2 September 2026
We Have Got Children and Social Media Wrong
We have spent years deciding who should be allowed onto social media. We have barely asked how these platforms are built.
By June Ho
Cover photo credit: Cottonbro Studio / Pexels
In the span of little more than a month, a series of watershed moments has reshaped the landscape of online platform accountability. On August 26, Meta, the owner of Facebook and Instagram, agreed to a settlement expected to cost up to US$16.7 billion (S$21.2 billion) to resolve claims by 51 consolidated actions by American states and territories alleging that its platforms violated child privacy laws and endangered young users. The deal capped years of litigation that had already seen the company ordered to pay US$942 million (S$1.2 billion) in New Mexico alone.
In late July, the European Commission had signalled its intention to designate Roblox as a “very large online platform” and ChatGPT as a “very large search engine” under its Digital Services Act, marking the first time a gaming platform and a generative AI chatbot would be brought under the EU’s most stringent digital regulatory tier. These developments, taken together, represent an unmistakable inflection point: regulators and courts are no longer content to treat online harms as an inevitable externality of the digital age.
What makes this regulatory reckoning especially urgent is how deeply digital platforms are woven into our children’s lives. Telegram, Snap, Signal, Roblox and Sesame may be unfamiliar territory to many parents. To their children, they are part of everyday life: places to play, communicate, find friends and, increasingly, encounter harm.
These services may be classified as messaging platforms, social-media services, games or AI tools. But such distinctions mean little to children who flit among them with ease.
An Urgent Wake-Up Call
Singapore is beginning to recognise the scale of the problem. At the recent National Day Rally, Prime Minister Lawrence Wong said platforms with inadequate safeguards could be required to raise their minimum age above 13. He also announced stronger age-assurance measures and protections against design features that keep young users compulsively glued to their screens.
This could mark a watershed in Singapore’s approach to online safety: a shift from regulating what children see online to examining how digital services gatekeep and how they are designed to capture and hold children’s attention.
The shift is overdue. Features, including infinite scroll, autoplay, engagement-optimised algorithms, beauty filters, and the dopamine reward of the “like” button, engineered to exploit developing minds for profit will need to go.
As part of the consent judgment in the Meta case, the company must make changes to its apps, including implementing daily usage limits and “night time blocks” for teenagers who use the company’s apps, “enhanced age assurance measures” that would prevent children from using them, and the creation of additional tools for parents and guardians. Meta’s trial may be over, but the underlying issues extend far beyond one company. The young move effortlessly between social media, games, messaging apps, livestreams and chatbots. The risks can move with them.
Regulation must therefore follow the risk to the child, regardless of how a company classifies its platform.
The Limits of Singapore’s Current Approach
Singapore already has a substantial online-safety framework. The more established platforms are designated under IMDA’s Code of Practice for Online Safety, which focuses on content moderation, reporting, and transparency. It does not, however, address the design features at the heart of the Meta case.
Singapore’s regulatory framework for online safety rests principally on two instruments. The Online Safety (Relief and Accountability) Act 2025, which commenced in June this year, together with the Online Safety Commission, provides victims with statutory remedies after harm has occurred. It creates liability for communicators, administrators, and platforms, but generally operates only once harmful content has been communicated and reported.
The platform’s duty is therefore substantially notice-based, rather than design-based. Yet a child who is being groomed online may not recognise the manipulation, much less know that it should be reported.
IMDA’s Code of Practice for Online Safety is more preventive. It requires designated social-media services to implement system-level measures to reduce exposure to harmful content. But only six platforms are currently designated: Facebook, HardwareZone, Instagram, TikTok, X, and YouTube.
That leaves a potentially important vacuum. Some of these platforms are hardly at the centre of most children’s digital lives. It omits the games, messaging apps and other online spaces through which they move every day.
Telegram illustrates this challenge. Its dating bot Leomatch, which reportedly has more than 14 million monthly users, has been used to prey on minors. In February 2026, a 25-year-old man was sentenced to 11 years’ imprisonment and 10 strokes of the cane after using the bot to lure two girls under 16 into sexual activity. Its channels distributing sexual-abuse material have also resurfaced after earlier versions were shut down.
As the net tightens around platforms that maintain a corporate presence and engage with legal systems, a troubling paradox persists. Platforms that cooperate — however imperfectly — bear the brunt of enforcement, while those that remain opaque, jurisdictionally elusive, and systemically unresponsive continue to operate largely beyond the reach of the law.
The Ministry of Home Affairs has acknowledged the risks. Yet Telegram remains outside a regime built chiefly for conventional social services. Telegram has a well-documented history of non-responsiveness to law enforcement. It was only after founder Pavel Durov’s arrest in France in August 2024 — on charges including complicity in enabling the distribution of child sexual abuse material, drug trafficking, and refusal to cooperate with investigators — that Telegram updated its privacy policy to acknowledge it may share user data with law enforcement under valid legal requests. The platform’s decentralised nature and multi-jurisdictional corporate structure make it exceptionally difficult for any single country’s authorities to compel compliance with local laws.
So ironically, the more established platforms that engage with the system, maintain local corporate presences, and cooperate with regulators expose themselves to litigation and enforcement, while platforms that remain opaque, unresponsive, and jurisdictionally elusive can be harder to hold to account.
Closer to home, the original SG Nasi Lemak Telegram group with more than 11,000 obscene photos and videos was created in November 2018 and grew to more than 44,000 members at its peak, with 29 administrators, before it was shut down. But similar copycat groups have continued to appear, circulating photos and video clips of women and schoolgirls — including minors — grabbed from platforms such as TikTok and Facebook, with victims’ usernames clearly visible.
The persistence of these groups points to a structural enforcement gap: even when prosecutors successfully pursue individual perpetrators, Telegram’s lack of cooperation allows new groups to spring up with little friction. Its capacity to host groups of up to 200,000 members, lax age verification, and its resistance to proactive content moderation in private spaces create a cycle that domestic criminal enforcement alone cannot break.
Roblox exposes the same mismatch. With more than 79 million daily active users — over half reportedly under 13 — it is simultaneously a game, a social space and a communications network. To paedophiles and sexual predators, it is a playground. Their modus operandi cited in reports is consistent: grooming begins in-game before children are “off-linked” to encrypted messaging services, where oversight becomes harder.
In April 2026, Roblox agreed to pay US$35.8 million (S$45.5 million) to settle claims by three US states that it failed to protect young users from predators, grooming, and exposure to sexual and violent content. As part of the settlements, it also committed to stronger age verification, including facial age estimation, government-issued ID checks, and behavioural monitoring to flag users whose ages may have been misclassified.
What Singapore Must Do
Singapore has articulated a sensible “third way” that rejects both blanket bans and reliance on industry self-regulation in favour of targeted, platform-accountable intervention. That instinct is sound. But this middle ground only works if backed by enforceable design obligations.
Four recommendations would make the framework more coherent.
First, broaden the regulatory perimeter. Regulatory coverage should follow the child, not the platform category — regardless of whether it considers itself social media, a game, a messaging app or an AI companion.
Telegram’s Leomatch bot and Roblox’s social features create risks that may rival or exceed those associated with designated platforms. IMDA’s designation framework already permits the designation of services with “significant reach or impact in Singapore”. That principle could be applied more pre-emptively and more consistently across the digital services children use.
Second, mandate safety by design. IMDA’s Code of Practice for Online Safety should impose positive design duties, not merely relying on reactive reporting requirements. Any feature accessible to users under 18 should require a safety impact assessment at the design stage, submitted to IMDA for review before deployment. This would move child safety, which is key, to the drawing board.
Third, require algorithms to detect red flags such as escalating intimacy, age-mismatched communication and solicitation of personal information. These should be reviewed by trained staff before any accounts are restricted or reports are filed, with safeguards against false alarms and arbitrary enforcement.
In this regard, the Singaporean start-up Empathly — founded by a then-18-year-old Jamie Yau whilst a student at Singapore Polytechnic — is already helpful. It uses AI to detect harmful content across English, Hokkien, Cantonese, Malay, and Singlish before it is sent. The tool prompts users to reconsider their language without blocking communication. Such tools deserve a structured pathway from prototype to deployment.
Fourth, address cross-platform migration. The practice of moving children from one service to another demands a coordinated response. Regulators should establish a centralised risk-signal repository so when a user is flagged for predatory behaviour on one platform, that risk signal should follow across designated services.
This concept mirrors, in broad terms, the approach taken in financial-crime regulation, in which suspicious transaction reports flow to a central authority regardless of the reporting institution.
The Room He Walked Into
I write this not only as a lawyer, but also as a mother.
My eight-year-old son is neurodivergent. A few months ago, he discovered online gaming. Watching him light up over it has been one of the unexpected joys of this year. Gaming gives him a way to play, pursue the things he loves, and feel a little more connected to a world that doesn’t always make room for him.
I do not want a law that treats his presence online as the problem. Nor do I want one that assumes every child experiences the digital world in the same way.
I want a law that makes sure the room he’s walked into isn’t designed to exploit the trust and attention he brings to it.
That is what safety by design means, stripped of its regulatory language. A child’s capacity for deep focus is not an engagement metric. A child’s trusting nature, or difficulty recognising manipulation, is not consent to be manipulated.
Singapore already has the institutional machinery, legislative scaffolding and the political will to do more.
The remaining question is whether we will build that protection into the architecture before the next child walks through the door — or wait until after the harm has occurred.
More Forefront