UK online safety legislation mandates device-level blocks on underage nude imagery
The UK Government has proposed legislation requiring technology companies to implement device-level safeguards to prevent users under 18 from accessing or sharing nude imagery. The initiative aims to shift the responsibility for online safety from families to hardware and service providers in response to rising reports of sextortion.
Key Takeaways
- Legislation would require technology companies to build safeguards directly into devices to prevent grooming and exploitation.
- Internet Watch Foundation data shows sextortion reports rose from 19 in 2022 to 394 by 2025.
- Approximately 90% of UK children own a smartphone by age 11, according to SWGfL research.
- The proposal targets self-generated content, which accounted for 91% of child sexual abuse reports in 2024.
Why It Matters
This proposal represents a significant shift in regulatory strategy by moving the burden of child safety from end-users to the device and service architecture level. For streaming platforms and social media providers, this could necessitate deeper integration with operating system-level content filters and more aggressive automated scanning tools. As the UK seeks to establish the world's strictest digital safety standards, global technology firms may face fragmented compliance requirements if other jurisdictions do not adopt similar device-level mandates. Industry observers should monitor the specific technical requirements the UK Government issues for hardware manufacturers to determine the feasibility of these 'impossible to bypass' safeguards.
Additional Context
The UK Government's proposed device-level safeguards build on enforcement mechanisms already established under the Online Safety Act 2023, which gave Ofcom broad powers to regulate platforms hosting user-generated content. In July 2025, Ofcom published its first set of illegal content duties requiring platforms to conduct risk assessments and deploy proportionate measures to protect users from harmful material, marking the regulator's initial enforcement phase under the Act. The Internet Watch Foundation, which maintains the UK's hash database of known child sexual abuse imagery, has been central to the technical infrastructure that platforms use for detection. The IWF reported in its 2024 annual report that it identified a record 291,000 webpages containing child sexual abuse imagery, a figure that underscores the scale of content moderation challenges the new device-level proposal aims to address upstream.
On the business and compliance side, technology firms operating in the UK face a tightening regulatory timeline. Ofcom issued its first codes of practice for illegal content in December 2024, setting out specific technical measures platforms must adopt or face fines of up to 10% of global revenue. The proposed device-level legislation would extend obligations beyond platforms to hardware manufacturers and operating system providers, a category not previously covered under the Online Safety Act. South West Grid for Learning, which operates the UK Safer Internet Centre, has been involved in shaping the educational and technical guidance that accompanies these regulatory moves. Charlotte Aynsley, the organization's policy lead, has advocated for age-assurance technologies as a prerequisite for effective enforcement, arguing that without reliable age verification at the device level, platform-level content filters remain easily circumvented.
Technical feasibility remains the central question for hardware manufacturers. Apple's existing Child Sexual Abuse Material detection system, which uses perceptual hashing to scan images before they are uploaded to iCloud, was paused in 2022 after backlash from privacy researchers and civil liberties groups, illustrating the tension between device-level scanning and user privacy expectations. The UK proposal appears to mandate similar scanning capabilities but frames them as non-optional for any device sold in the UK market. The Information Commissioner's Office published guidance in early 2025 on how age-assurance technologies can comply with UK data protection law, signaling that regulators are attempting to align the Online Safety Act's enforcement requirements with GDPR-compatible data handling. For streaming platforms and social media services, the practical implication is that content moderation may increasingly be handled at the operating system layer before media ever reaches their servers.
Read full article at swgfl.org.uk
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source