Context: The National Human Rights Commission (NHRC) has sought explanations from Union ministries, Delhi Police and Meta over paid Instagram advertisements allegedly directing users to Telegram channels offering Child Sexual Abuse Material (CSAM). The case highlights gaps in platform accountability, mandatory reporting and conversion of online alerts into prosecutions.
What Did the NHRC Ask?
The NHRC has raised two major concerns:
- Compliance with POCSO: Section 19 of the Protection of Children from Sexual Offences (POCSO) Act, 2012 requires any person who knows or apprehends that a POCSO offence has occurred or may occur to report it to the Special Juvenile Police Unit or local police.
- Platform responsibility: The Commission has asked whether Meta reported the alleged offences and, if not, who was responsible for ensuring compliance. Internal correspondence, grievance redressal or engagement with regulators cannot replace the statutory reporting obligation.
Intermediary vs Publisher
- Intermediary: Under India’s IT framework, an intermediary generally provides a platform for third-party content while receiving certain legal protections subject to compliance with prescribed conditions.
- The complaint argues that AI-assisted systems on platforms such as Instagram increasingly generate captions, recommend posting schedules, optimise engagement and facilitate monetisation, going beyond passive hosting.
- The NHRC has therefore asked whether such functions are compatible with intermediary status or could make platforms more comparable to publishers of online curated content under the Information Technology Rules, 2021.
India’s Larger Reporting-to-Prosecution Gap
India received around 1.9 million CyberTipline reports in 2025—alerts generated when technology companies detect suspected CSAM. However, only a fraction result in police action.
CyberTipline: A system through which technology platforms report suspected online child sexual exploitation to the National Center for Missing & Exploited Children (NCMEC) in the US, generating alerts that may be shared with law-enforcement agencies.
How a CyberTipline Report Is Processed
- Reports are processed by the National Crime Records Bureau (NCRB) and Indian Cybercrime Coordination Centre (I4C) before being routed to relevant State and district authorities.
- Police conduct preliminary verification before registering an FIR because reports differ in quality and completeness.
- Investigators first establish whether the material prima facie depicts CSAM and identify the relevant jurisdiction before forwarding the case to the local or cyber police unit.
- A major challenge is establishing the victim’s age, particularly when images are blurred, of poor quality or otherwise inconclusive.
- After an FIR, investigators attempt to identify the person behind the account, while cases are generally tried in special courts under POCSO.
Why Convictions Are Difficult?
- Convictions depend heavily on the authenticity and evidentiary value of digital evidence.
- Defence arguments often question whether the accused was actually the person using the particular device, SIM card or internet connection associated with the offence.
- If investigators cannot establish the identity of the offender, police may ultimately file a closure report.
Limits of CyberTipline Reports
- A CyberTipline alert generally indicates where suspected CSAM was detected, not necessarily where it originated; establishing the source requires a separate investigation.
- The challenge is becoming more complex with the increasing use of encrypted platforms and AI-generated content, which can make detection, attribution and evidence collection more difficult.