← Platforms

Meta

meta.com

C

Partial

Files the overwhelming majority of all CyberTipline reports and operates the most developed detection stack of any assessed operator. The 2023 default rollout of end-to-end encryption on its largest messaging surface removed server-side detection from the place where most of that reporting originated.
Domain
meta.com
Category
Social
Last review
2026-04-15

Controversies

Default end-to-end encryption on Messenger

In December 2023 the operator began rolling out end-to-end encryption as the default on its largest messaging surface. The surface had been the origin of a substantial share of the operator's CyberTipline reporting, and server-side content matching is not possible once messages are encrypted. Child-protection organisations and several governments objected that the change would reduce the volume of detectable material without a demonstrated compensating mechanism, while privacy advocates argued that scanning private messages is itself a harm. The operator has described metadata analysis, behavioural signals and user reporting as its compensating measures, but has not published figures allowing their effectiveness to be compared against the detection they replaced. [2]

Recommendation systems connecting adults with minors

Regulators found that recommendation and discovery systems had surfaced minor accounts to adult accounts exhibiting predatory behaviour, and that engagement-optimised ranking contributed to the pattern. [4]

Detection & scanning

Whether known and novel abuse material is found at all, and across which surfaces of the product.

B
1.01

Hash matching on publicly posted media

Hash matching and classifier detection are applied across public surfaces. [1]

Pass
1.02

Hash matching on private messages and attachments

Server-side matching is unavailable on the primary messaging surface following the default encryption rollout. [2]

Fail
1.03

Classifier detection of previously unseen material

Classifier detection for previously unseen material is described and contributed to industry programmes. [1]

Pass
1.04

Detection applied to live and streamed video

Live surfaces are covered.

Pass
1.05

Detection of grooming and solicitation in text

Behavioural detection of adult accounts seeking contact with minors is described with published intervention volumes. [1]

Pass
1.06

Participation in industry hash-sharing programmes

Founding participant in industry hash-sharing programmes.

Pass

Reporting & transparency

What the operator tells NCMEC, law enforcement and the public, and whether those disclosures can be checked.

A
2.01

Files CyberTipline reports to NCMEC

Files the large majority of all CyberTipline reports received. [3]

Pass
2.02

Publishes child-safety enforcement figures

Quarterly enforcement reporting breaks out child endangerment by surface. [1]

Pass
2.03

Report quality sufficient for investigation

Report content is described as including the metadata investigators require.

Pass
2.04

Reporting cadence and timeliness

Reporting is filed on detection.

Pass

Response & enforcement

What happens after material is found: how fast it comes down, what happens to the account, and whether the decision can be contested.

B
3.01

Time to removal of confirmed material

Proactive removal rates are published; absolute latency is not.

Neutral
3.02

Account termination on confirmed violation

Termination on confirmed violation.

Pass
3.03

Prevention of re-registration

Re-registration controls are described. Effectiveness is not published.

Neutral
3.04

Preservation of evidence

Preservation practice is documented.

Pass
3.05

Escalation of imminent-harm cases

Imminent-harm escalation documented.

Pass

Product & policy posture

The design decisions that determine how much abuse is possible in the first place, before any detection is applied.

C
4.01

Protective defaults for minor accounts

Teen accounts default to private with restricted messaging. [1]

Pass
4.02

Restrictions on adult-initiated contact with minors

Adults cannot message unconnected teen accounts. [1]

Pass
4.03

Age assurance at registration

Age estimation is applied to some flows. Registration remains self-declared.

Neutral
4.04

Recommendation systems assessed for minor-safety harm

Recommendation systems have been the subject of regulatory findings that they connected adult accounts with minors. [4]

Fail
4.05

Encryption posture and stated mitigations

Compensating measures for the encrypted surface are described as metadata and behavioural signals plus user reporting. Their effectiveness relative to the prior server-side detection has not been published. [2]

Neutral
4.06

Published child-safety policy with defined enforcement

Policy is published with stated enforcement.

Pass

Record

Documented failures, enforcement actions, litigation and investigative reporting bearing on the assessment above.

2023-12

End-to-end encryption made default on the primary messaging surface

The change removed server-side content matching from the surface that had generated a substantial share of the operator's CyberTipline reporting. Child-protection organisations and several governments objected. [2]

2024-11

Regulatory findings on recommendation systems

Regulators found that recommendation and discovery systems had surfaced minor accounts to adult accounts exhibiting predatory behaviour. [4]

Sources

  1. [1]
  2. [2]
  3. [3]
  4. [4]
    Regulatory findings

    Illustrative placeholder · 2024-11

Know something we don’t?

If we’ve missed a controversy or there’s newer reporting on Meta, tell us. If you represent Meta, we welcome documentation of safety measures not yet reflected here.

Contact us

Report CSAM

If you have encountered CSAM, file a report through one of these channels.