Policing predatory platforms Can federal legislation effectively rein in social media’s opaque algorithms and deceptive design features?
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
In June, when Ottawa introduced Bill C-34, the Safe Social Media Act, one element — plans to block children under the age of 16 from certain social media platforms — dominated headlines and fuelled debates.
But this marks just one component of a complex, 92-page bill that would enact two separate pieces of legislation: the Digital Safety Act and the Digital Safety Commission of Canada Act.
The Free Press took a close look at the tabled bill, breaking down the changes it would make, if passed.
Heritage Minister Marc Miller, whose department is responsible for the file, told reporters in June the bill meant to ramp up Canada’s oversight of Big Tech.
“We have to be honest, we are behind — Canada is behind, our laws are behind the digital era,” he said.
“This is unacceptable. We’re failing our children. Enough is enough. Our parents cannot face these challenges alone and the safety of children can’t be an afterthought.”
Heritage Minister Marc Miller (centre) speaks at a press conference introducing a new social media bill designed to protect young users
What would Bill C-34 do?
While the legislation would block children under the age of 16 from holding social media accounts on certain platforms, it also carves out a caveat: an exemption may be granted to certain platforms if and when they can prove they’ve “established and maintained sufficient safeguards for children.” (The specifics of these safeguards have not yet been established).
The law would impose on social media companies and AI chatbots the duty to protect children from content that promotes self-harm, sexual exploitation, violence, hatred and bullying, as well as the non-consensual sharing of intimate images.
Among other steps, the law would implement:
- A 24-hour removal rule for content that sexually victimizes a child, as well as for non-consensually distributed sexual material, including deepfakes;
- A requirement that online services use age assurance to minimize the likelihood that children encounter pornography;
- Platforms would be required to provide easily accessible tools for users to flag harmful content;
- AI-generated content would need to be labelled as such;
- Chatbots, such as X’s Grok or ChatGPT, would have a duty not to engage — or encourage — users in discussions around suicidal ideation or talk of harming someone else. Instead, the chatbot would need to direct a user to a real person, though the bill would not ban children from using AI chatbots.
What’s the context?
In recent years, the volume of child sexual abuse material available on the internet has exploded, as have reports of children being harmed while using the web.
Over the last decade, a tool created by the Winnipeg-based Canadian Centre for Child Protection has sent out more than 141 million “takedown notices” to companies — flagging child sexual abuse material or content identified as “harmful-abusive.”
Between 2020-25, the centre logged a 300 per cent increase in reports of sextortion against teens. At least 45 teenagers in North America have died by suicide as a result of sextortion, according to tracking by Paul Raffile, a global cybercrime expert.
Meanwhile, in just one year, between 2024-25, British analysts at the Internet Watch Foundation observed a roughly 26,000 per cent rise in the number of abuse videos generated by AI.
Following the Feb. 10 mass shooting — carried out by a teenager who fatally shot eight people — in Tumbler Ridge, B.C., it was revealed the shooter had written violent messages on ChatGPT prior to the incident, and while this was flagged internally, the company behind the chatbot did not alert law enforcement.
What would the Digital Safety Commission do?
Another component of the law would create the Digital Safety Commission, a federal regulator that would handle complaints and enforcement around online safety.
It would also be responsible for establishing regulations, including implementing safety features for children using social media. The body would also be authorized to summon people to give testimony and to levy fines against rule-breakers.
The commission’s fines would max out at $20 million or five per cent of a company’s gross revenue, whichever is greater, though this is around half the amount proposed in 2024, under a previous attempt to introduce similar legislation.
It is also far less than fines that can be issued by Ofcom, the U.K. regulator responsible for digital safety, which top out at around $34 million in Canadian currency.
The commission would be made up of three to five members.
What might be missing?
Currently, tech companies operating in Canada are required to report child sexual abuse material on their sites to law enforcement, but this rule only applies after they become aware of it — whether because it was flagged to them or they detected it themselves. But companies aren’t obligated to proactively search their websites for illegal content.
The proposed legislation wouldn’t change this. It specifies: “Nothing in this Act requires an operator to proactively search content on a regulated service that it operates in order to identify harmful content.”
But the act does add a caveat: that future, not-yet-written regulations may require services to prevent content that sexually victimizes a child or revictimizes a survivor from being uploaded in the first place.
This process, of blocking users from uploading previously identified abuse imagery, is known as “proactive detection.”
In interviews with the Free Press earlier this year, multiple staff members with the Canadian Centre for Child Protection — when asked for the one change they’d make to protect children — called for future laws to mandate the “proactive detection” of child sexual abuse material. The centre even offers a free proactive detection tool to companies called Shield.
It means that while Bill C-34 doesn’t mandate proactive detection, it doesn’t rule it out either.
Also notable is that the bill explicitly excludes private messaging services, like WhatsApp or Telegram, from its responsibilities, despite the fact these encrypted platforms are places where child luring and the sharing of child sexual abuse material occurs.
How does age assurance work?
Age assurance is a broad term referring to any method meant to identify how old an online user is, and it’s how companies would comply with laws requiring them to “age gate” certain services — keeping out minors.
This breaks down into two different approaches: age verification and age estimation.
Age verification, which involves determining a user’s exact age, can take a few forms. The European Union, for instance, is working on rolling out a “mini wallet,” where users could confirm to a site that they are over a certain age, without sharing any other personal data, such as their birthday or identity. The wallet would use an ID card or a link to another source, such as a banking app, to establish age.
Another approach comes from the private sector, such as with U.K.-based company Yoti. Yoti uses both age verification (such as a user uploading their ID or credit-card details to confirm they are 18 or older) and age estimation (the company’s algorithm estimates a user’s age from a selfie) and then, when the user wants to enter an age-gated environment, the Yoti app confirms the user is above a certain age.
Age estimation, as the name implies, gauges a user’s approximate age — whether through analysis of biometrics or a user’s online behaviour, both of which are typically done with artificial-intelligence tools.
Biometrics refers to everything from a user’s fingerprint to their voice and likeness.
The federal Office of the Privacy Commissioner of Canada said in a recent policy note that while age assurance can actually support children’s privacy, it must be undertaken with privacy rights in mind.
The directive noted that “neither age verification, estimation, nor inference are inherently more (or less) privacy-protective.”
The office cited several potential privacy risks involved with age assurance: breaches of personal information, like facial images or government-issued identification; tracking of a person’s online activities; and unequal collection of personal information if age estimation is less accurate for certain groups of people.
What are other countries doing?
In late 2025, Australia moved to block children under 16 from holding accounts on certain social media platforms, including TikTok, Snapchat, X, Instagram and Facebook.
As for AI chatbots, Australia requires that companies don’t serve up content to children on suicidal ideation, self-harm, pornography or explicit violence. (And since March, pornography websites have been required to block under-18s).
The U.K. also requires internet companies to prevent children from viewing pornography, as well as self-harm, suicide and eating-disorder content. According to Ofcom, the U.K. regulator responsible for online safety, children as young as eight have accessed pornography online.
Around the world, at least nine countries now have online safety regulators, including France, South Africa, Australia, Fiji, Ireland and the U.K.
What’s Australia’s experience?
Julie Inman Grant, a former Microsoft executive who is now Australia’s eSafety Commissioner, told the Free Press in an April interview that social media companies deactivated 4.7 million under-16 accounts in the first two days of the law coming into effect.
However, as she explained, there has been resistance from some companies, such as allowing children multiple chances to get past age checks.
“They’re playing every trick in the book, because they don’t want this to be successful. If it is, it sets a global precedent, and then there’s kind of a domino effect,” she said.
Australia’s eSafety Commissioner Julie Inman Grant said tech companies continue to fight crackdowns.
Inman Grant was pragmatic: she didn’t expect compliance would happen overnight, with all under-16s removed from social media platforms, but rather, the idea is to change the culture over time— and provide parents the government’s backing to say “no” to their kids.
“This social media delay is really like a circuit breaker. We’ve been doing all these things for all these years, but we have to draw a line here and make a cultural shift,” she said.
“We’re trying to unwind 20 years of entrenchment of these companies building these systems, and deliberately saying in their discovery documents that tweens have ‘herd mentality’ and (that) ‘we need to get them when they’re young and hook them in, then you’ve got a pipeline of customers for life.’”
Inman Grant said the delay is necessary to allow children under 16 more time to develop their critical reasoning skills, adding that kids are up against “opaque algorithms” and “deceptive and harmful design features.”
What do Canadian experts and advocates say?
In June, Lianna McDonald, the executive director of the Canadian Centre for Child Protection, said the bill’s tabling marked a “crucial step towards protecting children.”
“By establishing clear obligations, most notably delaying access to social media until age 16, this bill recognizes that childhood is a finite and vulnerable period – one that demands protection, not exploitation,” she said in a press release, noting that the organization would carefully review the bill to provide a more detailed assessment.
Lianna McDonald, executive director of the Canadian Centre for Child Protection, called the bill ‘a crucial step towards protecting children.’
Michael Geist, a law professor at the University of Ottawa where he is the Canada Research Chair in Internet and E-commerce Law, wrote in a June blog post, titled Everything All At Once, that while some components of the bill — such as the duty to make certain content inaccessible within 24 hours and to increase transparency through measures like public digital safety plans — provide a “credible starting point,” Bill C-34 leaves a lot of unanswered questions.
As for the social media ban for under-16s and how companies might, eventually, be allowed to host teens again, Geist wrote: “The degree of uncertainty is astonishing: which social media services are covered, which age-verification technology is adequate, and what measures are needed for exemption are just some of the issues to be determined after the law is enacted.”
Geist criticized the “kitchen-sink” approach of the bill, saying it “invites opposition from every direction at once and virtually guarantees long delays in passing the bill, alongside even longer processes to bring the law into effect.”
The Canadian Civil Liberties Association zeroed in on the powers granted to the new digital regulator, with its executive director Howard Sapers saying in a press release that it introduces obligations “which are so alarmingly broad that providers of regulated services will be tempted to over-comply at the expense of users’ freedom of expression and privacy rights.”
Meanwhile, in a June press release, UNICEF Canada CEO Sevaun Palvetzian called the bill an “important and long-overdue step,” praising it for being flexible and noting the possibility for platforms to “welcome young people back once safety standards are met.”
But Palvetzian called on Ottawa to complete a child-rights impact assessment, saying kids have a right to “shape policies that in turn will fundamentally shape their lives.”
What’s next?
The bill’s potential changes are not imminent. It still needs to move through second and third readings, committee review (and potentially extensive changes), and then pass through further scrutiny in the Senate.
Even if it becomes law, the Digital Safety Commission would need to be staffed and operationalized, and because this new body would be responsible for writing some of the regulations underpinning the legislation, it would likely take years to fully come into effect.
marsha.mcleod@winnipegfreepress.com
Marsha McLeod
Investigative reporter
Signal
Marsha is an investigative reporter. She joined the Free Press in 2023.
Our newsroom depends on a growing audience of readers to power our journalism. If you are not a paid reader, please consider becoming a subscriber.
Our newsroom depends on its audience of readers to power our journalism. Thank you for your support.