Summary
- The government wants protections against nude-image creation, viewing, and sharing to operate across devices and apps used by under-18s.
- Safeguards would be enabled by default, while adults would need to prove their age before accessing affected functionality.
- The proposal shifts online-safety regulation towards operating systems, cameras, application design, and age assurance rather than content moderation alone.
The UK government is preparing legislation that would require technology companies to stop under-18s taking, viewing, or sharing nude images, extending online-safety regulation beyond social-media platforms and into the design of devices, operating systems, cameras, and applications.
The government said protections should operate across device features and third-party apps, with nudity safeguards switched on by default rather than relying on children or parents to activate them. Adults would retain access to affected functionality, but companies would be expected to establish that a user is over 18 through robust age assurance.
The move follows talks with Apple and Google that began in June, when ministers gave the companies three months to strengthen protections voluntarily. Although the government says progress has been made, it is now preparing legislation while leaving open the possibility that sufficiently strong voluntary measures could alter the final regulatory approach.
Apps used by children could also fall within the framework, which would create obligations spanning several layers of the technology stack. A camera controlled by an operating system, a messaging service supplied by another company, and an app running across several device manufacturers could all become part of the same regulatory problem even though responsibility is distributed between different businesses.
The proposal marks a substantial change in how UK child-safety policy is being applied. Existing online-safety rules concentrate heavily on harmful content, recommendation systems, illegal material, and interactions between users once they occur on an online service, whereas device-level controls would intervene before an image reaches a platform at all.
That distinction moves regulation closer to product architecture. If a device is expected to prevent a child creating or viewing a particular class of image, safety controls have to sit inside the operating system, application, account, or camera workflow rather than appearing later as a moderation decision.
Age assurance becomes part of device design
The government has set out the outcome it wants more clearly than the technology companies will be expected to use, leaving several difficult implementation questions unresolved. On-device image analysis could classify material without routinely sending photographs to a remote server, while server-side detection would create a different set of privacy, security, and data-retention consequences.
Neither approach is technically neutral. Local analysis requires suitable software and processing to be present across a wide range of devices, while centralised detection requires images or derived information to move through external infrastructure. Application developers may also have far less access to device-level controls than the companies operating the underlying platform.
Age assurance becomes equally important because adults are supposed to retain access to legitimate functionality. A system that treats a 17-year-old and an 18-year-old differently needs a reliable method of establishing age, but collecting more personal information simply to prove eligibility creates its own privacy and security risks.
The final legislation will therefore need to define what constitutes sufficiently robust age assurance and how frequently verification must occur. Those details will determine whether responsibility sits mainly with a device account, an operating-system provider, individual apps, or several parties at once.
False positives will be another practical problem because automated nudity detection cannot rely on sexual intent alone. Medical photographs, health services, family images, art, and other legitimate uses can contain exposed bodies, while classifiers can misinterpret images that human viewers would understand immediately from context.
A statutory requirement framed around preventing minors from taking or viewing nude images will consequently need a way to handle mistakes without rendering ordinary device functions unreliable. Technology companies may also face conflicting demands between making controls difficult for children to circumvent and allowing legitimate exceptions without creating an obvious route around the protection.
The structure of the mobile market adds further complexity. Apple controls both iOS and the devices on which it runs, while Google develops Android across a much broader manufacturer ecosystem. Third-party apps operate across both, meaning the same legal requirement could be implemented through very different technical architectures.
The proposal sits alongside a wider expansion of UK child-safety policy, including restrictions affecting younger social-media users and existing Online Safety Act duties around illegal and harmful content. Taken together, those measures increasingly ask companies to prevent particular interactions from happening rather than simply moderate their consequences afterwards.
That approach can intervene earlier, but it also reaches further into private communications and ordinary device functions. The closer regulation moves to cameras, photo libraries, account systems, and messaging tools, the more important proportionality, technical feasibility, and privacy protections become.
The government has said it intends to legislate as soon as possible while acknowledging the complexity of the work. Apple, Google, app developers, messaging providers, and age-assurance suppliers therefore have a clear direction of travel but not yet a final specification for the systems they may be required to build.
What is already changing is the boundary of online-safety regulation itself. The UK is moving from rules largely focused on how platforms manage content towards rules that can determine how devices and applications behave before content is created or shared, placing product architecture directly inside the regulatory perimeter.












