Children's Online Safety Regulation in the US - Why Laws Alone Won't Be Enough
For most of the internet’s history, America has been remarkably comfortable letting technology companies work things out for themselves. Silicon Valley built, consumers adopted, problems appeared and Washington generally arrived some years later. That arrangement is becoming increasingly difficult to sustain.
The argument over children’s online safety in the United States has moved from the margins of technology policy into Congress, state legislatures, courtrooms and family homes. In June 2026, the House passed the Kids Internet and Digital Safety Act, while on August 5 the Senate Commerce Committee advanced the latest version of the Kids Online Safety Act, or KOSA. The details and political arguments around these bills will continue, but the direction of travel is becoming difficult to miss: American technology companies are going to be expected to take considerably more responsibility for the environments they create for children.
California is moving in much the same direction. Its Protecting Our Kids from Social Media Addiction Act seeks to restrict addictive feeds and certain features for minors without parental consent, while the state continues to develop rules around age assurance.
The temptation is to frame all of this as a fairly familiar contest between government and Big Tech. Regulators demand more rules, technology companies warn about unintended consequences, lawyers argue over where constitutional and commercial boundaries sit, and eventually somebody wins.
But that misses a more interesting question.
What happens between the rule being written and the child actually using the product?
That gap matters because Washington can tell a platform that children should be protected, but it cannot realistically make millions of decisions about which content, interaction or experience is appropriate for every young person using that platform.
Technology has to do that.
And increasingly, it may need to do it in real time.
America actually has some experience of this middle ground. The Children's Online Privacy Protection Act, better known as COPPA, has governed the collection of personal information from children under 13 since 2000. What is less widely discussed is that COPPA also allows the Federal Trade Commission to approve industry-run Safe Harbor programs. Companies participating in an approved program can work within independently administered privacy standards that meet the FTC's requirements.
The video game industry offers a particularly good example.
The ESRB Privacy Certified program has operated as an FTC-approved COPPA Safe Harbor for 25 years. Products carrying its Kids Seal are assessed against requirements approved by the FTC, with ongoing reviews and spot checks rather than simply being awarded a badge and forgotten about. The program currently covers digital products and services across the games and interactive entertainment industry.
The Children's Advertising Review Unit, or CARU, offers another version of the same model. Its COPPA Safe Harbor program subjects participating services to monitoring and auditing of children's data practices, with companies including Pokémon and other major consumer brands having participated.
This is self-regulation, but not in the old sense of asking companies to promise that they will behave themselves.
There is a rulebook, an external standard, oversight and ultimately a regulator standing behind it.
That distinction may become much more important as America tries to work out what children's online safety should look like beyond COPPA.
What America can learn from Britain
An interesting glimpse of where this could lead comes not from Silicon Valley or Washington, but from the London School of Economics.
In an August 2026 article for LSE British Politics, former UK Deputy Information Commissioner Steve Wood examines what has actually happened since Britain and Europe began introducing more demanding children's online safety and privacy rules.
It is worth reading because the findings complicate the usual argument.
Wood's research, conducted through the Digital Futures for Children centre, examined 70 platforms across social media, gaming, AI chatbots and other services and identified 108 child-safety and privacy changes between 2024 and 2026. The researchers concluded that regulation was contributing to meaningful changes in platform behaviour, particularly protections designed into products by default.
Among the changes Wood highlights are Meta's Teen Accounts, Character.AI's changes to the experience available to under-18s, and Discord's move towards teen-appropriate settings by default.
So regulation appears capable of changing products.
But there is a catch, and it is an important one.
The research found limited public evidence about whether many of those changes actually work. Platforms can announce parental controls, age checks, safety settings and new policies, but outsiders frequently have little independent evidence showing whether those interventions meaningfully improve children's experiences.
That distinction between having a safety feature and knowing whether it works may turn out to be one of the defining issues in online safety.
Wood's research therefore argues for something beyond simply passing more laws: independent testing, common standards, greater access to platform data and stronger methods for assessing whether safety interventions deliver the outcome regulators intended.
For the United States, that should sound strangely familiar.
It is, in some respects, an expanded version of the philosophy already sitting inside COPPA's Safe Harbor system: government establishes the obligation, industry develops ways of meeting it, independent mechanisms help test compliance, and regulators retain enforcement power when the system fails.
The problem is no longer simply knowing someone's age
Age assurance is quickly becoming central to the American debate. In February 2026, the FTC issued a policy statement intended to encourage the development and adoption of age-verification technologies, while indicating that it intends to review how COPPA deals with those mechanisms.
But knowing that somebody is 15 rather than 25 only answers one question.
It does not tell a platform what that person is interested in, how intensely they are engaging with something, whether the content they are receiving is appropriate to that relationship or whether an experience that began as harmless entertainment is becoming something else entirely.
This is where the next generation of safety technology becomes interesting.
Historically, internet platforms became extraordinarily sophisticated at understanding people because understanding people made money. Recommendation engines learned what kept us watching. Advertising systems learned what made us click. Social platforms learned which subjects brought us back tomorrow.
We are now asking some of that intelligence to perform almost the opposite task.
Not simply: What will keep this person engaged?
But: What is appropriate for this person?
That is a very different optimisation problem.
“It is also where companies such as Thetafan Intelligence could have a role”.
Thetafan's patent-pending technology is being developed around the idea that the relationship between a person and the things they follow, watch and engage with can itself be understood and measured. Rather than treating every interaction as another piece of advertising data, that intelligence could help platforms understand different levels and patterns of engagement, giving them another signal through which experiences can be made more relevant and potentially more appropriate.
The important word is signal.
No single score, age check or algorithm should decide what is safe for a child. That would simply replace one blunt instrument with another. But platforms are going to need better ways of combining age, context, behaviour, content and engagement if they are expected to make intelligent safety decisions at the scale of hundreds of millions of users.
That creates an opportunity for a new class of technology businesses whose purpose is not to replace regulation but to help make it workable.
The alternative is increasingly expensive.
The FTC's 2022 action against Epic Games resulted in a $275 million penalty for alleged COPPA violations, alongside $245 million in consumer refunds relating to separate allegations about unwanted charges. In 2025, Disney agreed to a $10 million civil penalty over alleged COPPA violations involving children's data associated with YouTube videos.
Regulation, in other words, already has teeth.
What it still lacks is an elegant operating model for the far more complicated world that is arriving around it.
America does not need to choose between government regulation and Silicon Valley self-regulation. Nor should it rely entirely on parents policing increasingly sophisticated digital environments from the outside.
A more credible model sits somewhere between all three.
Government defines the boundaries and enforces them. Industry builds the systems capable of applying those standards at internet speed. Independent organizations test whether those systems actually work. Parents and young users are given meaningful control rather than another page of settings to navigate.
And new technologies can provide the intelligence needed to make those protections more responsive without turning safety into an excuse for even greater surveillance.
The lesson from the LSE research is therefore not that Britain has solved children's online safety and America should copy it. Britain clearly hasn't.
It is something more useful.
Passing the law is only the beginning.
The stakes just went higher with the recent $1 trillion USD Class Action Claim against Meta. The real test is whether the digital world can develop the standards, technology and independent measurement needed to make those protections work after the legislation leaves Washington.
That may be where the most interesting innovation comes next.

