A child using smart phone lying in bed late at night
getty
Child safety online is a material investment risk in most portfolios. It isn’t just a social issue anymore. It has evolved into a governance, litigation, and reputational issue as regulators increase scrutiny, AI reduces the cost of generating harmful content, and plaintiffs develop new legal theories. The $1.4 trillion that California, Colorado, Kentucky and New Jersey are seeking from Meta in a social media addiction trial next month is a case in point. Investors can reduce risks and improve both returns and sustainability by engaging with companies.
The first article in this series on child safety online outlined the growing scale of the risk from creating, distributing or possessing visual depictions of explicit conduct involving minors. The second article focused on how investors can engage with Apple and Alphabet. This third article in the series focuses on two more companies that have demonstrated a willingness to engage with shareholders on sustainability issues and are well positioned to improve child safety online: GoDaddy and Cloudflare.
GoDaddy and Cloudflare publicly emphasize sustainability and stakeholder trust. For example, Cloudflare leads its peer group in environmental engineering in that it embeds environmental efficiency directly into its network infrastructure instead of relying on offsets. Accordingly, risks to child safety online are a litmus test of whether GoDaddy’s and Cloudflare’s sustainability commitments extend beyond environmental performance and traditional governance topics.
This article outlines engagement topics for each company and ends with a call to action.
GoDaddy
GoDaddy already has a dedicated child safety team and automated content screening. GoDaddy also faces lower reputational, regulatory, and litigation risk from CSAM than Meta, Alphabet, and Apple, but material operational risk. As an internet domain registrar and web hosting company, GoDaddy bears the risk that CSAM may be hosted on its platform and has the technical ability to disable the website and remove the content.
Questions Investors May Wish to Ask GoDaddy
Investors should focus on how the company measures and manages effectiveness, not just activity, in reducing harmful content and enterprise risk. They should also consider asking the questions below:
- How does the company measure the effectiveness of its child safety efforts beyond the volume of content reviewed or removed?
- What metrics are used to assess whether harmful content is identified and disabled in a timely manner?
- How frequently does management report child safety risks and trends to the board?
- How does GoDaddy evaluate emerging risks associated with new hosting products and services?
Cloudflare
Cloudflare’s risk is lower than GoDaddy’s, but growing. Cloudflare reports allegations of CSAM to organizations that investigate claims and entities that remove content and provides a CSAM Scanning Tool to help website owners identify and report CSAM. I also could not find a material pending US lawsuit against Cloudflare for CSAM transmitted, cached, or hosted through its services. However, Cloudflare’s latest Form 10K discusses potential liability from illegal customer content and specifically identifies emerging CSAM regulation. Indeed, as Cloudflare expands from reverse-proxy and cybersecurity protection into hosting, storage, and compute, CSAM litigation may emerge as a governance, regulatory, and business-model risk.
Questions Investors May Wish to Ask Cloudflare
The key question for investors to ask the company at this stage in its evolution can be found immediately below.
- Which child safety controls are mandatory across Cloudflare-controlled content products, and which remain optional?
- What criteria are used to determine when optional controls become mandatory?
- How is management assessing child safety risks as Cloudflare expands into hosting, storage, and compute services?
- What information regarding child safety risks and regulatory developments is regularly reported to the board?
A Moral Imperative and a Financial One
Protecting children and youth is both a moral imperative and a financial one. Investors have an opportunity to encourage leading companies to reduce harms and strengthen safeguards. As concerns about child and youth safety online continue to grow, so do the associated legal, regulatory, reputational, and commercial risks facing companies and the long-term portfolios that own them.
Institutional and retail investors can take three immediate steps: (i) incorporate online child safety into stewardship priorities and proxy voting frameworks, (ii) engage directly or collaboratively with GoDaddy and Cloudflare on the specific questions outlined above, and (iii) request consistent disclosure on detection effectiveness, response times, and safeguards for AI-generated content.
Investors routinely engage companies on climate, governance, cybersecurity, and human capital management. Child safety online increasingly belongs in that same category: a foreseeable, measurable, and potentially material risk that boards and investors can influence through effective stewardship. The companies discussed here have demonstrated a willingness to engage with investors on sustainability issues.
The next step is for shareholders to ask whether child safety receives the same level of attention.
This Series
The first article in this series on child safety online explained why child safety online is becoming a material stewardship issue. The second and third articles each identified two companies that investors can engage with today. Future articles will examine additional companies and escalation pathways available to shareholders.
————————————————
