Online Safety Is More Than an Age Limit

My inbox is flooded with questions from journalists that center around one question: “do you favor a social media ban for youth?” In short, no, I do not. Below I offer a lengthy explanation as to why. Happy reading.

The Framing

Europe’s debate about children’s online safety is becoming increasingly focused on age limits. But removing young people from regulated platforms will not necessarily remove the risks they face. We need to regulate harmful systems, require safer design ,and preserve children’s ability to participate in digital society. The debate about children and social media is often presented as a simple choice. Either governments introduce a firm age limit, or they fail to protect children from harmful content, problematic design, cyberbullying and commercial exploitation.

It is an understandable framing. The harms are real, and the frustration of parents, educators, and policymakers are justified. Too many digital services were built around engagement, data collection, and advertising before the needs and rights of children were seriously considered.

The choice between a ban and inaction is a false one

Children’s online safety cannot be reduced to the question of whether they should be permitted to open an account. Safety depends on what young people encounter, how services are designed, which commercial incentives shape their experiences, what protections are active, and whether platforms can be held accountable when those protections fail. The more important question is therefore not simply: At what age should children be allowed online? Instead, we should be asking “What kind of digital environment are we allowing them to enter?”

As I shared earlier this week, I participated as an academic expert in the Special Panel on Child Safety Online, contributing research-based knowledge about how children and adolescents use and experience digital technologies. The resulting report, which I reviewed here, is worth a read. One of the report’s main strengths is that it treats online safety as a developmental, systemic, and children’s-rights issue. A three-year-old, a twelve-year-old and a seventeen-year-old do not have the same vulnerabilities, abilities, or need for independence. A credible safety policy must recognise those differences, The report therefore places considerable emphasis on safety by design, age-appropriate default settings, digital competence, support for parents and schools, youth participation, independent research (YES!), and clear responsibility for technology companies.

That last point is essential. Platforms should be required to demonstrate that their services are safe for minors. The burden of creating safety cannot continue to rest primarily with children and parents, who are expected to navigate complex systems designed by some of the world’s most powerful companies.

Account removal is not the same as risk removal

And about bans: let me be clear, I do not support a general prohibition that excludes every young person below a single age from social media. That is not because I believe the problems have been exaggerated. Young people can encounter cyberbullying, sexual exploitation, harmful recommendation loops, manipulative commercial practices, unrealistic social comparisons, and content that is inappropriate for their developmental stage.

The problem is that a general ban does not necessarily resolve those risks. It may simply move them.

Young people do not automatically stop using a service when official access is closed. They may watch without logging in, provide an inaccurate date of birth, use someone else’s account or migrate to less moderated spaces with fewer protections. When that happens, parents, educators, researchers and responsible service providers may lose visibility into children’s online behaviour. A child who previously used an identifiable youth account with age-appropriate settings may return through a route with fewer safeguards and less supervision. In short, we removed the account without removing the exposure.

Early evidence from Australia illustrates why we should distinguish carefully between the implementation of an age restriction and its actual safety outcomes. Millions of accounts may be removed or restricted, but that does not in itself prove that harmful experiences have disappeared. It is too early to draw a definitive conclusion about the long-term effects of the Australian approach. But the initial reported evidence should make us (very) cautious about claiming that account deletion automatically produces safety.

“Social media” is not a single product

Another point worth mentioning: the term “social media” is frequently used as though it describes one uniform category of technology. It does not. A messaging service, a video platform, a multiplayer game, a public discussion forum, and a short-form recommendation feed may all contain social features, but they involve different patterns of use, different risks, and different opportunities. Even within a single platform, the experience can vary considerably. Watching an educational video is not the same as receiving unsolicited messages. Searching for information is not the same as being carried through an endless personalised feed. Participating in a moderated classroom environment is not the same as entering a public comment section. The relevant unit of regulation should therefore not always be the platform as a whole. In many cases, it should be the specific feature, design mechanism, or interaction.

We should ask:

  1. Which functions create a foreseeable risk for children?
  2. Which default settings reduce that risk?
  3. Which recommendation patterns repeatedly expose young people to problematic content?
  4. Which contact features make unwanted interaction possible?
  5. Which protections have been independently shown to contribute to safer online experiences?
  6. Which features empower children in healthy ways?

YouTube is one example of why these distinctions matter (for transparency, I’m an advisor for YouTube). The service has introduced measures intended to reduce repeated recommendations of certain potentially problematic content to teenagers. Pause and bedtime reminders are enabled by default for teen accounts. Families can use supervised experiences and link accounts through the Family Center. YouTube Kids provides a separate environment for younger children. These measures do not make YouTube perfect or risk-free. No platform is. And I still think there is more work to be done in this specific ecosystem. In general, platforms must be examined critically, improved where necessary, and subjected to independent evaluation. But these efforts by YouTube, to me, demonstrate why generic prohibition language is inadequate. When we treat every platform as an identical harmful product, we overlook the protective infrastructure that has already been developed and, as a result, and may remove young people from the very systems through which those protections are delivered. (In this case: the “better (read: more age-appropriate” YouTube variant is no longer available in Australia, so children are likely instead opting for the no-account route … without any of the guardrails that were designed for them 😩).

Age assurance should create safer access, not only deny access

Some knowledge of a user’s age can help a digital service provide a more appropriate experience. Age assurance could be used to activate safer default settings, restrict contact from unknown adults, adjust recommendation systems, reduce data collection, or direct a young person toward a supervised version of a service. That said, age verification is frequently discussed as though only children would need to prove their age. In practice, a universal age threshold may require platforms to determine whether every account holder (including every adult) is above or below the limit. That turns age assurance into a major privacy question for society as a whole.

What information should a person be required to provide to access a digital platform? Will the system use an identity document, bank information, an electronic identity, a facial scan or behavioural signals? Who will process the information? Where will it be stored? How long will it be retained? Could it later be used for another purpose? What happens if the database is breached or the system classifies someone incorrectly? A privacy-preserving system that confirms only that a user is above a threshold is preferable to one that repeatedly requires people to submit copies of identity documents. In that way, I find the recent European work on systems that can provide a simple “above the required age” response without disclosing a person’s exact age or identity promising (but still have concerns). Still, privacy-friendly technology does not eliminate the need for democratic scrutiny. Age-assurance systems must be proportionate, data-minimising, and secure. Their error rates must be transparent. Users must have accessible ways to challenge an incorrect decision. They must also be inclusive. Not every young person has a suitable identity document, a bank account, a personal device or the digital skills needed to complete a verification process. Children in vulnerable circumstances may be the least able to navigate complex identification systems, while also being among those most dependent on online access to information and support.

Throwing the baby out with the bath water

The age-limit debate also pays too little attention to the organisations that use digital platforms to serve young audiences. Social platforms are not only commercial systems. They are distribution channels for journalism, science, education, culture, health information and civil-society organisations. Youth-focused media such as news services, educational programmes and children’s magazines use these platforms not only to distribute information, but also to understand what matters to their audiences. The interaction is part of the public function they perform. Removing young people from these services does not remove their need for reliable information, social connection, or participation. Reducing harm should not require removing everything that is educational, socially valuable, or supportive.

Even more, I notice that discussions of online safety often position children only as vulnerable recipients of technology. Children are vulnerable in important ways, and adults have a responsibility to protect them. But children are also rights-holders. They have rights to information, education, participation, expression, association, play, privacy, and protection. Those rights must be balanced. Protection cannot be used as an automatic justification for excluding young people from spaces in which contemporary social, cultural, and political life takes place.

A seventeen-year-old preparing to vote, applying to university, seeking health information or participating in a civic campaign has a legitimate interest in digital participation. The answer cannot be to treat that young person as developmentally equivalent to a seven-year-old.

Good policy should support a gradual transition toward autonomy. Younger children need highly protected and supervised environments. As children grow, they should gain greater independence alongside stronger skills, clearer rights, and appropriate safeguards. That is more difficult than choosing a single age and drawing a line. But difficulty is not a reason to adopt a policy that is easier to communicate than it is to justify.

I’ve said it before and I’ll say it again – ban the system, not the child

Europe has an opportunity to move the online-safety debate beyond the narrow choice between a blanket ban and the status quo.

We should prohibit manipulative design practices that create disproportionate risks for minors. We should restrict commercial systems that depend on intensive tracking and profiling of children. We should require age-appropriate defaults, safer recommendation systems, meaningful parental and youth controls, and rapid responses to serious harm. We should also require independent access for researchers, transparent reporting, and credible evidence that safety interventions work. Companies should not be allowed to declare their own systems safe without scrutiny. Regulators should not measure success only by counting deleted accounts. And children should not be expected to carry the primary responsibility for protecting themselves from systems they did not design.

The objective should not be to remove children from digital society. It should be to create a digital society in which they can participate safely, gradually, and with increasing independence. Change harmful business models. Regulate risky design mechanisms. Require providers to build safe, age-appropriate systems.

Don’t ban the child.