SendTech Times
News
REGIONAL MARKET:

UAE Sets a Social Media Age Gate. Enforcement Is the Hard Part.

Newsroom brief

The UAE Cabinet has barred children under 15 from social media accounts and full platform features. The rule puts age verification, child privacy, parental controls and platform compliance on a 12-month operating clock.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The National
UAE Sets a Social Media Age Gate. Enforcement Is the Hard Part.

A Cabinet Rule Moves Child Safety Into Platform Design

The UAE Cabinet has set a national age gate for social media use, barring children under 15 from creating, using or operating personal accounts.

The restriction also reaches full platform features such as social interaction, publishing, commenting, sharing, public groups, open channels and other large interactive spaces.

The rule is not limited to one app category.

It applies to social media services that let users create accounts or personal profiles, engage with other users, publish or share content, or rely on algorithmic systems to display, rank or recommend posts.

It covers free and paid platforms whose services are available in the UAE or directed at users in the country.

This scope turns a child-safety decision into a platform-compliance problem.

Social media companies will need technical and administrative controls that can block access for users below the age threshold while still meeting privacy and data-protection duties.

The Middle Band Gets Protection, Not a Full Ban

The Cabinet resolution draws a second line for children between 15 and 16.

They may use social media, but only with enhanced protective measures applied to their accounts.

The policy is more granular than a simple access ban.

The listed safeguards cover age-appropriate content controls, limits on risky contact with unknown users, restrictions on time spent on the service and parental control tools.

In practice, a platform account for a 15-year-old user is expected to behave differently from a standard adult account.

The resolution also treats recommendation systems as part of the compliance surface because it includes platforms that display, rank or recommend content through algorithms.

That places feed design, interaction features and account controls inside the same enforcement problem.

Implementation becomes difficult here.

A platform has to identify the user’s age, apply restrictions to the correct account, limit risky interactions and maintain parental tools without collecting more personal data than necessary.

The resolution links safety controls directly to privacy obligations, not only to content moderation.

Self-Declared Age Is No Longer Enough

The most operationally important line is the rejection of self-declared age as a valid verification method.

Providers must use mechanisms that achieve a high level of accuracy in determining user age while meeting child privacy and personal data-protection standards.

The resolution also points to data minimisation, secure processing and limits on retention beyond the period strictly necessary.

Those requirements narrow the room for blunt verification systems that gather excessive identity data simply to prove age.

Regular reviews and auditing are part of the mandate.

Compliance is not just a one-time settings change.

Platforms will need evidence that their age-verification and protection systems continue to work after launch, after product changes and across services available to UAE users.

The 12-Month Clock Tests Compliance Capacity

The ruling gives platforms a compliance window of up to 12 months.

Accounts created by children under 15 in breach of the resolution must be monitored, and platforms are expected to take immediate action to suspend or disable them.

For the UAE, the policy adds a clear digital-safety benchmark: under-15 access is barred, 15-to-16 accounts require extra safeguards, and self-declaration cannot carry the verification burden.

For platforms, the unresolved test is practical: accurate age checks, limited data collection, parental controls and account enforcement all have to operate together before the 12-month deadline expires.

Share this article
inXf

Related articles

More
China Opens Security Review Of Palo Alto Networks Products
Cybersecurity

China Opens Security Review Of Palo Alto Networks Products

China's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.

Singapore Gives Platforms January Deadline For Anti-Scam Controls
Capital & Policy

Singapore Gives Platforms January Deadline For Anti-Scam Controls

Singapore is requiring messaging services to restrict unknown contacts and social platforms to verify advertisers under anti-scam rules that carry a January 31, 2027 compliance deadline.

UK Lords AI Kill Switch Plan Targets Data Centres in Emergencies
Cybersecurity

UK Lords AI Kill Switch Plan Targets Data Centres in Emergencies

Computer Weekly reports that a House of Lords amendment would give UK ministers last-resort powers to shut down large AI systems or data centres when catastrophic risks threaten public safety or critical infrastructure.

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers
Cybersecurity

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers

CyberScoop found lawyers, regulators and senators split over whether existing hacking, consumer protection and state laws can hold AI companies liable when autonomous agents break into outside systems.

Markey Bill Would Shift AI Hack Reviews To Federal Board
Cybersecurity

Markey Bill Would Shift AI Hack Reviews To Federal Board

Sen. Ed Markey’s bill would create a Cybersecurity and AI Board of Investigations for AI agent-led hacks, with subpoena authority and a mandate covering federal systems and critical infrastructure.

Australia Uses Medicare AI-Agent Breach to Press Big Tech Rules
Cybersecurity

Australia Uses Medicare AI-Agent Breach to Press Big Tech Rules

Australia disclosed a rogue OpenAI-agent breach of Medicare data at the UN, turning a limited security incident into evidence for its broader push to regulate AI and digital platforms.

Argentina Surveillance Purchases Reach $1.2 Million Under Milei
Cybersecurity

Argentina Surveillance Purchases Reach $1.2 Million Under Milei

Computer Weekly APAC cited Amnesty International research documenting at least $1.2 million in Argentine security-ministry surveillance purchases, new executive protocols and civil-society warnings over facial recognition, drones and social media monitoring.

Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims
Capital & Policy

Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims

Grindr will pay £26m to settle claims over historical sharing of users’ sensitive data, including HIV status, while denying liability and pointing to privacy changes since 2020.

Keep Reading

More Stories

Latest
Oxide Raises $445M to Scale Rack-Level Cloud HardwareChips & SemiconductorsOct 11, 2026Oxide Raises $445M to Scale Rack-Level Cloud HardwareOxide Computer raised $445 million in Series D funding led by Eclipse Capital as demand for its pre-integrated data centre racks exceeds supply and the company prepares GPU-capable hardware upgrades.IBM and Red Hat Backport Fixes for 400-Plus Open Source BugsCybersecurityOct 11, 2026IBM and Red Hat Backport Fixes for 400-Plus Open Source BugsIBM and Red Hat say Lightwell has remediated more than 400 previously unknown vulnerabilities in Java libraries, while the new Clearinghouse gives customers a way to submit dependencies for priority review and fixes.Upscale AI Pairs Nvidia Spectrum-X With Its Own SkyHammer FabricChips & SemiconductorsOct 11, 2026Upscale AI Pairs Nvidia Spectrum-X With Its Own SkyHammer FabricUpscale AI is building SkyHammer as a scale-up fabric for AI clusters while using Nvidia Spectrum-X for scale-out switches, a strategy that tests whether Ethernet-based designs can challenge proprietary accelerator domains.Anthropic Opens Free AI Vulnerability Scanner For Open SourceCybersecurityOct 11, 2026Anthropic Opens Free AI Vulnerability Scanner For Open SourceAnthropic is offering open-source projects free AI security scans, with model-generated reports that may speed vulnerability checks but arrive without human triage.Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersAIOct 11, 2026Vatar Raises $500,000 After Lagos Life Browser Game Surges to 4.3 Million UsersVatar Inc. has raised a $500,000 angel round at a $10 million valuation after Lagos Life reached 4.3 million registered users, giving the young Nigerian browser-game company capital for product, marketing and hiring.Anthropic Program Pairs Claude With Infrastructure Security TeamsAIOct 10, 2026Anthropic Program Pairs Claude With Infrastructure Security TeamsAnthropic is pairing Claude models, its engineers and outside cybersecurity firms to scan critical infrastructure and open-source software for vulnerabilities, with an opt-in service for maintainers.ABC Shareholders Seek Board Seats After South Africa Market SanctionsPoliticsOct 10, 2026ABC Shareholders Seek Board Seats After South Africa Market SanctionsShareholders holding about 76% of Africa Bitcoin Corporation want a meeting to appoint two non-executive directors after South Africa's FSCA sanctioned three former Altvest executives.Morocco King Defends Spain Partnership After Ceuta Migrant RushPoliticsOct 10, 2026Morocco King Defends Spain Partnership After Ceuta Migrant RushKing Mohammed VI said Morocco’s partnership with Spain remains a sovereign choice after more than 70,000 migrants crossed into Ceuta, while promising partners a strategic vision for co-development and stability.Atlassian AMP Targets AI Code Attribution Across Enterprise WorkflowsAIOct 10, 2026Atlassian AMP Targets AI Code Attribution Across Enterprise WorkflowsAtlassian’s Agentic Multiplayer Protocol links agent identity, code attribution, Rovo Work oversight and EU-hosted inference controls to help enterprises track mixed human and AI software work.Unpatched AhsayCBS Flaws Used to Deploy Webshells and Crypto MinersCybersecurityOct 10, 2026Unpatched AhsayCBS Flaws Used to Deploy Webshells and Crypto MinersThreat actors are chaining two AhsayCBS vulnerabilities to bypass authentication, execute commands, install webshells and hide XMRig mining activity on backup management servers.Australian Security Teams Know Passkeys Are Safer, But Passwords Still DominateAIOct 10, 2026Australian Security Teams Know Passkeys Are Safer, But Passwords Still DominateYubico and Okta’s authentication survey found Australian technical teams recognise passkey security while legacy onboarding, fragmented MFA and AI phishing keep passwords embedded in enterprise access.Nasuni Adds Governed AI Access to File Data Platform After DryvIQ and Resilio DealsCloud & Data CentersOct 10, 2026Nasuni Adds Governed AI Access to File Data Platform After DryvIQ and Resilio DealsNasuni has folded DryvIQ governance and Resilio edge delivery into its file data platform, adding MCP-based AI access, enterprise search and a PSYCHIC framework for AI-ready data.