{{item.title}}
{{item.text}}
{{item.text}}
Young users are spending more time in digital ecosystems than ever before. The average 7- to 14-year-old spends 3.6 hours per day on recreational screen time, and they’re doing more than just consuming content—97% report making independent purchasing decisions at least some of the time. The platforms themselves continue to change as well, with generative AI (GenAI) chatbots and AI-driven experiences rapidly becoming part of how children interact online. In parallel, online harms are evolving, with GenAI introducing new threats—from deepfake-laden content to emotional dependency on AI chatbots.
One emerging threat, AI-generated child sexual abuse material (CSAM), increased by 154%1 from 2024 to 2025, according to Internet Watch Foundation in the UK. Parents, guardians, regulators, and lawmakers are paying close attention to these shifts, recognizing that the online environment is becoming more complex and dangerous by the day.
Concerns about child safety are also shaping expectations of online platforms. In PwC’s Trust and Safety Outlook 2026 research, the areas most often ranked in respondents’ top three priorities for more company investment are controls over who can contact minors (44%), content moderation for harmful and inappropriate content (38%), and age assurance and verification (38%). These findings suggest that robust child safety measures are increasingly influencing platform trust, adoption, and retention.
Harms facing minors are not new, but AI technologies, particularly GenAI models and AI-powered chatbots, are reshaping how they manifest. Rapid innovation, marked by the continuous release of more capable AI models and the rapid integration of AI into user experiences, is accelerating their reach. Meanwhile, increased personalization and more human-like interactions are deepening engagement and dependency, creating new risk vectors.
| Risk | Current threats | Emerging threats |
| Sexual exploitation and abuse |
|
|
| Financial exploitation and fraud |
|
|
| Peer abuse and harassment |
|
|
| Harmful or inappropriate content |
|
|
| Psychological and developmental harm |
|
|
Framework and analysis by PwC
Policymakers are shifting away from voluntary self-policing toward regulatory frameworks that place affirmative obligations on platforms to protect children, with growing consensus around core themes, such as age assurance, parental controls, and data governance. However, meaningful variation exists in how these obligations are defined and enforced.
Existing compliance programs may not be scoped for the full range of emerging exposures. Most frameworks were not designed with LLMs or GenAI in mind, leaving platforms with limited regulatory guidance precisely where risks are evolving fastest. Requirements diverge significantly across jurisdictions: on age thresholds, allocation of responsibility between platforms and parents, and the degree of prescriptive versus principles-based obligations.
Beneath these regulatory gaps are broader unresolved questions about where responsibility should sit among platforms, parents, and governments, and how much autonomy young users should have. According to PwC’s Trust and Safety Outlook 2026 research, 18% of US guardians say the single most important factor in deciding whether to allow their child to use an online platform is their child’s age, maturity, and ability to use the product responsibly.
Other leading responses highlighted factors within a platform’s control, including age-appropriate design and default settings (14%), controls over who can contact or interact with their child (12%), and the platform’s developmental or educational value (11%). For platforms, the risk of being caught underprepared is real.
| Regulation | Jurisdiction | Key obligations | Age threshold | Status |
| COPPA Rule (2025 amendments) | United States | Strengthened parental consent, data-use limits, targeted advertising restrictions for children | Under 13 | In effect |
| Online Safety Act | United Kingdom | Risk assessments, proportionate safety measures for services likely accessed by children, duty of care obligations | Under 18 | In effect |
| Digital Services Act (DSA) | European Union | Child-specific protections and systemic risk assessments for very large online platforms (VLOPs) | Under 18 | In effect |
| GDPR | European Union | Privacy by default, restricted profiling, best interests design for child users | Under 16 | In effect |
| Age-Appropriate Design Code (Children’s Code) | United Kingdom | Privacy by default, restricted profiling, best interests design for child users | Under 18 | In effect |
| Kids Online Safety Act (KOSA) | United States | Duty of care to prevent harms, default privacy settings, limits on addictive features for minors | Under 17 | Pending federal passage |
Facing a rapidly evolving landscape of harms and increasing regulatory burden, online platforms should use a proactive, systematic approach to child safety. Leading online platforms are taking systematic approaches across the five stages of the Trust and Safety life cycle—combining preventive and detective measures to prepare and continuously monitor threats at scale.
The next step is building the infrastructure to decide faster, as threats, regulations, and product launches rarely arrive in sequence. For example, a new AI feature ships while a regulatory consultation is still open. Or a new harm emerges while a policy update is still in review. Platform providers that have invested in the life cycle will be able to make these calls with greater speed and confidence, drawing on live regulatory intelligence, pretested policy positions, and enforcement systems already calibrated for emerging risks. Those that haven’t may find themselves making high-stakes decisions reactively, without a strong basis to justify them.
The commercial implications are real. Parents are already making platform choices based on child safety signals, and that pattern will likely only intensify as AI-enabled harms become more visible and regulation more demanding. Platforms that lead on child safety won’t just reduce regulatory exposure; they’ll build the kind of durable trust with users that translates into adoption, retention, and long-term competitive advantage.
{{item.text}}
{{item.text}}