The short version
- In force now: UK Online Safety Act codes, the EU DSA (including Article 28 minor protections), the amended US COPPA Rule, and Australia's social media minimum age from 10 December 2025.
- Still proposed: US KOSA (folded into H.R. 7757, passed the House June 2026 but stalled in the Senate) and the EU CSA Regulation.
- UK child safety duties applied from 25 July 2025 and push toward highly effective age assurance; fines reach 18 million pounds or 10 percent of global revenue.
- The EU temporary voluntary-scanning derogation lapsed after 3 April 2026, creating uncertainty around voluntary CSAM detection.
- Prioritize in-force regimes and their deadlines; monitor proposals rather than pre-building to them.
Child-safety regulation for online platforms is moving quickly and unevenly across jurisdictions. Some rules are in force with hard deadlines behind them. Others remain proposals that have stalled. This is a current, dated map for trust and safety and policy teams, accurate as of July 2026. It describes obligations and status; it is not legal advice.
United States: mostly proposed, one rule updated
The Kids Online Safety Act (KOSA) remains unenacted. In 2026 the House folded KOSA and COPPA 2.0 into an omnibus package, the Kids Internet and Digital Safety (KIDS) Act (H.R. 7757), which the House passed on June 29, 2026. The House version omits the "duty of care" that Senate sponsors consider essential, and Senate sponsors have signaled the House text is unacceptable without it. As of now the package is not law, and passage this session is uncertain. Treat KOSA as proposed.
COPPA is the one piece of US federal child-safety regulation that is both in force and recently updated. The Children's Online Privacy Protection Act and its implementing Rule apply to operators that collect personal information from children under 13 and require verifiable parental consent, enforced by the Federal Trade Commission. The FTC finalized amendments to the COPPA Rule in January 2025. The amended Rule took effect June 23, 2025, with a general compliance date of April 22, 2026. The amendments add separate consent for targeted advertising, expand the definition of personal information to include biometric and government identifiers, and impose data retention limits.
United Kingdom: Online Safety Act in force, codes rolling out
The Online Safety Act 2023 is in force, and Ofcom is the regulator implementing it through codes of practice and risk-assessment duties. The rollout has come in phases.
The illegal harms duties came first. Under Ofcom's illegal harms regime, in-scope user-to-user and search services had to complete illegal content risk assessments and the illegal content safety duties became enforceable in March 2025. The assessed harms include child sexual exploitation and abuse alongside terrorism, fraud, and other categories.
The child-specific duties followed. Ofcom published its Protection of Children Codes in April 2025. Services likely to be accessed by children had to complete children's risk assessments by 24 July 2025, and the child safety duties applied from 25 July 2025. These duties push services toward highly effective age assurance, safer recommender systems, and moderation of content that is harmful to children. Ofcom's enforcement powers include fines of up to 18 million pounds or 10 percent of qualifying worldwide revenue, whichever is greater.
European Union: DSA in force, CSA Regulation stalled
Two EU instruments matter here, and they are at very different stages.
The Digital Services Act (DSA) is in force. Article 28(1) requires online platforms accessible to minors to put in place appropriate and proportionate measures for a high level of privacy, safety, and security for minors, and Article 28 restricts advertising based on profiling where the platform is reasonably certain the user is a minor. On 14 July 2025, the European Commission published guidelines on the protection of minors under Article 28. The guidelines set out a non-exhaustive list of measures, such as private accounts by default for minors and modified recommender systems. Following them is voluntary and does not guarantee compliance, but the Commission will use them to assess compliance with Article 28(1).
The proposed CSA Regulation (2022/0155) is a different story. The Commission proposed it in May 2022 to require providers to detect, report, remove, and block CSAM and to establish an EU Centre. It remains a proposal and is contested. Per eucrim, the Council reached its position on 26 November 2025 and deliberately excluded mandatory detection orders. Trilogue negotiations began in December 2025, but disagreement over detection orders persists. Separately, the temporary derogation that had allowed providers to voluntarily scan for CSAM under the ePrivacy rules lapsed after 3 April 2026, following the European Parliament's rejection of a proposed extension in March 2026. The net effect is legal uncertainty around voluntary detection in the EU and no in-force CSA Regulation.
Australia: eSafety regime active, minimum age now live
Australia's Online Safety Act framework, administered by the eSafety Commissioner, has moved from codes to a headline age restriction.
The most significant development is the social media minimum age obligation, which commenced on 10 December 2025. Age-restricted social media platforms must take reasonable steps to prevent Australians under 16 from creating or keeping accounts. The eSafety Commissioner published regulatory guidance on 16 September 2025 taking a principles-based approach to "reasonable steps" rather than mandating specific technical measures. eSafety has indicated that platforms including Facebook, Instagram, Snapchat, Threads, TikTok, Twitch, X, YouTube, Kick, and Reddit are in scope. Penalties for systemic failure to take reasonable steps can reach up to 49.5 million AUD, and the obligation sits on platforms, not on children or parents.
Alongside the age restriction, eSafety's phase 2 industry codes were registered in September 2025 and take effect from 9 March 2026, covering categories such as app distribution platforms, social media services, relevant electronic services, and designated internet services.
How to read the map
The pattern is clear. The UK, EU (DSA), Australia, and US COPPA are live regimes with real deadlines and enforcement. KOSA and the EU CSA Regulation are proposals whose futures are unsettled. Platforms operating across these markets should prioritize the in-force obligations, track the proposals for scope changes, and avoid building compliance programs around laws that have not passed.
Sources and further reading
- Federal Trade Commission (COPPA Rule amendments). https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data
- Ofcom (Protecting people from illegal harms). https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/statement-protecting-people-from-illegal-harms-online
- European Commission (Guidelines on protection of minors). https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors
- eucrim (CSA Regulation Council position). https://eucrim.eu/news/csa-regulation-council-position-reached/
- eSafety Commissioner (Social media age restrictions). https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions