
Lisa Nandy child online safety plan: device-level protections and new law
Lisa Nandy’s child online safety push, and why it suddenly gets serious
Lisa Nandy’s child online safety agenda moves from warm words to hard leverage on 8 September 2026, with a clear message to Parliament: the government is no longer willing to rely on voluntary promises from Big Tech to protect children online. In an oral statement, the Secretary of State for the Department for Digital, Culture, Media and Sport sets out what she describes as “next steps” to create an online environment that is not only safer, but also “enabling and empowering”. But the centre of gravity is protection, specifically stopping children from taking, sharing, or viewing nude images on their devices.
And the shift is not subtle. Nandy tells MPs that officials from her department and the Home Office have run an “unprecedented work programme” with Apple and Google since June, engaging senior leaders and engineers to explore device-level protections. The companies, she says, have made “significant commitments”, including operating-system level changes intended to make it harder for children to share nude imagery. Yet she also says the proposals do not meet the “scale of this crisis”, and she announces the government will introduce primary legislation to require major tech platforms to build in device-level protections for children.

This is the crux of the news: a UK government plan to legislate for device-level child protections, after a three-month industry challenge and direct technical engagement with Apple and Google. It is a big deal because it targets the operating system layer, not just individual apps or websites. That is where the power sits, and where enforcement could bite.
What exactly is announced on 8 September 2026, and what changes are on the table?
Nandy’s statement outlines a timeline and a tactic. In June 2026, the government challenges industry on a three-month timeline to produce roadmaps for strengthening device-level protections for children, with the explicit aim of preventing children from taking, sharing, or viewing nude images on phones and tablets. By 8 September 2026, she returns to Parliament with an update: Apple and Google have engaged, and the government has seen progress on operating-level measures.
Two details matter here. First, Nandy says there is progress in the “blocking, not blurring” of nude imagery on underage devices. That distinction signals a tougher stance on what safety features should do by default. Blurring is often framed as a compromise, it reduces accidental exposure but still allows access. Blocking is more absolute, and therefore more contentious, because it raises questions about false positives, edge cases, and who decides what is blocked.
Second, she points to “significant milestones already in implementation”, including what she describes as Apple’s rollout earlier in 2026 of operating-system level age assurance tied to safety features, preventing a child from receiving or sharing nude imagery on iMessage or FaceTime. In other words, the government is not only asking for new controls, it is also using existing platform features as proof that technical change is possible when companies prioritise it.
But Nandy also makes clear that voluntary progress is not enough. She tells MPs she is “not prepared to give them the benefit of the doubt” that progress will continue at the pace required while harm is happening now. The headline development is therefore legislative: the government commits to introducing primary legislation to require major tech platforms to build device-level protections for children, and to bring it to Parliament “as soon as we can”, while working across the House to “get it right”.
The problem the government says it is trying to solve, in numbers
Nandy frames the issue as a crisis of sexual harm online, with children “groomed, coerced, and manipulated” into creating and sharing intimate images across online services. She uses specific figures to justify intervention, and they are not presented as abstract. They are presented as a direct rebuttal to the idea that the internet is already safe enough, or that government should stay out.
One of the most striking statistics she cites comes from the Internet Watch Foundation: it believes that 91% of these images are self-generated by children themselves. That matters because it shifts the narrative away from a simplistic model of adults producing abusive content, towards a reality where coercion, pressure, and manipulation can lead children to create material that is then weaponised. Nandy explicitly links this to blackmail and sexual extortion.
She also tells Parliament that each year around 9,000 child sexual abuse offences involve an online element, and that under 18s are the subject of almost a quarter of online blackmail. Those figures, as presented in the statement, are used to argue that the status quo is unacceptable and that the state has a duty to intervene, just as it would in any other environment where children face systemic harm.

There is an important nuance here. The government’s focus is not only on content moderation inside apps, but on preventing the creation and transmission of certain images at the device level. That is a different kind of policy lever, and it is being justified by the scale and nature of harm described in these numbers.
Who is involved, and why Apple and Google sit at the centre
The key political figure is Lisa Nandy, speaking as Secretary of State for the Department for Digital, Culture, Media and Sport. The statement also makes clear this is not a single-department effort. Officials from her department and the Home Office oversee the work programme with Apple and Google, which signals that the government is treating this as both a safety issue and a law enforcement issue.
On the industry side, Apple and Google are singled out because they control the dominant mobile operating systems and the device ecosystems that sit underneath most children’s online lives. It is one thing to pressure an individual social media platform. It is another to influence the operating system that governs permissions, messaging defaults, parental controls, and the basic mechanics of sharing images. If the government wants device-level protections, it has to deal with the companies that build the devices’ core software.
Nandy describes the engagement as involving “senior leaders and engineers”, which is telling. This is not just policy teams trading position papers. It implies technical discussions about how protections might work in practice, what is feasible, and what trade-offs are unavoidable. And it also hints at a familiar pattern: governments increasingly want safety outcomes, but they need the engineers who understand the systems to make those outcomes real.
There is also a political backstory in the statement itself. Nandy references the government’s Action Plan to tackle Violence Against Women and Girls, published in December of the previous year, and she credits MPs for an ambition that the UK would become the first country where it would be “impossible” for children to take, share, or view nudity online. That is an extremely high bar. It sets expectations that incremental tweaks will not satisfy, and it helps explain why the government is now reaching for primary legislation.
Lisa Nandy child online safety legislation: what it could change, and what it risks
Legislating for device-level protections is a different beast from telling platforms to remove harmful posts faster. It potentially changes the default capabilities of devices used by under 18s, and it could reshape how age assurance is implemented at operating-system level. Nandy’s statement explicitly points to age assurance “tied to safety features” as a direction of travel. That suggests a model where a device knows, or infers, that a user is underage, and then automatically applies stricter rules around receiving, sending, or viewing nude imagery.

For industry, the immediate implication is that “safety by design” stops being a slogan and becomes a compliance requirement. If primary legislation sets obligations on major tech platforms, companies may have to demonstrate that protections are built in, not bolted on. That could accelerate development work that has previously been optional, deprioritised, or limited to certain markets. It could also create a new competitive dynamic, where safety features become part of how devices and ecosystems are judged by regulators, parents, schools, and ultimately consumers.
But there are risks and tensions baked into the approach, even if the statement does not spell them out. Blocking rather than blurring raises questions about accuracy and context. Automated detection can misclassify images, and the consequences of a false positive can be serious, especially for teenagers who may be sharing legitimate content such as health information or consensual images between peers (still problematic, but legally and ethically complex). And any system that relies on age assurance raises questions about how age is verified, what data is collected, and how privacy is protected. The statement does not provide technical detail on these points, so it is not possible to assess the safeguards from this source alone.
There is also a governance question. Nandy argues that technology has been developed “almost exclusively in the private sphere”, and that government has a “central role” in shaping it for good. That is a philosophical stance as much as a policy one. It implies a more interventionist approach to consumer technology, and it sets up a future where the UK may try to export its model, or at least claim leadership, by setting rules that others may follow.
Historical context: why this moment feels like a turning point
Nandy explicitly situates the issue in a longer history of technology “upending society”. That framing is not new, but it is useful. Every major communications shift, from mass print to broadcast television to the early internet, has triggered a lag between adoption and regulation. The difference she highlights is that today’s technology is largely built and governed by private companies, at global scale, with product decisions made far from public scrutiny.
In the UK, the broader direction of travel over the past decade is towards stronger online safety expectations and more formal accountability for platforms. What is distinctive in this 2026 statement is the focus on the device layer and the explicit willingness to legislate if voluntary commitments fall short. It is a move from regulating behaviour on platforms to regulating capabilities on devices. That is a step closer to the infrastructure of digital life, and it is why Apple and Google are central rather than incidental.
There is also a comparison to be made with earlier waves of child protection policy. Historically, child safety interventions often start with guidance and voluntary standards, then move towards mandatory rules when harms persist. Nandy’s language follows that arc. She acknowledges progress, then says it is not enough, then announces primary legislation. It is a classic escalation, but applied to operating systems and image sharing rather than physical spaces or broadcast content.
And there is a political reality underpinning it. The statistics she cites, including the Internet Watch Foundation’s belief that 91% of images are self-generated, and the estimate of around 9,000 offences each year with an online element, make it difficult for any government to argue for inaction. Once those numbers are in the public record, the question becomes not whether to act, but how far to go, and how to avoid collateral damage.

What This Means For You
For parents and carers, the immediate takeaway is that “child online safety” is increasingly being designed into the device, not just managed through app settings. That can be good news, because device-level protections are harder for children to bypass than individual app controls, and they can apply across services rather than in one place. But it also means families may see more prompts about age, more default restrictions, and more conversations at home about why certain features are blocked. The practical move is to treat device setup as a safeguarding moment, not a one-off admin chore, and to keep an eye on operating system updates that change safety features.
For teenagers, the direction of travel is towards fewer grey areas and more hard stops, especially around intimate images. That will frustrate some users, fair enough, but it also reflects the reality that self-generated imagery is being used for blackmail and sexual extortion. The most useful mindset shift is to see “never create it in the first place” as the safest option, because once an image exists, control is easily lost. If new protections make it harder to take or share certain images, that friction is not moralising, it is a safety barrier designed to interrupt coercion and impulsive decisions.
For schools, youth workers, and anyone supporting children, the key implication is that safeguarding policy will increasingly intersect with consumer tech policy. If the government legislates for device-level protections, institutions may need to update guidance on phones and tablets, and be ready to explain what the protections do and do not do. The actionable step is to plan for a mixed environment, where some children’s devices have stronger OS-level protections and others do not, and to keep education focused on coercion, consent, and reporting routes, not just on “don’t do it”. Technology can reduce risk, but it cannot replace trusted adults and clear support pathways.
Closing thoughts: a tougher bargain between government and Big Tech
Nandy’s statement is, at heart, a declaration that the UK wants to set the terms of engagement with the biggest technology companies when children’s safety is at stake. The government is willing to work with Apple and Google, and it clearly has, but it is also willing to legislate when voluntary measures do not match the urgency of harm. That combination of collaboration and coercion is likely to define the next phase of online safety policy.
The unresolved question is how the government turns an ambition as absolute as making it “impossible” for children to take, share, or view nudity online into workable law and workable engineering. The statement provides the political intent and some early signals of technical direction, such as blocking rather than blurring and age assurance tied to safety features. It does not provide the detailed design, the thresholds, or the accountability mechanisms. Those will matter, because the closer regulation gets to the operating system, the more it touches privacy, usability, and the everyday autonomy of young people.
Still, the trajectory is clear. Child online safety is no longer framed as a matter of better reporting buttons and faster takedowns alone. It is moving into the architecture of devices. And once that happens, the debate stops being only about what children see online. It becomes about what their devices are allowed to do in the first place.
