A man in Carter County, Montana, has been charged with felony counts of sexual abuse of children after allegedly using an AI tool to manipulate images of a local child. The investigation, initiated by tips from the National Center for Missing and Endangered Children, revealed that the perpetrator sourced images from public social media accounts to create the illicit content. This case is one of the first in Montana to utilize new legislation specifically targeting the use of AI in the creation of child sexual abuse material.
Prosecutors in Montana reportedly charged Shy Herbert McCutchan with felony counts of sexual abuse of children, alleging he used an AI tool to manipulate images of a local child. Authorities said the purportedly AI-altered material was discovered through cloud backups linked to his accounts. The case is among the first in Montana to apply new laws targeting AI-generated or manipulated child sexual abuse content.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.3 Fraud, scams, and targeted manipulation
The perpetrator used AI to create sexual imagery of a specific child by manipulating photos taken from social media, which fits the targeted creation of humiliating or sexual imagery under this sub-domain.
Additional risk subdomains
- 1.2 Exposure to toxic content: The incident involves the generation of child sexual abuse material (CSAM), which is explicitly defined as toxic content.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by a human user who intentionally used a deployed AI tool to manipulate images of a child to create illicit content.
EU AI Act risk tier
- Risk tier: 1 Unacceptable
Unacceptable Risk: The AI system was used to create child sexual abuse material (CSAM), which represents an exploitative system targeting vulnerabilities of a child, violating fundamental rights and posing significant dangers to society.
AI system and alleged parties
- AI system: None named
- AI purpose: Deepfake Image Generation; Image Retouching
- Behaviour type: Tool
- Alleged developer: Unknown generative AI developer
- Alleged deployer: Shy Herbert McCutchan
- Alleged harmed parties: Unnamed Montana child, Unnamed family of Montana child, minors, General public of Montana, General public
Harm severity
Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Minor, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Substantial, indirect Negligible
Malicious content
Reported: The report explicitly describes the creation of toxic and malicious content in the form of AI-generated child sexual abuse material.
Directly caused: The perpetrator used AI to digitally alter the image of a Montana child, producing AI CSAM.
Indirectly caused: N/A
Inferred additional harm: It is possible the generated content was uploaded to cloud backups or shared online, potentially exposing others or expanding its reach, though the report only confirms upload to a wireless cloud backup.
Privacy
Reported: The report explicitly describes privacy violations where a child's images were taken from a social media account and manipulated.
Directly caused: The perpetrator captured images of a child from the parents' public social media account to use as inputs for AI manipulation.
Indirectly caused: N/A
Inferred additional harm: N/A
Child sexual exploitation and abuse
Reported: The report explicitly describes a CSEA incident involving AI-generated CSAM.
Directly caused: The perpetrator used AI to digitally alter images of a child under 12, producing AI CSAM.
Indirectly caused: N/A
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Technology
- AI Image Manipulation Tools: AI tools allowed digital alteration of child images to create CSAM.
Data Inputs
- Public Social Media Photos: Perpetrator acquired real child photos from public social media accounts.
Human Factors
- Malicious Intent of Perpetrator: Perpetrator actively sought to generate and possess CSAM using AI.
- Public Sharing by Parents: Parents posted child photos publicly, making them accessible to predators.
Process and Methods
- Lack of Social Media Safeguards: Public social media allowed unauthorized downloading of child photos.
Regulatory Environment
- Historical Regulatory Gaps: New laws like House Bill 82 were needed to prosecute AI-altered CSAM.
Information quality
- Classification confidence: High
- Reason for confidence: The report clearly outlines the criminal charges, the role of AI in manipulating the child's image, the source of the images, and the legal context. There is no ambiguity about the perpetrator's actions or the nature of the harm.
- Ambiguities identified: The specific AI tool or software used to manipulate the images is not identified.
An individual in Montana used AI to generate child sexual abuse material from publicly sourced social media photos. While representing a severe local crime and a violation of individual rights, the incident has negligible national security implications and is handled through standard domestic law enforcement.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: Shy McCutchan
Threat characteristics
- Imminence: Long-term. The suspect has been arrested and charged, meaning the immediate threat is resolved, though the strategic challenge of AI-generated CSAM remains.
- Autonomy: Human-controlled. The AI tool was used purely as an instrument by the human perpetrator to manipulate images, with no autonomous decision-making.
- Novelty: Evolved capability. Represents an evolution of child exploitation threats through the targeted use of AI image manipulation on publicly sourced social media photos.
Impact by dimension
- Physical security: Negligible. No threat to physical systems, critical infrastructure, kinetic weapons, or physical safety of the public was indicated in this incident.
- Information security: Negligible. The incident does not involve intelligence compromise, classified data theft, or state-sponsored information warfare operations.
- Sovereignty: Negligible. No disruption to state authority, electoral systems, border control, or core government operations occurred.
- Economic security: Negligible. The incident has no impact on strategic industries, financial systems, or national technological competitive advantage.
- Societal stability: Minor. While representing a severe violation of an individual child's rights, the impact is localized and managed through standard domestic law enforcement and legal procedures.