The future of online safety isn’t age verification. It’s trust.
24 July 2026

THE FUTURE OF ONLINE SAFETY ISN’T AGE VERIFICATION. IT’S TRUST.
When the UK government recently revived its controversial proposal to ban social media for under-16s, the public debate predictably fractured along a familiar fault line: how exactly do we verify a user’s age? Tech executives warned of privacy intrusions, parents expressed relief, and politicians promised robust digital enforcement. It is an intuitive question to ask. It also happens to be the wrong one.
As both a parent and someone who has spent almost twenty years building technology in the digital gambling sector—one of the world’s most heavily regulated, adversarial online environments—I welcome any serious attempt to protect young people from online harm. The status quo is untenable. Yet, I deeply worry that policymakers are approaching tomorrow’s existential digital challenge with yesterday’s analogue thinking. The real issue confronting us isn't social media, nor is it the mechanics of age verification. It is the systemic collapse of digital trust.
Across the gaming and fintech sectors, a single lesson repeats itself: technology evolves, but fraud evolves faster. Every new safeguard creates a new workaround, rendering static regulatory solutions obsolete before the ink on the legislation is even dry. Today, generative artificial intelligence has supercharged the velocity of this arms race.
One of the biggest misconceptions in public policy is that identity verification begins and ends with a static document upload. To a lawmaker, requiring a teenager to upload a passport or use a facial-scanning app seems like a robust barrier. In reality, it is a speed bump. Long before AI entered the mainstream, the digital gambling industry was forced to grapple with synthetic identities, deepfaked documentation, and automated bot networks designed to mimic human players.
The lesson we learned was fundamental: identity isn't something you establish once. It’s something you continuously assess throughout the entire user lifecycle.
Today, digital trust is built from hundreds of dynamic, ambient signals rather than a single passport scan. When a user interacts with a platform, a modern risk engine looks at a constellation of data: behavioral biometrics (how fast they type, how they move a mouse), device fingerprints, network consistency, and transaction velocity. If behavioral patterns abruptly alter, the system flags it. None of these signals proves fraud or underage access in isolation, but together they tell a coherent story.
Over a decade, the core regulatory question in fintech shifted from a binary, static query—"Is this customer over 18?"—to a continuous, dynamic one: “Should I still believe you are who you say you are?” It is precisely this shift toward behavioral risk assessment that policymakers must apply to online safety. A static age gate is bypassed once and forgotten; continuous trust frameworks are ambient and inescapable.
The depth of this challenge was driven home to me recently while sitting on an industry panel alongside senior representatives from HSBC and Revolut. We were there to discuss deepfakes, but as the conversation unfolded, it exposed a bizarre corporate contradiction occurring right now.
Walk into any corporate boardroom today, and the mandate is to aggressively deploy autonomous AI agents, conversational assistants, and digital twins designed to flawlessly mimic human interaction. We celebrate these breakthroughs because they lower costs. Yet, at the exact same time, financial institutions are frantically telling consumers the exact opposite: do not trust unfamiliar voices, doubt video calls, and treat every incoming digital interaction with profound suspicion.
This creates a dangerous psychological paradox. By aggressively pushing automated agents disguised as convenient customer service, businesses are actively desensitising consumers to the exact synthetic traits that define malicious deepfakes. We are conditioning society to accept the synthetic as authentic, dismantling our natural internal warning signs.
This shift is no longer theoretical. Recently, I received a WhatsApp message ostensibly from a CEO I work closely with, urgently demanding highly confidential, commercially sensitive information. Having been targeted by digital fraud in the past, my suspicions were raised by subtle anomalies in the text style. Yet, moments later, my mobile rang. The voice on the other end of the line was unmistakably, perfectly, the voice of the CEO.
In that moment, the psychological friction vanished and my guard almost dropped entirely. It was only by forcing myself to maintain an artificial skepticism—asking a series of highly specific, context-heavy questions that a generic AI script couldn't anticipate—that the scammers finally hung up. It was an incredibly close call, and it illustrated a terrifying reality: when technology can flawlessly clone a trusted voice in real-time, our natural psychological defenses are rendered useless.
If an executive equipped with decades of tech experience can nearly be compromised, how can we expect a teenager to navigate this landscape? The policy discussion around young people focuses heavily on preventing access, but it completely ignores how adolescents themselves interact with this technology. Teenagers are not passive consumers; they are highly adaptable digital natives who already utilize synthetic media and manipulate digital environments faster than adults.
Yet, this fluency creates a dangerous paradox. Because the next generation is so adept at using AI, they are uniquely desensitized to its deceptive potential. They can create a deepfake, but they are entirely unequipped to spot when an AI agent is subtly manipulating them through emotional engineering or manufactured urgency. Their technical literacy has outpaced their emotional discernment.
This is why blunt legislative prohibitions are destined to fail. History across the gambling, alcohol, and tobacco sectors proves conclusively that outright bans do not eliminate demand; they simply drive it underground into unregulated black markets. Social media will be no different. Australia enacted the world’s first outright under-16 social media ban, yet subsequent data reveals that teenagers continue to access restricted platforms via routine workarounds, forcing Canberra to desperately threaten tech platforms with multi-million dollar fines to patch the leaks.
Instead of hiding behind the illusion of an unenforceable ban, we must shift toward a three-pillared strategy built on real-world pragmatism.
First, we must replace static age gates with continuous trust architecture. If governments truly want to protect minors, they must mandate that platforms move away from "one-and-done" ID uploads and instead deploy ambient, behavioral risk engines. By constantly analyzing non-invasive signals—like typing cadences, engagement velocity, and network consistency—platforms can dynamically flag profiles exhibiting age-inconsistent behavior, forcing automated re-verification long after the initial sign-up.
Second, digital literacy must mature into "trust literacy." We must shift the educational focus from teaching children how to use technology to teaching them when to suspect it. Education must evolve to expose the mechanics of psychological manipulation, voice cloning, and synthetic urgency, teaching the next generation to maintain artificial skepticism in a world of flawless digital deception.
Finally, we must establish a stringent product design code of conduct. There is an undeniable irony in an alumnus of the digital gambling sector calling for behavioral regulation. But it is precisely because of that background that I know how razor-thin the line is between fostering loyalty, optimizing an anticipation loop, and engineering an unhealthy, compulsive attachment. Product executives must be tasked with genuine safety accountability, rather than letting them weaponize advanced neuroscience under the sanitized corporate banner of "engagement optimization." Stripping platforms of toxic, addictive design loops is an engineering and architectural responsibility, not a parenting failure.
A blunt social media ban creates a comforting, politically convenient illusion of safety while leaving the underlying architecture of the internet fundamentally broken. It treats a symptom while ignoring the systemic disease. If Westminster truly wants to protect the next generation in an era of synthetic abundance, it must look to the battle-tested innovations on the frontlines of fintech and digital gaming. That framework, rather than the logistics of age verification, will define the next decade of public policy, corporate strategy, and human safety.