The Content Safety API is Google’s machine-learning classifier for child sexual abuse material (CSAM), launched in September 2018 and offered free to qualifying NGOs and industry partners.1 Unlike hash matchers such as PhotoDNA, it targets previously unseen imagery: rather than matching against confirmed material, it generalizes from learned patterns to flag content no database has ever contained. It is the classifier half of Automated CSAM detection.
What it actually is
Google is precise about the product’s role in its own documentation: the classifier is a prioritization aid, not a detector that adjudicates. It scores submitted images and videos by how likely they are to be abusive, so that human reviewers — whose time is the binding constraint in every moderation operation — work the highest-risk queue first.2 Google recommends running it immediately before the manual review step and requires partners to make their own determination before acting on any item. A Google-reported trial figure claims a reviewer took action on 700 percent more content in the same time with the tool; that is a vendor productivity claim, not an independent accuracy measurement.
Companion tools and licensing
The API sits in Google’s “child safety toolkit” alongside CSAI Match, YouTube’s proprietary hash-matching technology for video, which compares partner-submitted fingerprints against YouTube’s repository of known abusive segments and was among the first video hash-matching systems deployed.2 Both are licensed free, but not openly: organizations apply, and Google approves access. Google describes partners as processing billions of files a year through the toolkit.
The documented limitation
The classifier-plus-human-review pipeline is also the one that failed in the cases the vault already documents. In the Mark and Cassio cases, Google’s system flagged parents’ medical photographs of their own children — exactly the context-blind category a classifier cannot see — and human review, which Google says is staffed by specialists trained by pediatricians to recognize medical-context imagery, sustained the error through account termination and police reports.3 The product’s design centers reviewer capacity; the failure mode centers Automation bias in the determination Google requires partners to make for themselves. Both statements come from Google’s own materials and the documented cases, and the full pattern is Automated CSAM detection.
-
Google’s September 2018 launch post, introducing the classifier and the free licensing model. ↩
-
Google’s child safety toolkit page, describing the prioritization design, the own-determination requirement, CSAI Match, and the application process. ↩↩
-
EFF Google scans false accusations (Electronic Frontier Foundation, August 2022), on the Mark and Cassio cases and the failure of specialist review. ↩
Built on 3 sources (3 external).
Working out connections…
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (117 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "Kimi K3", "label": "Kimi K3 (97%)", "lines": 114, "share": 0.9743589743589743}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (3%)", "lines": 3, "share": 0.02564102564102564}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}