Roblox Agrees to Court-Enforceable Safety Overhaul After Australian Tests Expose Contact Loopholes
Despite rolling out age verification and account tiers globally, the platform still allowed adults to reach children without parental consent, eSafety testing revealed.

The Gap Between Policy and Practice
Roblox has entered into a legally binding agreement with Australia's eSafety commission to implement sweeping child protection measures after regulatory testing uncovered persistent vulnerabilities in its platform. The commitment comes despite the gaming company having introduced age verification systems and tiered account structures over the past nine months.
The core issue: adults could still initiate contact with Australian children without parental oversight, according to eSafety's investigation. Tests conducted by the regulator demonstrated that connection requests from adult users to minors remained possible, and that both age groups could interact freely on community forums. Equally concerning, any user could view the profiles, biographies, avatar images, and friend lists of underage accounts, with no mechanism to limit this visibility.
At DailyTechWire, we've tracked the widening gap between platform commitments and enforcement capabilities across social and gaming environments. Roblox's case illustrates a pattern familiar in Asia-Pacific markets: technical controls that look robust on paper but contain implementation flaws that persist through multiple product cycles.
A Timeline of Incomplete Fixes
Roblox introduced mandatory age verification in Australia in late 2025, making it the first market to face the requirement. The rollout encountered immediate friction when users found ways to circumvent the age-check mechanism. The company defended its verification technology publicly, but eSafety's subsequent testing suggests theControversySafeguards proved insufficient in practice.
By early 2026, Roblox had extended age verification to the United States for chat functionality. In May, the platform segmented its user base into three tiers: Kids accounts with access only to Minimal or Mild content and chat disabled by default; Select accounts with moderate permissions; and standard Roblox accounts with broader access. This tier system reached global availability in June.
Yet eSafety's tests, conducted after these measures went live, revealed that the architectural changes had not closed the contact pathways the regulator considered most dangerous. The commission noted that Roblox "believes it is meeting its obligations" under Australia's Online Safety Act, a phrasing that suggests disagreement over interpretation rather than outright non-compliance.
What the Undertaking Requires
Under the court-enforceable agreement, Roblox must deliver four categories of change within three months. First, it must implement technical controls that prevent adults from contacting children they do not know without explicit parental consent. This goes beyond opt-in settings, requiring a default-deny architecture.
Second, children's accounts must be private by default. Profile information, connection lists, and activity data that were previously visible to all users will need to be locked down unless a parent actively chooses to make them public.
Third, the platform must provide accessible and clearly signposted reporting mechanisms. The implication here is that existing reporting flows were either hard to find or inadequately surfaced to younger users.
Fourth, Roblox must engage a third-party auditor to assess the effectiveness of its safety measures on an ongoing basis. This external validation layer is designed to address the disconnect eSafety observed between stated policy and actual behavior in the live environment.
If Roblox fails to meet the three-month deadline, eSafety can petition the court to compel compliance. The undertaking carries legal weight that voluntary commitments do not.
The US Parallel: Settlements and State Pressure
Roblox's Australian troubles sit alongside mounting pressure in the United States. In May, the company agreed to pay Nevada $12 million to settle allegations related to child safety. As part of that settlement, Roblox committed to a verification system requiring government-issued ID submission and facial age estimation. Notably, users need complete only one of those two methods, not both, a design choice that may leave room for evasion.
The Nevada settlement also included a promise to block users under 16 from messaging adults unless those adults are designated "trusted friends" via QR code assignment. This trusted-friend model mirrors features in other platforms but depends heavily on parents understanding and actively using the QR mechanism.
Several other US states have filed lawsuits against Roblox, and the regulatory drumbeat is intensifying. The platform's business model, built on user-generated content and social interaction, makes it particularly sensitive to any constraint that reduces engagement. Child safety measures that limit messaging, friend requests, or profile visibility risk dampening the network effects that drive retention and monetization.
Why Age Verification Alone Isn't Enough
The eSafety findings underscore a broader lesson for platforms operating across Asia-Pacific and Western markets: age verification is a necessary but insufficient control. Knowing a user's age does not, by itself, prevent harmful contact. It only enables segmentation.
Effective child protection requires layered defenses: default-private profiles, algorithmic detection of grooming patterns, friction in adult-child messaging flows, rapid takedown processes, and transparent reporting channels. Verification serves as the foundation, but the protective structure must be built on top of it.
Roblox's experience also highlights the challenge of retrofitting safety into platforms designed for open social interaction. The company has more than 70 million daily active users, many of whom are children. Any change to messaging, friending, or profile visibility affects core engagement metrics. Balancing safety and growth is not a technical problem alone; it is a business-model tension that regulators are increasingly unwilling to tolerate.
What Happens Next
Roblox now has until late November to demonstrate compliance with the eSafety undertaking. The three-month window is tight for a platform of its scale, particularly given the need to implement default-private settings retroactively for millions of existing child accounts and to build out parental consent workflows that do not yet exist in their required form.
The third-party audit requirement will be watched closely by regulators in other jurisdictions. If Australia succeeds in establishing an ongoing external validation model, it may become a template for enforcement elsewhere. Singapore, South Korea, and the European Union have all signaled interest in stronger platform accountability mechanisms, and the audit-plus-undertaking structure offers a middle path between self-regulation and prescriptive legislation.
For Roblox, the path forward involves not just meeting the Australian deadline but demonstrating to regulators worldwide that its platform can sustain child safety at scale without constant external pressure. The company's ability to do so will shape not only its own regulatory risk but also the expectations applied to user-generated gaming platforms across the region.


