Start here

Plain-English explainers on the rules and practices that come up most often: what each one requires, and what to do about it.

Online safety has stopped being about content

For most of the last decade, keeping children safe online meant removing bad things after they appeared: takedown queues, reporting buttons, moderation teams measured on how fast they cleared a backlog. That model is being replaced. The regimes now in force across the UK, the European Union, Australia and Southeast Asia ask a different question — not what a service removed, but how it was built, and whether anyone thought about children before it shipped.

This is the single most useful thing to understand about the current landscape. Content moderation is now the last line, not the strategy. The obligations that carry real consequences are upstream: assess the risk to children, design against it, turn the riskiest features off for young users by default, and be able to show your working.

What the regimes have in common

The statutes differ in scope, in who they bind and in how hard they bite, but four elements recur almost everywhere.

  • A duty to assess risk to children — documented, before launch and again when the service changes materially. This is the obligation most organisations underestimate, because it cannot be satisfied retrospectively.
  • Age assurance of some kind, with the strength expected to be proportionate to the risk being gated.
  • A named regulator with investigatory powers, and codes of practice that supply the operational detail the statute leaves open.
  • Accountability that attaches to a person, not only to a company — senior managers who can be asked what they knew.

Divergence sits mostly in scope and threshold: which services are caught, how far obligations reach beyond the largest platforms, and how much is asked of the organisations that merely use those platforms to reach children.

Age assurance, and why it is contested

Age assurance has become the mechanism on which most of these regimes depend, and it is the one that most often goes wrong. The difficulty is that every method trades something away.

Self-declaration protects privacy and stops almost nobody. Document checks are robust and create a database of children's identity documents that somebody must then defend — a new target, and a new harm if it leaks. Facial age estimation avoids storing documents but is least accurate at precisely the ages that matter most, and its errors are not evenly distributed across skin tones and presentations. Inference from behaviour is invisible to the user and hard to contest.

There is no option without cost, which is why proportionality is doing so much work in the drafting. The practical test is whether the measure is sized to what is actually being gated, and whether a child wrongly judged to be an adult — or wrongly locked out of support they need — has a route back. Age assurance that excludes the most vulnerable children from help is not a safety measure. It has moved the harm.

What bans do and do not achieve

Minimum-age laws and outright bans on social media for younger children are the most visible policy response, and the most contested. They have a real strength: they are legible. Parents, schools and legislators understand them, they are enforceable in a way design duties are not, and they shift the burden onto platforms rather than onto individual families.

The objections are equally real. Bans push determined children towards services with less moderation rather than more. They remove access to peer support, information and community from the children who rely on it most — LGBTQ+ young people, those in isolated places, those seeking help they cannot ask for at home. And they relieve pressure on the design question by appearing to have settled it. A child who is off a platform until sixteen and then arrives on a service designed with no thought for them has been delayed, not protected.

The honest position is that age limits and design duties are complements, and that a jurisdiction relying on the first while neglecting the second has chosen the easier half.

What organisations that serve children inherit

These laws bind platforms. Schools, NGOs, health providers, sports bodies and companies that reach children through those platforms are affected all the same, in three ways.

  • Reach changes underneath you. When age assurance or a minimum age lands, the channel through which you reached young people may simply stop working, with little notice.
  • Expectations rise. Funders, regulators, insurers and boards increasingly ask organisations working with children to demonstrate a standard close to the one imposed on platforms — whether or not the statute names them.
  • Your own services are in scope more often than you think. A messaging feature, a forum, a mentoring app or a help line with a chat function can attract obligations the organisation never anticipated.

One standard, many regimes

An organisation operating across several of these jurisdictions cannot run a separate compliance programme for each. It needs one child-safety standard, grounded in children's rights, that maps onto each regime as it arrives.

The UN Convention on the Rights of the Child and General Comment 25 supply that standard, and they give you something no statute does: a way to weigh protection against children's rights to participation, privacy and information, so that age limits and identity checks do not quietly become a new source of harm.

Where to start reading

The articles below work through the specifics — how the UK Online Safety Act and the EU Digital Services Act differ for children, the five Southeast Asian regimes and what they share, Australia's Children's Online Privacy Code, whether social media bans protect children, what Meta's teen restrictions actually changed, and the conversations children are now having with chatbots.

Child Safe ME advises organisations on online safety strategy and on the policy framework that has to hold it together.

Articles in this category

A guide to how children's online safety regulation has shifted from moderating content to regulating design, and what that means for organisations.

Topic guides: AI Safety for Children · Organisational Safeguarding · All articles

Online safety Explainer September 16, 2026 10 min read

GDPR and Children's Data Across the EU: Consent Ages, Profiling, DPIAs and Enforcement

Consent ages from 13 to 16, child-friendly transparency, profiling limits, DPIAs and record fines: what GDPR requires for children's data across the EU.

Read: How GDPR protects children's data in the EU
Online safety Explainer September 16, 2026 9 min read

UNCRC General Comment No. 25 Explained: Children's Rights in the Digital Environment

The UN guidance behind today's children's online safety laws: what General Comment 25 says, what it asks of businesses, and how to apply it.

Read: What General Comment 25 means for organisations
Online safety Explainer September 16, 2026 9 min read

What Is Age Assurance? Methods, Trade-offs and What Regulators Now Expect

Age verification, facial estimation, digital ID and more: what age assurance means, what each method costs, and what regulators now expect.

Read: What age assurance is and how it works
Online safety Explainer September 14, 2026 6 min read

UK Online Safety Act vs EU Digital Services Act: What Child-Facing Services Must Do Under Each

Two regulators, two rulebooks, one question: can you show your service is safe for children? The UK and EU regimes compared, with practical steps.

Read: UK Online Safety Act versus EU DSA for child-facing services
Online safety Explainer September 14, 2026 7 min read

Singapore, Malaysia and Indonesia Have All Moved on Children's Online Safety in 2026. Here Is How They Compare

Three Southeast Asian markets now have binding children's online safety rules. A country-by-country comparison, and one standard to meet them all.

Read: How Southeast Asia's new child online safety laws compare
Online safety Explainer September 14, 2026 6 min read

Australia's Children's Online Privacy Code and Duty of Care: What Child-Serving Organisations Must Do Now

Australia now has an under-16 minimum age, AI codes, a coming duty of care and a children's privacy code due by 10 December 2026. What organisations must do.

Read: What Australia's new child online safety rules mean for organisations
Online safety Perspective June 17, 2026 5 min read

Protecting Children Online: Why the Conversation Cannot Stop at a Ban

Banning social media for under-16s is a meaningful step, but not the whole solution. Children also need safer platforms, digital literacy, and real accountability...

Read: Why a social media ban isn't enough to protect children
Online safety Perspective September 26, 2025 3 min read

We Urgently Need To Open Honest Conversations With Children About Chatbots

Children are increasingly turning to AI friends for advice, support, and companionship. From skincare routines to navigating emotions, AI is quietly shaping how children see themselves and make decisions. While there are clear benefits, we must also face the risks and mitigate them...

Read: Honest conversations with children about chatbots
Online safety Perspective April 14, 2025 2 min read

Meta's New Teen Restrictions Are a Positive Step — But It's Just the Beginning

With improved privacy settings, limited contact from unknown adults, and better controls over harmful content, these updates reflect growing concern over how social media impacts children and young people. But safeguarding children online requires more than platform-level restrictions...

Read: What Meta's teen restrictions get right — and miss

Stay close to the work

Maryam publishes regular commentary on online child safety and child safety in AI. Follow her on LinkedIn, or get in touch to discuss what your organisation needs.

Follow Maryam on LinkedIn

Get in touch

← Back to all articles