Establishing, to a defensible standard, whether a user falls within a protected category — and treating that determination as contestable rather than authoritative.
What the obligations are converging on.
Regulators across several jurisdictions are moving toward comparable objectives — age and risk assurance, feature-level duties, recommender accountability, and evidence an authority can examine — expressed through different instruments. This page sets out that context institutionally.
Six recurring requirements.
Where separate regimes are asking for structurally similar things, whatever the instrument.
Duties increasingly attach to particular capabilities — recommendation, messaging, discovery — rather than to a service in the abstract.
Expectations that the behaviour of ranking and recommendation systems can be described, configured and examined.
A shift from attestation toward records an authority can examine: what was applied, to whom, and on what basis.
Comparable objectives expressed through different instruments, so a single platform faces materially different obligations by territory.
Obligations framed around how a service is designed rather than only how it responds after harm occurs.
Developments, with their sources.
Each entry states the issuing authority, the source record, its date, and the date CIVITERA last checked it. Descriptions report what the source says at that date.
The Act received Royal Assent in December 2024. It requires age-restricted social media platforms to take reasonable steps to prevent Australians under 16 from holding accounts, with minimum-age restrictions in force from 10 December 2025. The eSafety Commissioner administers the regime on a principles-based basis rather than mandating a single technology.
- Authority
- eSafety Commissioner (Australia)
- Source
- eSafety statement on the Online Safety Amendment (Social Media Minimum Age) Act 2024
- Source date
- 2024-12-11
- Last reviewed
- 2026-09-08
Under Article 28 of the Digital Services Act, platforms accessible to minors are required to take appropriate and proportionate measures for their privacy, safety and security. The Commission Guidelines address age assurance, private-by-default settings, recommender systems, persuasive design and governance. The Guidelines are voluntary and are used by the Commission as a reference point.
- Authority
- European Commission
- Source
- Commission publishes guidelines on the protection of minors
- Source date
- 2025-07-14
- Last reviewed
- 2026-09-08
Ofcom finalised the Codes on 24 April 2025, with relevant child-safety duties taking effect from 25 July 2025. The Codes set out measures including protection from harmful content, safer feeds and recommender-system configuration, and highly effective age assurance for services likely to be accessed by children in the United Kingdom.
- Authority
- Ofcom
- Source
- Protection of Children Codes of Practice under the Online Safety Act
- Source date
- 2025-04-24
- Last reviewed
- 2026-09-08
S.1748 (119th Congress) would set duties for online platforms used by minors, including options to disable addictive product features, opt-outs from personalised recommendation systems, and default safeguards. It was advanced by the Senate Commerce Committee by voice vote on 5 August 2026 and had not been enacted as at the last-reviewed date.
- Authority
- U.S. Senate Committee on Commerce, Science, and Transportation
- Source
- Commerce Committee advances kids online safety legislation
- Source date
- 2026-08-05
- Last reviewed
- 2026-09-08
Issued by IMDA under the Broadcasting Act on 15 January 2025 and taking effect from 31 March 2025, the Code requires designated app distribution services to put system-level measures in place to reduce the risk of minors being exposed to harmful content.
- Authority
- Infocomm Media Development Authority (IMDA)
- Source
- Online Safety Code of Practice for App Distribution Services
- Source date
- 2025-01-15
- Last reviewed
- 2026-09-08
Announced measures directed at age assurance for social media services. As at the source date the measures were described as planned rather than in force, and implementation detail was not settled.
- Authority
- Infocomm Media Development Authority (IMDA)
- Source
- Announced plans for social media age-assurance measures
- Source date
- 2026-07-04
- Last reviewed
- 2026-09-08
Bill C-63 proposed an Online Harms Act including a duty to protect children and a Digital Safety Commission. It was introduced on 26 February 2024 and lapsed on prorogation in January 2025 without becoming law. Retained as historical context.
- Authority
- Parliament of Canada
- Source
- Bill C-63, Online Harms Act (44th Parliament)
- Source date
- 2024-02-26
- Last reviewed
- 2026-09-08
A House Government Bill that would enact a Digital Safety Act and establish a Digital Safety Commission of Canada, creating safety-by-design duties for social media and AI chatbot services with a focus on children and youth. Introduced and first read on 10 June 2026; at second reading as at the last-reviewed date.
- Authority
- Parliament of Canada
- Source
- Bill C-34, Safe Social Media Act
- Source date
- 2026-06-10
- Last reviewed
- 2026-09-08
Announced settlement terms include daily time limits with usage pauses for teen users, night-time restrictions, limits on notifications during school hours, enhanced age-assurance measures, age-appropriate content controls, limits on social-comparison features, and strengthened parental controls. Amounts and allocations vary by settling jurisdiction.
- Authority
- State Attorneys General (announcements by participating states)
- Source
- Announcements of settlement terms with Meta Platforms
- Source date
- 2026-08-26
- Last reviewed
- 2026-09-08
A settlement resolving claims concerning children’s privacy obligations. The announcement sets out the resolution reached; obligations follow from the settlement terms rather than from any general rule stated here.
- Authority
- U.S. Department of Justice
- Source
- Justice Department secures settlement with TikTok and ByteDance resolving children’s privacy claims
- Source date
- 2026-08-21
- Last reviewed
- 2026-09-08
This page is institutional context, not legal advice, and is not a live tracker. Entries describe what the cited source states as at its source date and the date shown as last reviewed; they are not a statement of what any law requires of any organisation at any later time. CIVITERA holds no regulatory authority, issues no approvals, and certifies no systems. Organisations should take their own advice on obligations that apply to them.
Where regulators ask for evidence rather than assurance, the burden lands on architecture: a platform has to be able to show which controls were applied, to whom, and on what basis. That is the gap CIVITERA’s governance technologies address.
CIVITERA does not advise on compliance, determine whether an obligation applies, or certify that any system satisfies one. It develops and licenses the intellectual property that lets an institution express its obligations technically.
Publicly available patent records may be independently verified through USPTO systems where applicable. Information concerning non-public applications is provided through controlled verification procedures to qualified counterparties.
The child-safety programme.
Platform operators, public authorities and research institutions can engage on architectural requirements and technical evaluation.