The T&S Handbook · Part 2: Build
Child safety and age assurance
How do you keep children safe on a product adults use too?
All chapters
Part 1: Before the first hire
Part 2: Build
- 4Writing policy and an enforcement ladder
- 5Detection and prevention
- 6Child safety and age assurance
- 7Standing up review operations
- 8Hiring and structuring the team
- 9Choosing vendors and tools
Part 3: Run
- 10Quality, calibration and appeals
- 11Measuring what matters
- 12Severe harm escalations
- 13Crisis response
- 14Moderator wellbeing
- 15Working with Product, Legal, Comms and leadership
Part 4: Scale and govern
General information, not legal advice. Laws differ by country, change often and apply differently to each service. Check with your own legal team or outside counsel before acting on anything here.
In one minute
Why it matters
Games and social apps are where children spend time with each other online, so they're also where offenders find them. Offenders often make first contact in a game or a public space and then move the child to a private messaging app where nobody is watching. Children also end up in spaces built for adults: in Thorn's late-2025 survey of US 9-to-17-year-olds, about one in six said they had used a dating app (Thorn, Youth Perspectives on Online Safety).
Regulators have stopped treating this as voluntary. The UK's Online Safety Act requires services likely to be accessed by children to assess the risks to them. Since July 2025, services that allow the most harmful content, such as pornography or content promoting suicide, self-harm or eating disorders, must use highly effective age assurance to stop children encountering it (section 12). The EU's Digital Services Act (Article 28) requires online platforms accessible to minors to take appropriate and proportionate measures for a high level of privacy, safety and security, and the European Commission's July 2025 guidelines spell out what that means for age assurance and default settings. In April 2026, Australia's eSafety Commissioner sent legally enforceable notices to the companies behind Roblox, Minecraft, Fortnite and Steam, asking what they do about grooming, sexual extortion and radicalisation. In the US, the 2024 REPORT Act made online enticement and child sex trafficking things platforms must report to NCMEC, not just images. The question is no longer whether you have a child safety policy. It's whether you can show it works.
What good looks like
What you have, and what you can show, at each stage
Early
A founder or first safety hire covers trust and safety, usually with under a million users.
What you have
A minimum age, safe defaults for every under-18 account, adults unable to message minors they aren't connected to, a way to report an under-age account, and a restricted path for child-safety escalations, with CyberTipline reporting set up if US law applies to you.
What you can show
Every under-18 account is on safe defaults. Time from a child-safety report to action.
Growing
A dedicated safety team, millions of users, and new markets or features on the way.
What you have
Age estimation where features open up (chat, voice, gifting), grooming signals on adult-to-minor contact with responses that build, a small group of trained child-safety reviewers, and re-checks when an account seems to have changed hands.
What you can show
Age-check coverage for the people using chat and voice. Confirmed unsafe-contact cases per 10,000 young users, split by how the contact started.
At scale or regulated
Tens of millions of users, a heavily regulated sector, or extra duties as a very large platform under EU or UK law.
What you have
Age assurance matched to each surface and each market's law, thresholds with one owner and a change log, investigators who map networks of accounts, cross-industry signal sharing, and children's risk assessments that are kept up to date.
What you can show
Adults found in teen spaces, children found in adult spaces, time to catch an account that changed hands, the share of cases caught before the move to another app, and a record that answers "why this account?"
How to do it
8 steps
Jump to a step
- 01Decide what each level of assurance unlocks
- 02Set defaults that limit who can reach a child
- 03Treat age as something that can change
- 04Detect grooming as a pattern
- 05Work the queue by risk
- 06Handle the account, not just the content
- 07Give the thresholds one owner, and write every change down
- 08Measure prevention, not just removal
- Step 01
Decide what each level of assurance unlocks
Most debate about age assurance is about the method: face scans, ID documents, parental consent. Start with a different question: what should each level of confidence let a user do?
What you know How you know it What it unlocks A typed date of birth The user told you Locked-down defaults: a private account, no discovery by strangers, no private messages from adults they don't know An age estimate Facial or behavioral age estimation Text and voice chat with people of about the same age A verified age, or a parent's sign-off ID check, a trusted third party or verifiable parental consent Anything that lets an adult reach a minor privately This puts friction where the risk is. Most users never feel it, because most features don't need more than the first row. Context and platform matter a great deal: a learning app for 8-year-olds and a game with an adult audience will draw these lines in different places.
The lines that matter most are usually 13, 16 and 18. They're where laws change (COPPA's under-13 consent rules, minimum ages for social media, adult content) and where your product should change what's allowed. Optimize your checks for getting those boundaries right, not for precision across every age.
Errors aren't equal. Put an adult in a teen space and they get annoyed, and some borrow a younger relative's account. Put a 15-year-old in an adult space and every protection built for them is gone. When you tune a threshold, weigh those two mistakes differently.
- Step 02
Set defaults that limit who can reach a child
The protections most likely to work act before any harmful message is sent. For every account you believe belongs to a minor:
- The account is private, and it doesn't show up in search or recommendations to adults.
- Adults can't message, friend or voice-chat with minors they aren't already connected to.
- Precise location is off, and photos have location data removed.
- Gifts, currency transfers and spending are limited, especially from new accounts.
- No advertising based on profiling. The DSA bans it when a platform is reasonably certain the user is a minor.
The UK's Children's Code expects high-privacy defaults like these for services likely to be used by under-18s. Your own data will usually point the same way. If you look at where confirmed cases began, many start with an open message from an adult the child didn't follow. That's a default setting to change, not a moderation problem to staff up for.
- Step 03
Treat age as something that can change
Most age checks happen once, at sign-up or when a feature unlocks. But accounts don't stay with one person. They get shared, sold and handed down to a younger sibling, and months later the person using the account no longer matches the age on file.
Decide what triggers a fresh look: a report that the user is under age, behavior that doesn't fit the age on file, a long-dormant account coming back, or signs that an account has been sold. When something looks off, you have three choices:
- Ban it. This hits many legitimate users and teaches people to hide their age better.
- Do nothing. This leaves the gap open.
- Put the account back on safer defaults right away and ask for a stronger check. The child stays protected while it gets sorted out, and an adult can clear it in minutes.
The third is almost always right.
- Step 04
Detect grooming as a pattern
Grooming rarely shows up in a single message. It builds over weeks. An adult account friends many younger players it has no connection to. It gifts currency early, asks about parents and whether the child is alone, moves the conversation to private voice, and eventually pushes for another app. Each step can be innocent on its own. Together they're a pattern.
So the response should build as signals stack:
Signals on an adult-to-minor contact Response One signal Log it. Nothing visible happens. Two or more within a short window Add friction: gifting limits, a safety prompt to the child, no new private channels between the two accounts. A request to move to another app, or for images, after that Restrict contact, and send the full history to a trained reviewer. Thresholds should come from data, not instinct. Test them against past confirmed cases and past false alarms. Set them where precision holds and the review team can keep pace. Revisit them every quarter, because offenders learn what triggers friction and route around it. Detection tools now exist to help, such as Thorn's conversation classifiers, Roblox's open-sourced Sentinel and specialist vendors, and which fits depends on your volume and how much engineering you can put behind it. A tool still needs your thresholds and your reviewers behind it.
Privacy sets the other boundary. Limit pattern detection to adult-to-minor pairs. Start with metadata (who contacts whom, how often, from how new an account) before reading message content. Agree retention limits with Legal before launch. Check each market: rules on scanning private messages vary, especially in the EU.
- Step 05
Work the queue by risk
There will be weeks when flagged relationships outnumber reviewers. When that happens, protective actions stay automatic, and the queue is worked by risk: requests to move off-platform first, then cases involving children under 13. A restricted account waiting a day for review is a cost worth paying.
The reviewers who handle these cases need specific training, a restricted escalation path, and limits on how much of this material they see in a day. See chapter 14.
- Step 06
Handle the account, not just the content
When you find child sexual abuse material or an adult enticing a child, some steps aren't optional. The content comes down, gets preserved and gets reported. In the US that means the NCMEC CyberTipline, under 18 U.S.C. § 2258A. Since the REPORT Act, that includes enticement and child sex trafficking, and you must preserve what you reported for a year. A child in immediate danger comes before everything else: escalate to law enforcement straight away. Chapter 12 covers the first hour.
The judgment call is the account. You can act immediately and visibly, or restrict the account quietly while investigators map linked accounts and law enforcement decides what it needs. Immature programs default to the ban because it's the only lever their tooling gives them, and it looks like success on a dashboard. In practice, the offender comes back on a fresh account with none of the history that flagged them. Their other accounts go unexamined. And the child is still reachable wherever the conversation already moved.
Offenders work across services, so one platform's ban is one move in a longer sequence. The Tech Coalition's Lantern program lets participating companies share signals about online child sexual exploitation and abuse across platforms. If you're eligible, join. If you aren't yet, design your investigation records so you could share well-structured signals when you are.
The standard isn't speed. It's a safe child and a fully mapped network.
- Step 07
Give the thresholds one owner, and write every change down
Where the age lines and detection thresholds sit affects product, safety, legal and privacy at once. If nobody owns them, each team nudges them toward its own goals and nobody notices the drift. Give them one owner and the same sign-off as a policy change.
Write every change down, with the numbers behind it. Every threshold gets tested the day a regulator, a parent or a court asks why a specific account was or wasn't restricted. That question is only answerable if one person owned the thresholds, each change was recorded, and the decision to report to law enforcement was made by people trained for it.
- Step 08
Measure prevention, not just removal
Completion rate (how many users finished an age check) is a weak metric on its own. These tell you whether the system works:
- Adults in teen spaces: how many accounts in teen groups turn out to be adults.
- Children in adult spaces: how many children end up in adult groups or adult-only products.
- Time to catch an account that changed hands.
- Time from first signal to protective action on adult-to-minor contact.
- Share of confirmed cases caught before the move to another app.
- Precision at each step of the grooming response, and how long high-risk cases wait for review.
- Confirmed unsafe-contact cases per 10,000 young users, split by how the contact started, so you can close the path, not just ban the account.
Mistakes to avoid
And what to do instead
- 01
Checking age once, at sign-up
Re-check when an account seems to have changed hands, and fall back to safer defaults while you do.
- 02
Choosing a method before deciding what it unlocks
Decide what's at stake for each feature first, then pick the lightest check that's strong enough.
- 03
Banning every account that looks young
You'll hit legitimate users and teach children to lie better. Move the account to safer defaults and ask for a stronger check.
- 04
Reviewing messages one at a time
Grooming is spread across weeks of contact. Look at the relationship.
- 05
Treating the ban as the end of the case
Preserve, report, and map linked accounts before you tip off the offender.
- 06
Reporting completion rates as success
Report who ended up where, and how much contact you prevented.
- 07
Letting thresholds drift
One owner, a written change log, and the same sign-off as policy.
Start from this template
Copy it, fill it in, make it yours
Template
Age assurance ladder
Fill in one row per level for your product.
| Level | How it's established | What it unlocks | What it never unlocks | Re-check when |
|---|---|---|---|---|
| Self-declared | Typed date of birth | |||
| Estimated | ||||
| Verified or parent-approved |
Template
Grooming response ladder
Agree it with Legal and Privacy before launch.
| Signals on an adult-to-minor contact | Window | Automatic response | Who reviews, and how fast |
|---|---|---|---|
| One signal | Log only | No review | |
| Two or more | |||
| Off-platform or image request |
Template
Child safety review
One page for leadership, monthly or on the cadence your leadership reviews already run: age-check coverage for chat and voice users; adults found in teen spaces; children found in adult spaces; unsafe-contact cases per 10,000 young users by entry path; share of cases caught before the move off-platform; CyberTipline reports and time to report; threshold changes since the last review and who signed them off.
Do it with
Free tools and metrics that go with this chapter
COPPA readiness
Check a service against the US COPPA Rule's duties for children under 13.
Abuse pre-mortem
Profile a product and see its child safety risks and safeguards before launch. Open content
Incident tabletop
Rehearse The gifts that weren't gifts (a kids' multiplayer game), The gift card ultimatum (sextortion on a teen social app) and The 15-year-old on the app (a minor on an 18+ service).
Legal obligations
COPPA, the CSAM reporting duty, DSA Article 28, the UK children's safety duties and Australia's social media minimum age, in plain language.
Further reading
Steven's posts on this topic, and sources worth the time
From Steven's writing · 7 posts
- Reading roundup
Saturday reading: child safety gaps in games, Ofcom in court and California's new laws
Australia's eSafety found Fortnite and Minecraft still mostly rely on self-declared age. Age assurance is the foundation, because every other safeguard assumes you know who's a kid.
- Share
Why early grooming detection matters
Tools that help platforms spot grooming early protect kids and the communities around them.
- Essay
Grooming is a pattern, not a message
Responses build as signals stack on adult-to-minor contact, with thresholds tested on past cases, a queue worked by risk, privacy limits agreed up front, and four numbers that show it works.
- Share
Nudify apps: harm no single platform sees in full
The image is made on one service, the tool promoted on another and the harm lands on a third. That's why cross-platform signal sharing through Lantern matters.
- Essay
Age assurance: what should each check unlock?
The method matters less than what each level of assurance lets a user do. Errors aren't equal, accounts change hands, and someone has to own the thresholds.
Show 2 more posts
- Essay
Games are where kids socialize now, and regulators know it
Grooming builds over weeks and usually moves off-platform. Protections that work act earlier and limit who can reach a child. Measure prevented contact, not just removals.
- Essay
A banned account is not a closed case
Online enticement is a pattern of contact, not a file, and is now mandatory to report. The hard call is the account: ban visibly, or restrict quietly while the network is mapped.
Outside sources
- NCMEC CyberTiplinewhere US platforms report child sexual exploitation, including enticement. Its annual data shows what gets reported.
- Tech Coalition: Lanterncross-platform signal sharing about online child sexual exploitation and abuse.
- European Commission: guidelines on the protection of minorswhat DSA Article 28 expects on age assurance and defaults.
- ICO: the Children's Codethe UK's standards for services likely to be used by children.
- FTC: the COPPA RuleUS duties for services that collect data from children under 13.
- Thorn: Youth Perspectives on Online Safetywhat 9-to-17-year-olds say about their lives online.
Recent changes
3 changes to this chapter, newest first
The updates page has every change to the handbook, by date.
- RevisedWith 18 other chapters
Practical advice that varies by platform, such as cadences, sample sizes, targets and who owns what, is now set out as options with examples, so each team can choose what fits.
- Drafted
First full draft: what each level of age assurance should unlock, safe defaults, grooming responses that build as signals stack, the account decision, and how to measure prevention.
- AddedWith 14 other chapters
Linked the first 16 posts to the chapters they inform, and set out the ten principles behind the handbook.