For years, online safety has largely been treated as a platform problem. If something harmful happened on social media, in a game, or on a messaging app, attention usually turned to the company running that service. The phone in someone's hand was mostly just the way they got there, but that distinction is starting to blur.
The UK government has now said it is preparing legislation that would require major technology companies to build stronger child-safety protections directly into devices. The immediate focus is intimate imagery, with ministers wanting technology that can stop under-18s from taking, viewing, or sharing nude images, rather than relying only on individual apps to intervene after an image has already been created or sent. The move follows a three-month government work program with Apple and Google. The government says both companies made progress, but not enough to match its ambition.
This is a notable change in where responsibility is being placed and may indicate that the next phase of online safety could be built into the device itself.
Phones are becoming part of the safety system
The idea is not entirely new. Apple's Communication Safety feature, for example, can detect potentially nude photos or videos on a child's device, blur them, and present warnings and support before the child chooses what to do next. Apple says the feature is on by default for children under 18 on supported devices running current software. However, what is changing is the expectation around measures like these—they are moving from optional product features into the regulatory conversation.
In June, the UK government challenged Apple and Google to develop stronger device-level protections. On September 8, Culture Secretary Lisa Nandy told Parliament that the companies had made "meaningful changes" at the operating-system level, including progress toward blocking rather than simply blurring nude imagery on underage devices. But ministers said the work still fell short and committed to preparing primary legislation.
The government also wants apps used by children to prevent access to or sharing of nudity, creating protection across more than one layer of the technology stack. This matters because a child does not experience the internet as a neat collection of regulatory categories. For example, a photo can begin in a camera, move through a messaging service, be saved to cloud storage, be reposted on a social platform, and then be used to threaten, blackmail, or humiliate someone elsewhere. Safety measures attached to only one service can leave gaps between all the others.
A wider move toward layered protection
Ofcom's 2026 report on age assurance argued that there is no single age-checking method that eliminates circumvention and called for "layers of protections across the system." The regulator specifically pointed to app stores, operating systems, and device-level technology as areas where further innovation is needed.
This is a useful way to understand the direction of travel because online safety has often been approached service by service, e.g., make the social network safer, make the game safer, and make the adult site safer. Layered protection asks a different question: what if some safeguards sit underneath all of those services?
Age signals are an obvious example; if a device or operating system can establish an age range in a privacy-preserving way, that information could potentially support safer defaults across multiple apps. The same logic is now being applied to intimate imagery. Instead of waiting for an image to reach a platform's moderation system, a safeguard closer to the device could interrupt the process earlier.
That does not make platform responsibility less important. If anything, the emerging model appears to spread responsibility across more of the ecosystem, such as devices, operating systems, app stores, apps, and online services, each handling part of the problem.
Why prevention is important for intimate-image abuse
The policy debate is happening against a very difficult backdrop, with the government cited Internet Watch Foundation data showing a sharp rise in reports linked to child sexual extortion. It also referred to the high prevalence of imagery the IWF classifies as "self-generated"—a term the IWF itself says can be misleading, because children may have been groomed, coerced, or extorted into creating or sharing it. Those findings help explain why policymakers are looking further upstream.
Once an intimate image is in somebody else's hands, the harm can change quickly. It may be copied, redistributed, manipulated, or used as leverage. Our guidance on sextortion explains how intimate images or messages can be used to coerce someone into sending more content, paying money, or complying with other demands. Our sexting resource also highlights the loss of control that can follow when an image is screenshotted or shared beyond its intended recipient.
That makes prevention an appealing goal. Stopping an image from being created or sent in a high-risk situation can be very different from trying to contain it after it has spread. The underlying problem is that prevention is also where the debate becomes more complicated.
Safety at device level comes with difficult questions
A safeguard built into a phone can reach places that an individual social network cannot. That is precisely what makes it powerful, but also what makes questions about privacy, accuracy, and control unavoidable.
How does a device know that its user is under 18? What information has to be collected or inferred to establish age? Can sensitive-image detection happen entirely on the device? What happens when automated systems misclassify an image? How easy should it be for a parent, teenager, or adult to change the setting? And how do protections work across encrypted services without weakening the security people rely on?
Those are not arguments against device-level safety, but they are questions that need serious answers if it is going to earn public trust. Ofcom's age-assurance work makes a similar point that stronger protections still have to comply with privacy and data-protection obligations.
There is also a question of proportionality; a system designed to protect a 10-year-old may not be appropriate for a 17-year-old in exactly the same form. Effective safety design has to account for the fact that children gain independence as they grow while still recognizing that older teenagers can face serious risks online.
The bigger change is who is expected to act
Perhaps the most important part of the recent announcement is not the technical proposal at all, but the change in expectation.
For a long time, online safety advice placed a great deal of responsibility on individuals and families to use privacy settings, think before you share, block harmful accounts, report abuse, and talk to a trusted adult. All of that does still matter, but it is increasingly being joined by a different principle that companies should design technology so people, especially children, are less likely to encounter preventable harm in the first place.
We are seeing that principle surface in several areas at once, with age assurance becoming more widespread, governments scrutinizing recommender systems and persuasive design, and regulators demanding stronger default protections for children. Now the device and operating system are being pulled more explicitly into the same conversation.
For digital wellbeing, that shift is especially important. The experience of being online is not created by one app alone; it is shaped by the device, its defaults, the operating system, the services installed on it, and the choices those services make about safety. Looking at those layers together is a more realistic reflection of how people actually use technology.
What happens next?
The UK legislation has not yet been introduced, so some of the hardest details remain unresolved. The government has also left room to reassess whether legislation is necessary if companies develop and implement adequate technical solutions while that work is underway. That means the final shape of device-level protection could still change significantly.
Even so, the direction of travel is difficult to ignore. Governments and regulators are no longer looking only at the platform where harm becomes visible; they are beginning to look at the infrastructure underneath it.
If that approach continues, future online safety debates may be less about whether a particular app has the right reporting button and more about what protections should exist before an app is even opened. The smartphone has spent the past two decades becoming the gateway to our digital lives, and it may now be asked to become one of their first lines of defense.
