Roblox has long positioned itself as a family-friendly gaming platform, but a damning assessment from Australia’s eSafety Commissioner is forcing the company to confront serious questions about how well it actually protects its youngest users. Despite rolling out a round of safety updates last fall, the platform is still leaving children exposed to adult strangers in ways that should alarm every parent whose kid logs on.
What Regulators Actually Found When They Tested the Platform
Australia’s eSafety Commissioner, Julie Inman Grant, confirmed this week that her agency conducted hands-on testing of Roblox earlier this year after suspecting the company was not doing enough to prevent child exploitation. The results were troubling. Adult strangers could still send connection requests directly to children with no parental notification triggered whatsoever. Even more concerning, children’s profiles remained publicly visible to anyone on the platform, exposing account names, avatar images, listed interests, and the full names and numbers of their existing connections.
That last detail is particularly alarming. A bad actor who connects with one child can immediately browse that child’s visible contact list and identify additional targets. It essentially turns Roblox’s social graph into a roadmap for grooming. No privacy toggle existed to let families restrict this information from public view. For a platform with an estimated 88 million daily active users, the majority of whom are under 17, that is a significant systemic failure.
Why This Keeps Happening Across Gaming Platforms
Roblox is not alone in struggling with child safety, but its scale makes the stakes unusually high. The platform’s user-generated model means millions of virtual spaces exist with varying levels of moderation. Research from child safety organizations consistently shows that online predators gravitate toward platforms with large youth audiences and weak social controls, because those features make initial contact easy and low-risk.
The broader gaming industry has faced mounting regulatory pressure across the United States, United Kingdom, and European Union to build stronger protections directly into platform architecture rather than relying on reactive moderation. Default privacy settings, not optional ones, are increasingly seen as the baseline standard regulators expect. When a company treats child safety as an opt-in feature rather than a default, it creates exactly the kind of gap that eSafety’s testing exposed.
What Parents and Buyers Should Know Before Their Kids Play
For families considering gaming platforms or connected devices for children, this situation is a critical reminder that a brand’s reputation for being kid-friendly does not automatically mean its safety infrastructure is robust. Before allowing a child on any social or gaming platform, parents should verify what information is publicly visible by default, whether connection requests require parental approval, and how quickly the platform responds to regulatory findings.
When investing in tech products or subscriptions for younger users, child safety features should weigh as heavily as price or content quality. Platforms that respond slowly to regulatory findings or treat privacy as optional are a meaningful red flag for any family making a purchasing decision in the connected gaming space.
