Skip to content

PAN Lab example

StopNCII & Take It Down

Two ways to run a hash bank: the intimate-image removal pair

Two nonprofits run the same radical design from opposite ends. A person who holds intimate material of themselves computes a hash of it on their own device — the material never leaves their hands — and participating platforms compare the hash against what is uploaded to them, reviewing any match under their own policies. Modeled on the documented pair of deployments that run this mechanism: one gives the reporter a case number, a PIN, a status page and a whole-case withdrawal; the other is anonymous by construction, with no status, no notification and no withdrawal at all. The design that guarantees the privacy is the same design that removes the audit surface: no entry in the bank can ever be checked against anything, because the reference material exists nowhere the operator can reach. When this system fails, nobody is falsely accused — a person who did everything right stays unprotected on platforms off the roster, on encrypted surfaces, on re-encoded copies, and on partner copies their withdrawal cannot reach. Independent researchers reconstructed recognizable faces from hashes of the very classes this mechanism uses, told the operator its printed reassurance was wrong, and got no reply across three years. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets. Cost is not what blocks it. Even with the budget ignored and every offered lever applied, two pathways stay open, and together they are the service: the match surfacing to the platform's own review, which is the one route by which anything is ever removed, and the outside evaluators' read of the public client, which is the one check the record shows working. Closing those would mean switching the mechanism off. That is a measurement of the deployment this network is derived from, not a puzzle waiting to be cracked. Explore and Service Targets Only can be won.

Stylized model of a documented deploymentContent moderation & editorial AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the StopNCII-class on-device hash-removal index network: 8 components and 14 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 3 assumed · 9 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    This models the on-device hash-removal deployment class documented in the StopNCII / Take It Down case file — a pair of named configurations of one mechanism, modelled together because the pair is what makes the parameters derivable: the case, PIN, status and withdrawal mechanics exist on the adult side (StopNCII, operated by the Revenge Porn Helpline within SWGfL) while the anonymity, no-status and no-withdrawal design exists on the minor side (Take It Down, operated by NCMEC), and the published volume record is fullest on the NCMEC side. This is not a reconstruction of either actual system.

  • assumed

    This is a help system and its failures are protection gaps. Every documented failure mode is a gap in protection — a platform off the roster, an encrypted surface, a re-encoded copy that no longer matches, a partner copy a withdrawal does not reach, a status question the anonymous configuration can never answer — and never a false accusation against any person. A hash match obliges nobody: the platform's own policy review stands between a match and any action, and nothing on this diagram computes an outcome for anyone the service protects or anyone whose upload is matched.

  • baseline

    Demand reads 3 from the operators' own volume reporting, entered as the operator self-reports they are: 2 million images protected across more than 785,000 cases by November 2025 on the adult side (a reported 97 percent increase over 2024), and submissions rising from 83,000+ in 2024 to 130,000+ covering 273,000+ images and videos in 2025 on the minor side. These are advocacy-tier counts of reporting behaviour, never incidence, and no prevalence reading is taken from them here or anywhere in the case file.

  • baseline

    Capacity reads 1 because the manual counterfactual is per-item, per-platform victim reporting, and the record's one independent measurement of such a channel on a participating platform found it removing nothing: an audit study's non-consensual-nudity reports achieved zero removals over 21 days on the same platform whose copyright channel removed 100 percent in about 25 hours. That study tested the platform's victim-facing report flow, not the hash matcher, and it is used here for exactly that separation and nothing else. The operator-side manual channel is also documented thin: a case status can take three to five days to move, and one of the two configurations has no reporter channel at all.

  • baseline

    Two stores are drawn because the operator's own words draw them: hashes are shared with participating companies and with new partners as they join, and participating companies reserve the right to continue enforcing their policies once they have acquired knowledge of the hash. A withdrawal — which exists in one configuration only, removes a whole case rather than an entry, and depends on credentials the operator does not store and cannot reset — retracts the bank's copy and not the partners'. The reconciliation between the two stores is drawn at zero because that is what the record documents: no operator publishes how many partners hold a copy, how long they hold it, or what a partner does with a withdrawn hash.

  • baseline

    The central design decision is carried structurally rather than asserted: hashing on the reporter's device means the material never leaves their control, and it also means no entry in the bank can ever be verified against anything by anyone, because the reference material exists nowhere the operator can reach. The one place an entry can be checked against held material is a platform that already holds the material — exactly where the exposure the design exists to prevent has already occurred. That is why the submission write runs at full strength with nothing substantive screening it, why the only live check at generation is the mechanical validity screen, and why the platform-side review is the system's only substantive check anywhere.

  • baseline

    The privacy-sensitive flags on the hash-carrying pathways follow a peer-reviewed independent evaluation, not an assumption: researchers reconstructed recognizable pre-images (hair colour and length, face shape, other facial features, some background) from hashes of the same classes this deployment uses, at mean perceptual similarity of 60.10 percent for PDQ and 74.04 percent for PhotoDNA, and concluded the hashes should be treated as sensitive in the same way as the original images. The magnitudes were measured on a public celebrity-face benchmark using an off-the-shelf conditional image-to-image generative network, never on any reporter's material; they describe the invertibility of the hash class, not any individual's exposure.

  • baseline

    The evaluators' disclosure channel is drawn at zero, its measured throughput, and the model-to-operator rung into the evaluators at the bottom of the scale, because both are measurements the record supplies: the evaluators reached the deployment solely by inspecting its public web client, wrote to the operator twice between August and December 2023, received no reply, and recorded that the website did not change. The FAQ sentence their result contradicts — that material cannot be reverse engineered from the hash values — was still live when the dossier re-verified it on 27 August 2026.

  • baseline

    The same-functions model coupling is drawn at a substantial level because matching requires identical hash functions at the device and at every partner, so a documented property of the function class — the published targeted second-preimage and detection-avoidance attacks on PhotoDNA and PDQ, and the inversion result — holds everywhere at once rather than at one desk. This is the adversarial surface of the artifact, cited to the two security evaluations; it is a match-error and poisoning surface, and nothing about it implies any accusation of any person.

  • baseline

    Roster statements are date-stamped and drawn as a coverage parameter, not a stable fact: as fetched 2026-08-27 the adult index lists 17 partners and the minor index 12, with the two rosters overlapping and diverging (one large video platform matches the minor list and not the adult one; one large social platform the adult and not the minor; at least one large chat platform neither), and the operator's own pages disagree with its own milestone article on four names. A large search operator announced in September 2025 that it will use the adult index's hashes in its search product — announced, Search-scoped, and not on the partners page as fetched — and it is carried as an announcement, never as a rostered partner.

  • baseline

    The 2026 statutory overlay is deliberately not modeled as a component or a pathway: the US notice-and-removal duty (48 hours, enforced by the Federal Trade Commission from 19 May 2026) and the UK's hash-matching code measures are a separate, mandatory, per-request legal channel that operates independently of the voluntary hash indexes, and conflating the statute's duty with hash matching is the specific error the dossier's fact corrections forbid. The overlay lives in the case file and in the scenario's framing as the pressure now converting voluntary infrastructure into regulated duty while leaving the index's unauditability untouched.

  • assumed

    Served people are not in the dynamics. The people the pair exists to protect — those who hold intimate material of themselves and submit hashes of it — are boundary-only, as are the people whose uploads are matched. No outcome for either is computed from anything drawn here; the two per-algorithm reconstruction magnitudes are recorded external observations carried in the case file with their benchmark caveat, and the operator network of desks, matchers, reviewers and evaluators is what this diagram propagates.

What this example does not show

  • All volume figures here are operator self-reports at advocacy tier — 2 million images protected and 785,000+ cases (November 2025), 130,000+ submissions covering 273,000+ images and videos (2025) — and they are counts of reporting behaviour, never of incidence. No prevalence reading is taken from them, and no effectiveness magnitude exists anywhere in the record: no operator in this class publishes an audited error rate for its deployed system, and the separate 'over 90 percent' removal claim on the adult operator's site describes its parent helpline's casework, not the hash index, and is carried nowhere in this atlas.
  • The hash-inversion magnitudes (mean perceptual similarity 60.10 percent for one image algorithm, 74.04 percent for the other) were measured on a public celebrity-face benchmark using an off-the-shelf conditional image-to-image generative network, never on any reporter's material. They describe the invertibility of the hash class, not any individual's exposure, and they always travel with that caveat here.
  • The audit study cited for the manual counterfactual tested a participating platform's victim-facing report channels — copyright reports removed 100 percent of test images in about 25 hours, non-consensual-nudity reports removed none in 21 days — and did not test the hash matcher. It is used here only for the separation between platform participation and a working victim channel, never as a measurement of the hash pipeline.
  • This is a help system and every documented failure is a protection gap: a non-participating platform, an encrypted surface, a re-encoded copy, a partner copy a withdrawal cannot reach, a status question the anonymous configuration can never answer. Nothing in the record is a false accusation, and a hash match triggers platform policy review, not automatic sanction.
  • Rosters churn and the record shows the operator's own pages disagreeing: partner statements here are as-fetched 2026-08-27 and must not be read as stable. The announced search-product use of the adult index's hashes (September 2025) is Search-scoped, was announced as rolling out over months, and the announcing company was not on the partners page as fetched — it is an announcement, not a rostered partner.
  • The 2026 statutory overlay — the US notice-and-removal duty FTC-enforced from 19 May 2026, and the UK's priority offence, creation offence and expected hash-matching code measures — is a separate, mandatory, per-request legal channel. It operates independently of the voluntary indexes, it does not require joining them, and nothing here conflates the statute's 48-hour duty with hash matching.
  • Served people are not modeled. The people the pair protects, and the people whose uploads are matched, are boundary-only; the Lab models institutional propagation through the operator network — desks, matchers, reviewers, evaluators — and computes no outcome for anyone at the boundary.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • StopNCII.org (operated by the Revenge Porn Helpline within the UK charity SWGfL, developed with Meta, launched December 2021) and Take It Down (operated by the US National Center for Missing & Exploited Children, launched February 2023) run one on-device hash-removal mechanism in two configurations: the person who holds the material generates a hash on their own device, only the hash leaves the device, the original is never uploaded or stored, third-party submission is refused and eligibility is self-attested, and participating platforms match the hash against uploads on public or unencrypted surfaces, reviewing any match under their own policies. StopNCII states its algorithms as PDQ and PhotoDNA for photos and MD5 for videos; independent researchers verified by inspecting the Take It Down web client that it runs PDQ. The operators' own volume reports — advocacy-tier counts of reporting behaviour, never incidence — were 2 million images protected across more than 785,000 cases by November 25, 2025 on the StopNCII side (a reported 97 percent increase over 2024, 17 industry partners) and 130,000+ submissions covering 273,000+ images and videos in 2025 on the Take It Down side, up from 83,000+ submissions in 2024. As fetched 2026-08-27 the two partner rosters overlap and diverge (YouTube on the minor index only, X on the adult index only, Discord on neither), encrypted surfaces are outside both by design, and Google announced on September 17, 2025 that it will use StopNCII hashes in Search — an announcement scoped to Search results, with Google absent from the StopNCII partners page as fetched the same day.

    empirical
    • Advocacy StopNCII.org (Revenge Porn Helpline / SWGfL). Service pages: How It Works, Industry Partners, Frequently Asked Questions https://stopncii.org/
    • Advocacy National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/
    • Advocacy National Center for Missing & Exploited Children. CyberTipline Data (2025 report overview, including Take It Down volumes) https://www.missingkids.org/gethelpnow/cybertipline/cybertiplinedata
    • Academic Hawkes, S., Weinert, C., Almeida, T., & Mehrnezhad, M. (2024). Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools. IEEE Security & Privacy Magazine https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf
    • Advocacy SWGfL (2025, November 25). StopNCII.org Being Used to Protect 2,000,000 Images Online in the Fight Against Intimate Image Abuse https://swgfl.org.uk/magazine/stopncii-org-being-used-to-protect-2-000-000-images-online-in-the-fight-against-intimate-image-abuse/
    • Vendor Google (2025, September 17). Developing a new partnership to combat non-consensual intimate imagery on Search (The Keyword blog) https://blog.google/products/search/stopncii-program-partnership/
  • A peer-reviewed independent evaluation (IEEE Security & Privacy Magazine 2024) reconstructed recognizable pre-images — hair colour and length, face shape, other facial features, some background — from PDQ, PhotoDNA, NeuralHash, and aHash hashes using an off-the-shelf conditional image-to-image generative network trained on 1,000 public celebrity-face images on 2015-era consumer hardware, with mean perceptual similarity of 60.10 percent for PDQ and 74.04 percent for PhotoDNA, measured on a public celebrity-face benchmark and never on any reporter's material; the authors concluded the hashes should be treated as sensitive in the same way as the original images. The same team quoted Take It Down's FAQ answer that material 'cannot be reverse engineered or created from the hash values shared with NCMEC', reported that answer to be wrong, wrote to the operator twice between August and December 2023, received no reply, and recorded that the website did not change; the sentence was still on the FAQ page on 2026-08-27. A separate USENIX Security 2023 evaluation demonstrated efficient targeted second-preimage and detection-avoidance attacks against PhotoDNA and PDQ, concluding existing perceptual hash functions are likely insufficiently robust for adversarial settings. No operator in this class publishes an audited error rate for its deployed system.

    empirical
    • Academic Hawkes, S., Weinert, C., Almeida, T., & Mehrnezhad, M. (2024). Perceptual Hash Inversion Attacks on Image-Based Sexual Abuse Removal Tools. IEEE Security & Privacy Magazine https://pure.royalholloway.ac.uk/ws/portalfiles/portal/63677133/TiD_OA.pdf
    • Academic Prokos, J., Fendley, N., Green, M., Schuster, R., Tromer, E., Jois, T., & Cao, Y. (2023). Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning. 32nd USENIX Security Symposium https://www.usenix.org/conference/usenixsecurity23/presentation/prokos
    • Advocacy National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/
  • The two configurations diverge on the victim channel by design, and both operators document the propagation surface a withdrawal does not reach. StopNCII gives a reporter a case number, PIN, and status page (updates can take 3 to 5 days) and services whole-case withdrawal against credentials the operator states it does not store and cannot reset; Take It Down is anonymous by construction, with no status channel, no notification of matches, and no withdrawal mechanism at all. StopNCII states that hashes persist after the reporter deletes the image and are shared with new partners as they join, and its FAQ states that participating companies 'reserve the right to continue enforcing their policies once they've acquired knowledge of the hash' — so an entry's reach grows after submission and a withdrawal retracts the bank's copy but not partner-held copies. A hash match obliges nobody: matching platforms review the content against their own policies before any action, platform-side matching is deployed self-hosted or by vendor API, and every documented failure of this protective system is a protection gap — a non-participating platform, an encrypted surface, a re-encoded copy that no longer matches, a partner copy a withdrawal cannot reach — never a false accusation.

    empirical
    • Advocacy StopNCII.org (Revenge Porn Helpline / SWGfL). Service pages: How It Works, Industry Partners, Frequently Asked Questions https://stopncii.org/
    • Advocacy National Center for Missing & Exploited Children, "Take It Down" (minor-focused hash removal service); with the NCMEC service page. https://takeitdown.ncmec.org/
    • Vendor Thorn, "Safer" (CSAM detection service for platforms). https://safer.io/
  • A University of Michigan audit study (ACM CSCW 2026) posted 50 synthetic-persona deepfake nude images to X and reported half through X's non-consensual-nudity mechanism and half as DMCA copyright violations: the DMCA reports achieved 100 percent removal within about 25 hours (mean 20.3 hours), while the non-consensual-nudity reports achieved zero removals over 21 days. The study tested X's victim-facing report channels, not hash matching, and X is a StopNCII partner — independent evidence that a platform's participation in a hash program can coexist with a non-functioning victim-facing report channel, which is why the match channel and the platform report channel are modeled separately.

    empirical
    • Academic Zhang and colleagues, Reporting Non-Consensual Intimate Media: An Audit Study of Deepfakes (ACM CSCW 2026; read in the arXiv 2409.12138 preprint version) https://arxiv.org/html/2409.12138v1
  • The voluntary hash indexes acquired a mandatory legal overlay during 2024-2026, on separate tracks that operate independently of hash-program membership. In the US, the TAKE IT DOWN Act's Section 3 notice-and-removal duty took effect May 19, 2026: covered platforms must remove reported non-consensual intimate imagery and known identical copies within 48 hours of a valid request, enforced by the FTC, which opened a complaint portal and sent compliance letters to fifteen major companies including Alphabet, Discord, and X — companies that do not all participate in either voluntary hash index. In the UK, NCII sharing became a priority offence under the Online Safety Act via 2024 regulations, a creation offence covering purported intimate images including deepfakes came into force February 6, 2026 under the Data (Use and Access) Act 2025, Ofcom's hash-matching code measures were expected in force from summer 2026, and a Crime and Policing Bill amendment announced February 19, 2026 would require 48-hour takedown with penalties up to 10 percent of worldwide turnover. The statutes mandate responding to removal requests; they do not require joining either hash index, and they leave the indexes' unauditability untouched.

    empirical
    • Government Federal Trade Commission (2026, May). FTC Begins Enforcing the TAKE IT DOWN Act (press release) https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-begins-enforcing-take-it-down-act
    • Reference Fladgate LLP (2024). UK Government set to strengthen Online Safety Act to combat non-consensual intimate image sharing https://www.fladgate.com/insights/uk-government-set-to-strengthen-online-safety-act-to-combat-non-consensual-intimate-image-sharing
    • Reference Osborne Clarke (2026, February). Digital regulation | UK Regulatory Outlook February 2026 https://www.osborneclarke.com/insights/regulatory-outlook-february-2026-digital-regulation

Where this connects

Institutional pressures in this domain

  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).

All of them in context on the Content moderation & editorial AI domain page.

Levers available here and the patterns behind them

Documented case histories