Mozilla is calling on lawmakers to move beyond legislation focused solely on age verification and access restrictions, arguing that protecting children online requires broader changes to how digital platforms are designed. In a new policy paper, the organization says many recent child safety proposals place too much emphasis on technical controls while failing to address the business models and product features that contribute to harmful online experiences.
The commentary comes as governments in several countries continue advancing laws intended to make social media and online services safer for minors. Many proposals include mandatory age verification, parental monitoring tools, restrictions on messaging, or limits on access to certain types of content. Mozilla says these measures may reduce some risks but warns they should not become the primary strategy for improving children’s online safety. Instead, the organization argues that policymakers should require platforms to build products that are safer by design rather than relying on surveillance or identity checks.
According to Mozilla, many of today’s online harms stem from product decisions that prioritize engagement over user well-being. The organization points to features such as algorithmic recommendation systems, infinite scrolling, autoplay, excessive notifications, and frictionless content sharing, arguing that these design choices can encourage prolonged use and increase young people’s exposure to harmful or inappropriate material. Mozilla says legislation should encourage companies to evaluate whether these features create unnecessary risks for children instead of treating age assurance as a complete solution.
Mozilla also raises concerns about mandatory age verification systems that require users to submit identity documents, facial scans, or other sensitive personal information before accessing online services. The organization argues that collecting additional personal data can create new privacy and security risks, particularly if that information is stored by third-party verification providers or becomes the target of cyberattacks. According to Mozilla, any child safety framework should follow the principle of data minimization by collecting only the information that is strictly necessary.
The organization recommends that lawmakers adopt a broader “safety by design” approach. Rather than focusing primarily on verifying users’ ages, Mozilla says platforms should be expected to conduct risk assessments, evaluate how product features affect children, improve transparency around recommendation systems, and provide users with greater control over personalized content. The paper also calls for stronger independent oversight and accountability to ensure companies assess and reduce foreseeable harms during product development.
Mozilla argues that parents also need practical tools that complement, rather than replace, platform responsibility. The organization says families should be able to use privacy-respecting parental controls, customize recommendations, and make informed decisions about how children interact with online services. At the same time, it cautions that responsibility for child safety should not fall entirely on parents, particularly when platforms intentionally deploy engagement-driven features that are difficult to supervise.
The policy paper concludes that effective child protection requires a combination of privacy safeguards, responsible platform design, regulatory oversight, and user empowerment. Mozilla says governments should avoid adopting measures that weaken encryption, expand mass data collection, or undermine fundamental privacy rights in pursuit of child safety, arguing that protecting children and preserving an open, secure internet should be treated as complementary goals rather than competing priorities.
