Regulatory context

What the obligations are converging on.

Regulators across several jurisdictions are moving toward comparable objectives — age and risk assurance, feature-level duties, recommender accountability, and evidence an authority can examine — expressed through different instruments. This page sets out that context institutionally.

Themes

Six recurring requirements.

Where separate regimes are asking for structurally similar things, whatever the instrument.

Age and risk assurance

Establishing, to a defensible standard, whether a user falls within a protected category — and treating that determination as contestable rather than authoritative.

Feature-level obligation

Duties increasingly attach to particular capabilities — recommendation, messaging, discovery — rather than to a service in the abstract.

Recommender accountability

Expectations that the behaviour of ranking and recommendation systems can be described, configured and examined.

Evidence and auditability

A shift from attestation toward records an authority can examine: what was applied, to whom, and on what basis.

Jurisdictional divergence

Comparable objectives expressed through different instruments, so a single platform faces materially different obligations by territory.

Safety-by-design duties

Obligations framed around how a service is designed rather than only how it responds after harm occurs.

10 developments · 6 jurisdictions

Developments, with their sources.

Each entry states the issuing authority, the source record, its date, and the date CIVITERA last checked it. Descriptions report what the source says at that date.

Australia · Enacted LegislationOnline Safety Amendment (Social Media Minimum Age) Act 2024

The Act received Royal Assent in December 2024. It requires age-restricted social media platforms to take reasonable steps to prevent Australians under 16 from holding accounts, with minimum-age restrictions in force from 10 December 2025. The eSafety Commissioner administers the regime on a principles-based basis rather than mandating a single technology.

Authority
eSafety Commissioner (Australia)
Source
eSafety statement on the Online Safety Amendment (Social Media Minimum Age) Act 2024
Source date
2024-12-11
Last reviewed
2026-09-08
In ForceChild Safety · Age Assurance
European Union · Regulator GuidanceDSA Article 28 Guidelines on the Protection of Minors

Under Article 28 of the Digital Services Act, platforms accessible to minors are required to take appropriate and proportionate measures for their privacy, safety and security. The Commission Guidelines address age assurance, private-by-default settings, recommender systems, persuasive design and governance. The Guidelines are voluntary and are used by the Commission as a reference point.

Authority
European Commission
Source
Commission publishes guidelines on the protection of minors
Source date
2025-07-14
Last reviewed
2026-09-08
GuidanceAge Assurance · Recommender Systems
United Kingdom · Regulatory CodesUK Protection of Children Codes

Ofcom finalised the Codes on 24 April 2025, with relevant child-safety duties taking effect from 25 July 2025. The Codes set out measures including protection from harmful content, safer feeds and recommender-system configuration, and highly effective age assurance for services likely to be accessed by children in the United Kingdom.

Authority
Ofcom
Source
Protection of Children Codes of Practice under the Online Safety Act
Source date
2025-04-24
Last reviewed
2026-09-08
In ForceChild Safety · Age Assurance
United States · Proposed LegislationKids Online Safety Act — S.1748

S.1748 (119th Congress) would set duties for online platforms used by minors, including options to disable addictive product features, opt-outs from personalised recommendation systems, and default safeguards. It was advanced by the Senate Commerce Committee by voice vote on 5 August 2026 and had not been enacted as at the last-reviewed date.

Authority
U.S. Senate Committee on Commerce, Science, and Transportation
Source
Commerce Committee advances kids online safety legislation
Source date
2026-08-05
Last reviewed
2026-09-08
ProposedChild Safety · Recommender Systems
Singapore · Regulatory CodeOnline Safety Code of Practice for App Distribution Services

Issued by IMDA under the Broadcasting Act on 15 January 2025 and taking effect from 31 March 2025, the Code requires designated app distribution services to put system-level measures in place to reduce the risk of minors being exposed to harmful content.

Authority
Infocomm Media Development Authority (IMDA)
Source
Online Safety Code of Practice for App Distribution Services
Source date
2025-01-15
Last reviewed
2026-09-08
In ForceAge Assurance · Child Safety
Singapore · Proposed PolicyPlanned Social Media Age-Assurance Measures

Announced measures directed at age assurance for social media services. As at the source date the measures were described as planned rather than in force, and implementation detail was not settled.

Authority
Infocomm Media Development Authority (IMDA)
Source
Announced plans for social media age-assurance measures
Source date
2026-07-04
Last reviewed
2026-09-08
ProposedAge Assurance · Child Safety
Canada · Lapsed LegislationOnline Harms Act — Bill C-63

Bill C-63 proposed an Online Harms Act including a duty to protect children and a Digital Safety Commission. It was introduced on 26 February 2024 and lapsed on prorogation in January 2025 without becoming law. Retained as historical context.

Authority
Parliament of Canada
Source
Bill C-63, Online Harms Act (44th Parliament)
Source date
2024-02-26
Last reviewed
2026-09-08
LapsedChild Safety · Content Moderation
Canada · Proposed LegislationSafe Social Media Act — Bill C-34

A House Government Bill that would enact a Digital Safety Act and establish a Digital Safety Commission of Canada, creating safety-by-design duties for social media and AI chatbot services with a focus on children and youth. Introduced and first read on 10 June 2026; at second reading as at the last-reviewed date.

Authority
Parliament of Canada
Source
Bill C-34, Safe Social Media Act
Source date
2026-06-10
Last reviewed
2026-09-08
ProposedChild Safety · Age Assurance
United States · Settlement / Consent JudgmentMultistate Attorneys General Settlement with Meta Platforms

Announced settlement terms include daily time limits with usage pauses for teen users, night-time restrictions, limits on notifications during school hours, enhanced age-assurance measures, age-appropriate content controls, limits on social-comparison features, and strengthened parental controls. Amounts and allocations vary by settling jurisdiction.

Authority
State Attorneys General (announcements by participating states)
Source
Announcements of settlement terms with Meta Platforms
Source date
2026-08-26
Last reviewed
2026-09-08
SettlementChild Safety · Addictive Design
United States · SettlementTikTok / ByteDance COPPA Settlement

A settlement resolving claims concerning children’s privacy obligations. The announcement sets out the resolution reached; obligations follow from the settlement terms rather than from any general rule stated here.

Authority
U.S. Department of Justice
Source
Justice Department secures settlement with TikTok and ByteDance resolving children’s privacy claims
Source date
2026-08-21
Last reviewed
2026-09-08
SettlementChild Safety · Privacy

This page is institutional context, not legal advice, and is not a live tracker. Entries describe what the cited source states as at its source date and the date shown as last reviewed; they are not a statement of what any law requires of any organisation at any later time. CIVITERA holds no regulatory authority, issues no approvals, and certifies no systems. Organisations should take their own advice on obligations that apply to them.

What this means for architectureExpressible obligations

Where regulators ask for evidence rather than assurance, the burden lands on architecture: a platform has to be able to show which controls were applied, to whom, and on what basis. That is the gap CIVITERA’s governance technologies address.

What CIVITERA does not doInterpret the law

CIVITERA does not advise on compliance, determine whether an obligation applies, or certify that any system satisfies one. It develops and licenses the intellectual property that lets an institution express its obligations technically.

Publicly available patent records may be independently verified through USPTO systems where applicable. Information concerning non-public applications is provided through controlled verification procedures to qualified counterparties.

Programme

The child-safety programme.

Platform operators, public authorities and research institutions can engage on architectural requirements and technical evaluation.

The programmeContact the governance division