Google agrees to report child abuse material directly to India's cyber police

22.09.2026 11 min 27

Google has agreed to send reports about child sexual abuse material found on its services straight to Indian police, instead of routing them only through the American non-profit that has acted as the world's clearing house for such cases. The company confirmed the plan on 21 September, six days after Meta agreed to the same thing. What has not been published is the instrument behind the new channel, the list of services it covers, or the data that will travel with each report.

In brief

  • A Google spokesperson told Business Standard the company has "proposed to operationalise the provision of relevant information to the I4C in cases related to CSAM". I4C is the Indian Cyber Crime Coordination Centre, a unit of the Ministry of Home Affairs.
  • Until now Google and Meta filed such reports with the US-based National Center for Missing & Exploited Children (NCMEC), which passes them to police in the country involved. That route stays: US law requires it, and NCMEC says any direct reporting is supplemental.
  • Two Indian government sources told Reuters they had pressed Google and Microsoft in recent weeks, arguing that the detour through an intermediary costs time when a child is in immediate danger.
  • Below: what the two routes actually differ in, how many reports are involved, what happens when detection is wrong, and why a VPN has nothing to do with any of it.

Two routes for the same report

Nothing in the announcement changes how the material is found. Google scans for it on its own servers, using hash matching against databases of known images and machine learning that flags content resembling confirmed material. What changes is who sees the result first.

Through NCMECDirect to I4C
Who receives it firstNCMEC analysts in the US, who make the report available to the law enforcement agency for the country indicated by the dataIndia's Cyber Crime Coordination Centre, which then passes the case to the state or union territory concerned
Legal basis18 USC 2258A, which obliges US providers to report suspected material to the CyberTiplineNo published instrument. Google says it wrote to I4C and to the IT ministry explaining the step
ScopeEvery case a US provider becomes aware of, on every service it runsNot stated. No list of products, no list of report categories
Public recordAnnual counts per country and per company, published by NCMECNone announced

Google's full statement to Business Standard was short: "Google is deeply committed to fighting CSAM online and preventing its platforms from being used to create, store or distribute such material. We invest significantly to detect, deter, remove, and report CSAM." To Reuters the company described the proposal as part of its ongoing discussions with the government of India. John Shehan, who runs NCMEC's Exploited Children Division, told MediaNama that a platform reporting directly to Indian police would be doing so on top of the CyberTipline obligation, not instead of it.

How Delhi got here

  1. India's National Crime Records Bureau signs a memorandum with NCMEC to receive tipline reports. By 31 March 2024 more than 6.9 million of them had been forwarded to states and union territories, according to a Rajya Sabha reply.
  2. The Ministry of Home Affairs launches the Sahyog portal, run by I4C, to speed up takedown notices to platforms.
  3. The Karnataka High Court upholds Sahyog and the takedown power behind it, rejecting X Corp's challenge.
  4. A BBC Eye investigation reports that Instagram carried paid ads selling child abuse material. India's child rights commission issues a notice to Meta on 3 July; Meta publishes a statement on its child safety work on 7 July.
  5. Mark Zuckerberg apologises to Indian officials over child abuse content and deepfakes on Meta's platforms.
  6. Government sources say Meta has agreed to report child safety matters directly to the I4C portal.
  7. Google confirms it has proposed the same arrangement. Details will start flowing "as soon as the company has the technical framework ready", a source tells Business Standard.

There is one more change that was never announced at all. NCMEC no longer sends India's reports to the crime records bureau that signed the 2019 memorandum: Shehan told MediaNama that I4C is now the designated recipient. Indian authorities made that switch, and no public record says when it took effect or under what instrument. So the country's main channel for these reports had already moved to a home ministry body before any of this week's news.

21.3mreports received by the CyberTipline worldwide in 2025
1,933,900reports made available to India in 2025, more than for any country except the US
1,461,378reports filed by Google in 2025, up from 1,175,084 in 2024
77%of 2025 reports involved an upload by a user outside the US

Who files the most

Reports filed with the CyberTipline in 2025by platform
PlatformReports
Facebook4,907,710
Instagram3,673,045
WhatsApp2,355,302
Google1,461,378
Amazon AI Services1,105,405

Five providers account for more than three quarters of everything the CyberTipline receives. Google's own volume grew by about a quarter in a year while Facebook's fell from 8.59 million in 2024 to 4.91 million in 2025. None of these numbers count crimes. They count reports, most of them raised by automated matching, which NCMEC then makes available to the law enforcement agency for the country the data points to.

What the shortcut does not fix

Speed at the top of the pipe does not create speed at the bottom. Police and public order are state subjects in India, so a report that lands in a central system still has to become a first information report at a station that may be a thousand kilometres away. The pace after that is set by courts: in one case the Central Bureau of Investigation registered a child abuse material case in October 2016 and the conviction came on 11 June 2025.

The existing channel does produce results. In June 2025 the CBI arrested a man in Mathura after matching material from his devices against Interpol's database and against CyberTipline reports generated by Google and shared with I4C, and said it had identified and rescued the child victims. What nobody publishes is the denominator. NCMEC counts how many reports each country received; it does not count what was done with them, and Shehan said law enforcement feedback on outcomes is voluntary. Cases built on this kind of tip do exist, as the Italian operation against a paid Telegram network showed in September, but the ratio of reports to cases is not a public number in India or anywhere else. How one of those investigations is actually built is a useful contrast to a pipeline statistic.

What is not yet known: whether direct reporting supplements the NCMEC route for every India-related case or only some; which services are covered, from YouTube and Search to Drive, Photos and Gmail; how AI-generated material and grooming cases with no file attached will be handled; what personal data travels with each report; which unit inside I4C receives it; and whether a person whose account is reported is told anything at all. MediaNama put these questions to Google and has not received answers.

When the flag is wrong

Automated detection makes mistakes that are hard to unmake. In 2021 two fathers, one in San Francisco and one in Houston, photographed their sons' genitals at a doctor's request, because the pandemic had moved consultations online. The photos synced to Google. The company disabled both accounts, filed reports, and police in both cities investigated and concluded that no crime had occurred. Google did not restore either account. Its current policy states that appeals in this category are reviewed up to two times, after which further appeals are closed.

That is the part of the story the new route touches most directly for ordinary users. A flag that used to travel through an intermediary with its own analysts will now also go straight to a police body, in a country whose data protection act, passed in 2023, lets the government exempt its own agencies from most of the duties it imposes on everyone else.

  • Run Google Takeout once and keep the export somewhere that is not Google. An account suspension takes photos, mail and documents with it on the same day.
  • Set your recovery address at a different provider, so losing one account does not lock you out of the way back into it.
  • Do not tie banking, government or work logins to a single mailbox you do not control the fate of.
  • Medical photos of a child belong in the clinic's own channel or a local folder, not in a gallery that syncs to a cloud account by default.
  • Know the appeal path before you need it: the form, the evidence you would attach, and the fact that the review limit in this category is two.
  • Remember that two decisions are separate. Police clearing you does not oblige the platform to give the account back.

A VPN does nothing here, and it is worth saying so plainly. It changes the IP address a service sees, not what that service finds inside an account you are signed into on your own devices. Scanning happens on the provider's servers, on files you uploaded. The fight where technology does matter is the one over scanning messages before they are encrypted, which is what the European Chat Control proposal has been circling for three years. India is not proposing that. It is asking for a faster pipe to the reports platforms already generate.

Does this mean Google stops reporting to NCMEC?
No. US federal law requires providers based in the United States to report suspected child sexual abuse material, online enticement and child sex trafficking to the CyberTipline. NCMEC's John Shehan told MediaNama that anything a company sends directly to Indian police is supplemental and does not replace that obligation.
Which Google services does the new channel cover?
Google has not said. The statement refers to "cases related to CSAM" without naming products, so it is unclear whether YouTube, Search, Drive, Photos and Gmail are treated the same way. MediaNama asked the company this question directly and has not published an answer.
Can Indian police now demand my Google data more easily?
No new power to demand data comes with the arrangement. The channel carries reports that Google generates itself when its systems flag material. Requests for user data from police still go through the legal process Google describes in its transparency reporting, and the company publishes the volume of those separately.
Does a report mean someone is guilty?
No. A CyberTipline report is a flag, usually raised by automated matching, and NCMEC does not confirm each one before making it available to law enforcement. The 2021 cases of two fathers whose medical photos were reported, investigated and cleared, and which became public a year later, show what a false positive looks like in practice.
Would a VPN or encryption change what is reported?
A VPN would not: it hides the IP address from the service, while the scanning happens on the service's own servers on content in your account. End-to-end encrypted services see less by design, which is exactly why proposals to scan messages before encryption are fought so hard in the EU. The Indian arrangement is about the speed of existing reports, not about breaking encryption.

indiagooglechild abuse materialyoutubemetancmeci4cchild protectionchildren onlinelaw enforcementpolicecontent moderationsurveillanceprivacypersonal dataplatform regulation

Read also