← Policy & Global Updates
Policy, devices & child protectionUnited Kingdom

The UK proposes child protection at the device layer

The UK Government is preparing legislation intended to prevent children from taking, viewing or sharing nude images through device-level protections switched on by default, with possible complementary duties for applications used by children.

01

What it could improve

The proposal is a notable attempt to intervene before harmful images are created or circulated. It would place responsibility on device and application providers, make protective settings the default and require adults—not children—to demonstrate when restrictions should not apply.

02

What remains unresolved

The proposal’s goal is clear, but an absolute technical rule applied to every image and user context raises significant questions about accuracy, proportionality, privacy and children’s legitimate access to information and support.

  • Automated nudity detection can produce false positives and false negatives across health, family, cultural, educational and safeguarding contexts.
  • Blocking image capture, display and transmission across cameras and third-party apps may require sensitive on-device analysis and careful treatment of encrypted communications.
  • Adult verification must not create unnecessary identity disclosure, centralised records or exclusion for people without particular documents or devices.
  • Device-level controls can be bypassed through older hardware, unmanaged devices, browsers, remote services or other image-generation tools.
  • A single under-18 rule may not adequately reflect adolescents’ evolving capacities, confidential access to health information or legitimate safeguarding disclosures.
  • Technical blocking must connect to trusted reporting, victim support and action against grooming behaviour; image detection alone cannot address the full pattern of exploitation.
03

The Child-Friendly Internet perspective

The proposal powerfully illustrates the principle that technology should adapt to children. For that principle to remain child-centred, device-level safeguards should be proportionate, privacy-preserving, independently evaluated and connected with service, network and safeguarding responses.

  • Use layered protections so responsibility is shared across devices, applications, services and networks rather than concentrated in one filter.
  • Apply the least intrusive assurance and detection method capable of achieving the specific safety purpose.
  • Provide carefully governed exceptions and recovery pathways for legitimate health, education and safeguarding needs.
  • Evaluate outcomes with children’s rights, accuracy, circumvention and unintended consequences in view.
?

The central question

How can device-level prevention protect children from exploitation without turning every image, device or age check into a new privacy risk?