Online safety legislation is the collective attempt to govern a medium that was built for adults, ported to children, and never redesigned. The UK Online Safety Act 2023, the EU Digital Services Act, Australia's eSafety regime, and a patchwork of US state laws (California's AADC, Utah's SMRA, Florida's HB 3) all share a premise: the platforms will not self-correct, so the state must impose duties of care. The premise is correct. The execution is contested. Every one of these statutes has been challenged in court, narrowed, delayed, or partly enjoined. Parenthood at the collective scale lives inside that contest — not as observer but as the constituency the laws claim to protect.
The first thing to understand is what these laws actually do. They impose risk-assessment obligations on platforms above a size threshold, require transparency reporting, mandate friction (defaults, age gates, content classifiers), and create regulator powers to fine or block. The UK Act, for example, gives Ofcom enforcement against "priority illegal content" and a separate "harmful to children" category. The DSA imposes systemic risk assessments on Very Large Online Platforms. California's AADC required Data Protection Impact Assessments for any service "likely to be accessed by children" — until the Ninth Circuit enjoined the core provisions in NetChoice v. Bonta on First Amendment grounds in 2024.
The second thing is what they cannot do. Legislation cannot replace parental judgment, cannot dissolve the encryption-versus-scanning dilemma, cannot determine truth about a teenager's developmental readiness, and cannot survive without enforcement budgets that match the scale of the regulated entities. Ofcom has roughly 1,400 staff. Meta has roughly 70,000. The Federal Trade Commission's Bureau of Consumer Protection has a few hundred lawyers. The asymmetry is structural. So legislation works best when it forces architectural changes rather than content judgments — defaults, friction, transparency, audit rights — and worst when it tries to define "harm" with specificity sufficient to survive constitutional review.
The third thing is the federalism trap. In the United States, the absence of a federal child-online-safety law since COPPA (1998) has produced a state-level land rush. Each state writes its own definition of "minor," "harm," "age verification," and "platform." The result is compliance theater for large platforms (which can afford it) and exit for small ones (which cannot). The Kids Online Safety Act (KOSA) has passed the Senate twice without a House vote, partly because civil-liberties coalitions argue it would entrench surveillance and partly because the platforms quietly lobby against duty-of-care language that creates legal exposure.
The fourth thing — the one most often missed — is that "online safety" is a portmanteau hiding four distinct problems. Child sexual abuse material is a crime requiring law enforcement. Recommender amplification of self-harm content is a design defect requiring engineering remediation. Predatory contact is an interaction problem requiring identity and reporting tools. Commercial surveillance of minors is a privacy problem requiring data-minimization rules. Conflating these into a single statute produces incoherent enforcement. The UK Act tries to disaggregate; KOSA does not. The DSA splits the difference by routing different harms to different obligations.
For parents acting collectively — as voters, school-board members, plaintiffs, witnesses at hearings — the practical lever is to demand specificity. "Make the internet safer for children" is a slogan. "Require platforms with more than X million users to disable algorithmic recommendation for accounts flagged as minors, by default, with override only by verified parental consent, and to publish quarterly red-team reports on bypass rates" is a policy. The first wins votes. The second changes outcomes. The gap between them is where most of the last fifteen years of legislative effort has been lost.
The fifth thing is timing. The laws now reaching enforcement were drafted against a 2018-2021 threat model: TikTok, Instagram, Discord, Snapchat. The 2025 model includes Character.AI, Replika, AI companion apps, generative deepfake tools, and on-device LLM agents that operate outside the platform paradigm entirely. Statutes written to regulate "user-to-user services" will struggle to bind systems where the harmful counterparty is a language model. A second wave of legislation — addressing synthetic media, AI companions, and on-device inference — is already drafting itself in committee rooms in Brussels, Sacramento, and Westminster. Parents who organize now will shape that second wave. Those who wait will inherit it.
Collective parenthood, then, is not the sum of household rules. It is the slow work of writing the rules that govern the rule-writers. The 1,000-page manual treats this as a Law 4 problem (Plan) with heavy Law 5 (Revise) load: every statute is a draft, every enforcement action a correction, every court ruling a forced rewrite.