Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

As artificial intelligence, social media platforms and algorithmic systems become an increasingly important part of children’s everyday lives, governments are facing a fundamental question: Who should bear responsibility for protecting minors in the digital world – children and their parents, or the companies that design and operate the technology?
Baroness Beeban Kidron has become one of the most prominent international advocates for placing that responsibility firmly on the technology industry. A member of the UK House of Lords and a long-standing campaigner for children’s rights in the digital environment, she has played an influential role in the debate over age-appropriate design, online safety and the responsibilities of technology companies.
In an interview with The Transatlantic Ledger, Kidron argues that digital products used by children should be subject to safety standards and liabilities comparable to those expected in other industries. She calls for stronger accountability for platform design, greater scrutiny of algorithms and clear safeguards governing the use of children’s data in artificial intelligence.
Her message is particularly relevant as the United States, the United Kingdom and the European Union consider how far governments should go in regulating increasingly powerful digital platforms and AI systems. For Kidron, the central issue extends beyond individual technologies: it is about whether democratic institutions are prepared to set the rules for the digital economy – or allow the technology industry to continue defining them.
The Transatlantic Ledger: You have long argued that children’s rights must be embedded into the design of digital services. Where do you believe governments and technology companies are still falling short in protecting children online?
Baroness Beeban Kidron: Governments and companies are palpably falling short because too much responsibility remains with the child or parent. Children are required to manage privacy, screen time, content and strangers, while companies control the design and what content is served.
They will have done “enough” when we mandate that digital products have the responsibilities of other products, and the same liabilities, which in turn will give users consumer rights.
The real shift is from asking children to navigate unsafe products responsibly to requiring companies to design products that respect children’s privacy, safety, development and agency by default.
Should technology companies have a legal duty to demonstrate that their products are safe for children before those products or features are introduced to the market?
Absolutely.
The United Kingdom has adopted an ambitious approach to online safety regulation. What do you see as the greatest strengths of the UK model, and where do you believe further improvements are necessary?
The strength of the UK approach is that responsibility has begun to move upstream – from children and parents to the companies that design and deploy the services. The Age Appropriate Design Code established privacy and age-appropriate design obligations, while the Online Safety Act increasingly looks at functionality and systems as well as individual pieces of content.
The weakness of both is enforcement: legislation only changes children’s lives if regulators act quickly enough and have powers capable of dealing with companies that resist. The mistake the UK government made was thinking that the sector was willing to be regulated. In fact, in small ways and big, it has and continues to resist.
Age assurance has become one of the most controversial elements of online child protection. How can governments ensure that children are protected without creating disproportionate surveillance or compromising the privacy of users?
I am always bewildered by this question. Who in the connected world does not suffer widespread surveillance? But even if you don’t accept that assertion, the choice between age assurance and privacy is a false proposition. Good age assurance should establish what a service needs to know – often simply whether someone is above or below an age threshold. It is not necessary to create a permanent identity system or collect unnecessary personal data.
In the short term, companies should be bound to the principles of portability, proportionality, data minimisation, security and independent standards. In the longer term, I would like to see a great deal more creativity in how we address this issue. There are people distributed across children’s lives – doctors, schools, parents, NGOs and public services – that know the age or needs of a child. Instead of always seeking to create new information, we should see how existing information could be codified and shared in a way that is both private and secure for children. Privacy cannot mean pretending children and adults are the same when the law itself gives them different rights and protections.
How much responsibility should social media platforms bear for design features that encourage prolonged engagement, such as infinite scrolling, algorithmic recommendations, notifications and personalised content feeds?
These features are not accidents. Infinite scroll removes stopping cues; autoplay removes the decision to continue; notifications bring users back; recommender systems learn what holds an individual child’s attention. The question is not whether children have agency, but whether it is reasonable to place a developing child’s self-control against products deliberately optimised to defeat it. Design is conduct, and companies should be accountable for its foreseeable effects.
Generative AI is increasingly becoming part of children’s education, entertainment and everyday communication. What specific risks does AI create for children that existing online safety legislation may not adequately address?
AI adds risks that are qualitatively different because it can auto-generate, infer, persuade, remember and act. It is designed in a way that allows intimate conversations, can infer sensitive characteristics a child never disclosed, generate harmful or sexual material, make educational or health decisions with no training, and manipulate or bully. Existing online-safety law catches some of this, but the spread of chatbots and the accessibility of AI products means that we need to introduce a Duty of Care.

Children and teenagers are increasingly interacting with AI-powered chatbots and digital companions. Should companies offering these services to minors face specific safety standards or restrictions?
As outlined above, the spread and accessibility of AI-powered chatbots and digital companions means that we need to introduce a Duty of Care.
Should technology companies be permitted to use data generated by children to train artificial intelligence systems? Where should lawmakers draw the line between technological innovation and the protection of minors?
Draw the line in favour of children. Only opt-in data, in pre-agreed contracts that include children’s privacy and rights – as well as the ability to opt out – should be permitted. It is a sad fact that tech companies have shown profound disregard for children and childhood, and it now requires us to set a high bar to let them engage with children.
Should major technology platforms be required to provide regulators and independent researchers with greater access to information about how their algorithms affect children and young people?
They should have greater responsibility for the impact, and researchers should have greater access by right.
Technology companies frequently warn that extensive regulation could slow innovation and weaken international competitiveness. Do you believe there is a genuine conflict between protecting children and maintaining a competitive digital economy?
I reject the premise that safety and innovation are opposites. We heard for years that age assurance, safer defaults and other child protections were technically impossible; regulation changed the incentive and companies built them. The more useful question is what kind of innovation we want. A market in which companies can gain advantage by externalising harm is not innovative – it is badly governed. A market in which doing the right thing means you can’t compete is the very definition of market failure.
We must stop pretending there is no cost to these products – there is. It is simply being paid by children and society more broadly. The tech companies should pay the full load of innovation – that includes safety and responsibility for social harms. The Children & AI Design Code explicitly argues for responsible innovation, not slowing AI down.
The United States has traditionally taken a different regulatory approach to digital platforms than the United Kingdom and European Union. What lessons, if any, should U.S. policymakers draw from the European and British experience?
My slightly cheeky answer is that soon politicians in all jurisdictions will find their tech policy aligned to electoral success. Child safety, data centres, job displacement, copyright and national security will soon be on the doorstep. In the meantime, the principal lesson is that design rules can change products without destroying the internet.
The UK Age Appropriate Design Code helped establish that childhood does not end at 13, that services likely to be accessed by children have responsibilities even if children are not their intended audience, and that privacy and safety can be built into defaults. Similar approaches are now appearing in U.S. states, which suggests this is less a European philosophy than an emerging design standard.
Would closer cooperation between the United States, United Kingdom and European Union on online safety and AI governance strengthen the protection of children, or do the different legal traditions make a common approach unrealistic?
Without tackling the issue of corporate lobbying or the politics of America First, global standards are not an option.
Critics argue that the largest technology companies possess enormous financial resources and political influence when governments consider new digital regulation. Are democratic institutions currently strong enough to regulate the technology sector effectively?
Democratic institutions are strong enough if they choose to exercise their power. Technology companies possess extraordinary wealth, evidence, engineering expertise and access to policymakers, and governments mistake consultation for co-government.
I have written about this extensively in my book USERS: How Big Tech Took Control, and What to Do About It. But the bottom line is that we need governments across the world to represent the interests of their citizens and not the powerful.
We need a return to the ideas of democracy, society and public goods and, in doing so, ask not what the tech sector wants but what technology can do to support our collective interests. Having power and wealth in so few hands is unsustainable. The bunkers built by tech billionaires attest to that fact.
Looking ahead five to ten years, which technological development concerns you most from the perspective of children’s rights: increasingly powerful AI, immersive virtual environments, personalised algorithms, biometric technologies, or something else entirely?
My biggest concern is the collapse of democracy, rather than the rise of any particular technology. If we were to imagine a world in which tech companies routinely worked to democratically arrived-at rules, and were subject to standards and liabilities as other businesses are, then we would look forward to the incredible creativity and future that technology could bring.
If you could establish three fundamental principles that every technology company worldwide had to follow when designing products or services used by children, what would those principles be?
Safe by design. Test before scale. Liability with the owner.
Baroness Beeban Kidron’s answers point to a fundamental shift in the debate over children and technology: away from expecting children and parents to protect themselves, and toward requiring technology companies to demonstrate that their products are safe by design.
Her argument reaches far beyond social media or individual online harms. Artificial intelligence, AI companions, algorithmic recommendation systems and the growing commercial use of children’s data are creating challenges that existing regulatory frameworks were not necessarily designed to address. Kidron therefore makes the case for stronger duties of care, independent scrutiny and corporate liability.
At the same time, she rejects the idea that stronger regulation must come at the expense of innovation. Instead, she argues that safety should become part of innovation itself – and part of the cost of doing business in the digital economy. Perhaps the most significant point emerging from the interview, however, concerns democratic power. Kidron sees the challenge not simply as controlling a particular technology, but as ensuring that elected governments remain capable of setting and enforcing rules in the face of some of the world’s most powerful corporations.
Her three principles provide a concise summary of that approach: “Safe by design. Test before scale. Liability with the owner.” As AI becomes more deeply embedded in childhood, education and everyday communication, the question facing policymakers on both sides of the Atlantic may therefore be less about whether technology should be regulated – and increasingly about how quickly democratic institutions are prepared to assume that responsibility.