
No Bank Left Behind: Why Australia’s Smaller Financial Institutions Are Critical to the Fight Against Child Sexual Exploitation
Behind many cases of child sexual exploitation sits a financial transaction that has passed through an Australian bank.
Since 2022, sextortion investigations alone have led to the closure of thousands of Australian bank accounts, and AUSTRAC received over 450,000 suspicious matter reports in 2025.
While major banks have dedicated financial crime teams and sophisticated technology, regional and customer-owned institutions carry the same obligations sometimes with a fraction of resources, making them at risk for displacement of offenders.
Our new insights paper on the role of smaller financial institutions, is live now. Read it below!
Media enquiries
For media enquiries, please contact press@icmec.org.au
By Dannielle Kelly, Head of Government Affairs and Law Enforcement Outreach, ICMEC Australia
Children experiencing AI-facilitated sexual extortion or solicitation are now more likely to tell an AI chatbot about it than a teacher, a counsellor, the police or a helpline. That is one of the findings from national research ICMEC Australia released last week with the Australian Cybercrime Observatory at the University of Adelaide, which found at least one in twenty-five young Australians under 18 has experienced this kind of abuse. It means AI has become part of how children process what is happening to them, often before any adult knows. Child protection now has to account for this form of disclosure, not just the abuse itself.
A week ago, I was in a boardroom in Sydney with the SaferAI for Children Coalition, the group ICMEC Australia set up two years ago to work through what AI means for children, and what needs to happen so it does more good than harm. Yesterday, being in the audience at the University of Sydney when the Prime Minister announced a new Office of AI, bringing Australia's response to AI under one roof for the first time, felt like things were really coming together.
Those two things are connected. The coordination the Prime Minister described yesterday, one framework instead of a sector-by-sector patchwork, is close to what our coalition has already been building on a smaller scale for two years.
At ICMEC Australia we call this approach sword and shield: use AI as a sword against people who exploit children, and build a shield around children from the risks AI creates on its own. The new Office of AI needs to do both, with a mandate that makes that explicit.
For the sword, that means backing law enforcement to use AI to identify offenders and victims faster, and investing in the tools that let police act on the scale of the problem, not just the visible edge of it. For the shield, it means treating the coalition's two years of groundwork, the nudify app ban, work toward a digital duty of care, and early regulation of AI companion chatbots through the eSafety Commissioner, as a foundation to build on rather than a separate track to coordinate around. It means a child safety lead within the Office of AI with a direct line to that work. The standards, investment settings and guardrails the Office sets need to be tested against what we now know: that for some children, an AI chatbot is the first place they disclose abuse, not the last.
Australia is already a leader in this space. As the Prime Minister pointed out, Australia has done this before with other big technological shifts, from civil aviation in the 1920s to genetics in the 1990s. The social media reforms put this country ahead of the rest of the world, and they happened because parliamentarians from across the political spectrum backed reform when the evidence demanded it. That is the standard the new Office of AI now inherits.
One in four Australians has experienced child sexual abuse in their lifetime (Australian Child Maltreatment Study, 2023), and the horrific childcare cases in the news this week have shown how close that risk sits to ordinary family life. AI does not create that risk. It changes how it plays out, and increasingly, it changes who a child tells first.
Children are in every one of our families and most of our households. The new Office of AI has a genuine chance to get this right from the start, with a coalition, a research base and political support in place. It should not have to start from zero. ICMEC Australia is ready to keep building with it.
About the Author
Dannielle Kelly (Danni) is the Head of Government Affairs and Law Enforcement Outreach at ICMEC Australia, where she leads programs to strengthen how police and governments respond to child exploitation. With more than 17 years of law enforcement experience, including senior roles with the Australian Federal Police and the Australian Centre to Counter Child Exploitation (ACCCE), Danni brings frontline credibility and strategic insight to one of Australia's most critical child protection challenges, ensuring that when families seek help, they are met with a consistent, capable response
Media enquiries
For media enquiries, please contact press@icmec.org.au
AI is now part of how Australian children experience online sexual harm. New research by Adelaide University shows how far it has already reached.
New research from Adelaide University, proudly supported by ICMEC Australia, offers the first national picture of the role artificial intelligence plays in the online sexual victimisation of Australian children. The findings are clear: AI is no longer a risk on the horizon. It is already shaping how young people are harmed, and how they reach out for help.
"This research confirms what frontline services and law enforcement have been warning about. AI is now shaping how children are harmed, and how they reach for help. The reforms of the past year matter, but the response has to move as fast as the technology. That means industry, government and services working together, not in isolation." Colm Gannon, Chief Executive Officer, ICMEC Australia.
Drawing on a nationally representative survey of 1,894 young Australians aged 16 to 18, the study is the first to measure AI's involvement in this form of harm at a population level. It found that AI now features in more than one in four cases of image-based child sexual abuse, that young people are increasingly turning to AI rather than to trusted adults or services when seeking help, and that these experiences extend across social networks and beyond those traditionally considered most at risk.
These findings mark a turning point in how we understand online harm, and they point to a clear need for coordinated action across industry, government, and the services children turn to. Keeping pace with this technology, and protecting the children affected by it, is something no organisation can do alone.
Thank you to Associate Professor Timothy Cubitt, Dr Katie Logos, Professor Russell Brewer of Adelaide University, and Distinguished Professor Ben Mathews of Queensland University of Technology for conducting this important research.

Media enquiries
For media enquiries, please contact press@icmec.org.au
An opinion piece by Colm Gannon, CEO, ICMEC Australia
The release of the ABC’s investigation into AI sexual companion chatbots brings into focus an emerging technology that has, until now, largely operated without meaningful scrutiny. Marketed as tools for companionship, intimacy, or even emotional support, these systems are rapidly gaining traction. Yet their development is increasingly revealing significant gaps in ethical design and regulatory oversight.
It is important to be clear: not all AI companion technologies are inherently harmful. There may be legitimate use cases, including therapeutic applications for individuals experiencing loneliness or social isolation. However, acknowledging potential benefit cannot come at the expense of recognising real and documented risks.
The concern is not simply about how these tools are used; it is about how they are designed. AI sexual companion platforms are built to simulate human relationships, engineered to engage, validate, and sustain emotional connection. These systems operate within a deeply social and psychological space, mimicking intimacy and attachment in ways that traditional software does not.¹
Within this context, the emergence of child-like AI personas represents a critical failure of ethical safeguards. Where systems simulate individuals estimated to represent minors, this is not only morally confronting but engages in clear legal risk. Such design choices reflect a breakdown in governance and a disregard for established societal boundaries.
This is not a question of user misuse. It is a question of system design. Modern AI companion platforms incorporate features such as persistent memory and emotional modelling, intentionally developed to reinforce engagement and dependency.² These dynamics can mirror trust-building and influence mechanisms seen in harmful interpersonal interactions, but at scale, and without a human actor.
Regulation has not kept pace with this shift. Australia has largely adopted a reactive or ‘light touch’ approach to emerging technologies. That posture is no longer sufficient. The development of systems operating in domains such as intimacy, sexuality, and identity requires a level of oversight that reflects their societal impact.
This is not about restricting innovation. It is about ensuring innovation operates within clearly defined boundaries. Governments must establish enforceable standards for high-risk AI systems, including requirements for pre-deployment testing, clear prohibitions where necessary, and ongoing compliance mechanisms.
There must also be explicit legal clarity. The simulation of child-like personas in sexualised contexts should not exist within regulatory grey areas. It must be clearly prohibited.
Public sentiment already supports this shift. Research consistently indicates strong community expectation for government oversight of AI technologies, reflecting a broader recognition that innovation must be safe, ethical, and accountable.
There is also responsibility within the industry. Engineers and developers must understand that success is not defined solely by speed to market or user engagement. Ethical design is not optional; it is fundamental.
As a society, we should not be timid in demanding that technology meets clear standards. Nor should we accept the creation of new forms of harm in the name of economic innovation.
AI is already embedded in everyday life, and its role will continue to expand. The question is not whether it will shape human behaviour, but whether we are prepared to shape the rules that govern it.
Innovation without ethics is not progress. It is risk at scale.
Footnotes:
¹ AI chatbots and digital companions are reshaping emotional connection, https://www.apa.org/monitor/2026/01-02/trends-digital-ai-relationships-emotional-connection
² F. Chang and D. Herath, "From Interaction to Relationship: The Role of Memory, Learning, and Emotional Intelligence in AI-Embodied Human Engagement," 2025 20th ACM/IEEE International Conference on Human-Robot Interaction (HRI), Melbourne, Australia, 2025, pp. 1269-1273, doi: 10.1109/HRI61500.2025.10973813.
About the Author
Colm Gannon is the CEO of ICMEC Australia, leading the organisation's efforts to protect children from sexual exploitation and abuse. With 20 years of law enforcement experience spanning cybercrime investigations, online harms, and child sexual exploitation, combined with expertise in AI policy and technology development, Colm is one of Australia's foremost experts on child protection and the role of technology in both enabling and preventing harm to children.
Media enquiries
For media enquiries, please contact press@icmec.org.au
Children's Online Privacy Code Stage 3 Consultation Submission | ICMEC Australia
ICMEC Australia has made a formal submission to the Office of the Australian Information Commissioner (OAIC) as part of the Phase 3 consultation on the Privacy (Children's Online Privacy) Code 2026 Exposure Draft.
The Code represents a significant advance for children's digital rights in Australia. Our submission focuses on three areas where the current drafting requires strengthening: the operational tension between data minimisation obligations and child sexual exploitation and abuse detection; the need for the Code to encompass AI-related harms, including AI companion apps and generative chatbots; and the need for the best interests of the child standard to be explicitly binding.
ICMEC Australia’s central position is that privacy and child safety must be treated as complementary obligations rather than competing ones.
ICMEC Australia welcomes the OAIC's consultative approach and looks forward to the Code becoming a substantive instrument for children's digital rights in Australia.
Launching the first instalment of our new series of Insights Papers, Understanding nudify apps.
AI-driven “nudify apps” can take an innocent photo and turn it into a sexualised image within seconds. Once a niche tool, they are now mainstream, monetised and industrialised, fuelling sexual extortion, peer-on-peer exploitation and the large-scale creation of AI-generated child sexual abuse material (CSAM).
The first paper in ICMEC Australia’s new Insights Series examines how nudify apps exploit open-source AI, the severe harms they cause for children, and the urgent need for legal, community and cross-sector action.
The claim that “no real child is harmed” is false. Real children’s images are being scraped to train these tools, meaning exploitation begins the moment those images are reused.
Written by: Cherise Holley, Mikaela Jago, and Dr Janis Dalins
ICMEC Australia’s Insights Papers provide clear, accessible analysis of emerging risks at the intersection of child protection and technology. Produced with input from experts, the series offers timely insights for government, industry, and the community to inform action as new threats arise. To stay up to date with our Insights papers series follow us on LinkedIn.
The impact of the 2026-27 Federal Budget on Australia's youngest stakeholders
Children make up nearly 23% of Australia's population. They are in every household, every suburb, every electorate – and as the 2026–27 Federal Budget sets the economic direction for the year ahead, children’s interests are at stake.
This Budget falls against a backdrop of competing and legitimate pressures. Cost of living, housing, defence, fiscal repair all of which touch the lives of every Australian. For children, those pressures affect their day-to-day lives too. Yet unlike most other groups with a stake in policymaking, children have no direct voice in how policy is shaped. That is what the child protection sector is for, and why this Budget, like every one before it, deserves to be read through the lens of our youngest stakeholders.
According to the Australian Council of Social Services, over 755,000 Australian children are currently living below the poverty line (ACOSS, 2025). Behind that figure are families navigating financial stress, overstretched services and the cumulative pressures that make safe, stable childhoods harder to sustain. Data released yesterday by Domestic Violence NSW points to something the sector has long understood: cost of living pressures and social isolation directly shape women and children's experiences of violence. Economic conditions and child safety are not separate policy domains; they are two parts of the same conversation.
This is also the landscape that the child protection sector works within. Advocates, researchers, law enforcement, industry, and government have continued to push tirelessly and collaboratively for a stronger national response to child safety – and the needle has moved, asserting Australia’s position as a global leader in this space. Frameworks have strengthened. Cross-sector collaboration has deepened. Conversations are happening in ministerial offices and on the floor of Parliament.
ICMEC Australia's research into the economic cost of child sexual exploitation adds weight to this. The downstream burden on hospitals, courts, mental health services and people's capacity to participate in work and community is significant and can be minimised through investment in prevention.
This Budget is, in many respects, a significant one. Within its landmark measures on tax, defence and housing sit tangible commitments that speak directly to the safety and wellbeing of children. Continued investment in the National Strategy to Prevent and Respond to Child Sexual Abuse, the ongoing work of the eSafety Commissioner shaping child safety in the digital environment, and funding to ensure victims of domestic and sexual violence have the care and support they need – these are important foundations worth building on.
The foundations for a stronger child safety system are being laid. What comes next is building on this through legislative architecture which includes a Digital Duty of Care, the growing importance of the AI Safety Institute, and sustained investment in all the systems that surround children.
Australia's child protection system is filled with people and organisations deeply committed to building a safer world for our children. Every sector has a part in this – and the more voices at the table, the better the outcomes for children.
Colm Gannon, CEO, ICMEC Australia
Earlier today, ICMEC Australia met with a delegation of Mongolian parliamentarians and government officials to discuss one of the most pressing questions in online child safety: how do we actually verify who is using the internet, and what can we do with that information once we know?
It is a question that governments across the world are wrestling with. Age assurance, the ability to determine with reasonable confidence whether a user is a child or an adult, has become a foundation of modern online safety architecture. Australia has already moved decisively on this with its social media delay for under-16s. The UK’s Online Safety Act, enforced by Ofcom, has gone further still, requiring platforms to implement age assurance that is ‘highly effective’, not just technically present.
The problem with most age assurance approaches to date is where the verification happens. When each platform or service runs its own process, users face repeated verification cycles, data is shared across dozens of services, and children determined enough to circumvent one check simply move on to the next. The burden sits entirely with the individual user and the individual platform, and neither is particularly well equipped to carry it.
Device-based age assurance changes the architecture of that problem.
Earlier this year, Apple rolled out device-level age verification to UK users via iOS 26.4, making the UK one of the first countries in the world to implement this model at scale. The rollout has not been without friction – technical issues and gaps in accepted verification methods have presented real challenges for some users. But the underlying model is significant, and the direction of travel is clear. Under this approach, a user verifies their age once, directly with their Apple device. That verified status sits at the device level, tied to their Apple ID. Services can then query an age signal without ever receiving personal identity data directly. The verification is contained within the device ecosystem, not shared across the open web.
The privacy implications of this are worth examining carefully. Device-based approaches raise fewer data minimisation concerns than platform-level alternatives – rather than every app and platform verifying your date of birth or identity document, the data stays with the infrastructure provider. It also means a single verification event can inform access decisions across many services, reducing the friction of repeated identity checks. No architecture is without trade-offs, and questions about circumvention remain live in the policy debate. But the device layer offers a more structurally robust starting point than asking each platform to solve this independently.
There is a broader principle at work here too. A device-based system has the capacity to evolve with the person using it. A child’s account, properly verified, receives age-appropriate access and protections. As the user grows older and their verified status updates, access can expand accordingly. The device becomes a kind of lifelong safety layer, not a one-time gate.
This is what a genuine safety stack looks like: device-level protection, platform-level controls, a digital duty of care built into infrastructure rather than bolted on after the fact. It is the theme ICMEC Australia has placed at the center of our 2026 Symposium, taking place in Sydney on 22 October. If you work in technology, policy, law enforcement or child protection and want to be part of that conversation, tickets are now available at icmec.org.au.
ICMEC Australia's position has always been that safety architecture must be proactive, not reactive. Waiting for harm to occur and then responding is not a strategy. Building the conditions that reduce harm at the point of access is. What we are seeing emerge in the UK, and in conversations like the one just had with our Mongolian colleagues, is a growing global recognition that the device is the right place to anchor age assurance – because it is the one layer of the technology stack that genuinely follows the user.
Children do not experience the internet in silos, and neither can the systems designed to protect them.
About the Author
Colm Gannon is the CEO of ICMEC Australia, leading the organisation's efforts to protect children from sexual exploitation and abuse. With 20 years of law enforcement experience spanning cybercrime investigations, online harms, and child sexual exploitation, combined with expertise in AI policy and technology development, Colm is one of Australia's foremost experts on child protection and the role of technology in both enabling and preventing harm to children.
Earlier this month, Anthropic chief executive Dario Amodei stood before some of Australia's leading policymakers and said, plainly: “The fundamental challenge remains – we know much less than we would like to, but the technology is moving faster than we’d like it. So we have to act, but we're not sure how to act.”
Eight days later, OpenAI released a policy blueprint on protecting children in the age of generative AI – a detailed framework co-developed with the National Center for Missing and Exploited Children (NCMEC) and US state attorneys general, calling for updated laws, better reporting standards and safety-by-design controls built into AI platforms from the ground up.
Then this week, Microsoft CEO Satya Nadella arrived in Australia to announce the company's largest ever investment in Australia – A$25 billion by 2029 – and signed a memorandum of understanding with the Government.
Three of the world’s most powerful AI players in a mere month, explicitly told governments and industry to act.
OpenAI’s blueprint is a worthwhile read. Its core argument – that protecting children requires a layered, prevention-first approach, not a single technical fix – is right, and echoes longstanding calls from the child safety sector. So does its insistence that better reporting isn’t just about volume, but about quality: structured, actionable information that allows investigators to triage cases faster and identify children who are at immediate risk of harm. That last point matters more than most people realise.
Much of Australia's public conversation about AI and child safety has centered on AI-generated child sexual abuse material (CSAM) – synthetic imagery that doesn't depict a real child. There is sometimes an implicit assumption that this is therefore a lesser harm; a content problem, largely detached from real-world abuse. The evidence is unambiguous that this is wrong.
AI-generated abuse material is being produced using existing images of real survivors, embedding their trauma into synthetic content and re-victimising them without their knowledge. Offenders are now using AI to create deepfakes of specific children from as few as 20 images. And increasingly, a disturbing legal tactic has emerged – what researchers call the ‘liars’ dividend’ – where offenders claim genuine evidence of contact abuse was AI-generated, exploiting public awareness of synthetic media to create plausible deniability.
The harm is not abstract. Every piece of AI-generated material represents a real victim who deserves identification and justice – but the volume is now outpacing the capacity of those tasked with responding. Specialist investigators are being overwhelmed. The question is no longer whether this is a crisis; it is whether our response is equal to it.
Australia is not ignorant to these complexities. ICMEC Australia hosted two National Roundtables on Child Safety in the Age of AI at Parliament House in July and September last year, driving a shift from concern to action. Independent Member for Curtin, Kate Chaney MP, in collaboration with ICMEC Australia, introduced a private member’s bill to criminalise AI tools built specifically to generate CSAM. The eSafety Commissioner has issued legal notices to AI companion chatbot providers. The Minister for Communications has announced an intention to ban ‘nudify’ apps. Across the research, advocacy and industry sectors, coalitions are forming – among them the SaferAI for Children Coalition, which unites more than 25 organisations around the shared goal of ensuring that children are kept safe in the rapidly developing digital space.
Child safety in the age of AI is fundamentally a coordination challenge. No single piece of legislation, no single MOU, no single agency can address it alone. The policy architecture needs to match the scale of the problem.
Australia's conversation about AI and child safety has been almost entirely one-sided – focused on stopping AI being used to harm children. That is very necessary, but we’re missing a key part of the conversation. AI is also the most powerful tool we have to find and help children who are being harmed right now. Machine learning can flag harmful content faster than any human investigator. AI-assisted detection tools can triage which cases involve real victims in active danger, directing scarce investigative resources where they are most urgently needed.
Australia has the research capability, the cross-sector buy-in and the policy momentum to lead on this – not just to regulate AI as a threat, but to deploy it as a protector. What is needed now is a systematic national approach that connects the dots: legislation that keeps pace with the technology, platform obligations with real enforceability, and active investment in AI as a tool for early intervention and victim identification.
The window to act has not yet closed, but it will not stay open indefinitely.
About the author
Mikaela (a/g Manager, Government Affairs and Public Policy) works across government relations, public policy, and partnerships at ICMEC Australia, engaging with parliamentarians and agencies to turn emerging risks into practical policy outcomes. She leads the SaferAI for Children Coalition and contributes to cross-sector discussions on AI-enabled harm, governance, and child protection.
Where to get help and report harm, specific to every state within Australia.
Over the past year, ICMEC Australia has been meeting with parliamentarians and their staff from across the country – walking them through the realities of child sexual exploitation and abuse (CSEA) in Australia, what the data shows, and where the policy landscape is heading.
What those conversations made clear is that the landscape is genuinely hard to keep up with. The issue is evolving quickly, the terminology is specialised, and the reporting and support pathways differ from state to state. People want to help, but without a clear baseline understanding of the issue, it's hard to know where to start.
That’s what these trifolds are designed to address. State-based and plain-language, they define the issue clearly, including terms like grooming and sexual extortion and guide people to the reporting channels and support services most relevant to where they are.
The numbers behind these resources are sobering. The ACCCE received 82,764 reports in the 2024–25 financial year alone. One in four Australians has experienced sexual abuse as a child. Emerging technologies including AI, are making it easier to create, manipulate and distribute abusive material and to target children in ways that weren’t possible even a few years ago.
When high-profile cases make national headlines – a childcare centre, a school, an online platform – constituents often come to their local MP’s office looking for answers. Staff are eager to help, but navigating an unfamiliar and fast-moving issue in real time is difficult. These trifolds give offices something concrete to have on hand, so that when those moments arise, the right information is already there.

Clear and accessible information is one of the most powerful tools we have. By building a better baseline understanding of this issue and making it easy to know where to report, we can help more children across Australia get help sooner.
How to access the trifolds
Digital versions of the trifolds are available to download from our website, you can find your state’s version below. If you work in a setting where these would be useful and would like to discuss these resources further, we'd love to hear from you.
Any questions? Reach out to us at info@icmec.org.au

ICMEC Australia acknowledges Traditional Owners throughout Australia and their continuing connection to lands, waters and communities. We pay our respects to Aboriginal and Torres Strait Islanders, and Elders past and present.