Editorial by Barbara Lazarotto
The debate over how to regulate youth’s online presence has been growing worldwide. Different solutions are being constantly proposed at both the international and EU levels, but not without controversy. These solutions range from platform-based solutions, such as age-assurance mechanisms and CSAM scanning tools, to a total ban on children in online environments as implemented in Australia.
Naturally, this discussion is complex. As a millennial who grew up during the rise of the internet and household computers, I had a childhood without the internet, but an adolescence with unregulated access, which allowed me to observe how it can be harmful and to have experiences I wouldn’t have had otherwise. With this background in mind, in this editorial, I aim to explore the proposed solutions and the pushback from minors, underlining the importance of hearing their voices.
Mapping the Multi-sided Responses
As mentioned, different proposals on how to protect minors online have emerged worldwide, moving beyond simple content removal toward structural and systemic changes.
At the EU level, the landscape is currently defined by the transition from temporary measures to permanent law. The interim CSAM Regulation, adopted in July 2021, allowed service providers like WhatsApp and Facebook Messenger to voluntarily detect and report CSAM. However, with this interim measure set to expire in April 2026, the focus has shifted to the permanent “CSA Regulation.” On November 26, 2025, the EU Council agreed on a common negotiating position for this new law, which notably maintains the voluntary nature of scanning for encrypted messaging services. This was a pivotal concession following years of pushback from academics and civil society regarding the necessity and proportionality of the tool.
In parallel, the “Safety by Design” framework under the Digital Services Act (DSA) seeks to address the root of the problem. Article 28 DSA and the Commission’s Guidelines on the protection of minors require platforms to ensure a high level of privacy, safety, and security of minors by design and by default, explicitly targeting interface architectures and engagement-optimizing features such as recommender systems, default visibility, and addictive design patterns. This design-based approach is operationalized through the EU’s emerging age-verification and age-assurance infrastructure, which enables platforms to apply differentiated default settings to minor accounts at scale. Against growing calls in several Member States for outright social-media bans for minors, the DSA thus represents a regulatory strategy that seeks to make platforms structurally safer for children rather than excluding them.
A more radical model has emerged in Australia. On December 10, 2025, Australia enforced a world-first blanket ban on social media for children under 16. Unlike the EU’s focus on safer design, the Australian Social Media Minimum Age Act places the onus on platforms to take “reasonable steps” to block access entirely. Early data from January 2026 suggests the scale of this experiment is massive, with over 4.7 million accounts reportedly deactivated in the first month alone.
The United Kingdom is watching this experiment with intense scrutiny. While the UK’s Online Safety Act (enforced throughout 2025) emphasizes age verification and safety duties, the government launched a new consultation in January 2026 to consider an “Australia-style” ban. However, regulators are already facing practical challenges. While early enforcement has coincided with sharp declines in traffic (reportedly around 77%) to regulated sites like Pornhub, later VPN use has risen sharply, as users seek to circumvent age checks and geolocation blocks.
At the same time, the government’s long-running digital ID and age-verification agenda has seen repeated recalibration, with earlier plans for mandatory online eID having stalled and civil liberties groups raising privacy concerns, contributing to a broader policy review that now includes an “Australia-style” social media ban under consultation. Evidence from Australia’s roll-out suggests that circumvention technologies such as VPNs and simple disguises can undercut the practical effect of age bans in the absence of robust verification mechanisms, and that platforms may need to rely on behavioral indicators and multi-signal detection to enforce such measures effectively.
Another major development comes from Brazil with the passing of the new Law 15.211/25 (Digital ECA – English translation), which will enter into force in March 2026. Digital ECA marked a milestone as one of the world’s first comprehensive laws protecting children online. It applies to any digital service likely to be accessed by minors and requires providers to embed child protection by design and by default, including reliable age-verification systems, guardian-linked accounts and parental control tools, and high-privacy default settings for children. The statute places strict limits on behavioral advertising, profiling, and manipulative monetization practices, while imposing duties to detect, remove, and report harmful content involving minors.
Across all these models, age verification remains the central technical hurdle. Whether the goal is to restrict access or to ensure age-appropriate design, these laws raise urgent questions about data transparency. Critics warn that these mandates create “honeypots” of sensitive data, particularly as platforms turn to third-party face-scanning or biometric technologies to prove compliance. Additionally, research conducted in Brazil shows that 30% of Brazilian teens have bypassed age verification mechanisms.
Guidance, Not Control: Supporting Children’s Agency
Some of these measures have met with resistance. In Australia, two teens, Noah Jones and Macy Neyland, along with a rights organization, are challenging the country’s social media ban for those under 16 in the country’s Supreme Court, arguing that the measures are disproportionate and trespass on the “constitutional right of freedom of political communication.” Noah has said that these young teens are the “true digital natives” who “want to remain educated, robust, and savvy in our digital world” while Macy said young people were the “voters of tomorrow” and should not be banned from expressing their views.
In Brazil, following Roblox’s recently implemented, globally mandatory facial age checks to restrict children from chatting with older users and limit communication to similar-age groups, signaling a growing refusal among minors to be passive subjects of digital policy discussions, has emerged.
Children protest on Roblox against the restriction of chat use
While critics often dismiss these protests, they signal that when minors are systematically excluded from conversations, the only remaining avenue for their interests to be considered is the very activism that adults often seek to suppress. Furthermore, there is a clear distinction between “protecting” and “disempowering” minors.
This move follows a landmark University of Manchester study recently released, which tracked 25,000 teenagers and argued that “screen time” itself is not a direct cause of mental health issues, suggesting that a ban might be a blunt instrument for a nuanced problem. This is in tune with Leandra Voss, a member of ctrl+alt+reclaim, opinion: “Politicians should listen to young people’s experiences when regulating. We’re asking for platforms to stop profiting from our harm. To keep us safe they need to fix the algorithms and the design of the platforms – making them less addictive and exploitative for young people. Fixing the problem at the source will be more effective than blunt bans.”
While many of these bans are designed to protect minors from harm, some are already acutely aware of the digital risks and injustices they face. For these “politicized” children, the worst possible outcome is being made aware of a threat and then stripped of the agency to respond. Rather than shielding them, blanket bans often create a state of forced powerlessness. Yet the responsibility for navigating this digital landscape should not rest solely on the state, platforms, or the child. Parents or caregivers must also be included in the equation.
True protection does not come from silence, but from open conversations among caregivers, minors, policymakers, and platforms, involving continuous negotiation over the guidance of the adult and the evolving competence of the child, helping to develop an adequate sense of belonging and empowerment. In this context, platform parenting control tools must be designed with accessibility at their core, since not all caregivers possess the digital literacy required to navigate these systems and guide their children effectively, rather than simply relying on blunt, state-mandated bans.
