Bill C-34 Asks Platforms to Prove They Are Safe. Can Anyone Actually Judge That?
In June 2026, the federal government introduced Bill C-34, the Safe Social Media Act. Most of the headlines focused on one thing: it would keep Canadians under 16 off social media. But the more interesting part is the exit door the bill leaves open. A platform can avoid the ban if it can show a new regulator that its service is safe for younger users.
That design has a name in policy circles. It is called a “presumptive ban.” A recent piece in Tech Policy Press by Owen Bennett, a former head of international online safety at the UK’s Ofcom, takes this idea apart and asks a simple question: even if we like the concept, can the regulator actually do the job it hands them? It is worth reading in full, and it raises points that every Canadian business watching C-34 should sit with.
What a “presumptive ban” actually means
Start with the plain version. A “hard” ban, like the one Australia rolled out, is simple: under-16s are off, full stop. A presumptive ban is different. The starting assumption is that a platform is unsafe for teens, so it is banned by default. But the platform can earn its way back in by proving to a regulator that it meets a safety standard.
Think of it like a restaurant and a health inspector. The kitchen stays closed until the inspector signs off. The burden is on the restaurant to show it is clean, not on the inspector to catch it being dirty.
Under Bill C-34, the inspector is a brand new body, the Digital Safety Commission of Canada. Platforms that want under-16 users would need to satisfy that Commission that they have adequate safeguards in place.
The problem hiding in plain sight
Here is where Bennett’s argument bites. The whole model depends on the regulator being willing and able to say “yes, this is safe.” And there are good reasons to think a regulator will find that very hard to do.
Reason one: the incentives are lopsided. Put yourself in the shoes of the official who has to sign the safety certificate. If you approve a platform and nothing goes wrong, you get nothing. No praise, no reward, just your job done. But if you approve a platform and a child is later harmed on it, that decision has your name on it. It becomes a scandal. Meanwhile, if you simply say no, almost nothing bad happens to you.
So the safe choice for the official is to say no, or to keep asking for more, indefinitely. The old line in corporate IT was “no one ever got fired for buying IBM.” The same logic pushes a regulator toward caution that looks less like careful judgment and more like refusing to decide.
Reason two: it flips the regulator’s job. Most regulators today play defense. They assume you are following the rules, and they step in when they catch you breaking them. That is a “negative” role, and the risk to the regulator is fairly low because the rules are written down and the burden is on them to prove a breach.
A presumptive ban asks for the opposite. Now the regulator has to actively declare a platform safe before anything goes wrong. That is a “positive” role, and it carries a lot more personal and institutional risk. No matter how detailed the standard is, someone still has to make a judgment call, and own it.
Reason three: “safe” is genuinely hard to measure. Checking whether a company filed the right paperwork is one thing. Deciding whether an entire platform is a safe place for a 14-year-old is another. It needs far more data, deeper access to how the systems actually work, and a real understanding of how harm shows up in different corners of a product. Regulators of social media already sit on the wrong side of an information gap. Without new tools, certifying safety is not just difficult, it may be impossible in practice.
What would have to change
Bennett does not argue the idea is hopeless. He lays out what it would take to make it work, and the list is a useful checklist for anyone reading C-34 closely.
First, a clear and precise definition of what “safe” means, with real metrics platforms can aim for and regulators can measure against. Right now the bill leaves a great deal of this to be worked out later. Law professor Michael Geist counted roughly 50 open questions the legislation hands off to the Commission and to future regulations.
Second, more than one set of eyes. If the regulator is the only body that can certify safety, its caution becomes a single point of failure. Bennett points to models in other industries where independent third parties can assess and audit safety cases against agreed standards. Spreading that work out reduces the bottleneck.
Third, transparency. A regulator with the power to switch teen access on or off is making decisions of real public weight. The public, and the companies affected, deserve to see how those calls get made. Secrecy invites both excessive caution and political pressure.
Fourth, an honest debate about whether this is even the right approach. Is it healthy for unelected officials, rather than Parliament, to decide which platforms teens may use? And do heavy certification processes quietly favour the big incumbents, who can afford the lawyers and compliance teams, over smaller Canadian competitors who cannot?
Why this matters for Canadian businesses
At Newport Thomson, we track this closely because C-34 is not only a social media story. The bill also reaches AI chatbot services, requires age verification that touches every adult user, and creates a powerful new regulator whose decisions will shape the Canadian internet for years.
The lesson from Bennett’s analysis is that the mechanism matters as much as the intention. A presumptive ban sounds like a reasonable middle path between “ban everything” and “do nothing.” But a middle path only works if the body at the centre can actually walk it. If the Digital Safety Commission is built in a way that makes “no” the easy answer and “yes” the risky one, the practical result may land closer to a hard ban than anyone intended, with the added cost of a slow, unclear, uncertain process for the businesses caught in it.
C-34 will move through Parliament over the coming months. Now is the time for businesses, platforms, and privacy professionals to engage with how the safety-certification machinery is built, not just whether the age line sits at 16.
Read Owen Bennett’s original analysis in Tech Policy Press: “Can Regulators Actually Deliver a Presumptive Teen Social Media Ban?” You can review the government’s summary of the Safe Social Media Act here.
