top of page

Show Notes 221: The Internet Watch Foundation. Safety by Design: How Tech Can Protect Children Online

11 minutes ago
19 min read




What should founders build into their products before the first user signs up?


In this vital episode of the Cambridge Tech Podcast, hosts Faye Holland and James Parton speak with Emma Hardy, Communications Director at the Internet Watch Foundation, about the fast moving fight to prevent child sexual abuse online.


Emma brings a clear message for founders, investors and product leaders: safety cannot be an afterthought. From generative AI to user generated content, every new capability can create opportunities for harm as well as value. The strongest companies consider both from day one.


The Internet Watch Foundation, or IWF, is a UK charity that identifies and works to remove online child sexual abuse imagery. Its teams combine specialist human judgement with technical tools, intelligence and partnerships across industry, government, law enforcement and academia. Emma explains how digital fingerprints, known as hashes, can help prevent previously identified imagery from being uploaded again on participating platforms.


AI is changing the threat landscape at pace. Emma describes how offenders adopt emerging technology quickly, including tools that generate realistic abusive imagery. While automation can help detect and prioritise content, human expertise remains essential when assessing new material, identifying contextual clues and building intelligence that can help protect a child.


For startups, the practical takeaway is simple: build safety into the product, the business model and the operating culture. Emma encourages teams to examine how an idea could be misused before it reaches scale, rather than attempting to retrofit protections after harm has occurred. The IWF can support organisations, particularly those handling user generated content, with expertise and services designed to make platforms safer.


"Build it safe from the start. Don’t try and retrofit safety."

Key points

  • The IWF marks 30 years of work tackling online child sexual abuse imagery.

  • Its global membership includes more than 230 technology companies.

  • Hashing helps platforms block known illegal imagery before it can be uploaded again.

  • Human analysts remain central to assessing new content and supporting victim identification work.

  • AI generated imagery is increasing the urgency of robust safeguards, testing and regulation.

  • Report Remove, delivered with Childline, helps under 18s report sexual images or videos of themselves for removal or prevention of sharing.

  • Founders should explore Safety by Design resources and engage specialist partners early.


This is an essential listen for anyone building, backing or governing technology. Subscribe to the Cambridge Tech Podcast for candid conversations with the people shaping safer, smarter innovation across the UK tech ecosystem.


Subscribe to the Cambridge Tech Podcast to stay close to the people, ideas and opportunities moving the ecosystem forward.


Produced by Joe Donaghy of Cambridge TV. Supported by media partner Business Weekly.


Subscribe on all major podcast platforms or visit cambridgetechpodcast.com. 🎧



Episode Transcript


Welcome to the Cambridge Tech Podcast. Talking all things technology from the heart of the UK's tech capital. Here are your hosts, Fay Holland and James Parton. I'm Fay. And I'm James. Joining us today is Emma Hardy, who is the Communications Director for the Internet Watch Foundation. And just a quick heads up to all of our listeners, we are going to be covering some very difficult issues today, specifically the issue around child sexual abuse on the internet, which some listeners might find triggering.


Emma, thanks for taking the time to join us today. We always like to get to know our guests, so could you just give us a little introduction to your background? I'd be delighted to.


Thank you very much for having me on the podcast today. My name is Emma Hardy and I'm a communications director at the Internet Watch Foundation and also a co-director at the UK Safer Internet Centre. And I guess if I was talking about my background, it starts with journalism, meanders then into PR and communications in the public sector and a very long stint at this most wonderful organisation called the Internet Watch Foundation. It's a charity. It works incredibly closely with tech companies, with governments all over the world, with regulators, the third sector and academia as well. And we identify and we remove images and videos that show the sexual abuse and exploitation of children on the Internet. So it's a very...


Serious subject matter, but for such a serious subject matter, it's a very happy place to work. And I get to work with some of the most incredible people, thoughtful, compassionate people that I think I've ever met. That's amazing.


And that's probably why you've been there for 15 years, right?


Yeah. It's an incredibly long time and I pinch myself because it doesn't seem like that. The IWF, when I joined it, it was 15 people and it was working out of a townhouse in Oakington, which is not far from the Science Park in Cambridge. And it was there because the founder of the IWF, a local man, that was his townhouse and he put that forward as a place for IWF as a base to start from. But since I've been there, the IWF has grown incredibly. We moved to a business park at Waterbeach. And then in Histon, and now we're on Cambridge Science Park. And every time we've moved offices, I've thought, gosh, we're never going to fill this place. This is enormous. And then lo and behold, averaging about three or four years later, we're going, we need to find new premises. Where do we go now? What do we need? I think the home at the Science Park is incredible because we're surrounded by other companies and organisations doing really important work in technology and science. It feels like a wonderfully natural home. And also we've had the ability to be able to tailor and bespoke our building just as we need it to be because the people who work at IWF have the legal ability to be able to actively search for child sexual abuse on the internet, which is something that if any ordinary person did as a strict liability offence, it's basically straight to jail. But they have this carve out and we need to create the right conditions and the right environment for them. And also the security aspects of it are incredibly important. And our home on the science park has provided all of those aspects for us and more.


So you mentioned it's the 30th anniversary this year. I guess my first kind of question is 30 years is a long time. So how does the organisation deal? just keep pace with the rate of change and the technologies that you're now having to deal with, like social media, blockchain, AI, all of these things that didn't exist 30 years ago. It seems quite incredible to think that child sexual abuse on the Internet has always been incredibly complex. And I think I've always known and understood that and been talking about that since I started 15 years ago. But it's just incredible at the place we are at now. And it is very hard to keep up with technology. But because we have a membership of more than 230 tech companies all over the world, They're a massive support to us. We can reach out to them. We speak to them regularly to understand what's going on, what the new frontiers are. We also work really closely with lots of others across this sector as well in roundtables and convenings and forums all over the world. But the fact of the matter is we have a team of people who sit at the front line of child sexual abuse and they visit places on the internet that you or I would never particularly be aware of existed. And they see the conversations unfolding in these forums, particularly on the dark web, for example. We'll take the example of AI. Quite a few years ago now, but maybe only four years ago now, it was starting to be really talked about in terms of its ability to generate information images, maybe one day it will be really good at generating videos. And we started to see that coming through in terms of the abuse that we witness on the internet. We have always seen how offenders and people who want to sexually abuse and exploit and potentially commercialize the abuse of children, they will be the first to adopt new technology. That has always been the case and it's always been really clear to us. So when AI and anything else comes along that's new on the horizon, we start to see people bragging about how they've used this technology to do this, do that. We've seen reams of pages on forums dedicated to sharing information about how you get your prompt just right and exactly what model you need to use. To be able to generate lifelike pictures of children being sexually abused. We saw that happening. So being the organization that we are, we start cataloging it, we build evidence, we do some research, we publish. We're now on our third report into how AI is being used and abused by people who either have a sexual interest in children or certainly have an interest in making money off people who have a sexual interest in children. And we have just cataloged how technology is getting better and better at such an alarming rate. It used to be very easy for us to spot when an image was AI generated and it's not anymore. And also what can be done about it. And it doesn't necessarily always mean the tech company has to build it better and safer, although that is the case. It's also about what regulation do we need to be thinking about, what policy aspects we need to be thinking about, and how do we engage with these companies so that they can think, actually, I'm building this amazing tech over here, but let's really think through what that looks like if it's going to be abused by anybody. And I guarantee you, if it has potential... To be abused by people who are interested in the sexual abuse of children. It will be and we will see it first.


You said there are like 230 technology companies that are your members. Are they the technology companies that are developing technology and want it therefore to be not misused and to do the best that they can? Or are they tech companies that don't want this to happen and want to work with you and support you as an organization? What's that balance? What's the difference?


I like to believe that every company that works with IWF is doing so because they really do care about preventing and stopping the sexual exploitation of children or in and around that. So it might be that they want to make their product safer, a platform safer for children or for anybody, or they might want to ensure that they are doing everything they can, that they do not appeal to people who want to be abusing the technology. Whether the degree of success in that area differs because it depends very much. Every platform is so different. So I'll give you an example and also it will reveal a little bit more about the work that IWF does. So when our analysts who are sitting in this lovely bright area office in Cambridge are doing their work, they are searching for child sexual abuse material and taking reports from the public and from the police and from other tech companies. It all comes into us. They will assess the image or video in front of them. They will assess it against UK law. So what category of abuse is it? How old is the child? And they will gather huge amounts of data about every single one of those instances. So from the hosting provider right the way through to what evidence is in there that this is a new child and it's happening recently and is it in the UK? And they're building victim identification cases that can be sent over to the National Crime Agency as well. So they do a whole amount of work. That data and intelligence is distills into services and data sets that we offer back out to tech companies. The point of that is we can stop that image that we've just found, which we've never seen before, from being re-uploaded on the internet through these data sets and services. I always pick on Facebook as an example, but it's just an example because lots of people, everyone's had a Facebook account. So we create a list of hashes. So that is the digital fingerprint of child sexual abuse. And we create it in lots of different algorithms. And we push it out to the members that we work with whose platforms can make use of that. And what that means is that incident of child sexual abuse, an image or a video, it will be prevented from being uploaded to Facebook or whatever platform if somebody else tries to do that because we've created that digital fingerprint. Those companies, they work with us. We provide them in return services and data sets that can keep their platforms and services safer, keep their users safer. It doesn't necessarily mean they're doing all they can because we see how actually tech companies could be designing safer services in the first place. And I think this really speaks to the fact that there are some great ideas out there and the most amazing tech development, but there isn't necessarily that stop and pause moment of, or maybe there is, but not that we can see that stop and pause moment of, okay, so how could this be used for nefarious reasons? What would that look like? How do we properly test that? Which brings me back round to AI. The interesting conundrum with AI generated child sexual abuse imagery is how does a tech company know that their product cannot produce child sexual abuse imagery if they're not legally allowed to test it and try and make it happen. We've been really successful in working with the government and influencing the incoming piece of legislation that is going to enable designated bodies like the IWF, is what the press release said, to be able to test upcoming AI models and software to ensure that it cannot produce images and videos depicting the sexual abuse of children. That testing point is absolutely crucial and that's one of the unique abilities, I think, of IWF because we've got all this data, we're legally allowed to hold it. We can train classifiers and other pieces of tech, but we can also hopefully in future do the testing to ensure that product or that model or whatever it is cannot produce that sort of imagery. Technology moves fast, and now so can you. Discover Polestar, the all-electric performance brand vehicles redefining how we drive. Precision engineering, minimalist design, and software that evolves with you. Experience it at Holden Group in Norwich and Bury St Edmunds. Or let us bring the test drive to your door.


Proud sponsors of the Cambridge Tech Podcast. Polestar, electric performance redefined. Discover at holdengroup.co.uk slash polestar.


When you talked about the challenges of keeping up with the pace of change and the new challenges that technologies like AI are presenting, I assume that there's the positive side of that as well, that you're able to use now AI and other tools to actually help combat the production and distribution of this kind of content. Is that true? Are you able to use AI to supplement your human resource, to do more searches, to do more categorization of images? Is that a development that you're leading inside IWF?


When we see an image or video of child sexual abuse that we have not seen previously, it will always get human eyes on. That's the unique thing about IWF. We will have human eyes that will determine ultimately the grading of that image according to UK law. It's incredibly important that we keep really high level of confidence there. I wouldn't necessarily categorise it as AI supporting us, but technology certainly does support us. So where we build huge data sets, and we train classifiers, that is going to help us find more imagery. We have crawlers as well. We work with other hotlines around the world that also very successfully deploy crawlers that are going to places and they know what they're looking for in terms of this type of imagery to bring it back. As far as we're concerned right now, everything will receive a human eye where it's new, but where we've seen an image previously, and this is quite a hard thing to talk about or hear if it's not something you ever think about, but we see a huge quantity of repeatedly shared imagery. So the same image, the same child or children over and over again. We also have this team of human beings in Cambridge that do this work. And if we can prevent them seeing the same images over and over again, technology is already built. Before AI came down the road, there's already technology to stop that happening. We just simply match the hash. Hash an image. Does it match already? Yes, we've seen it. Yes, we've given it this grading. Great. That doesn't need to go anywhere near our analyst's eyes again because we have to really think about their welfare. But particularly where we are looking at a brand new image that we haven't seen before. And let's just say it's an image of a victim we haven't seen before. And there are clues in the imagery that only humans can pick out. Does that look like a room in the UK? There are tells. There are things that tell us where in the world this child might be. If we're building an intelligence package that we want to send off to the police to enable a child to be rescued from this situation, I can't do all that yet. Maybe, maybe one day it could. But we need that human to make that judgment, to build that package, to send it off. To the police so that they can do some of the rescuing of that child. So we are looking at how technology can help us, but it will supplement that really important investigatory piece that we still need, that we still definitely need humans for. You have that investigatory work that is key to what you're actually doing. You've given us a few examples of that. What other areas do you work in?


So you said that you've worked with government, so there's policy work. There's actually educating people and bringing this to other people's awareness and attention.


What are those different roles that IWF takes on?


The IWF takes on a huge amount surrounding its core work of finding and removing child sexual abuse. And just to give you a few examples of that, we have a policy team. And what we're aiming to do is to help governments. Civil service we're working with regulators around the world we're doing a lot of work at the moment in europe to try and help lawmakers build good laws and legislation that are ultimately going to protect children keep them safer stop the abuse from happening in an ideal world much of our work comes in after the child has been abused and after the image is shared on the internet We would ideally like to see that the abuse just cannot happen in the first place, that actually really good laws and policies are made and that the tech companies come along with us to build really safe platforms so that a child cannot be abused online in the first place. So we do a huge amount on the policy front. Right now, we have just actually this week launched a campaign, an advocacy campaign across various member states in the EU because there's a really important piece of legislation, which is in its final discussion stage. It's the Child Sexual Abuse Regulation. It could offer us strong and harmonized laws around how to prevent, find, deal with child sexual abuse imagery online. It's had a rocky road, but our campaigning work, our advocacy work, we're really hoping to support policymakers in understanding this area and then voting in a way that means that we get really good laws to protect children. So that's an example of what we do on the policy front. On the education front, for many years now, we've been really successful with mounting campaigns, particularly in the UK. That have been award-winning actually and then other countries have come and they've used them in their own territories so in Brazil for example in Hungary in other places which is all about reaching children and young people and parents and carers and then educators to help them have greater awareness of the risks online particularly of grooming behavior predatory behavior And how to talk about this. So as a parent, how do you go about having a conversation with your child about how to be safe online and what that grooming and predatory behavior might be? There's certain words you will and won't want to use with that child. Unfortunately, or fortunately, depending on how you look at it, because again, we're at the front line of seeing this, children aged seven to 10 are at so much risk of of being groomed. We see them so often in the images and videos that we find. They have been the fastest growing set, but children aged 11 to 13 are always the greatest in number in the reports that we see. If you are not having conversations, sensible age appropriate conversations with your child at seven years old and you're leaving it till they're 14, that's too late. You've already missed out on all those years where we see that children are being groomed, deceived, extorted, coerced, manipulated, encouraged online into some kind of sexual activity, which is often over a webcam. Or a phone or a device. And it typically happens when the child is alone in their bedroom or bathroom. So if we can try and get some helpful messages out to parents and carers, which are horrible and scary to hear, but could prompt a conversation or maybe different ways in which tech is actually used in the house. And that keeps that child safe, then oh my gosh, we should do that because we're seeing the output come through to us in our hotline. So we've run campaigns over a number of years now and we also co-create resources for parents and for teachers and educators with the National Crime Agency. There's an area of work where they have a whole educational arm to what they do. So our latest resources have been on AI. It's the topic, isn't it, at the moment?


It has been the topic for a while. But breaking that down for parents, what that is and what might be the risks. Also for schools, we have seen how class photos have been ripped from school websites. Children have been nudified using technology. And then somebody has gone back to the school to blackmail the school and say, unless you pay up, we are going to publish naked pictures of your school children. They weren't naked when the pictures were taken, but AI has made it that you can nudify children. You can nudify anyone, particularly women and girls. So before we move on, this is such an important topic. Where are those for parents listening to this? Where are those resources in terms of signposting those for people? You know, that's excellent, isn't it? Because I'm talking about all this harm and yet, yes, people are going to go, oh, my God, how can I find out more? What are these conversations? If you go to iwf.org.uk, there is a section right at the top that says resources and you can find the resources there on AI. But also if you go to the About Us and Campaigns tab, it will take you through to all the campaigns that we're running. Think before you share. It won an award last week, actually, the Third Sector Best Campaign of the Year Award. It just photographs fruit, but fruit that looks rather rude. And it was aimed at teenagers. And of course, if you use humour, this is what's been the trick over the years, use humour. To get something spoken about and get awareness of something that is really rather serious and horrible. So the Think Before You Share campaign is there. And you can, if you go to iwf.org.uk, go to the campaigns area, you can find your way there. And there's a whole section for parents and carers, a whole section for teachers and educators with lesson plans and PowerPoints. And there's importantly a section for teenagers that shows them what they can do. And on that point, if you are a parent, a carer, an auntie, an uncle, a nan, a granddad, whatever, you need to know about report remove. So report remove is this fantastic jewel in the crown of IWF. We have set up with Childline, NSPCC's Childline, in 2021, the ability for children to report nude and sexual imagery of themselves. This is important because the IWF deals with already published sexual images of children on the internet. This service gives children the ability to report that image or video through to us in a really safe way where Childline can wrap the blanket of care around them. And we will assess the image or video against UK law, as we usually do, and we can create a pre-emptive hash of that image. So that's a digital fingerprint. It goes on our list. It means that if anyone tries to upload that image or video that isn't yet uploaded, they then if it's on one of the platforms that work with us, then that image will be prevented from ever going online. If the image already is online, then the child can just report to us that web address, the URL, and we will work in our usual way. We'll get it taken down from the internet by working with that platform or the hosting provider. So report removed. And all you have to do... Is A, know about it, B, Google report remove, and I promise you it will come straight up. So if you're a parent listening to this, you're more likely to be a parent than you are a children or young person, I imagine, then you need to make sure that the young people in your life know about it and they tell their friends. And we are receiving so many reports from young people every day, rather sadly, but also wonderfully that we've got this service because we're about one of only a couple of countries in the world that actually has such a service available for children to be able to use.


Thanks so much for sharing that. You mentioned our audience. Obviously, the name of the podcast kind of hints towards the fact that our listeners are working in technology in the tech sector, both in the UK and internationally. So if we can just draw the conversation to a close around, what would your... Advice or your guidance be to someone that's thinking about building a new technology or a new startup? Where can they go for best practice? What are your kind of top tips of the kinds of things they should be considering?


I would say that step where you stop and breathe and wonder, how could this be used nefariously? Let's just think that through is ever more important. Safety by design. Google safety by design or Bing it or whatever your search engine of choice is. And there will be a lot of literature and guides that come up created, for example, by the Australian East Safety Commissioner. They've done a lot of work around this, for example, and others. Build it safe from the start. Don't try and retrofit safety because ultimately your users don't deserve retrofitted safety and certainly children don't deserve that. Build it safe from the start. And also come and talk to us because there are ways that we're able to help and support, particularly if your idea takes user-generated content. There are free services that we offer for startups. Go again to iwf.org.uk. You can go to our website, but we're on the science park. So just literally come and knock on our door. You could just do that, knock on our door the old fashioned way. Or you can send us an email or whatever. Come and talk to us about your idea. And we could help suggest ways in which your product or service idea might be abused in future because we've worked with loads of companies. And don't worry about it. Like deal with it up front. Don't wait until it becomes a problem because it could really become a problem.


Yeah, Emma, I have to say thank you. It's a really tough subject. It's a very emotional subject as well. So I would say a huge thanks to those lists and the work that they do. Thank goodness that people are able and willing to do that role. And I think it's so important to keep bringing attention to it. And you've been doing it for 30 years. And let's ensure that you continue to keep doing that. And personally, it has been a very articulate and considered and informative conversation. So thank you for that level of clarity. And you've just said your door is open. For advice, for help and for support to ensure that you can keep doing what you're doing. So thank you very much for being with us today. And just remind everyone where to go to for more information. It's iwf.org.uk. Brilliant. Thank you, Emma. Thanks for having me.


Today's show was produced by Joe Donaghy of Cambridge TV and supported by our media partner, Business Weekly. The Cambridge Tech Podcast is available on all major podcast platforms and on cambridgetechpodcast.com. If you've enjoyed this podcast, please give it a five-star review. It'll really help others discover the show. If you enjoy hearing about technology and innovation in Cambridge, try Oxford Plus. I'm Susanna Diaga, host, and I talk to founders about their journeys, investors about what they look for, and policymakers about how we can bring more capital into UK innovation so that companies can stay and scale here.


My guests include Lord William Hague, Herman Hauser, and Lisa Flashner from the Ellison Institute of Technology. From founder stories to pension capital and public markets, Oxford Plus is Oxford-based, but relevant to everyone growing, funding, or shaping UK innovation.


Proud sponsors of the Cambridge Tech Podcast. Polestar, electric performance redefined. Discover at holdengroup.co.uk slash polestar.



To listen and subscribe, search for ‘Cambridge Tech Podcast’ on your favourite podcasting platform or visit cambridgetechpodcast.com.


Cambridge Tech Podcast Logo in Blue
  • eMail us
  • Follow us on Linked In
  • Follow us on Substack
  • Follow us on Facebook

© James Parton & Faye Holland. All rights reserved.
The CAMBRIDGE word mark is a trade mark of The University of Cambridge and is being used under licence.

bottom of page