|
CORE IDEA Online safety is not simply a list of warnings. It is created by the interaction between user behaviour, platform architecture, privacy settings, identity systems, moderation, law and the rapidly changing capabilities of artificial intelligence. |
About this guide
Digital life is now ordinary life. Friendships, communities, work, gaming, romance, creativity and support increasingly move between physical and online spaces. That creates enormous opportunities, but it also changes how deception, coercion, harassment, fraud and exploitation can occur. Artificial intelligence can now generate convincing messages, images, voices and video. Immersive environments add avatars, spatial audio, movement and proximity. Dating platforms can accelerate intimacy before identity has been established. Children and vulnerable adults may be reachable through games, social networks and private messaging.
This guide brings together Neurohaven’s existing material on online safety and digital romance with updated evidence and regulation. It is written for ordinary users, parents and carers, professionals, community moderators, designers and people entering social or immersive digital spaces.
|
NEUROHAVEN PRINCIPLE Make the safe action the easy action. A user under pressure should be able to mute, block, leave, preserve evidence and report without navigating a maze of menus. |
The threat landscape in 2026
Most online harms are not entirely new. What has changed is their speed, realism, scale and ability to cross platforms. A scammer can move from a dating app to encrypted messaging, generate plausible photographs, clone a voice, fabricate a video call, imitate a trusted person and ask for money or intimate material within the same relationship.
|
Threat |
How it appears |
Best first response |
|
Phishing & account takeover |
Urgent links, fake login pages, QR codes, MFA prompts, stolen-session scams |
Do not use the supplied link; open the service independently and use passkeys or strong 2SV. |
|
Romance & investment fraud |
Rapid trust-building followed by money, crypto, 'emergency' or investment requests |
Stop payments; verify identity and story independently; tell someone outside the relationship. |
|
Catfishing / impersonation |
Stolen or synthetic images, inconsistent biographies, excuses to avoid verification |
Reverse-search where possible; use live, unpredictable verification and independent channels. |
|
Deepfake voice/video |
A familiar face or voice appears to ask for money, credentials or secrecy |
Treat unusual requests as unverified; call back on a known number or confirm a shared fact. |
|
Sextortion / image-based abuse |
Threats to publish intimate images unless money or more images are provided |
Do not pay; preserve evidence; report; use specialist takedown/support routes. |
|
Grooming & coercive contact |
Special attention, secrecy, boundary testing, isolation, gifts, migration to private channels |
End or restrict contact; preserve evidence; involve a trusted adult/safeguarding route where relevant. |
|
Harassment & stalking |
Repeated messages, doxxing, tracking, following in virtual spaces, swatting threats |
Block/mute, tighten privacy, document patterns, escalate credible threats. |
|
AI-agent manipulation |
Bots presented as human, pseudo-therapy, emotional dependency, requests for secrets |
Require clear AI identity; do not treat an agent as a verified person or professional. |
|
Data & biometric privacy |
Collection of voice, face, location, movement, gaze or behavioural patterns |
Share the minimum; review permissions; prefer services with clear retention and deletion controls. |
1. A safer digital baseline
Secure the account before securing the conversation
Account security remains the foundation of online safety. In 2026, passkeys are increasingly preferable to passwords because they are bound to the legitimate service and are resistant to conventional phishing. Where passkeys are unavailable, use a reputable password manager, unique passwords and strong two-step verification. Keep devices updated and protect the email account used for password recovery particularly carefully.
· Use passkeys where offered; otherwise use unique passwords generated and stored by a reputable password manager.
· Use two-step verification, ideally an authenticator app or hardware-based method rather than SMS when alternatives exist.
· Never approve an unexpected login or authentication prompt merely because it appears on your own phone.
· Keep phones, browsers, operating systems and apps updated. Remove apps and browser extensions you no longer use.
· Lock devices with a PIN/biometric method and protect account-recovery methods as carefully as the main password.
· Back up important files and recovery information.
Privacy is not secrecy
Privacy means controlling who can learn what about you, when and for what purpose. Small details can be combined: a first name, workplace, regular gym, school uniform, street view from a window, car registration, birthday post and location tag may together identify a person or routine.
· Avoid publishing precise home, school, workplace or routine information unless there is a clear reason.
· Review audience and discoverability settings, not just whether an account is labelled 'private'.
· Strip location metadata from sensitive media where appropriate and consider what can be inferred from backgrounds.
· Treat voice, face, gait, gaze and movement data as potentially identifying information in immersive systems.
· Before granting camera, microphone, contacts, location or photo-library access, ask whether the feature genuinely needs it.
|
IMPORTANT HTTPS means the connection to a website is encrypted. It does not prove that the website, seller, investment or person is genuine. |
2. Socialising online: friendship, communities and belonging
Online friendships can be authentic and important. Text, voice, games and shared virtual spaces may reduce some social barriers and allow people to meet around interests rather than geography. For some neurodivergent people, asynchronous communication and controllable social distance can make connection easier. The risk is not that an online friendship is 'less real'; it is that identity, intention and boundaries may be harder to judge.
Healthy signs
· The relationship develops at a tolerable pace and allows disagreement or time apart.
· The person respects boundaries and does not demand constant availability.
· They do not pressure you to hide the relationship, move platforms immediately, send money or reveal intimate information.
· Their identity and story remain reasonably consistent over time.
· They tolerate sensible verification rather than treating it as an insult.
· The relationship adds to life rather than progressively isolating you from offline supports.
Red flags
- · Intensity very early: 'soulmate', 'only person who understands me', or highly personal disclosure designed to accelerate trust.
· Repeated crises that require money, gift cards, crypto, account access or secrecy.
· Attempts to move rapidly from a moderated platform to private or disappearing messages.
- · Boundary testing: sexual jokes, requests for images, pressure to reveal location or private details, or escalating dares.
· Creating conflict between you and family/friends/moderators, or claiming everyone else is trying to separate you.
· Threats, guilt, humiliation, mass messaging, doxxing or mobilising other users against you.
3. Digital romance and online dating
Digital romance is not a lesser form of intimacy. People can develop substantial emotional attachment through text, voice, video, games and avatars. Online communication can support reflection, disclosure and connection across geography, disability, identity and social anxiety. It can also magnify idealisation: people fill in missing information, curate themselves and may become emotionally committed before basic facts have been verified.
Why online intimacy can feel unusually intense
Digital communication strips away some physical cues while increasing opportunities for selective self-disclosure. Asynchronous messaging allows people to craft thoughtful responses, while constant notifications can create a rapid cycle of anticipation and reward. This can be positive, but it can also make ambiguity feel like intimacy and frequency feel like reliability. A long message history is evidence that a conversation occurred, not proof of the other person’s identity, motives or circumstances.
Safer dating progression
- Keep early communication on the platform while you establish basic consistency and boundaries.
- Verify identity gradually. A live video call helps but is no longer definitive because synthetic video and voice are improving.
- Use an independent verification step for anything consequential: another established account, a known telephone number, mutual contacts or a real-world meeting.
- Do not send money, crypto, gift cards, financial credentials or copies of identity documents to someone merely because the relationship feels emotionally close.
- For a first meeting, choose a public place, arrange your own transport, tell someone where you are, keep control of your phone and drinks, and have an exit plan.
- Do not allow embarrassment about having met online to stop you seeking help if something goes wrong.
Romance fraud and 'pig-butchering' style scams
Some frauds deliberately combine romance or friendship with investment. The relationship may be cultivated for weeks or months before the person introduces a supposedly exclusive trading opportunity, cryptocurrency platform or investment group. Professional-looking interfaces, AI-generated endorsements and fabricated account balances can make the scheme appear credible. A request to invest through a platform chosen by the new contact should be treated as a major warning sign.
|
RULE OF THUMB Love, friendship and investment should not need to be bundled together. If a new romantic or social contact becomes your financial adviser, stop and verify independently. |
4. Sex, intimacy, consent and image-based abuse
Consent in digital intimacy is specific and reversible. Consent to receive or send an image is not consent to save it indefinitely, forward it, upload it, manipulate it, create a synthetic sexual image from it, or use it for blackmail. Once an intimate image leaves a device, control can be difficult to recover even when the recipient originally seemed trustworthy.
· Avoid including identifying details in intimate images if you would be harmed by wider distribution.
· Never assume disappearing-message features prevent screenshots, screen recording or capture by another device.
· Do not pay a sextortion demand. Payment rarely guarantees deletion and may lead to further demands.
· Preserve usernames, URLs, messages, payment requests and threats before blocking where it is safe to do so.
· Report intimate-image abuse to the platform and use specialist reporting/takedown tools where applicable.
· Synthetic or deepfake intimate images can still be profoundly abusive even when no original nude image existed.
5. Deepfakes, synthetic identity and the end of 'seeing is believing'
A familiar voice, face or video call can no longer be treated as conclusive proof of identity. Generative AI can clone voices, alter faces, generate plausible photographs and produce highly personalised scam messages. The correct response is not permanent suspicion; it is a new habit of independent verification when a request is unusual, urgent, secret or consequential.
|
If this happens… |
Do this… |
|
A relative calls asking for emergency money |
Hang up and call their known number, or another family member. Use a pre-agreed family phrase if available. |
|
A boss sends a voice note asking for a secret transfer |
Confirm through normal organisational channels and established approval processes. |
|
A new romantic contact appears on video |
Ask for natural, unpredictable interaction; then verify through a second independent route before financial or intimate decisions. |
|
A public figure endorses an investment |
Assume the endorsement could be synthetic until verified on official channels and through an authorised financial source. |
6. Grooming, manipulation and coercive control
Grooming is usually a process, not a single message. It can involve attention, gifts, special status, secrecy, boundary testing, sexualisation, emotional dependence and gradual isolation. The same pattern can occur in social media, games, livestreams, private chat, fandoms and immersive worlds. Children are a central safeguarding concern, but adults with loneliness, cognitive impairment, trauma, financial vulnerability or other support needs may also be targeted.
What platforms should treat as risk signals
· Adults repeatedly initiating private contact with young users or moving them to less moderated channels.
· Rapid escalation from public interaction to secrecy, sexual content, gifts or financial exchange.
· Attempts to obtain a young person’s location, school, private contact information or images.
· Repeated contact after blocking, account cycling or coordinated harassment.
· Age ambiguity combined with sexualised interaction.
· Requests to keep contact secret from parents, carers or moderators.
7. Children and teenagers: safer by default
The UK safety framework has shifted firmly toward platform responsibility. Under the Online Safety Act, services likely to be accessed by children must assess risks and put proportionate protections in place. Ofcom’s 2026 material emphasises effective age assurance, anti-grooming measures, safer recommender systems and stronger protections against harmful content. Privacy law also requires child-appropriate design rather than assuming children can manage adult-style privacy choices.
· Use high-privacy defaults for young users and limit discoverability by unknown adults.
· Restrict unsolicited direct messaging and risky friend/contact recommendations.
· Avoid public display of precise location, school or activity routines.
· Make reporting and blocking understandable to the child, not only to the parent.
· Design livestreaming and private messaging as higher-risk features requiring stronger safeguards.
· Give parents/carers clear, specific information without covertly turning the child into a surveillance target.
· Reassess risks whenever a platform adds significant new features such as AI agents, live voice, spatial tracking or commerce.
|
2026 UK CONTEXT Ofcom reported in July 2026 that age checks were being deployed at unprecedented scale, while also warning that the job was not done and that some age-inference approaches remained questionable. |
8. AI companions, agents and synthetic relationships
- AI systems are moving from tools toward social actors: companions, tutors, guides, moderators, game characters and pseudo-therapeutic agents. This creates a distinctive safety problem because the user may emotionally interpret fluent language as evidence of understanding, loyalty, authority or consciousness.
Minimum safeguards for an AI agent
· It should be unmistakably labelled as AI and should not impersonate a human user.
· It should not claim professional qualifications or authority it does not possess.
· It should not ask users for money, passwords, secrets, sexual material or off-platform contact.
· It should not manipulate a user to continue the relationship or imply abandonment if the user leaves.
· It should explain, in accessible language, whether conversations are stored, reviewed or used to improve systems.
· High-risk conversations should have appropriate human escalation pathways rather than relying on the agent alone.
· Children require substantially stronger safeguards; current evidence raises particular concerns about emotional dependency, sexual content, privacy and crisis handling in companion-style AI.
9. Safety inside immersive and avatar-based spaces
Immersive environments can make online interactions feel physically immediate. Harassment may become spatial: following, surrounding, blocking a route, shouting at close range, unwanted gestures, sexualised avatar behaviour or haptic contact. Research on metaverse users has documented unwanted contact, sexually explicit spaces and unwanted haptic experiences. Safety tools therefore need to work at the speed of the event.
Essential user controls
· Instant mute and block accessible without leaving the scene.
· A one-action personal-space or safety-bubble control.
· Immediate teleport/leave/return-home action.
· Per-user voice volume and proximity controls.
· Clear recording/evidence rules and privacy-respecting incident capture where lawful.
· Ability to prevent blocked users from re-entering through alternate accounts or invitations where feasible.
· Controls suitable for keyboard/mouse, controller, mobile and VR, not only one interface.
Spatial and biometric privacy
Voice, head movement, hand movement, gaze, body position, room mapping and interaction patterns can become sensitive behavioural data. A privacy-preserving immersive platform should collect only what the feature needs, retain it for the shortest useful period and avoid silently converting behavioural data into hidden personality, vulnerability or advertising profiles.
10. Harassment, hate, stalking and coordinated abuse
Online harassment ranges from isolated insults to persistent stalking, threats, doxxing, sexual harassment, hate campaigns and coordinated attacks. The response should be proportionate to the pattern and risk. Repeated contact across accounts, knowledge of home/work routines, credible threats, threats involving weapons or children, impersonation, publication of private information and attempts to mobilise others are more serious than a single unpleasant message.
If targeted
- Prioritise immediate safety. Leave the space or stop responding if engagement is escalating risk.
- Preserve evidence before blocking if it is safe: screenshots, usernames, URLs, dates, transaction records and message history.
- Block/mute and tighten privacy and account recovery settings.
- Tell someone outside the online conflict, particularly where threats or coercion are involved.
- Report through the platform. For serious threats, stalking, sexual offences or fraud, use the appropriate external authority or specialist service.
- Do not retaliate by publishing private information or attempting vigilante identification.
- Scams: how modern social engineering works
The strongest scams are behavioural rather than technical. They exploit urgency, authority, affection, fear, scarcity, embarrassment and the desire to help. AI increases the volume and personalisation of these messages, but the underlying psychological levers remain familiar.
|
Pressure tactic |
Typical wording |
Safer response |
|
Urgency |
Do this now or the account will close |
Pause. Open the service independently. |
|
Authority |
I’m from your bank / police / IT team |
End contact and use the organisation’s published contact route. |
|
Affection |
If you loved/trusted me, you would… |
Treat emotional pressure as a warning, not proof of intimacy. |
|
Secrecy |
Don’t tell anyone; it will ruin the deal |
Consult someone independent before acting. |
|
Scarcity |
Only today / exclusive group / guaranteed return |
Assume high-pressure investment claims are unsafe until independently verified. |
|
Fear / shame |
Pay or I’ll expose you |
Do not pay; preserve evidence and seek specialist help. |
12. Neurodiversity, impulsivity and vulnerability without stigma
Safety guidance should not imply that neurodivergent people are inherently poor judges of character. However, any person can become more vulnerable when they are lonely, sleep-deprived, distressed, intoxicated, highly excited, financially pressured or strongly seeking acceptance. Some ADHD-related patterns — rapid responding, novelty seeking, impulsive spending, intense focus on a new relationship or sensitivity to rejection — can make deliberate pause mechanisms useful. Autistic users may prefer explicit rules and predictable boundaries, while ambiguity or manipulative social inference can create difficulty for some individuals.
· Use a 'pause before payment' rule for new contacts and high-emotion situations.
· Discuss major online financial decisions with an independent person.
· Turn off non-essential notifications if constant contact is driving impulsive responding.
- · Use written boundary rules: what information, money, images or access you never share online.
· Do not frame exploitation as the victim having been 'naive'; sophisticated manipulation can deceive highly experienced people.
13. Platform responsibility: safety by design
A serious online-safety model cannot rely on users reading advice. Architecture determines exposure. Who can contact whom? Can strangers locate minors? Can a blocked user immediately return? Can an AI agent masquerade as a person? Are financial requests, external links or sexual content treated as higher-risk interactions? Does the platform collect more data than it needs? These are product questions as much as moderation questions.
Design principles
· Private-by-default where exposure is not necessary for the feature.
- · Data minimisation: collect only what is needed and define retention/deletion clearly.
· Clear labels for humans, AI agents, moderators and automated messages.
· Fast mute, block, teleport and exit controls available during active interaction.
· Friction around suspicious links, financial solicitation and repeated unsolicited contact.
· Strong protections around minors, age ambiguity and cross-age messaging.
· Escalation to human review for serious safeguarding, threats, sexual exploitation and identity abuse.
· Evidence-preservation processes that are lawful, proportionate and understandable.
· Transparent consequences and appeals rather than invisible moderation.
· Safety testing in the real interface, including controller/VR usability and high-stress scenarios.
· Risk reassessment before major new features or significant changes are launched.
A simple incident model
|
Level |
Example |
Immediate control |
Platform response |
|
1 — Unwanted |
Annoying contact, mild incivility |
Mute / leave |
User controls; pattern detection if repeated |
|
2 — Harassing |
Repeated abuse, following, sexualised behaviour |
Block / teleport / report |
Review, restrictions, anti-evasion controls |
|
3 — High risk |
Threats, stalking, grooming, sextortion, doxxing |
Leave, preserve evidence, escalate |
Priority human review; preserve relevant records lawfully |
|
4 — Immediate danger |
Credible imminent threat or serious safeguarding emergency |
Exit and seek real-world help |
Emergency protocol and lawful external escalation where appropriate |
14. If something has already gone wrong
People often delay asking for help because of embarrassment, especially after romance fraud, intimate-image abuse or a relationship that others had questioned. That delay benefits the offender. The practical priority is to limit further harm.
- Stop further payments, transfers, image sharing or disclosure of credentials.
- Preserve evidence before deleting messages or accounts where safe.
- Secure the affected email, financial and social accounts; change compromised credentials and revoke unknown sessions.
- Contact the bank/payment provider immediately for financial fraud.
- Report the account/content to the platform and use appropriate specialist reporting routes.
- Tell a trusted person. Isolation makes coercion easier.
- Where there is immediate danger, credible threat, stalking, child safeguarding concern or serious sexual exploitation, use the appropriate emergency or law-enforcement route.
|
SEXTORTION Do not keep negotiating in the hope of buying deletion. Do not send more images. Do not assume payment ends the threat. |
15. A 60-second safety check before acting
|
IDENTITY |
Have I independently verified who this is? |
|
URGENCY |
Why must this happen now? What changes if I wait 20 minutes? |
|
SECRECY |
Am I being told not to tell anyone? |
|
MONEY |
Is a new social/romantic contact asking for money, crypto, gift cards or an investment? |
|
INTIMACY |
Would I be safe if this image/message became public? |
|
LINKS |
Can I reach the service independently instead of using this link/QR code? |
|
LOCATION |
Am I revealing where I live, work, study or regularly go? |
|
AI |
Could the voice, image, video or account be synthetic or impersonated? |
|
BOUNDARIES |
Has the person respected 'no', delay and disagreement? |
|
EXIT |
Do I know how to block, leave, report and preserve evidence? |
16. Quick guidance by context
For adults using dating apps
· Keep control of transport and meeting location; tell someone where you are.
· Verify independently before financial or highly intimate decisions.
· Treat investment proposals, emergency loans and secrecy as major red flags.
· Remember that video is useful but no longer definitive proof of identity.
For parents and carers
· Keep communication open enough that a child can disclose a mistake without expecting humiliation or automatic loss of all devices.
· Understand the platforms, games and messaging features they actually use.
· Prioritise stranger contact, private messaging, livestreaming, sexual coercion and location disclosure as higher-risk areas.
· Use technical controls as one layer, not a substitute for conversation and platform responsibility.
For professionals and community moderators
· Look for patterns of coercion and repeated contact, not only individual pieces of content.
· Have a clear route for safeguarding, financial fraud, intimate-image abuse and credible threats.
· Do not ask victims to repeatedly retell distressing events when evidence already exists.
· Use proportionate confidentiality and data-retention rules.
For Miniverse designers
· Design the emergency exit before the social feature.
· Separate identity, presence and discoverability controls.
· Label AI explicitly and prevent AI-human ambiguity.
· Test blocking and safety controls under realistic pressure, including VR/controller use.
· Treat each new capability — voice, payments, livestreaming, AI, private rooms, haptics — as a new risk surface.
17. What is changing next
The next phase of online safety will be shaped by stronger age assurance, AI-generated identity, agentic systems capable of acting on users’ behalf, increasingly realistic real-time voice/video synthesis, wearable and spatial computing, and regulation that expects measurable risk reduction rather than policy statements alone.
· Passkeys and phishing-resistant authentication are likely to become normal rather than optional.
· Deepfake detection will help but cannot replace independent verification because detection and generation will continue to co-evolve.
· Platforms will face increasing pressure to distinguish adults from children without creating excessive privacy intrusion.
· AI agents will require clearer identity, data-use and behavioural boundaries.
· Immersive systems will need safety controls that account for proximity, spatial harassment, haptics and biometric/behavioural data.
- · Safety governance will increasingly be judged by outcomes: whether risky contact, harmful recommendations and repeat offenders are actually reduced.
Sources and further reading
- Selected current sources used to update and consolidate this guide. Access dates: August 2026.
Ofcom — Protection of children duties under the Online Safety Act — ofcom.org.uk ↗
Ofcom — Online safety regulatory documents and guidance — ofcom.org.uk ↗
Ofcom — Use of Age Assurance Report 2026 — ofcom.org.uk ↗
Ofcom — Tech firms commit to stronger anti-grooming measures — ofcom.org.uk ↗
Ofcom — Children who create and view livestreams — ofcom.org.uk ↗
ICO — Age Appropriate Design Code / Children’s Code — ico.org.uk ↗
NCSC — Password managers and passkeys — ncsc.gov.uk ↗
- NCSC — Passkeys: more secure than traditional ways to log in — ncsc.gov.uk ↗
NCSC — Sextortion scams — ncsc.gov.uk ↗
FBI IC3 — 2025 Internet Crime Report — ic3.gov ↗
eSafety Commissioner — Deepfakes — esafety.gov.au ↗
- eSafety Commissioner — The metaverse: experiences in virtual reality — esafety.gov.au ↗
eSafety Commissioner — Digital use and risk among children aged 10–15 — esafety.gov.au ↗
stopncii.org ↗ — Preventing non-consensual intimate image sharing — stopncii.org ↗
NCMEC Take It Down — Help with intimate images taken under 18 — takeitdown.ncmec.org ↗
Editorial note
This is general educational information, not individual legal, safeguarding, cybersecurity or medical advice. Laws, platform rules and reporting systems change. For serious incidents, use the current official guidance and reporting route in the relevant jurisdiction.