Retour

ONLINE SAFETY & DIGITAL LOVE

A practical 2026 guide to socialising, dating, scams, privacy, AI, deepfakes, immersive spaces and safer platform design

CORE IDEA  Online safety is not simply a list of warnings. It is created by the interaction between user behaviour, platform architecture, privacy settings, identity systems, moderation, law and the rapidly changing capabilities of artificial intelligence.

About this guide

Digital life is now ordinary life. Friendships, communities, work, gaming, romance, creativity and support increasingly move between physical and online spaces. That creates enormous opportunities, but it also changes how deception, coercion, harassment, fraud and exploitation can occur. Artificial intelligence can now generate convincing messages, images, voices and video. Immersive environments add avatars, spatial audio, movement and proximity. Dating platforms can accelerate intimacy before identity has been established. Children and vulnerable adults may be reachable through games, social networks and private messaging.

This guide brings together Neurohaven’s existing material on online safety and digital romance with updated evidence and regulation. It is written for ordinary users, parents and carers, professionals, community moderators, designers and people entering social or immersive digital spaces.

NEUROHAVEN PRINCIPLE  Make the safe action the easy action. A user under pressure should be able to mute, block, leave, preserve evidence and report without navigating a maze of menus.

The threat landscape in 2026

Most online harms are not entirely new. What has changed is their speed, realism, scale and ability to cross platforms. A scammer can move from a dating app to encrypted messaging, generate plausible photographs, clone a voice, fabricate a video call, imitate a trusted person and ask for money or intimate material within the same relationship.

Threat

How it appears

Best first response

Phishing & account takeover

Urgent links, fake login pages, QR codes, MFA prompts, stolen-session scams

Do not use the supplied link; open the service independently and use passkeys or strong 2SV.

Romance & investment fraud

Rapid trust-building followed by money, crypto, 'emergency' or investment requests

Stop payments; verify identity and story independently; tell someone outside the relationship.

Catfishing / impersonation

Stolen or synthetic images, inconsistent biographies, excuses to avoid verification

Reverse-search where possible; use live, unpredictable verification and independent channels.

Deepfake voice/video

A familiar face or voice appears to ask for money, credentials or secrecy

Treat unusual requests as unverified; call back on a known number or confirm a shared fact.

Sextortion / image-based abuse

Threats to publish intimate images unless money or more images are provided

Do not pay; preserve evidence; report; use specialist takedown/support routes.

Grooming & coercive contact

Special attention, secrecy, boundary testing, isolation, gifts, migration to private channels

End or restrict contact; preserve evidence; involve a trusted adult/safeguarding route where relevant.

Harassment & stalking

Repeated messages, doxxing, tracking, following in virtual spaces, swatting threats

Block/mute, tighten privacy, document patterns, escalate credible threats.

AI-agent manipulation

Bots presented as human, pseudo-therapy, emotional dependency, requests for secrets

Require clear AI identity; do not treat an agent as a verified person or professional.

Data & biometric privacy

Collection of voice, face, location, movement, gaze or behavioural patterns

Share the minimum; review permissions; prefer services with clear retention and deletion controls.

1. A safer digital baseline

Secure the account before securing the conversation

Account security remains the foundation of online safety. In 2026, passkeys are increasingly preferable to passwords because they are bound to the legitimate service and are resistant to conventional phishing. Where passkeys are unavailable, use a reputable password manager, unique passwords and strong two-step verification. Keep devices updated and protect the email account used for password recovery particularly carefully.

·       Use passkeys where offered; otherwise use unique passwords generated and stored by a reputable password manager.

·       Use two-step verification, ideally an authenticator app or hardware-based method rather than SMS when alternatives exist.

·       Never approve an unexpected login or authentication prompt merely because it appears on your own phone.

·       Keep phones, browsers, operating systems and apps updated. Remove apps and browser extensions you no longer use.

·       Lock devices with a PIN/biometric method and protect account-recovery methods as carefully as the main password.

·       Back up important files and recovery information.

Privacy is not secrecy

Privacy means controlling who can learn what about you, when and for what purpose. Small details can be combined: a first name, workplace, regular gym, school uniform, street view from a window, car registration, birthday post and location tag may together identify a person or routine.

·       Avoid publishing precise home, school, workplace or routine information unless there is a clear reason.

·       Review audience and discoverability settings, not just whether an account is labelled 'private'.

·       Strip location metadata from sensitive media where appropriate and consider what can be inferred from backgrounds.

·       Treat voice, face, gait, gaze and movement data as potentially identifying information in immersive systems.

·       Before granting camera, microphone, contacts, location or photo-library access, ask whether the feature genuinely needs it.

IMPORTANT  HTTPS means the connection to a website is encrypted. It does not prove that the website, seller, investment or person is genuine.

2. Socialising online: friendship, communities and belonging

Online friendships can be authentic and important. Text, voice, games and shared virtual spaces may reduce some social barriers and allow people to meet around interests rather than geography. For some neurodivergent people, asynchronous communication and controllable social distance can make connection easier. The risk is not that an online friendship is 'less real'; it is that identity, intention and boundaries may be harder to judge.

Healthy signs

·       The relationship develops at a tolerable pace and allows disagreement or time apart.

·       The person respects boundaries and does not demand constant availability.

·       They do not pressure you to hide the relationship, move platforms immediately, send money or reveal intimate information.

·       Their identity and story remain reasonably consistent over time.

·       They tolerate sensible verification rather than treating it as an insult.

·       The relationship adds to life rather than progressively isolating you from offline supports.

Red flags

  • · Intensity very early: 'soulmate', 'only person who understands me', or highly personal disclosure designed to accelerate trust.

·       Repeated crises that require money, gift cards, crypto, account access or secrecy.

·       Attempts to move rapidly from a moderated platform to private or disappearing messages.

  • · Boundary testing: sexual jokes, requests for images, pressure to reveal location or private details, or escalating dares.

·       Creating conflict between you and family/friends/moderators, or claiming everyone else is trying to separate you.

·       Threats, guilt, humiliation, mass messaging, doxxing or mobilising other users against you.

3. Digital romance and online dating

Digital romance is not a lesser form of intimacy. People can develop substantial emotional attachment through text, voice, video, games and avatars. Online communication can support reflection, disclosure and connection across geography, disability, identity and social anxiety. It can also magnify idealisation: people fill in missing information, curate themselves and may become emotionally committed before basic facts have been verified.

Why online intimacy can feel unusually intense

Digital communication strips away some physical cues while increasing opportunities for selective self-disclosure. Asynchronous messaging allows people to craft thoughtful responses, while constant notifications can create a rapid cycle of anticipation and reward. This can be positive, but it can also make ambiguity feel like intimacy and frequency feel like reliability. A long message history is evidence that a conversation occurred, not proof of the other person’s identity, motives or circumstances.

Safer dating progression

  1. Keep early communication on the platform while you establish basic consistency and boundaries.
  2. Verify identity gradually. A live video call helps but is no longer definitive because synthetic video and voice are improving.
  3. Use an independent verification step for anything consequential: another established account, a known telephone number, mutual contacts or a real-world meeting.
  4. Do not send money, crypto, gift cards, financial credentials or copies of identity documents to someone merely because the relationship feels emotionally close.
  5. For a first meeting, choose a public place, arrange your own transport, tell someone where you are, keep control of your phone and drinks, and have an exit plan.
  6. Do not allow embarrassment about having met online to stop you seeking help if something goes wrong.

Romance fraud and 'pig-butchering' style scams

Some frauds deliberately combine romance or friendship with investment. The relationship may be cultivated for weeks or months before the person introduces a supposedly exclusive trading opportunity, cryptocurrency platform or investment group. Professional-looking interfaces, AI-generated endorsements and fabricated account balances can make the scheme appear credible. A request to invest through a platform chosen by the new contact should be treated as a major warning sign.

RULE OF THUMB  Love, friendship and investment should not need to be bundled together. If a new romantic or social contact becomes your financial adviser, stop and verify independently.

Consent in digital intimacy is specific and reversible. Consent to receive or send an image is not consent to save it indefinitely, forward it, upload it, manipulate it, create a synthetic sexual image from it, or use it for blackmail. Once an intimate image leaves a device, control can be difficult to recover even when the recipient originally seemed trustworthy.

·       Avoid including identifying details in intimate images if you would be harmed by wider distribution.

·       Never assume disappearing-message features prevent screenshots, screen recording or capture by another device.

·       Do not pay a sextortion demand. Payment rarely guarantees deletion and may lead to further demands.

·       Preserve usernames, URLs, messages, payment requests and threats before blocking where it is safe to do so.

·       Report intimate-image abuse to the platform and use specialist reporting/takedown tools where applicable.

·       Synthetic or deepfake intimate images can still be profoundly abusive even when no original nude image existed.

5. Deepfakes, synthetic identity and the end of 'seeing is believing'

A familiar voice, face or video call can no longer be treated as conclusive proof of identity. Generative AI can clone voices, alter faces, generate plausible photographs and produce highly personalised scam messages. The correct response is not permanent suspicion; it is a new habit of independent verification when a request is unusual, urgent, secret or consequential.

If this happens…

Do this…

A relative calls asking for emergency money

Hang up and call their known number, or another family member. Use a pre-agreed family phrase if available.

A boss sends a voice note asking for a secret transfer

Confirm through normal organisational channels and established approval processes.

A new romantic contact appears on video

Ask for natural, unpredictable interaction; then verify through a second independent route before financial or intimate decisions.

A public figure endorses an investment

Assume the endorsement could be synthetic until verified on official channels and through an authorised financial source.

6. Grooming, manipulation and coercive control

Grooming is usually a process, not a single message. It can involve attention, gifts, special status, secrecy, boundary testing, sexualisation, emotional dependence and gradual isolation. The same pattern can occur in social media, games, livestreams, private chat, fandoms and immersive worlds. Children are a central safeguarding concern, but adults with loneliness, cognitive impairment, trauma, financial vulnerability or other support needs may also be targeted.

What platforms should treat as risk signals

·       Adults repeatedly initiating private contact with young users or moving them to less moderated channels.

·       Rapid escalation from public interaction to secrecy, sexual content, gifts or financial exchange.

·       Attempts to obtain a young person’s location, school, private contact information or images.

·       Repeated contact after blocking, account cycling or coordinated harassment.

·       Age ambiguity combined with sexualised interaction.

·       Requests to keep contact secret from parents, carers or moderators.

7. Children and teenagers: safer by default

The UK safety framework has shifted firmly toward platform responsibility. Under the Online Safety Act, services likely to be accessed by children must assess risks and put proportionate protections in place. Ofcom’s 2026 material emphasises effective age assurance, anti-grooming measures, safer recommender systems and stronger protections against harmful content. Privacy law also requires child-appropriate design rather than assuming children can manage adult-style privacy choices.

·       Use high-privacy defaults for young users and limit discoverability by unknown adults.

·       Restrict unsolicited direct messaging and risky friend/contact recommendations.

·       Avoid public display of precise location, school or activity routines.

·       Make reporting and blocking understandable to the child, not only to the parent.

·       Design livestreaming and private messaging as higher-risk features requiring stronger safeguards.

·       Give parents/carers clear, specific information without covertly turning the child into a surveillance target.

·       Reassess risks whenever a platform adds significant new features such as AI agents, live voice, spatial tracking or commerce.

2026 UK CONTEXT  Ofcom reported in July 2026 that age checks were being deployed at unprecedented scale, while also warning that the job was not done and that some age-inference approaches remained questionable.

8. AI companions, agents and synthetic relationships

  • AI systems are moving from tools toward social actors: companions, tutors, guides, moderators, game characters and pseudo-therapeutic agents. This creates a distinctive safety problem because the user may emotionally interpret fluent language as evidence of understanding, loyalty, authority or consciousness.

Minimum safeguards for an AI agent

·       It should be unmistakably labelled as AI and should not impersonate a human user.

·       It should not claim professional qualifications or authority it does not possess.

·       It should not ask users for money, passwords, secrets, sexual material or off-platform contact.

·       It should not manipulate a user to continue the relationship or imply abandonment if the user leaves.

·       It should explain, in accessible language, whether conversations are stored, reviewed or used to improve systems.

·       High-risk conversations should have appropriate human escalation pathways rather than relying on the agent alone.

·       Children require substantially stronger safeguards; current evidence raises particular concerns about emotional dependency, sexual content, privacy and crisis handling in companion-style AI.

9. Safety inside immersive and avatar-based spaces

Immersive environments can make online interactions feel physically immediate. Harassment may become spatial: following, surrounding, blocking a route, shouting at close range, unwanted gestures, sexualised avatar behaviour or haptic contact. Research on metaverse users has documented unwanted contact, sexually explicit spaces and unwanted haptic experiences. Safety tools therefore need to work at the speed of the event.

Essential user controls

·       Instant mute and block accessible without leaving the scene.

·       A one-action personal-space or safety-bubble control.

·       Immediate teleport/leave/return-home action.

·       Per-user voice volume and proximity controls.

·       Clear recording/evidence rules and privacy-respecting incident capture where lawful.

·       Ability to prevent blocked users from re-entering through alternate accounts or invitations where feasible.

·       Controls suitable for keyboard/mouse, controller, mobile and VR, not only one interface.

Spatial and biometric privacy

Voice, head movement, hand movement, gaze, body position, room mapping and interaction patterns can become sensitive behavioural data. A privacy-preserving immersive platform should collect only what the feature needs, retain it for the shortest useful period and avoid silently converting behavioural data into hidden personality, vulnerability or advertising profiles.

10. Harassment, hate, stalking and coordinated abuse

Online harassment ranges from isolated insults to persistent stalking, threats, doxxing, sexual harassment, hate campaigns and coordinated attacks. The response should be proportionate to the pattern and risk. Repeated contact across accounts, knowledge of home/work routines, credible threats, threats involving weapons or children, impersonation, publication of private information and attempts to mobilise others are more serious than a single unpleasant message.

If targeted

  1. Prioritise immediate safety. Leave the space or stop responding if engagement is escalating risk.
  2. Preserve evidence before blocking if it is safe: screenshots, usernames, URLs, dates, transaction records and message history.
  3. Block/mute and tighten privacy and account recovery settings.
  4. Tell someone outside the online conflict, particularly where threats or coercion are involved.
  5. Report through the platform. For serious threats, stalking, sexual offences or fraud, use the appropriate external authority or specialist service.
  6. Do not retaliate by publishing private information or attempting vigilante identification.
  7. Scams: how modern social engineering works

The strongest scams are behavioural rather than technical. They exploit urgency, authority, affection, fear, scarcity, embarrassment and the desire to help. AI increases the volume and personalisation of these messages, but the underlying psychological levers remain familiar.

Pressure tactic

Typical wording

Safer response

Urgency

Do this now or the account will close

Pause. Open the service independently.

Authority

I’m from your bank / police / IT team

End contact and use the organisation’s published contact route.

Affection

If you loved/trusted me, you would…

Treat emotional pressure as a warning, not proof of intimacy.

Secrecy

Don’t tell anyone; it will ruin the deal

Consult someone independent before acting.

Scarcity

Only today / exclusive group / guaranteed return

Assume high-pressure investment claims are unsafe until independently verified.

Fear / shame

Pay or I’ll expose you

Do not pay; preserve evidence and seek specialist help.

12. Neurodiversity, impulsivity and vulnerability without stigma

Safety guidance should not imply that neurodivergent people are inherently poor judges of character. However, any person can become more vulnerable when they are lonely, sleep-deprived, distressed, intoxicated, highly excited, financially pressured or strongly seeking acceptance. Some ADHD-related patterns — rapid responding, novelty seeking, impulsive spending, intense focus on a new relationship or sensitivity to rejection — can make deliberate pause mechanisms useful. Autistic users may prefer explicit rules and predictable boundaries, while ambiguity or manipulative social inference can create difficulty for some individuals.

·       Use a 'pause before payment' rule for new contacts and high-emotion situations.

·       Discuss major online financial decisions with an independent person.

·       Turn off non-essential notifications if constant contact is driving impulsive responding.

  • · Use written boundary rules: what information, money, images or access you never share online.

·       Do not frame exploitation as the victim having been 'naive'; sophisticated manipulation can deceive highly experienced people.

13. Platform responsibility: safety by design

A serious online-safety model cannot rely on users reading advice. Architecture determines exposure. Who can contact whom? Can strangers locate minors? Can a blocked user immediately return? Can an AI agent masquerade as a person? Are financial requests, external links or sexual content treated as higher-risk interactions? Does the platform collect more data than it needs? These are product questions as much as moderation questions.

Design principles 

·       Private-by-default where exposure is not necessary for the feature.

  • · Data minimisation: collect only what is needed and define retention/deletion clearly.

·       Clear labels for humans, AI agents, moderators and automated messages.

·       Fast mute, block, teleport and exit controls available during active interaction.

·       Friction around suspicious links, financial solicitation and repeated unsolicited contact.

·       Strong protections around minors, age ambiguity and cross-age messaging.

·       Escalation to human review for serious safeguarding, threats, sexual exploitation and identity abuse.

·       Evidence-preservation processes that are lawful, proportionate and understandable.

·       Transparent consequences and appeals rather than invisible moderation.

·       Safety testing in the real interface, including controller/VR usability and high-stress scenarios.

·       Risk reassessment before major new features or significant changes are launched.

A simple incident model

Level

Example

Immediate control

Platform response

1 — Unwanted

Annoying contact, mild incivility

Mute / leave

User controls; pattern detection if repeated

2 — Harassing

Repeated abuse, following, sexualised behaviour

Block / teleport / report

Review, restrictions, anti-evasion controls

3 — High risk

Threats, stalking, grooming, sextortion, doxxing

Leave, preserve evidence, escalate

Priority human review; preserve relevant records lawfully

4 — Immediate danger

Credible imminent threat or serious safeguarding emergency

Exit and seek real-world help

Emergency protocol and lawful external escalation where appropriate

14. If something has already gone wrong

People often delay asking for help because of embarrassment, especially after romance fraud, intimate-image abuse or a relationship that others had questioned. That delay benefits the offender. The practical priority is to limit further harm.

  1. Stop further payments, transfers, image sharing or disclosure of credentials.
  2. Preserve evidence before deleting messages or accounts where safe.
  3. Secure the affected email, financial and social accounts; change compromised credentials and revoke unknown sessions.
  4. Contact the bank/payment provider immediately for financial fraud.
  5. Report the account/content to the platform and use appropriate specialist reporting routes.
  6. Tell a trusted person. Isolation makes coercion easier.
  7. Where there is immediate danger, credible threat, stalking, child safeguarding concern or serious sexual exploitation, use the appropriate emergency or law-enforcement route.

SEXTORTION  Do not keep negotiating in the hope of buying deletion. Do not send more images. Do not assume payment ends the threat.

15. A 60-second safety check before acting

IDENTITY

Have I independently verified who this is?

URGENCY

Why must this happen now? What changes if I wait 20 minutes?

SECRECY

Am I being told not to tell anyone?

MONEY

Is a new social/romantic contact asking for money, crypto, gift cards or an investment?

INTIMACY

Would I be safe if this image/message became public?

LINKS

Can I reach the service independently instead of using this link/QR code?

LOCATION

Am I revealing where I live, work, study or regularly go?

AI

Could the voice, image, video or account be synthetic or impersonated?

BOUNDARIES

Has the person respected 'no', delay and disagreement?

EXIT

Do I know how to block, leave, report and preserve evidence?

16. Quick guidance by context

For adults using dating apps

·       Keep control of transport and meeting location; tell someone where you are.

·       Verify independently before financial or highly intimate decisions.

·       Treat investment proposals, emergency loans and secrecy as major red flags.

·       Remember that video is useful but no longer definitive proof of identity.

For parents and carers

·       Keep communication open enough that a child can disclose a mistake without expecting humiliation or automatic loss of all devices.

·       Understand the platforms, games and messaging features they actually use.

·       Prioritise stranger contact, private messaging, livestreaming, sexual coercion and location disclosure as higher-risk areas.

·       Use technical controls as one layer, not a substitute for conversation and platform responsibility.

For professionals and community moderators

·       Look for patterns of coercion and repeated contact, not only individual pieces of content.

·       Have a clear route for safeguarding, financial fraud, intimate-image abuse and credible threats.

·       Do not ask victims to repeatedly retell distressing events when evidence already exists.

·       Use proportionate confidentiality and data-retention rules.

For Miniverse designers

·       Design the emergency exit before the social feature.

·       Separate identity, presence and discoverability controls.

·       Label AI explicitly and prevent AI-human ambiguity.

·       Test blocking and safety controls under realistic pressure, including VR/controller use.

·       Treat each new capability — voice, payments, livestreaming, AI, private rooms, haptics — as a new risk surface.

17. What is changing next

The next phase of online safety will be shaped by stronger age assurance, AI-generated identity, agentic systems capable of acting on users’ behalf, increasingly realistic real-time voice/video synthesis, wearable and spatial computing, and regulation that expects measurable risk reduction rather than policy statements alone.

·       Passkeys and phishing-resistant authentication are likely to become normal rather than optional.

·       Deepfake detection will help but cannot replace independent verification because detection and generation will continue to co-evolve.

·       Platforms will face increasing pressure to distinguish adults from children without creating excessive privacy intrusion.

·       AI agents will require clearer identity, data-use and behavioural boundaries.

·       Immersive systems will need safety controls that account for proximity, spatial harassment, haptics and biometric/behavioural data.

  • · Safety governance will increasingly be judged by outcomes: whether risky contact, harmful recommendations and repeat offenders are actually reduced.

Sources and further reading

  • Selected current sources used to update and consolidate this guide. Access dates: August 2026.

Ofcom — Protection of children duties under the Online Safety Act — ofcom.org.uk ↗

Ofcom — Online safety regulatory documents and guidance — ofcom.org.uk ↗

Ofcom — Use of Age Assurance Report 2026 — ofcom.org.uk ↗

Ofcom — Tech firms commit to stronger anti-grooming measures — ofcom.org.uk ↗

Ofcom — Children who create and view livestreams — ofcom.org.uk ↗

ICO — Age Appropriate Design Code / Children’s Code — ico.org.uk ↗

NCSC — Password managers and passkeys — ncsc.gov.uk ↗

  • NCSC — Passkeys: more secure than traditional ways to log in — ncsc.gov.uk ↗

NCSC — Sextortion scams — ncsc.gov.uk ↗

FBI IC3 — 2025 Internet Crime Report — ic3.gov ↗

eSafety Commissioner — Deepfakes — esafety.gov.au ↗

  • eSafety Commissioner — The metaverse: experiences in virtual reality — esafety.gov.au ↗

eSafety Commissioner — Digital use and risk among children aged 10–15 — esafety.gov.au ↗

stopncii.org ↗ — Preventing non-consensual intimate image sharing — stopncii.org ↗

NCMEC Take It Down — Help with intimate images taken under 18 — takeitdown.ncmec.org ↗

Editorial note

This is general educational information, not individual legal, safeguarding, cybersecurity or medical advice. Laws, platform rules and reporting systems change. For serious incidents, use the current official guidance and reporting route in the relevant jurisdiction.