> Parents can lock devices into "child mode" that emits "user is child" headers. Websites can then block.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
No offense but if you're proposing a solution that involves whitelists... that solution has already failed.
The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.
And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?
There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.
It seems to me that every other solution than a "this is a child" header is either impractical or way worse.
> that solution has already failed.
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
https://onlinesafetyact.co.uk/in_memoriam/
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.