Click here to read our latest report “Beyond Extremism: Platform Responses to Online Subcultures of Nihilistic Violence”

Blurred Lines: The Child Safety Gap in the Crime-Terror Nexus

Blurred Lines: The Child Safety Gap in the Crime-Terror Nexus
29th September 2026 Cecilia Polizzi

This Insight is part of GNET’s LatAm series, which looks at the crime-terror nexus in Latin America and the implications/risks for tech moderation.

Since 2021, major platforms have informally treated Latin American cartels as equivalent to terrorist entities in their internal moderation hierarchies, including through shadow-banning — suppressing the visibility of content or search results without notifying the user — of terms linked to groups like Cártel Jalisco Nueva Generación (CJNG). Yet automated detection infrastructure, built and trained primarily on established violent extremist content patterns, is ill-equipped to detect much of the cartel content targeting minors. Cartels evade filters through coded emojis, slang, narcocorrido-style audio, and visual signalling that automated systems optimised for dominant threat profiles and languages with large volumes of digitised training data, such as Arabic and English, do not reliably recognise. The gap is compounded by staff cuts to moderation teams, most recently TikTok’s closure of its Nashville office in August 2026, eliminating 250 roles – including content moderators – which reduces the oversight needed for culturally specific content. The mismatch has taken on new weight since the US formally designated CJNG, the Sinaloa Cartel, Tren de Aragua and other organised criminal groups as Foreign Terrorist Organisations (FTOs).      

This Insight maps the specific mechanisms – linguistic, cultural, audiovisual, and infrastructural – through which cartel content evades existing tech platform moderation. It explores what this misalignment means for minors, and the broader implications for platforms. The Insight also highlights the shared patterns of the crime-terror nexus, including evasion techniques and pathways of youth engagement, as designated terrorist organisations on both sides of the crime-terror boundary are now exploiting the same detection gaps, on the same platforms, targeting the same demographic.

The analysis reveals a distinct child safety gap, whereby platforms have developed increasingly sophisticated systems to identify terrorist propaganda, graphic violence, and other categories of harmful content, yet remain less capable of detecting cultural signalling, entertainment formats, coded language, and aspirational portrayals of criminal identity. For minors, such content represents not merely exposure to harmful material, but a potential entry point into violent ecosystems across the terror-crime spectrum. 

Designated but Undetected

The application of the FTO label to cartels represents a marked shift in US policy, granting the executive branch an expanded set of enforcement instruments. The designation created a set of demands for platforms that had previously only applied to extremist groups such as al-Qaeda, the Islamic State (IS) and their affiliates. What this means in practice is that platforms now carry the same compliance exposure for a CJNG recruitment video in Mexican Spanish with narcocorrido audio as they do for an IS propaganda release in Arabic. However, notwithstanding the growing pressure, platforms’ capacity to meet the EU’s Terrorist Content Online Regulation, the Digital Services Act and the UK Online Safety Act, and reduce the exposure created by US material support statutes, remains limited. Detection tools were purpose-built for a different threat type, and the evolving bypassing strategies deployed by ‘bad actors’ regardless of orientation continue to outpace them.

The Evasion Taxonomy

Social media platforms have struggled to manage criminal syndicates’ online activities.      Mexican cartels post content that glorifies narco-culture, promote and coordinate violence, recruit and spread disinformation, creating a volume of unverified information that puts young people at greater risk. Groups’ splintering over the past decade is also reflected online, with factions and their affiliates boosting profiles on social media. Most commonly active on Facebook, which in Mexico counts more than 110 million users, criminal actors exploit the platform for coordinating offline harm, recruitment, promotion of narco-culture and drug trafficking, and are intentional about circumventing moderation. The most gruesome content lives on burner accounts only active for a short period of time. Affiliates reshare it repeatedly until moderators flag and remove it, or migrate to platforms like Telegram, which remove violent content less aggressively. Groups also avoid directly naming themselves, instead using emojis to signal their affiliation; research by the Colegio de México and Northeastern University’s Civic AI Lab documented approximately 100 TikTok accounts linked to CJNG’s systemic use of emojis both in videos and in comment sections, as well as hashtags and audiovisuals referencing specific cartels or the crime lifestyle to render the content more appealing to young people. 

Figure 1: TikTok screenshots identified by the Violencia y Paz project (page 13) featuring representations of the Santa Muerte (Our Lady of Holy Death) and individuals involved in “halconeo” (spying on public security institutions) for a criminal organisation.

The evasion playbook mirrors that of terrorist organisations. After IS extensively used social media to spread jihadi propaganda, platforms initiated a crackdown on graphic imagery and violent groups. In response, IS transferred violent content to unofficial accounts and sought alternate measures to continue distributing content through members and sympathisers. Criminal groups have mimicked the strategy and, by decentralising content, were able to continue disseminating it across the digital ecosystem.  

The mirroring of digital strategy between crime syndicates and terror movements extends to additional registers and communications typologies. IS networks repackage official content instead of redistributing it in its original form. Just as cartels use emojis and narcocorrido audio, IS feeder groups overlay pink heart emojis, nasheed remixes, pop culture references, or manipulate recorded audio and metadata. Where cartels bury messaging and calls to action in comment sections, IS operates through unofficial outlets that mimic legitimate journalism. As cartels evade classifiers through coded language, regional slang, and emoji systems that existing models were not trained to recognise, IS affiliates exploit equivalent gaps in under-resourced languages such as Pashto, Somali, and Bahasa. 

The downstream consequences also converge. An analysis by CTC Sentinel drawing on six European case studies identified a recurring pattern involving emotionally vulnerable, digitally native youth, exposed to algorithm-driven jihadi content. The UN Analytical Support and Sanctions Monitoring Team noted that European authorities dismantled four terrorist cells run by minors networked through the same virtual groups, who were in the final stages of preparing to execute simultaneous attacks in several European cities. In Mexico, an estimated 30,000 children, some as young as six years old, have become involved with criminal groups through both digital and non-digital channels.

The funnel implemented by cartels to recruit young people into their ranks, while absent of an ideological component, follows the logic of terrorist organisations already identified in P/CVE analysis, including leveraging vulnerabilities, manufacturing belonging, replacing identity and desensitising to violence. The overlap is not metaphorical. 

Rancho Izaguirre: The Pipeline Made Lethal

Rancho Izaguirre (Jalisco, Mexico), a clandestine site linked to the CJNG, emerged as one of the most disturbing manifestations of Latin America’s ongoing crisis of cartel violence and has been the focus of ongoing investigation since its 2024-2025 discovery by federal forces and search collectives. Since at least 2012, the ranch allegedly operated as a forced recruitment and training facility, where CJNG lured predominantly vulnerable youth, including minors, through fake job advertisements on TikTok, Facebook and Instagram offering security guard or farming (such as agave harvesting) positions at $200-600 per week.

Figure 2: TikToks shared in Latin Times reporting by the Jalisco Cartel use imagery closely associated with drug trafficking and organised crime in order to lure in new recruits. 

The ads were, in fact, bait to recruit youth into CJNG’s ranks. Newcomers either underwent sicario training, designed to produce cartel hitmen, or faced execution. In 2025, a local group of volunteers uncovered hundreds of shoes, items of clothing, three makeshift cremation areas, and charred human remains, which earned Rancho Izaguirre the nefarious reputation of being an extermination camp.

Rancho Izaguirre represents an example of evasion strategies becoming lethal. The pipeline ran seamlessly from digital spaces to forced conscription and, ultimately, extermination, through platforms already enforcing against this category of actor, including shadow-banning CJNG-linked terms. The failure was not the absence of enforcement mechanisms, but the inability of existing systems to identify and intercept the content that sustained the pipeline.

The Mismatch 

Social media platforms proactively seek to maintain transparent content policies and mitigate the exploitation of their services by organised groups. 

However, policing crime content appears to be an uphill battle due to the rapid fragmentation of these movements, as evidenced by the Sinaloa Cartel’s fracture into Los Chapitos and La Mayiza, each maintaining distinct online presences,  the need to preserve freedom of expression and information, and the flaws of moderation systems.

Aside from bilateral or multilateral arrangements between platforms to cooperate in addressing various pathologies in online discourse, such as hate speech, harassment, violence against specific groups, terrorism, racism, xenophobia, homophobia, or misogyny, each platform maintains a specific set of rules for content moderation. Generally, three approaches follow: removing specific posts related to violence; deactivating accounts linked to groups deemed violent or dangerous; and cancelling others that repeatedly violate content rules. However, most filters are first identified through artificial intelligence or flagged by users.  While automation is critical to detect, review, and remove content at scale, AI classifiers are only capable of identifying what they were trained to recognise. Terrorist organisations, hate groups, and criminal enterprises are priority categories for law enforcement tracked by platforms. Despite treating cartel content with considerable seriousness, elevating enforcement, shadow-banning terms and applying internal designations, criminal groups’ content has proven particularly hard to hone in on.  

The consequences fall disproportionately on minors. Under the Digital Services Act, platforms must assess whether their features, including recommendation systems and default privacy settings, pose risks to children. In July 2026, the European Commission’s July 2025 preliminary findings on TikTok established that the platform failed DSA requirements, with 16-and 17-year-olds’ content surfaced to strangers through the ‘For You’ feed. In the same month, both Facebook and Instagram were found to breach the Act due to their addictive design features and therefore posed a risk to users “including minors and vulnerable adults.” 

The centrepiece of cross-platform detection is the GIFCT Hash-Sharing Database (HSDB), which contains hashes of terrorist and violent extremist content shared with companies that join the GIFCT’s Hash Sharing Consortium. The HSDB is managed and continually enhanced to effectively tackle the evolution of technology, content types      and extremism. However, it was originally conceived against the backdrop of the United Nations Security Council’s Consolidated Sanctions Lists, meaning that “nearly all hashes reflected content related to al-Qaeda, the Taliban, the Islamic State, or other groups that the UN had designated as terrorist organisations” (page 5).

Platforms, including X and Facebook, organise their responses to crime syndicates partly based on the formal designation of entities as terrorist, hate, or criminal outfits by the U.S. government. At Facebook, users and pages can also be taken down for consistently violating content standards, but not for praising or depicting a criminal group, unless that group is on the “Dangerous Organizations” list maintained by Meta. Based in part on U.S. designations of violent organisations, groups can be added to that list following the company’s internal deliberations. While it is admittedly complex to address crime content online, it is notable how much more effective platforms have been in eliminating that of terrorist groups.

Avoiding a Compliance Paradox

The FTO designation of Latin America’s cartels created an obligation for platforms that requires them to fundamentally rethink how classifiers are trained, what content is hashed, and which languages and formats are resourced. However, economic considerations such as company layoffs and other complexities may weigh against these changes. Developing classifiers for low-resource languages needs training data, linguistic analysis, and sustained investments. Expanding hash-sharing databases to include new content types inherently means that content must have been previously identified as policy-violating, engendering a circular dependency that limits the capacity of matching algorithms. While human moderators are indeed capable of conducting evaluations, including grey-area cases and maintaining regionally competent teams, the market for moderation shows signs of decline as companies have begun to scale back their trust and safety operations. The FTO designation expanded the scope of terrorist content, but platform investment in detecting the subset of that content that targets minors has not followed. 

The system works as intended within the parameters it was designed for. However, a newly designated set of FTOs operating entirely outside those benchmarks and producing large volumes of content intended for minors through linguistic and cultural references that systems neither parse nor interpret challenges performance. Taxonomic expansion, together with sustained investment in safety and moderation teams, may help platforms address an evolving threat landscape. 

–

Cecilia Polizzi is an international security strategist and leading expert on child recruitment and radicalisation. She has shaped policy and strategy for national governments and multilateral organisations including NATO, OSCE, the Council of Europe, the European Commission, and UN agencies. Polizzi has spoken before the United States Institute of Peace, the Italian Ministry of Defence, and other high-level institutions, and has published extensively in academic journals and other outlets. She is the Founding CEO of the Next Wave Center, a leading organisation in the counter-terrorism and extremism community, focused on addressing the recruitment and radicalisation of minors. Recognised for her international impact, she was awarded the 2025 McCain Global Leaders fellowship. X: https://x.com/_CeciliaPolizzi

–

Are you a tech company interested in strengthening your capacity to counter terrorist and violent extremist activity online? Apply for GIFCT membership to join over 30 other tech platforms working together to prevent terrorists and violent extremists from exploiting online platforms by leveraging technology, expertise, and cross-sector partnerships.

The views and opinions expressed in this Insight are the authors’ own and do not necessarily reflect those of GNET or any of its partners.