Has child safety become the universal justification for digital surveillance?
It has also become the reason for a growing range of technological restrictions.

Image by Cybernews.
- Australia’s under-16 social media ban showed little immediate effect; more than 85% of participants still used covered platforms.
- Experts warn age checks can push governments toward wider identity systems and larger stores of sensitive data.
- Scanning private messages could weaken privacy and create tools that governments or attackers may misuse.
- Researchers urge stronger investigations, safer platform design, education, and prevention instead of broad technical restrictions.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Protecting children online is one of the few political objectives almost nobody is willing to challenge – and that consensus is understandable. Children face real harms online, from sexual exploitation and grooming to addictive platform design, harassment, and exposure to inappropriate content.
But precisely because the objective is so difficult to oppose, child safety has also become an extraordinarily powerful justification for a growing range of technological restrictions: age verification, social media bans, identity checks, and proposals to scan private communications.
The question increasingly confronting policymakers is not whether children should be protected, but whether these measures actually protect them and what infrastructure governments are building in the process.
Australia offers an early warning.
The Australian experiment
In December 2025, Australia began enforcing its world-first Social Media Minimum Age Act, which requires designated platforms to take reasonable steps to prevent children under 16 from having accounts.
Yet an observational study published in The BMJ in June 2026 found little evidence of an immediate substantive effect on teenagers’ social media use.
Three months after implementation, more than 85% of participants under 16 still reported using platforms covered by the legislation. Most continued to use their own accounts, and some reported circumventing restrictions through fake accounts or private browsers.
The fact is, daily social media use remained stable among 12- and 13-year-olds and fell only modestly among 14- and 15-year-olds.
The researchers cautioned that the findings cover only the early months of implementation and should not be read as a definitive verdict on the policy. However, the results illustrate a fundamental problem confronting governments pursuing age restrictions: teenagers are often more technologically resourceful than the systems designed to exclude them.
Europe’s approach
The Australian experiment matters beyond its borders, with countries across Europe now considering their own restrictions on young people's access to social media. Meanwhile, age assurance is increasingly becoming part of the wider debate over how people should prove who – or how old – they are online.
At the same time, the European Union has been wrestling with an even more consequential child-safety dispute: how far digital platforms should be required or permitted to inspect private communications in order to detect child sexual abuse material (CSAM).
The proposed permanent EU framework is commonly known among experts as "Chat Control." Negotiations remain ongoing, while disputes over temporary rules allowing voluntary detection have already exposed the central fault line: whether combating horrendous crimes against children requires weakening the confidentiality of digital communications.
Scanning of private communications
Bart Preneel, professor of cryptography and information security at KU Leuven, argues that this is the wrong technological approach to a very real problem.
"Abuse of children and distribution of CSAM are serious societal problems that require a substantial effort from law enforcement," he said, stressing the need for cooperation with digital service providers.he said, stressing the need for cooperation with digital service providers.
But large-scale scanning of private communications, Preneel argues, is neither the most effective response nor a proportionate one.
"If this scanning is extended to end-to-end encrypted messages through client-side scanning, it becomes a highly pervasive measure that undermines the core of protection offered by the encryption and breaks its end-to-end nature," he said.
End-to-end encryption is designed so that only the people communicating can read the messages. Client-side scanning attempts to circumvent that obstacle by analyzing material on a user's device before or after encryption.
For governments seeking CSAM, this can appear to offer a compromise: preserve encryption while still detecting illegal material. Cryptographers have repeatedly challenged that premise.
Preneel warns that scanning mechanisms can be evaded, generate false positives, and introduce additional complexity into systems that are supposed to remain secure. Perhaps more significantly, once a device contains an infrastructure capable of inspecting content against predetermined criteria, the question becomes who determines what it should look for.
"Client-side scanning also presents serious risks in terms of function creep and abuse,"Preneel said, including the possibility of identifying users sharing lawful material critical of a government.
That is why the dispute extends beyond CSAM. A surveillance mechanism does not inherently understand the political justification that led to its creation. Technologically, infrastructure designed to detect one category of content can potentially be adapted to detect another.
Age verification raises a different but related set of problems.
Age verification workarounds are easy
Not every system requires people to upload passports or other identity documents. Preneel points out that privacy-preserving technologies such as anonymous credentials can minimize the amount of information disclosed about a person, but even well-designed systems face another obstacle: circumvention.
Age controls are relatively easy to evade through mechanisms such as VPNs, he said, while broad restrictions can prevent young people – particularly members of minority or vulnerable groups – from accessing information that may be important to them. "In the long run, age verification undermines the open nature of the internet," Preneel said.
The privacy problem becomes substantially worse when age assurance is connected with already extensive digital identity ecosystems.
Brazilian technologist and privacy expert Yasodara Córdova says age verification itself does not necessarily require collecting identity data. In principle, systems can establish that a person is above a particular age without identifying them.
But she warns that the incentives surrounding digital identity point in the opposite direction.
“In countries that already have a digital identity infrastructure based on the premise of surveillance, such as Brazil and the United States, this will be difficult, because there is already an industry that collects and centralizes data on children and young people – including biometric data,” warned Córdova.
If age information becomes another attribute attached to those identity profiles, Córdova sees both privacy and cybersecurity risks.
"From a technical point of view, it is a security and privacy nightmare because all the data collected is accessible to all kinds of malicious attackers,"she said.
Rather than making children safer, badly implemented age-verification systems could therefore produce new databases containing precisely the information criminals need for identity fraud.
Córdova makes a similar argument about weakening encrypted communications. Vulnerabilities do not distinguish between governments with legitimate investigations and criminals seeking access. If a security system is deliberately weakened, attackers can exploit the same weakness.
“If the industry adopts a centralized age verification model – in which identity credentials are used to create a profile of everyone –protection for encrypted communications is weakened by default, we will face serious problems,” she warned once again, also noting that “I very much appreciate the comments made by Meredith Whittaker, CEO of Signal, when she argues that measures to weaken encryption have no proven effectiveness, particularly in combating the sexual exploitation of children.”
What are other possible solutions?
For Córdova, the alternatives are less technologically spectacular but potentially more effective: target the financial networks that monetize child sexual exploitation, strengthen specialized digital-investigation units, improve international cooperation among police and platforms, and invest in prevention.
She adds, “The exemplary punishment of criminals who abduct children and adolescents for this purpose is something that rarely occurs with the necessary severity in countries such as Brazil and the US, amongst others.”
Preneel likewise argues that law enforcement should focus resources on infiltrating criminal networks involved in the production and commercial distribution of CSAM. Platforms, meanwhile, can make reporting easier and respond more rapidly when abusive or clearly illegal public content is identified.
The distinction matters because some of the most politically attractive solutions focus on restricting potential victims rather than redesigning dangerous environments or pursuing perpetrators.
"Policymakers focus on technology measures because they seem to present quick fixes to a difficult societal problem," Preneel said. Even when those solutions are ineffective, governments can at least demonstrate that they have acted.
That political incentive is especially powerful where children are concerned.
Jessica Galissaire, senior policy researcher at Interface, an independent expert organization specializing in information technology and public policy, researches the protection of minors in digital environments. She says the debate too often presents children's privacy and children's safety as though policymakers must sacrifice one to obtain the other.
Children have the right to freedom of expression, too
Children, she points out, have rights to privacy, expression, and information just as adults do. They “indeed have several fundamental rights, like freedom of expression, the right to be informed, the right to privacy, etc., that are guaranteed by the International Charter on the Rights of the Child and its accompanying General Comment 25, which states that children’s rights must be upheld also online, not only in the physical world,” she said.
Restrictions on children's expression and access to information, it states, should be lawful, necessary, and proportionate. That complicates the seemingly intuitive idea that removing children from parts of the internet automatically constitutes protection.
“The measures currently being debated around the world, like banning kids from social media under a certain age, greatly infringe upon children’s right to access information, freedom of expression, and other fundamental rights, including their privacy. I would go even further than saying that politicians tend to treat privacy and safety as opposing interests,”noted Galissaire.
Galissaire argues that these trade-offs need to be subjected to proper assessments of necessity, proportionality, and effectiveness rather than resolved by simply declaring safety the overriding concern.
"Nothing proves that age-gating some online services will lead to children being safer online," she said.
That does not mean the harms are imaginary. Galissaire stresses that dangers facing young people online are increasingly well documented. The problem, she argues, is that the political urgency to "do something" can make certain interventions attractive before there is strong evidence that they work.
As someone advocating a more nuanced approach, she says she has sometimes been accused of siding with technology platforms or of not wanting to protect children at all. That reaction illustrates the political power of the child-safety frame. Once a measure is presented as protecting children, opposition to the particular method can easily be interpreted as opposition to the objective itself.
"Politicians do not want to be seen as 'doing nothing' to protect children," Galissaire said. The result, she argues, is a preference for highly visible "easy fixes" whose effectiveness remains uncertain.
Her alternative echoes the arguments made by Córdova: to look more closely at the platforms themselves.
"If we really want to protect children online, we need to go after the designs and features that are knowingly developed by some of the biggest platforms, and that are at the origins of most of the harms children encounter online," she said.
That moves responsibility away from forcing every user to identify themselves or excluding young people from digital spaces, and towards examining recommendation systems, addictive product features, and the design decisions that shape what users encounter.
The solution?
Australia’s experiment has already demonstrated one of the oldest problems in internet regulation: technical restrictions can change user behavior without necessarily eliminating the underlying activity.
Block one route, and users find another. Require proof of age, and some teenagers lie, borrow credentials, open multiple accounts, or use tools designed to obscure their location.
Governments can respond by tightening verification further, but doing so creates a ratchet effect: Weak verification fails, producing demands for stronger verification; stronger verification requires more reliable information about users; and increasingly reliable identification can mean collecting more sensitive data or making anonymous access harder.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The same logic applies to private communications. If conventional scanning cannot inspect encrypted messages, pressure grows for mechanisms capable of reaching content before encryption protects it. At each stage, the justification remains compelling: protect children. But good intentions do not determine whether a technology is effective, secure, or proportionate.
Experts point towards a more uncomfortable conclusion: protecting children may require slower, less politically gratifying interventions – better investigations, safer platform design, social services, education, and prevention – rather than technological systems promising a simple solution.