The Children’s Media Foundation (CMF)

CMF Submission to the DSIT Consultation: Growing up in the Online World.

CMF Submission to the DSIT Consultation: Growing up in the Online World.

Holding Big Tech to Its Own Promises: The Case for Mandatory Audits Over a Social Media Ban

 

Our Position

The Children’s Media Foundation (CMF) supports the Children’s Coalition for Online Safety’s call for meaningful, evidence-led reform of the online environment for children. We endorse the Coalition’s four key asks of Government: mandating age-appropriate principles, removing commercial incentives for harmful design, applying the same rigour to AI systems, and creating strong leadership for online safety regulation.

On the question of a social media ban, we propose that rather than legislate to exclude under-16s from platforms deemed unsafe or damaging to their wellbeing, Government should instead mandate existing regulators to be far more proactive in ensuring those platforms have adequate age-appropriate design features activated by default, and to aggressively pursue those who wilfully ignore or pay lip service to regulations and codes already on the statute book.

A ban treats the symptom; fixing the design treats the cause. We regard exclusion legislation as an instrument of last resort, warranted only if the proactive regulatory approach articulated in this document demonstrably fails.

We diverge from the Coalition’s proposals on institutional design. CMF believes the more immediately attainable and direct route to change is to instruct the existing regulators, Ofcom and the ICO, to exercise the substantial powers Parliament has already granted them, proactively, systematically and with children’s safety and well-being as an explicit enforcement priority.

The Powers Already Exist – The Scope Needs to Expand

A common assumption in the social media ban debate is that Government needs new legislation to hold platforms to account. CMF’s analysis of the Online Safety Act 2023 leads us to conclude this is not the case.

Under Section 107 and Schedule 12 of the Online Safety Act, Parliament has already granted Ofcom direct powers to audit and investigate any regulated platform, inspect the internal design choices, algorithmic architecture or children’s risk assessments of any service, without waiting for a complaint and without seeking new legislation. The OSA’s categorisation framework, already established in law and applied by Ofcom, creates a clear hierarchy of obligation:

  • Category 1 services user-to user services such as those offered by Meta, TikTok, YouTube and X (as defined in the OSA), must meet every child safety threshold if they allow any users under 18, and are legally required to publish a public summary of their child risk assessments. The only exemption from child safety obligations is if they completely ban under-18s and implement highly effective age verification to keep them out.
  • Category 2A and 2B services, (as designated under the OSA), must perform a Children’s Access Assessment and are subject to full child safety obligations if that assessment confirms significant child usage.
  • All categorised services must conduct and maintain children’s risk assessments, accessible to Ofcom’s inspectors at any time.

CMF is not proposing a new classification system. The audit would operate entirely within the structure Parliament established and Ofcom already administers.

Ofcom’s Enforcement Progress – and the Next Frontier

Ofcom deserves credit for its enforcement of age assurance obligations against commercial pornography sites; precisely the kind of proactive, design-level intervention the OSA was intended to enable. It demonstrates the enforcement model works when applied with purpose.

The challenge now is to extend that same approach to the harms affecting the greatest number of children: the behavioural design features embedded in mainstream platforms that millions of UK children use daily. Algorithmic recommendation systems optimised for engagement, compulsive notification architecture and infinite scroll are the features the California courts found negligently harmful. These are features Ofcom’s existing powers already entitle it to examine.

To date, Ofcom does not appear to have progressed any follow-up investigations under its own programme “to protect children through age assurance on social platforms”, or its programme “to monitor whether services are meeting their children’s risk assessment duties”. Its April 2026 request for risk assessments from dozens of firms is a welcome signal of intent, but submitting documents is the beginning of accountability, not its conclusion.

NB: The first Online Safety levy is due for collection in September 2026 from many companies (such as Meta, Google, Microsoft, Apple, ByteDance, Amazon (Twitch), Snap, Roblox and X) and should provide Ofcom with a sustainable funding base for this expanded programme.

Our Recommendation: A Mandatory Annual Children’s Platform Audit

The CMF recommends that Ofcom and the ICO, acting under existing powers conferred by the Online Safety Act and UK GDPR respectively, establish a mandatory Annual Children’s Platform Audit (ACPA). This requires a Secretary of State direction and a clear government mandate – not new primary legislation.

How the Audit Would Be Triggered

Ofcom’s annual Children and Parents: Media Use and Attitudes report directly surveys children aged 8–17 across four cohorts (8–9, 10–12, 13–15 and 16–17) capturing the arc from early independent internet use through to adulthood. Parent-proxy data covers 3–7-year olds, though the directly evidenced cohorts are the stronger basis for regulatory action. CMF recommends the audit trigger be anchored to the three cohorts spanning ages 8–15.

Any platform recorded by Ofcom’s survey as being used by 1% or more of children in any of those three cohorts should be automatically included on a published Children’s Reach Register. 1% represents approximately 20,000 children in each cohort, a scale that is statistically reliable within Ofcom’s methodology and sufficient to exclude genuinely niche services. At current penetration levels this would capture YouTube, TikTok, Instagram, Facebook, WhatsApp, Snapchat, Roblox, Minecraft and a range of gaming and video platforms.

The register serves a dual purpose: identifying platforms requiring a full audit and providing Ofcom with its own published evidence to challenge any platform that has self-certified it does not materially reach children. A platform appearing in the Reach Register cannot credibly maintain an accurate Children’s Access Assessment to the contrary. Put simply, Ofcom’s own survey data becomes an active enforcement instrument, not a passive monitoring tool. A higher-scrutiny tier would need to apply where the survey shows significant usage in the 8–9 or 10–12 cohort by a platform with a stated minimum age of 13 or above, and data across all 8–15 cohorts will similarly be used to challenge services claiming a 16-plus audience.

What the Audit Would Examine

Each platform identified on the register must then demonstrate compliance across three areas:

  • Age assurance effectiveness: What technically robust mechanisms enforce the platform’s stated minimum age? Self-declaration checkboxes do not qualify. Platforms unable to show a material reduction in under-age access face automatic escalation in regulatory risk tier.
  • Self-declared safeguard compliance: Does the platform’s actual product design – recommendation systems, notification architecture, feed curation – match its published safety commitments? Where specific protective features have been publicly committed to (e.g. Meta’s Teen Accounts, YouTube’s supervision tools, Roblox’s parental controls), the audit verifies they are deployed as described and produce the stated effect. A platform cannot proclaim publicly that its safeguards protect children while they are merely voluntary.
  • Children’s Code design compliance: Does the platform’s design comply with the ICO’s Children’s Code prohibitions on dark patterns, incentivising engagement and profiling that drives compulsive use? Internal data on engagement patterns, session lengths and notification response rates for under-18 users is disclosable under Ofcom’s information request powers. Where audit findings raise questions about the Age-Appropriate Design Code, it would be for the ICO – as statutory enforcer of UK GDPR and the Children’s Code – to determine whether a violation has occurred and to impose remedial action or financial penalties.

Consequences: Graduated and Proportionate

Audit outcomes will need to feed into existing enforcement pathways: i.e. no new powers required. Ofcom acts on duty of care and content safety under the Online Safety Act; the ICO acts on data protection and Children’s Code compliance under UK GDPR, as established in the regulators’ joint Memorandum of Understanding.

  • Platforms passing the audit receive a compliance certificate published on the register, providing regulatory certainty and reputational benefit.
  • Platforms with material age assurance gaps trigger a formal ICO enforcement notice, with the presumption (as established in the ICO/Ofcom joint statement) that children’s data has been processed unlawfully, reversing the burden of proof.
  • A platform failure to meet self-declared safeguards triggers an Ofcom direction requiring specific design changes, within a defined period, with penalties of up to 10% of qualifying worldwide revenue; the maximum already authorised under Section 101 of the Online Safety Act for non-compliance.
  • Potential Age-Appropriate Design Code violations are referred to the ICO, which can impose fines of up to 4% of global annual turnover.
  • Persistent multi-year failures escalate to access restriction orders – a targeted, service-specific measure that is proportionate in a way a blanket ban is not.

On the Question of a Social Media Ban

The CMF’s opposition to an outright ban is conditional, not absolute. It rests on our belief that the UK’s existing regulatory architecture, properly mandated and properly used, can achieve the same protective outcomes more effectively, and without the costs of exclusion. Early evidence from Australia’s December 2025 ban is instructive: determined teenagers are circumventing it at scale, and it has done nothing to change the product design features that cause harm regardless of age.

We would, however, actively support the case for a ban if any of the following conditions are met:

  • Platforms demonstrably obstruct, delay or game the audit regime – a pattern documented in Meta’s COPPA conduct, where executives were instructed not to record evidence of known under-age users specifically to preserve a legal defence.
  • The ICO and Ofcom, despite receiving a clear mandate, fail within 12 months to open substantive enforcement actions against major platforms on the Children’s Reach Register – not merely procedural notices, but actions directed at age assurance failures and product design non-compliance.
  • Audit results show no material reduction in under-age access and no demonstrable changes to the product design features identified as non-compliant.
  • Evidence emerges of deliberate design decisions to circumvent the audit while maintaining the commercial value of child audiences.

In any of these circumstances, a ban would become the only proportionate response. CMF makes this explicit so that our support for the reform-first approach cannot be mistaken for complacency about outcomes.

What We Are Asking Government to Do

None of what we propose requires new primary legislation – only political will and clear direction:

  • Issue a Secretary of State direction to Ofcom confirming that platforms’ own published minimum age policies and safety commitments constitute the floor of their OSA duty of care, and that non-compliance with self-declared safeguards is an enforcement trigger. This operates within existing OSA powers.
  • Issue a policy statement to the ICO from DSIT confirming that proactive children’s platform enforcement is a top regulatory priority, with a defined share of enforcement capacity directed at Children’s Code design compliance – not only reactive data breach and direct marketing work.
  • Commission the first Annual Children’s Platform Audit within six months of the consultation response, using Ofcom’s 2025 media literacy survey data as the trigger for the initial Children’s Reach Register.
  • Commit to a 12-month review with a published compliance assessment. If the audit regime does not produce material improvement, the Government should bring forward the digital duty of care instrument needed to close the gap on addictive design – and reconsider the case for an age-based ban.

Leave a Reply

Your email address will not be published. Required fields are marked *

twelve − four =

This site uses Akismet to reduce spam. Learn how your comment data is processed.

The Children’s Media Foundation (CMF)