Known vs. Unknown CSAM: Why Hash Matching is No Longer Enough for Platform Safety
Is hash matching enough for CSAM detection? Learn the difference between known and unknown CSAM and how platforms approach detection.
Hash matching is one of the foundations of online child safety. It allows platforms to compare uploaded images and videos against databases of previously confirmed child sexual abuse material, or CSAM, making it possible to identify known illegal content quickly and at scale.
However, as bad actors look to increasingly bypass historical databases, the challenge today is that online safety risks extend beyond content that has already been identified. New abuse material is created every day. Existing images are altered to evade detection. Generative AI has introduced entirely new forms of synthetic abuse imagery. By definition, none of this material exists in a known-content hash database. While hash matching remains an essential baseline, it is fundamentally reactive: it cannot catch what hasn’t been fingerprinted. In recent findings, the Internet Watch Foundation (IWF) reported a 26,385% surge in AI-generated CSAM, with 65% categorized as the most severe form of abuse (Category A).
Because newly created, modified, or synthetic material has no historical digital fingerprint, relying on hashing alone leaves up to 90% of unseen threats completely undetected. These trends highlight a growing reality: platforms increasingly face harmful content that has never been seen before.
This shift changes an important question for Trust & Safety teams. The challenge is no longer simply, “Can we identify known CSAM?” It’s “How do we identify CSAM when there isn’t already a known match?”
For many organizations, that means going beyond hash matching alone. While known-content matching remains the essential foundation, it now needs to be combined with predictive technologies and operational processes that can find and assess previously unseen content, apply consistent decision-making, and respond appropriately when potential CSAM is identified.
In this guide, we’ll explain how hash matching works, where it excels, where its limitations begin, and why many platforms are adopting
Is hash matching enough for CSAM detection?
Historically, hash matching was established as the primary technical control for CSAM detection. To understand its limitations, it helps to understand how it works.
Hash matching does not store or compare actual images in a database. Instead, a mathematical algorithm processes a confirmed image to generate a unique digital fingerprint— known as a cryptographic or perceptual hash. When a user uploads media to a platform, the system converts that file into a hash and checks it against a database of known hashes (such as those maintained by NCMEC or the IWF). If the fingerprints match, the file is identified as previously confirmed abuse material and can be removed instantly.
However, modern bad actors actively exploit this mechanic. Because hashing relies on matching exact digital fingerprints, making slight pixel modifications, altering metadata, cropping, or using generative AI to create novel abuse changes the underlying code of a digital fingerprint. To the hash database, the new file looks completely unrelated.
Because these novel threats have no existing reference fingerprint, they pass through traditional upload filters completely untriaged—leaving platforms exposed and unaware until manual reports are filed long after the content has proliferated.
To close this visibility gap, leading Trust & Safety programs are evolving from purely reactive hash lookups to a layered defense. By pairing known-content matching with predictive visual AI, platforms can analyze deep visual signals at upload, categorize unseen threats by severity in real time, and route high-harm files away from internal workforces to specialized review teams.
How does modern CSAM detection work?
Effective CSAM detection now requires a multi-layered strategy because no single technology can identify every form of harmful content.
For most mature Trust & Safety programs, detection begins at upload by automatically checking incoming images against databases of known CSAM using hash matching. However, automated hash matching is not an out-of-the-box feature of standard web infrastructure. It requires a platform to actively integrate third-party APIs and hash feeds—such as with NCMEC, the Internet Watch Foundation (IWF), or specialized hashing tools. Platforms that lack these API integrations or vetting credentials cannot perform automated hash lookups, leaving them reliant on manual user reports.
Furthermore, even for platforms with full access to global hash databases, hash matching only solves half the problem. When a user uploads novel, modified, or AI-generated material, no reference hash exists to trigger an alert. In these scenarios, platforms need predictive visual AI and image classification technology to assess whether previously unseen content presents a risk before it propagates across the service.
How a layered detection and prediction approach works
| Step | Purpose |
|
Known-content detection |
Uploaded images are matched against databases of previously confirmed CSAM using hash-matching technologies. When a known match is identified, platforms can respond according to their policies and legal obligations. |
|
Unknown-content prediction & severity classification |
If no known match is found, image classification technologies can analyze the visual characteristics of the content to assess whether it may contain previously unseen, modified, or AI-generated CSAM. |
|
Classification outputs |
The classifier returns probability and confidence signals that help the platform assess potential risk and determine how the content should be handled. |
|
Platform decision |
Organizations apply their own thresholds, policies, and operational workflows to determine whether content should be escalated, reviewed, or otherwise processed. |
Hash matching and image classification solve different problems.
- Hash matching answers the question, “Have we identified this content before?” It is highly effective for detecting previously confirmed CSAM but depends on an existing reference database.
- Image classification addresses a different challenge. Rather than looking for a known digital fingerprint, it analyzes the content of an image and returns signals that help platforms assess material that has not previously been identified or cataloged.
For many organizations, these approaches work together. Hash matching provides fast, reliable detection of known CSAM, while image prediction and classification extends coverage to previously unseen content that would otherwise receive no match. Together, they provide a more complete approach to CSAM risk mitigation than either method alone.
Resolver’s Athena offers a full layered approach as a managed service. Athena is Resolver’s real-time CSAM prediction and severity classification service, powered by Roke’s Vigil AI Classifier. It combines known-content hash matching with risk prediction of novel content, alongside image classification, enabling severity triaging to help platforms assess potential CSAM at the point of upload, including material that has no existing hash reference.
Trust & Safety leads are often hesitant to adopt AI classification because of latency issues or fears of holding sensitive user content.
- Sub-150ms Latency: Modern visual AI engines analyze image payloads directly at the point of upload, allowing real-time blocking in live feeds or direct messaging without degrading user experience.
- Zero Image Retention: Athena operates under a strict privacy-by-design model. Transactional media is analyzed on the fly and immediately purged—zero user images or metadata are stored on Resolver systems, eliminating data liability.
- Low-latency and high-scale: Modern classification APIs process image payloads at the point of upload with negligible latency, allowing real-time intervention in direct messages or public feeds before content proliferates.
- Privacy by design: Content is deleted immediately after the AI model completes its assessment, retaining zero user metadata beyond volume reporting for billing.
What is unknown CSAM?
Unknown CSAM is child sexual abuse material that has not previously been identified or cataloged in known-content databases. Because no existing hash or reference exists, platforms cannot identify it through hash matching alone and must use additional prediction methods to assess potential risk.
Unknown CSAM is defined by what platforms do not yet know about the content, not how it was created. It may include:
- First-generation abuse material that has never been reported or cataloged.
- Previously unseen content that has no existing hash or digital fingerprint.
- Altered versions of known material that can no longer be reliably matched using existing reference databases.
- Synthetic or AI-generated imagery, which represents one type of previously unseen content but is not the only source of unknown material.
Because this content has not been previously identified, platforms need additional ways to assess potential risk. Depending on the platform’s approach, this may include automated analysis, classification, human review, and structured escalation workflows to determine the appropriate response.
Known vs. unknown CSAM
| Known CSAM | Unknown CSAM |
|
Previously identified and cataloged |
Not previously identified or cataloged |
|
May be detected using known hashes |
Requires additional prediction methods |
|
Supports rapid identification and response |
Requires assessment, classification, and review before appropriate action can be determined |
Why does unknown CSAM matter for platforms?
Unknown CSAM matters because it cannot be identified using known-content databases alone. As previously unseen material becomes more common, platforms need consistent ways to detect, assess, review, and respond to content that has no existing reference. This requires more than detection technology alone. To proactively keep your environments and users safe and compliant, teams need structured operational processes that support..
- Evolving threat vectors: Financial sexual extortion (sextortion), grooming networks, and nudification apps mean that harm moves faster than static database updates. In recent partner testing, 90% of the CSAM identified by Resolver did not match known hash lists.
- Scale and velocity of novel content: Generative AI tools allow bad actors to produce or alter high-quality synthetic abuse material at an unprecedented rate.
- Moderator wellbeing and triage: Unfiltered alerts of unknown material can easily overwhelm human moderation teams. Structured classification (such as triaging into official Severity Categories A, B, and C) ensures high-priority harms are acted on immediately, while protecting staff through appropriate wellbeing measures and automated filters.
- Regulatory compliance and transparency: Emerging global online safety regulations require platforms to demonstrate active risk mitigation and publish transparent reporting on the scale of child abuse content on their services. Missing unknown CSAM creates severe compliance and liability gaps.
For Trust & Safety teams, unknown CSAM introduces challenges that extend beyond identifying harmful content. Teams also need to make consistent decisions, prioritise cases appropriately, and demonstrate how those decisions were reached.
Key considerations include:
- Detection and Prediction: Previously unseen content cannot be identified through hash matching alone, so platforms need additional ways to assess potential risk.
- Prioritization: Not every alert requires the same response. Structured classification helps moderation teams focus specialist review where it is needed most.
- Operational consistency: Clear review and escalation workflows help ensure similar cases are handled consistently across teams and over time.
- Governance: Platforms increasingly need to demonstrate how detection and prediction measures operate in practice, how decisions are documented, and how safety processes are reviewed and improved.
As the volume of previously unseen content grows, effective CSAM deterrence becomes part of a broader Trust & Safety operating model that combines detection, prediction, human expertise, and governance into a consistent, explainable process.
What do platforms need to demonstrate for CSAM compliance?
Effective CSAM disruption depends on far more than deploying a standalone filter. Driven by global regulatory frameworks—such as the UK Online Safety Act (enforced by Ofcom), the EU Digital Services Act (DSA), and US reporting mandates to NCMEC—platforms are increasingly required to prove proactive risk mitigation, operational auditability, and defensible decision-making.
Compliance gaps rarely arise because a platform lacks technology. Instead, gaps occur when detection, prediction, review, law enforcement reporting, and governance operate as disconnected silos. Regulators expect platforms to demonstrate not just that action was taken, but how and why those decisions were made.
To satisfy evolving regulatory standards and maintain operational integrity, mature Trust & Safety programs must demonstrate several core capabilities:
| Capability | What platforms should be able to demonstrate | Operational & regulatory impact |
|
Risk assessment |
Where CSAM-related risks exist and how they are evaluated. |
Establishes a defensible, risk-based safety architecture required by regulators. |
|
Detection & Prediction coverage |
How known and previously unseen content is identified and assessed. |
Eliminates the “unknown CSAM” blindspot before content proliferates. |
|
Calibrated Severity Triage (A/B/C) |
Categorizing flags by legal severity frameworks (e.g, UK Categories A, B, and C) rather than simple binary alerts. |
Prioritizes high-harm, Category A abuse for immediate action rather than managing alerts in a chronological queue. |
|
Decision processes |
How outputs are assessed and how decisions are reviewed, escalated, and acted upon. |
Prevents uncalibrated AI from flooding queues with false positives while ensuring high-confidence hits meet reporting deadlines. |
|
Records and evidence |
Documented evidence showing what actions were taken, why thresholds were set, and how edge cases were resolved. |
Provides complete legal transparency during regulatory audits or law enforcement inquiries. |
This reflects a fundamental shift in global online safety. Regulators no longer evaluate platforms on whether they checked a database box. Increasingly, compliance requires demonstrating that your Trust & Safety program is risk-based, scalable, and capable of isolating high-severity harms in real time without overwhelming internal teams or law enforcement networks.
What do platforms need to demonstrate for CSAM compliance?
A mature counter-CSAM program proactively combines effective detection and prediction capabilities with structured operational processes. Rather than relying on a single technology, mature programs continuously assess risk, evaluate the effectiveness of safety measures, document decisions, and maintain governance that demonstrates how risks are managed over time.
While every platform’s approach will differ, mature counter-CSAM programs typically share several characteristics:
| Characteristic | Why it matters |
|
Evidence-based risk assessment |
Detection and prediction strategies are informed by documented evidence, internal data, and relevant external intelligence rather than assumptions alone. |
|
Layered detection and prediction capabilities |
Hash matching, unknown-content discovery and severity classification, and supporting operational controls work together to address different types of CSAM-related risk. |
|
Demonstrated control effectiveness |
Safety measures are regularly reviewed to understand whether they continue to reduce risk as intended. |
|
Governance and accountability |
Roles, responsibilities, and oversight are clearly defined so risk management activities can be carried out consistently. |
|
Continuous review and record keeping |
Risk assessments, decisions, and supporting evidence are documented and updated as services and risks evolve. |
Maturity also depends on how well these components connect. Alerts, specialist assessment, reporting decisions, and governance records should form a traceable process rather than operating as isolated activities.
As online harms continue to evolve, mature programs treat CSAM prediction as an ongoing operational capability rather than a standalone technology or annual compliance exercise.
How does Resolver’s Athena support a structured CSAM detection and prediction approach?
Athena extends traditional safety stacks by analyzing deep visual signals and returning real-time risk classification outputs for previously unseen content. Rather than replacing existing systems or acting as a rigid “black box,” Athena provides flexible data outputs that platforms integrate directly into their operational policies, review queues, and enforcement workflows.
Powered by Roke’s Vigil AI Classifier, Athena is trained directly on legally held law enforcement datasets from the UK’s Child Abuse Imagery Database (CAID). To prevent reviewer burnout and false alarms, the model is rigorously calibrated against licensed adult datasets, ensuring high precision between legal adult content and CSAM. Furthermore, unlike “fire-and-forget” models, Athena undergoes continuous retraining in secure laboratory environments to stay ahead of novel synthetic threats and model drift.
When Athena analyzes an image, it returns multiple outputs that support operational decision-making:
| Athena output | What it delivers | How platforms use it |
|
Category scores |
Evaluates content across official legal severity tiers (Categories A, B, and C) alongside “Indicative” grooming signals. |
Prioritizes immediate, high-harm Category A evidence for instant escalation rather than reviewing alerts chronologically. |
|
PCSAM |
Combines signals into a single probability score of CSAM risk. |
Gives engineering teams a simple, configurable threshold to automate blocks or account suspensions. |
|
Model Confidence Rating |
Measures AI classification certainty (Entropy). |
Streamlines triage by auto-actioning high-confidence flags while isolating borderline cases for human review. |
|
Modular & End-to-End Deployment |
Deployable as a lightweight API or a fully managed 24/7 review service. |
Integrates flexibly into existing infrastructure or routes traumatic review queues entirely to Resolver’s specialist analysts. |
Platforms retain full control over how these outputs are actioned. During evaluation and live deployment, organizations configure sensitivity thresholds that align with their specific risk tolerance, moderation capacity, and legal obligations. Whether used as a modular API addition to augment internal tools or paired with Resolver’s 24/7 specialist analysts for managed review, Athena ensures your platform maintains a defensible, continuous standard of care.
Extend CSAM prevention beyond hash matching
Hash matching remains an essential foundation for identifying known CSAM, while image classification extends detection to prediction of previously unseen content. Together, these capabilities provide broader visibility.
As online harms continue to evolve in novel ways, detection and prediction alone is only part of the challenge. Platforms and online services also need operational processes that allow them to assess classification outputs, apply policies consistently, document decisions, and demonstrate how risk is managed over time. The question is no longer simply whether harmful content can be detected, but whether organizations can respond in a way that is scalable, consistent, and defensible.
Resolver’s Athena has been specially designed to support that broader operational model. Powered by Roke’s Vigil AI Classifier, and trained on the UK’s Child Abuse Imagery Database (CAID), Athena combines known-content hash matching with image classification and integrates those outputs into existing Trust & Safety workflows, helping organizations extend detection to risk prediction while maintaining oversight and control.
Don’t let first-generation or AI-generated CSAM slip through your upload filters. See how Resolver’s Athena combines known-content matching with law-enforcement-trained visual AI to provide sub-150ms, zero-retention protection.
For a more detailed explanation of how defensible CSAM detection is implemented in practice, see the Athena service overview.
About the author: Frances McAuley is Director of Product in Resolver’s Trust & Safety Division, where she leads the development of intelligence‑led capabilities supporting regulated platforms across online safety, compliance, and enforcement.