54 Attorneys General Tell Congress: AI-Generated Child Abuse Images Are a Crisis Now
What happened
Fifty-four attorneys general, representing nearly every state and territory in the country, put their names on a single letter to Congress on September 5, 2023. That kind of unanimity almost never happens in American politics, which is exactly what makes it worth reading closely. The letter warned that generative AI tools are now being used to produce child sexual abuse material and asked lawmakers to intervene before the problem outgrows any agency's ability to respond.
The scale of the ask matters more than the wording. State law enforcement officials, the people who actually investigate these cases, were telling Congress that existing statutes and existing tools were not built for a world where abuse imagery can be synthesized instead of photographed. A predator no longer needs a victim in the room to generate material realistic enough to trade, sell, or use for coercion. Detection systems trained to flag known abuse images struggle against content a model invented an hour ago, with no fingerprint in any database.
What went wrong here is not one company's product decision. It is a governance vacuum. Image generation models were built and released without a working answer to who is responsible when the output is illegal, and without a reliable way to prove, after the fact, that a given image came from a specific model, prompt, or account. Attorneys general do not send joint letters to Congress over hypothetical risks. They send them when the mechanism for accountability does not exist yet, and when 54 offices agree on that, the gap is already being exploited somewhere.
Congress has options short of banning the technology outright: mandated provenance tracking on generated media, liability rules for model operators, and reporting requirements that mirror what already applies to hosted abuse content. Each of those depends on the same underlying capability, a verifiable trail connecting an output back to the system and the people who built or ran it.
That is the piece missing from this story and from the wider AI industry today. No one in the chain, not the model provider, not the platform, not the investigator trying to build a case, can currently produce a cryptographic record showing what a model generated, who reviewed it, and when. Building that record is the difference between a letter asking Congress to act and a system that makes the abuse traceable from the start.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.