Skip to content

PAN Lab example

The GIFCT hash-sharing database and member matching system

One member writes the entry; every member reads it

Thirty-nine platforms share one index. A member company finds terrorist or violent extremist material on its own service, judges it against its own terms of service, judges it a second time against a separate rulebook the consortium owns, converts it to a perceptual hash, attaches labels and publishes the hash. Every other integrated member queries that store against its own uploads from then on. Modeled on the documented record of the Global Internet Forum to Counter Terrorism and its Hash-Sharing Database. Hold two things steady before anything else. First, what a match does: the consortium states that adding hashes prompts no direct or automatic action on another member's platform and that each member independently determines what action to take, and its own published flow sends a match to the receiving platform's human review before anything happens there. So this is not an automatic cross-platform ban. It is one company's classification arriving in every other company's review queue, which is a smaller claim and a harder one. Second, where the volume sits: at the end of 2025 the store held approximately 2.4 million hashes over approximately 408,000 unique and distinct items, and 75.62 percent of the behaviourally labelled ones sat in the category the consortium defines as glorifying, praising, condoning or celebrating attacks after the fact. The category whose meaning is hardest to argue about, imminent credible threat, carried 2.07 percent. Read that series carefully, because the denominator moves: the 2022 and 2023 reports give shares of total hashes and the 2024 and 2025 reports give shares of behaviourally labelled hashes, and roughly 8 percent of hashes carry no behavioural label at all. Every figure in this paragraph is the consortium's own, from its annual transparency reports, and none of it has been independently verified. Now the authority, which is the case. Only the contributing member may take its own hash out, on four published grounds, one of which is that it no longer keeps the material and can no longer check the hash. The consortium that owns the taxonomy may create hashes and may add an alternative opinion beside a record. In December 2024 the reviewers it commissioned wrote that it is only allowed to add alternative opinions and lacks the ability to modify the labels members apply, and that as things stand it cannot directly remediate labelling mistakes; they recommended it be given authority to audit, validate and fix labelling errors, and the 2025 report does not record that authority being granted. The same review reports that content in the database frequently lacks labels or is labelled inconsistently or incorrectly, that labelling errors have accumulated, and that it was especially difficult to determine whether content advocates for or calls to violence. So the only party who can fix an entry is the party least placed to learn it is wrong, because nothing tells a contributor that its hash matched, or misfired, on somebody else's service. Checking is thin for a structural reason rather than a political one. The store holds hashes, not content, which is exactly why the sharing is acceptable between companies and exactly why nobody outside can inspect it. The peer-reviewed literature says it is not yet clear how third-party review could be carried out at all given the database itself has no content, and an expert commentary five years earlier said none of the associated content is available for independent review or audit by regulators or researchers. The consortium said the same thing from the inside in 2022, explaining that it is neither a technology company nor a social media platform and has no access to source content to determine what a hash corresponds to — which is why the only quality review ever published was one members ran on their own submissions. One correction has ever been described in public: feedback from one company on two hashes prompted the contributor to re-review and remove them, because the content was a music video that was not violent, graphic or explicit. It reached the index because a second company happened to look. Feedback of any kind sits on about 2 percent of entries, and the consortium warns its own sample is uneven and not statistically significant. Two absences bound what anyone can say here, and neither is a gap in this network. No error rate of any kind has ever been published for the index or for any member's matcher. And no removal anywhere has ever been publicly attributed to a match, so the documented disappearance of lawful war-crimes documentation at scale measures the environment this index feeds rather than the index itself. The person whose upload was matched is outside all of it. Every member runs its own appeal channel, because the consortium's membership criteria require one, and that appeal reaches the acting platform's decision and stops. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets with the thirteen you are given, and here the obstacle is money. The cheapest arrangement that clears every gate costs seventeen. It takes six instruments, two of them at full strength: funding a study of what the arrangement is really doing, making challenge a scheduled duty rather than a favour, raising checking intensity when something flags instead of waiting for the next cycle, marking where a record came from, gating who may reach the store at all, and keeping less. You are four short, and no ordering fixes that. What holds you out is the pathways rather than the benefit. Lift the pathway requirement alone and about three thousand arrangements inside your thirteen clear every remaining gate, both service margins included. Lift any single service gate instead and nothing wins at all. Explore and Service Targets Only can be won, and cheaply: two instruments, costing four of your thirteen.

Stylized model of a documented deploymentContent moderation & editorial AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Consortium-class shared enforcement index network: 12 components and 26 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 1 assumed · 9 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • baseline

    D48-derived new org (Phase 6, content-moderation-editorial). REGISTER FIRST, because it governs every value here: this is a CONSORTIUM board, and the decision surface sits BETWEEN companies. Nothing on this diagram is a single platform's moderation pipeline. The contributing member's own enforcement of its own policy happens upstream of everything drawn here; the consuming member's own enforcement of its own policy happens downstream of everything drawn here; and each member's own user-appeal channel, which the consortium's membership criteria require every member to operate, sits inside those platforms and is outside this boundary. What this network draws is the share itself: who may write an entry, who may read it, who may correct it, and who may check it.

  • baseline

    TOPOLOGY. Twelve nodes, all documented, none decorative. ONE model, because the automated element in this deployment is a perceptual hash comparison and the record is explicit that there is no classifier at the centre; both judgements that matter are human and they happen in two different companies. THREE operator classes because the record documents three groups with three different authorities: the class that may add and remove an entry, the class that decides what a match does, and the secretariat that owns every rule and may touch no record. FOUR record stores because the sources measure four separate things and the wiring between them is the case: the shared index, the peer feedback record, the material a contributing platform retains behind its own entries, and the annual published aggregate that every outside statement about this deployment is built from. TWO reviewers because the record documents two separately constituted examining channels with different access: a commissioned channel filled twice and both times without access to the material, and an outside channel with no access at all whose only instrument is the operator's own published figures. ONE input source because the sanctions designation list is a real external instrument that decides what enters, maintained by a body outside this deployment. ONE worklist because the consortium's own published flow routes a match to the receiving platform's human review before anything happens, and drawing that queue is how this board states the corrected framing rather than the popular one.

  • baseline

    ABSENCES ARE DERIVED TOO, and four of them are load-bearing. There is NO enforcement node, and this is the correction the evidence record marks as binding: the consortium states that adding hashes prompts no direct or automatic action on another member's platform and that each member independently determines what action to take, and its own published flow routes a match through human review first. An enforcement node would draw an automatic cross-platform ban, which the record refutes; the honest and stronger claim is that one company's classification enters every other member's review queue, and that is drawn as a worklist and a peer pathway instead. There is NO external boundary and no egress pathway: governments and other non-technology organisations have no access, five legacy non-member companies had their access rescinded in 2022, and a multistakeholder body's 2025 warning about growing government interest in such databases is a prospective risk rather than a documented crossing. There is NO guardrail, because no bounded automated screen over the comparison's output is documented anywhere; what screens a match is a person at the receiving platform. There is NO node for the person whose upload was matched, and none could be drawn: served people are never in these dynamics, the record contains no individual user, uploader or moderator, and the whole finding of this case is that they are absent from it as a party.

  • baseline

    WHERE THE LAB SHAPE DIVERGES FROM THE PAN SHAPE, and nothing is asserted here that the PAN file does not already record. Four divergences. First, PAN carries two stores and the Lab draws four: the material a contributing platform retains is carried in PAN inside the contributing reviewer's attributes and inside the index store's removal grounds, and the annual published aggregate is carried in PAN inside its source list and its description, so the Lab draws each as the store it is, which lets the audit gap and the retention expiry be pathways rather than adjectives. Second, PAN carries the sanctions designation list inside the contributing reviewer's attributes; the Lab draws it as an input source, because the dominant inclusion criterion coming from an instrument this deployment does not maintain is a structural fact rather than a modelling convenience. Third, PAN carries the outside critique group inside its independent-auditor actor label together with the commissioned reviewers; the Lab separates them, because they have different access, different instruments and different documented effects, and section 5.1 licenses two classes where the sources document distinct groups. Fourth, PAN has no edge kind for a check: three of this board's seven check pathways REDRAW PAN edges, and their widths still come from the PAN entry, while the other four are derived from the cited record directly.

  • baseline

    BASELINES, and exactly how far the PAN org carries them. The PAN entry for this deployment holds twenty-four pathways. Fifteen of this network's twenty-six pathways have a one-to-one counterpart among them and mirror that pathway's width on one stated four-rung mapping, recorded in the derivation comment beside this org, with no exceptions. The other nine are folded into the drawn pathway that tells the same story, and each fold is named in that comment; no drawn width was moved to absorb one. The remaining eleven are derived from the cited record directly. Four contrasts carry the case. The index reaches the comparison at the top rung while a disagreement reaches the entry it disagrees with at zero, which is the arrangement's asymmetry in two numbers. The contributor writes an entry at the top rung while the secretariat writes one at zero, which is correction authority unbundled from correction knowledge. The store's composition reaches the published report at the middle rung while a published figure reaches back to the store at zero, which is the audit gap drawn rather than complained about. And an entry can be resolved to the material it stands for at the low rung, for exactly one party and only while that party keeps the material, which is the one verification pathway this whole arrangement contains.

  • baseline

    DEMAND 3 / CAPACITY 1, and what the capacity value does NOT rest on. Demand 3 on the consortium's own dated figures: approximately 2.4 million hashes over approximately 408,000 unique and distinct items at end-2025, an increase of about 123,500 hashes during the year, 39 member platforms with 23 named as integrated, over 5 billion net monthly active users across all members, and an incident framework activated 14 times across seven countries in 2025 against seven times in 2024, with one 2022 incident carrying 119,764 incident-labelled hashes on its own. Capacity 1 rests on documented difficulty and documented thinness rather than on a measured backlog. The consortium's commissioned reviewers record that the judgement requires substantial expertise in the terrorist and violent extremist threat landscape; that the consortium's own review found it especially difficult to determine whether content advocates for or calls to violence and that more clarity was needed on what counts as a hate-based ideology; that content frequently lacks labels or is labelled inconsistently or incorrectly and that labelling errors have accumulated; that members lack the internal pipelines to hash and send non-designated material; and that improving representativeness is not a priority for them. The peer-reviewed literature puts industry safety and security headcount at approximately 40,000 people. NO queue depth, review time, backlog or per-reviewer workload figure has ever been published for this deployment by anyone, and no value on this diagram is scaled by one.

  • baseline

    EVIDENCE STATUS, labelled where it is used, because this record is unusually single-sourced on the quantitative side. OPERATOR-TIER AND NOT INDEPENDENTLY VERIFIED: every figure about the index — hash counts, distinct-item counts, behavioural-label shares, incident tables, feedback uptake, membership lists, the removal grounds — comes from the consortium's own annual transparency reports, and independent verification is not merely absent but architecturally blocked, because the store contains hashes rather than content. COMMISSIONED AND OPERATOR-PUBLISHED: the December 2024 database review is independent in authorship, by two named academics at a university-based consortium, and was commissioned, framed, hosted and published by the party it examines; every use of it here carries both halves. BLOCKED AND CORROBORATED: the 2021 human rights impact assessment could not be fetched from its publisher, so it is used only for facts the consortium's own 2024 and 2025 reports state independently, and no part of it is quoted. PEER-REVIEWED: the 2025 international-law journal article, whose quantitative claims match the 2022 transparency report exactly. ADVOCACY AND EXPERT ANALYSIS: the 2019 legal-policy critique, the 2020 human rights investigation, the 2020 expert commentary, the 2025 multistakeholder position. DENOMINATOR DISCIPLINE: the behavioural-label shares are not comparable across report years without stating the denominator, and this network states it every time it uses one.

  • baseline

    WHAT THE RECORD DOES NOT SAY, recorded as unknowns and never as zeros on any measured quantity. No false-positive rate, false-negative rate, precision or recall has ever been published for the index or for any member's matcher. No count exists of how much content was removed, demoted or blocked because of a match on any platform. No count exists of user appeals arising from a match, because platform appeal statistics do not separate hash-matched actions. No public list says which member contributed which hash, and the record does not say whether a consuming member can see the contributor at all. And nothing published says what became of a founding member's contributions after it concluded its membership in 2025: because only a contributing member may remove its own hashes, a departure leaves the question of who may now correct them unanswered anywhere in the record. Where this network draws a zero it is drawing a pathway the sources document as absent, unreachable or refused, never a measured quantity that came out at zero.

  • assumed

    THE HARM CIVIL SOCIETY MEASURES IS MEASURED OFF THIS INDEX, and this network does not attribute it here. A human rights organisation reported in September 2020 that 619 of 5,396 pieces of content cited in its own reports since 2007, 11 percent, had been removed, and that an independent archive found 361,061 of its preserved videos, 21 percent, no longer accessible. Those figures measure the platform-side automated removal environment that this index feeds. Not one of them is attributed to a match, and no such attribution exists anywhere in the public record. The honest statement, and the one this board makes, is that lawful documentation of violence is demonstrably removed at scale by the systems this index feeds, and that no mechanism exists to tell whether the index contributed. Nothing on this diagram computes a harm to any person, and no removal, appeal, reinstatement or outcome for any individual is derived from anything drawn here.

  • baseline

    HOW THIS DRAWING WAS COARSENED, and what it still says. This network was re-derived in September 2026 at the coarsest granularity at which every documented mechanism of the deployment is still a separate element: twelve nodes as before, and twenty-six pathways where forty were drawn. Nothing was dropped. Where two pathways told one documented story they are drawn as one and the survivor's own text carries both: the secretariat's three reads are one read, because each arrives as something it can count and none as anything it can change; the two refusals of the retained material to parties outside the contributing company are one, as are the two refusals of the index to outside readers; the contributor rereading its own entries is the reconciliation of an entry against its material; the consuming company's doubt reaching the contributor is drawn as the challenge it is rather than also as a read of the feedback record it passes through; the commissioned review's recommendations, including its position on bystander and journalistic footage, are drawn where they landed; and the retention of the material, the attachment of feedback to an entry and a match's absence from the feedback record are each narrated on the pathway they bound.

What this example does not show

  • STATUS AND POSTURE, verbatim from the evidence dossier and load-bearing. Ongoing and growing. The database has operated continuously since 2017, is at its largest recorded size (approximately 2.4 million hashes covering 408,000 unique and distinct items at the end of 2025), and the membership is at its largest (39 platforms, over 5 billion net monthly active users across all members, by GIFCT's count). Governance is being widened at the top (two elected at-large Operating Board seats from late 2025) while the structural gap this dossier is about is unchanged: as of 2026-08-28 there is no published cross-platform appeal, no user-facing channel into the index, and no external audit of how the taxonomy is applied. GIFCT's own commissioned reviewer recommended in December 2024 that GIFCT be given authority to audit and fix labelling errors; the 2025 report does not record that authority having been granted.
  • LITIGATION AND REGULATORY POSTURE, dated. As of 28 August 2026 there is no litigation against the consortium and no regulator supervises it as such. The instruments that do bind fall on the member platforms individually: Regulation (EU) 2021/784, applicable from 7 June 2022, requiring hosting service providers to remove terrorist content within one hour of a national authority's removal order; the EU Digital Services Act; and the UK Online Safety Act 2023. The Christchurch Call names shared databases of hashes and URLs among its industry commitments and is non-binding. That regulation is carried here for its title, its adoption date and the one-hour duty only — the instrument text was not readable in the evidence pass, so no article number, recital or complaint-mechanism provision is asserted anywhere. The posture carries an as-of date because a multistakeholder body flagged growing government interest in such databases as an active 2025 risk.
  • EVERY QUANTITATIVE FIGURE ON THIS BOARD IS THE OPERATOR'S OWN. Hash counts, distinct-item counts, behavioural-label shares, incident tables, feedback uptake, membership lists and removal grounds all come from GIFCT's annual transparency reports, and independent verification is not merely absent but architecturally blocked: the store contains hashes rather than content. This scenario attributes them to a named report by year wherever it uses them and treats none of them as an audited quantity.
  • THE BEHAVIOURAL-LABEL SHARES ARE NOT A TREND, and the denominator is why. The 2022 and 2023 reports give shares of TOTAL hashes and the 2024 and 2025 reports give shares of BEHAVIOURALLY LABELLED hashes, so the apparent rise in glorification from 62 percent to 75.94 percent across that boundary is largely a change of basis. Normalised to the labelled subset the recent years run 78.0, 72.1, 75.94 and 75.62 percent, and roughly 8 percent of hashes carry no behavioural label at all. No unqualified year-on-year series appears anywhere in this bundle.
  • A MATCH IS NOT A REMOVAL, and this scenario never treats it as one. Matching is automatic; action is not. The consortium states that adding hashes prompts no direct or automatic action on another member's platform, and its own flow diagram routes a match through the receiving platform's human review before any enforcement under that platform's own policy. No enforcement node is drawn on this network for exactly that reason. The structural claim this board does make is the subtler one: one company's classification enters every other member's review queue, and no affected person can reach the store it came from.
  • NO REMOVAL IS ATTRIBUTED TO A MATCH, anywhere, by anyone. Human Rights Watch's finding that 619 of 5,396 pieces of content cited in its own reports had been removed, the Syrian Archive's 361,061 inaccessible videos, and the Brennan Center's report of over 100,000 Syrian Archive videos removed by automated tools all measure the platform-side removal environment this index feeds. This scenario says that lawful documentation of violence is demonstrably removed at scale by the systems the index feeds, and that no mechanism exists to tell whether the index contributed. It says nothing stronger, because nothing stronger is on the record.
  • NO ERROR RATE EXISTS, and its absence is the finding rather than a gap in this model. No false-positive rate, false-negative rate, precision or recall has ever been published for the index or for any member's matcher. The 2022 member-run sampling exercise reported a very small number of incorrectly labelled hashes and an even smaller number outside the taxonomy, with no denominator given. Every strength on this diagram is a modelling choice within the rungs the PAN entry's own widths support, and every PAN edge for this deployment is marked estimated.
  • THE COMMISSIONED REVIEW IS INDEPENDENT IN AUTHORSHIP AND OPERATOR-PUBLISHED, and this scenario labels it both ways every time. The December 2024 database review was written by two named academics at a university-based consortium and was commissioned, framed, hosted and published by GIFCT through its own working-group programme, and its authors had no access to the hashed material. It is the strongest critical evidence in the file and it is also an operator-published document. Separately, the 2021 human rights impact assessment could not be fetched from its publisher, so it is cited only for facts GIFCT's own reports state independently, nothing from it is quoted, and no recommendation of it is numbered.
  • THE CONTESTED CHARACTERISATIONS ARE THE CRITICS', supported by the operator's published silence rather than by an operator admission, and the operator's own mitigations are named alongside with their reach described precisely. Member appeal duties reach the acting platform's decision. The feedback channel reaches other members. The commissioned reviews reach the consortium's governance, and the record credits one of them with the Human Rights Policy and the two elected board seats. The Independent Advisory Committee advises and does not operate the database. None of them reaches an entry on behalf of a person whose upload was matched.
  • THIS BOARD IS THE SHARE, NOT A PLATFORM, and it asserts nothing about any member's own deployment. It does not draw any member's moderation pipeline, any member's enforcement, or any member's user-appeal channel — all of which sit inside companies and outside this boundary. It is also kept strictly apart from the victim-initiated hash indexes elsewhere in this domain: those are protective, the person depicted submits, and the operator runs a case channel; this one is company-initiated and enforcement-facing, and the affected person is never a party. The surface similarity between them is a trap the evidence record marks in terms.
  • Matched people are not modelled. No removal, appeal, reinstatement or outcome for any person is computed from anything on this diagram, and no individual user, uploader or moderator is named or characterised anywhere, because the record contains none. The removal figures civil society has measured are recorded external observations about the surrounding environment. The structural fact the record does establish — that nothing tells a matched person a shared index was involved — is stated as an absence rather than drawn as a pathway with no valid endpoint.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • The GIFCT Hash-Sharing Database is a cross-company index of terrorist and violent extremist content: a member platform that has found such material on its own service judges it against that platform's own policy, judges it a second time against the Global Internet Forum to Counter Terrorism's taxonomy, converts it to a perceptual hash, attaches labels, and publishes the hash to a shared store that every other integrated member queries against its own uploads. On GIFCT's own figures in its 2025 Annual and Transparency Report, the store held approximately 2.4 million hashes at the end of 2025 — an increase of about 123,500 during the year — covering approximately 408,000 unique and distinct items, comprising about 329,000 visually distinct images, 79,000 visually distinct videos, and 200 textually distinct PDF items. Membership stood at 39 platforms with 23 named as integrated or integrating, against 12 companies with access in the 2022 report and four founders in 2017 (Facebook, Microsoft, Twitter, and YouTube); GIFCT counts over 5 billion net monthly active users across all members. Access is gated by GIFCT membership plus a signed information-sharing agreement plus the hash-sharing database code of conduct, and GIFCT stated in 2022 that governments and other non-tech company organizations do not have access to the database. There are three inclusion pathways: association with an entity on the United Nations Security Council 1267 Consolidated Sanctions List, satisfaction of the behavioural inclusion criteria added by the July 2021 taxonomy expansion, or an activation of the Incident Response Framework. GIFCT operates no platform, holds no source content, and states that it does not own or store any source data or personally identifiable information of users associated with member platforms. Every quantitative figure here is GIFCT's own and none has been independently verified.

    empirical
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2022). 2022 GIFCT Transparency Report https://gifct.org/wp-content/uploads/2022/12/GIFCT-Transparency-Report-2022.pdf
    • Vendor Global Internet Forum to Counter Terrorism. GIFCT's Hash-Sharing Database (public explainer page; as fetched 2026-08-28 it describes no appeal, review or redress process for a user whose content is hashed) https://gifct.org/hsdb/
  • Only the contributing member may remove its own hash from the GIFCT Hash-Sharing Database. GIFCT publishes four removal grounds: the contributing platform's own review, another member's feedback, new information or evolving context, and data availability — the case where the contributor no longer retains the underlying content and so can no longer verify the hash. GIFCT itself may create hashes for inclusion and may add an alternative opinion to a record. In the Year 4 Hash Sharing Working Group review published in December 2024, Dr Sean Doody and Dr Michael Jensen of the National Consortium for the Study of Terrorism and Responses to Terrorism recorded that GIFCT 'is only allowed to add additional alternative opinions to records and lacks the ability to modify the labels added to hashed content by members' and that 'as it currently stands, GIFCT itself cannot directly remediate labeling mistakes for hashes submitted to the HSDB'. They recommended that GIFCT 'should be endowed with the proper authority to directly audit, quality control, validate, and fix labeling errors', noting that this 'would almost certainly require members to provide GIFCT access to pre-hashed content'. GIFCT's 2025 Annual and Transparency Report does not record that authority being granted. That review is independent in authorship and was commissioned, framed, hosted, and published by GIFCT through its own working-group programme, and its authors had no access to the hashed content.

    empirical
    • Academic Doody, S., & Jensen, M. (2024). Hash-Sharing Database Review: Challenges and Opportunities. National Consortium for the Study of Terrorism and Responses to Terrorism (START), published by GIFCT as a Year 4 Working Group output https://gifct.org/wp-content/uploads/2025/02/GIFCT-24WG-1224-HSDR-Challenges-1.1.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
  • Independent review of the GIFCT Hash-Sharing Database is architecturally obstructed rather than merely withheld, and three separate sources say so in nearly the same terms. Gavin Sullivan, writing in the London Review of International Law in 2025, states that 'Despite widespread agreement that third-party reviews of the hash-sharing database are necessary, it is not yet clear how such reviews can be carried out given the hash-sharing database itself has no content', and records that the member disagreement mechanism 'is a means for platforms to signal disagreement with a hash's inclusion in the database' and is 'only open to GIFCT members', and that GIFCT participants 'consider themselves one step removed from the human rights impact' of the system. Courtney Radsch wrote for Just Security on 30 September 2020 that 'none of the associated content is available for independent review or audit, either by regulators or researchers'. GIFCT gave the same reason from the inside in its 2022 Transparency Report, explaining that it 'is neither a tech company nor a social media platform and does not have any access to source content to determine what the hash corresponds to' — which is why the only quality review ever published was conducted by members on their own submissions. In that 2022 exercise, members randomly sampled three strata of hashes they had themselves submitted (sanctions-list-derived, incident-derived, and hashes carrying another member's disagreement feedback), reported no significant quality errors and no accuracy difference between strata, and found 'a very small number of hashes were incorrectly labeled and an even smaller number did not meet the taxonomy for inclusion', with labels corrected and out-of-scope hashes removed; no denominator was given. Two commissioned reviews exist — a Business for Social Responsibility human rights impact assessment reviewed between December 2020 and May 2021 and published in July 2021, and the December 2024 database review — and neither had access to the hashed material. No false-positive rate, false-negative rate, precision, or recall has ever been published for the index or for any member's matcher.

    empirical
    • Academic Sullivan, G. (2025). Algorithmic governance of terrorism and violent extremism online. London Review of International Law, 13(1), 47-75 https://academic.oup.com/lril/article/13/1/47/8152419
    • Investigative Radsch, C. C. (2020, September 30). GIFCT: Possibly the most important acronym you've never heard of. Just Security https://www.justsecurity.org/72603/gifct-possibly-the-most-important-acronym-youve-never-heard-of/
    • Vendor Global Internet Forum to Counter Terrorism (2022). 2022 GIFCT Transparency Report https://gifct.org/wp-content/uploads/2022/12/GIFCT-Transparency-Report-2022.pdf
    • Academic Doody, S., & Jensen, M. (2024). Hash-Sharing Database Review: Challenges and Opportunities. National Consortium for the Study of Terrorism and Responses to Terrorism (START), published by GIFCT as a Year 4 Working Group output https://gifct.org/wp-content/uploads/2025/02/GIFCT-24WG-1224-HSDR-Challenges-1.1.pdf
  • The largest category in the GIFCT Hash-Sharing Database is also its least determinate, and the labels the index depends on are documented as unreliable by GIFCT's own reviewers. GIFCT defines 'Glorification of Terrorist Acts' as content that 'glorifies, praises, condones, or celebrates attacks after the fact'. As a share of BEHAVIOURALLY LABELLED hashes it stood at 75.62 percent at the end of 2025 and 75.94 percent at the end of 2024, with graphic violence against defenceless people at 16.02 and 16.65 percent, recruitment and instruction at 6.29 and 5.27 percent, and imminent credible threat at 2.07 and 2.14 percent; approximately 92 percent of hashes carried behavioural labels at end-2025 and approximately 91 percent at end-2024. The 2022 and 2023 reports state their shares on a DIFFERENT basis — of total hashes — at 65.23 and 62 percent for glorification, so the series is not comparable across that boundary without stating the denominator; normalised to the labelled subset the recent years run 78.0, 72.1, 75.94 and 75.62 percent. Angel Diaz of the Brennan Center for Justice read GIFCT's first transparency report in September 2019 as showing 85.5 percent glorification against 0.4 percent imminent credible threats, and criticised 'glorification', 'praise', and 'condone' as 'notoriously imprecise' terms that 'will almost inevitably capture expressions of general sympathy or an understanding for certain viewpoints, not to mention news reporting', alongside the absence of appeals processes, redress mechanisms, and third-party audits assessing error rates. The commissioned December 2024 review reports an internal GIFCT finding that 'content in the HSDB frequently lacks labels or is sometimes labeled inconsistently or incorrectly' and that 'labeling errors have accumulated'; that it was 'especially difficult to determine if content advocates for, or is making a call to, violence'; that more clarity was needed on what constitutes a hate-based ideology; that ideology labels were never made mandatory and 'are missing for most hashes'; and that members 'primarily share TVEC from designated entities', with a small number of the largest members responsible for most of the activity and some members contributing nothing, because improving the representativeness of the database 'is not currently a priority for them'.

    empirical
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2024). 2023 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2024/04/GIFCT-Annual-Report-2023.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2022). 2022 GIFCT Transparency Report https://gifct.org/wp-content/uploads/2022/12/GIFCT-Transparency-Report-2022.pdf
    • Advocacy Diaz, A. (2019, September 25). Global Internet Forum to Counter Terrorism transparency report raises more questions than answers. Brennan Center for Justice https://www.brennancenter.org/our-work/analysis-opinion/global-internet-forum-counter-terrorism-transparency-report-raises-more
    • Academic Doody, S., & Jensen, M. (2024). Hash-Sharing Database Review: Challenges and Opportunities. National Consortium for the Study of Terrorism and Responses to Terrorism (START), published by GIFCT as a Year 4 Working Group output https://gifct.org/wp-content/uploads/2025/02/GIFCT-24WG-1224-HSDR-Challenges-1.1.pdf
  • A hash in the GIFCT Hash-Sharing Database compels no action anywhere. GIFCT states in its 2024 Annual and Transparency Report that 'Adding hashes does not prompt any direct or automatic action on another member's platform, such as removing content. Each member can use the hashes provided through the HSDB to identify content on their respective platform that matches known terrorist or violent extremist content. Each member also independently determines what potential action to take.' The flow diagram in its 2025 report routes a match to 'Platform B flags the content for human review' and then to 'Platform B can confirm the hash is a match and takes action against the content in line with its own policies'. The modelled pipeline is therefore a contributor's moderation decision, a hash with labels, the shared store, a consuming member's automated comparison, that member's human review, and that member's enforcement — two independent human policy judgements in two different companies bracketing one automated comparison. Matching is automatic; action is not. GIFCT's own reviewers add that 'The HSDB is not meant to be the final authoritative source on what constitutes TVEC, and tech companies are always free to remove content according to their own moderation' policies, and GIFCT states that its taxonomy 'represents a selection of high-severity content that seeks to capture areas of strong consensus among members' and can be 'more limited than individual member company's policies'. The accurate structural claim is that one company's classification automatically enters every other member's review queue, not that it removes anything.

    empirical
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Academic Doody, S., & Jensen, M. (2024). Hash-Sharing Database Review: Challenges and Opportunities. National Consortium for the Study of Terrorism and Responses to Terrorism (START), published by GIFCT as a Year 4 Working Group output https://gifct.org/wp-content/uploads/2025/02/GIFCT-24WG-1224-HSDR-Challenges-1.1.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2022). 2022 GIFCT Transparency Report https://gifct.org/wp-content/uploads/2022/12/GIFCT-Transparency-Report-2022.pdf
  • No published channel connects a person whose content was matched to the GIFCT Hash-Sharing Database. GIFCT's membership criteria require each member to have 'the ability to receive, review, and act on reports of activity that is illegal and/or violates terms of service and user appeals', so every member runs its own user-appeal process — and that appeal reaches the acting platform's own policy decision, not the shared index. The only disagreement mechanism that touches the index runs between companies: members may indicate agreement or disagreement with a hash's labelling and inclusion, with all feedback visible to GIFCT and to participating members. Uptake was 34,014 hashes across approximately 9,000 distinct items, or 1.63 percent, at the 2022 report, and approximately 2 percent in each report since; in the 2023 breakdown the vast majority was agreement, 5 percent of feedback-carrying hashes disagreed about descriptive labels while still agreeing the item belonged, and disagreement that the content met the taxonomy at all ran to less than 0.01 percent of feedback-carrying hashes. GIFCT warns that this feedback 'should be treated with caution and not be considered statistically significant'. Gavin Sullivan records that the mechanism is 'only open to GIFCT members'. As fetched on 28 August 2026, GIFCT's public hash-sharing database explainer page describes no appeal, review, or redress process for a user whose content is hashed and publishes no participating-company list, and GIFCT's Human Rights Policy update of 18 May 2026 describes due-diligence tooling and Independent Advisory Committee oversight without describing any remedy, grievance, or appeals mechanism for affected users. The Global Network Initiative argued in October 2025 that individuals 'should be able to challenge wrongful takedowns or account suspensions and have their content re-evaluated' and that oversight of such databases 'should be independent, with stakeholder participation from affected communities, researchers, and human rights bodies'. Against this sit GIFCT's own mitigations, each with its documented reach: member-side appeal duties reach the acting platform, the feedback channel reaches other members, the commissioned reviews reach GIFCT's governance, and the Independent Advisory Committee advises without operating the database.

    empirical
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Vendor Global Internet Forum to Counter Terrorism. GIFCT's Hash-Sharing Database (public explainer page; as fetched 2026-08-28 it describes no appeal, review or redress process for a user whose content is hashed) https://gifct.org/hsdb/
    • Vendor Global Internet Forum to Counter Terrorism (2026, May 18). Updates to our Human Rights Policy (as fetched 2026-08-28 the update describes no remedy, grievance or appeals mechanism for affected users) https://gifct.org/2026/05/18/updates-to-our-human-rights-policy/
    • Academic Sullivan, G. (2025). Algorithmic governance of terrorism and violent extremism online. London Review of International Law, 13(1), 47-75 https://academic.oup.com/lril/article/13/1/47/8152419
    • Advocacy Global Network Initiative (2025, October 27). Hash databases, due diligence, and the boundaries of government oversight https://globalnetworkinitiative.org/hash-databases-due-diligence-and-the-boundaries-of-government-oversight/
  • Civil society has measured lawful documentation of violence disappearing from platforms at scale, and none of it is attributed to the GIFCT Hash-Sharing Database. Human Rights Watch reported on 10 September 2020 that it had reviewed 5,396 pieces of content cited in 4,739 of its own reports since 2007 and found 619 of them — 11 percent — removed, and that the Syrian Archive found 361,061 of the YouTube videos it had preserved, 21 percent, no longer accessible; the Brennan Center recorded that over 100,000 of the Syrian Archive's videos were removed from YouTube through the use of automated tools. Human Rights Watch also recorded that YouTube removed 6.1 million videos in the first quarter of 2020 with 49.9 percent taken down before any user saw them, and that Facebook's automated systems flagged 99.3 percent of terrorist-propaganda content before any user report; and it recorded that civil society could not establish what the shared database contained — then over 300,000 unique hashes as of July 2020 — or whether its contents matched any individual platform's definition of terrorism. Every one of those removal figures measures the platform-side automated removal environment that the shared index feeds. Not one of them is attributed to a hash match, and no such attribution exists anywhere in the public record: GIFCT publishes no count of content removed, demoted, or blocked because of a match, platform appeal statistics do not separate hash-matched actions, and no mechanism exists by which a person whose content was matched learns that a shared index was involved. GIFCT's own commissioned reviewers took the position in December 2024 that bystander, survivor, and journalistic footage of an attack is out of scope for hashing, having 'no core hate-based ideology or extremist identifier associated with the producer of the content'; that position is a reviewer's recommendation rather than a published change to the inclusion criteria, and no mechanism exists to check whether it is followed.

    empirical
    • Advocacy Human Rights Watch (2020, September 10). 'Video Unavailable': Social Media Platforms Remove Evidence of War Crimes. https://www.hrw.org/report/2020/09/10/video-unavailable/social-media-platforms-remove-evidence-war-crimes
    • Advocacy Diaz, A. (2019, September 25). Global Internet Forum to Counter Terrorism transparency report raises more questions than answers. Brennan Center for Justice https://www.brennancenter.org/our-work/analysis-opinion/global-internet-forum-counter-terrorism-transparency-report-raises-more
    • Academic Doody, S., & Jensen, M. (2024). Hash-Sharing Database Review: Challenges and Opportunities. National Consortium for the Study of Terrorism and Responses to Terrorism (START), published by GIFCT as a Year 4 Working Group output https://gifct.org/wp-content/uploads/2025/02/GIFCT-24WG-1224-HSDR-Challenges-1.1.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
  • GIFCT reported in its 2025 Annual and Transparency Report that 'X (formerly Twitter), a founding member of GIFCT, concluded its GIFCT membership in 2025 to focus on its internal trust and safety efforts'. X appears among the hash-sharing-database-integrated members listed in the 2024 report and is absent from the 2025 report's list. That statement is GIFCT's characterisation of a member's decision, and nothing published says what became of the hashes that member had already contributed — a question that matters because only a contributing member may remove its own hashes, so a departure leaves the entries in place with no party identified as able to correct them. Governance moved in the other direction over the same period: GIFCT's 2025 report names Meta, Microsoft, and YouTube as holding the founding Operating Board seats, with Discord and Twitch elected to two at-large seats for 2026 — the first non-founder board seats — which GIFCT attributes to recommendations in the 2021 human rights impact assessment it commissioned from Business for Social Responsibility. Membership grew from 33 platforms at the end of 2024 to 39 at the end of 2025, and GIFCT activated its Incident Response Framework fourteen times across seven countries in 2025 against seven times in 2024. GIFCT is not a regulated entity anywhere: no regulator supervises the consortium as such, and the instruments that bind — Regulation (EU) 2021/784, applicable from 7 June 2022 and requiring hosting service providers to remove terrorist content within one hour of a national authority's removal order, the EU Digital Services Act, and the UK Online Safety Act — fall on member platforms individually. The Christchurch Call, launched on 15 May 2019 and supported by 55 governments plus the European Commission and 19 online service providers, names 'the expansion and use of shared databases of hashes and URLs' among its industry commitments and is non-binding.

    empirical
    • Vendor Global Internet Forum to Counter Terrorism (2026). 2025 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2026/05/2025-GIFCT-Annual-Report.pdf
    • Vendor Global Internet Forum to Counter Terrorism (2025). 2024 GIFCT Annual and Transparency Report https://gifct.org/wp-content/uploads/2025/07/GIFCT-Annual-and-Transparency-Report-2024.pdf
    • Advocacy Business for Social Responsibility (2021). Human Rights Impact Assessment: Global Internet Forum to Counter Terrorism (commissioned by GIFCT; publisher returned HTTP 403 on 2026-08-28, so this entry is carried only for facts corroborated in GIFCT's own 2024 and 2025 reports) https://www.bsr.org/en/reports/human-rights-impact-assessment-global-internet-forum-to-counter-terrorism
    • Government European Commission, Migration and Home Affairs. Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 April 2021 on addressing the dissemination of terrorist content online (carried for title, adoption date and the one-hour removal-order duty on hosting providers only; the instrument text was not readable from this environment on 2026-08-28) https://home-affairs.ec.europa.eu/networks/eu-knowledge-hub-prevention-radicalisation/welcome-package/learning-resources/regulation-eu-2021784-european-parliament-and-council-29-april-2021-addressing-dissemination_en
    • Government Christchurch Call. The Christchurch Call commitments; supporters (launched 15 May 2019; non-binding) https://www.christchurchcall.org/the-christchurch-call-commitments/

Where this connects

Institutional pressures in this domain

  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).

All of them in context on the Content moderation & editorial AI domain page.

Levers available here and the patterns behind them

Documented case histories