Last week, Meta agreed to major changes to Facebook and Instagram for under-18s in participating US states and territories as part of a proposed $18bn settlement.
The changes include time limits, overnight restrictions, stronger age checks and additional protections for teenage users.
Those changes do not automatically apply to children in the UK.
Here, the Online Safety Act is already in force, with Ofcom responsible for making sure online services meet their legal duties to protect children.
Although the Online Safety Act already sets the legal rules that online services must follow, and gives Ofcom powers to enforce them, it does not currently require every specific protection now being proposed to help keep children safer online.
What protects children in the UK now?
The Online Safety Act is already in force. It places legal responsibilities on online services used in the UK to protect their users. This applies even when the company itself is based outside the UK.
Ofcom is responsible for regulating these services and can investigate and take enforcement action when companies fail to meet their duties. This includes services used by children such as social media and gaming platforms.
So, regulation is already happening, but there are always opportunities to make systems safer.
What are the new device-level protections?
On 8 June 2026, the UK Government announced plans for a different type of protection. Instead of relying only on individual apps to protect children, it wants safeguards built into smartphones and tablets themselves.
The aim is to prevent under-18s from:
- taking nude images;
- sending or receiving nude images;
- viewing nude images; and
- accessing pornography.
The Government said companies such as Apple and Google should activate existing technology or develop technical solutions to make this possible.
Why does this matter?
Because a child does not experience the internet through one app. They may move between a camera, browser, messaging service, social media platform or gaming service within minutes.
Protection built into the device itself could therefore work across all the different apps, rather than relying on every individual app to do the same thing.
Is it in place yet?
No, not yet as a UK-wide legal requirement. The Government gave technology companies three months from 8 June to act voluntarily. If they do not, the Government has said it will bring forward legislation to require them to act.
What about the UK social media ban?
The Government announced plans to prevent major social media services being offered to children under 16. The proposed ban is expected to cover services such as: Instagram, Facebook, TikTok, Snapchat, YouTube and X.
Messaging services such as WhatsApp and Signal are not currently intended to be included in the ban.
The Government plans to publish the detailed rules before the end of 2026, with the new restrictions expected to start taking effect from Spring 2027.
What happens when a child turns 16?
For 16 and 17-year-olds, it has announced extra protections that would be switched on by default, including:
- restrictions on social media between midnight and 6am;
- notifications restricted overnight;
- autoplay switched off;
- personalised feeds switched off;
- livestreaming restricted; and
- stranger contact restricted in relevant services.
Some of these settings will be able to be changed by 16- and 17-year-olds themselves.
The Government says this is intended to avoid a sudden “cliff edge” in protection when someone turns 16.
But, how will a platform know someone's age?
That is still being worked out. The Government has asked Ofcom to explore and set out acceptable ways for services to check whether a user is over 16. This is called ‘age assurance’.
So we do not yet have the full picture of exactly how every platform will carry out those checks.
So, what happened with Meta in the US?
On 26 August 2026, Meta reached a proposed settlement with US state attorneys general following legal action concerning alleged harms to children and teenagers.
Meta denies wrongdoing, and the settlement still requires court approval.
If approved, it will introduce additional protections for under-18s using Facebook and Instagram in participating US states and territories.
These include:
- a two-hour daily limit across Facebook and Instagram;
- restrictions between midnight and 6am;
- notifications muted during school hours;
- like and reaction numbers hidden by default;
- stronger age assurance;
- additional parental controls; and
- measures intended to make it harder for potentially suspicious adults to find or contact teenagers.
Does that mean UK teenagers get those protections too?
No. This is a US settlement. It does not automatically change the rules for a child using Instagram or Facebook in the UK.
Meta could choose to introduce some or all of the same measures more widely. UK regulators or Government could also require similar measures here.
But the US settlement itself does not do that.
The changes Meta has agreed to as part of the settlement are a significant step towards improving online safety for children, but they are not the complete solution. It is important that scrutiny of technology companies continues to ensure the settlement does not permit a backdoor to self-regulation, at company-level.
What does the Meta settlement tell us?
It shows that technology companies can change the way their products work for children when they are required to.
A platform can:
- limit when and for how long children use them;
- change how notifications work;
- strengthen age checks;
- change default settings; and
- make it harder for potentially suspicious adults to interact with children.
These are product-design decisions.
But we should also be clear about what the settlement does not mean. It does not mean Facebook and Instagram have suddenly become completely safe-by-design. Many of the measures are still limits, settings or controls, and some can also be changed.
True safety-by-design needs to go deeper. We need to be asking:
- How has the product been designed or adapted specifically for child users, to maximise their safety and wellbeing?
- Who can find and contact a child?
- Who or what can an algorithm recommend to them?
- How easy is it to request, create or share sexual images?
- Can technology recognise signs of grooming or sexual extortion earlier?
- Can the opportunity for abuse be reduced before a child is harmed?
A screen-time limit changes how long a child uses a platform. Safety-by-design changes how safe that platform is while they are there, and will limit addictive design implications for children.
So, what gaps still remain?
The measures being introduced are significant. But even if all of them are introduced, there are still important questions that need answering.
1. Everything depends on knowing a child's age
More and more of the proposed protections depend on age.
Under-16s would not be allowed onto certain social media services, different protections would apply at 16 and 17, and device-level measures are also intended specifically to protect children. That means effective age assurance becomes crucial.
If a service believes a child is an adult, the protections intended for that child may not be applied.
What is needed: Age checks that are highly effective to make age-based protections meaningful, while recognising that no single system should become the only thing keeping children safe.
2. Device-level protection cannot prevent every route into abuse
The proposed device protections can play an important role in preventing nude images from being taken, viewed or shared.
But Technology-Assisted Child Sexual Abuse can begin long before an image exists. It can begin with grooming, sexualised conversations, and algorithms connecting children with harmful people or content. Abuse can also cross between online and offline spaces.
Some of these risks are addressed in the Government's package through proposed restrictions on stranger contact and livestreaming.
What is needed: We still need the platforms themselves to reduce the opportunities for grooming, coercion and exploitation before the point at which an image is created or shared.
3. A safer setting is not always the same as a safer product
The Government is trying to avoid a cliff edge at 16, which is welcome. But some of those settings can be changed by the teenager themselves.
For 16 and 17-year-olds, overnight restrictions, autoplay and personalised feeds will be switched off or restricted by default. But, the Government has also confirmed that 16- and 17-year-olds will be able to change their own settings.
This raises a simple question: should children have to keep safety settings switched on, or should some risks be designed out of the platform altogether?
What is needed: Safeguards built into the way products work, rather than relying only on children or parents to keep the right settings switched on.
4. We need to know whether these measures will actually reduce harm
It will not be enough for companies to say that they have introduced age checks, curfews, filters, parental controls or safer defaults. The real test will be whether changes lead to less grooming, less sexual extortion, less unwanted sexual contact and fewer opportunities for abuse and improved wellbeing.
What is needed: Clear measures of success, strong enforcement and transparent reporting so we can see whether the new protections are actually making children safer.
MCF's position: A ban cannot replace safety-by-design
At MCF we are not saying that age restrictions have no role. We are saying they cannot become an alternative to making technology safer.
A ban controls who gets in. Safety-by-design changes what happens when they get there.
Children's safety should not depend on avoiding a platform, finding the right setting or reaching a particular birthday. Where risks can be anticipated, technology should be designed to reduce those risks from the outset.
The Meta settlement shows something important: Technology companies can change their products when they are required to.
But the ambition must go further than time limits, curfews and settings that can simply be changed.
The UK should not settle for keeping children away from unsafe technology. We should require the technology itself to become safer.
The technology can change. The question now is whether we are prepared to require it to.