One weekend in March 2026 I was at a rugby tournament with my son playing for Old Leamingtonians down in Bournemouth. Later that day since they live in the area we went to see my brother and sister-in-law who are great at being grandparents for their kids' kids, and as my son picked up his phone they asked me where I stood on the idea of banning social media for under-16s.
From my perspective it’s a difficult question, because like most parents I do think children need better protection online. But I also think coming from a tech perspective, a lot of the ideas now being floated are badly thought through, technically illiterate and likely to create new problems rather than solve the original one.
As of March 2026, the UK government is consulting on measures including a minimum age for social media, restrictions on addictive design features such as infinite scroll and autoplay, stronger age assurance and better support for parents. At the same time, Parliament has been debating amendments and new powers around under-16 access to online services, including suggestions that reach as far as VPNs.
Our discussion concluded that the concern is real, but the policy conversation is drifting towards slogans. And slogans are a poor substitute for understanding how the technology works and what controls would work as a solution.
The definition problem
My biggest point of contention, running a company that is involved in many different communities, is that the term social media has become so vague that it is almost useless as a policy category. What exactly are we banning?
Take YouTube. It is obviously a video platform, but it also has comments, subscriptions, creator communities, recommendation loops and all the social behaviour that comes with them. We work with clients who run community platforms where members can post, reply, discuss and interact with each other. Are those social media? If they are not, why not? If they are, should they fall under the same rules as TikTok, Instagram or Snapchat?
Then there are games with chat, like Roblox and Fortnite, messaging apps with channels, livestreaming services with live comments like Twitch, forums, private groups and new platforms that can appear almost overnight, gain huge traction and run from offshore. The internet does not sit still long enough for ministers to draw a neat box around one category and assume the job is done.
The vaguer the definition, the more arbitrary the enforcement becomes. And once enforcement becomes arbitrary, larger firms lawyer up, smaller services fall through the cracks, and parents are left assuming there is some simple, settled boundary where none really exists. It is impossible to categorize in long term policy something that is so fluid, technology is not something that is sitting still, it is accelerating and with the introduction of AI we have already seen the problems that diffusion image generation can cause. Regulating technology in this way is never going to keep up.
VPNs are not contraband
The VPN discussion shows how quickly this debate can slide from concern into technical nonsense.
My son is 11. He got a mobile phone a few months after his birthday. I route his DNS requests through our home network using a VPN, with NextDNS, pfBlockerNG and Google's family controls doing the heavy lifting. That lets me put guard rails in place in a practical way: filtering, safe browsing, sensible limits and some visibility over what is happening. It is not perfect, but it is a real-world parental control setup that works. Sadly, it required a fair amount of my geekiness to set this up so it is not something that is for Joe Public, however there are services like SecureTeen that use VPNs to achieve exactly what I have set up manually.
So, when people start talking loosely about banning VPNs for children, my immediate reaction is: how exactly do you think SecureTeen will work? And what happens to the much more ordinary use cases that have nothing to do with evading age gates? 4 Roads' laptops and desktop machines use a VPN to connect securely to work systems. Businesses use them constantly, and schools and public bodies do too.
A VPN is a tool. Like any tool, it can be used well or badly. Treating it as inherently suspect confuses misuse with the technology itself. It is the policy equivalent of seeing someone use a kitchen knife badly and concluding that the answer is to ban knives.
Bans do not make the problem disappear
Blunt bans also misunderstand behaviour, especially among teenagers.
Trying to ban something does not automatically make it less attractive. Often it does the opposite and makes it cool. The forbidden has a habit of becoming interesting, and for younger people that can quickly become social currency. We have seen versions of this pattern before: when one harmful behaviour becomes uncool, another product or workaround rushes in to fill the vacuum, for example when I was young smoking was cool, now it’s vaping. The shape changes, but the underlying demand does not disappear.
That is why I am sceptical that simply banning mainstream social platforms for under-16s would have the clean effect many people imagine. Some children would comply. Some would borrow accounts. Some would lie about their age. Some would migrate to smaller, less accountable services with poorer moderation, weaker safety tooling and far less scrutiny. If your policy pushes risk out of the visible mainstream and into darker corners of the internet, you have not really solved the problem. You have redistributed it.
Regulate the mechanism, not the label
What I think deserves much more attention is hyper-personalisation and uncontrolled automated profiling.
The larger problem is not simply that a service allows people to comment, share or message each other, although tighter moderation needs to be added by platforms. The more serious harm often comes from systems that learn what keeps a child or adult watching, then keep feeding them more of the same without limits. One click becomes ten. One anxious search becomes a conveyor belt of anxiety content. One body-image video becomes a tunnel of body-image videos. That is not a neutral library. It is an engine designed to maximise attention and becomes addictive.
If we want better regulation, that is where it should bite. Restrict personalised recommendation systems. Default younger users to safer, less manipulative feeds, moderate conversations more aggressively. Limit autoplay and infinite scroll. Force greater transparency around recommendation criteria. Give children and parents clearer controls to reset, reduce or turn off personalisation. In other words, regulate the architecture that amplifies harm instead of arguing forever about whether a particular platform does or does not fit a politically convenient label.
Ofcom is already pushing platforms towards safer feeds, stronger age checks and better protections for children, although there is work to be done on privacy. That work should be sharpened, extended and enforced - not distracted by performative arguments that make for strong headlines and weak policy.
Digital parenting is now just parenting
There is another uncomfortable part of this discussion that we should not avoid and one that other parents may disagree with: adults need to take more responsibility for understanding the technology their children use. Stuffing a device in a child’s hand at a young age to keep them entertained without controls is a recipe for disaster.
We teach children how to cross the road. We teach them how to ride a bike. We teach them not to talk to strangers, how to read social situations and how to manage risk in the physical world. Yet many adults still act as though the digital world is somehow separate from real life, rather than part of the world children inhabit every day.
Digital parenting does not mean becoming a network engineer. It means learning enough to set up sensible controls, understanding what the apps do, talking about algorithms, privacy, scams, social pressure, attention traps and the difference between connection and manipulation. It means helping children build judgement, not just trying to build walls.
Of course, platforms should shoulder more of the burden, and government should create rules that make safer defaults easier for families and not have their ears bent by lobby groups. And parents should be able to easily configure and make sure their families are safe. In the computer industry we have a term "Secure by Default" in the family context it should be "Secure and Child Safe by Default" with simple tools and simple reporting.
The better answer
Protect children online, absolutely. Push harder on age assurance where it is genuinely effective, whilst maintaining privacy. Restrict hyper-personalisation for everyone. Tackle autoplay, infinite scroll and other compulsive design patterns. Force ISPs and mobile networks to provide greater controls over network traffic and devices. Give parents better tools that are simpler to use. Teach children how digital systems shape what they see.
But let us stop pretending that banning social media or blocking VPNs is a serious substitute for understanding the systems we are trying to regulate. It is not. It is policy by panic or by misguided adventure.
Children do not need adults performing technological outrage from the sidelines. They need adults willing to understand the digital world well enough to guide them through it.
The Online Safety Toolkit: 4 Roads' automated safety for Verint Community.
First published on LinkedIn on 31 March 2026.




