What are the primary safety gaps identified in gaming platforms?
The eSafety Commissioner found that major gaming providers demonstrate inconsistent approaches to protecting minors from serious online harms. The investigation revealed that weak safety protocols on these platforms can allow predatory adults to establish contact with children, potentially leading to grooming for sexual exploitation or radicalisation.
According to eSafety Commissioner Julie Inman Grant, children have a fundamental right to play online without exposure to predators, sexual extortionists, violent extremist content, or other harmful materials. The report highlights a spectrum of protection, ranging from proactive industry participation to significant technological omissions.
The risk of predatory contact
The core concern identified by the regulator is the ability of bad actors to bypass existing safeguards. When platforms lack robust detection tools, they create an environment where grooming can occur undetected. This process often begins with seemingly innocuous interactions that escalate into exploitation or the promotion of violent ideologies.
How do technical implementation differences affect user safety?
Technical discrepancies in content detection represent one of the most significant findings of the report, particularly regarding Valve's Steam platform. The regulator noted that Valve was the only provider among the major platforms that did not utilize industry-standard technology designed to detect and remove known harmful content.
The report specifically criticized the lack of proactive measures in certain chat environments. While some platforms use advanced automated systems, others rely on tools that are primarily configured to flag scams rather than detecting child sexual exploitation or violent material. This creates a reactive rather than a preventative safety environment.
Language model training and detection
A recurring technical issue identified in the report concerns how platforms train their automated systems. Both Roblox and Valve were noted for relying exclusively on internal datasets to train their language detection models. Furthermore, the report highlighted that these companies do not engage in the regular retraining of these models, which is essential for staying ahead of evolving predatory language and slang used by offenders.
Why is age verification inconsistent across major games?
The methods used to verify user age vary significantly between platforms, creating loopholes that allow adults to access high-risk communication features. For many services, the primary method of verification is self-declaration, which is easily bypassed by users providing false information.
The report highlighted the following trends in age verification:
- Minecraft and Fortnite: These platforms generally allow users to self-declare their age. This mechanism means that individuals can easily access communication features intended for older audiences by simply misrepresenting their age.
- Steam: While Steam has historically relied on self-declaration, the report acknowledged that the platform has recently introduced age checks utilizing credit card verification.
- Roblox: The platform has implemented stronger age verification measures since December 2025, according to the findings.
The impact of self-declaration loopholes
When a platform relies on self-declaration, it essentially shifts the burden of honesty onto the user. For children, this is an ineffective safeguard. The ability for an adult to claim they are a minor—or conversely, for a minor to claim they are an adult to bypass restrictions—remains a critical vulnerability in the gaming ecosystem.
How does information sharing impact global safety efforts?
The investigation found a lack of cohesion in how gaming companies participate in industry-wide safety initiatives. Effective protection often relies on platforms sharing data regarding breaches and emerging threats, yet the report found significant gaps in this collaborative approach.
The level of cooperation varied widely among the investigated entities:
| Platform/Developer | Industry Cooperation Status |
|---|---|
| Mojang Studios (Minecraft) | Shared expertise regarding child exploitation and violent extremism. |
| Roblox | Shared expertise regarding child exploitation and violent extremism. |
| Valve (Steam) | Did not participate in sharing industry expertise. |
| Epic Games (Fortnite) | Failed to share breach instances under a global programme. |
The failure of Epic Games to share breach information is particularly notable, as it occurred under a global programme specifically designed to combat online child sexual exploitation and abuse. Such information gaps hinder the ability of the wider industry to respond to coordinated threats.
What is the broader context of Australian online safety regulation?
These findings come at a time when Australia is positioning itself as a global leader in digital regulation. The country has recently implemented significant measures to curb online harms, though the scope of these regulations varies between social media and gaming.
In December 2025, Australia introduced a landmark social media ban for users under the age of 16. However, it is important to note that this specific ban did not extend to gaming platforms. This distinction has drawn criticism from some observers who argue that online gaming can be just as addictive as social media platforms. Additionally, the Australian government has recently pushed for tech giants to provide users with the ability to opt-out of algorithmic content delivery.
The response from gaming providers
In response to the findings, Roblox stated that the company prioritises the safety of its Australian community, particularly its youngest users. A spokesperson for Roblox also noted that the company has invested heavily in safeguards, including mandatory age checks. Other platforms, including Valve and Epic Games, were contacted for comment regarding the report's specific criticisms but had not provided detailed responses at the time of the report's release.
Frequently asked questions
Which gaming platforms were included in the eSafety report?
The Australian eSafety Commissioner's report focused on four major gaming entities: Steam (owned by Valve), Roblox, Fortnite (developed by Epic Games), and Minecraft (developed by Mojang Studios). The report examined how each of these platforms implements child safety measures and protects younger users.
What were the main risks identified for children?
The primary risks identified include exposure to predatory adults, sexual extortion, violent extremist content, and other forms of harmful material. The report warns that inadequate safety measures can facilitate grooming and the exploitation of children through online communication channels.
How does Valve's safety approach differ from others?
According to the report, Valve is the only provider among the major platforms that does not use industry-standard technology to detect and remove known harmful content. Additionally, Valve was noted for not proactively using tools to detect child sexual exploitation in chats.
Why is self-declared age a problem in gaming?
Self-declaration allows users to bypass safety restrictions by simply stating they are a different age. This means adults can easily access high-risk communication features intended for older users, and children may inadvertently enter environments that lack appropriate protections.
Did the Australian social media ban include gaming?
No, the social media ban introduced in December 2025 for users under 16 did not include online gaming platforms. While the ban targets social media, critics have suggested that gaming platforms present similar risks regarding addiction and safety.
Key takeaways
- The eSafety Commissioner found significant, inconsistent safety gaps across Steam, Roblox, Fortnite, and Minecraft.
- Valve's Steam was the only major platform identified that lacks industry-standard harmful content detection technology.
- Roblox and Valve were criticized for using only internal datasets to train their language detection models.
- Epic Games failed to share breach information under a global programme designed to combat child exploitation.
- Nine out of ten Australian children aged 8 to 17 are active online gamers.
Conclusion
The eSafety Commissioner's report highlights a critical disconnect between the prevalence of online gaming among Australian youth and the robustness of the safety measures provided by major platforms. While some companies like Roblox have made strides in age verification and industry collaboration, others like Valve and Epic Games show significant gaps in technological implementation and information sharing. As Australia continues to lead global discussions on digital safety and algorithmic regulation, the gaming industry faces increasing pressure to move beyond self-declaration and internal data silos toward proactive, industry-wide standards of protection.
