Beyond Age-Gating: Regulating Platform Design for Child Safety | #childsafety | #kids | #chldern | #parents | #schoolsafey


Image Source: Getty Images

India’s Economic Survey 2025-26 recorded 96.96 crore internet connections in 2024, up from 25.15 crore a decade earlier. Among rural 14- to 16-year-olds, 89 percent have a smartphone at home. The Survey identified digital addiction as a public health risk, highlighting concerns about how services are designed to hold users’ attention. At this scale, the policy question is no longer how to get children online, but what happens once they are there.

Karnataka proposed barring under-16s from social media in March 2026, Andhra Pradesh under-13s, and the Union government examined graded age brackets. In July 2026, the Allahabad High Court issued notice on a petition to keep minors off Roblox, and the Ministry of Electronics and Information Technology (MeitY) told Parliament that intermediaries must remove nudity and morphed images within two hours of a complaint. Each example narrows who gets in or how fast material comes out, but not what happens between those two points, or how services shape exposure.

What shapes a child’s day is decided earlier. A platform’s ranking system chooses what a 13-year-old sees first, and product teams set autoplay and stranger-messaging defaults long before a moderator reviews a post. Research on content moderation finds the weightiest decisions are taken upstream, by engineers and product managers. A 2025 survey of 1,003 American minors found 11 percent had an online sexual interaction on a given platform, and 19 percent on Snapchat, Kik and BeReal. The same children may face different levels of risk across platforms, showing that risk is shaped by the product itself, rather than by any single post. This exposes a gap in how online harm is currently measured.

What Current Measures Miss

Seven percent of minors in that survey had seen AI-generated nude imagery of another child. The National Crime Records Bureau recorded 1,238 cybercrimes against children under the Information Technology Act in 2024, 1,099 of them for publishing or transmitting sexually explicit material. Those records begin with a complaint, so they count reporting, not exposure. A survey of 89,000 urban parents found 82 percent describing the reporting route as slow or unclear. Measuring how often a child runs into it needs a figure that only the platform holds.

India already has a law about how services are built for children. Section 9(2) of the Digital Personal Data Protection Act, 2023 (DPDP Act) bars a data fiduciary from processing likely to have a detrimental effect on a child’s well-being, and Section 9(3) bars tracking, behavioural monitoring, and targeted advertising directed at children. The Rules notified on 13 November 2025 require verifiable consent but do not yet set a test or threshold for detrimental effect, a test for behavioural monitoring, or a measure for either.

Global Lessons on the Limits of Age-Gating

Australia’s under-16 rule took effect on 10 December 2025, and the eSafety Commissioner’s assessment of 31 July 2026 found account ownership among 10- to 15-year-olds falling from 52 to 42 percent in three months, with use of at least one restricted platform staying above 81 percent, down from 85.9 percent before. Most under-16s who held accounts before the law either kept them or opened new ones. Around half of those still using one said the platform never checked their age, so the rule is untested where platforms decline to run the check.

Forty-seven percent of American minors had used a platform before reaching its minimum age. A parent or older sibling helped 19 percent access the platform, suggesting that parental consent alone is insufficient as a gatekeeping mechanism. Among minors who were underage, 41 percent reported online sexual interactions, compared with 13 percent among those who were not underage. Age-gating can therefore block users who comply with the rule while leaving those who evade it exposed to the same platform.

Protection can also rely on age estimates. The European Commission’s Article 28(1) guidelines of July 2025 keep document checks for the highest-risk services and accept age estimation elsewhere. The Information Commissioner’s Office (ICO)’s Children’s Code sets the fallback: if a service is unsure of a user’s age, it applies the code’s protections to everyone. Both leave the device alone, which matters where one handset serves a household, and the cost falls to the service as signals improve. A requirement to verify the identity of every user, by contrast, would shift that cost to households and make it a permanent condition of access.

Online safety rules are written around one child and one account.

Reading the Platform as a System

Online safety rules are written around one child and one account. They do not reach the parts of a service that decide what a child sees: the ranking algorithm, the reporting queue, and the phone a family shares, where exposure is shaped and measured.

A platform’s recommendation algorithm learns from what a child watches and shows more of it, shaping what comes next. Reporting is meant to correct this, but it usually does not. After an online sexual interaction, 75 percent of minors block the other account and 53 percent report it. Blocking removes the account from one child’s feed without putting it before anyone who can rule on it, so nothing follows for the next child.

No single feature is built to produce grooming. It happens when ordinary features line up: an adult can message a stranger, the recommendation system puts a child in front of him, the reporting path is slow, and the child gives a false birthday at sign-up. A rule that fixes one of these leaves the others working. A system is best judged by what it does, not what it claims. Ranking, notifications, and retention are built to increase time spent, and safety policy is applied afterwards. India’s takedown clocks measure how fast a platform removes a post, not how often a child saw one.

No single feature is built to produce grooming. It happens when ordinary features line up.

Safe harbour depends on duties that are difficult to measure. Section 79 of the Information Technology Act, 2000 (IT Act) ties it to due diligence, and Rule 4(4) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules 2021) asks large platforms to endeavour to identify child sexual abuse imagery. Analysis of the regime sets a bouncer duty against a chaperone duty. A bouncer duty is narrow and checkable: verify a document, then serve or refuse. A chaperone duty is open-ended, asking the gatekeeper to detect and disrupt wrongdoing as a relationship unfolds. India runs a chaperone regime.

Way Forward

Several governments have tried to keep children off platforms by law, with modest results. The European Commission and the Information Commissioner’s Office (ICO) have taken the other approach, protecting anyone whose age the service cannot determine. Research on where change happens in a system ranks goals and rules as the strongest points at which to intervene, and numerical targets among the weakest. A minimum age and a two-hour clock are numerical targets. Sections 9(2) and 9(3) are rules, and they could be expanded to govern design rather than entry.

MeitY could expand on what those sections require of a product. Ranking a minor’s feed on watch history is behavioural monitoring, and a rule saying so turns Section 9(3) into an instruction that engineers can act on. Autoplay, streak counters and stranger-messaging defaults on a minor’s account would then need to be justified against Section 9(2), where a line in a privacy policy now suffices.

India already treats product design as a legal question in consumer law. The Central Consumer Protection Authority’s Guidelines for Prevention and Regulation of Dark Patterns, 2023 identify 13 interface designs, including false urgency and subscription traps, and prohibit them because designs that push users towards unintended choices can undermine their ability to make informed decisions and exercise control over their data. MeitY could apply the same logic to children’s services by identifying design features that should not be permitted on a minor’s account.

MeitY could also require the largest platforms to file a declaration before changing ranking systems or interfaces on minors’ accounts, setting out the likely effects on identified risks. Article 34 of the Digital Services Act works that way. The same firms could publish how often a minor encounters material that violates the platform’s own rules, including synthetic sexual imagery, with an independent auditor verifying the reported figure.

India’s response to online harm should be judged by how rarely children run into it and by how services are built.

Legislators could place these duties outside Section 79, so a lapse triggers a defined penalty instead of an open-ended loss of immunity. Consumer law offers a second route, and liability elsewhere is moving towards the way a service is designed: Meta settled a consumer protection suit by 51 US attorneys general in August 2026, agreeing to daily time limits, an overnight block and an unranked feed for minors. In India, the Consumer Protection Act 2019 covers deficiency in service and personal injury, and a published figure on how often children encounter harmful material would supply the evidence a claim needs. Work on dark patterns reaches the same conclusion: audit the systems that personalise users’ experiences and require firms to demonstrate that they do not manipulate them.

India’s response to online harm should be judged by how rarely children run into it and by how services are built.


Purushraj Patnaik is a Research Assistant with the Centre for Digital Societies at the Observer Research Foundation.

The views expressed above belong to the author(s). ORF research and analyses now available on Telegram! Click here to access our curated content — blogs, longforms and interviews.

————————————————


Source link