated filters trained mostly on previously identified content.
A study from AI Forensics, separate from its work with Le Monde, found that Meta’s own systems automatically deleted screenshots of certain sexually explicit advertisements when ordinary users tried to repost them as organic content, meaning the company’s technology could clearly recognize the content as violating its rules in that context. That same technology, applied to the original paid advertisement before it ever ran, apparently did not stop it from being approved in the first place. That’s not a story about a system that can’t detect the problem. It’s a story about a system that detects it inconsistently, depending on which part of the platform the content shows up in.
A related investigation by the Tech Transparency Project documented hundreds of paid advertisements for weapons and weapon accessories that Meta’s ad review approved despite clear policies against exactly that kind of content. Different subject matter, same underlying failure: technology capable of flagging prohibited material in one context, not applied consistently to the one part of the platform, paid advertising, where Meta has the most direct control and the clearest financial stake in the outcome.
Meta itself has acknowledged this dynamic more than once, noting that no system is perfect against people actively trying to defeat it. That’s true of every content moderation system ever built, at every company, in every era of the internet. It is also not, on its own, an acceptable place to stop, particularly when the content in question involves children, and the system being defeated is one the company designed, built, profits from directly, and fully controls from top to bottom.
A harder question underneath all of this
Separately from the advertising failures, Meta and YouTube have also faced legal scrutiny over whether their core products were designed to be addictive in ways that harmed young users more broadly. A Los Angeles jury and a New Mexico jury each reached findings against the companies on related questions this year, examining whether platform design choices, not just content moderation gaps, contributed to harm among users who began using these services as children. That’s a distinct legal and factual question from the ad moderation failures described here, and it would be unfair to collapse the two into a single accusation. But the two threads do reinforce each other in an important way. They both point toward the same underlying tension: systems built primarily to maximize engagement and revenue, evaluated afterward for whether they also protected the people using them, rather than being built with that protection as a design constraint from the start.
What a real fix would actually require
It’s worth being fair about the sheer scale Meta is operating at, because that context matters and shouldn’t be waved away. Billions of people use its platforms every single day, and the company has reported removing tens of millions of pieces of violating content in short windows of time, the overwhelming majority of it caught before anyone even reports it. That is a genuinely difficult problem, and no moderation system anywhere, run by any company, catches everything. Meta has also helped build and fund cross industry tools specifically aimed at this problem, including a coalition called Lantern that lets participating tech companies share signals about predatory accounts so multiple platforms can act on the same intelligence at the same time, rather than each company fighting the exact same bad actors in isolation. That kind of cooperation is a genuine, meaningful response, not just a public relations gesture, and it deserves real acknowledgment even from the harshest critics of the company.
But scale being a real and legitimate constraint doesn’t make it a sufficient excuse, especially for the specific slice of this problem that is paid advertising. Organic content moving through a platform at galactic scale is one thing, an ocean that’s genuinely hard to police in real time. A paid advertisement is a fundamentally different category. It is a transaction. Someone pays money, submits specific creative material, and a company’s own review system evaluates and approves that exact material before it runs in front of an audience the advertiser has specifically selected.
That is a dramatically more controllable surface than the general firehose of user uploads, and it’s precisely the surface where researchers, across multiple separate investigations, keep finding the clearest evidence that detection technology exists and simply isn’t being consistently enforced.
What would actually change this pattern is not some unknowable mystery requiring new technology nobody has thought of yet. Independent, recurring audits of Meta’s ad review process, conducted by outside researchers without financial ties to the company, would surface problems long before journalists or foreign governments have to do it instead, as has happened repeatedly.
Meaningful consequences, financial or regulatory, tied to a demonstrated pattern of failure across multiple incidents rather than treated as isolated one off scandals, would give the company a stronger incentive than the ones it currently faces. Regulators pushing for actual documented explanations, not blog posts and press statements, of how specific violating ads made it through review in the first place is a reasonable and overdue demand, and India’s insistence on a formal written accounting rather than a public relations response is the right instinct, one other governments would do well to copy.
Advertisers themselves also have more leverage here than they’ve historically used. When Walmart and Match pushed hard in 2023, they got direct answers from senior Meta leadership, even if those answers weren’t ultimately satisfying to either company. Most of the time, it’s outside reporters, nonprofit researchers, and foreign regulators doing that pushing instead of the companies who actually pay Meta’s bills. Advertisers collectively spend enormous sums keeping this business model running. A more organized and sustained use of that leverage, rather than the occasional angry email that eventually fades once the news cycle moves on, could shift incentives in a way that individual scandals, however damning, have so far failed to do on their own.
None of this requires believing that Meta secretly wants any of this content on its platforms. Almost nobody who has looked closely at this issue believes that, and it isn’t really the accusation that matters most here. What matters is a much more mundane and, in its own way, more damning fact: this is one of the most profitable companies in the world, with some of the most sophisticated detection technology ever built, technology that has been shown, by its own actions and by independent researchers working completely separately from one another, to work when it’s actually applied.
The question this entire pattern of investigations keeps raising isn’t whether Meta can catch this kind of content. The evidence says it clearly can, at least some of the time, in some parts of the platform. The real question is why, in its most tightly controlled and directly monetized system, the one it built specifically to review content before anyone ever sees it, it keeps not catching it until somebody else does that work first.
Also Read: How Anthropic Quietly Proved Its Own AI Would Kill to Avoid Being Shut Down
Insight into the Growing Incel Culture
A suspect was taken into custody Monday morning after deploying fireworks and a flammable liquid outside 26 Federal Plaza in Lower Manhattan, a building housing ICE, the FBI and other federal agencies.
Reading Summoners is similar to walking into a city that never stops moving. There is always movement below the surface, even in quiet streets. Bells are suspended, ready to ring. Just out of sight, spirits wait. People live their lives with the knowledge that death is inevitable and that someone will be held accountable when …