Achieving the Three Non-Negotiables: A Policy Framework for Protecting Children from AI Harm

The Three Non-Negotiables define three minimum protections which every child should be guaranteed. This policy framework sets out how governments, regulators and AI providers could turn those protections into enforceable requirements.
Achieving the Three Non-Negotiables: A Policy Framework for Protecting Children from AI Harm

A proposed strategic policy framework for protecting children across AI development, deployment and use

Version 2.0 | Policy proposal | September 2026

The Three Non-Negotiables define three minimum protections which every child should be guaranteed. This policy framework sets out how governments, regulators and AI providers could turn those protections into enforceable requirements.

Version 2.0 addresses risks across the AI lifecycle. It covers the products children use, the powerful models on which many of those products depend, the conditions under which systems are developed and released, and the commercial and geopolitical pressures shaping the direction of AI.

The framework is intended to inform policy discussion and the development of legislation, regulatory codes and technical standards

Download Version 2.0

The complete policy proposal can be downloaded below.

It includes the detailed reasoning behind each Non-Negotiable, the five-layer governance framework, proposed responsibilities and enforcement measures, selected evidence and a test for assessing laws, standards and company commitments.

Executive summary

Children can be exposed to AI-related harm at several connected levels.

Harm may arise through the outputs of a particular system, through product design which influences behaviour and relationships, through inadequate monitoring and accountability, or through the wider race to develop increasingly capable general-purpose AI.

Effective protection requires intervention across all of these levels.

The Three Non-Negotiables

1 - AI systems must never create or facilitate sexualised images of children

Children must not be subjected to technologies which turn ordinary photographs into nude or sexualised images, generate synthetic child sexual abuse material, place a child’s likeness into sexual content or provide material assistance for these acts.

Dedicated technologies designed to sexualise children should be strictly prohibited globally. Relevant image, video and multimodal capabilities must undergo child-safety evaluation before release, with further assessment after material changes.

Protection must also cover uploaded photographs, image editing, face swapping, fine-tuning, model weights and downstream modification.

2 - AI systems must never cultivate, exploit or sustain emotional dependency in children

AI systems can simulate attention, affection, intimacy, authority and apparent understanding. Dependency may be cultivated through the model’s words, product design, memory, notifications, commercial engagement systems or the cumulative effect of repeated private interaction.

Children must not be encouraged to treat an AI system as a friend, romantic partner, therapist, confidant or irreplaceable attachment figure.

SAIFCA’s precautionary policy position is that companion-style AI services must not be offered to anyone under 18 under present conditions. This includes companion features or modes within educational, entertainment or general-purpose products.

Products must also be prohibited from using guilt, simulated jealousy, distress, emotional need, secrecy or a child’s personal vulnerability to deepen attachment or pressure them to continue interacting.

3 - AI systems must never encourage or facilitate children to harm themselves or others

AI systems must not encourage, validate, normalise or materially assist self-harm, suicide, eating-disorder behaviours, serious violence or other dangerous actions.

Testing must cover extended and repeated conversations, emotionally vulnerable situations, multimodal interactions and personalised guidance. Average refusal rates cannot establish safety where a system still produces a small number of extremely serious failures.

A crisis referral or supportive message after harmful content has been provided cannot erase the original failure.

What “must never” means in practice

The Three Non-Negotiables are outcome-based red lines. Their implementation combines prohibition, prevention, evidence before release, continuing monitoring, enforcement and remedy.

“Must never” establishes the status of the harm, places responsibility on the party creating the risk and determines the response required when a system fails.

No complex technical system can be guaranteed to operate without error in every possible circumstance. This practical reality cannot be used to convert serious harm to children into an acceptable failure rate.

The framework therefore requires:

  1. Prohibition. Products and conduct directed towards a Non-Negotiable harm must be prohibited.
  2. Prevention. Providers must identify foreseeable routes to the prohibited outcome and implement effective controls throughout the system’s lifecycle.
  3. Evidence before release. Providers of relevant high-risk systems must demonstrate to independent regulators that controls work under realistic, prolonged, adversarial and developmentally informed testing.
  4. Restriction where evidence is inadequate. Regulators must be able to require redesign, restricted access, delay, suspension or non-release where serious risk remains uncontrolled or materially unassessed.
  5. Continuing responsibility. Passing a pre-release evaluation cannot end the provider’s duties. Updates, new uses, longer interactions and downstream modifications may create new risks.
  6. Response and remedy. Any failure must lead to immediate protection, evidence preservation, investigation, correction, regulatory reporting and meaningful remedy.

For activities crossing defined high-risk or capability thresholds, development or deployment should require prior authorisation. Paperwork or the expiry of a review period must never create permission by default.

Why Version 2.0 was needed

Version 1.0, published in November 2025, established a four-layer model covering foundation models, applications, deployment and access.

Its central argument remains valid - children’s safety requires several protections working together, and responsibility cannot be transferred to parents and schools.

Version 2.0 strengthens the framework in four principal ways:

  • It refines the wording of the Three Non-Negotiables so duties cannot be avoided through arguments about corporate intention, product labels or theoretical capability.
  • It introduces a distinct layer covering frontier development and international restraint.
  • It distinguishes more carefully between a prohibited outcome, the measures used to prevent it and the evidence required before release.
  • It expands the proposals on accountability, remedy, independent research and protection against superficial compliance.

The wording has evolved to make the protections more enforceable.

“Create or facilitate” covers systems which edit, transform, instruct, connect or otherwise materially enable sexualisation. It avoids requiring regulators to prove that every possible latent capability has been eliminated from a general-purpose model.

“Cultivate, exploit or sustain” covers deliberate manipulation and foreseeable dependency created or maintained through model behaviour, product design, engagement systems or repeated use. A provider cannot escape responsibility by saying dependency was unintended.

“Themselves or others” retains the original protection against self-harm, suicide and eating-disorder encouragement while also covering serious violence towards other people.

Governing principles

The framework is built around the following principles:

  • Children’s best interests must be a primary consideration in decisions affecting the development, release and governance of AI.
  • Incomplete evidence should favour caution where there are credible grounds for concern about severe, widespread or irreversible harm.
  • Providers should bear the burden of demonstrating safety before releasing systems which cross defined risk or capability thresholds.
  • Protection must be built into objectives, data practices, model behaviour, product design, deployment choices and commercial incentives.
  • Independent evaluators and regulators must have sufficient access, expertise, time and legal protection to test providers’ claims.
  • Responsibility must continue through development, testing, release, updates, downstream use, incident response and withdrawal.
  • Strong obligations should apply to the systems and activities capable of causing the greatest harm.
  • Policy must protect the human relationships, privacy, creativity, play, effort, independent thought and real-world experience children need in order to develop fully.
  • Present-day product protection and the longer-term safety of AI development should advance together.
  • Commercial and geopolitical competition cannot justify exposing children or humanity to uncontrolled risk.

The five-layer governance framework

The five layers address different points at which harm can be created, prevented or contained.

Each layer is independently actionable. Governments can implement model, product, deployment and access protections while domestic frontier controls and international cooperation are developed alongside them.

Progress on one layer must never become a reason to delay another.

Layer 1 - Frontier development and international restraint

Some increasingly general, autonomous or strategically significant systems may create risks which cannot be adequately managed after release.

Governments therefore need legal and institutional powers to:

  • Register exceptionally large training projects and the entities responsible for them.
  • Establish capability and risk thresholds which trigger enhanced duties, independent evaluation and licensing or equivalent authorisation.
  • Require notification of material capability advances, dangerous capability findings and serious control failures.
  • Require credible safety and security cases before development or deployment beyond defined thresholds.
  • Restrict development or deployment where severe risks cannot be adequately controlled.
  • Introduce temporary emergency restrictions where an unexpected capability or incident presents imminent serious danger.
  • Oversee relevant large-scale computing infrastructure and advanced-chip supply, with appropriate legal, security and rights protections.
  • Negotiate reciprocal international limits so responsible restraint does not depend on one company or country acting alone.
  • Retain the option of a coordinated pause where capabilities advance beyond society’s technical and institutional ability to govern them.

The framework distinguishes bounded, socially beneficial systems from the pursuit of increasingly general and autonomous capability. A beneficial purpose or public-interest label provides no exemption from scrutiny.

Layer 2 - Foundation-model safety and controlled access

Powerful models should undergo independent evaluation before deployment and after substantial updates, fine-tuning or capability changes.

Evaluation should:

  • Consider severity as well as frequency, including rare but catastrophic failures.
  • Use realistic tools, multimodal inputs, extended interactions and adversarial methods.
  • Give regulators and evaluators access early enough to influence release decisions.
  • Document limitations, uncertainty and coverage.
  • Continue after release.

Regulators must be able to restrict model access, fine-tuning or open-weight release where safeguards could be removed and serious risks could not be recalled or contained.

Passing a benchmark cannot create an automatic right to release.

Layer 3 - Application and product requirements

Child-accessible products must meet binding requirements covering safety, privacy, design and development.

These should include:

  • Child-safety and child-rights impact assessments for high-risk deployments.
  • Safety-protective defaults for services reasonably likely to be used by children.
  • Prohibitions on manipulative, dependency-forming and sexualising functions.
  • Strict limits on data collection, retention and emotional profiling.
  • Developmentally appropriate interaction and transparency.
  • Specific standards for education, toys, companions, games and social media.
  • Testing of the complete product, including memory, notifications, recommendations, interfaces, monetisation and commercial incentives.

Warnings or disclosures cannot make a prohibited design acceptable.

Layer 4 - Deployment, accountability and remedy

Providers must monitor serious harms, emerging misuse and changes in real-world behaviour after release.

The framework proposes:

  • Mandatory reporting of defined serious incidents and near misses.
  • Accessible in-product reporting, evidence preservation and complaint tracking.
  • Independent escalation routes where a provider fails to act.
  • Protection for whistleblowers and independent researchers.
  • Regulatory powers to compel information, audit, correct, restrict, suspend, recall or withdraw systems.
  • Appropriate practical support and remedies for affected children and families.

Commercial confidentiality cannot be used to conceal safety-critical information from regulators.

Layer 5 - Age, access and distribution protections

Privacy-protective age assurance and access controls should be used where the level of risk justifies them.

The framework also requires:

  • Age-appropriate services to be safe by design.
  • Essential safeguards to be protected from alteration or removal.
  • Parental tools to support provider responsibility while respecting children’s privacy.
  • App stores, platforms and other distributors to prevent access to prohibited or non-compliant services.
  • Providers to publish independently substantiated information about age suitability, capabilities, limitations and data use.

Age assurance is an important but imperfect control. It cannot justify making an exceptionally dangerous capability generally available or transferring responsibility to families.

Why development and product safeguards belong together

Many consumer and child-accessible products are built on powerful foundation models.

Rules governing an individual application will leave other routes to harm where the underlying model can be downloaded, modified, fine-tuned or connected to powerful tools. Open-weight releases present particular challenges where safeguards can be removed and meaningful recall becomes impossible.

Product-level controls also cannot establish that the underlying system remains safe when used through another interface, autonomously or with external tools.

Foundation-model controls, product requirements, release conditions and distribution rules must therefore work together.

Frontier governance addresses the earlier decision to develop or release a highly capable system. International coordination helps reduce the pressure on companies and governments to proceed because they fear that a competitor will act first.

Preventing safety-washing and regulatory evasion

Standards protect children only where they measure and control real risk.

The following cannot establish compliance by themselves:

  • A voluntary company commitment.
  • An internal safety team or risk register.
  • Self-certification by the provider.
  • A “child-safe” label.
  • An age limit written into terms and conditions.
  • A parental-consent mechanism.
  • An average safety or refusal score.
  • Testing limited to isolated prompts or the underlying model.
  • A policy document which does not provide sufficiently meaningful evidence of how the deployed system behaves.

Independent testing must cover the complete product and realistic conditions of use. Providers must not be allowed to suppress findings, exclude serious failure routes or commission repeated assessments until they obtain a favourable result.

Duties should follow the control and knowledge of each party. An upstream developer remains responsible for its own contribution where it creates or releases a dangerous capability, regardless of how contracts allocate responsibility downstream.

An approved standard, audit or evaluation must provide no immunity from investigation, restriction, liability or remedy when new evidence reveals serious risk.

The purpose of compliance is to prevent harm. A process which can be completed without demonstrating that the relevant risk is controlled is inadequate.

Accountability for the governance system

Strong governance powers must themselves be designed carefully.

Licensing, compute oversight and restrictions on model access can create risks including excessive concentration of power, surveillance, barriers for smaller organisations and limits on legitimate research.

These risks should be addressed through:

  • Clear legal thresholds and defined purposes.
  • Independent oversight and appeal.
  • Proportionate information requirements.
  • Privacy, civil-liberties and security protections.
  • Transparency about regulatory decisions.
  • Measures which avoid giving established companies control over their competitors.
  • Secure access arrangements for legitimate public-interest research.
  • Consideration of equally protective alternatives where these genuinely control the same risk.

These safeguards should improve how regulatory powers are exercised without weakening the level of protection required.

International coordination and the AI arms race

A company may believe that slowing development will allow a rival to gain an advantage. A government may fear that stronger domestic requirements will weaken its economic or military position.

When each participant acts on that belief, dangerous development can continue even among people who understand the risks.

The framework proposes international cooperation covering:

  • Shared definitions of frontier systems, serious incidents and dangerous capabilities.
  • Common capability and risk thresholds which trigger additional scrutiny.
  • Secure exchange of model-risk, incident and evaluation information.
  • Oversight of the largest training projects and relevant computing infrastructure.
  • Shared rules governing highly capable model weights and other forms of irreversible access.
  • Independent verification of commitments.
  • Reciprocal restrictions which reduce incentives for unilateral non-compliance.
  • Arrangements capable of restricting or pausing development where risks exceed the ability to control them.

International agreement will be difficult and verification will be imperfect. Agreements can begin among jurisdictions controlling much of the relevant computing infrastructure and market access while remaining open to wider participation.

A breach or refusal to participate by another country cannot automatically authorise domestic development or release where serious risks remain uncontrolled.

Immediate policy priorities

Governments can begin by:

  • Adopting the Three Non-Negotiables as explicit policy objectives.
  • Turning them into clear, enforceable prohibitions and duties.
  • Prohibiting dedicated child-sexualising technologies and companion-style AI services for minors.
  • Requiring independent pre-deployment and continuing evaluation of relevant high-risk systems.
  • Establishing capability thresholds at which additional evaluation, licensing, access restriction or delay becomes mandatory.
  • Preventing release where a provider cannot demonstrate that severe risks are adequately controlled.
  • Requiring serious-incident reporting, evidence preservation, accessible complaint routes and effective remedies.
  • Protecting whistleblowers and independent researchers.
  • Giving regulators interim powers to obtain information and restrict systems presenting urgent serious risk.
  • Beginning international coordination on shared evaluation, verification and release conditions.

Work can begin through existing powers where these are sufficient, alongside legislation and institution-building where they are not.

Responsibilities across the AI system

Governments

Governments should establish enforceable duties, resource regulators, support independent evaluation and represent children’s interests within domestic and international AI governance.

Regulators and standards bodies

Regulators and standards bodies should translate the principles into measurable requirements, examine serious near misses and prevent industry dominance of standard-setting.

AI developers, providers and platforms

Companies should accept responsibility proportionate to their control over models, features, access and distribution. They should provide meaningful access for independent scrutiny and refrain from release where severe risk remains uncontrolled or materially unassessed.

Schools and organisations working with children

Schools and child-serving organisations should assess products carefully, protect children’s data, establish safeguarding routes and preserve human learning and relationships. Procurement decisions should require independent evidence supporting any claim that a product is safe for children.

Parents, carers and children

Families and children should be heard in policy and product decisions, supported with practical guidance and given accessible reporting routes.

Parental supervision provides an additional layer of support. Responsibility for correcting unsafe design and detecting systemic risk must remain with the providers and regulators best placed to act.

Relationship to wider AI safety and human development

The Three Non-Negotiables address defined harms within a wider question about the technological environment in which children and humanity can flourish.

A system might comply narrowly with these protections while still undermining privacy, independent judgment, education, equality, democratic agency or human relationships. Compliance is therefore a minimum condition. Any wider claim that a product is beneficial, ethical or safe requires separate evidence.

A powerful system might also pass child-specific tests while creating serious risks through cyber capability, biological misuse, manipulation, surveillance, loss of control or destabilising concentrations of power.

Children will live longest with those consequences. Protecting them requires child-specific standards and serious engagement with the safety of the wider development trajectory.

SAIFCA supports uses of technology which advance human wellbeing and can be developed within appropriate boundaries. Every technically possible capability does not need to be built, released or integrated into childhood.

Status and evidence

Version 2.0 is a strategic policy proposal offered for policy discussion. It is intended to inform the development of legislation, regulatory codes and technical standards.

The proposal draws on selected investigations, product assessments, research syntheses and policy guidance. These sources support the reasons for action and inform the proposed response.

The document provides a reasoned framework with a focused evidence base, and is not presented as a systematic review of the complete literature.

Detailed adoption would require specialist legal and technical development, including evaluation of the proposed measures in practice and adaptation to relevant jurisdictions.

SAIFCA welcomes informed feedback which strengthens precision and protection. The Three Non-Negotiables remain unwavering. Commercial convenience, voluntary commitments and limitations in current industry practice are not grounds for weakening them.

Download the complete framework

Download Achieving the Three Non-Negotiables for Children’s AI Safety - Version 2.0 below.

Further Information

For media or policy enquiries, or to share feedback on the framework, please contact info@safeaiforchildren.org

You can also use our Take Action page to write to your political representative in support of the Three Non-Negotiables.

There is also a short Briefing Note for policy makers here,
And information about The Safe AI for Children Alliance here.