The government will force tech platforms to stop children sharing nude images. That is the announcement. The mechanism is unspecified. The enforcement is theoretical. The record of similar promises is long and discouraging.

This is not an argument against the intent. A society that permits commercial platforms to profit from the sexual exploitation of children deserves what it gets. The question is whether announcements of this kind bear any relation to what actually happens, and whether the state that makes them possesses either the technical capacity or the institutional memory to deliver.
Consider the pattern. Every two years a minister stands up and promises that the internet will be made safe for children. The companies nod. The legislation, when it arrives, tends to rest on age verification they don't wish to implement and detection systems that don't yet exist at scale. The children remain exactly where they were. The only thing that changes is the press release.
The Online Safety Act received Royal Assent. It contained provisions requiring platforms to prevent children accessing harmful content. The implementation guidance is still being written. Ofcom is still consulting on the codes of practice. Companies are still designing their compliance strategies. In the meantime, the material circulates. Parliament passed a law. The law has yet to touch a child's phone.
The serious case for state intervention here is real and deserves its full weight. These aren't public squares. They're private attention machines designed to maximise engagement, and they've systematically failed to prevent the circulation of child sexual abuse material because prevention costs money and reduces growth. Major technology firms have had fifteen years to solve this voluntarily. They haven't. The invisible hand has produced a market in which algorithmic recommendation systems serve content to children that would be criminal to show them in any other context. A functioning state would treat that as a market failure and step in. The libertarian objection that parents should simply supervise their children's devices founders on the reality that these systems are designed by some of the most sophisticated behavioural engineers in human history to be more compelling than parental oversight. You are asking ordinary families to outcompete billion-dollar optimisation engines. That isn't a policy. It's an abdication.
The counter-case is equally real. The state that cannot run a functional IT procurement system, that watched the Post Office destroy lives for two decades, that presides over courts with backlogs measured in years, now announces it will compel American technology giants to re-engineer their products in ways those giants have spent a decade resisting. One of these actors has leverage. It isn't the one making the announcement. Major platforms can delay, lobby, relocate legal entities, and design around enforcement faster than Whitehall can write the guidance. The regulatory cycle is measured in years. The product cycle is measured in quarters. By the time the framework arrives, the thing being regulated has already moved.
There's a third difficulty the announcement doesn't address, and it's the hardest one. The technology required to detect this material at scale is the same technology required to read everyone's messages. The choice is between privacy and detection, and it's a real choice, not a question the correct policy can dissolve. End-to-end encryption makes mass surveillance impossible. It also makes automated detection impossible. A government serious about this question would admit the trade-off and argue for one side. You can have private messaging or you can have automated content scanning. You cannot have both, and pretending otherwise is how we get announcements that sound decisive and deliver nothing.
The opposing argument here is that client-side scanning can thread the needle: the detection happens on the device before encryption, so privacy is preserved and the material is caught. That's the theory. The practice is that client-side scanning requires every device to run government-mandated code that examines content before the user sends it, which is surveillance by another name, and every security researcher who has examined the proposal has concluded it creates vulnerabilities that hostile states will exploit. You have built a backdoor and called it safety. The backdoor does not care who uses it.
The state could choose the other side. It could say: we will break encryption, we will read the messages, we will catch the material and accept the cost to privacy and security. That would be an honest argument between two real goods. Instead we get promises that imply the trade-off doesn't exist, delivered by people who appear not to understand the systems they're regulating.
If this announcement leads to criminal charges against platform executives within eighteen months, the state was serious. If it leads to another consultation, another framework, another promise to get tough next time, it was the usual theatre. The intent may be sincere. The capacity to deliver has yet to appear. We have watched this film before. The ending doesn't change.
What do you think?
Sign in - it's free to add your take, reply, and vote on others.
No takes yet. Be the first to make the argument.
The record stays free. If it was worth your time, buy us a coffee - or become a member for the commentary and the archive.