Every parent wants the same thing: kids who are safe online. I've spent thirty years in cybersecurity, including time as an NSA contractor and as the chief technologist of a $10 billion IT business. Since becoming a dad, I've turned that work toward family technology, and today Family IT Guy reaches millions of families a month. Keeping kids safe on the internet is the problem I chose to spend my career on. This is what I have learned about it, and about the laws now being written to solve it.
The two dangers that actually threaten kids
Two problems do the real damage, and both are serious.
The first is addictive algorithms. Social media companies put behavioral scientists and engineers side by side to build systems that capture and hold attention: bottomless feeds, autoplay, notifications tuned to pull a kid back, variable rewards that work the way a slot machine does. These are product decisions, not accidents. Children are especially exposed, because the part of the brain that governs impulse control and risk does not finish developing until the mid-20s. A teenager's brain is not built to resist systems engineered to be hard for adults to put down.
The results show up in the data. Suicide is now the second leading cause of death for people ages 10 to 24, and the suicide rate for children ages 10 to 14 tripled between 2007 and 2019, the same years social media moved into kids' pockets and bedrooms. The human version of that statistic looks like Alexis Spence, who made an Instagram account at 11, two years under the platform's minimum age. Its algorithm steered her toward starvation and self-harm content. By 12 she had drawn a self-portrait labeled "stupid ugly fat" and "kill yourself." At 15 she was in emergency treatment for an eating disorder and suicidal thoughts. Hers became the first lawsuit to draw on Meta's own internal research.
The second danger is anonymous communication: the open pathways that let strangers reach children through games, messages, comments, and virtual worlds. About one in three internet users worldwide is under 18, and behind a friendly username can be someone using grooming tactics to set up a meeting. The reports bear it out. Sextortion, where someone coerces a child with explicit images, was reported to the national tip line 187,000 times in 2023, 546,000 times in 2024, and roughly a million times in 2025. In 2025 a 10-year-old girl in California was kidnapped by a stranger she met through a game and a chat app.
AI makes both dangers worse. It makes the recommendation engines better at holding attention and the feeds impossible to exhaust. It automates grooming, generates abuse material, and powers chatbots built to create emotional dependency in children who cannot tell a machine from a friend.
These are real problems, and they deserve real solutions. The useful question is which solutions actually reach them.
What actually protects them
The one protection that cannot be uninstalled is a child who understands why. That comes from parents doing, not only knowing: setting up the controls, modeling a healthy relationship with technology, explaining the reasons, and staying close enough to catch trouble early. The tools to do it already exist. Apple and Google family accounts gate every download and purchase today, at no cost, with the decision sitting where it belongs, in the family. The work is teaching parents to use them and giving kids the judgment to carry when no one is watching.
Government has a real role too, and it is already working. Existing consumer-protection and product-liability law is reaching the companies that built the harm: in March 2026 two juries found Meta liable for harming children under existing state law, including a $375 million verdict in New Mexico. Criminal enforcement reaches the predator in the chat, where no age check can. Those are levers worth funding and strengthening.
There are also ways to get companies to protect kids on purpose. Today, if a company identifies a user as a child, that knowledge can trigger legal liability, so the rational move is to avoid knowing: don't ask, don't check, build one product for everyone and let kids use it anyway. A safe harbor would flip that. Protect a company that acts in good faith to find and protect minors, the way Good Samaritan laws protect a bystander who steps in to help, and you reward the behavior you want instead of punishing it. Tax credits for child-safety research, funding for digital-literacy education, and certification for products built to be safe all do the same thing: they give companies a reason to protect kids, instead of creating another system of records to maintain.
Where government helps, and where it doesn't
Government is a lever for accountability. It can hold a company responsible for harm. It is not the right place to make a family's decisions, and age-verification mandates put it there.
To check that a user is old enough, a system has to collect identity information on every user, including every adult. That information does not disappear when the session ends. It becomes a standing record of who tried to reach what, held somewhere, governed by whatever rules exist at the time and by whoever holds power next. Every database of personal information ever built has eventually been used beyond the purpose it was created for. The question is not whether that happens, but when.
The common answer is that the technology is private now. Some of it can be. A zero-knowledge proof is a method that confirms a single fact, like "over 18," without handing over the underlying ID. That is the good version, and it is real. But even the good version has to be drawn from a central identity database, and that database is the part that gets breached. France built the most privacy-protective design in the world and anchored it on the national identity system. In April 2026 a 15-year-old pulled 11.7 million records out of that system through a basic flaw. The cryptography did not fail. The database underneath it did.
And the mandate does not even reach the harm it is sold to fix. Sextortion and grooming happen in the chat, inside an app the child already has. An age check at the download door never touches that room. Worse, the check moves kids rather than stopping them. A pre-registered study by researchers at NYU and Stanford looked at search behavior across 18 states with these laws: searches for the compliant site fell 51 percent, searches for a non-compliant site rose 48 percent, and searches for VPNs, the tools that route around the check, rose 24 percent. Australia removed 4.7 million under-16 accounts by December 2025, and a survey months later found more than 60 percent of those teenagers still had access. The system produced records, not safety.
None of this is an argument against caring. It is the reason a regulatory mandate is the wrong tool for a family's job.
The questions worth asking
If you are weighing one of these laws, three questions are worth sitting with, about that bill and any bill like it.
What specific harm are we solving, and how will we know if it worked? Most of these bills define no success, set no measurement, and leave no way to find out if the problem they target gets worse.
Does the solution match the problem? If the harm is addictive algorithms, a mandate at the app-store door changes no algorithm. If the harm is predators reaching kids, it changes no chat system. It gates access to the store. The harm happens inside the apps.
What would happen if we rewarded the outcome we want instead of punishing the failure? Safe harbors, tax credits, education funding, certification. None of them require a database of every child's identity and activity. All of them work toward the outcome we actually want.
The pressure to protect kids is real, and so are the dangers. The choice is whether we meet them with the tools that reach the harm, or with a system that records everyone and reaches none of it.
If you are working through one of these questions, I am glad to walk through the technical reality with you or your staff.
Ben Gillenwater, Family IT Guy
Get in touch
The full reasoning behind this, with citations: A Declaration of Principles