On September 22, 2026, Google agreed to report child sexual abuse material (CSAM) directly to the Indian Cyber Crime Coordination Centre (I4C), a Ministry of Home Affairs body. exchange4media reported that Google will start sharing once a technical framework is built, and no date has been given. Meta said the previous week that it would send child-safety reports directly to India's national cybercrime portal.
The move is mostly right in direction. The unfinished part is the legal and technical plumbing around it.
The strongest case for the change
Until now, Google and Meta sent suspected child exploitation reports to the US-based National Center for Missing & Exploited Children (NCMEC), which forwarded them to the relevant country. NCMEC's CyberTipline received over 21.3 million reports globally in 2025, according to the same exchange4media report. Indian officials told reporters that this extra layer "can delay police intervention, particularly in cases involving children facing immediate danger."
That argument is strong. When a child is being abused now, hours matter. A relay through a foreign nonprofit, which has to triage millions of tips and match each to a jurisdiction, is a poor fit for those cases. NCMEC is not the problem. The issue is that a single clearinghouse cannot be the only route for time-critical reports.
Indian law has also pointed this way for two years. In Just Rights for Children Alliance v. S. Harish (September 2024, 2024 INSC 716), the Supreme Court held that social media intermediaries must report POCSO offences to the authorities specified under Section 19 of the Protection of Children from Sexual Offences Act, 2012, in addition to NCMEC. Google's decision is therefore closer to compliance than to a concession.
Why the pressure is rising
The petitioner in that case, Just Rights for Children Alliance, went back to the Supreme Court in August 2026. Bar & Bench reported that the plea sought a uniform standard operating procedure for detection and reporting, criminal action against non-compliant platforms, and mandatory reporting to Indian police rather than only to bodies like NCMEC. The Court issued notice to the Centre. The hook for this piece places the next hearing on October 15, 2026, with MeitY and the Law Ministry under pressure to file an action-taken report. A Supreme Court record of proceedings shows the Alliance's Writ Petition (Civil) No. 1120/2026 against the Union of India live on the docket, with notice issued on September 10, 2026.
Google's announcement, like Meta's, is best read as a move made with that hearing in view. That is no reason to discount it, but it explains the timing, and why the announcement came with no start date.
What is missing
A direct channel changes who holds sensitive data and what they can do with it. Three gaps matter.
First, there is no published protocol. I4C is the Home Ministry's nodal body for cybercrime and runs the National Cybercrime Reporting Portal. Its mandate is to coordinate law enforcement agencies. Nothing public says what a CSAM report contains, who in a state police force receives it, how fast it must be acted on, or how long it is retained. A faster pipe without a service-level standard is not a guarantee of faster rescue.
Second, scope creep is a real risk. NCMEC's role is narrow and statutorily defined. A domestic channel run by a ministry with a broad cybercrime mandate could, over time, be asked to carry other categories of report. CSAM is the case where nearly everyone accepts proactive reporting. The question is whether the channel will be limited to it, and no document currently says so. The principle should be explicit: reports cover a defined offence category, not general content or user data.
Third, the privacy law that would discipline this is not yet in force. MediaNama noted this week that the Digital Personal Data Protection Act, 2023 was brought into force in stages from November 2025, but its substantive provisions on processing personal data are due only in May 2027. For now, the main limits on how I4C handles what it receives are administrative and procedural rather than statutory.
A proportionate approach
The answer is not to stall a measure that protects children. It is to make the channel narrow, fast and auditable at the same time.
- Publish the protocol. MeitY and the Home Ministry should set out the report format, the escalation path for imminent-danger cases, and a response-time target. The Supreme Court's request for a uniform standard operating procedure is the natural vehicle.
- Limit the scope in writing. The channel should be confined to POCSO-category material. Any extension to other offences should need a separate, public decision.
- Keep NCMEC in the loop. Dual reporting, which the 2024 judgment already requires, preserves cross-border cooperation. Much CSAM involves offenders and victims in several countries, and NCMEC's hash-sharing and international network are real assets. Replacing it would be a mistake.
- Measure outcomes. Platforms and I4C should report aggregate volumes, time to police action, and the number of children identified, so the claim that direct reporting is faster can be tested rather than assumed.
Enforcement-minded readers will note that platforms have been slow to build domestic channels, and that some pressure was warranted. Civil-liberties-minded readers will note that a government agency now receives a new stream of sensitive material with no statute governing it. Both are right.
The measure of success is not that Google signed on. It is whether a child in danger in Jaipur or Jorhat is reached sooner, and whether the system that achieves this stays confined to the offence it was built for. The October 15 hearing is the occasion to set the rules, and the technical framework Google is still building should be built to those rules.