Australia says Roblox hasn't fixed its child predator problem
Australia's eSafety regulator found Roblox still failing to adequately protect children under 16 from contact with adult strangers despite previously implemented safety measures Testing revealed adults could send connection requests to children without parental consent, and children's profiles and connections were publicly visible with no privacy controls Roblox committed to new safety measures including requiring parental consent for adult-child contact, default-private accounts for minors, tra
Analysis
TL;DR
- Australia's eSafety regulator found Roblox still failing to adequately protect children under 16 from contact with adult strangers despite previously implemented safety measures
- Testing revealed adults could send connection requests to children without parental consent, and children's profiles and connections were publicly visible with no privacy controls
- Roblox committed to new safety measures including requiring parental consent for adult-child contact, default-private accounts for minors, transparent reporting mechanisms, and independent third-party audits
- Roblox faces parallel scrutiny in the US from a Senate subcommittee investigation and multiple state lawsuits over child safety concerns
Why It Matters
This case highlights the growing regulatory pressure on social gaming platforms to enforce robust child safety measures, setting a precedent that could influence compliance requirements globally. For AI and platform safety practitioners, it underscores the critical importance of effective age-estimation systems, default privacy protections, and independent auditing as regulatory expectations tighten.
Technical Details
- eSafety's testing identified specific compliance gaps: unrestricted adult-to-child connection requests, publicly visible child profiles and connection lists, and forum interactions between children and adults outside game environments
- Roblox's existing "Roblox Kids" and "Select" accounts for users under 16 were found insufficient to prevent the identified risks
- New commitments include implementing parental consent gates for adult-child contact, default-private account settings for minors, and deploying an independent third-party auditor to evaluate the effectiveness of age-estimation measures
- The platform currently lacks granular privacy controls, with no option to restrict visibility of children's biographical information, avatar images, or connection lists
Industry Insight
- Regulators are moving from advisory guidance to active enforcement and testing; platforms should proactively audit their safety mechanisms rather than react to regulatory findings
- Default-private-by-design for minor accounts is becoming an expected standard, not a discretionary feature—platforms should adopt this as a baseline
- Independent third-party auditing of safety and age-estimation systems is emerging as a regulatory expectation; building audit readiness into product development cycles will reduce compliance risk as scrutiny intensifies globally.
Disclaimer: The above content is generated by AI and is for reference only.