Governance structures designed to prevent digital harm often serve more as records of accountability than as mechanisms to ensure it. Multiple layers of oversight, platform policy, terms of service, and regulatory frameworks can each show compliance, yet together they often leave the person harmed with no clear way to seek remedy. The presence of a safety mechanism and its ability to actually protect are not the same thing. When accountability is spread across layers that do not communicate, no single layer is responsible for the results.
The Design Problem
This pattern appears across harm types and geographies. Parental control tools that report message volumes but tell parents nothing about risk. Disclosure systems that respond to a child’s report by confiscating the device. Platform moderation frameworks that can demonstrate compliance with their own standards while the harm they were designed to address continues. In each case the system is functioning as designed. The design, however, is not oriented toward the person it was built to protect.
Evidence of safety is what a system can point to: reports filed, content removed, policies published, audits passed. It is measurable, documentable, and institutionally legible. What it does not measure is whether the person the system was built for is actually safer. A system oriented toward producing that evidence serves the organisation that needs to demonstrate compliance, not the person who needs to be protected.
The Accountability Gap
When each layer of governance can point to its own compliance, the person harmed has no one to hold accountable. The architecture produces responsibility without ownership. Safety that serves the institution’s accountability needs before the end user’s actual needs has the relationship backwards. Remedy needs to be built into the governance architecture as a required outcome, not left to individuals to pursue through litigation after the system has already failed them.
Where Responses Concentrate
Safety resources, policy attention, and educational campaigns tend to concentrate at the level where harm is most visible and legible to institutions, not where it originates. A system that works for its assumed user while failing everyone else is not a generally effective safety system. It is a safety system for the specific kind of person it was designed for.
The Core Finding
Safety systems that measure process rather than outcome risk producing evidence of safety without producing safety itself.
This article is adapted from SHIELD’s 2026 Conference Reference Document from the SHIELD Global Online Safety Conference. The reference document synthesizes themes, insights, areas of agreement, tensions, and open questions that emerged during the event.
Download the full document here