Regulation is working. That might be the problem

Ayşe Elif Posos Devrani, Turkish-German University, Department of Cultural and Communication Sciences, Istanbul, Turkey

PUBLISHED ON: 27 Jul 2026

Why this moment matters

For much of the past decade, the central question in children’s digital policy was whether governments could compel technology platforms to change at all. The answer, it turns out, is yes. Since the UK’s Age-Appropriate Design Code (AADC) – a statutory code issued by the Information Commissioner’s Office (ICO) requiring online services likely to be accessed by children to apply high-privacy settings by default – came into force in 2021, the volume of documented child-safety changes across major platforms has grown substantially. The EU’s Digital Services Act (DSA), which took full effect in 2024 and prohibits profiling-based advertising to minors, and the UK’s Online Safety Act (OSA), which requires platforms to assess and mitigate risks to children, have reinforced this momentum.

The question has shifted. We now know regulation can move platforms. What we do not yet know is whether that movement is making children safer, or whether platforms are learning to satisfy regulatory expectations while the underlying risks persist. Two reports published two years apart by the Digital Futures for Children centre (a joint initiative of the London School of Economics and the 5Rights Foundation) allow this tension to be examined as it develops over time.

Two reports, one shift

In 2024, Steve Wood tracked 128 child-safety and privacy changes across Meta, Google, TikTok, and Snapchat between 2017 and 2024, with a pronounced spike of 42 changes in 2021, the year the AADC came into force (Wood, 2024). The message was cautiously positive: regulation was producing visible change.

Two years later, the same author published a follow-up covering 2024–26 (Wood, 2026). The underlying question had shifted. Rather than asking whether platforms were changing, the new report asked whether children were actually safer as a result. This move, from counting outputs to assessing outcomes, is the most consequential difference between the two reports. Table 1 summarises the headline figures.

 
Table 1: Comparing the 2024 and 2026 reports on children’s digital regulation (Source: Wood, 2024, 2026. Table created by the author).
  2024 report (2017–2024) 2026 report (2024–2026)
Platforms assessed four major platforms (Meta, Google, TikTok, Snapchat) 70 platforms, including AI services and games
Changes recorded 128 108
Dominant change type (four major platforms) “by default” settings, around half of all changes end-user tools, led by parental controls
Platforms with at least one age assurance method not assessed 46 of 70
Central recommendation strengthen transparency and outcome assessment remove the OSA safe harbour; require pre-market approval and independent certification

The default-to-tools reversal

The clearest finding is the reversal in the third row of Table 1. In 2017–24, “by default” changes, such as private accounts and geolocation switched off automatically, accounted for roughly half of all recorded changes across the four major platforms. These reflect the AADC’s core principle: protection should be built into the architecture of a service, not left to the user to switch on.

By 2024–26, for the same four platforms, the largest category of change had become end-user tools, with parental controls as the leading subcategory (Wood, 2026). The shift from default settings to tools is significant. A default requires nothing from anyone. A tool requires a parent to locate it, understand it, and activate it. Wood (2024) had already cited evidence that parental controls perform poorly as a stand-alone protective measure. That this is now the dominant mode of compliance, among the platforms with the longest record of regulatory engagement, suggests the safety-by-design logic underpinning the AADC is being diluted at precisely the point where it should be most embedded.

The pattern does not hold uniformly. Among the other platforms where changes were documented, “by default” measures remained the predominant category, particularly age assurance. One reading is that newer entrants are following the playbook the major four established years ago, while those incumbents, having already built out their default architecture, are now directing visible compliance effort toward a category that is easier to announce and harder to verify.

Age assurance: measurable but not verified

Age assurance (mechanisms used to estimate or verify the age of users in order to apply age-appropriate protections) is the area where regulation’s effects are most legible, and Table 1 shows why it is also the most contested. Of 70 platforms assessed, 46 were found to use at least one age assurance mechanism; the most widely used method is facial age estimation, followed by photo ID matching and credit cards (Wood, 2026). Many platforms cite the OSA directly as the reason for introduction. Yet Internet Matters (2026), in an early study conducted after the OSA’s children’s codes took effect in July 2025, found that almost half of children considered age checks easy to bypass and around a third reported having done so; more than a quarter of parents said they had allowed their child to bypass them. Age assurance is simultaneously regulation’s most measurable output and one of its least verified outcomes.

The AI gap

A third finding concerns artificial intelligence, which Wood (2024) barely addressed and Wood (2026) treats as an active regulatory gap. Analysis by Lorna Woods suggests that some standalone chatbots may fall outside the OSA where they do not qualify as user-to-user services or search engines, leaving important gaps and unresolved boundary questions (Woods, 2025). The AADC has not been updated to address AI systems, and the EU AI Act contains no presumption that systems likely to be accessed by children are high-risk by default. Given these regulatory gaps, Wood (2026) concludes that it is unclear what has driven recent safety changes by AI platforms, but suggests that US court cases concerning child suicides and AI chatbot use, alongside enacted or proposed state-level legislation, may have contributed. Where the EU/UK safety-by-design architecture does not reach a technology, litigation may be beginning to fill part of the gap. But litigation is reactive by nature and does not necessarily operate within the children’s rights frameworks, such as the UN Convention on the Rights of the Child, that have shaped a decade of EU and UK policy.

What needs to change

What connects these findings is a structural problem that no amount of additional compliance activity can resolve on its own: the regulatory architecture currently rewards self-reported change over verified outcomes. The 2026 report’s recommendations point toward a product safety model: pre-market risk assessment approval by Ofcom (the UK regulator responsible for implementing the Online Safety Act) before high-risk features reach children, independent testing and certification, and mandatory sign-off by the ICO (the UK data protection authority responsible for the Age-Appropriate Design Code) on data protection impact assessments for new uses of children’s data (Wood, 2026).

Three implications of this shift matter most, in my view.

First, and most urgently, the OSA’s Section 49(1) safe harbour, under which compliance with Ofcom’s codes is treated as fulfilling the underlying safety duty, needs to go. As long as meeting the code counts as meeting the duty, codes become ceilings rather than floors. Platforms with the longest regulatory track record are already demonstrating what happens when compliance becomes an end in itself: effort migrates toward the category that is easiest to document, not the one most likely to protect children.

Second, the research infrastructure needs to catch up with the regulatory ambition. Counting documented changes has a limited shelf life as evidence of protection. Independent and replicable effectiveness testing is not a luxury for future research agendas. At scale, such testing will require mandatory access to platform data, building on the mechanism already established under Article 40 of the DSA for very large online platforms and search engines. Without it, we are, in effect, taking platforms at their word.

Third, as the product safety model gains traction in UK and EU policy debate, I would argue that the question of whose standards and for which children deserves to be asked now, not retrospectively. The regulatory frameworks assessed in both reports were designed primarily around children’s experiences and platform markets in the Global North. Before this model is exported (and it will be) researchers and policymakers alike need to ask whether it is calibrated for the digital environments, risk profiles, and enforcement capacities of the contexts it will enter. This is not a reason to delay. It is a reason to design better.

We now know regulation can move platforms. What remains to be seen is whether it can move them in ways that actually protect children.