Online safety for children looks different than it did even two years ago. The apps have changed, the law has changed, and so has the type of harm parents need to watch for. Scams now arrive with AI-generated voices. Grooming has largely moved into private messaging. And the Online Safety Act 2023 has started to change what your child actually sees on the apps they use every day.
This guide sets out the current picture for the UK and Ireland: what the latest research says, the risks worth your attention right now, age-by-age advice, the technical settings that make a real difference, and where to go if something goes wrong. We will also cover how to talk to your child about all of this without it turning into an interrogation.
Table of Contents
Why Online Safety for Children Looks Different in 2026
Two things have shifted the ground under this topic. The first is regulation. The second is how quickly AI tools have moved from novelty to everyday use among children. Both change what “keeping your child safe” actually involves in practice.
What the Latest Ofcom Data Shows
Ofcom’s Children and Parents: Media Use and Attitudes report, published in May 2025, gives the clearest recent picture of how UK children actually use the internet. One in five children aged three to five (19%) now has their own mobile phone, rising to nearly a third (30%) of six- and seven-year-olds. Social media use among three- to five-year-olds has risen sharply too, from 29% to 37% in a single year.
There is a genuine bright spot in the data. Ofcom found that 94% of eight- to seventeen-year-olds who go online using their phone have at least one restriction in place, whether that is a school policy or a setting at home, and 92% can recall having had a lesson at school about staying safe online. Awareness has clearly improved. The gap now is less about whether children have heard the message and more about whether the tools and habits at home keep pace with how young they are when they get their first device.
How the Online Safety Act Changes What You’ll See
The Online Safety Act 2023 is no longer a piece of legislation sitting in the background. Ofcom, the regulator responsible for enforcing it, has moved into active enforcement. In March 2026, Ofcom fined Kick Online Entertainment SA £800,000 for failing to put age checks in place to stop children reaching pornographic content, with a further penalty added for not responding to information requests on time. That same month, Ofcom wrote to major platforms requiring them to enforce their own minimum age policies using what the Act calls “highly effective age assurance,” giving them until the end of April 2026 to explain how.
In practice, this means your child may start encountering age checks, prompts to confirm their date of birth, or restricted settings by default on platforms that previously asked nothing at sign-up. If a service your child uses is likely to be accessed by under-eighteens, it now has a legal duty to assess and manage the risks that come with that, not simply publish a set of community guidelines and hope for the best.
The Risks Parents Actually Need to Watch For
Stranger danger is not the whole picture anymore, and treating it as the only risk leaves gaps. A useful, current approach to online safety for children needs to cover the threats below, since they are the ones showing up most consistently in UK data right now.
Grooming and Private Messaging
NSPCC data drawn from 44 UK police forces recorded 7,263 Sexual Communication with a Child offences in 2024/25. A large share of these cases begin on public-facing platforms such as gaming apps or social media, before the conversation moves to private or encrypted messaging, where it becomes far harder for anyone outside the conversation to notice a problem developing. NSPCC research published in November 2025 makes the same point: once contact shifts into private messaging, the protections most platforms rely on largely stop working.
This is why the setting worth checking first is not a content filter but who can message your child directly, and whether that list is limited to people they actually know.
AI-Generated Images and Deepfakes
AI tools that clone a voice or fabricate an image are no longer a niche threat. Half of children now use tools like ChatGPT for schoolwork or for fun, according to Ofcom’s 2025 research, and the same underlying technology is being used to create fake images and voice messages that can be used to deceive, embarrass or extort. A simple way to explain this to a younger child is to describe it as a “digital mask”: something can look and sound exactly like a friend, or even like you, without actually being them.
Financial Scams and In-Game Spending
The scale of this problem has grown quickly. Research released for Safer Internet Day 2025 by the UK Safer Internet Centre found that 46% of eight- to seventeen-year-olds have been scammed online, and 9% have lost money as a result. A separate study commissioned by the NSPCC found that nearly one million children aged eleven to sixteen in Britain, 839,127 of them, had been scammed online in the previous year, with an average loss of £103 per incident and more than 3,000 scam attempts aimed at young people every single day.
Fake giveaways, phishing links disguised as game currency offers, and marketplace scams on social media are the most common routes in. If your child has ever asked to borrow your card for an in-game purchase, that is a good moment to talk through how to spot a fake offer before it happens again, not just to say no once and move on. For older children starting to manage their own money online, our guide to identity theft protection covers the habits worth building early, such as never reusing a password across gaming and banking accounts.
Cyberbullying
NSPCC Childline data shows 6,617 counselling sessions in 2024/25 where bullying was the main concern raised, with young people describing hurtful posts made about them and messages that followed them from school into their bedroom at night. Cyberbullying does not stay contained to one app or one hour of the day, which is part of what makes it harder for a child to switch off from than bullying that happens only at school.
Online Safety for Children by Age
There is no single set of rules that suits a five-year-old and a fifteen-year-old equally. What follows is a rough guide by age, built around what children actually do at each stage rather than an ideal most families never reach.
Early Years (3 to 5)
At this age, supervision is still largely physical: sitting with your child, choosing what they watch, and treating any device as something used together rather than handed over. Given that more than a third of children this age now use some form of social media, usually through a parent’s account, check exactly what “using it together” means in practice and whether your child ever has access on their own.
Primary School (6 to 10)
This is typically when a child’s first personal device arrives, and Ofcom’s data shows nearly a third of six- and seven-year-olds already have one. Set up parental controls before handing over the device, not after a problem appears, and agree together which apps and games are allowed. SafeSearch, available on Google, Bing and other major search engines, is worth turning on now if it is not already.
Preteens (11 to 13)
Most social platforms set a minimum age of thirteen, but plenty of children join earlier using a false birth date, so age gates alone are not something to rely on. This is the age where private messaging becomes more common and where conversations about grooming, in-game spending, and how to block or report someone start to matter more than filtering software.
Teenagers (14 and Over)
Older teenagers need less direct oversight and more practical judgement, since most of what they do online now happens outside anything you can realistically monitor. Shift the focus toward privacy settings they control themselves, how to recognise a scam or a fake profile, and what to do if something goes wrong, rather than trying to see every message. Our piece on positive online behaviours has practical starting points for building that judgement rather than just restricting access.
Setting Up Practical Protections
Technical settings will not replace conversation, but they buy time and reduce the number of things that can go wrong while your child is still learning to spot risks themselves. Good online safety for children is mostly a handful of settings, checked properly once, rather than an endless list of software to buy.
Parental Control Software and Router-Level Filters
Filtering at the router level covers every device on your home network in one place, rather than needing separate setup on each phone or tablet. Dedicated parental control software goes further, letting you set time limits, block specific apps, and see a summary of what your child has been doing online, which is worth reviewing together rather than checking in secret.
Platform Settings Worth Checking
Most major platforms now offer stricter default settings for under-eighteens, partly as a direct result of the Online Safety Act, but defaults are only a starting point for online safety for children, not a guarantee. On each app your child uses, check who can message them, whether their location is visible to strangers, and whether their account is set to private. The National Cyber Security Centre publishes clear, regularly updated guidance on using social media safely, including how to review these settings on the platforms children use most.
SafeSearch and Search Engine Filters
SafeSearch filters explicit results out of search engines such as Google and Bing, which reduces the chance of a child stumbling onto violent or sexual material while researching something entirely innocent for homework. It takes a couple of minutes to turn on across a family’s devices and is one of the few settings that genuinely needs setting up only once.
Talking to Your Child Without Turning It Into an Interrogation
Settings and software only go so far. Ofcom’s research found that 92% of children can recall a lesson at school about staying safe online, so most children already have the theory. What they often lack is a low-pressure way to bring up something that has actually happened to them.
A Family Agreement That Actually Gets Used
A short, written agreement, covering things like which apps are allowed, what time devices go off at night, and what happens if your child sees something upsetting, works better than an unwritten set of rules you both half remember differently. Revisit it every few months as your child gets older, rather than treating it as fixed once it is written.
Scripts for Difficult Conversations
Specific questions work better than a general “is everything okay online.” Try asking what they enjoy doing online and who they talk to there, what they would do if a stranger messaged them, or whether they know how to block and report someone on the apps they use. Building cybersecurity education into ordinary conversation, rather than saving it for one big talk, makes it much more likely your child will actually come to you if something goes wrong.
Reporting and Support Across the UK and Ireland
Where to report a problem depends on where you live, and the options differ more than most parents realise. Knowing the right contact in advance is part of online safety for children that families in the UK and Ireland often only learn about after something has already gone wrong. The table below sets out the main routes.
| Region | Report to | What they cover |
|---|---|---|
| England and Wales | CEOP (Child Exploitation and Online Protection) | Grooming, sexual abuse material, suspicious contact |
| Northern Ireland | PSNI, alongside CEOP | Grooming, harassment, threats made online |
| Scotland | Police Scotland, alongside CEOP | Grooming, online abuse, image-based abuse |
| Ireland | An Garda Síochána, and Coimisiún na Meán | Criminal offences, and complaints about platform compliance |
Ireland’s approach is worth a specific mention. Coimisiún na Meán, the country’s media regulator, adopted its first Online Safety Code in October 2024, placing binding requirements on video sharing platforms to run effective complaint handling, age verification and parental controls. Parents in Ireland can raise a complaint directly with the regulator if a platform is not meeting these duties, which sits alongside reporting a specific incident to An Garda Síochána. For further regional context, our guide to cyberbullying in Ireland covers the reporting routes and school-based supports available there in more detail.
Start with one setting and one conversation, rather than trying to fix everything at once. Check who can message your child directly on the app they use most, and ask them one specific question from the list above rather than a general check-in. Good online safety for children is not a single project you finish and file away. Treating online safety for children as an ongoing habit, built in small steps, is what actually holds up as the apps and the risks keep changing.
Frequently Asked Questions
What are the four Cs of online safety?
Content, contact, conduct and contract. This framework is the backbone of most UK school guidance on online safety for children. Content covers what a child sees, contact covers who reaches them, conduct covers what they do or post themselves, and contract covers the terms they agree to, often without reading them, when they sign up to an app.
At what age should a child have a social media account?
Most platforms set thirteen as the minimum, largely because of US data protection law rather than any UK-specific reasoning. Emotional readiness matters more than the number itself. A child who struggles with in-person friendships or takes criticism hard is often not ready at thirteen, whatever the app’s settings allow.
How do I explain deepfakes to a primary school child?
A simple comparison that tends to land well is the idea of a “digital mask”: a video or voice message can look and sound exactly like someone real without actually being them, in the same way a mask can look like a face without being one.
Can I see my child’s deleted messages?
Usually not directly, since most apps do not keep a visible copy once a message is deleted. Some parental control tools log activity before deletion, but relying on this instead of an ongoing conversation tends to break trust faster than it solves problems.
How does the UK Online Safety Act protect my child?
It places a legal duty of care on platforms likely to be used by children, requiring them to assess the risks their service poses and put in place measures such as age verification, safer default settings and faster removal of harmful content, with Ofcom able to issue significant fines for non-compliance.
What should I do if my child has been sextorted?
Do not pay, and do not delete the messages or images, since they may be needed as evidence. Report it to CEOP immediately and contact the platform to have the content removed. Reassure your child that they are not in trouble and that reporting it quickly gives the best chance of stopping it from spreading further.