Context
- The NHRC has issued notices to MeitY, MIB and Delhi Police over Instagram advertisements allegedly directing users to Telegram channels offering Child Sexual Abuse Material (CSAM).
- The probe raises two major regulatory questions:
- Compliance with POCSO: Whether the mandatory duty to report suspected child sexual offences under the POCSO Act, 2012 was properly followed.
- Status of AI-driven platforms: Whether platforms that actively recommend, generate, amplify or monetise content can continue to claim legal protection as mere intermediaries.
What is the Mandatory Reporting Requirement under POCSO?
- Section 19 of POCSO requires any person who knows about or apprehends the commission of a sexual offence against a child to report it to the Special Juvenile Police Unit or local police.
- The NHRC has sought clarification from Meta on whether the alleged offences were reported and, if not, who was responsible for compliance.
- Internal communication, grievance handling or discussions with regulators cannot substitute the statutory reporting obligation.
Why is the Intermediary Status of AI Platforms Being Questioned?
- Traditional intermediaries mainly host third-party content without actively controlling it.
- AI-driven platforms now recommend, curate, amplify and monetise content, raising questions about their role.
- The key issue is whether such active involvement makes them more like publishers rather than simple intermediaries under the IT Rules, 2021.
About CyberTipline Reports
- CyberTipline reports are alerts (not FIR) about suspected online child sexual exploitation, generated when technology companies detect such content or activity on their platforms.
- India received around 9 million such reports in 2025, covering child abuse material, online grooming, sextortion, trafficking and attempts to distribute such content.
- How the system works: Technology platforms → US-based child protection organisation → Indian authorities → State/District Police
- Technology companies report suspected cases to the National Center for Missing & Exploited Children (NCMEC) in the United States, which operates the CyberTipline.
- Reports relating to India are forwarded to Indian agencies, where the National Crime Records Bureau and Indian Cybercrime Coordination Centre process and route them to the relevant state and district authorities.
- In Delhi, the Intelligence Fusion and Strategic Operations unit verifies the jurisdiction and forwards the report to the concerned police station.
How Does a CyberTipline Report Become an FIR?
A CyberTipline report is first verified by the police before it can lead to an FIR.
- Police check account details, IP addresses, phone numbers, email IDs and other digital records to identify the person involved and determine the jurisdiction.
- A hash value works like a digital fingerprint of a file, helping investigators check whether the material found matches the content reported through the CyberTipline.
- Not every report is equally reliable. Some provide enough evidence for quick action, while others require further verification.
- An FIR is registered when the available material prima facie indicates child sexual abuse. A key challenge is confirming the age of the person shown, especially when images are unclear or blurred.
- The scale of the problem is reflected in Crime in India 2024: out of 1,238 cybercrime cases involving children under the Information Technology Act, 1,099 involved publishing or transmitting sexually explicit material depicting children.
What Happens After an FIR is Registered?
- Investigators attempt to identify the person behind an account through subscriber information, IP tracing and internet-service-provider records.
- Digital devices may be seized and subjected to forensic examination.
- The integrity of digital evidence is maintained through documented chain of custody, supported by certificates under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023.
- Cases are tried before POCSO Special Courts. Under Section 28(3) of POCSO, these courts have jurisdiction over offences under Section 67B of the IT Act.
- Since prosecutions depend substantially on digital evidence, proper collection, preservation and authentication are critical.
Challenges and Way Forward
| Challenges | Way Forward |
| 1. Difficulty tracing the source: A CyberTipline report may identify where the material was detected, but finding where and by whom it originated requires further investigation. | 1. Strengthen investigations: Improve access to digital evidence and investigative tools to trace the original source and offender. |
| 2. Delays in reporting: Reports pass through multiple agencies before reaching the police, causing delays even when the child, offender and platform are all in India. | 2. Faster reporting: Reduce unnecessary layers and establish a quicker reporting chain between platforms, central agencies and local police. |
| 3. Evolving technology: Encryption and AI-generated content can reduce the effectiveness of conventional detection methods such as hash matching. | 3. Upgrade technology: Develop better tools to detect encrypted, synthetic and AI-generated abusive content. |
| 4. Changing nature of crime: Offenders continuously adopt new technologies and methods, making a one-time investment in law-enforcement capacity inadequate. | 4. Continuous capacity building: Regularly upgrade skills, forensic infrastructure and technological capabilities of cybercrime investigators. |
| 5. Unclear platform responsibility: AI systems can actively curate, recommend and amplify content, creating uncertainty about platform accountability. | 5. Clear platform accountability: Define stronger responsibilities for platforms that actively influence or distribute content through AI. |
| 6. Weak compliance with reporting duties: Suspected offences may not always be reported as required under Section 19 of POCSO. | 6. Ensure strict POCSO compliance: Make platforms and responsible individuals promptly report suspected offences as legally required. |
| 7. Fragmented institutional response: Multiple agencies and levels of government handle CyberTipline reports, making coordination difficult. | 7. Better inter-agency coordination: Enable real-time information sharing among technology platforms, central agencies and state police. |
Conclusion
The NHRC probe exposes a crucial gap between rapidly evolving online threats & existing enforcement mechanisms. Stronger platform accountability, faster reporting and continuously upgraded investigative capabilities are essential to ensure that technology becomes a tool for protecting children, rather than enabling their exploitation.
FAQs
Q1. What triggered the NHRC probe?
Instagram ads allegedly directed users to Telegram channels offering Child Sexual Abuse Material (CSAM), raising concerns about compliance with child‑protection laws.
Q2. What does Section 19 of POCSO require?
It mandates that anyone aware of or suspecting child sexual offences must report to police or the Special Juvenile Police Unit. Internal grievance handling cannot replace this statutory duty.
Q3. Why is the intermediary status of AI platforms being questioned?
Unlike traditional intermediaries, AI‑driven platforms actively recommend, curate, and monetise content, making them closer to publishers under IT Rules, 2021.


