Child safety and age assurance
Age assurance, grooming and enticement, and what actually protects kids on products adults use too.
Grooming is a pattern, not a message
Responses build as signals stack on adult-to-minor contact, with thresholds tested on past cases, a queue worked by risk, privacy limits agreed up front, and four numbers that show it works.
Age assurance: what should each check unlock?
The method matters less than what each level of assurance lets a user do. Errors aren't equal, accounts change hands, and someone has to own the thresholds.
Games are where kids socialize now, and regulators know it
Grooming builds over weeks and usually moves off-platform. Protections that work act earlier and limit who can reach a child. Measure prevented contact, not just removals.
A banned account is not a closed case
Online enticement is a pattern of contact, not a file, and is now mandatory to report. The hard call is the account: ban visibly, or restrict quietly while the network is mapped.
Why early grooming detection matters
Tools that help platforms spot grooming early protect kids and the communities around them.
Nudify apps: harm no single platform sees in full
The image is made on one service, the tool promoted on another and the harm lands on a third. That's why cross-platform signal sharing through Lantern matters.
Automation and decision quality
Where automated decisions should end, where people take over, and how to tell when automation is getting it wrong.
Appeal overturns: the early warning for automation
Overturned appeals show drift weeks before anything else. Automation expands only where its overturn rate matches human review, and changes roll back when the rate moves.
Automation rate isn't a measure of maturity
Automate as much as the evidence supports. Where a wrong decision can't be reversed or someone's safety is at risk, automation prepares the case and a person closes it.
Measuring what matters
Outcomes over activity, and making the business case for safety with your own data.
Harassed players look like your best-retained users
Raw retention data hides the cost of toxicity because harassed players are the most engaged. A matched cohort shows it, and safety exposure belongs on the retention dashboard.
Activity is easy to measure. Impact is harder.
A 40% jump in removals could mean better detection, more harm or over-enforcement. Report outcome metrics next to operational ones, and tell leadership when they disagree.
Safety by design and operations
Getting safety into a product before launch, and running it well after.
Run the abuse pre-mortem at design review
At design review, changing a default is a quick edit. After launch it means taking something away. T&S earns the invite by being selective and fast, and accepted risks get an owner and a date.
Watch the rate, not the volume
In Stream's live sports chat data, volume swung 7.5x but the rate of racist content held steady. Alert on rate jumps to spot raids, and slow down new accounts instead of locking the room.
Launches get a security review. Almost none get an abuse review.
Introducing the free abuse pre-mortem: 12 questions, rated risks, safeguards with owners in priority order, likely laws, and a launch plan for Jira, Linear or GitHub.
You can't moderate your way out of a systems problem
Treating Trust & Safety mainly as an operations function is a mistake. Reputation, history, age and behavior signals belong in one risk model, automation needs clear limits, and safety belongs in the product architecture from the start.
What's changing
Regulation, litigation and the news that will land on your roadmap.
Saturday reading: child safety gaps in games, Ofcom in court and California's new laws
Australia's eSafety found Fortnite and Minecraft still mostly rely on self-declared age. Age assurance is the foundation, because every other safeguard assumes you know who's a kid.
The era of voluntary child safety is ending
India's push for age checks, Florida's case against OpenAI, Copilot data labeling, TikTok's Alabama settlement and Meta's New Mexico verdict. The question has moved from "do you have a policy?" to "can you prove it works?"