Kamran Balayev is an international legal and policy expert, business leader, and former London mayoral candidate.
When Parliament passed the Online Safety Act, it was clear that technology companies would be made to take on greater responsibility for protecting children and young people online. A noble goal, yes, although a strange consequence is now emerging. As regulators continue to focus on platforms, schools are rapidly becoming the institutions expected to manage the consequences when those platforms fail.
They did not design TikTok’s recommendation algorithms, nor do they control Instagram’s engagement systems. They are by no means the architects of the attention economy, and yet when a child falls victim to the sins of the online world, it is often the school that must respond first. For years, Britain has debated how best to regulate technology companies. Questions over big tech still remain, but in focusing so much attention on the culprits, far less attention has been paid to the institutions that are expected to deal with the fallout.
Big tech often argues that the issues which arise from their platforms require collective responses. But that argument can obscure a far more uncomfortable reality. The largest social-media platforms did not merely inherit these risks. Instead, they built the systems through which many of them spread.
Internal Meta research, first reported in 2021, revealed concerns about Instagram’s effects on some teenage users. Since then, Meta, TikTok, Snapchat and YouTube have faced growing scrutiny from courts, regulators and legislators over what they knew about risks to children and how quickly they responded.
The legal consequences are now apparent. In the United States, for instance, thousands of lawsuits have been brought against major social media companies, alleging harm caused to children and adolescents. In March 2026, a New Mexico jury ordered Meta to pay $375 million in civil penalties after finding that it had violated state consumer-protection law. In August, the court imposed a further $567 million judgment and ordered significant changes to Meta’s protections for young users, bringing its total financial exposure in the case to $942 million.
Whatever the ultimate outcome of these legal battles, they point to a much broader shift. The debate is now moving beyond whether harms exist and towards the question of who is responsible.
What did platforms know? When did they know it? And why did action so often appear to lag behind evidence?
And whilst these questions are being floated, regulators are becoming far more aggressive. The European Commission has issued preliminary findings against Meta and TikTok under the Digital Services Act, while also scrutinising Snapchat, YouTube and major app stores over safeguards for minors. The era of light-touch oversight is ending.
The distinction between online and offline harms is becoming increasingly meaningless.
A child groomed through a messaging platform does not escape that experience when they put the phone down. A victim of image-based abuse still arrives at school the next morning, having to carry the weight of such harms. Disputes that begin on social media frequently spill out from the confines of DMs or comment sections, leading to safeguarding investigations, disciplinary matters or mental-health referrals within schools.
The practical burden falls elsewhere. Whilst schools investigate safeguarding concerns, the police investigate offences. Local authorities coordinate child-protection interventions and the NHS absorbs mental-health consequences. Parents devote time, money and emotional energy to managing incidents.
The scale is by no means trivial, either. The Professionals Online Safety Helpline, which supports educators and safeguarding professionals across the UK, recorded 2,219 cases in 2024 and escalated 4,064 URLs to platforms for removal. In economic terms, the institutions creating risk and the institutions managing its consequences are often not the same.
Technology companies generate enormous revenues from engagement-driven platforms, everyone knows this. Schools, by contrast, receive many of the safeguarding consequences. This offloading of consequences is something that policymakers have thus far been reluctant to confront.
The Department for Education’s statutory safeguarding guidance makes it clear that schools must protect children both offline and online. Designated safeguarding leads are expected to take responsibility for online safety, including filtering and monitoring systems.
At the same time, Ofcom has moved the Online Safety Act from legislation to enforcement. Illegal-content duties became enforceable in March 2025, and platforms now face fines of up to £18 million or 10 per cent of qualifying worldwide revenue if they fail to comply with their legal obligations.
Taken together, these developments reflect something important – online harm is now viewed as a risk that can be prepared for.
Such a recognition changes expectations. Schools are increasingly expected to identify digital risks, educate pupils, engage parents and respond to incidents. Whether formally acknowledged or not, they are becoming part of Britain’s online-safety infrastructure. The problem, however, is that responsibility and control remain badly misaligned.
Schools can do a whole host of things. They can educate children about online risks, support victims and respond to incidents. What they cannot do is redesign algorithms, alter business models or change the incentives that drive the modern day attention economy.
And yet they are increasingly expected to manage the consequences of those systems.
The current government can point to genuine progress. The Online Safety Act is finally being enforced. Ofcom possesses powers that would have been unavailable only a few years ago. Platforms face greater scrutiny than at any point in the history of the internet. But regulation arrived late.
By the time the Online Safety Act entered its enforcement phase, evidence of grooming, sextortion, cyberbullying, image-based abuse and algorithmic harms had been accumulating for years. Policymakers spent much of the past decade debating problems that schools were already confronting daily.
Even now, government has focused overwhelmingly on what platforms must do while paying comparatively little attention to what schools are expected to do when those platforms fail.
Schools are expected to take on a raft of responsibilities, yet there remains no dedicated national framework for measuring the resources these responsibilities consume and no serious debate about where the limits of school responsibility should lie. Without such a framework, the burden being imposed on education providers is far from sustainable.
The next phase of online-safety policy should move beyond regulation and towards proper accountability. At present, Britain risks creating a system in which technology companies remain the primary beneficiaries of the digital economy while schools, families, police forces and public services absorb a growing share of the cost – a deal that was never supposed to occur.
If schools are becoming part of Britain’s online-safety infrastructure, policymakers should acknowledge that reality openly. They should establish clear standards, provide specialist training and ensure that safeguarding responsibilities are matched by the necessary resources.
For decades, conservatives have argued that strong institutions are the foundation of a healthy society. But strong institutions are not built by transferring responsibilities without transferring resources.
The Online Safety Act was supposed to make technology companies more accountable. Its success should not be measured solely by what happens inside Silicon Valley boardrooms. It should also be measured by whether Britain has reduced the burden placed on the institutions left to deal with the consequences. So far, the evidence suggests those institutions are still carrying far more of the load than they should.
Kamran Balayev is an international legal and policy expert, business leader, and former London mayoral candidate.
When Parliament passed the Online Safety Act, it was clear that technology companies would be made to take on greater responsibility for protecting children and young people online. A noble goal, yes, although a strange consequence is now emerging. As regulators continue to focus on platforms, schools are rapidly becoming the institutions expected to manage the consequences when those platforms fail.
They did not design TikTok’s recommendation algorithms, nor do they control Instagram’s engagement systems. They are by no means the architects of the attention economy, and yet when a child falls victim to the sins of the online world, it is often the school that must respond first. For years, Britain has debated how best to regulate technology companies. Questions over big tech still remain, but in focusing so much attention on the culprits, far less attention has been paid to the institutions that are expected to deal with the fallout.
Big tech often argues that the issues which arise from their platforms require collective responses. But that argument can obscure a far more uncomfortable reality. The largest social-media platforms did not merely inherit these risks. Instead, they built the systems through which many of them spread.
Internal Meta research, first reported in 2021, revealed concerns about Instagram’s effects on some teenage users. Since then, Meta, TikTok, Snapchat and YouTube have faced growing scrutiny from courts, regulators and legislators over what they knew about risks to children and how quickly they responded.
The legal consequences are now apparent. In the United States, for instance, thousands of lawsuits have been brought against major social media companies, alleging harm caused to children and adolescents. In March 2026, a New Mexico jury ordered Meta to pay $375 million in civil penalties after finding that it had violated state consumer-protection law. In August, the court imposed a further $567 million judgment and ordered significant changes to Meta’s protections for young users, bringing its total financial exposure in the case to $942 million.
Whatever the ultimate outcome of these legal battles, they point to a much broader shift. The debate is now moving beyond whether harms exist and towards the question of who is responsible.
What did platforms know? When did they know it? And why did action so often appear to lag behind evidence?
And whilst these questions are being floated, regulators are becoming far more aggressive. The European Commission has issued preliminary findings against Meta and TikTok under the Digital Services Act, while also scrutinising Snapchat, YouTube and major app stores over safeguards for minors. The era of light-touch oversight is ending.
The distinction between online and offline harms is becoming increasingly meaningless.
A child groomed through a messaging platform does not escape that experience when they put the phone down. A victim of image-based abuse still arrives at school the next morning, having to carry the weight of such harms. Disputes that begin on social media frequently spill out from the confines of DMs or comment sections, leading to safeguarding investigations, disciplinary matters or mental-health referrals within schools.
The practical burden falls elsewhere. Whilst schools investigate safeguarding concerns, the police investigate offences. Local authorities coordinate child-protection interventions and the NHS absorbs mental-health consequences. Parents devote time, money and emotional energy to managing incidents.
The scale is by no means trivial, either. The Professionals Online Safety Helpline, which supports educators and safeguarding professionals across the UK, recorded 2,219 cases in 2024 and escalated 4,064 URLs to platforms for removal. In economic terms, the institutions creating risk and the institutions managing its consequences are often not the same.
Technology companies generate enormous revenues from engagement-driven platforms, everyone knows this. Schools, by contrast, receive many of the safeguarding consequences. This offloading of consequences is something that policymakers have thus far been reluctant to confront.
The Department for Education’s statutory safeguarding guidance makes it clear that schools must protect children both offline and online. Designated safeguarding leads are expected to take responsibility for online safety, including filtering and monitoring systems.
At the same time, Ofcom has moved the Online Safety Act from legislation to enforcement. Illegal-content duties became enforceable in March 2025, and platforms now face fines of up to £18 million or 10 per cent of qualifying worldwide revenue if they fail to comply with their legal obligations.
Taken together, these developments reflect something important – online harm is now viewed as a risk that can be prepared for.
Such a recognition changes expectations. Schools are increasingly expected to identify digital risks, educate pupils, engage parents and respond to incidents. Whether formally acknowledged or not, they are becoming part of Britain’s online-safety infrastructure. The problem, however, is that responsibility and control remain badly misaligned.
Schools can do a whole host of things. They can educate children about online risks, support victims and respond to incidents. What they cannot do is redesign algorithms, alter business models or change the incentives that drive the modern day attention economy.
And yet they are increasingly expected to manage the consequences of those systems.
The current government can point to genuine progress. The Online Safety Act is finally being enforced. Ofcom possesses powers that would have been unavailable only a few years ago. Platforms face greater scrutiny than at any point in the history of the internet. But regulation arrived late.
By the time the Online Safety Act entered its enforcement phase, evidence of grooming, sextortion, cyberbullying, image-based abuse and algorithmic harms had been accumulating for years. Policymakers spent much of the past decade debating problems that schools were already confronting daily.
Even now, government has focused overwhelmingly on what platforms must do while paying comparatively little attention to what schools are expected to do when those platforms fail.
Schools are expected to take on a raft of responsibilities, yet there remains no dedicated national framework for measuring the resources these responsibilities consume and no serious debate about where the limits of school responsibility should lie. Without such a framework, the burden being imposed on education providers is far from sustainable.
The next phase of online-safety policy should move beyond regulation and towards proper accountability. At present, Britain risks creating a system in which technology companies remain the primary beneficiaries of the digital economy while schools, families, police forces and public services absorb a growing share of the cost – a deal that was never supposed to occur.
If schools are becoming part of Britain’s online-safety infrastructure, policymakers should acknowledge that reality openly. They should establish clear standards, provide specialist training and ensure that safeguarding responsibilities are matched by the necessary resources.
For decades, conservatives have argued that strong institutions are the foundation of a healthy society. But strong institutions are not built by transferring responsibilities without transferring resources.
The Online Safety Act was supposed to make technology companies more accountable. Its success should not be measured solely by what happens inside Silicon Valley boardrooms. It should also be measured by whether Britain has reduced the burden placed on the institutions left to deal with the consequences. So far, the evidence suggests those institutions are still carrying far more of the load than they should.