UK Government proposes social media curfew for 16 and 17 year-olds
The question
What changes are the UK Government proposing to keep teens safe online and what should platforms do now to prepare?
The key takeaway
The UK Government is moving towards a more interventionist approach to children’s online safety, with proposed measures including: overnight social media curfews: restrictions on addictive platform features for 16 and 17 year olds; and enhanced safeguards for AI chatbots used by under-18s. At the same time, the Information Commissioner’s Office (ICO) has made clear that any measures affecting children’s online experiences, particularly those involving under-16s, must be implemented in a privacy-preserving manner and comply with UK data protection law.
The background
As reported in the Summer 2026 Edition of Snapshots, the UK Government has consulted on a number of different digital child safety measures including social media bans, curfews and time restrictions. The much-publicised outcome of this consultation is that the UK will follow Australia in banning social media platforms from offering services to under-16s, including the likes of Instagram, TikTok, YouTube and Facebook. According to the UK Government, these plans are intended to ensure children are protected online, with 9 in 10 parents who contributed to the consultation saying they supported a ban for under-16s.
The development
Following the announcement of plans for a social media plan for under-16s, in July the UK Government announced plans to introduce default overnight “curfews” for social media services used by 16 and 17-year olds, stating that access will be switched off by default between midnight and 6:00 a.m. The announcement also proposed that engagement-driven features, such as autoplay videos and algorithmically personalised content feeds, would be disabled by default for older teenagers during this time. These measures are intended to encourage healthier online habits while preserving user choice, as 16 and 17-year-olds will be able to amend the default settings if they wish.
The UK Government frames the 16-17 year-old age bracket as needing additional safeguards to ensure that turning 16 does not create a “cliff edge” in protections. In particular, it referenced a pilot with “more than 300 teenagers and parents” reporting positive effects from overnight curfews on their routines, sleep and concentration.
In relation to AI services, the UK Government has announced its intention to bring forward a package of measures to improve the safety of AI chatbots for children. The proposals include introducing regular breaks for under-18s using AI chatbots and taking action against service providers in relation to dangerous, misleading or unverified mental health advice. The UK Government has also indicated that it is considering a range of regulatory options, including banning AI chatbots that pose a serious threat to children and plans to expand the Kids Online Safety Hub to provide guidance for children and parents, alongside media literacy initiatives in schools covering AI and the safe use of AI chatbots.
Separately, the ICO has published a statement in response to the UK Government’s announcement on restrictions affecting under-16s’ use of social media. While the statement does not introduce new legal obligations, it provides an important indication of the regulator’s expectations. In particular, the ICO reiterates that providers of children’s online services should design such services with children’s best interests and privacy in mind by default, and that any measures relying on age assurance or default settings must be implemented in a technically robust, proportionate and data protection-compliant manner.
Why is this important?
For large online platforms, the direction of travel is towards “safety by default” for teen users, specifically targeting autoplay, personalised feeds and time-of-day usage patterns, which may require significant engineering and governance changes. The UK Government’s announcement is significant as it is an indicator of potential future regulatory expectations which may affect product roadmaps, risk assessments, and the evidence platforms may need to provide in respect of how teen protections work in practice. The ICO statement is a reminder that any “child protection” feature that relies on identifying age bands will be scrutinised through a data protection lens, including whether age assurance approaches are necessary, proportionate and privacy-preserving.
For AI chat experiences, the specific mention of “regular breaks” and potential restrictions on mental-health advice outputs increases the likelihood of nearer-term regulatory scrutiny. This matters not only for dedicated AI chatbot providers but also for platforms embedding AI assistants, search/chat features and developer tooling that can be used by under-18s.
Any practical tips?
Although many of the announced measures remain proposals, organisations providing social media, AI chatbots or other online services likely to be accessed by children should consider taking preparatory steps now. In particular, organisations may wish to:
- review age assurance arrangements: assess whether existing age assurance or age estimation mechanisms are sufficiently robust to support age-based functionality, while remaining proportionate and compliant with UK data protection law
- evaluate default settings for younger users: consider whether features such as autoplay, infinite scrolling, personalised recommendations, notifications and late-night access are appropriate for users under 18, and whether safer defaults could be introduced should the UK Government’s proposals be implemented
- review AI chatbot safeguards: assess whether additional protections are required for younger users, including age-appropriate guardrails, escalation mechanisms for sensitive topics (particularly mental health), usage reminders or break prompts, and clear pathways to trusted sources of support
- revisit compliance with the Children’s Code: the ICO’s statement reinforces that children’s best interests and privacy by default remain central regulatory expectations. Organisations should ensure that their services continue to align with the Children’s Code and that data protection impact assessments (DPIAs) remain up to date where children’s data is processed
- monitor legislative and regulatory developments: the announcements set out the UK Government’s policy direction but further detail is expected on implementation, including the scope of affected services, technical requirements and timelines. Organisations should monitor future regulatory developments and ICO guidance to understand when compliance obligations might change
- engage cross-functional teams early: implementing age-based experiences is likely to require coordinated input from legal, privacy, product, engineering, trust and safety, and public policy teams. Early planning can help organisations assess technical feasibility, user experience impacts and compliance risks before any new requirements take effect.
Autumn 2026
Stay connected and subscribe to our latest insights and views
Subscribe Here