Domain Atlas / Content moderation & editorial AI

Case fileUnited Kingdom and global (StopNCII.org, operated by the Revenge Porn Helpline within SWGfL); United States and global (Take It Down, operated by the National Center for Missing & Exploited Children); participating platforms worldwide; US federal overlay from May 2026 (TAKE IT DOWN Act), UK Online Safety Act overlay 2024-2026medium deployment

StopNCII & Take It Down

StopNCII.org (operated by the Revenge Porn Helpline within the UK charity SWGfL, developed with Meta, launched December 2021) and Take It Down (operated by the US National Center for Missing & Exploited Children, launched February 2023) run one on-device hash-removal mechanism in two configurations: the person who holds the material generates a hash on their own device, only the hash leaves the device, the original is never uploaded or stored, third-party submission is refused and eligibility is self-attested, and participating platforms match the hash against uploads on public or unencrypted surfaces, reviewing any match under their own policies. StopNCII states its algorithms as PDQ and PhotoDNA for photos and MD5 for videos; independent researchers verified by inspecting the Take It Down web client that it runs PDQ. The operators' own volume reports — advocacy-tier counts of reporting behaviour, never incidence — were 2 million images protected across more than 785,000 cases by November 25, 2025 on the StopNCII side (a reported 97 percent increase over 2024, 17 industry partners) and 130,000+ submissions covering 273,000+ images and videos in 2025 on the Take It Down side, up from 83,000+ submissions in 2024. As fetched 2026-08-27 the two partner rosters overlap and diverge (YouTube on the minor index only, X on the adult index only, Discord on neither), encrypted surfaces are outside both by design, and Google announced on September 17, 2025 that it will use StopNCII hashes in Search — an announcement scoped to Search results, with Google absent from the StopNCII partners page as fetched the same day.[6]

What happened

StopNCII.org, launched in December 2021 by the Revenge Porn Helpline within the UK charity SWGfL and developed with Meta, and Take It Down, launched in February 2023 by the US National Center for Missing & Exploited Children, are two named configurations of one mechanism — and this case file is about the pair, because neither alone supports a derivable picture. The mechanism: an adult who holds intimate material of themselves (StopNCII), or a person who was under 18 when the material was made (Take It Down), opens a web client that computes a perceptual hash of the material on their own device. Only the hash leaves the device; the original is never uploaded, never stored, and never seen by any operator. Third-party submission is refused and eligibility is self-attested. The hash enters the operator's bank and is shared with participating platforms, whose matching systems — self-hosted or supplied by vendors such as Thorn's Safer — compare it against uploads on public or unencrypted surfaces. A match surfaces the uploaded content to the platform's own trust-and-safety review, which decides under the platform's own policy whether to act: a hash match obliges nobody, and every removal is a human platform decision. StopNCII states its algorithms plainly — the PDQ perceptual-hash tool and PhotoDNA for photos, MD5 for videos — and independent researchers verified by inspecting Take It Down's web client that it runs PDQ. The two configurations then diverge, by design, into a natural experiment on the victim channel: StopNCII gives the reporter a case number, a PIN and a status page (updates can take 3 to 5 days) and services whole-case withdrawals against credentials the operator does not store and cannot reset; Take It Down is anonymous by construction, with no status channel, no notification of matches, and no withdrawal mechanism at all. StopNCII states that hashes persist after a reporter deletes the image, are shared with new partners as they join, and that participating companies "reserve the right to continue enforcing their policies once they've acquired knowledge of the hash" — so an entry's reach grows after submission, and a withdrawal, where one exists, retracts the bank's copy but not the partners'.

The scale and the gaps are both documented, and the figures are the operators' own. SWGfL reported on November 25, 2025 that StopNCII hashes were protecting 2 million images across more than 785,000 cases — a 97 percent increase over 2024 — with 17 industry partners; NCMEC's dashboard reports Take It Down submissions rising from 83,000+ (166,000+ hashes) in 2024 to 130,000+ covering 273,000+ images and videos in 2025. These are advocacy-tier counts of reporting behaviour, never incidence, and no operator in this class publishes an audited error rate for its deployed system. Coverage is a patchwork the person reporting cannot see around: as of August 27, 2026, YouTube matches the Take It Down list but not StopNCII's, X matches StopNCII's but not Take It Down's, Discord matches neither, and encrypted messaging surfaces are outside both by design. Google announced on September 17, 2025 that it would begin using StopNCII hashes to proactively remove non-consensual intimate imagery from Search results — an announcement scoped to Search, rolling out over months, and Google did not appear on the StopNCII partners page as fetched the same day the rosters above were. The operators also document the match-error surface themselves: cropped, filtered or clipped material may defeat the original hash, video and image hashes are different formats, and the index reaches participating platforms only. On the adversarial side, an evaluation presented at the USENIX Security conference in 2023 demonstrated efficient targeted second-preimage and detection-avoidance attacks against PhotoDNA and PDQ, concluding existing perceptual hash functions are likely insufficiently robust for adversarial settings. When this system fails, nobody is falsely accused: every documented failure is a protection gap — a non-participating platform, an encrypted surface, a re-encoded copy, a partner copy a withdrawal cannot reach, a status question the anonymous configuration can never answer.

The governance event of the record has an unusually clean shape. In 2023-2024, researchers at Royal Holloway and partner institutions reconstructed recognizable pre-images — hair colour and length, face shape, other facial features, some background — from PDQ, PhotoDNA, NeuralHash and aHash hashes, using an off-the-shelf conditional image-to-image generative network trained on 1,000 public celebrity-face images on 2015-era consumer hardware, with mean perceptual similarity of 60.10 percent for PDQ and 74.04 percent for PhotoDNA. The measurements were made on a public celebrity-face benchmark, never on any reporter's material; the authors concluded the hashes should be treated as sensitive in the same way as the original images. The same team quoted Take It Down's FAQ — "No, images and videos cannot be reverse engineered or created from the hash values shared with NCMEC." — reported that answer to be wrong, wrote to the operator twice between August and December 2023, received no reply, and recorded that the website did not change. The sentence was still on the FAQ page on August 27, 2026. Meanwhile the voluntary index is being pulled into a mandatory legal regime on both sides of the Atlantic. The US TAKE IT DOWN Act's notice-and-removal duty took effect May 19, 2026: covered platforms must remove reported non-consensual intimate imagery and known identical copies within 48 hours of a valid request, enforced by the Federal Trade Commission (FTC), with compliance letters sent to fifteen major companies — including Alphabet, Discord and X, companies that do not all participate in either voluntary hash index. The UK made NCII sharing a priority offence under the Online Safety Act in 2024, brought a creation offence into force on February 6, 2026, expects Ofcom's hash-matching code measures in force from summer 2026, and has announced a 48-hour takedown amendment with penalties up to 10 percent of worldwide turnover. Separately, a University of Michigan audit study (ACM CSCW 2026) reported 50 synthetic-persona deepfake images through X's own victim-facing channels: reports filed under the Digital Millennium Copyright Act (DMCA) achieved 100 percent removal within about 25 hours, while reports through the non-consensual-nudity mechanism achieved zero removals over 21 days — a study of the platform's report flow, not of hash matching, and independent evidence that a platform's participation in a hash program can coexist with a non-functioning victim-facing report channel.

The sociotechnical reading

The defining fact of this deployment class is that its central protection and its central weakness are the same design decision. Hashing on the victim's device means the material never leaves their control — the strongest data-minimization posture in this atlas, and the reason a person in the worst week of their life can use the service at all. It also means the index can never be verified against anything by anyone: no analyst assesses a submission in either named configuration, eligibility is self-attested, and the reference material an entry would be checked against exists nowhere any operator can reach. Verification of this artifact is possible only where a platform already holds the material — exactly where the exposure the design exists to prevent has already occurred. The Lab network draws that as structure rather than prose: the submission write runs at full strength with nothing but a mechanical validity screen in front of it, the operator's bank carries no inbound check at all, and the only substantive check anywhere in the system is the platform's own policy review of a match, in a different organisation from the index. The pairing is what makes any of this measurable. Two operators run the same mechanism with opposite victim-channel designs — case, PIN, status and withdrawal on one side; anonymity, no status, no notification, no withdrawal on the other — so each is the other's controlled contrast, and the propagation facts on the record are StopNCII's own: hashes outliving the material, partner copies beyond a withdrawal's reach, rosters that grow and churn. A neighbouring deployment shows what the missing gate looks like when the content class permits one: the Internet Watch Foundation's hotline — a child-sexual-abuse-material service, a different content class and no part of this pair — has a trained analyst assess every report against published legal guidelines before anything is listed, which is the assessment-before-listing step the on-device design forecloses by construction.

The record's second lesson is about what happens when the only outside check has no reach. The independent security evaluation is the strongest examination this artifact has ever received, performed without operator cooperation through the public web client, and it produced a specific, reproducible, published contradiction of the operator's printed privacy reassurance. The disclosure loop then failed completely and measurably: two letters, no reply, no site change, and the contradicted sentence still live three years later — while the operators' volume figures doubled and lawmakers on two continents began converting the voluntary mechanism into legally load-bearing infrastructure, without ever adding an audit surface. The honest boundaries matter as much as the findings. The reconstruction magnitudes describe the invertibility of the hash class on a public benchmark, not any individual's exposure. The volume figures are operator self-reports and count reporting behaviour, not abuse. The Michigan audit tested a platform's report channel, not the hash pipeline, and it is used here only to keep those two channels separate. The statutes mandate answering removal requests; they do not mandate joining an index, and nothing about them audits one. And the failure modes of this protective system are gaps, not accusations: the map's open pathways are the places where a person who did everything right remains unprotected — and, in the anonymous configuration, will never know either way.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

stopnciiGroundingAdvocacySave

StopNCII.org (Revenge Porn Helpline / SWGfL). Service pages: How It Works, Industry Partners, Frequently Asked Questions https://stopncii.org/

https://stopncii.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

nationalcenterformissingexplGroundingAdvocacySave

National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/

https://takeitdown.ncmec.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

thornGroundingVendorSave

Thorn, "Safer" (CSAM detection service for platforms). https://safer.io/

https://safer.io/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

hawkes2024GroundingAcademicSave

Hawkes, S., Weinert, C., Almeida, T., & Mehrnezhad, M. (2024). Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools. IEEE Security & Privacy Magazine https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

Grounds: model org: ncii_hash_removal_service

Topics: privacy-security

prokos2023GroundingAcademicSave

Prokos, J., Fendley, N., Green, M., Schuster, R., Tromer, E., Jois, T., & Cao, Y. (2023). Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning. 32nd USENIX Security Symposium https://www.usenix.org/conference/usenixsecurity23/presentation/prokos

https://www.usenix.org/conference/usenixsecurity23/presentation/prokos

Grounds: model org: ncii_hash_removal_service

zhangandcolleagues2026GroundingAcademicSave

Zhang and colleagues, Reporting Non-Consensual Intimate Media: An Audit Study of Deepfakes (ACM CSCW 2026; read in the arXiv 2409.12138 preprint version) https://arxiv.org/html/2409.12138v1

https://arxiv.org/html/2409.12138v1

Grounds: model org: ncii_hash_removal_service

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalStopNCII.org (operated by the Revenge Porn Helpline within the UK charity SWGfL, developed with Meta, launched…

StopNCII.org (operated by the Revenge Porn Helpline within the UK charity SWGfL, developed with Meta, launched December 2021) and Take It Down (operated by the US National Center for Missing & Exploited Children, launched February 2023) run one on-device hash-removal mechanism in two configurations: the person who holds the material generates a hash on their own device, only the hash leaves the device, the original is never uploaded or stored, third-party submission is refused and eligibility is self-attested, and participating platforms match the hash against uploads on public or unencrypted surfaces, reviewing any match under their own policies. StopNCII states its algorithms as PDQ and PhotoDNA for photos and MD5 for videos; independent researchers verified by inspecting the Take It Down web client that it runs PDQ. The operators' own volume reports — advocacy-tier counts of reporting behaviour, never incidence — were 2 million images protected across more than 785,000 cases by November 25, 2025 on the StopNCII side (a reported 97 percent increase over 2024, 17 industry partners) and 130,000+ submissions covering 273,000+ images and videos in 2025 on the Take It Down side, up from 83,000+ submissions in 2024. As fetched 2026-08-27 the two partner rosters overlap and diverge (YouTube on the minor index only, X on the adult index only, Discord on neither), encrypted surfaces are outside both by design, and Google announced on September 17, 2025 that it will use StopNCII hashes in Search — an announcement scoped to Search results, with Google absent from the StopNCII partners page as fetched the same day.

stopnciiGroundingAdvocacySave

StopNCII.org (Revenge Porn Helpline / SWGfL). Service pages: How It Works, Industry Partners, Frequently Asked Questions https://stopncii.org/

https://stopncii.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

nationalcenterformissingexplGroundingAdvocacySave

National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/

https://takeitdown.ncmec.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

hawkes2024GroundingAcademicSave

Hawkes, S., Weinert, C., Almeida, T., & Mehrnezhad, M. (2024). Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools. IEEE Security & Privacy Magazine https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

Grounds: model org: ncii_hash_removal_service

Topics: privacy-security

EmpiricalA peer-reviewed independent evaluation (IEEE Security & Privacy Magazine 2024) reconstructed recognizable pre-…

A peer-reviewed independent evaluation (IEEE Security & Privacy Magazine 2024) reconstructed recognizable pre-images — hair colour and length, face shape, other facial features, some background — from PDQ, PhotoDNA, NeuralHash and aHash hashes using an off-the-shelf conditional image-to-image generative network trained on 1,000 public celebrity-face images on 2015-era consumer hardware, with mean perceptual similarity of 60.10 percent for PDQ and 74.04 percent for PhotoDNA, measured on a public celebrity-face benchmark and never on any reporter's material; the authors concluded the hashes should be treated as sensitive in the same way as the original images. The same team quoted Take It Down's FAQ answer that material 'cannot be reverse engineered or created from the hash values shared with NCMEC', reported that answer to be wrong, wrote to the operator twice between August and December 2023, received no reply, and recorded that the website did not change; the sentence was still on the FAQ page on 2026-08-27. A separate USENIX Security 2023 evaluation demonstrated efficient targeted second-preimage and detection-avoidance attacks against PhotoDNA and PDQ, concluding existing perceptual hash functions are likely insufficiently robust for adversarial settings. No operator in this class publishes an audited error rate for its deployed system.

hawkes2024GroundingAcademicSave

Hawkes, S., Weinert, C., Almeida, T., & Mehrnezhad, M. (2024). Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools. IEEE Security & Privacy Magazine https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf

Grounds: model org: ncii_hash_removal_service

Topics: privacy-security

prokos2023GroundingAcademicSave

Prokos, J., Fendley, N., Green, M., Schuster, R., Tromer, E., Jois, T., & Cao, Y. (2023). Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning. 32nd USENIX Security Symposium https://www.usenix.org/conference/usenixsecurity23/presentation/prokos

https://www.usenix.org/conference/usenixsecurity23/presentation/prokos

Grounds: model org: ncii_hash_removal_service

nationalcenterformissingexplGroundingAdvocacySave

National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/

https://takeitdown.ncmec.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

EmpiricalThe two configurations diverge on the victim channel by design, and both operators document the propagation su…

The two configurations diverge on the victim channel by design, and both operators document the propagation surface a withdrawal does not reach. StopNCII gives a reporter a case number, PIN and status page (updates can take 3 to 5 days) and services whole-case withdrawal against credentials the operator states it does not store and cannot reset; Take It Down is anonymous by construction, with no status channel, no notification of matches, and no withdrawal mechanism at all. StopNCII states that hashes persist after the reporter deletes the image and are shared with new partners as they join, and its FAQ states that participating companies 'reserve the right to continue enforcing their policies once they've acquired knowledge of the hash' — so an entry's reach grows after submission and a withdrawal retracts the bank's copy but not partner-held copies. A hash match obliges nobody: matching platforms review the content against their own policies before any action, platform-side matching is deployed self-hosted or by vendor API, and every documented failure of this protective system is a protection gap — a non-participating platform, an encrypted surface, a re-encoded copy that no longer matches, a partner copy a withdrawal cannot reach — never a false accusation.

stopnciiGroundingAdvocacySave

StopNCII.org (Revenge Porn Helpline / SWGfL). Service pages: How It Works, Industry Partners, Frequently Asked Questions https://stopncii.org/

https://stopncii.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

nationalcenterformissingexplGroundingAdvocacySave

National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/

https://takeitdown.ncmec.org/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

thornGroundingVendorSave

Thorn, "Safer" (CSAM detection service for platforms). https://safer.io/

https://safer.io/

Appears in: PAN framework development

Grounds: book grounding: trafficking and exploitation detection (ch15); model org: ncii_hash_removal_service

EmpiricalA University of Michigan audit study (ACM CSCW 2026) posted 50 synthetic-persona deepfake nude images to X and…

A University of Michigan audit study (ACM CSCW 2026) posted 50 synthetic-persona deepfake nude images to X and reported half through X's non-consensual-nudity mechanism and half as DMCA copyright violations: the DMCA reports achieved 100 percent removal within about 25 hours (mean 20.3 hours), while the non-consensual-nudity reports achieved zero removals over 21 days. The study tested X's victim-facing report channels, not hash matching, and X is a StopNCII partner — independent evidence that a platform's participation in a hash program can coexist with a non-functioning victim-facing report channel, which is why the match channel and the platform report channel are modeled separately.

zhangandcolleagues2026GroundingAcademicSave

Zhang and colleagues, Reporting Non-Consensual Intimate Media: An Audit Study of Deepfakes (ACM CSCW 2026; read in the arXiv 2409.12138 preprint version) https://arxiv.org/html/2409.12138v1

https://arxiv.org/html/2409.12138v1

Grounds: model org: ncii_hash_removal_service

EmpiricalThe voluntary hash indexes acquired a mandatory legal overlay during 2024-2026, on separate tracks that operat…

The voluntary hash indexes acquired a mandatory legal overlay during 2024-2026, on separate tracks that operate independently of hash-program membership. In the US, the TAKE IT DOWN Act's Section 3 notice-and-removal duty took effect May 19, 2026: covered platforms must remove reported non-consensual intimate imagery and known identical copies within 48 hours of a valid request, enforced by the FTC, which opened a complaint portal and sent compliance letters to fifteen major companies including Alphabet, Discord and X — companies that do not all participate in either voluntary hash index. In the UK, NCII sharing became a priority offence under the Online Safety Act via 2024 regulations, a creation offence covering purported intimate images including deepfakes came into force February 6, 2026 under the Data (Use and Access) Act 2025, Ofcom's hash-matching code measures were expected in force from summer 2026, and a Crime and Policing Bill amendment announced February 19, 2026 would require 48-hour takedown with penalties up to 10 percent of worldwide turnover. The statutes mandate responding to removal requests; they do not require joining either hash index, and they leave the indexes' unauditability untouched.