Today, Keir Starmer stood at a podium in Downing Street and announced that the UK will ban social media for anyone under 16. TikTok, Instagram, Snapchat, YouTube, X, and Facebook — gone for minors, though not YouTube Kids, WhatsApp, or Signal. Regulations could land as early as spring 2027. He called it "a full ban" and said it was "the right choice." He said the UK was going "further than any country in the world," as though that were a point of pride rather than a warning sign.
He also said we need to "resist learned helplessness" about what big tech companies claim is possible. This from the man who personally absented himself from the Commons vote on this exact measure in March — when the government defeated a backbench amendment to do precisely what he's now announcing. One hundred and seven Labour MPs also missed that vote. Funny how the helplessness evaporates once the political pressure gets uncomfortable enough.
The Online Safety Act Was Supposed to Fix This
The Online Safety Act took eight years to pass. Eight years, multiple ministers, three prime ministers, and an extraordinary number of near-collapses over contested provisions — including a clause that would have required platforms to scan encrypted private messages for illegal content, which critics including former National Cyber Security Centre head Ciaran Martin warned would break end-to-end encryption and build surveillance infrastructure the government didn't even have the technology to use yet.
The "legal but harmful" content provisions — powers that would have required platforms to remove content that wasn't illegal but that Ofcom deemed harmful — were eventually stripped out after critics across the political spectrum warned they'd amount to "the biggest accidental curtailment of free speech in modern history." David Davis, a Conservative MP, used exactly that phrase. Kemi Badenoch said the bill was in "no fit state to become law."
What remained was still substantive: platforms required to take responsibility for illegal content and content harmful to children, Ofcom as regulator, fines of up to £18 million or 10% of global turnover. The government called it world-leading legislation that would make the UK "the safest place in the world to be online."
Critics warned at the time — loudly, repeatedly, from multiple directions — that the infrastructure being built would be repurposed. That age verification requirements would expand. That the child safety framing would be used to justify ever-broader controls. The Constitution Society noted explicitly that "under the cover of protecting children," the government had already "conferred on itself future powers to access end-to-end encrypted messages."
People said this was a slippery slope. They were right. It took less than three years.
By July 2025, Ofcom began enforcing mandatory age verification checks for adult content. Within days, VPN usage in the UK surged by 6,430 percent. A petition demanding the Act be scrapped cleared 450,000 signatures. The government said it had no plans to repeal it. Technology Secretary Peter Kyle called what he'd inherited "a very uneven, unsatisfactory legislative settlement." The world-leading thing that was going to fix all of this was barely two years old. So naturally, the answer is more of the same, harder.
We Already Ran This Experiment
Australia's under-16 social media ban took effect on December 10, 2025. Fines for non-compliance could reach $49.5 million AUD. Over 4.7 million accounts were removed in the first month.
By December 11th, the Australian Prime Minister's own TikTok account had comments from people saying "I'm still here, wait until I can vote."
Fourteen-year-old Evelyn, in New South Wales, told the Washington Post she planned to use her mother's face ID to log in to Snapchat and Instagram. That's the entire security model, defeated by a teenager who knows where her mum keeps her phone.
By April 2026, surveys found most Australian teenagers acknowledged the ban wasn't working. The methods: VPNs, parents' biometrics, borrowed devices, platforms not covered by the law. Meta warned the Australian government explicitly that a blanket ban would just push kids to other apps, describing the result as a "whack-a-mole effect" — teenagers use over 40 apps a week, and most aren't covered.
Starmer's government sent ministers to Australia to study the ban before making today's announcement. They went, they looked, they came home and announced it anyway.
The VPN Problem Cannot Be Solved Without Becoming a Police State
The government's answer to circumvention is always some version of "we'll make the platforms block VPNs too." Australia's eSafety Commissioner said platforms would be expected to integrate VPN detection and IP intelligence APIs to flag high-risk IP ranges. What this looks like in practice is a cat-and-mouse game that VPN providers have been winning for a decade. When a platform blacklists a VPN's IP range, the VPN provider deploys new addresses. The streaming industry has been fighting this battle since Netflix went global and has never definitively won. You think platforms scrambling to meet government compliance deadlines are going to out-resource the VPN industry?
Blocking VPN IP ranges also harms adult users with entirely legitimate reasons to use them — privacy, remote working, security. VPNs are a basic recommended cybersecurity tool. And actually banning VPNs? That requires a level of internet monitoring that takes you out of "liberal democracy" territory entirely. One researcher on the age verification question put it plainly: once you put the technology in place, governments have "time and again" been found to abuse it, because "you get this scope creep." The Online Safety Act was supposed to prove that concern wrong. We've already seen how that went.
Banning Accounts Destroys the Safety Tools That Already Exist
Major platforms already have parental controls. Youth account modes with restricted content, engagement limits, oversight tools where parents can link their account to their child's and monitor usage. Imperfect, underpublicised, should probably be defaults rather than opt-ins — but they exist.
When you ban under-16s from having accounts at all, those tools disappear. A teenager who gets on Instagram via their mum's face ID is now in the full adult experience. No parental controls. No content filters. No youth mode. You've pushed them past every safeguard and handed them the unprotected version of the thing you were trying to protect them from.
Scotland's children's commissioner raised this in response to the UK's own consultation: a ban could send children to more unregulated parts of the internet. A joint statement from 42 child protection organisations including the NSPCC called blanket bans "a blunt response that fails to address the successive shortcomings of tech companies and governments." That's not a tech lobby talking. That's the organisation that has made child protection its entire reason for existing.
"Nine in Ten Parents Support It" Is Not an Expert Opinion
The consultation received 116,211 responses. The government is claiming nine in ten parents supported a minimum age of 16 for social media access, and that number is going to be quoted everywhere today. But this is a self-selected sample of people who chose to respond to a government consultation about children's social media. Parents worried about their kids' online activity are vastly overrepresented by design. The government hasn't published the full analysis yet — they've announced the policy based on it. Draw your own conclusions about the sequencing.
More importantly: nine in ten parents wanting something doesn't mean it works. That's not how evidence-based governance functions. Of course nine in ten parents want their children safe from online harm. The question is whether this specific measure achieves that.
When you ask that more carefully, the picture changes. The pre-ban Australian survey found that 86% of young people and 83% of parents said teenagers would find a way around the restrictions. That's not outside scepticism. That's the people the policy is meant to protect, and their parents, telling you it won't work in advance. The government ran the consultation, heard that, then did it anyway.
Two thirds of Australian adults surveyed after the ban said greater parental involvement could make it more effective. The ban is enforcement outsourced to the state precisely because many parents don't want to do the harder work. That's not a moral failing — parenting is genuinely difficult and these platforms are genuinely designed to exploit attention — but let's be honest about what's happening. The government is offering parents a political gesture that feels like action, in exchange for not having to have difficult conversations with their teenagers.
It's worth remembering that in February, while still supposedly weighing all options, the government ran a campaign called "You Won't Know Until You Ask" — urging parents to speak to their children about harmful content online, with ads pushed out on Facebook, Instagram, and TikTok. The campaign acknowledged that half of parents had never spoken to their children about harmful content online. The answer to that gap, apparently, was to ban the platforms rather than close it.
The Molly Rose Foundation — named for a teenager who died after engaging with harmful content online, run by people who want effective child protection rather than effective headlines — published research in April finding that more than 60% of Australian under-16s are still using restricted platforms. Half of children who used restricted platforms before the ban said it made no change to their online safety. One in seven said the ban made them feel less safe. Their chief executive called it "a high stakes gamble" that "delivers a false sense of safety that quickly unravels."
When the organisation named after the child whose death became the most prominent argument for these restrictions tells you it isn't working, you should probably listen.
While We're At It: The Nude Image Scanning Order
On June 8th at London Tech Week, Starmer gave Apple and Google a three-month ultimatum: implement device-level controls that prevent children from taking, sending, receiving, or viewing nude images — across the entire device, not just within specific apps — or face legislation. Home Secretary Shabana Mahmood said tech companies have "a moral duty to act by making it impossible for children to take, share or view nude images." Technology Secretary Liz Kendall said companies should "switch these protections on by default, for every child, on every device."
The government's proposal isn't asking Apple and Google to enable existing opt-in features. Those already exist — Apple's Communication Safety feature detects nudity in Messages, AirDrop, FaceTime, and some third-party sharing flows, on-device. That's a parental control. What the government wants is nudity blocked across the whole device by default — camera, third-party messaging apps, search, browsers, everything — deactivatable only by age verification. Starmer said "this is not an impossible challenge. These are some of the most innovative companies in the world. I believe they can solve it."
What he's describing is client-side scanning: software that analyses content on your device before it's encrypted and transmitted, checking it against a classifier before you can send or view it. Your phone, running a government-mandated content filter in real time, on everything you look at.
Apple already tried this. In 2021, they announced CSAM Detection — scanning photos before iCloud upload against a database of known child sexual abuse material. The security community's reaction was immediate and categorical: any on-device scanning infrastructure, once built, can be repurposed by governments to scan for anything. The mechanism doesn't care what it's looking for; it's the mechanism itself that's the problem. Apple scrapped the project entirely by late 2023, citing the risk of creating new threat vectors and the potential for "a dangerous precedent regarding device surveillance."
Apple built the thing, looked at what they'd built, and decided not to ship it. Starmer is now demanding they build it anyway.
Signal published their response on June 8th, titled "Surveillance Is Not Safety." The proposal operates via "a dystopian combination of age verification and content scanning. This proposal will not safeguard children. It endangers us all." Signal's president Meredith Whittaker has been unambiguous: the app will exit the UK market before it complies. She said this during the Online Safety Act debates. She's still saying it. "Absolutely, 100% walk."
Silkie Carlo of Big Brother Watch: "This will only result in population-wide ID checks for all of us to use our phones, tablets, and laptops." Because that's what age verification actually means in practice. To know that a device belongs to a child, the device has to know who you are. Which means everyone has to prove who they are. Which means your phone, by legal mandate, knows your verified identity and is scanning your content against it. One solutions architect described the logical endpoint: "the device becomes a regulated enforcement point, with inspection potentially occurring at the endpoint before end-to-end encryption protects transmission." That's not a phone. That's a wiretap you paid for yourself.
And even setting all that aside: it won't work. A teenager who wants to send a nude image will use an app the scanner doesn't cover, or a platform outside UK jurisdiction, or a secondary device, or a browser through a VPN. The same kids who were back on TikTok on day two in Australia, the ones who got around it using their mum's face. They'll find a way around a nudity filter in approximately the amount of time it takes to search "how to turn off content scanner UK."
What you will have built, in exchange for that ineffective protection, is the technical and legal infrastructure to scan content on every phone in the country. History is not kind about what governments eventually do with that kind of infrastructure.
The Right Way Is Hard
Algorithmic liability. If a platform's recommendation engine surfaces self-harm content to a vulnerable teenager, the platform should face consequences scaled to the harm caused — not a fine that's a rounding error in their ad revenue, but consequences that actually hurt. That requires investigation infrastructure, specialist digital courts, and the political will to take on companies with more lawyers than most governments have employees.
Addictive design regulation. Infinite scroll, autoplay, push notifications optimised for engagement over wellbeing — these are design choices, not natural laws. Regulate them, not just for children but for everyone, because the same features that harm a 14-year-old harm a 40-year-old, just more slowly. Set minimum friction requirements. Ban variable-ratio reward schedules in recommendation systems. Make engagement-maximisation that demonstrably worsens user wellbeing a regulatory offence.
Real data minimisation. The data that makes targeted advertising so effective on teenagers is the same data that makes recommendation systems so good at finding their specific vulnerabilities. Restrict data collection for minors, enforce it with audits, and fine based on the volume of illegally collected data — not on the existence of a policy document claiming they don't do it.
Proper funding for digital literacy. Not a campaign with TV ads and Facebook posts. Actual curriculum, actual teacher training, actual time in schools for young people to learn how recommendation algorithms work, what engagement design is, how to recognise manipulation. The literacy that makes people resilient to online harm.
None of that is a headline. None of it resolves before the next election. None of it lets you stand in Downing Street and say you went further than any country in the world.
The UK watched Australia implement this ban. They watched the circumvention methods spread across social media within 24 hours. They watched Meta warn it wouldn't work. They watched surveys confirm, months later, that it hadn't. They consulted for three months and received 116,000 responses.
They did it anyway.
The under-16s will be back on their accounts within a week. Starmer should talk to some of them. They'd explain the part about face ID.