Safe Participation Framework: Opportunity and Safety for the Next Generation in the Age of AI
Published Sep 10, 2026 · Printed beneath the title as "Sep 10, 2026", matching the article:published_time metadata (2026-09-10T16:00:17Z). The metadata also records article:modified_time 2026-09-23T17:04:07Z, so the page was edited after publication.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
Microsoft's Chief Digital Safety Officer and Chief Privacy Officer set out the company's approach to children and teenagers online, organised as three pillars — safety by design, age-differentiated experiences, and education and empowerment. The framework is built on the claim that protection and participation go together: "Children and families should not have to choose between the protections they need and the opportunities technology can provide." It is aimed partly at lawmakers. Microsoft says it is sharing the approach "to help inform emerging regulatory frameworks," and presents it as a foundation "we expect it to continue evolving as technology, research, and societal expectations change." Its regulatory philosophy is proportionality: "Achieving that goal requires real protections that are proportionate to risk and implemented in ways that respect users’ privacy. Risks are not uniform across different technologies and services, and safeguards should reflect and address those differences." The concrete commitments are mostly product facts. All Copilot users must now sign in, and "access is restricted for children under 13 (or older where required by local law)". Copilot directs users to crisis support when self-harm risks are detected and adds break reminders and "guardrails to protect against delusional outputs". A new Windows Age API is meant to give developers "trusted age signals" while "minimizing the collection and sharing of personal data". Bing has strengthened CSAM protections across its generative AI experiences. On education, digital literacy is called "a core component of child safety", and Microsoft says it will expand its AI-companionship toolkit for young people through Europe, Asia and the Americas and deepen research partnerships with AI Safety Institutes. It is candid about its limits: "We do not claim to have all the answers."
Stated positions (12)
- Protection and opportunity are framed as complements, not trade-offs: "Children and families should not have to choose between the protections they need and the opportunities technology can provide."
- Technology companies carry a dual duty: "a responsibility both to protect young people from harm and to ensure they can benefit from technology through thoughtfully designed experiences, age-appropriate protections, and demonstrable safeguards."
- The framework is offered to shape regulation: Microsoft shares it "to help inform emerging regulatory frameworks and advance protection and opportunity together."
- Safeguards should be proportionate and service-specific: "Risks are not uniform across different technologies and services, and safeguards should reflect and address those differences."
- Safety by design means "identifying foreseeable risks, examining the impact of product features and user experiences, and implementing proportionate safeguards."
- Young people "are not a single group"; age-appropriate design should make protections "responsive to the needs of users at different stages of development."
- Copilot now requires sign-in for all users, and "access is restricted for children under 13 (or older where required by local law)."
- Copilot directs users "to crisis support resources when self-harm risks are detected" and adds break reminders, reporting tools, transparency and "guardrails to protect against delusional outputs."
- Platform-level age signals: the new Windows Age API and expanded age assurance are intended "to provide developers with trusted age signals" while "minimizing the collection and sharing of personal data."
- Bing "has also strengthened protections against child sexually abusive material (CSAM) across its generative AI experiences," and SafeSearch has been expanded globally to more categories of harmful content.
- Education is treated as safety infrastructure: "Digital literacy is, therefore, a core component of child safety." The Behind the Chat AI-companionship toolkit will expand "throughout Europe, Asia, and the Americas" from this autumn.
- Over the coming year Microsoft will "deepen partnerships with researchers, AI Safety Institutes (AISIs), governments, and civil society to advance the research, evaluations, and benchmarks needed for safer digital and AI experiences."
About this document
A signed blog post of about 1,100 words on Microsoft On the Issues (blogs.microsoft.com), dated Sep 10, 2026 and bylined "Mike Jackson, Chief Digital Safety Officer, and Cari Benn, Chief Privacy Officer, Microsoft". It is the Safe Participation Framework itself; no separate framework document or PDF exists. The only embedded asset is an image of the three pillars, and the outbound links go to product announcements (Windows Family Safety and the Windows Age API, 8 Sep 2026), an earlier NCII post, the Behind the Chat toolkit on Microsoft Learn, and a 9 Sep 2026 news release with the AFT and UFT on a national AI safety and privacy standard for schools. After a short introduction citing Microsoft's AI Youth Futures Council, it has four headed sections: "Pillar one: Safety by design", "Pillar two: Age-differentiated experiences", "Pillar three: Education and empowerment" and "A framework for the future". It names no law, bill or regulator. Its commitments are product and programme facts (Copilot sign-in and under-13 restriction, crisis referral, the Windows Age API, Bing CSAM protections, SafeSearch expansion, the toolkit roll-out) plus research partnerships with AI Safety Institutes. The page is tagged "cyber, DCU".
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Proportionate, risk-based safety by design for young users
Protections for children should be designed in from the outset by identifying foreseeable risks and applying safeguards proportionate to risk. Because risks differ across technologies and services, safeguards should differ too, and should be implemented in ways that respect privacy.
The AI Act is built on the same proportionality, grading duties by risk. Its one youth-specific rule is Article 5(1)(b), which prohibits AI systems that exploit vulnerabilities due to a person's age to materially distort behaviour in a way that causes or is likely to cause significant harm.
Mississippi's Walker Montgomery Protecting Children Online Act requires digital service providers to adopt strategies to mitigate minors' exposure to harmful material, such as content promoting self-harm or sexual exploitation. The Act remains in effect while federal litigation continues.
Age assurance and age-gated access
Reliable, privacy-preserving age signals are central to age-appropriate experiences. Microsoft's Windows Age API and expanded age assurance give developers trusted age signals while minimising data collection, and Copilot now requires sign-in, with access restricted for children under 13 or older where local law requires.
The AI Act contains no age-assurance or age-gating requirement, and our corpus holds no EU instrument that imposes one on AI services.
The Mississippi Act requires digital service providers to have prospective account holders register their age and to make commercially reasonable efforts to verify it. Minors under 18 may not open accounts without express parental consent — a higher age than Copilot's under-13 default, which Microsoft says it raises where local law requires.
Crisis referral and healthy-use safeguards in conversational AI
Copilot directs users to crisis support resources when self-harm risks are detected, and encourages healthy use through transparency, break reminders, reporting tools and guardrails against delusional outputs.
Article 50(1) obliges providers to inform people that they are interacting with an AI system. The Act sets no crisis-referral, break-reminder or self-harm protocol for chatbots.
California SB 243, in force since 1 January 2026, requires companion chatbot operators to maintain and publish crisis-prevention protocols that refer users expressing self-harm to crisis services. For users known to be minors, it also requires AI disclosure and break reminders at least every three hours.
Child sexual abuse material and synthetic intimate imagery
Microsoft cites a record running from PhotoDNA in 2009 to safeguards against synthetic and non-consensual intimate imagery. Bing has strengthened protections against CSAM across its generative AI experiences, and SafeSearch has been expanded globally to cover more harmful content.
The AI Act has no CSAM-specific duty, and our corpus holds no EU instrument on child sexual abuse material to compare against.
The federal TAKE IT DOWN Act criminalises publishing non-consensual intimate imagery, including AI-generated depictions. Its Section 3 platform notice-and-removal obligations have been enforced by the FTC since 19 May 2026.
Digital and AI literacy as part of child safety
Technology alone cannot deliver safe participation; digital literacy is a core component of child safety. Microsoft's Behind the Chat toolkit on AI companionship, with classroom and parent materials, will expand across Europe, Asia and the Americas.
Article 4's AI-literacy duty covers the staff of providers and deployers, not the public or young users. Nothing in the Act asks providers to educate children or families.
Executive Order 14277 sets a national strategy for AI literacy among K-12 students and educators, run by a White House Task Force on AI Education that works with private-sector partners. It directs federal action and places no obligation on companies.
Parental controls and family tools
Family safety and privacy tools on Xbox and Windows let parents manage interactions, content, spending, screen time and privacy. Microsoft is applying the same lessons to Copilot, and this month announced new protections and defaults for children and teenagers in Windows Family Safety.
The AI Act does not address parental controls, and our corpus holds no EU instrument requiring them of AI or platform services.
The White House's National Policy Framework for AI, published on 20 March 2026 as legislative recommendations to Congress, lists child-safety protections and parental controls among its priorities. It is a set of recommendations and carries no legal force.
Microsoft describes the youth-safety practice it already runs and argues for proportionate, service-specific rules. On that point it matches the EU AI Act's risk-based structure more closely than the enforcement-heavy US state approach. The AI Act has little to say about children: its only youth-specific rule is the Article 5 ban on exploiting age-related vulnerabilities, so crisis referral, age signals and parental tools are all voluntary in the EU as far as this corpus shows. The binding youth-protection law is in the US, and it is state law. California's SB 243 codifies the crisis-referral and break-reminder practices Copilot now uses, and Mississippi's statute requires age verification and parental consent for all under-18s, a stricter line than Copilot's under-13 default. The federal TAKE IT DOWN Act has covered synthetic intimate imagery since May 2026. The framework cites none of these laws and positions itself as input to regulation still being written.
Source
https://blogs.microsoft.com/on-the-issues/2026/09/10/safe-participation-framework-opportunity-and-safety-for-the-next-generation-in-the-age-of-ai/- Date on the page:
- Sep 10, 2026
- Source checked:
- opened and confirmed on 2026-09-29