San Francisco's city attorney has issued a cease-and-desist order demanding that Meta halt paid advertisements containing AI-generated child sexual abuse material and explain how the content repeatedly evaded its moderation systems. The directive from City Attorney David Chiu follows research showing that Meta ran more than 350 such ads in recent months, some featuring real minors including a European royal family member, transformed into video clips depicting sexual acts. The ads promoted apps capable of digitally undressing people or creating other nonconsensual intimate imagery.

The advertisements discovered by researchers at the Tech Transparency Project appeared across Facebook, Instagram, and Threads, reaching more than 29,000 accounts in European Union countries as well as targeting users in the United States, Australia, and India. Some identical ads were uploaded multiple times to Meta's platforms. More than 250 of the total ads ran after an initial August report by WIRED exposed 53 similar advertisements, yet the issue persisted. Meta has now removed all the ads for violating its policies, though the company says most generated fewer than 200 impressions and the total advertising spend was under $5,000. In some cases, Meta didn't respond to reports about abusive ads for over a week, during which hundreds more people viewed them, and when certain ads were initially removed they weren't flagged as containing child sexual abuse content.

"Meta has failed to address a known issue of AI-generated child sexually explicit ads, while profiting from them," Chiu states in his letter to Meta's lawyers. The four-page letter argues that no company should allow its advertising systems to be exploited in this manner, particularly one claiming all advertisements receive review and approval before distribution. The city attorney writes that the findings are especially troubling because they don't reflect an isolated failure that Meta corrected when first alerted. Tech Transparency Project director Katie Paul says Meta is "not effectively" addressing the issue, noting that as of Wednesday, new ads featuring some of the same children previously reported to Meta have appeared on the platform.

Chiu's letter raises significant legal questions about Meta's ad policies and safety systems, demanding explanations for how the ads avoided moderation, how the company escalates and reports such content to the National Center for Missing and Exploited Children, and how it handles repeat offenders. The cease-and-desist characterizes the findings as evidence of "broader systemic problems" with Meta's ability to detect potential child sexual abuse in advertising. Meta responded by claiming the ads fall "outside the city attorney's jurisdiction" because there's no indication they were displayed in San Francisco, though Meta's ad library doesn't break down where within the US ads may have run. City Attorney's Office spokesperson Alex Barrett-Shorter countered that San Francisco consumers can access the unlawful ads through Meta's online spaces, making it the city's business.

The letter requests that Meta's legal, child-safety, and advertising staff engage in prompt discussions with the city office and provide a response within 28 days. Chiu writes that his office's objective isn't simply identifying past failures but ensuring Meta implements systems preventing children from being sexually exploited through paid advertisements and that the company reliably satisfies legal obligations when it becomes aware of apparent child sexual exploitation. Despite Meta's community standards and advertising policies prohibiting child sexual abuse material and nudify apps, and despite the company previously removing hundreds of thousands of ads for such apps and suing a Hong Kong-based company linked to nudifier platforms, researchers continue finding thousands of problematic ads. The cease-and-desist concludes that Meta's isolated takedown efforts are woefully inadequate given the scale, persistence, and nature of the documented problems. Platform accountability for automated moderation will likely face heightened regulatory scrutiny as governments weigh whether self-policing suffices when the stakes involve real children. The case may test whether cities can assert jurisdiction over online harms accessible to their residents, even when platforms argue the violations occurred elsewhere.