Skip to content

Briefing

Online Safety

Tech giants to report on child abuse measures after 'alarming' gaps

Make us a preferred source

Link copied

The news: Australia’s eSafety Commissioner has issued legal notices to tech giants including Apple, Google, Meta and Microsoft, requiring the companies to report to the regulator every six months about measures they have in place to tackle online child sexual abuse.

The numbers: eSafety said that compliance with the notice is mandatory, and there may be financial penalties of up to $782,500 a day for services that do not respond.

The companies will have until 15 February 2025 to provide their first round of responses.

The context: Issued under Australia’s Online Safety Act, notices were also sent to services Discord, Snap, Skype and WhatsApp, and require all recipients to explain how they are tackling child abuse material, live-streamed abuse, online grooming, sexual extortion and the production of “synthetic” or deepfaked child abuse material created using generative AI.

For the first time the notices will require tech companies to report periodically to eSafety for the next two years, with eSafety publishing regular summaries of the findings to improve transparency, demonstrate safety weaknesses and incentivise improvements.

The companies were chosen partly based on answers many of them provided to eSafety in 2022 and 2023, exposing a range of safety concerns when it came to protecting children from abuse, eSafety Commissioner Julie Inman Grant said.

eSafety noted that Apple and Microsoft said in 2022 that they do not attempt to proactively detect child abuse material stored in their iCloud and OneDrive services, despite the fact that these file storing services "serve as a haven for child sexual abuse and pro-terror content to persist and thrive in the dark".

Skype, Microsoft Teams, FaceTime, and Discord were found to not use any technology to detect live-streaming of child sexual abuse in video chats, despite evidence of the "extensive use of Skype, in particular, for this long-standing and proliferating crime".

Meta admitted it did not always share information between its services when an account is banned for child abuse, meaning offenders banned on Facebook may be able to continue perpetrating abuse through their Instagram accounts, and offenders banned on WhatsApp may not be banned on either Facebook or Instagram.

eSafety also found that eight different Google services, including YouTube, are not blocking links to websites that are known to contain child abuse material.

Elsewhere, despite eSafety investigators "regularly observing use of Snapchat for grooming and sexual extortion", eSafety found that the service was not using any tools to detect grooming in chats.

The report also revealed "wide disparities" in how quickly companies respond to user reports of child sexual exploitation and abuse on their services. In 2022, Microsoft said on average it took two days to respond, or as long as 19 days when these reports required re-review, which was the longest of all the providers. Snap on the other hand reported responding within four minutes.

What they said: "We’re stepping up the pressure on these companies to lift their game," Inman Grant said.

"They’ll be required to report to us every six months and show us they are making improvements.

"When we sent notices to these companies back in 2022/3, some of their answers were alarming but not surprising as we had suspected for a long time that there were significant gaps and differences across services’ practices.

"In our subsequent conversations with these companies, we still haven’t seen meaningful changes or improvements to these identified safety shortcomings."


By Hugo Mathers