Domain Atlas / Content moderation & editorial AI
GIFCT hash-sharing database
Explore this deployment in the PAN Lab ↗
In the PAN Lab, the readouts of this case's model organization carry a shaded evidence band whose width follows the least-established class among the modeling inputs the readings rest on.
The least-established input behind this case's model organization's readings is an assumption, not a measurement. Evidence base: 1 assumed · 8 published baseline.
The GIFCT Hash-Sharing Database is a cross-company index of terrorist and violent extremist content: a member platform that has found such material on its own service judges it against that platform's own policy, judges it a second time against the Global Internet Forum to Counter Terrorism's taxonomy, converts it to a perceptual hash, attaches labels and publishes the hash to a shared store that every other integrated member queries against its own uploads. On GIFCT's own figures in its 2025 Annual and Transparency Report, the store held approximately 2.4 million hashes at the end of 2025 — an increase of about 123,500 during the year — covering approximately 408,000 unique and distinct items, comprising about 329,000 visually distinct images, 79,000 visually distinct videos and 200 textually distinct PDF items. Membership stood at 39 platforms with 23 named as integrated or integrating, against 12 companies with access in the 2022 report and four founders in 2017 (Facebook, Microsoft, Twitter and YouTube); GIFCT counts over 5 billion net monthly active users across all members. Access is gated by GIFCT membership plus a signed information-sharing agreement plus the hash-sharing database code of conduct, and GIFCT stated in 2022 that governments and other non-tech company organizations do not have access to the database. There are three inclusion pathways: association with an entity on the United Nations Security Council 1267 Consolidated Sanctions List, satisfaction of the behavioural inclusion criteria added by the July 2021 taxonomy expansion, or an activation of the Incident Response Framework. GIFCT operates no platform, holds no source content, and states that it does not own or store any source data or personally identifiable information of users associated with member platforms. Every quantitative figure here is GIFCT's own and none has been independently verified.[4]
What happened
A member platform finds terrorist or violent extremist material on its own service. It judges that material against its own terms of service, and then a second time against a separate rulebook — the taxonomy of the Global Internet Forum to Counter Terrorism. If it clears the second test, the platform converts the material to a perceptual hash, attaches labels, and publishes the hash to the GIFCT Hash-Sharing Database. Every other integrated member queries that database against its own uploads from then on.
At the end of 2025 the database held approximately 2.4 million hashes covering approximately 408,000 unique and distinct items — about 329,000 visually distinct images, 79,000 videos and 200 PDF items — an increase of roughly 123,500 hashes during the year. Membership stood at 39 platforms, 23 of them named in the 2025 report as integrated with the database or integrating, against 12 companies with access in the 2022 report. GIFCT counts over 5 billion net monthly active users across all its members. Every one of those figures comes from GIFCT's own annual transparency reports, and none of them has been independently verified by anyone.
The first thing to hold steady is what a match does, because the popular version of this system is wrong in a specific way. GIFCT states plainly that "Adding hashes does not prompt any direct or automatic action on another member's platform, such as removing content", and that each member "independently determines what potential action to take". Its own published flow routes a match to the receiving platform's human review, and then to enforcement under that platform's own policy. So the pipeline is: a contributor's moderation decision, a hash with labels, a shared store, a consumer's automated comparison, a consumer's human review, a consumer's enforcement. Two independent human policy judgements in two different companies, bracketing one automated comparison. What the database does is not remove anything. What it does is set the agenda for every other member's review queue.
The second thing is where the volume sits. GIFCT's taxonomy has four behavioural categories, and it defines the largest of them, "Glorification of Terrorist Acts", as content that "glorifies, praises, condones, or celebrates attacks after the fact". At the end of 2025 that category carried 75.62 percent of behaviourally labelled hashes; "Imminent Credible Threat", the category whose meaning is hardest to argue about, carried 2.07 percent. Read the series carefully, because the denominator moves: the 2022 and 2023 reports give shares of TOTAL hashes and the 2024 and 2025 reports give shares of BEHAVIOURALLY LABELLED hashes, so the apparent jump from 62 percent to 75.94 percent between them is largely a change of basis. Normalised to the labelled subset, the recent years run 78.0, 72.1, 75.94 and 75.62 percent — and roughly 8 percent of hashes carry no behavioural label at all. The Brennan Center's Angel Diaz made the point about the category itself in September 2019, reading GIFCT's first transparency report as 85.5 percent glorification against 0.4 percent imminent credible threats: "glorification", "praise" and "condone", he wrote, are "notoriously imprecise and will almost inevitably capture expressions of general sympathy or an understanding for certain viewpoints, not to mention news reporting."
The third thing is who may fix an entry, and it is the structural finding of this case. Only the contributing member may remove its own hash, on four grounds GIFCT publishes: its own review, another member's feedback, new information or changed context, and the expiry of its own retention of the underlying content. GIFCT itself may create hashes for inclusion and may annotate a record with an alternative opinion. In December 2024 the reviewers GIFCT commissioned through its own Year 4 Hash Sharing Working Group — Dr Sean Doody and Dr Michael Jensen of the National Consortium for the Study of Terrorism and Responses to Terrorism — wrote that GIFCT "is only allowed to add additional alternative opinions to records and lacks the ability to modify the labels added to hashed content by members", and that "as it currently stands, GIFCT itself cannot directly remediate labeling mistakes for hashes submitted to the HSDB". They recommended that GIFCT "should be endowed with the proper authority to directly audit, quality control, validate, and fix labeling errors", and noted that this "would almost certainly require members to provide GIFCT access to pre-hashed content". The 2025 report does not record that authority being granted.
The same commissioned review reports that the labels the database depends on are unreliable. An internal GIFCT review of the hash-sharing database — the HSDB, in the consortium's own shorthand — found that "content in the HSDB frequently lacks labels or is sometimes labeled inconsistently or incorrectly" and that "labeling errors have accumulated"; that it was "especially difficult to determine if content advocates for, or is making a call to, violence"; and that more clarity was needed on what counts as a hate-based ideology. Ideology labels were never made mandatory and are missing for most hashes, which is also why the reviewers could not quantify the database's ideological skew — though they could state its direction, finding that members "primarily share TVEC from designated entities" and that the database "remains dominated by content produced by designated organizations". Members told the reviewers why: improving the representativeness of the database "is not currently a priority for them", and many lack the internal pipelines to hash and send material that is not tied to a designated entity.
Only one quality review of the database has ever been published, and the members ran it on themselves, because nobody else could. GIFCT explained in 2022 that it "is neither a tech company nor a social media platform and does not have any access to source content to determine what the hash corresponds to", so it asked several members to randomly sample three strata of hashes they had themselves submitted — sanctions-list-derived, incident-derived, and hashes carrying another member's disagreement feedback — and review them. Members reported no significant quality errors and no accuracy difference between the strata, and found "a very small number of hashes were incorrectly labeled and an even smaller number did not meet the taxonomy for inclusion"; labels were corrected and out-of-scope hashes removed. No denominator was given. Separately, feedback from one company on two hashes prompted the contributing member to re-review and remove them: "The content was a music video that was not violent, graphic, or explicit." That is the one concrete erroneous entry described anywhere in the public record, and it surfaced because a second company happened to look.
That disagreement channel is the only correction mechanism this arrangement has, and it runs between companies. Members may indicate agreement or disagreement with a hash's labelling and inclusion, and all of it is visible to GIFCT and to participating members. Uptake was 1.63 percent of hashes in the 2022 report — 34,014 hashes across roughly 9,000 distinct items — and approximately 2 percent in every report since; in the 2023 breakdown the vast majority was agreement, 5 percent of feedback-carrying hashes disagreed about descriptive labels while still agreeing the item belonged, and disagreement that content met the taxonomy at all ran below 0.01 percent. GIFCT warns that its own feedback data "should be treated with caution and not be considered statistically significant". Writing in the London Review of International Law in 2025, Gavin Sullivan records that the mechanism "is a means for platforms to signal disagreement with a hash's inclusion in the database" and is "only open to GIFCT members", and that GIFCT participants "consider themselves one step removed from the human rights impact" of the system.
External review is not merely absent but architecturally obstructed. Sullivan again: "Despite widespread agreement that third-party reviews of the hash-sharing database are necessary, it is not yet clear how such reviews can be carried out given the hash-sharing database itself has no content." Courtney Radsch had written the same thing for Just Security in September 2020: "none of the associated content is available for independent review or audit, either by regulators or researchers." The material behind an entry sits, if anywhere, on the contributing platform under that platform's own retention policy — and GIFCT's fourth removal ground records what happens when that lapses, at which point the entry can no longer be checked against anything by anyone. The privacy property that makes this sharing acceptable between companies is the same property that puts verification out of reach.
What GIFCT has instead is a governance layer, and it is real. It commissioned a human rights impact assessment from Business for Social Responsibility, reviewed between December 2020 and May 2021 and published in July 2021, and credits it as the origin of its Human Rights Policy and of the two elected at-large Operating Board seats added for 2026 — Discord and Twitch, the first non-founder board seats, alongside the founding members GIFCT names in its 2025 report as Meta, Microsoft and YouTube. It requires every member to publish a commitment to the UN Guiding Principles and to run its own user-appeal process. Its 2024 working groups convened 145 participants from 32 countries. Its updated Human Rights Policy post of 18 May 2026 describes due-diligence tooling and the oversight role of its Independent Advisory Committee. As fetched on 28 August 2026, neither that post nor the public explainer page for the database describes any remedy, grievance or appeals mechanism for a person whose content was matched — and each member's own appeal channel reaches that member's enforcement decision, never the shared index.
Two absences bound what this file can say. No false-positive rate, no false-negative rate — the share of matching material a matcher missed — and no precision or recall figure has ever been published for the index or for any member's matcher. And no removal anywhere has ever been publicly attributed to a hash match. Human Rights Watch reported in September 2020 that 619 of 5,396 pieces of content cited in its own reports since 2007 — 11 percent — had been removed, and that the Syrian Archive found 361,061 of the videos it had preserved, 21 percent, no longer accessible; the Brennan Center recorded over 100,000 Syrian Archive videos removed from YouTube by automated tools. Those figures measure the platform-side removal environment this index feeds. Not one of them is attributed to a match, and no such attribution exists. The honest claim is that lawful documentation of violence is demonstrably removed at scale by the systems the index feeds, and that no mechanism exists to tell whether the index contributed.
One last event, recorded because the record's silence about it is the point. GIFCT reported that "X (formerly Twitter), a founding member of GIFCT, concluded its GIFCT membership in 2025 to focus on its internal trust and safety efforts". X appears among the database-integrated members in the 2024 report and is absent from the 2025 list. Because only a contributing member may remove its own hashes, a departure leaves the question of who may now correct them unanswered anywhere in the published record.
The sociotechnical reading
Most cases in this atlas sit inside one organisation: a model, the people who act on it, the records it writes, and someone whose job is to check. This one draws its line between companies, and almost everything interesting follows from where that line falls.
Start with the automated element, because it is the smallest part of the system and the part the popular account overstates. There is no classifier here. There is a perceptual hash comparison, which asks one question — is this the same item as one on the list — and answers it. Every judgement that matters is human, and the two that matter most happen inside two different companies with two different policies. The contributor decides an item belongs in the index. The consumer decides what a match means on its own service. Neither sees the other's reasoning; what crosses between them is a hash and a label.
Now watch the authority. The party that may write an entry is the contributing member. The party that may remove an entry is the same contributing member, and nobody else. The party that owns the taxonomy, the code of conduct, the information-sharing agreements and the membership gate — GIFCT itself — may create hashes and may annotate a record, and its own commissioned reviewers wrote that it lacks the ability to modify a label and cannot directly remediate a mistake. So correction authority is unbundled from correction knowledge, and the split is total: the only party who can fix an entry is the party least likely to learn it is wrong, because nothing tells a contributor that its hash matched, or misfired, on somebody else's platform.
Then watch what checking is possible. There are three reconciliations you might want. Check a published figure against the index: impossible from outside, because access is members-only, and unclear even in principle, because the store has no content. Check a disagreement against the entry it disagrees with: the annotation sits beside the record and cannot enter it. Check an entry against the material it stands for: possible for exactly one party, the contributor, against material it still holds, for as long as its own retention policy keeps it — and GIFCT's fourth removal ground is precisely the case where it does not. One of three works, for one party, on a clock.
The volume and the ambiguity then land in the same place. Three quarters of the behaviourally labelled entries sit in the category GIFCT defines as glorifying, praising, condoning or celebrating attacks after the fact, and the category whose meaning is hardest to dispute carries about 2 percent. That is not a drafting accident: an index built to capture strong consensus between companies will fill up with the class of material that is easiest to agree is objectionable and hardest to agree on the boundary of. The consortium's own review says as much from the inside, reporting that it was especially difficult to determine whether content advocates for or calls to violence, and that labelling errors have accumulated.
Two dynamics compound in the record and both are drawn on the Lab network. Errors accumulate rather than clear, because the correction path is narrow, voluntary and used on about 2 percent of entries, while the write path is wide and continuous. And agreement is manufactured by construction: every integrated member compares against the same list, so concurrence between platforms is a property of the list and not evidence about it. Nowhere in the record does one member's matching get checked against another member's on the same material.
The last structural fact is about who is not here. The person whose upload is matched appears in this system as an upload and is absent from it as a party. They can appeal to the platform that acted, because GIFCT's membership criteria require every member to run a user-appeal channel — but that appeal reaches the acting platform's own policy decision and stops there. Nothing tells them that a shared index was involved. Nothing tells the contributing company that its judgement travelled and misfired somewhere else. No route exists between the two. That asymmetry is not a gap in an otherwise complete design; it is what a company-initiated cross-platform enforcement index is.
Two boundaries hold on the Lab network and neither is decoration. Served people are not modelled: no removal, appeal, reinstatement or outcome for any person is computed from anything on the diagram, and the removal figures civil society has measured are recorded external observations of the environment this index feeds, carried without an attribution the record does not support. And this board is the SHARE, not a platform: it does not draw any member's own moderation pipeline, any member's own enforcement, or any member's own appeal channel, all of which sit inside companies and outside this boundary.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.