By Tom Jarvis
Warning: This article discusses image-based sexual abuse, including abuse involving children and includes graphic source screenshots from CIR’s investigation. Readers may find the content distressing
Telegram deepfake bots are only the visible face of a wider abuse business. CIR’s analysis found referral networks, backup websites, payment routes and upstream generation providers that can keep the ecosystem alive after one bot disappears.
In late 2025, a UK secondary school was targeted by an extortion attempt involving AI-generated abuse images of pupils. The Guardian reported that the Internet Watch Foundation (IWF) classified 150 images as child sexual abuse material (CSAM) and stored their unique file fingerprints, allowing detection if they appeared online without the need for law enforcement to possess the files themselves. The IWF did not believe the case was isolated. By November 2025, UK reports of AI-generated CSAM had more than doubled, from 199 to 426, with girls making up 97% of victims.
That case shows why Telegram deepfake bots matter beyond the app where they appear. The bots reviewed by CIR are not just offensive search results or disposable accounts. They are storefronts for a commercially organised abuse system that can survive individual takedowns because the audience, money, backup routes and generation capacity often sit elsewhere.
The scale already points to a wider market. WIRED identified at least 50 Telegram bots in 2024 that claimed to create explicit images or videos and collectively displayed more than 4 million monthly users. In January 2026, the Guardian reported on large Telegram channel networks used to create and share AI-generated nude images. CIR’s earlier Grok analysis showed how abuse scales when image-generation access is easy; Telegram shows how it scales when discovery, payment and relaunch paths are also easy. The question is therefore not only whether a model refuses a prompt, but whether the surrounding product pathway makes non-consensual sexual image creation easy to find, repeat, monetise and share.
Understanding, or even eradicating, the Telegram layer will not stop the most egregious cases, but it highlights the resilience of the infrastructure and the multiple ways these organisations can generate funds and provide their illicit services to users. It also highlights a “gateway” effect where users are enticed in with free credits, turning curiosity into an ability to generate images at scale.
CIR’s analysis reviewed public Telegram bot interfaces, public channels and posts, referral messages, linked web pages, payment prompts, public gallery features, bot metadata and screenshots. The timeframe included two weeks of research in June 2026, looking back through posts historically. This captured references and links from the past which have survived takedowns. As a result, many links were already dead, and the live bots viewed were just a snapshot of what has been available over the past years. It did not require uploading images of non-consenting people, generating abusive outputs, or identifying victims. The findings should be read as a map of recurring behaviours, not as a claim that every bot uses the same infrastructure.
