UK Forces Apple and Google to Implement On-Device Nude Image Scanning or Face Criminal Liability
The UK government has given tech giants a 90-day ultimatum to activate device-wide scanning for explicit images on children's phones. Failure to comply could result in legislation, fines, and criminal charges for tech executives.
By Factlen Editorial Team
- Privacy & Encryption Advocates
- Warns that client-side scanning breaks end-to-end encryption and creates a mass surveillance backdoor vulnerable to authoritarian abuse.
- UK Government & Safety Advocates
- Argues that tech companies have a moral duty to implement device-level blocks to stop the proliferation of self-generated explicit content.
- Tech Platform Operators
- Prefers narrow, app-specific safety features rather than compromising the entire operating system's privacy architecture.
What's not represented
- · Teenagers affected by the scanning
- · Global human rights organizations
Why this matters
This mandate forces a historic showdown over the future of digital privacy and end-to-end encryption. If implemented, it would require operating systems to scan every photo taken or received, creating a surveillance infrastructure that privacy advocates warn could be exploited globally.
Key points
- The UK government has given Apple and Google 90 days to implement device-wide nude image scanning on smartphones and tablets.
- The mandate aims to combat a rise in sextortion, noting that 91% of child abuse reports involve self-generated content.
- Privacy advocates warn that the required client-side scanning effectively breaks end-to-end encryption and creates a mass surveillance backdoor.
- Adults will be required to complete an age verification process to opt out of the default scanning infrastructure.
The United Kingdom has dramatically escalated its ongoing battle over digital child safety, issuing a stark and unprecedented ultimatum to the world’s two largest mobile operating system providers. On June 8, 2026, Prime Minister Keir Starmer used a keynote address at London Tech Week to demand that Apple and Google implement device-wide nude image scanning on all smartphones and tablets used by children. The sweeping directive targets the core architecture of iOS and Android, marking one of the most aggressive regulatory interventions into consumer device design to date.[1]
The mandate gives the tech giants a strict 90-day window to activate built-in features that can automatically detect and block the creation, sharing, or viewing of explicit images across their ecosystems. If the companies fail to comply voluntarily by the September deadline, the government has promised to introduce aggressive legislation to force the issue. This rapid timeline sets up a high-stakes standoff between national regulators and Silicon Valley, fundamentally challenging how much control governments can exert over the baseline functionality of personal computing devices.[4]
The stakes of this proposed legislation are virtually unprecedented in the consumer technology sector. Government officials have explicitly stated that 'nothing is off the table' regarding enforcement mechanisms. Beyond massive corporate fines for non-compliance, the Home Office has confirmed that, as a last resort, it is exploring criminal liability for tech executives who refuse to build the requested scanning infrastructure into their operating systems. This threat of personal prosecution represents a severe escalation, designed to force the hand of platform operators who might otherwise absorb financial penalties as a cost of doing business.[1][4]
The Home Office justifies the aggressive timeline by pointing to a sharp rise in online grooming and sextortion cases targeting minors. According to government data released alongside the announcement, 91 percent of online child sexual abuse reports recorded recently contained self-generated content created by the children themselves. Officials argue that tech companies have a moral duty to intervene at the device level before these images can be weaponized by predators or spread across the internet. By stopping the images at the point of creation, the government believes it can sever the supply chain of exploitation.[1]

Both Apple and Google already deploy some child safety features within their respective ecosystems, though they are currently limited in scope. Apple’s 'Communication Safety' feature warns children when they send or receive explicit images across specific apps like Messages and AirDrop, while Google offers 'Sensitive Content Warnings' that blur imagery in its native messaging app. Furthermore, Apple recently began requiring age checks for UK iPhone users, becoming the first major company to activate safety features by default for accounts that are not officially verified as belonging to an adult over the age of 18.[1]
However, the UK government argues these existing measures are fundamentally inadequate because they only cover specific, first-party applications. Currently, nudity detection does not extend to the device's core camera app, the local photo gallery, third-party encrypted messaging services like WhatsApp and Signal, or standard web browsers. The Home Office contends that predators simply route around the protected apps, exploiting these blind spots to continue their abuse. Consequently, the government is demanding a comprehensive block that covers the entire phone, leaving no unmonitored spaces where explicit content can be generated or stored.
To close this gap, the government is demanding a system that operates at the root of the operating system. This requires a mechanism known as 'client-side scanning' (CSS), where an algorithm inspects every photo taken or downloaded directly on the device itself, before it ever interacts with an app or the internet. By scanning locally, the system can theoretically detect prohibited content regardless of which app the user intends to open. This shifts the burden of moderation away from individual app developers and places it squarely on the hardware and operating system providers.[2][3]
To close this gap, the government is demanding a system that operates at the root of the operating system.
This technical requirement has ignited a fierce backlash from privacy advocates and cybersecurity experts. Because the scanning must happen before an image is encrypted and sent, critics argue it effectively bypasses end-to-end encryption entirely. If the operating system itself is inspecting the content of a message before it is mathematically locked, the fundamental promise of secure, private communication is broken, regardless of the robust encryption protocols used by the messaging app. Experts warn that this creates a systemic vulnerability that undermines the security of the entire digital ecosystem.[3][4]

The encrypted messaging app Signal published a scathing response the same day as the announcement, calling the mandate a 'Faustian bargain' that trades fundamental privacy for the illusion of safety. Signal argues that forcing every smartphone to classify private content creates a population-wide mass surveillance infrastructure that cannot be safely contained once it is built. The company has previously threatened to pull its services from the UK entirely rather than compromise its encryption standards, setting the stage for a massive disruption in how millions of British citizens communicate securely.[4]
Security researchers warn of a dangerous 'slippery slope' effect. They argue that once a backdoor is built into iOS and Android to scan for nudity, the underlying architecture becomes a master key for broader surveillance. Authoritarian regimes could easily demand the same client-side scanning tools be repurposed to detect political dissent, protest flyers, or banned literature. Once the capability exists on the device, its application is determined by whoever holds legal authority in a given jurisdiction, making it impossible for tech companies to guarantee the tool will only be used for child safety.[4]
The mandate also introduces significant friction for adult users. Under the proposed rules, adults will only be able to take, share, or view nude content if they successfully complete a formal age verification process. This means the scanning infrastructure will be active by default on every device sold in the country, requiring users to actively opt out by proving their age. The government insists this strikes the right balance, but privacy advocates argue it treats every citizen as a suspect until they surrender their personal data to prove otherwise.[1]
This age assurance requirement means millions of adults would likely need to submit government ID, credit card information, or biometric data to their device manufacturer just to unlock standard camera and gallery functions. This raises secondary concerns about data collection, identity tracking, and the creation of massive databases of verified adult users. Cybersecurity experts warn that these centralized registries of verified identities could themselves become prime targets for hackers and cybercriminals, potentially exposing the exact sensitive information the government claims it wants to protect.[3]

Apple has faced this exact controversy before. In August 2021, the company announced a plan to scan user devices for known child sexual abuse material (CSAM) hashes before they were uploaded to iCloud. However, Apple was forced to abandon the project entirely after a massive outcry from civil liberties groups, cryptographers, and its own employees, who warned it compromised the fundamental security of the iPhone. That retreat demonstrated the immense technical and public relations challenges of implementing client-side scanning, even for a company with Apple's resources.
Now, Apple and Google find themselves caught between a strict legal mandate in a major market and the core privacy promises they make to their global user base. Google has stated it is 'working constructively' with UK partners to find privacy-preserving solutions, while Apple has remained notably silent on the specific ultimatum. Neither company has detailed how they plan to navigate the September deadline, leaving the tech industry guessing whether they will attempt to build the requested tools, challenge the mandate in court, or restrict device features in the UK market.[4]
As the deadline approaches, the tech industry is watching closely. If the UK successfully forces the implementation of device-wide client-side scanning, it will set a global precedent that reaches far beyond British borders. Other nations are already observing the standoff, and a victory for the Home Office could trigger a cascade of similar demands worldwide. Ultimately, the resolution of this conflict will fundamentally alter the boundary between personal privacy and device-level surveillance, reshaping the security architecture of smartphones for billions of users across the globe.[3][4]
How we got here
August 2021
Apple announces a plan to scan user devices for CSAM hashes, but later abandons it due to severe privacy backlash.
October 2023
The UK passes the Online Safety Act, setting the stage for stricter regulation of digital platforms and messaging services.
June 8, 2026
Prime Minister Keir Starmer issues a 90-day ultimatum to Apple and Google to implement device-wide nude image scanning.
September 2026
The deadline for tech companies to comply voluntarily before the UK government introduces enforcement legislation.
Viewpoints in depth
The UK Government's View
Device-level scanning is the only way to protect children from the rising threat of sextortion.
The Home Office and child safety advocates argue that the current app-by-app approach to moderation has failed, leaving massive blind spots in the camera and photo gallery. Because 91% of online child sexual abuse reports now involve self-generated content, they believe tech companies have a moral obligation to stop these images at the point of creation. They maintain that this is not a privacy violation, but a necessary safeguard that adults can easily bypass through age verification.
Privacy Advocates' View
Client-side scanning breaks end-to-end encryption and creates a dangerous mass surveillance tool.
Cybersecurity experts, civil liberties groups, and encrypted messaging providers like Signal view the mandate as a catastrophic threat to digital privacy. They argue that scanning a file before it is encrypted fundamentally nullifies the security of end-to-end encryption. Furthermore, they warn that building a backdoor for nudity detection creates a population-wide surveillance infrastructure that authoritarian regimes will inevitably co-opt to scan for political dissent or banned literature.
The Tech Industry's View
Platform operators prefer narrow, opt-in safety features that do not compromise the entire operating system.
Companies like Apple and Google find themselves caught between strict national regulations and their global privacy commitments. They generally prefer implementing safety features that are limited to specific, first-party apps—such as blurring explicit images in native messaging apps—rather than building root-level scanners that inspect every file on the device. The threat of criminal liability for executives, however, significantly raises the stakes of their typical resistance to such mandates.
What we don't know
- How Apple and Google will officially respond to the ultimatum before the September deadline.
- Whether the UK government will actually pursue criminal charges against tech executives if the companies refuse to comply.
- What specific age verification methods will be required for adults to opt out of the scanning.
Key terms
- Client-Side Scanning (CSS)
- A technology that analyzes files, photos, or messages directly on a user's device before they are encrypted and transmitted over the internet.
- End-to-End Encryption (E2EE)
- A secure communication method that prevents third parties, including the service provider, from accessing data while it is transferred from one device to another.
- Age Assurance
- Methods used to verify a user's age, often requiring the submission of government ID, credit card details, or biometric data to access restricted content.
Frequently asked
Will this scanning affect adult smartphone users?
Yes. Under the proposed mandate, the scanning infrastructure will be active by default on all devices. Adults will only be able to disable it by completing a formal age verification process, which may require submitting government ID or biometric data.
Does client-side scanning break end-to-end encryption?
Privacy experts argue that it does. Because the scanning occurs on the device before the image is encrypted and sent, it bypasses the encryption entirely, allowing the operating system to inspect the content of private messages.
What happens if Apple and Google refuse to comply?
The UK government has stated that if the companies do not voluntarily implement the scanning within 90 days, it will introduce legislation to force compliance. This could include massive corporate fines and, as a last resort, criminal liability for tech executives.
Sources
[1]UK Home OfficeUK Government & Safety Advocates
New plans to stop children taking, sharing or viewing nude images
Read on UK Home Office →[2]TechRadarPrivacy & Encryption Advocates
Surveillance is not safety: UK's device scanning order faces privacy backlash
Read on TechRadar →[3]Computer WeeklyPrivacy & Encryption Advocates
The UK and Europe are ramping up opposition to encryption
Read on Computer Weekly →[4]Mysterium VPNPrivacy & Encryption Advocates
The Scan That Covers Every App, the Camera, and Whatever Comes Next
Read on Mysterium VPN →
Every angle. Every day.
Get shopping stories with full source coverage and perspective breakdowns delivered to your inbox.





