On July 30, 2026, an advisory panel at Japan's Children and Families Agency (CFA) published an interim report on child online safety. It proposes penalties for social media operators whose safeguards for children are judged inadequate. It also asks platforms to assess risks such as sexual offences and consumer scams, and to verify age by means that do not rely only on self-declaration. The My Number Card is named as one option. Algorithmic recommendation and infinite scroll are flagged as features that can raise risk. A final report is due by the end of 2026, with legislative revisions expected in the 2027 Diet session.
The direction is better than the alternatives now spreading abroad. The identity-based age-check mechanism is where it could go wrong.
The strongest case for the panel
The case for acting is real. Japan's core statute, the Act on Establishment of Enhanced Environment for Youth's Safe and Secure Internet Use (Act No. 79 of 2008), is catalogued by the government's law translation service. Its centre of gravity is filtering, and commentators describe it as a 2008-era design. Nippon.com's analysis notes that carrier filters block only specified sites by default, that parents can easily switch them off, and that social media platforms face "no legal obligation" to protect children from harmful content.
The harms are also documented. A June 2024 ministry survey cited by Nippon.com found 46% of young people had experienced internet-related difficulties. The same piece reports that a 2023 survey found about 70% of 10-to-19-year-olds use TikTok and about 95% use Line. The harms it lists include intimate-image exploitation, grooming, and recruitment into "shady part-time work" scams. A regime that regulates the handset filter but not the platform that delivers the harm has a real gap.
What the panel gets right
First, it does not default to a ban. The panel said it will keep discussing blanket age restrictions, given views that online spaces can be an important place of belonging for some children. Japan Today reported an earlier panel view that a blanket age-based ban, as seen in other countries, may not be appropriate. That restraint matters. Australia's under-16 restriction, described by Nippon.com as carrying fines of up to A$50 million, shifts the question from "is this service safe?" to "is this child allowed?" It also pushes teenagers toward unregulated corners of the internet.
Second, the risk-assessment duty is a process obligation. A platform must identify foreseeable harms to minors, mitigate them and be able to show its work. That is proportionate because it scales with the service: a small forum and a global video platform face different risk profiles and different mitigation costs. It also rewards the safety-by-design engineering that already exists.
Third, naming design features is more evidence-friendly than naming content. Infinite scroll and recommendation engines are choices a company makes. Regulating them does not require officials to decide which speech is acceptable, which keeps the framework consistent with a pro-speech position. The caveat is that the evidence linking these features to harm is still contested. The final report should say what evidence supports each feature it targets, and should require that any restriction be narrowly scoped to minors' accounts.
Where the risk sits
The first risk is age assurance. The interim report asks for checks that go beyond self-declaration and names the My Number Card as one option. The words "one option" are doing important work. If the card becomes the practical default, every adult who wants to read or post on a social platform may have to link a government identifier to their online activity. Commenters cited by Japan Today raised exactly this point, noting that reliable age checks tend to require government ID and could drive broader digital-ID requirements.
A proportionate design would have four features:
- Method neutrality. Platforms may choose among privacy-preserving methods, such as on-device age estimation, tokenised over-18 attestations, or carrier-based signals, and are not steered to a single national ID.
- Data minimisation. The verifier learns only "over or under threshold," and the platform never receives the identity document. Nothing is retained.
- No identity linkage. Age proof cannot be used to build a cross-service profile.
- A fallback for people without the card. Exclusion from lawful speech should not be the price of not carrying a particular ID.
The second risk is the penalty design. The report says penalties should be considered if measures are found insufficient. "Insufficient" is a standard that regulators can stretch. Penalties should attach to a failure to run and act on a documented assessment, not to any bad outcome that occurs on a platform. Otherwise companies will over-restrict content and features for everyone, which harms the young people the rule is meant to serve, including those for whom online communities are a lifeline.
The third risk is timing and detail. The report is interim, and the final report is not due until the end of 2026. Legislative text in the 2027 Diet session will decide how these ideas are defined. Definitions of the covered service, the size threshold for obligations, and the regulator's power to fine are all still open.
What to watch
The practical test comes in the final report. Does it keep age assurance method-neutral, or does it tilt toward the My Number Card? Does it tie penalties to process failures? Does it exempt small services from the heaviest duties? Japan has room to build something more measured than either a blanket ban or a filtering regime designed in 2008. It will only get there if its safeguards for children do not turn into an identity requirement for everyone.