PAN Lab example
The NCMEC CyberTipline reporting and triage system
The statutory funnel: one queue and a borrowed field set
Every platform in one country that finds material recording the sexual abuse of a child must report it to a single place, and that place is forbidden by law to throw anything away. Modeled on the documented statutory clearinghouse: 21,351,493 reports arrived in 2025 carrying 61.8 million files, 99.2 per cent of them from companies and 0.8 per cent from people. The same statute that compels the report says nothing requires a platform to search for anything, and says every field that would make a report usable — who, when, where, the material itself, the whole conversation — is included at the sole discretion of the sender. So the clearinghouse triages on information the senders may withhold, and forwards the result whether or not it can tell one report from another. It often cannot look at the evidence either: because a court held it part of the government for search purposes, its analysts open only files a platform employee already opened. In one appellate record a platform reviewer opened 31 of 156 flagged files, and the clearinghouse employee opened exactly those 31 and none of the other 125. That report then went to the wrong county and sat for half a year. Downstream, 61 task forces sharing $33.9 million received nearly two million reports in one year, and the channel that would tell anyone which reports were worth the hours is built, well designed and voluntary: federal agencies returned 7,085 pieces of feedback on 3.4 million reports. The finding of the only field study of this system is not that a machine is wrong. It is that two reports can look identical when one leads nowhere and the other to a child being abused, and nothing in either says which. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets, and the barrier is the statute, not the budget. Ignore the ten units entirely. Every arrangement of every instrument offered here was read, more than a million of them at every strength, and none clears every gate. Two pathways stay open in all of them. They are the two the law compels: the hand-off from the triage desk to a task force, and the hand-off to federal and foreign agencies. Nothing you place can narrow a flow a statute requires to exist. Lift the pathway requirement alone and 505 arrangements inside your ten clear everything else. Lift any single service test instead and nothing wins at all. That is a measurement of the deployment this network is derived from, not a puzzle waiting to be cracked. Explore and Service Targets Only can be won, and cheaply: one instrument, costing three of your ten.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Clearinghouse-triage-class with a compelled output and a borrowed field set network: 13 components and 24 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 8 assumed · 8 measured. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the statutory clearinghouse class documented in the CyberTipline case file: one congressionally authorised intake that every United States platform must report into, an automated jurisdiction-resolution and entity-matching step with no classifier at the decision point, an analyst label, and a statutory duty to make every report available to law enforcement. It is a stylised class, not a reconstruction of the actual system, and no figure on any pathway is an accuracy rate for anything, because no accuracy rate for any element of this deployment is published by anyone.
- measured
Reports are not victims and volume is not a safety metric in either direction. Hundreds of reports may concern one person; roughly 35 per cent of the 2025 file volume is exact or near duplicate of something already in the record; a large share is older material recirculating; and the operator's own 2022 figure was that 49 per cent of reports were actionable. Equally, a platform reporting more may be scanning harder rather than hosting more, and one reporting less may have encrypted, de-duplicated, improved detection or stopped looking. Nothing on this board ranks senders by report count, and no report total is converted into a count of children.
- measured
The three actionability figures in this record sit on three different bases and are never blended. The operator's 2022 report gave 49 per cent of all reports as actionable. The mandated transparency tables count reports made available PER RECIPIENT AGENCY, and the operator states a report may go to more than one agency, so the 2025 rows sum to 19,286,122 actionable and 4,719,166 informational against a 21,351,493 report total. The operator's public page gives more than 18.8 million referred and more than 4.5 million informational. The likeliest reconciliation of the last two is de-duplication of multi-agency reports, the operator does not say so, and this board does not assert it. No single actionability rate is computed anywhere here.
- measured
The clearinghouse's legal status is contested and the contest is the mechanism. A 2016 appellate decision held it a governmental entity or, in the alternative, a government agent, so its opening of a reported file is a search. The organisation disagrees, describes itself as a private non-profit and merely a middleman, prints that disclaimer at the foot of every report it sends and in its law-enforcement tooling, and complies anyway. Nothing here calls it a government agency. What the diagram draws is the compliance, not the status: the prior-view indication reaching the analyst at the top rung, and the reach of that practice bounded by the destination.
- measured
The doctrine is split and the split is live. The Second, Fourth and Ninth Circuits require a warrant before a government actor opens a file a platform never opened; the Fifth and Sixth Circuits and one state supreme court hold an automated hash scan a private search whose scope law enforcement did not exceed. A certiorari petition was filed on 14 April 2026 and distributed on 17 June 2026 for the conference of 28 September 2026, and as of 28 August 2026 the Court has neither granted nor denied it. A petition is not a grant and a grant would not be a ruling. The 2026 Fourth Circuit decision found a violation and affirmed the conviction on attenuation, so it is not a suppression win. Named criminal defendants are cited for legal architecture and procedural posture, and no case fact about any of them travels beyond that.
- assumed
The Lab draws TWO input sources where the PAN entry draws none. The reporting interface and the reporting form's optional field set both live in the PAN file inside the intake store's own contents and inside the analyst class's attributes. Drawing each as an input source turns two facts from adjectives into pathways: that the composition and volume of the work are decided by organisations that are not operators of this deployment, and that a single field on someone else's form governs what the analyst may examine. Nothing is asserted here that the PAN file does not already record.
- assumed
The Lab draws the receiving agency's case system, which the PAN entry does not carry as a store. The PAN file models the recipients as operator classes and folds their tooling into their attributes. Drawing the case record separately turns three documented facts into pathways: that the report is replicated into a case record that deconflicts against work from other sources, that two incompatible systems hold it with different capabilities, and that the step which decides whether anyone opens a file is a warrant application taken at that end rather than at the clearinghouse. The Lab also draws the courts, which the PAN entry carries as a governance actor, as a reviewer beside the oversight channel on the fidelity spec's licence, because they hold different access, a different instrument and a different documented effect.
- assumed
The analyst triage queue is drawn as a named element with no pathways of its own, which is the schema's contract for a mediator: it sits on the routing pathway and adds no flow. That is also the honest state of the evidence. The queue exists and is described by the operator; reports whose files are part of a known series can be forwarded within minutes without entering it and reports that enter it typically go out within a few days; and no queue depth, review time, backlog or per-analyst workload figure has ever been published for this deployment by anyone. A width on this element would be a number nobody has counted.
- measured
Capacity at one rung rests on documented thinness and documented difficulty, not on a measured backlog. The organisation has more than 400 employees across five programme areas with no CyberTipline analyst headcount published; it describes a never ending cycle of trying to replace a workforce that industry trust and safety teams recruit away at non-profit salaries; a federal department employee described the constraint as bailing water while being asked to build a drainage system. On the receiving side the appropriation is fixed while arrivals are not: $33,976,146 across 61 expected awards in fiscal 2025 against 1,932,435 reports made available to those units. Those are the grounds. A backlog figure is not among them, because none is published.
- assumed
Every pathway width here is a modelling choice on a documented mechanism, and every edge in the PAN entry for this deployment is marked estimated. Sixteen of the twenty-four pathways mirror a PAN edge on one stated rung mapping with no exceptions; two of those sixteen are PAN peer edges redrawn as Lab checks, because a channel that corrects is inhibiting in this vocabulary and neutral in PAN's, and their widths still come from PAN. The other eight are derived from the cited record directly. No width on this board is an error rate, a defect rate or an override rate, because no such rate exists for any element of this deployment.
- measured
Three pathways are drawn at zero. Two rest on the operator's own record rather than on an absence of evidence: the federal write into the feedback record, which is 7,085 instances against 3,435,257 reports in the class's best published year, and the outcome feedback into the resolution step, for which no mechanism is published at all and which carries the closure reason that never travels back onto the report it concerns. The third rests on documented refusals: any standard for what a report must contain. That one is the deployment's central finding, and the record states it three times over — the statute makes every useful field discretionary, the clearinghouse concedes it lacks authority to make platforms change their reporting, and it will not publish written guidance for fear of being characterised as directing what companies report.
- measured
The generative-artificial-intelligence load is carried as arrival composition and never as a capability claim about anything on this board. The operator counted more than 400,000 2025 reports with such a nexus, more than 182,000 involving offenders possessing, generating or attempting to generate the material, and more than 158,000 files so categorised; the figure released through a Senate committee for the same year was 1.5 million reports with such a connection, including over 12,000 reports of the material found in training data. Two counts on two bases, both stated. The 2024 field study had warned that the organisation's first million-report day, caused by one widely circulated item, was survivable because of automated clustering, and that a million genuinely distinct generated images would not be. No product or model is identified anywhere in this bundle.
- assumed
The declared modernisation programme is drawn nowhere and priced nowhere. It is a $10 million three-year commitment to build a faster and more scalable platform, supported by three cloud and analytics companies, and no published measurement of its effect exists. Describing it as delivered, or drawing a pathway that depends on it, would assert an outcome the record does not contain. It is carried as scenario posture instead. The same discipline applies to the vendor question: a 2024 statutory amendment extended the organisation's limited liability to contracted, cybersecurity-vetted vendors, which is what makes commercial hosting of this data workable, and no records are documented as having left the governed estate, so no boundary crossing is drawn on a prospective one.
- assumed
Served people are not in these dynamics and their absence is part of the finding. The children in the material, the people a platform reported on information it alone chose the contents of, and the people whose report was routed to the wrong agency or to no locatable one are all outside the operator network this board draws, and nothing here computes an outcome for any of them. The operator network is the analysts, the task force desks, the federal and international recipients, the oversight channel and the courts. There is no channel anywhere in this record by which a person reported on reaches the clearinghouse, and the record does not describe one.
- measured
The only public field study of this system is drawn nowhere on this board, because it held no authority and no instrument over the deployment, and what was done about its findings was done by others. It was published on 22 April 2024, built on interviews with 66 individuals across platforms, the clearinghouse, law enforcement, prosecutors and defence attorneys, with three days of on-site observation and the operator's cooperation; its authors did not receive report data. It supplies the triage framing this case rests on: two reports can look identical when one leads nowhere and the other to ongoing abuse, and nothing in either says which. Its findings are attributed respondent perceptions, several of them contradicting each other, and they are quoted here as such and never as measured system properties. The operator published a roughly 300-word response the same day that called the recommendations creative, said it looked forward to exploring them, disputed no finding and gave no number, and two of the study's concrete technical recommendations were unshipped capacity: a commissioned interface matching report network addresses against peer-to-peer file-sharing data, completed in autumn 2020 and not integrated as of 2024, and an offer of cloud translation capacity that was not taken up. The uptake that is documented is the oversight channel's: the May 2024 amendment extended the organisation's limited liability to contracted vendors, which answers one of the study's central recommendations, and in April 2026 the per-sender answers turned its qualitative quality finding into published measurement. Three weeks after publication the institution that published it was described as being dismantled, a characterisation Stanford disputed, with the child-safety work continuing under another laboratory, and the only other known study of this system, commissioned by a federal science directorate in 2021, was never made public.
- assumed
How this drawing was coarsened, and what it still says. This network was re-derived in September 2026 at the coarsest granularity at which every documented mechanism of the deployment is still a separate element: thirteen nodes where fourteen were drawn, and twenty-four pathways where forty were. Nothing was dropped for size. Where two pathways drew the same documented flow they are drawn once: the report reaches the task force desks and the federal and international recipients by the routing step and by the compelled hand-off, so their separate reads of the record are not drawn; the prior-view indication's consequence at the receiving end is the warrant step, which is drawn; a hash matching a file coded before the rule bit is one reconciliation, however it surfaces; and the outcome returns that reach the desk are the task force check. The field study is carried in the assumption above. Every width that remains is the width first derived, and every fact the folded elements carried is in the copy of an element that remains or in these assumptions.
What this example does not show
- STATUS, verbatim from the evidence dossier: Operating, mandatory and structurally unchanged in the respect that matters: NCMEC is still required by 18 U.S.C. § 2258A(c) to make every report it receives available to law enforcement, still cannot compel any platform to include any particular field, and still declines to open files the reporting platform did not view when the report is bound for US law enforcement. What has moved since the 2024 study is at the edges — the REPORT Act's preservation, penalty and vendor-liability changes (May 2024), a report-bundling feature used by one large platform, a declared $10 million modernisation programme, and a sharpening constitutional split now before the Supreme Court on a pending petition. Report volume fell 43 per cent between CY 2023 and CY 2024 and has only partly recovered; the fall is attributed by the operator mainly to platform-side encryption, not to any change in the clearinghouse.
- LITIGATION AND REGULATORY POSTURE, dated 2026-08-28. No court or regulator supervises this clearinghouse's performance. What the courts supervise is its epistemic reach, and they are split: the Second, Fourth and Ninth Circuits (and the Tenth in the alternative holding that opened the question) require a warrant before a government actor opens a file no platform employee opened; the Fifth and Sixth Circuits and one state supreme court hold an automated hash scan a private search whose scope law enforcement did not exceed. A certiorari petition was filed on 14 April 2026 and distributed on 17 June 2026 for the conference of 28 September 2026, and as of the verification date the Court has neither granted nor denied it. A petition is not a grant and a grant would not be a ruling. The March 2026 Fourth Circuit decision found a Fourth Amendment violation and AFFIRMED the conviction on attenuation; it is not a suppression win. This posture must be re-checked after the September 2026 conference before publication.
- REPORT COUNTS ARE NOT VICTIM COUNTS, and this is the most common error about this system. Hundreds of reports may concern one person; roughly 35 per cent of the file volume is exact or near duplicate; a large share is older material recirculating; and the operator's own 2022 figure was that 49 per cent of reports were actionable. The inference does not run backwards either: every interviewee in the field study with a view believed the underlying threat is understated rather than overstated. Every number here travels with its basis.
- THE THREE ACTIONABILITY FIGURES ARE NOT COMPARABLE AND ARE NEVER BLENDED. The mandated tables count reports made available PER RECIPIENT AGENCY, and the operator states a report may go to more than one, so the 2025 rows sum to 19,286,122 actionable and 4,719,166 informational against a 21,351,493 report total, while the operator's public page gives more than 18.8 million referred and more than 4.5 million informational. The likeliest reconciliation is de-duplication of multi-agency reports; the operator does not say so and nothing here asserts it. The 49-per-cent figure is from the operator's 2022 report as quoted by the field study and sits on a third basis. No single actionability rate is computed anywhere in this scenario.
- OPERATOR CLAIMS ARE LABELLED AS OPERATOR CLAIMS, and where the parties disagree all the voices are carried. The attribution of the 2024 volume decline to end-to-end encryption is the operator's analysis, given by a named officer on the record; one platform attributes part of the fall to a bundling feature it partnered on and says it maintains safety measures inside encryption; two other companies claimed consolidation and an operator spokesperson said any such changes were not made through the official pipeline feature. The per-sender quality figures are the operator's answers to a March 2026 oversight letter as characterised in that committee's own April 2026 release: they are the best public per-sender data that exists, they are second-hand, and they are oversight findings about data completeness rather than enforcement findings. The companies were pressed for responses; none has been found to have violated the statute on this record.
- THE FIELD STUDY IS A FIELD STUDY, NOT AN AUDIT, and its publisher's status is itself disputed. Its findings are attributed perceptions from interviews with 66 individuals, several of them contradicting each other — one local officer said 90 per cent of what reached him was unusable, and an officer in a better-resourced department said very few were truly unactionable. Three weeks after publication, contemporaneous reporting described the Stanford Internet Observatory as being dismantled; Stanford disputed the word, saying the important work continues under new leadership, with child-safety work moving to another laboratory. Both are carried. Nothing here implies an ongoing monitoring programme, and the only other known study of this system, commissioned in 2021 by a federal science directorate, was never made public.
- THIS IS NOT A CLASSIFIER-ACCURACY STORY AND NOTHING HERE IS AN ERROR RATE. The clearinghouse runs no classifier over the reports it triages; its constraint is legal and organisational. The accuracy questions that do appear belong to the detection side and to the courts — the 2026 appellate opinion recorded that the record before it contained no evidence of how the platform trains its reviewers, how accurate they are, or how accurate its hashing is in practice — and they are carried here as what the record lacks. Every value on every pathway is a modelling choice on a documented mechanism.
- TWO BOUNDARIES WITH SIBLING CASE FILES. The platform side — detection, human confirmation, the account-level sanction and the appeal channel — is a different deployment and a different case file, and the two meet at exactly one artefact, the prior-view indication, which each tells from its own side. And the victim-initiated hash-removal programme run by the same organisation is a DIFFERENT PROGRAMME with an opposite information design: the reporter supplies a hash and nothing else, nothing is investigated, and no referral to law enforcement follows. It appears here at one point only, as a hotline contributing 130,362 reports to this intake in 2025.
- THE DECLARED MODERNISATION PROGRAMME IS ANNOUNCED, NOT DELIVERED. A $10 million, three-year commitment to build a faster, more resilient and more scalable platform, supported by three cloud and analytics companies with further corporate investors. No published measurement of its effect exists. It is drawn nowhere on this board and priced nowhere in the budget, and describing it as delivered would assert an outcome the record does not contain.
- Served people are not modelled. The children in the material, the people a platform reported on information it alone chose the contents of, and the people whose report went to the wrong agency or to no locatable one are all outside the operator network this board draws, and no outcome for any of them is computed from anything here. The published resolution-failure share and the feedback-return ratio are recorded external observations from the operator's own mandated report: the first measures a routing failure and the second measures a channel's use, and neither is an accuracy rate for anything.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
The CyberTipline is the single congressionally authorised reporting mechanism for online child sexual exploitation in the United States, built by the National Center for Missing & Exploited Children in March 1998, when it received 2,772 reports in its first calendar year. The congressionally mandated transparency report to the appropriations committees gives the recent series: 36,210,368 reports in calendar 2023, 20,512,803 in 2024, and 21,351,493 in 2025, the 2025 arrivals carrying 61,833,177 files. Of the 2025 total, 21,181,300 came from electronic service providers and 170,193 from members of the public, a 99.2 to 0.8 per cent split, and the public channel carried more than 5,700 reports directly from the person depicted. More than 2,000 providers are registered, just over 300 submitted any report in 2025, and five accounted for more than 75 per cent. The automated element at the centre is not a classifier: it resolves where a report belongs and matches it against entities already in the record across fields such as electronic mail addresses and network addresses, with analyst review on the matching, and no accuracy figure for it is published by anyone. The matching is exact-match; fuzzy matching that would catch a suspended account's near-identical new handle is not implemented, and material attached to a report is not automatically scanned for matches. The clearinghouse's own resolution failures are published as a series: reports whose location could not be determined ran 1,368,404 (3.8 per cent) in 2023, 1,957,640 (9.5 per cent) in 2024 and 3,044,434 (14.3 per cent) in 2025, and reports whose location cannot be resolved are made available to United States federal law enforcement by default, so a failure of resolution is itself a routing rule.
empirical- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Vendor National Center for Missing & Exploited Children, CyberTipline data. https://www.missingkids.org/cybertiplinedata
- Vendor National Center for Missing & Exploited Children (2025, 2026). CyberTipline Reports by Electronic Service Providers, calendar years 2024 and 2025 https://www.missingkids.org/content/dam/missingkids/pdfs/2025-reports-by-esp.pdf
Federal law makes reporting mandatory, detection voluntary, and report content discretionary, and no instrument anywhere sets a standard for what a report must contain. 18 U.S.C. section 2258A(a) requires a provider to report an apparent violation 'as soon as reasonably possible after obtaining actual knowledge', a duty extended in May 2024 to minor sex trafficking under section 1591 and enticement under section 2422(b). Section 2258A(b) says the report 'may, at the sole discretion of the provider, include' the identity of the person involved, the historical reference showing when the material was uploaded, the geographic location including the network address, the visual depictions themselves, and the complete communication. Section 2258A(f) says nothing in the section requires a provider to monitor any user or to 'affirmatively search, screen, or scan' for violations. Section 2258A(e) sets failure-to-report penalties of $600,000 to $850,000 for a first violation and $850,000 to $1,000,000 for subsequent ones, scaled by whether the provider has at least 100 million monthly active users. The clearinghouse concedes it lacks authority to make platforms change their reporting, and it declines to publish written guidance to senders: its staff told researchers that if there were a written document, 'defense attorneys would characterize this in criminal cases as NCMEC is advising companies what to report', and that it preferred best practices to come from an industry body composed solely of private companies. It also has no authority to require feedback from any receiving agency. So the only price signal any sender faces is a penalty for failing to report, which is one-sided.
empirical- Government 18 U.S.C. section 2258A, Reporting requirements of providers (Legal Information Institute, Cornell Law School) https://www.law.cornell.edu/uscode/text/18/2258A
- Government Public Law 118-59, Revising Existing Procedures On Reporting via Technology Act (REPORT Act), 7 May 2024 https://www.govinfo.gov/content/pkg/PLAW-118publ59/html/PLAW-118publ59.htm
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
The clearinghouse's legal status is contested, and the contest decides what its own operators may examine. In United States v. Ackerman, 831 F.3d 1292 (10th Cir. 2016), the court held that NCMEC qualifies as a governmental entity in light of its authorising statutes and the functions Congress gave it, and in the alternative acted as a government agent, so its opening and viewing of the reported files was a warrantless search. In United States v. Wilson, 13 F.4th 961 (9th Cir. 2021), the court held that the private-search exception does not cover files the platform never opened. NCMEC disagrees with the first holding, describes itself as a private non-profit and, in its staff's words to researchers, 'merely a middleman', prints a disclaimer that it is not an agent or instrumentality of the government at the foot of every report it sends and in its law-enforcement tooling, and complies anyway: it opens only the files a platform employee recorded as viewed, for reports bound for United States law enforcement. The mechanism is one indication added to the reporting form at the start of 2014. United States v. Lowers, 170 F.4th 134 (4th Cir. 2026), records it operating: a platform's hashing flagged 156 files uploaded to one account, a reviewer at the platform opened 31 of them, the report identified which had been viewed and which had not, and 'An employee at NCMEC received that CyberTip and opened and viewed the same 31 images as the Google Reviewer. The NCMEC employee did not open any of the remaining 125 unreviewed files.' The same rule cuts both ways: the no-opening practice applies to reports bound for United States law enforcement, and the clearinghouse is able to open a file with the indication absent where the report will go to law enforcement outside the United States, which in 2025 was 77.1 per cent of reports. This is voluntary compliance with a contested holding, and this atlas does not describe NCMEC as a government agency.
empirical- Government United States v. Ackerman, 831 F.3d 1292 (10th Cir. 2016) (opinion PDF via Justia) https://cases.justia.com/federal/appellate-courts/ca10/14-3265/14-3265-2016-08-05.pdf
- Government United States v. Wilson, 13 F.4th 961 (9th Cir. 2021) (opinion PDF, United States Court of Appeals for the Ninth Circuit) https://cdn.ca9.uscourts.gov/datastore/opinions/2021/09/21/18-50440.pdf
- Government United States v. Lowers, 170 F.4th 134 (4th Cir. 10 March 2026), No. 24-4546 (opinion PDF via Justia) https://cases.justia.com/federal/appellate-courts/ca4/24-4546/24-4546-2026-03-10.pdf
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
The clearinghouse is required to forward everything, and its only lever over the downstream load is a label defined by the absence of information rather than by the seriousness of the conduct. 18 U.S.C. section 2258A(c) provides that NCMEC 'shall make available each report' to the relevant agencies, and NCMEC states in its own report to the appropriations committees that it is required by law to make available every CyberTipline report it receives, and that the label is applied based on the information a reporting party voluntarily chose to include. Its definitions, verbatim: 'An actionable report contains information indicative of a suspected prior, ongoing, or planned child sexual exploitation incident. An informational report contains severely limited information in which there is no apparent child sexual exploitation nexus; or so little information was provided by the reporting party that it is impossible to identify a location to refer the report to; or contains frequently seen child sexual exploitation or abuse material that has been shared in a non-malicious context, such as for inappropriate comedic effect or moral outrage or concern for the child depicted.' Field-study respondents report that United States law enforcement typically read the informational label as meaning a report can be set aside, and that not every report which could be set aside carries it. The second, smaller channel is urgency: more than 53,000 reports in 2025 escalated as urgent or involving imminent danger, identified through sender notifications, internal alerts, and manual review, with the clearinghouse able to decline to escalate a report a platform escalated. THREE ACTIONABILITY FIGURES IN THIS RECORD SIT ON THREE DIFFERENT BASES AND ARE NEVER BLENDED: the operator's 2022 report figure of 49 per cent of all reports; the mandated per-recipient-agency tables, where a report may be counted against more than one agency and the 2025 rows sum to 19,286,122 actionable and 4,719,166 informational against a 21,351,493 report total; and the operator's public page figures of more than 18.8 million referred and more than 4.5 million informational. De-duplication of multi-agency reports is the likeliest reconciliation of the last two, the operator does not say so, and this atlas does not assert it.
empirical- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Government 18 U.S.C. section 2258A, Reporting requirements of providers (Legal Information Institute, Cornell Law School) https://www.law.cornell.edu/uscode/text/18/2258A
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Advocacy National Center for Missing & Exploited Children. CyberTipline Data (2025 report overview, including Take It Down volumes) https://www.missingkids.org/gethelpnow/cybertipline/cybertiplinedata
A primary appellate record measures this pipeline end to end and shows what a routing failure costs. In United States v. Lowers (4th Cir. 2026): files uploaded to one account on 20 September 2019 and hash-flagged by the platform within days; a report to NCMEC on 23 September; an NCMEC employee reading the network address as one Virginia county and forwarding the report there on 29 October 2019; that office, in the court's account, letting it sit for half a year; an investigator subpoenaing the internet service provider on 16 April 2020, learning the address was in a different city, and closing the file on 13 May 2020; and the receiving city's detective viewing three previously unopened files without a warrant and applying for a warrant on 27 May 2020. Eight months from upload to warrant, with one wrong jurisdiction and one half-year queue wait, and under the 90-day preservation rule then in force a preservation window that had lapsed twice. The Fourth Circuit held that 'a hashing algorithm, which reveals nothing about a given file but a non-descriptive serial number, does not frustrate a defendant's expectation of privacy in his unopened files', and that unless someone visually inspects the contents of a file containing apparent material before law enforcement does, the private-search doctrine is inapplicable; it aligned itself with the Second and Ninth Circuits and expressly recognised that this 'puts us at odds with the Fifth and Sixth Circuits'. It AFFIRMED the conviction on attenuation, so it is not a suppression win. It also recorded what the record did not contain: 'The record does not reveal how Google trains Google Reviewers on interpreting and applying the federal CSAM definition. Nor is there any record evidence indicating how accurate or reliable Google Reviewers are at actually identifying apparent CSAM. Similarly, there is no record evidence demonstrating how accurate Google's proprietary hashing algorithm is in practice.' The split is live: the Supreme Court of Wisconsin decided State v. Gasper 5-2 on 14 January 2026 on the other side, and a certiorari petition, No. 25-1191, was filed on 14 April 2026 and distributed on 17 June 2026 for the conference of 28 September 2026, neither granted nor denied as of 28 August 2026.
empirical- Government United States v. Lowers, 170 F.4th 134 (4th Cir. 10 March 2026), No. 24-4546 (opinion PDF via Justia) https://cases.justia.com/federal/appellate-courts/ca4/24-4546/24-4546-2026-03-10.pdf
- Government State v. Gasper (Wis. 14 January 2026), No. 2023AP2319-CR, and the docket in Gasper v. Wisconsin, No. 25-1191 (Supreme Court of the United States; petition filed 14 April 2026, distributed 17 June 2026 for the 28 September 2026 conference, neither granted nor denied as of 2026-08-28) https://www.supremecourt.gov/search.aspx?filename=/docket/docketfiles/html/public/25-1191.html
The return channel that would let anyone learn which reports were worth investigating is built, well designed, and largely unused, and the operator publishes the counts. The structured schema records case status (conviction, arrest, ongoing investigation, referred, closed), whether a child victim was identified on arrest, ten named closure reasons (unable to locate subject, provider legal response does not contain information, no crime committed, no prosecutorial merit, alleged child is an adult, age of child victim unable to be determined, false report, unfounded, person or user reported is deceased, other), and a direct question on whether the information NCMEC provided was useful, with a stale-information option. NCMEC states that agencies 'are not generally required by law to provide feedback on CyberTipline reports, and NCMEC has no authority to require such feedback be submitted' and that 'most agencies provide little or no feedback.' The measured uptake in calendar 2025: task force units returned 549,584 feedback instances against 1,932,435 reports received; federal law enforcement returned 7,085 against 3,435,257; local agencies returned 156; international recipients returned 265,079. The consequence is stated by the only field study of the system: it is unknown what share of reports, if fully investigated, would reveal hands-on abuse, and no empirical prioritisation rule exists anywhere in the pipeline. Respondent estimates of the share of reports leading to a United States arrest range from 5 per cent, given in congressional testimony in September 2023, to 7.6 per cent from one officer's 2023 figure, both for reports sent to task forces and neither covering the federal stream; one officer estimated that in 2022, 3.8 per cent of reports in his state led to a child being reached. Those are respondent figures on one stream, not system measurements.
empirical- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
Capacity on both sides of this pipeline is set by appropriation and by salary rather than by arrivals. NCMEC has more than 400 employees across five programme areas, of which the CyberTipline is one of two core exploitation programmes; no CyberTipline analyst headcount is published, and no queue depth, review time, backlog, or per-analyst workload figure has ever been published for this deployment by anyone. The field study records the staffing constraint in the operator's own terms: analysts are constantly recruited away by industry trust and safety teams, and the organisation described a never ending cycle of trying to replace the workforce; asked what it would do with more resources, it said it would build out its technology team; and a federal department employee described the position as 'The house is flooding, they're bailing water, and we're asking them to build a drainage system at the same time. You can't stop bailing, otherwise you'll drown.' Downstream, the Office of Juvenile Justice and Delinquency Prevention funded the 61 Internet Crimes Against Children task forces, a network of more than 6,200 federal, state, local, and Tribal agencies, at $33,976,146 in fiscal 2025 across a competition with 61 expected awards and a published award maximum of $1,042,765 with no published minimum; in 2025 the network conducted nearly 347,000 investigations leading to more than 17,000 arrests and trained approximately 73,000 professionals, while NCMEC made 1,932,435 reports available to those units. In fiscal 2023 NCMEC received $41.4 million for its fifteen programmes and the 61 task forces received $40.8 million between them, and the field study reports a perception among participants that a larger share for one means less for the other. Two of the study's technical recommendations were unshipped capacity rather than new ideas: a commissioned interface matching report network addresses against peer-to-peer file-sharing data was completed in autumn 2020 and, as of 2024, had not been integrated, and an offer of cloud translation capacity for recipients abroad had not been taken up. NCMEC's declared answer is a $10 million, three-year CyberTipline Modernization Initiative supported by three cloud and analytics companies with further corporate investors; it is an announced programme with no published outcome measurement.
empirical- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice. Internet Crimes Against Children Task Force Program, and the FY25 ICAC solicitation (O-OJJDP-2025-172479) https://ojjdp.ojp.gov/programs/internet-crimes-against-children-task-force-program
- Vendor National Center for Missing & Exploited Children (2026). Modernizing the CyberTipline (CyberTipline Modernization Initiative; announced, with no published outcome measurement) https://www.missingkids.org/supportus/cybertipline-modernization
Report counts are not victim counts, and reporting volume is not a safety metric in either direction. Roughly 35 per cent of the 2025 file volume is exact or near duplicate of something already held: of 29,408,181 images submitted, 19,091,252 were unique by exact hash and 13,994,568 distinct under visual-similarity matching; of 26,324,863 videos, 15,144,788 and 7,304,334. Hundreds of reports may concern one person, and the Belgian Federal Police reported receiving over 500 distinct reports about a single offender in five months. A large share of the material is older material recirculating, NCMEC does not break out reports where the child is already known and safe, and its own 2022 figure was that 49 per cent of reports were actionable. The inference does not run backwards either: every interviewee in the field study with a view believed the underlying threat is understated rather than overstated, and one respondent said 'We aren't doing a good enough job of selling the threat... The number gets trotted out to justify everything, and then people wonder why they don't get resources.' Sender volume is equally unsafe to read as a signal: NCMEC's own tables show one company's volume rising more than thirty-six-fold between 2024 and 2025 and the largest sender's roughly halving, and the four accounts of the 2024 decline disagree. NCMEC's chief legal officer attributed the fall of 15.7 million reports almost entirely to default end-to-end encryption on one platform's messaging surfaces, said her first question was whether a company had stopped reporting or gone out of business and that there was nothing like that, and said unbundling to count every incident still leaves a 7 million-report gap; that platform attributes part of the fall to a report-bundling feature it partnered on and says it maintains safety measures inside encryption; two other companies claimed consolidation and an NCMEC spokesperson said any such changes were 'not via the official feature in the CyberTipline reporting pipeline'. The generative-artificial-intelligence load arrived in the same period on two bases: NCMEC counted more than 400,000 2025 reports with such a nexus, more than 182,000 involving offenders possessing, generating, or attempting to generate the material, and more than 158,000 files so categorised, while the figure released through Senate Judiciary oversight for the same year was 1.5 million reports with such a connection, including over 12,000 reports of the material found in training data.
empirical- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Vendor National Center for Missing & Exploited Children, CyberTipline data. https://www.missingkids.org/cybertiplinedata
- Investigative Goggin, B. (2025, May 8). Child exploitation watchdog says Meta encryption led to sharp decrease in tips and reports. NBC News https://www.nbcnews.com/tech/security/child-exploitation-watchdog-says-meta-encryption-led-sharp-decrease-ti-rcna205548
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Government U.S. Senate Committee on the Judiciary (2026, April 9). Grassley Releases New and Disturbing Information on Online Child Exploitation, Presses Tech Giants for Answers (NCMEC's answers to a 16 March 2026 oversight letter, as characterised in the committee's release) https://www.judiciary.senate.gov/press/rep/releases/grassley-releases-new-and-disturbing-information-on-online-child-exploitation-presses-tech-giants-for-answers
Oversight of this deployment is layered and is weak in the one direction that would change the input. Congress authorises and funds the programmes and, since the fiscal-2022 appropriations act's joint explanatory statement, requires an annual transparency report to the appropriations committees specifying de-duplication, victim-identification, and series counts; that document is the count of record for almost every quantity in this case file. Two Senate offices have run direct oversight of the SENDERS through the clearinghouse's own data: on 30 April 2025 the author of the REPORT Act opened an inquiry with four companies over what her office called a sharp decline in reports since the Act's passage, citing testimony by NCMEC's president and chief executive; and on 16 March 2026 the Senate Judiciary Chairman put an oversight letter to NCMEC whose answers the committee released on 9 April 2026, covering eight companies that submitted over 17 million 2025 reports, 81 per cent of the total. As characterised in that committee release, NCMEC told the committee that one artificial intelligence service's more than 1.1 million reports contained zero per cent actionable information because the service was designed not to collect user or content data; that over 80 per cent of one messaging platform's more than 752,000 reports were deemed inactionable by law enforcement for insufficient information; that over 90 per cent of another sender's more than 135,000 reports were originally inactionable, improving after intervention; that one platform supplied location information in 4 per cent of its 2025 reports against 35 per cent in 2024; that another routinely submitted unrelated content; and that a fifth's omissions of location or account information rendered reports inactionable. THESE ARE OVERSIGHT FINDINGS ABOUT DATA COMPLETENESS AND NOT ENFORCEMENT FINDINGS: they are second-hand from NCMEC through a committee majority release, the companies were pressed for responses, and none has been found to have violated the statute on this record. Academic oversight is a single field study, published 22 April 2024 on interviews with 66 individuals plus three days of on-site observation with the operator's cooperation; NCMEC published a roughly 300-word response the same day that appreciated the study's 'thorough consideration of the inherent challenges', called the recommendations 'creative', disputed no finding, and gave no number. Three weeks later contemporaneous reporting described the Stanford Internet Observatory as being dismantled, with child-safety work continuing under another Stanford laboratory; Stanford disputed the characterisation, saying 'The important work of SIO continues under new leadership'. Both are carried. The only other known study of this system, commissioned in 2021 by a federal science directorate, was never made public. No regulator supervises this clearinghouse, and no court or regulator has ever ordered it to do anything.
empirical- Government Office of Juvenile Justice and Delinquency Prevention, U.S. Department of Justice (2026). CY 2025 Report to the Committees on Appropriations: National Center for Missing and Exploited Children (NCMEC) Transparency (content supplied by NCMEC) https://www.missingkids.org/content/dam/missingkids/pdfs/OJJDP-NCMEC-Transparency-CY-2025.pdf
- Government U.S. Senate Committee on the Judiciary (2026, April 9). Grassley Releases New and Disturbing Information on Online Child Exploitation, Presses Tech Giants for Answers (NCMEC's answers to a 16 March 2026 oversight letter, as characterised in the committee's release) https://www.judiciary.senate.gov/press/rep/releases/grassley-releases-new-and-disturbing-information-on-online-child-exploitation-presses-tech-giants-for-answers
- Government Office of U.S. Senator Marsha Blackburn (2025, April 30). Blackburn Launches Inquiry with Tech Companies on Efforts to Protect Kids Online Following Decline in Reports to CyberTipline https://www.blackburn.senate.gov/2025/4/technology/blackburn-launches-inquiry-with-tech-companies-on-efforts-to-protect-kids-online-following-decline-in-reports-to-cybertipline
- Academic Grossman, S., Pfefferkorn, R., Thiel, D., Shah, S., DiResta, R., Perrino, J., Cryst, E., & Stamos, A. (2024, April 22). The Strengths and Weaknesses of the Online Child Safety Ecosystem: Perspectives from Platforms, NCMEC, and Law Enforcement on the CyberTipline and How to Improve It. Stanford Internet Observatory / Cyber Policy Center https://stacks.stanford.edu/file/druid:pr592kc5483/cybertipline-paper-2024-04-22.pdf
- Vendor National Center for Missing & Exploited Children (2024). In Response to Stanford Internet Observatory Cyber Policy Center's Report (a non-disputing receipt of roughly 300 words; no finding acknowledged, none disputed) https://www.missingkids.org/blog/2024/in-response-to-stanford-internet-observatory-cyber-policy-centers-report
- Trade press Newton, C. (2024). The Stanford Internet Observatory is being dismantled. Platformer (carried with Stanford's dispute of the characterisation: the important work of SIO continues under new leadership) https://www.platformer.news/stanford-internet-observatory-shutdown-stamos-diresta-sio/
Where this connects
Institutional pressures in this domain
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
All of them in context on the Content moderation & editorial AI domain page.
Levers available here and the patterns behind them
- Mark AI-written records — Provenance labeling
- Review on schedule — Oversight cadence & retrospectives
- Vet connections — Connection authorization
- Understand the system — Understand the system
- Check copied records — Reconcile copied records
- Review the riskiest first — Risk-tiered oversight
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model
- Store less data — Data minimization
Documented case histories
- The CyberTipline: triage under a rule against looking
- The errors that became visible when the reviewers went home
- The most built-out correction structure and the reach it doesn't have
- The byline nobody was behind
- A staff byline the AI wrote and the review it implied
- StopNCII & Take It Down
- X Multilingual Hate-Speech Enforcement
- X Community Notes (crowd annotation)
- GIFCT hash-sharing database
- Google CSAM detection and total account closure
- Meta cross-check: the enforcement-exemption tier
- Sama Nairobi: the review workforce as the governed subsystem
- TikTok EU and UK trust-and-safety staffing substitution
- The score is published and the service cannot act on it
- YouTube Content ID