Online safety has stopped being about content
For most of the last decade, keeping children safe online meant removing bad things after they appeared: takedown queues, reporting buttons, moderation teams measured on how fast they cleared a backlog. That model is being replaced. The regimes now in force across the UK, the European Union, Australia and Southeast Asia ask a different question — not what a service removed, but how it was built, and whether anyone thought about children before it shipped.
This is the single most useful thing to understand about the current landscape. Content moderation is now the last line, not the strategy. The obligations that carry real consequences are upstream: assess the risk to children, design against it, turn the riskiest features off for young users by default, and be able to show your working.
What the regimes have in common
The statutes differ in scope, in who they bind and in how hard they bite, but four elements recur almost everywhere.
- A duty to assess risk to children — documented, before launch and again when the service changes materially. This is the obligation most organisations underestimate, because it cannot be satisfied retrospectively.
- Age assurance of some kind, with the strength expected to be proportionate to the risk being gated.
- A named regulator with investigatory powers, and codes of practice that supply the operational detail the statute leaves open.
- Accountability that attaches to a person, not only to a company — senior managers who can be asked what they knew.
Divergence sits mostly in scope and threshold: which services are caught, how far obligations reach beyond the largest platforms, and how much is asked of the organisations that merely use those platforms to reach children.
Age assurance, and why it is contested
Age assurance has become the mechanism on which most of these regimes depend, and it is the one that most often goes wrong. The difficulty is that every method trades something away.
Self-declaration protects privacy and stops almost nobody. Document checks are robust and create a database of children's identity documents that somebody must then defend — a new target, and a new harm if it leaks. Facial age estimation avoids storing documents but is least accurate at precisely the ages that matter most, and its errors are not evenly distributed across skin tones and presentations. Inference from behaviour is invisible to the user and hard to contest.
There is no option without cost, which is why proportionality is doing so much work in the drafting. The practical test is whether the measure is sized to what is actually being gated, and whether a child wrongly judged to be an adult — or wrongly locked out of support they need — has a route back. Age assurance that excludes the most vulnerable children from help is not a safety measure. It has moved the harm.
What bans do and do not achieve
Minimum-age laws and outright bans on social media for younger children are the most visible policy response, and the most contested. They have a real strength: they are legible. Parents, schools and legislators understand them, they are enforceable in a way design duties are not, and they shift the burden onto platforms rather than onto individual families.
The objections are equally real. Bans push determined children towards services with less moderation rather than more. They remove access to peer support, information and community from the children who rely on it most — LGBTQ+ young people, those in isolated places, those seeking help they cannot ask for at home. And they relieve pressure on the design question by appearing to have settled it. A child who is off a platform until sixteen and then arrives on a service designed with no thought for them has been delayed, not protected.
The honest position is that age limits and design duties are complements, and that a jurisdiction relying on the first while neglecting the second has chosen the easier half.
What organisations that serve children inherit
These laws bind platforms. Schools, NGOs, health providers, sports bodies and companies that reach children through those platforms are affected all the same, in three ways.
- Reach changes underneath you. When age assurance or a minimum age lands, the channel through which you reached young people may simply stop working, with little notice.
- Expectations rise. Funders, regulators, insurers and boards increasingly ask organisations working with children to demonstrate a standard close to the one imposed on platforms — whether or not the statute names them.
- Your own services are in scope more often than you think. A messaging feature, a forum, a mentoring app or a help line with a chat function can attract obligations the organisation never anticipated.
One standard, many regimes
An organisation operating across several of these jurisdictions cannot run a separate compliance programme for each. It needs one child-safety standard, grounded in children's rights, that maps onto each regime as it arrives.
The UN Convention on the Rights of the Child and General Comment 25 supply that standard, and they give you something no statute does: a way to weigh protection against children's rights to participation, privacy and information, so that age limits and identity checks do not quietly become a new source of harm.
Where to start reading
The articles below work through the specifics — how the UK Online Safety Act and the EU Digital Services Act differ for children, the five Southeast Asian regimes and what they share, Australia's Children's Online Privacy Code, whether social media bans protect children, what Meta's teen restrictions actually changed, and the conversations children are now having with chatbots.
Child Safe ME advises organisations on online safety strategy and on the policy framework that has to hold it together.