In this issue: The European Commission’s age verification app for online platforms is now “technically ready”. Florida’s Attorney General launches an investigation into ChatGPT over public safety and national security concerns. Roblox is introducing age-gated accounts and expanded parental controls for under-16 users. And Google Gemini is updating its model to strengthen protections for minors and improve responses to acute mental health situations.
Vys consultants have been on planes and trains over the last few weeks! We were at the Trust & Safety Summit in London, the Semafor World Economy Forum in Washington, DC, the GNI Rights & Risks Forum in Dublin, and the ASU+GSV Summit in San Diego. If you were unable to make one or more of these convenings but would like to chat about key learnings, reach out to us via hello@vyanams.com.
The European Commission’s President Ursula von der Leyen announced that the EU’s long-awaited age verification app for online platforms is “technically ready”. The open-source application would require users to upload their passport or ID to confirm their age anonymously, and is compatible with computers and mobile devices–reflecting our broader prediction that age assurance is becoming infrastructural. In parallel, EU’s digital chief Henna Virkkunen announced the bloc’s plans to establish a coordination mechanism to harmonize national implementation of age verification. Within hours of its release, however, cybersecurity experts claimed to identify glaring privacy concerns, with a security consultant claiming to have hacked the app in under 2 minutes. Vys founder Vaishnavi J spoke to CNET about the app’s accessibility concerns, as digital ID access remains unevenly distributed and age-gating measures may prove insufficient deterrents for tech-savvy minors.
(As companies grapple with age assurance implementation, VYS offers an Age Assurance Implementation Handbook–a practical roadmap for teams building out their strategy.)
Following European lawmakers’ failure to extend the ePrivacy directive, a measure governing how online platforms detect and remove child sexual abuse material (CSAM), Google, Meta, Snap, and Microsoft released a follow-up statement affirming that they would continue to proactively scan for CSAM on their respective platforms. In the statement, the companies condemned the regulatory gap created by the expiration of the ePrivacy directive: “We are disappointed by this irresponsible failure to reach an agreement to maintain established efforts to protect children online.” Lawmakers justified their decision by citing risks to users’ privacy rights, with former Parliament member Patrick Breyer claiming that “just as the postal service isn’t allowed to simply open our physical letters, the indiscriminate scanning of our private digital messages must remain strictly off-limits”.
Beginning April 7, the UK’s media watchdog Ofcom requires online platforms to report detected and unreported CSAM to the National Crime Agency, a law enforcement agency dedicated to countering serious and organized crime. The duty applies to user-to-user services, with expectations of expanding to search services.
Greece is the latest country to issue a social media ban for under-15 users. Prime Minister Kyriakos Mitsotakis described the restriction as a “difficult but necessary” measure, citing minors’ rising anxiety and sleep problems due to platforms’ “addictive design.” The ban, set to take effect by January 2027, would involve a state-backed application installed on children’s devices to enable parental controls and restrict minor access.
Across the Atlantic, Florida’s Attorney General James Uthmeier is launching an investigation into ChatGPT over public safety and national security concerns. Uthmeier promised that “subpoenas are forthcoming” after allegations revealed that the chatbot assisted a gunman in carrying out a campus attack on Florida State University in April 2025. Uthmeier also raised national security concerns by claiming that OpenAI’s data could potentially be exploited by China’s government. Uthmeier’s investigation comes amid OpenAI’s release of its Child Safety Blueprint, a three-part framework centered on modernizing laws addressing AI-generated and altered CSAM, improving provider reporting and coordinating systems, and embedding safety-by-design measures into AI models.
In the wake of the landmark social media addiction trial finding Meta and Google negligent for designing addictive features that harm young users, Massachusetts’ highest court ruled that a similar social media addiction lawsuit by the state’s AG could move forward. While Meta had previously sought immunity under Section 230 of the Communications Decency Act, a federal law shielding internet companies from lawsuits over user-generated content, the court rejected the defense by claiming that the lawsuit aimed to “hold Meta liable for its own business conduct” rather than the content itself. Meta pushed back on the court’s ruling, rejecting the “false distinction between content and platform design.”
Meanwhile, Massachusetts’s governor, Maura Healey, is also proposing a bill that would alter minors’ default settings on social media, mirroring our 2026 prediction that attention is shifting from access control to product governance. The bill would require companies to deactivate features like infinite scrolling, auto-play, and “addictive algorithms that target young people based on what they privately viewed in the past.” Healey’s proposal comes a week after state legislators passed a social media ban for under-14 users, with Healey describing her bill as “complementary” to the House legislation.
Indonesia is issuing a warning to Google for failure to ban under-16 users on YouTube. In a press briefing, Indonesia’s Communications and Digital Minister stated that YouTube did not demonstrate good faith in complying with the Child Protection in Digital Space Regulation, leading the government to issue a reprimand letter. If found non-compliant, sanctions could go as far as a block on the platform. Google did not respond to requests for comment.
A Tech Transparency Project (TTP) report found that Apple and Google’s app stores give increased visibility to ‘nudify’ apps–apps that can digitally strip users’ clothes off. The investigation additionally found that 31 nudify apps were rated as suitable for minors–an alarming finding given rising concern over deepfake scandals in schools. Since the report’s release, Apple and Google have respectively suspended many of the apps identified in the report.
Roblox is facing heightened pressure to strengthen its child safety protections. The company reached a $10 million settlement with Nevada over the platform’s alleged failure to protect minors; In addition to interface changes, the company must distribute resources to support in-state children’s programs, create awareness campaigns on online child safety, and hire a staff law enforcement liaison. Simultaneously, the Philippines continues its probe into Roblox, with a potential platform ban following concerns of minor abuse. Following a Senate inquiry, government officials chose to pursue a “compliance before restriction” approach to allow continued operations while mandating robust age verification, improved content moderation, and heightened safeguards for adult-minor interactions. Roblox is beginning a global overhaul of its safety systems by introducing age-gated accounts and expanded parental controls for under-16 users. By early June, accounts will be categorized into Roblox Kids (for users ages 5-8) and Roblox Select (for users ages 9-15). Accounts will present dynamically updated game catalogs based on content maturity labels and offer varying restrictions to user communications. The company is also enabling parents to block individual games, manage chat settings, and approve access to games restricted under the child’s account type.
(Exploring features or policies that support kids and teens? Reach out here to schedule a consultation.)
Instagram is planning an international rollout restricting content for teen accounts based on 13+ movie ratings. Under this new paradigm, the platform intends to reduce minor exposure to content with extreme violence, sexual nudity, and graphic drug use. However, Meta has previously moved away from associating the rating with the Motion Picture Association after receiving a cease-and-desist letter about an alleged trademark infringement. The company also released a new setting, ‘Limited Content’, that would enable parents to impose stricter content filters to prevent teens’ exposure to inappropriate comments under posts. The setting was previously launched in October 2025 in the UK, the US, Australia, and Canada.
Google Gemini is updating its model to strengthen protections for minors and improve responses to acute mental health situations. These updates include tighter persona safeguards to prevent the chatbot from presenting itself as human or a companion, avoiding language that simulates intimacy, and adding measures to reduce bullying and harassment. The company is also streamlining its crisis support systems, including a $30 million investment in global hotlines. When conversations signal mental health concerns, Gemini will display a “help is available” module with immediate care resources, along with a one-touch interface for accessing crisis support services.
Discord is partnering with ECPAT International, a network of civil society organisations combating child sexual exploitation, to produce actionable resources that guide teens, guardians, and community moderators on maintaining healthy online communities. The forthcoming articles build upon ECPAT’s report on gender-sensitive game safety and design, a project supported by our Vys team. The report dives into practical recommendations for game designers and uncovered research suggesting that gaming norms and cultural expectations surrounding teenage boys make it difficult for minors to voice concerns.
In a Tech Policy Press article co-written by ROOST’s founding president Camille François, Margaret Mitchell, Yacine Jernite, Vinay Rao, and J. Nathan Matias, the researchers advocate for model cards to accompany child safety tooling–short documents detailing a model’s intended use, performance, and limitations. The researchers liken these documents to AI lab system cards, which provide transparent documentation about algorithmic performance. By adopting a similar approach, the researchers argue that model card templates provide an appropriately robust safety net to protect children, allowing teams to “build complementary safeguards, help route that content to human review, or discuss platform-level changes to take pressure off the automatic classification systems.” As the piece succinctly states, “Children deserve to be protected as robustly as possible—and that requires tools we can actually understand.”

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.