The New Architecture of Online Child Safety
Governments worldwide are replacing platform-designed child safety tools with state-mandated access barriers — a new regulatory architecture that is technically fragile, contested by civil-liberties groups, and proceeding on political momentum.
In April, the European Commission did something unusual: it built its own age-verification app. The open-source tool was designed to replace the self-declaration checkboxes platforms had relied on for years — the state's direct answer to a problem platforms could not solve. Security researchers compromised it in under two minutes, bypassing both the PIN code and the biometric authentication. The Commission is rolling it out anyway. [1] That one fact holds the architecture of a global regulatory shift. Governments are replacing platform-designed content moderation with state-mandated access control as the primary way to protect minors online. The new regime is technically fragile, civil-liberties-contested, and proceeding regardless — driven by political momentum that has now outrun the advocacy community that first raised the alarm. The premise that made the shift possible came from the platforms themselves. In February, Meta's internal Project MYST — conducted with University of Chicago researchers — found that parental supervision tools and household restrictions fail to meaningfully reduce compulsive social media use. Teenagers circumvent the controls; algorithmic designs override surface-level restrictions. Instagram head Adam Mosseri confirmed the findings went nowhere.
We do a lot of research projects. — Adam Mosseri
[2] Around the same time, TikTok made a quieter admission.
Despite best efforts, there remains no globally agreed-upon method for effectively confirming a person's age in a way that also preserves their privacy. — TikTok
[3] The platforms had, in effect, testified against their own competence. Regulators noticed. In July, the European Commission charged TikTok with violating the Digital Services Act for failing to protect minors, and spokesperson Thomas Regnier marked the end of the deference era.
Putting default settings for minors is not a beauty contest under the DSA. It must be effective. — Thomas Regnier
[4] What followed was not a coordinated global policy but a pattern — the same mechanism appearing across jurisdictions with different political complexions. The enforcement point moved upstream: from in-app content filters to barriers at the operating system, the app store, and the jurisdictional border. In July, the U.S. Supreme Court allowed Texas's App Store Accountability Act to take effect, requiring app stores to verify ages and obtain parental consent for under-18 downloads. Apple is already applying age assurance.
Texas has not only the right, but the duty, to protect children from the harms of our modern digital space. — Ken Paxton
[5] In March, Apple deployed OS-level identity verification for 35 million UK users. [6] Brazil's age-verification law, enacted in March, explicitly bans self-declaration — the old checkbox — and requires identity document uploads with biometric photo verification instead. The country's data protection director was blunt about why.
that method is ineffective — Iage Miola
[7] In Indonesia, Roblox is now requiring facial scans for users under 16, converting 23 million accounts into tiered access levels: no chat for ages 5 through 12, limited chat for 13 to 15. A company vice president described the scope of the change.
Any user in Indonesia who has not used that tool, who has no facial age estimated, will be automatically placed in a Roblox Kids account and will not have access to chat. — Nicky Jackson Colaco
[8] Australia's under-16 ban, which took effect in December 2025, removed roughly 4.7 million child accounts across ten platforms. Meta alone pulled nearly 550,000 accounts from Instagram, Facebook, and Threads to comply, facing fines of up to AU$49.5 million for non-compliance. [9][10] Even the platforms now want the burden moved off them. Snap Inc. has made its preference explicit.
We continue to believe there are better solutions to age verification that can be implemented at the primary points of entry, such as the operating system, device, or app store levels. — Snapchat
The justifications for these measures have broadened well beyond youth mental health — the original frame that galvanized public concern. In Türkiye, Justice and Development Party Deputy Chair Hüseyin Yayman offered a different rationale.
It has become a platform that directly affects public order, family structures and national values. — Hüseyin Yayman
[10] In the Cayman Islands, Health Minister Katherine Ebanks-Wilks described the proposed under-16 ban in terms that bridged health and protection.
It is with strong support that I share today my position to prohibit social media use for those under the age of 16. This is not about criminalising young people; it is about holding the platforms accountable. It is both a childhood protection measure and a necessary public health intervention. — Katherine Ebanks-Wilks
Cayman Islands MP Pearlina McGaw-Lumsden offered the moral diagnosis behind the policy.
These platforms are not passive tools. They are highly engineered digital environments designed to maximise attention, emotional response and time spent on the platform. — Pearlina McGaw-Lumsden
[11] The movement has become cross-ideological — left-wing mental-health advocacy and right-wing sovereignty framing converging on the same instrument. That breadth is part of what makes it a regime rather than a set of disconnected national experiments. But the regime is fragile in ways that are already visible. Australia's ban is being widely circumvented: a Molly Rose Foundation survey found roughly two-thirds of 12-to-15-year-olds still access banned platforms, with 70 percent describing circumvention as easy.
Continued analysis as more data becomes available will support more robust, evidence-based conclusions regarding longer-term trends, reporting behaviors and impacts of a minimum age for social media. — eSafety Commissioner
The eSafety Commission's own briefing documents showed no meaningful shift in platform usage patterns. [12] Australian teenagers have been bypassing Snap's facial age-estimation by holding up photos of adult faces to the camera — the k-ID system only returns a yes-or-no signal on whether a face appears 16 or older.
As part of this process, k-ID does not receive a user’s ‘declared age’ or ‘declared gender’. This is an intentional design choice grounded in data protection and data minimisation principles. — Luc Delany
[13] And the European Commission's own app, the one built to replace platform self-declaration, was cracked in under two minutes. [1] The civil-liberties case is accumulating alongside the technical failures. The Electronic Frontier Foundation's Aaron Mackey identified the privacy cost.
We already know that the online ecosystem is porous, insecure and routinely subject to data breaches. — Aaron Mackey
[14] NetChoice, the tech trade group, filed for a federal injunction against Virginia's law limiting minors to one hour of daily social media use, arguing it violates the First Amendment. [10] The ACLU opposes North Carolina's under-14 ban on the same grounds. [15] New Zealand's Free Speech Union CEO identified the tradeoff in stark terms.
There’s been some reporting that some platforms appear to know that it’s young kids using their product and tailor the algorithm to kids … that seems like an unfair business practice. — Wab Kinew
[16] The sharpest cut, though, comes from the people who built the case for protecting children in the first place. The advocacy community is now divided. The Molly Rose Foundation — founded after a teenager's suicide — explicitly warned the UK against copying Australia's ban. [12] The NSPCC, Britain's leading child-protection charity, argued that bans drive children toward less regulated, encrypted platforms and advocated for Safety by Design instead. [11] UN High Commissioner for Human Rights Volker Türk delivered the strongest institutional counter to the ban approach.
Simply limiting access to platforms that remain unsafe cannot stand as the endpoint. — Volker Türk
[17] The people who raised the alarm are now warning that the cure may be worse than the disease. The politicians are not listening to them. What they are doing instead is building infrastructure. Andhra Pradesh is exploring age tokens integrated with India's DigiLocker system, drawing standards from Singapore, Australia, and Denmark.
there was an urgent need for a graded, age-based content access system to ensure that children are not exposed to harmful or inappropriate content. — Nara Lokesh
[18] Chai AI is voluntarily implementing OS-level age verification through Apple and Google APIs, eliminating the need for document uploads — the access-control architecture being adopted even ahead of explicit mandates. [19] California offers the one dissenting architecture: rather than banning access, its AB 1709 targets addictive features — infinite scroll, autoplay, algorithmic feeds — for users under 16. Assemblymember Josh Lowenthal drew the distinction.
We are not prohibiting children from accessing social media. — Josh Lowenthal
[20] But California's feature-regulation approach is the outlier. The momentum is with the access controllers, and the infrastructure is being standardized and shared across borders. The regime is being built by governments that have decided doing something visibly fragile is better than trusting platforms to do something they have already proved does not work. Whether it protects children or merely relocates the risk is an open question — and the people best positioned to answer it are no longer the ones making the decisions.
- 1. EU Updates Age Verification App After Security Flaws Found
- 2. Meta Internal Study Shows Teen Social Media Controls Fail
- 3. TikTok Deploys AI Age-Detection Across Europe and United Kingdom
- 4. European Commission Charges TikTok With Violating Minor Privacy Rules
- 5. Supreme Court Allows Texas App Store Age Verification Law
- 6. Global Governments Implement Social Media Bans for Minors
- 7. Brazil Implements New Age Verification Law for Minors
- 8. Roblox Mandates Facial Scans for Indonesian Users Under 16
- 9. Global Momentum Grows for Social Media Bans for Minors
- 10. Global Movement Emerges to Ban Social Media for Minors
- 11. Governments in Cayman Islands, India and UK Weigh Youth Social Media Bans
- 12. Australian Social Media Ban for Under-16s Faces Enforcement Failures
- 13. Australian Teens Bypass Snap Inc. Age Verification Using Adult Faces
- 14. U.S. Debates Mandatory Age Verification for Online Content
- 15. Philippines, North Carolina, and Canada Push Social Media Age Limits
- 16. Canada and New Zealand Pursue Social Media Bans for Minors
- 17. UAE Bans Social Media for Children Under 15
- 18. Andhra Pradesh Plans Social Media Restrictions for Children
- 19. Chai AI Implements Native Age Verification via Apple and Google
- 20. California and South Carolina Ban Addictive Social Media for Minors