The UK government announced its intention to legislate on device safety, specifically targeting the ability of under-18s to take, send, or view nude images. This follows the failure of a three-month deadline in June, during which Apple and Google were asked to submit proposals preventing such images.
Culture Secretary Lisa Nandy told MPs that while Apple and Google made commitments and implemented meaningful changes, their proposals do not address the scale of the crisis. She stated that government legislation would follow as quickly as Parliament could process it.
Apple’s response centred on its Communication Safety feature, introduced in 2021. The company committed to strengthening this capability further. Google similarly pointed to progress made and reiterated its ongoing commitment to the issue.
Three major organisations—the NSPCC, Internet Watch Foundation (IWF), and Molly Rose Foundation—welcomed the government’s commitment to fast-track legislation.
The IWF’s most recent report provided crucial context for urgency. In 2025, IWF recorded that one quarter of all child sexual abuse material (CSAM) it documented consisted of self-generated images. Over 12 months, this amounted to more than 140,000 pieces of self-generated material. The scale shifts the nature of the problem. This is not solely external predation; substantial harm occurs through peer pressure, coercion, and children’s own limited understanding of consequences.
Privacy advocates immediately raised concerns about implementation methods. Device-level blocking of such images could require age verification systems—an intrusive measure raising privacy concerns about what data companies would hold on minors. Client-side scanning, where devices scan images before transmission, similarly raises surveillance anxieties. If implemented across all devices, such scanning becomes a powerful monitoring infrastructure.
The government denied that its legislation would mandate surveillance or create adult access to private information. The precise mechanism—how devices would prevent such images without scanning all content—remained unspecified in public statements.
The tension is real. Preventing under-18s from accessing harmful content requires some form of detection or restriction. Doing so without creating surveillance infrastructure or requiring invasive age verification is technically challenging.
The June deadline’s failure reflected this difficulty. Device makers could not propose technically feasible, privacy-respecting solutions at scale. Now government legislation will impose a requirement, but the question of how to implement it remains contested.
What distinguishes this from other tech regulation is its focus on child protection rather than commercial behaviour or data practices. The IWF figures—140,000 self-generated CSAM images in a single year—establish genuine harm requiring response. The challenge lies in responding effectively without creating broader surveillance capabilities that could be repurposed.
Parliament’s process will test whether legislators can scrutinise technical proposals rigorously enough to distinguish protective measures from surveillance infrastructure. The stakes are both child safety and privacy rights.
**Word count: 416**
Let me write Article 6: