Korea Expands Illegal-Image Filtering to Community Uploads
From July, about 80 Korean platforms must screen public image uploads for illegal content, sparking cost and efficacy debates.
SocietyCommunity image uploads will now be checked against illegal-footage databases
Starting July 1st, some online services will add an automatic step that checks whether a photo being uploaded matches known illegal footage. The Broadcasting Media Communications Commission (BMCC), Korea’s regulator for broadcasting and telecom content, announced this on June 4th. The rule extends an existing video-filtering requirement to still images as well, and it has sparked debate among community operators over server costs and whether the system actually works. BMCC notice
Once an illegal recording is posted and starts circulating, victims keep suffering the same harm even after they request takedowns — it just keeps reappearing. The point of this policy is to block already-identified illegal content before it’s even posted. But to actually achieve that goal, you have to weigh three things together: how effectively the filter catches illegal content, whether it wrongly blocks legitimate photos, and whether the operating costs are sustainable.
Overseas, people keep bringing up Apple’s photo-scanning plan and the EU’s proposed legislation against child sexual abuse material as points of comparison. But all three cases differ in what gets scanned and where. When Korea’s filtering of public posts gets described using the same framework as scanning personal devices or private communications, it blurs the very point that actually deserves criticism.
What Happens to Korean Internet Services on July 1st
The legal basis is Article 22-5 of the Telecommunications Business Act and Article 30-6 of its enforcement decree. This extends the scope of existing technical-measure obligations—originally aimed at blocking the distribution of illegal filming content—to cover images as well.
The target is information that a given operator makes publicly available and distributes. This does not mean scanning every photo album on someone’s phone or every private one-on-one conversation. You have to distinguish, first, where something is posted, and what kind of photo is being compared against what. Telecommunications Business Act Article 22-5
The government has identified roughly 80 operators subject to prior-measure obligations. The list includes foreign companies like Google, Meta, and X alongside domestic ones like Naver and Kakao. General value-added telecommunications operators must fall under a service type designated by the enforcement decree, and meet thresholds such as ₩1,000,000,000 (~$720K) or more in the prior year’s revenue from that service, or an average of 100,000 or more daily users over the last three months of the prior year. Special-category operators, such as web-hard (cloud storage/file-sharing) services, are subject to separate criteria. Not every internet operator is covered uniformly. Enforcement Decree Article 30-6
The filtering method compares feature data from material already judged illegal by a review body against uploaded images. This is distinct from simple matching that only checks whether files are identical—but it’s also not a system where AI independently decides, on its own, whether every photo it’s never seen before is illegal. And the mere fact that the comparison happens on the operator’s own servers doesn’t mean every original photo is being transmitted to the government.

For operators, processing capacity is the real issue. Running the extra computation while maintaining upload speeds may require expanding servers or integrating new software. The more posts a service handles, the more it has to account for throughput, latency, and the staff needed to respond to outages. The accuracy of image-matching technology and the cost of bolting it onto a live service are two separate things to verify.
The government has said it will provide guidance on installing the technology and evaluating its performance, along with technical support. Even so, that doesn’t erase the costs operators bear for equipment and operational staff. How much equipment is needed, and what the installation and maintenance costs will be, has to be calculated based on each service’s actual processing volume.
Even operators that already run video filtering will see the number of files they need to process change once images are added. Whether existing equipment can handle the load, or new equipment is needed, has to be checked service by service. Simply having been handed software doesn’t mean the operational burden has been resolved.
Another issue operators raise is fairness. It may be easier to verify equipment installation and compliance at domestic communities than to secure the same level of cooperation from foreign operators. That said, foreign operators are also covered by the law. The mere absence of domestic business registration doesn’t mean there are no enforcement tools at all. This is a question that has to be settled by comparing actual compliance rates and the outcomes of corrective measures.
The argument that platforms should bear responsibility for preventing the distribution of illegal filming content is a fair one—harm can keep accumulating while a post sits online waiting to be reported. But it’s also not accurate to lump all domestic communities together as having operated with no safeguards, or to assume all foreign platforms already have adequate protections in place. The level of existing measures and the effectiveness of the new obligation need to be assessed service by service.
Demanding that operators take responsibility has to come paired with a concrete way for them to actually fulfill that responsibility.
I think that even when arguing for the necessity of filtering, the costs and effects need to be disclosed. How much re-distribution the added cost actually prevents, and—if a legitimate post is wrongly blocked—who restores it and how quickly: these are the things operators and users need explained before they can properly evaluate the system.
What Made the Apple and EU Cases Different
The underlying principle of automatically matching images shows up in many services. But there’s a real difference, in terms of privacy impact, between scanning public posts on a company’s servers and scanning private photos on a personal device.
In August 2021, Apple announced a plan to check US users’ photos against known child sexual abuse material (CSAM)1 on-device, before those photos were uploaded to iCloud Photos. This approach is called client-side scanning. What set it apart from Korea’s system was that the target wasn’t content meant to be posted publicly on a server — it was photos being uploaded to a personal photo storage service.
Security researchers and the digital rights group EFF2, among others, pushed back. Their concern was that building a feature to inspect photos on a device could open the door for governments to demand searches for other kinds of material, and that false detections could harm users. The argument was that the goal of protecting children and the potential for the scanning feature to be misused needed to be weighed together.
Apple shelved the plan, and in December 2022 announced it would not move forward with a CSAM detection tool for iCloud Photos. Apple’s statement at the time, as published by EFF, confirms this. EFF, December 2022
In the EU, the European Commission’s 2022 legislation targeting child sexual abuse material sparked a debate over private communications and encryption protections. In November 2025, the EU Council adopted a negotiating position that included risk assessment and mitigation obligations along with a legal basis for voluntary detection by service providers. This does not mean the final law has been settled, nor that all forms of automated detection have been abandoned. It’s the Council’s position for negotiations with the EU Parliament. EU Council announcement
A recurring worry in this debate is scope creep — the possibility that a feature originally built to find child sexual abuse material could be redirected to search for other kinds of content. This should be distinguished from a claim that such expansion has actually happened, but the question of who gets to change the list of scanned content, and who oversees that decision, needs to be settled from the outset.
“Bugs in our Pockets,” written by 14 researchers, analyzes exactly these security problems. First released in 2021, the paper was published in an academic journal in 2024. The authors argue that scanning content on personal devices threatens both privacy and security, and that designing such a system to be both safe and trustworthy is genuinely difficult. This paper shouldn’t be read as a direct performance evaluation of Korea’s server-side filtering technology.
What to Check in Korea’s Domestic System
Korea’s system needs to be understood in the context of strengthened digital sex crime countermeasures following the Nth Room case (a 2018–2020 South Korean digital sex crime scandal involving the blackmail and sexual exploitation of victims through encrypted messaging app chat rooms). Under the 2020 amendment to the Telecommunications Business Act, obligations to prevent the distribution of illegally filmed content were strengthened, extending technical measures from videos to images as well. The demand to stop redistribution before harm repeats itself is clear.
Even granting that demand, the method of implementation still deserves scrutiny.
The issues raised abroad by civil society groups and security researchers are worth referencing domestically too — limits on what gets scanned, error verification, appeals processes, and controls against scope creep. But lumping Apple’s withdrawal and the EU’s legislative debate together as if they represent a single social consensus, then contrasting that with Korea, obscures the actual differences between these systems.
The core question for Korea’s measure is how much it reduces the redistribution of material already ruled illegal through deliberation. The number of files scanned or the number of operators who installed equipment tells us nothing about whether harm actually decreased. We need to look at blocking outcomes, error rates, and redistribution after takedown requests, together.
Operators preparing for implementation also need clearer guidance — what gets solved through technical support versus what requires their own investment, and cost breakdowns by expected processing volume. This matters especially for looking at what burden falls on communities with many users but little revenue.

This system has sparked debate not just in Korean media and IT communities but on Privacy Guides abroad. Some posts overseas describe it as though it’s a system that surveils every image in Korea. Rather than taking that reaction at face value, we should explain the actual scope — that it applies to publicly posted content — while still weighing whatever concerns remain.
Agreeing that digital sex crimes must be stopped doesn’t mean the effectiveness of any particular technology has been confirmed. Protecting victims and scrutinizing the system shouldn’t be treated as opposing positions.
The compliance gap between domestic and foreign operators also needs to be made public. If foreign platforms aren’t cooperating enough, enforcement against those services and international cooperation both need to be strengthened. The fact that domestic operators have spent money doesn’t mean the entire distribution pathway is now under control. Conversely, there’s not enough evidence to conclude that domestic filtering has no effect at all.
We should also examine whether rising costs make domestic services less convenient, pushing users toward other platforms. It hasn’t been confirmed that any such migration has actually happened because of this measure. That’s exactly why we need to track how services change and how redistribution routes shift after implementation.
Oswarld’s Lens
While building technology strategy for companies, I’ve repeatedly seen budget and staff concentrated on channels that are easy to manage, simply because reaching customers where they actually are is difficult.
That approach produces a tidy record of expenditures. But if you never actually reach the customer, it doesn’t translate into revenue.
Looking at this new system, I found myself thinking that we need to separate the resources put in from the results we’re trying to achieve. A company’s revenue and the protection of crime victims aren’t the same kind of problem, but the same caution applies: we need to check whether concentrating measures on what’s easy to manage causes us to miss where the real problem is actually occurring.
Installing filters on domestic communities and responding to redistribution on overseas platforms have to proceed together. Beyond reporting how much equipment has been installed, authorities need to explain how quickly and how consistently victims’ material actually gets blocked.
Clearly explaining the scope of inspection also matters. The government needs to disclose, in language ordinary users can understand, the distinction between public posts and private communications, how it handles hash-matched fingerprints versus original images, and what remedy exists when something is wrongly flagged. Only then can it answer exaggerated claims while still remaining open to legitimate criticism about real risks.
I don’t think policy evaluation should stop at simply expanding operators’ obligations. The effectiveness of and errors in blocking redistribution need to be disclosed, and operating measures that small businesses can actually manage need to be worked out. The more urgent the purpose, the more rigorously we need to verify that the means actually work.
Closing section looks accurate and complete—no changes needed.
Closing
Starting in July, roughly 80 operators will be required to cross-check public images against illegal filming databases. The scope differs from Apple’s on-device scanning plan or the EU’s debates over private communications, but the same unresolved questions remain: accuracy, cost, and whether the inspection’s purpose stays narrowly bounded.
Once this takes effect, I want to see more than just the number of images blocked — I want the false-positive rate, recovery time, the drop in re-uploads, and the gap in compliance between domestic and foreign operators. Without that data, there’s no way to judge whether this expansion actually reduced harm.
Which information do you think should be disclosed first for this image-filtering system? Let me know in the comments — are you most curious about operating costs, blocking effectiveness, or how errors get handled?
Keep the perspective, not the noise.
We choose one consequential shift and trace what sits beneath it, every other day.
Confirm once to finish subscribing.
Already a subscriber? Sign in to join the conversation
References & Further Reading
Primary sources
-
Hal Abelson et al., “Bugs in our Pockets: The Risks of Client-Side Scanning”, Journal of Cybersecurity, Oxford Academic, 2024. : This is the key paper in which 14 international security researchers analyze the technical risks of client-side scanning. Chapter 2 is especially worth reading.
-
Enforcement Decree of the Telecommunications Business Act, Article 30-6 : The original text of the enforcement decree defining the scope of obligated operators and the required technical measures.
-
Privacy Guides Community, “South Korean Online Communities Will Need to Scan Every Images with AI Censorship Tools”, 2026. : Shows how overseas privacy communities are reading this issue.
-
Kyunghyang Shinmun, “‘Censorship state’ backlash over expanded blocking of illegal filming photos··· government says ‘targets only already-confirmed illegal material’,” by reporter Namhee Kim, June 5, 2026. : Kyunghyang Shinmun’s coverage of the Korea Media & Communications Commission’s briefing session for operators.
-
Korea Media & Communications Commission, “Illegal filming images must also be subject to distribution-prevention measures”, June 4, 2026. Outlines the implementation timeline, covered operators, and technical support.
-
The Council of the EU’s negotiating position on the child sexual abuse legislation, November 26, 2025. Note this is the Council’s adopted negotiating position, not the final law.
Background
- Tuta Blog, “EU Commission is planning what Apple stopped: Automatic CSAM scanning”, 2022. : A good summary of how Apple’s withdrawal of CSAM scanning connects to the trajectory of the EU’s Chat Control proposal.
- Chambers & Partners, “Data Protection & Privacy 2026 — South Korea”, 2026. : A report situating Korea’s AI Framework Act and data protection law within a global perspective.

Footnotes
-
CSAM (Child Sexual Abuse Material): the internationally standardized term for child sexual abuse material. The phrase “child pornography” was once used, but the field has moved to CSAM to avoid re-victimizing survivors. ↩
-
EFF (Electronic Frontier Foundation): a U.S. digital rights organization founded in 1990. It advocates for internet freedom, privacy, and free expression, and leads related litigation and campaigns. ↩
Your take shapes the next issue
What resonated most in this issue, or where has your experience been different?