In the absence of Federal regulation, online child safety is often treated as a matter of parental controls and user education. Therefore, to know whether a company really takes child safety seriously, a more reliable measure than what it says is what it does by default.
Over years of frontline survivor care work at Love146, we have observed online child exploitation become more sophisticated, while prevention efforts from the public and private sectors have been slower to change. Digital safety is still treated largely as a matter of consumer education, which places the responsibility on parents and children to configure privacy and safety settings themselves. This approach has a structural limitation: a significant share of online exploitation depends on how a product is designed, not on user interface. A platform’s default settings, meaning the configuration that applies before anyone makes a change, are a concrete and observable indicator of how a company prioritizes child safety.
What default settings indicate
When we launched our Protect Children by Default campaign in 2019, we applied a basic principle of technology policy to the issue of child exploitation: default settings carry disproportionate weight because most users never change them. When a platform releases a feature with its safety mechanisms turned off, responsibility for protection shifts to the child or the parent. A prevention-oriented design reverses that arrangement, so that safety applies automatically and access to higher-risk features requires a deliberate choice.
Two recent examples in product design
In the past several weeks, two product decisions illustrate the difference. According to Apple, the child-safety features it previewed in June 2026, scheduled to arrive with iOS 27 this fall, apply protections to a minor’s device by default. For all child accounts (under age 13), a feature called Ask to Browse requires parental approval before a child’s device opens a website it has not visited before. On these accounts, Ask to Buy will now require parental permission for any app download or in-app purchase. In addition, children will no longer be able to communicate with new contacts (via Phone, Messages, or FaceTime) until a guardian approves the request. For all youth under 18, communication safety tools that blur nudity and graphic imagery are enabled by default in Messages and FaceTime. It also provides screen distance warnings, prompting kids to keep the device further away from their eyes to reduce digital eye strain. Parents can build on these default settings through the Screen Time menu, where they can set daily time limits across specific app categories, (e.g., entertainment, games, or social media) with suggested amounts based on a child’s age and block specific apps during certain times of day. Apple based the age-related guidance on pediatric research, adapting the American Academy of Pediatrics’ Family Media Plan.
A few weeks prior, in May 2026, Meta debuted its Instants feature. Instants centers on photos that are sent in the moment and disappear after a single view, or after 24 hours if unopened. Marketed as a spontaneous, low-pressure app, it promotes the safety feature of restricting screenshotting and letting users “undo” a sent photo before the recipient opens it. Screenshots have also been blocked. However, the reality is that “screenshots” can be taken with other devices so this “safety feature” is really a false promise. In addition, while screenshot blocking can protect a young person from having an image captured, it can also prevent them from preserving evidence of harmful contact. For existing teen Instagram accounts, this new Instants feature was enabled by default rather than off by default, and turning it off required a user or parent to locate and change the setting. Its in-app introduction screens paired imagery of what appear to be teenagers with the feature’s three headline attributes: that photos disappear after a single view, that there is no viewer list, and that reactions and replies are private. The central design prioritizes ephemerality and limited visibility, which reduces the durable record that helps adults and investigators identify grooming and other potential harm. Based on Love146’s experience supporting survivors, the less persistent the record, the more difficult it is to detect harm after it has occurred. It’s not a surprise that within 24 hours of launch, child-safety groups were publishing instructions for disabling it.
A standard for accountability
The teen brain prioritizes peer approval, immediate emotional rewards, and new experiences. All of which Instants is built to activate. The logical decision-making part of their brain is still being developed; therefore, they are not well positioned to assess the privacy and safety implications of disappearing-media software. By activating Instants on teen accounts Meta is once again abdicating responsibility and reverting to its own default practices whereby it treats safety as a matter of parental controls and user education. For policymakers, regulators, and advocates, default settings provide a consistent and observable basis for assessing the safety of a platform and the priorities of a company, because they show what a product does before any user intervenes. When safety protections aren’t prioritized by default, the product design may contribute to avoidable risk and harm. Technology companies have the capability to apply additional safety measures to higher-risk features, incorporate expert input, and prioritize child safety over company revenue and engagement metrics.
Parenting
