The Internet Watch Foundation's latest figures make the trajectory unmistakable: AI-generated child sexual abuse material is scaling faster than enforcement or regulation can track. In the first half of 2026 alone, IWF analysts assessed 6,310 AI-generated images meeting the legal definition of child sexual abuse — already 40% above the full-year 2025 total of roughly 4,500. These figures cover still images only; video, where the IWF has previously noted a "huge surge," is not included in this count. The victims are overwhelmingly girls aged seven to thirteen. That demographic consistency across reporting periods suggests not random experimentation but systematic targeting — model fine-tuning and prompt engineering optimized for specific abuse categories. The photorealism threshold has been crossed: IWF analysts are now routinely encountering material indistinguishable from real imagery, which compounds both the investigative burden and the harm to children whose likenesses are appropriated. The Report Remove service, which helps children block intimate images from appearing online, has received 420 reports in H1 2026 from children who believe explicit images of themselves were AI-fabricated or manipulated — already exceeding the full-year 2025 total of 397. This is the demand-side signal: generative tools are being weaponized not just by anonymous producers but by peers and predators who know specific children. The regulatory picture is conspicuously empty. The Burnham government has not signalled an imminent AI-focused bill. AI Minister Kanishka Narayan's position — "nothing is off the table" but any proposal must pass a "Will it make the British people safer?" test — is the classic formulation that preserves optionality while committing to nothing. Existing UK law criminalizes AI-generated CSAM and adapting models to produce it, with sentences up to five years. But criminalization after the fact is not the same as prevention at the model layer. The IWF's Hannah Swirsky is direct about where responsibility sits: "It is incumbent on tech companies to build tools which cannot be abused this way." The call is for binding legislation compelling safety-by-design — not downstream takedowns, but upstream architectural constraints that prevent models from generating abuse material in the first place. This is the core policy fight: voluntary commitments from model developers versus statutory mandates with enforcement teeth. The National Crime Agency and IWF have resorted to advising parents to keep children's photos off social media entirely — making accounts private or restricting to close-friends groups. This is an adaptation signal: when the institutional response to a technology-enabled harm is to tell citizens to withdraw from the technology's inputs, the institutions have conceded that they cannot control the outputs. The structural dynamic is clear. Generative AI has collapsed the production cost of abuse material to near zero, while enforcement and regulation operate on legislative timescales. Every month without upstream model constraints is a month in which the production curve steepens. The 40% year-over-year growth is not a plateau — it is a doubling pattern in search of its next order of magnitude.