EU Flag - online safety conferences

What TSPA EMEA and FOSI Brussels Tell Us About Where Online Safety Is Heading

Last month, I was in the room at TSPA EMEA, watching trust and safety practitioners wrestle with what it actually takes to run compliant, effective operations in a regulatory environment moving faster than most teams can staff for. This week I was at FOSI Brussels, where regulators, civil society, and platforms talked about what those regulations are trying to accomplish and who gets to define success.

Two very different rooms. The same underlying pressure. And notably, many of the same faces, from long-time colleagues I’ve worked alongside for years, mixed in with plenty of people I was meeting for the first time. The trust and safety community is small, and getting smaller even as the work is getting bigger.

 

The Pope weighed in on AI

FOSI Brussels opened with something I didn’t expect: a reference to the Pope’s treatise on AI. Stephen Balkam and OpenAI’s Allison Fine Mishkin used it to frame what I’d call the dichotomy of AI. The technology presents genuine risks. It also presents genuine solutions. The field is trying to hold both at once, and the moral weight of that is not lost on anyone paying attention.

OpenAI’s work in this space is moving fast. Mishkin described active partnerships with national education systems to roll out AI literacy programs and certifications, with youth groups and third-party credentialing bodies involved. Safety by design was named explicitly, but so was something important that often gets dropped: safety by default. The distinction matters. Design is architecture. Default is what actually ships to users.

 

The regulation gap is not about intent, it’s about translation

At FOSI’s regulation panel, Ofcom’s Anna Lucas mentioned illegal hate speech, counter-terrorism content, and nonconsensual sexual imagery as upcoming enforcement focuses. The Netherlands’ ATKM brought a different frame: their mandate includes operating a CSAM hotline, alongside their duty of care framework that explicitly exceeds what the DSA requires. Both are part of the GOSRN network (nine regulators coordinating internationally) that is the structural answer to a problem everyone in that room knows well: harm doesn’t stop at borders, but jurisdiction does.

One line landed harder than others in their panel for me: “Policymakers and regulators do different things.” It sounds obvious. It’s not, especially to those who have watched other roles in this process clash, like a compliance team trying to satisfy a requirement written by someone who has never run a moderation queue.

The OECD reminded the room of the eight core safety-by-design principles, noting that most major platforms are now following them. That’s progress. But the observation underneath it was less encouraging: regulators have been pushed up the stack, away from the product experience, which means their ability to demonstrate impact on actual user outcomes is limited. The political pressure to show results is real. The tools and workflows to measure the right things are not yet there.

And the pace of regulatory action is not slowing. While that panel was happening, the UK Prime Minister had announced new plans the day before to restrict children taking, sharing, or viewing nude images. The same day as the conference, the Dutch government announced a ban on kidfluencers under 16 making commercial content on social media. 

At TSPA, the regulatory compliance workshops made the operational side of this gap visceral. Rooms full of practitioners. not policy teams, trading tips in real time: how are you handling this requirement? What does your reporting workflow actually look like? That energy tells you everything about where the industry is relative to what’s being asked of it. Teams are figuring this out largely alone, under deadline, without a shared playbook.

 

Apple showed what “by default” actually looks like

The Apple fireside at FOSI, timed just after WWDC, was more concrete than I expected. Ruben van der Dussen walked through the latest updates: expanded Screen Time controls, Ask to Buy and Ask to Browse, and a meaningful shift in how Apple thinks about parental tools. Less about restriction, more about allowance. Less about locking things down, more about changing what the default experience is for a minor before any parent has touched a setting.

The new detection capabilities are significant: gore and violence detection added to existing nudity detection, with contextual messaging and automatic parent alerts. Apple has also built out a dedicated resource for parents to help them navigate these features. This is what safety by default looks like at scale. The defaults ship with the device. The APIs extend them into the ecosystem.

 

Youth safety is the policy pressure point, but teens are in the room now

The Child Focus session opened with Malala’s direct call to action: young people must be part of the conversations and decisions that shape their lives. What followed made that case better than any adult panel could have.

Lenaëlle spoke about manosphere content, the algorithmic pipelines pulling young men toward increasingly extreme material, and said something that should appear in every policy document about platform accountability: “We expect tech companies to stop hiding behind algorithms, and policymakers to treat these issues with the urgency they deserve.” That’s not a policy recommendation. That’s a verdict from someone living inside the problem.

Thomas talked about an insular upbringing that the internet genuinely helped broaden, and about encountering grooming through the same channels. His ask was specific: a report button that actually works. Not a better UI. A basic function, functioning as promised.

The TikTok fireside with Global Youth Council member Tende extended that thread. The conversation moved beyond platform policy into lived experience – what safety actually feels like when you’re the user, not the operator.

The research panel added important context. A panelist suggested that social media platforms never had the opportunity to do safety by design. I’d push back on that. Some of us had a decade of hands-on experience in online safety when the major social networks went mainstream. The knowledge existed, but it was ignored. What we have now is not a second chance at design, but a chance to build the next generation of platforms and features correctly, rather than spend years correcting decisions that should never have been made. That distinction matters for how we think about accountability going forward.

The Adolescence series came up during the Molly Rose Foundation fireside as a cultural reference point for where public attention is landing. One observation they made about that series I’ve also made, that Adolescence illustrates many of the problems today’s youth are handling clearly, but it doesn’t offer any solutions.

 

AI is both the solution and the next problem

The TSPA afternoon was largely given to AI (a panel, then parallel roundtables) and there were a range of positions in the room. The panel itself was split: the moderator sometimes defaulted to a doom-and-gloom frame, while representatives from Besedo and Google pushed back with concrete examples of workflow improvement and efficiency gains. The Valinor rep landed somewhere in the middle, not an advocate but pragmatic. AI is a necessary evil at this point. So the question isn’t whether to use it, but how.

The roundtable I attended reflected something closer to resolve. The room was packed and the dominant position wasn’t ideological, but operational. AI is here and it’s a tool. The conversation wasn’t about whether AI belongs in T&S workflows. It was about calibration, escalation paths, where human review remains non-negotiable, and how you measure quality when the volume is that high.

That conversation is happening at the practitioner level. The policy conversation is still catching up.

 

What neither room fully resolved

Two things surfaced across both events that neither answered cleanly.

The first is accountability at the seams — who is responsible when harm happens across platforms, across jurisdictions, or across the boundary between an AI decision and a human review? And where do parents fit into that picture? Not as the fallback responsible party (we’ve seen where that leads) but as participants in a system designed to actually support them. The regulatory frameworks are largely platform-specific, but the harm and the families experiencing it, are not.

The second is what “working” actually means. Multiple sessions at both events referenced metrics (incident rates, response times, compliance dashboards) without anyone agreeing on the outcome variable. Fewer harmful posts removed? Fewer harmful experiences reported? Fewer kids in crisis? These are not the same measure and policy is being built on top of that ambiguity. The longitudinal research projects mentioned at FOSI are a start, but they are not yet an answer.

 

The short version

The people building and running trust and safety systems and the people writing the rules for them are not in enough rooms together. TSPA is practitioner-first. FOSI skews toward policy and civil society. Both are doing important work and the gap between them is where the real risk lives.

At GGWP, we sit at that intersection every day. We are working with platforms to build safety infrastructure that holds up under both operational reality and regulatory scrutiny. What both events made clear is that the teams getting ahead of this aren’t waiting for the regulations to finalize before they act. They’re building now.

—–

Joi Podgorny heads up Trust & Safety at GGWP. With over two decades of experience running and strategizing trust and safety operations across entertainment, gaming, and online communities, she works at the intersection of policy, product, and live operations.