The Australian eSafety Commissioner has identified “significant gaps” in the child safety protocols of some of the world’s largest gaming platforms, warning that technical failures are leaving minors exposed to grooming, extremist propaganda, and simulated sexual abuse material. In a transparency report titled “Playing it safe: how online game services are (or are not) keeping kids safe online” released October 2, 2026, the regulator singled out Valve’s Steam platform for failing to implement industry-standard detection tools used by its peers.
The findings are the result of legal transparency notices issued to Valve, Roblox, Epic Games (Fortnite), and Microsoft (Minecraft). According to the eSafety Commissioner, the investigation revealed that while gaming platforms have evolved into massive social ecosystems, their safety infrastructure has not kept pace with the risks posed by predators and extremist groups.

Technical Failures and the Steam Outlier
A primary concern highlighted in the report is the lack of proactive moderation tools on Steam. Valve was found to be the only major provider examined that does not use “hash-matching” technology—a standard automated system that identifies known child exploitation material and extremist content by comparing file signatures against databases of reported illegal imagery. While competitors like Roblox and Microsoft employ these tools to intercept harmful content before it is viewed, Steam relies heavily on user reports after the fact.
The regulator also noted that Valve could not provide specific data on how often its users are targeted for grooming or how many reports of child sexual abuse material (CSAM) it receives annually. This lack of data visibility is a critical friction point for Australian authorities, who argue that without proactive chat moderation, gaming platforms effectively serve as unmonitored “digital playgrounds” for bad actors.
Roblox and the Court-Enforced Mandate
While Roblox has implemented more robust technical filters than Steam, the platform remains under intense regulatory pressure in Australia. In August 2026, Roblox entered into a court-enforced undertaking following concerns about the ease with which adult users could contact children. Under this legal mandate, Roblox is required to make child accounts private by default and restrict the ability of unknown adults to message minors without explicit parental consent.
The eSafety report found that despite these measures, gaming platforms broadly struggle with “high-risk” user-generated content. Investigators identified instances of users creating digital recreations of real-world mass shootings, sharing terrorist propaganda, and hosting simulations of sexual activity involving children within these virtual worlds. These “experience-based” harms are often more difficult for traditional text-based filters to catch.
Age Verification and Regulatory Fines
The report also criticized the reliance on “self-declaration” for age verification on platforms like Fortnite and Minecraft. By allowing users to simply type in a birth date, the platforms permit minors to bypass safety settings intended for children and access high-risk features designed for adults. This practice is coming under increased scrutiny as the Australian government consults on a new “Digital Duty of Care” bill, which seeks to place more legal responsibility on platforms to prove they are actively protecting their youngest users.
The financial stakes for non-compliance are substantial. Under the existing Online Safety Act, companies that fail to provide adequate information or meet safety transparency requirements can face fines of up to AUD $825,000 per day. The eSafety Commissioner indicated that these transparency reports are a precursor to stricter enforcement, signaling that the era of self-regulation for the gaming industry is effectively over in the Australian market.