On September 10, the Australian Federal Police announced the Australian Centre to Counter Child Exploitation received 100,194 reports of online child sexual exploitation in 2025-26 . That is about 275 a day – a 21% rise over the year before, and up from 36,600 four years ago.
Author
- Joel Scanlan
Adjunct Associate Professor, School of Law; Academic Co-Lead, CSAM Deterrence Centre, University of Tasmania
Read as a measure of how much abuse Australian children are suffering, the figure is alarming. But it’s not an accurate measure. It’s primarily the count of reports made by companies who chose to look for harm occurring on their platforms. This figure is a floor for the harm occurring online.
Two days earlier, the federal government released an exposure draft of its long-awaited digital duty of care bill . The bill would make platforms responsible for a “safe online environment”.
But if passed in its current form, it would not require platforms to look for online harms, nor to tell anyone in Australia what they find if they do.
Where the 100,000 reports come from
According to the Australian Federal Police , most of the reports of online child sexual exploitation come primarily from the United States National Center for Missing and Exploited Children, with the rest from the public and government agencies.
The US centre runs the CyberTipline which received 21.3 million reports in 2025. Some 317 companies made them, and five tech companies made more than three-quarters of the total: Facebook, Instagram, TikTok, WhatsApp and Google.
Analysts from the US centre determine which country each report relates to, usually based on the computer’s IP address, and pass it on. Reports that relate to an Australian user, whether an adult sharing illegal material or a child being groomed, are handed to the Australian Centre to Counter Child Exploitation. That is where the bulk of the 100,000 reports came from.
Under American law, US companies must report abusive material once they become aware of it. But nothing makes them look .
According to the US centre, in 2025 , Google made 1,461,378 reports, and Facebook 4,907,710. Apple made 296. The number of reports tells you how hard each company looks, not the level of harm occurring.
Why the count is a floor
Because looking is optional, the count moves when companies change their minds.
When Meta switched Facebook Messenger to end-to-end encryption by default in December 2023, Facebook’s reports of online child sexual exploitation fell from 17.8 million in 2023 to 8.6 million in 2024 and 4.9 million in 2025 .
The US centre said the fall in reporting was “not because the crimes have stopped, but because some platforms aren’t reporting as they should”.
In 2020-21, companies were in limbo about whether the European Union’s privacy law allowed them to scan for abusive material, and reports of EU users fell by 58% across 18 weeks.
The count misses the services that never look.
Australia’s online watchdog, eSafety, has the power to compel companies to answer questions, through its transparency reporting process. This shows that in the first half of 2025, Google used no tools to detect new abuse material on Meet, Chat, Messages or Gmail, and Apple relied solely on user reports.
Where a company does not look, abuse only gets reported if a victim reports it.
What other countries require
The United States has required this reporting to the National Center for Missing and Exploited Children for more than 25 years.
Canada also has had a mandatory reporting law since 2011. Brazil’s Digital Statute for Children and Adolescents came into force in March 2026 and the United Kingdom’s duty started on April 7 2026 .
These newer laws exempt companies that already report to the US centre.
Each country compels the platforms based in its own jurisdiction, so coverage extends without anyone reporting twice. Based on investigations I have done as part of my ongoing research, only three Australian companies have voluntarily reported to the US centre in the last two years.
Australia has one reporting law for child abuse material, section 474.25 of the Criminal Code , written in 2004. Its limited scope only applies to Australian internet service and hosting providers, but it requires reporting to the Australian Federal Police.
It does not require anyone to look.
How the duty of care could be strengthened
Australia’s proposed duty of care law is generally strong. But platforms need to be responsible for reporting online child sexual exploitation rather than relying on victims to do so.
Twelve months after the digital duty of care becomes law, the current rules – called the Basic Online Safety Expectations – that tell platforms to proactively detect child abuse material will be repealed. In their place, the draft offers a general duty for platforms to take “reasonably practicable” steps and guidance the eSafety commissioner will publish.
We should put into law the obligation to proactively detect harm and report it.
The word “detect” (or similar) does not appear in the bill, and nothing in it requires a platform to tell the Australian Federal Police, eSafety or anyone else what it finds.
Three specific additions would give Australia a count of its own.
First, a requirement to proactively look for harm occurring on platforms, perhaps gated behind a certain level of risk under the assessment guidelines the duty describes.
Second, every service with Australian users should have to report the child sexual exploitation it detects, grooming included, to an Australian body or global counterpart like the US centre.
Third, name a domestic designated body where reports need to be sent.
None of this would reduce the annual figure. It would likely push the figure up because it would compel services that are not currently required to report.
Until platforms have to look and tell an Australian body what they find, the Australian Federal Police’s annual figures will only reflect how hard American companies voluntarily looked.
![]()