Stay Informed
Join our newsletter to receive updates about our mission, impact stories, and ways you can help make a difference.

European regulation of the online environment has moved quickly, and the result is a stack of overlapping instruments that even people working in the field struggle to keep straight. Here is what matters for child protection, without the acronym soup.
The DSA has applied in full since February 2024. For child protection the significant parts are the obligation on very large platforms to assess and mitigate systemic risks — explicitly including risks to the rights of the child — and the ban on advertising profiled to minors.
The enforcement record is what makes this real rather than aspirational. The Commission has opened formal proceedings against several major platforms on precisely these grounds, including on the design of features that keep minors engaged. Whether the eventual remedies change anything is still open, but the mechanism exists and is being used.
Article 50 of the AI Act, on transparency, applies from 2 August 2026. In short: people must be told when they are interacting with an AI system rather than a person, and synthetic image, audio and video content must be machine-readably marked as artificially generated.
For child protection this cuts two ways. The obligation is useful — undisclosed chatbots aimed at young people are a real problem. But marking requirements apply to those who deploy systems lawfully, and the people generating synthetic abuse material are not going to comply with a labelling rule. The provision that matters more for them is the prohibition on the material itself.
The proposed regulation on preventing and combating child sexual abuse — the one usually reported as "chat control" — remains the most contested file in this area. It has been through several presidencies without agreement.
The disagreement is genuine rather than manufactured. The proposal would allow authorities to order services to detect known and new abuse material, which for end-to-end encrypted services means either breaking the encryption or scanning on the device before it is applied. Child protection organisations are divided on it, and so are security researchers, and neither group is arguing in bad faith.
An interim regulation permitting voluntary detection has been extended to keep existing efforts lawful while the argument continues.
Three practical things. Consent for tracking is not optional and never was — the ePrivacy rules predate all of this and are what actually govern the cookie banner. Any AI feature shown to the public has to disclose itself, plainly, before someone interacts with it. And any system holding information about children needs a data protection impact assessment that has actually been done rather than filed.
None of it is exotic. Most of it is what a careful organisation would do anyway. The regulation mainly removes the option of not bothering.

Awareness campaigns are visible and comparatively cheap. The things that reduce harm are neither. A look at what the evidence supports.

Where the money goes, who checks, and why Swedish charity regulation makes it harder than it looks to spend a donation on the wrong thing.

A generation of children was taught to fear the wrong person. The replacement is less catchy and considerably more useful.
Join our newsletter to receive updates about our mission, impact stories, and ways you can help make a difference.