The Government’s response to Growing Up in an Online World makes one thing clear: having the right policies is no longer sufficient. Organisations whose services reach children and young people will increasingly need to show that their protections actually work. This short briefing sets out what that shift means in practice — and the questions worth asking of any detection system before a regulator asks them of you.
The direction of travel in UK online-safety policy has moved through three stages. First came the duty to have rules: terms of service, age limits, reporting routes. Then came the duty to enforce them: moderation teams, takedown processes, transparency reports. The Growing Up in an Online World agenda, and Ofcom’s enforcement posture under the Online Safety Act, mark the third stage — a duty to demonstrate effectiveness.
That word changes the conversation inside a platform. A policy can be written in an afternoon, and an age gate pointed at in an audit. Effectiveness has to be evidenced: what was detected, how early, what happened next, and what the outcome was for the young person involved. Ofcom’s own language — failsafe protections, highly effective age assurance — describes results, not intentions.
Most safety tooling in use today examines individual pieces of content: a message, an image, an upload. Each item is checked against rules or classifiers, and each is judged on its own. That approach catches what is harmful in isolation — and misses what is only harmful in sequence.
One message trips a rule. The thirty-nine before it — each individually unremarkable — were the harm being built.
The pattern — trust-building, isolation, escalation — is visible in the trajectory long before any single message would break a rule.
Grooming is the clearest example: safeguarding failures rarely happen in message one; they happen around message forty, after weeks of individually innocuous contact. The same is true of bullying pile-ons, scam scripting aimed at young account-holders, and radicalisation pathways. These are behaviours that develop through sequences of interactions over time — and a system that only reads one message at a time is structurally unable to see them.
This is the gap the policy shift exposes. A platform can be fully compliant on paper — policies published, filters running, reports actioned — and still be unable to evidence that developing harm is detected before it lands. Demonstrating effectiveness means being able to show detection at the level where the harm actually operates.
Whether you build, buy, or blend your detection capability, these are the questions the effectiveness agenda will ask of it. They are worth asking internally first.
About this briefing. Kognos TEI is a UK specialist systems and technology integrator working in online safety & trust. We prepared this briefing because the shift from having policies to demonstrating their effectiveness affects every platform young people use — and because behavioural detection, the capability it points to, is the field we work in. Among the technologies we represent in the UK is Tuteliq, a behavioural child-safety detection engine.
There is nothing to buy on this page. If these questions are ones your team is working through, we are happy to compare notes.
If the questions in this briefing are live ones for your trust-and-safety, safeguarding or compliance team, a short conversation costs nothing — and we are genuinely interested in how different platforms are approaching the effectiveness question.
hello@tei-uk.co.uk