Field Dispatch

The Encryption Tradeoff: 36.2 Million Reports and the Hardest Question

36.2 million CSAM reports. Apple tried to build a scanner and killed it. Signal threatened to leave the UK. The genuine, irreducible tradeoff that makes the ratchet thesis hardest to argue.

2026-06-12 10 min read Dispatches
Contents

The National Center for Missing and Exploited Children’s CyberTipline received 36.2 million reports of child sexual abuse material in 2023. Thirty-six point two million. Each report represents an image, a video, or a series of images depicting the sexual abuse of a child.

The detection systems (PhotoDNA hash matching developed by Microsoft, AI-based classifiers, proactive scanning of uploaded content) are the only mechanism operating at a scale commensurate with the problem. Law enforcement cannot manually review 36.2 million reports. The automated detection infrastructure is the minimum viable response.

End-to-end encryption is eliminating it.


The Numbers

Meta accounted for roughly eighty-five to ninety percent of NCMEC reports in 2023. Messenger was the largest single source. In December 2023, Meta rolled out default end-to-end encryption on Messenger and Facebook direct messages. The UK’s National Crime Agency estimated, in advance of the rollout, that approximately eighty-five percent of Meta’s child abuse tips could be lost.

The estimate was approximately right.

In 2024, NCMEC’s CyberTipline received 20.5 million reports. A nineteen percent drop from the 2023 record. NCMEC and NBC News attributed the decline directly to Meta’s encryption rollout. The encryption made scanning impossible on the largest single source of reports. The number went down. The abuse did not.

Simultaneously, Thorn’s analysis of the same 2024 NCMEC data found that reports of AI-generated CSAM rose from approximately 4,700 in 2023 to 67,000 in 2024. A 1,325 percent increase in a single year. The detection infrastructure is being hollowed out from one direction by encryption while being overwhelmed from another direction by generative AI. The system built to address the problem is falling behind the problem it was built to address.

The encryption advocates and the child safety advocates are looking at the same numbers and drawing opposite conclusions. They are both right.

Apple’s Scanner

In August 2021, Apple announced NeuralHash. A client-side scanning system that would check images on user devices against the NCMEC hash database before they were uploaded to iCloud. The technical architecture was carefully designed. The scanning happened on the device, not in the cloud. The hash comparison was performed locally. Apple’s servers would only receive a match notification if multiple matches accumulated against a single account, at which point Apple would conduct human review before referring to NCMEC.

The system would not, Apple argued, compromise end-to-end encryption. The scanning happened before encryption, on the user’s own hardware, against a narrowly scoped set of known CSAM hashes.

The response was immediate and overwhelming. Ninety-plus organizations in twenty-five-plus countries signed letters opposing the system. The Electronic Frontier Foundation, the ACLU, the German Society for Civil Rights, Privacy International, Reporters Without Borders. The entire international digital rights ecosystem coordinated against the rollout. The technical objection was that hash collisions could be engineered. Within weeks of the announcement, researchers had demonstrated collisions: distinct images that produced the same NeuralHash. The system could be fooled, and worse, could be weaponized. An adversary could send innocuous-looking content that matched CSAM hashes, generating false positives that would trigger account review.

The architectural objection was more fundamental. The scanning capability was technical, not legal. Today the hash database covers CSAM. Tomorrow a court order or a quiet regulatory request expands it to include terrorism content. Next year, copyright-infringing material. The year after that, content a government deems harmful to national security. The capability cannot be limited to one category by policy because the capability is not category-aware. The same scanner that detects CSAM detects whatever is in the hash database.

Apple killed NeuralHash in December 2022. The company’s statement was striking for an institution that had spent fifteen months defending the system: “Scanning every user’s privately stored iCloud data would create new threat vectors for data thieves to find and exploit… It would also inject the potential for a slippery slope of unintended consequences. Scanning for one type of content, for instance, opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems across content types.”

Apple, of all institutions, concluded that the surveillance capability built for child safety would, by its own architectural nature, become a surveillance capability for anything.

The UK Online Safety Act

The United Kingdom passed the Online Safety Act in 2023. Section 122 granted Ofcom the power to require platforms to use “accredited technology” to scan encrypted communications for CSAM.

There is no accredited technology. There is no technology that can scan end-to-end encrypted content without breaking the encryption. The bill text required Ofcom to mandate something that does not technically exist.

Signal’s response was published before the bill became law. The company’s president, Meredith Whittaker, told the BBC: “We would absolutely 100 percent walk.” Signal would withdraw from the UK market rather than comply with a scanning mandate. WhatsApp’s head Will Cathcart took a similar position: WhatsApp would rather be blocked in the UK than build a backdoor.

In September 2023, the UK government effectively backed down. A minister told the House of Lords that the scanning provisions would not be used until the technology to do them safely existed, which, by every available technical assessment, will never exist. The provision remained in law. Industry observers called it a “zombie provision,” dormant in statute, available for future activation if the political wind changes.

The pattern is the structural finding. The UK government wanted a scanning capability badly enough to legislate for it. The technical infeasibility plus the encrypted-messaging industry’s credible exit threats forced a backdown. The backdown was not the repeal. The provision remains. The next government, or the next high-profile case, could activate it. The infrastructure of the law persists across the political pause.

The Defense

Encryption protects journalists communicating with sources in hostile regimes. It protects dissidents organizing against authoritarian governments. It protects domestic abuse victims communicating with shelters and family members. It protects whistleblowers communicating with lawyers and journalists. It protects healthcare data, financial data, legal communications, and the billions of ordinary people whose private communications have, throughout human history, generally been considered nobody else’s business.

Every surveillance capability built for child safety can be repurposed for political surveillance. This is not a theoretical concern. China’s Great Firewall began as a content filter for pornography and gambling. India’s Aadhaar system, sold as financial inclusion, became infrastructure that denied food rations to families whose biometrics didn’t authenticate. The PATRIOT Act was for terrorism. It was used for drug enforcement. The FISA Court was for foreign intelligence. It approved warrantless surveillance of American citizens at a 99.97 percent approval rate.

Apple concluded the same. Their public statement was not the position of a privacy advocate. It was the position of the most security-engineering-capable company on earth, with fifteen months of internal engineering work behind the conclusion that the scanning architecture could not be safely constrained to its stated purpose. They built it, they tested it, they killed it, and they wrote down why.

The architecture does not know the difference between a CSAM hash and a political-dissent hash. The architecture sees a hash. The category is supplied by whoever maintains the hash database. The maintainer is, in every implementation, accountable to a government. The government can change the contents of the database. The user cannot inspect what is in the database. The scanning happens on the user’s device, against a list the user cannot see, controlled by a party the user cannot audit.

This is not the same as the warrant process. A warrant requires a specific target, specific evidence, a judge’s signature, and a defined scope. Client-side scanning is a general capability operating on every device in the population, against a list of arbitrary length, with no per-device judicial oversight. It is the digital equivalent of having a government employee inside every house, with a list of things to look for, and the contents of the list classified.

The Prosecution

Thirty-six point two million reports in a single year. Twenty point five million in 2024. The decline was not because the abuse declined. The decline was because encryption made it invisible.

The children depicted in the images are not abstractions. Each report is a child. The detection systems are how the children get identified, how the offenders get prosecuted, how the abuse networks get mapped, and how survivors get connected to recovery resources. The pipeline that NCMEC and the law enforcement coordination it supplies depends on is the largest child protection infrastructure in human history. Encryption is dismantling it on a calendar visible in NCMEC’s own annual reporting.

Thorn’s AI-generated CSAM number (67,000 reports in 2024, up from 4,700 in 2023) is the other side of the same problem. The technology that creates the abuse is scaling faster than the technology that detects it. The infrastructure between the abuse and the detection is being removed.

Anyone who argues for end-to-end encryption without addressing the 36.2 million number is not engaging with the documented consequence. The argument is not whether the children matter. The argument is whether breaking encryption for everyone, to protect the children that the encryption is currently making invisible, is the correct response. The argument is what is technically possible. The argument is what gets retasked once it exists.

The Honest Framing

The correct response is not weakening encryption. The architecture of the surveillance capability cannot be safely constrained, and Apple’s reversal is the strongest available evidence that the most resource-rich actor in the field concluded the same after building the system and testing it.

The correct response is investing in other investigative methods. Behavioral detection at the metadata layer, which does not require content access. Financial tracing of payment flows that fund abuse networks. Undercover operations against the production-and-distribution networks that produce the content in the first place. Victim-centric approaches that work backward from identified survivors to identified abusers. None of these scales the way automated scanning scales. All of them are how every other class of serious crime is investigated.

The UK’s capitulation suggests even governments recognize, when forced to confront the technical reality, that they cannot mandate scanning without breaking security for everyone. The zombie provision is the political compromise. The capability is preserved on paper, the activation is deferred until the technology exists, the technology does not exist, the provision sits in law as a future option.

The technical infeasibility argument is the load-bearing one. The privacy argument and the human-rights argument can be debated. The technical argument is whether the architecture, once built, can be confined to its stated purpose. The answer from Apple, from Signal, from WhatsApp, from the entire cryptographic engineering community is the same answer: no, it cannot.

For the Book

This is the counter-argument at its strongest. The ratchet thesis says safety infrastructure becomes control infrastructure. The encryption tradeoff asks: what if not building the infrastructure has a body count?

Both halves are true. The infrastructure becomes control infrastructure, Apple said so. The non-infrastructure has a body count, NCMEC said so. There is no third option that resolves the contradiction at the technical layer. There are only the second-best mitigations: invest in non-content methods, fund victim-centric response, prosecute the production networks at scale, accept that the encryption-mediated portion of the pipeline will be opaque, and refuse to mandate scanning architectures that cannot be safely constrained.

The reason the encryption tradeoff is the hardest case for the ratchet thesis is that the stated harm is unambiguous. Other safety arguments (for content moderation, for vehicle surveillance, for digital ID, for AI governance) have stated harms that the reader can debate. The harm in the encryption case is documented at the scale of tens of millions of NCMEC reports per year, attached to children whose abuse is not a policy abstraction.

The infrastructure-cost case is equally documented. NeuralHash. The UK zombie provision. The technical assessments by every cryptographic engineering body on earth. The historical record of every general-purpose scanning architecture that has ever been built getting retasked to whatever the current political pressure was.


The honest position is that both arguments are correct, the technical architecture forces a choice, and the choice has casualties on both sides. Anyone selling a third option is selling either bad cryptography or worse policy.

The receipts (free, on this site): NSA / Five Eyes surveillance · the digital-ID stack

This research appears in The Ratchet, Chapter 21.

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.