Research into under-13 safety controls on mainstream platforms found that protections often work only when children stay within the intended kid account types and settings; when kids use the wrong account type or explore beyond guardrails, they can more easily encounter inappropriate or risky communities. Testing that mimicked normal child behavior (not exploits) reported that platform search and discovery features can still surface communities linked to fraud and other illicit activity, highlighting practical gaps between stated age protections and what children can access during routine browsing.
OpenAI updated its Europe-facing privacy policy to reflect revised EU requirements, expanding the categories of data covered (including files, images, audio, video, and content created via newer tools/integrations) and adding clearer explanations of user controls. The policy also details options such as opting out of model training where available, managing memory features, exporting/deleting data, and using temporary chats, and it describes broader disclosure scenarios (e.g., sharing with service providers for infrastructure/safety/age and identity checks, and sharing information with a parent/guardian for teen account oversight) as well as retention practices that may keep some data after deletion requests for legal, security, or compliance reasons.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The researchers found that public or falsified-age access could expose children to fraud, sexually suggestive material, graphic violence, cybercrime-linked communities, escort promotions, and credit card fraud tutorials on platforms including YouTube, Roblox, Instagram, Discord, Twitch, and TikTok. They also reported stronger protections on Minecraft, Snapchat, Spotify, and Fortnite during the same testing period.
From December 1 to 17, 2025, a specialist research team evaluated mainstream platforms' protections for children under 13 using normal user behavior and US-based accounts. The testing examined whether kid and teen safety features could be bypassed without exploits.
Following an EU revision in November 2024, OpenAI updated its Europe-facing privacy policy to expand and clarify how it handles personal data across its website, applications, and services. The revised document added broader data categories, more detailed user controls, retention explanations, and updated controller information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.