Google agrees to report child abuse material directly to India's cyber police
Google has agreed to send reports about child sexual abuse material found on its services straight to Indian police, instead of routing them only through the American non-profit that has acted as the world's clearing house for such cases. The company confirmed the plan on 21 September, six days after Meta agreed to the same thing. What has not been published is the instrument behind the new channel, the list of services it covers, or the data that will travel with each report.
In brief
- A Google spokesperson told Business Standard the company has "proposed to operationalise the provision of relevant information to the I4C in cases related to CSAM". I4C is the Indian Cyber Crime Coordination Centre, a unit of the Ministry of Home Affairs.
- Until now Google and Meta filed such reports with the US-based National Center for Missing & Exploited Children (NCMEC), which passes them to police in the country involved. That route stays: US law requires it, and NCMEC says any direct reporting is supplemental.
- Two Indian government sources told Reuters they had pressed Google and Microsoft in recent weeks, arguing that the detour through an intermediary costs time when a child is in immediate danger.
- Below: what the two routes actually differ in, how many reports are involved, what happens when detection is wrong, and why a VPN has nothing to do with any of it.
Two routes for the same report
Nothing in the announcement changes how the material is found. Google scans for it on its own servers, using hash matching against databases of known images and machine learning that flags content resembling confirmed material. What changes is who sees the result first.
| Through NCMEC | Direct to I4C | |
|---|---|---|
| Who receives it first | NCMEC analysts in the US, who make the report available to the law enforcement agency for the country indicated by the data | India's Cyber Crime Coordination Centre, which then passes the case to the state or union territory concerned |
| Legal basis | 18 USC 2258A, which obliges US providers to report suspected material to the CyberTipline | No published instrument. Google says it wrote to I4C and to the IT ministry explaining the step |
| Scope | Every case a US provider becomes aware of, on every service it runs | Not stated. No list of products, no list of report categories |
| Public record | Annual counts per country and per company, published by NCMEC | None announced |
Google's full statement to Business Standard was short: "Google is deeply committed to fighting CSAM online and preventing its platforms from being used to create, store or distribute such material. We invest significantly to detect, deter, remove, and report CSAM." To Reuters the company described the proposal as part of its ongoing discussions with the government of India. John Shehan, who runs NCMEC's Exploited Children Division, told MediaNama that a platform reporting directly to Indian police would be doing so on top of the CyberTipline obligation, not instead of it.
How Delhi got here
- India's National Crime Records Bureau signs a memorandum with NCMEC to receive tipline reports. By 31 March 2024 more than 6.9 million of them had been forwarded to states and union territories, according to a Rajya Sabha reply.
- The Ministry of Home Affairs launches the Sahyog portal, run by I4C, to speed up takedown notices to platforms.
- The Karnataka High Court upholds Sahyog and the takedown power behind it, rejecting X Corp's challenge.
- A BBC Eye investigation reports that Instagram carried paid ads selling child abuse material. India's child rights commission issues a notice to Meta on 3 July; Meta publishes a statement on its child safety work on 7 July.
- Mark Zuckerberg apologises to Indian officials over child abuse content and deepfakes on Meta's platforms.
- Government sources say Meta has agreed to report child safety matters directly to the I4C portal.
- Google confirms it has proposed the same arrangement. Details will start flowing "as soon as the company has the technical framework ready", a source tells Business Standard.
There is one more change that was never announced at all. NCMEC no longer sends India's reports to the crime records bureau that signed the 2019 memorandum: Shehan told MediaNama that I4C is now the designated recipient. Indian authorities made that switch, and no public record says when it took effect or under what instrument. So the country's main channel for these reports had already moved to a home ministry body before any of this week's news.
Who files the most
| Platform | Reports |
|---|---|
| 4,907,710 | |
| 3,673,045 | |
| 2,355,302 | |
| 1,461,378 | |
| Amazon AI Services | 1,105,405 |
Five providers account for more than three quarters of everything the CyberTipline receives. Google's own volume grew by about a quarter in a year while Facebook's fell from 8.59 million in 2024 to 4.91 million in 2025. None of these numbers count crimes. They count reports, most of them raised by automated matching, which NCMEC then makes available to the law enforcement agency for the country the data points to.
What the shortcut does not fix
Speed at the top of the pipe does not create speed at the bottom. Police and public order are state subjects in India, so a report that lands in a central system still has to become a first information report at a station that may be a thousand kilometres away. The pace after that is set by courts: in one case the Central Bureau of Investigation registered a child abuse material case in October 2016 and the conviction came on 11 June 2025.
The existing channel does produce results. In June 2025 the CBI arrested a man in Mathura after matching material from his devices against Interpol's database and against CyberTipline reports generated by Google and shared with I4C, and said it had identified and rescued the child victims. What nobody publishes is the denominator. NCMEC counts how many reports each country received; it does not count what was done with them, and Shehan said law enforcement feedback on outcomes is voluntary. Cases built on this kind of tip do exist, as the Italian operation against a paid Telegram network showed in September, but the ratio of reports to cases is not a public number in India or anywhere else. How one of those investigations is actually built is a useful contrast to a pipeline statistic.
When the flag is wrong
Automated detection makes mistakes that are hard to unmake. In 2021 two fathers, one in San Francisco and one in Houston, photographed their sons' genitals at a doctor's request, because the pandemic had moved consultations online. The photos synced to Google. The company disabled both accounts, filed reports, and police in both cities investigated and concluded that no crime had occurred. Google did not restore either account. Its current policy states that appeals in this category are reviewed up to two times, after which further appeals are closed.
That is the part of the story the new route touches most directly for ordinary users. A flag that used to travel through an intermediary with its own analysts will now also go straight to a police body, in a country whose data protection act, passed in 2023, lets the government exempt its own agencies from most of the duties it imposes on everyone else.
- Run Google Takeout once and keep the export somewhere that is not Google. An account suspension takes photos, mail and documents with it on the same day.
- Set your recovery address at a different provider, so losing one account does not lock you out of the way back into it.
- Do not tie banking, government or work logins to a single mailbox you do not control the fate of.
- Medical photos of a child belong in the clinic's own channel or a local folder, not in a gallery that syncs to a cloud account by default.
- Know the appeal path before you need it: the form, the evidence you would attach, and the fact that the review limit in this category is two.
- Remember that two decisions are separate. Police clearing you does not oblige the platform to give the account back.
A VPN does nothing here, and it is worth saying so plainly. It changes the IP address a service sees, not what that service finds inside an account you are signed into on your own devices. Scanning happens on the provider's servers, on files you uploaded. The fight where technology does matter is the one over scanning messages before they are encrypted, which is what the European Chat Control proposal has been circling for three years. India is not proposing that. It is asking for a faster pipe to the reports platforms already generate.
Does this mean Google stops reporting to NCMEC?
Which Google services does the new channel cover?
Can Indian police now demand my Google data more easily?
Does a report mean someone is guilty?
Would a VPN or encryption change what is reported?
• Google to Report Child Sexual Abuse Material Directly to Indian Authorities - MediaNama
• Meta Will Report Child Safety Matters Directly to India's I4C. What Changes? - MediaNama
• After Meta, Google to share child sexual abuse case details with govt - Business Standard
• Google to report child abuse content directly to Indian authorities - Reuters via Khaleej Times
• CyberTipline Data - NCMEC
• 2025 CyberTipline Reports by Electronic Service Provider - NCMEC
• 2025 CyberTipline Reports by Country - NCMEC
• How we detect, remove and report child sexual abuse material - Google
• Learn how Google addresses online child sexual abuse and exploitation - Google Help
• Google Flagged Parents' Photos of Sick Children as Sexual Abuse - Gizmodo
• Zuckerberg apologises for child abuse ads, deepfakes, operating error - Deccan Herald
• Analysis of X Corp v. Union of India Judgment in Karnataka HC - SFLC.in