Need help dealing with violent or distressing online content? Learn more

Responses to transparency notices: Online game and gaming-adjacent services

This page focuses on findings from transparency notices given to online game and gaming-adjacent services.

By giving notices and information requests to online service providers, eSafety can obtain information about their compliance with the Basic Online Safety Expectations. Notices are enforceable, backed by civil penalties and other enforcement mechanisms, and can require non-periodic reporting (one-off reports) or periodic reporting (multiple reports).

eSafety can publish summaries of the information received under notices, improving industry’s transparency and driving accountability.

On this page:

October 2026 report (non-periodic)

This transparency report summarises the response to the notices given on 1 April 2026 to three online game services providers and one gaming-adjacent service provider, respectively: Roblox, Mojang Studios (Minecraft), Epic Games (Fortnite), and Valve (Steam and Steam Chat).

eSafety chose these services due to their popularity among Australian children and users. Issuing a notice does not necessarily mean that a company has deficient safety practices, nor does it indicate, in itself, eSafety’s views or levels of concern with that company’s compliance with the Expectations. However, large providers of online games, especially those with a high concentration of children, can carry a higher risk of children coming into contact with harmful material or activity online.

The notices required these providers to report on how they’re meeting the Basic Online Safety Expectations and steps they’re taking to protect children from child sexual exploitation and abuse, violence material and activity, cyberbullying and online hate. Children should be able to enjoy these benefits of online games without being exposed to these harms. 

In publishing this report, eSafety expects industry members to learn from each other and make concerted efforts to uplift the safety of children play games online, taking a best practice approach to meeting the Basic Online Safety Expectations. 

Read the key findings

Click or tap on the + to find out about the key findings from this transparency report.

The following points outline some of the key findings from the Notices, including steps taken by the service providers to detect and address harms to users.

The service providers took different approaches to preventing high-risk games from being accessible through their services. Left unchecked or unmoderated, there is a risk that these games could contain unlawful material or serve as high-risk environments for child sexual exploitation and abuse or activity which promotes, incites or instructs in matters of crime or violence.

  • Epic Games undertook a comprehensive review of every game (‘Island’) before it became accessible on Fortnite, whereas Roblox employed several tools to detect harmful, user-created ‘Experiences’ after they were published.
  • In Minecraft, players self-declared as 18 or older could access and play in Minecraft ‘worlds’ (servers) which were hosted by third-parties and were not proactively moderated by Mojang Studios. Mojang Studios relied on proactive scanning and user reports to detect third-party servers which were high risk for violence material and activity and for child sexual exploitation and abuse.  
  • While Valve did have review processes in place to detect games containing unlawful material, including material related to CSEA or pro-terror material, prior to publication, it relied solely on user reports to identify published games which contained unlawful material.

While most of the service providers employed tools to proactively detect unlawful and harmful material and activity within the services, the quality and coverage of these tools varied across each service. eSafety expects the online games industry to raise the bar to identify and combat serious harms such as child sexual exploitation and abuse, sexual extortion, and material and activity which promotes, incites, or instructs in matters of crime or violence.  

  • Unlike the other service providers, Valve did not use any hash-matching tools on Steam and Steam Chat. Hash-matching tools allow service providers to identify and remove material previously confirmed to be child sexual exploitation and abuse material or violence material on a service without this material having to be repeatedly re-analysed and re-viewed across services and jurisdictions.
  • Unlike the other service providers, Valve did not use tools to proactively detect harms in text or voice chat on Steam Chat, including Steam Community group chats, outside of a URL detection tool that ‘mainly blocked scams’. This left all chats on Steam Chat with limited protections from child sexual exploitation and abuse material and activity, and from violence material and activity.
  • Roblox and Valve relied solely on internal data sources to train the language analysis models used on Roblox and Steam. Roblox did not frequently update several of its tools against this data and Valve did not update this data regularly after initial training. Mojang Studios used external keyword lists related to violence material and activity to train the language analysis models it used on Minecraft but did not use any external keyword lists related to child sexual exploitation and abuse. By contrast, on Fortnite, Epic Games used both internal data and synthetically generated data which used ‘seed’ keywords and phrases from external keyword lists for its language analysis tools monitoring player chats.
  • Roblox’s ‘Image Auto-mod’ tool, which it used to detect violence material and child sexual exploitation and abuse material on all images on its service, had a recall rate of only 51%. Low recall can indicate under-enforcement by a tool, which can be a safety risk.

There was significant variation between the service providers in their participation in cross-industry information-sharing initiatives, including well-established initiatives to counter terrorism and child sexual exploitation and abuse. Online games and gaming-adjacent services are deeply interconnected, and moving between them is an ordinary part of the user experience. Information-sharing initiatives enable providers to identify new risks that arise from this and mitigate them more quickly than if they were acting alone.

  • For Minecraft, Mojang Studios participated in a number of information-sharing initiatives with industry groups, including the Thriving in Games Group, Lantern and The Global Internet Forum to Counter Terrorism (GIFCT).
  • Roblox shared signals with Lantern and worked directly with Discord to share information on trends in child safety and violent extremism.
  • For Fortnite, while Epic Games received URLs from the Internet Watch Foundation and Tech Against Terrorism, it did not participate in the ‘Lantern’ initiative, and did not share signals about breaches related to child sexual exploitation and abuse with other service providers through similar initiatives.
  • For Steam and Steam Chat, Valve did not participate in any information sharing initiatives.

Some of the service providers used fewer indicators than others to detect players who had been banned or suspended for offences related to child sexual exploitation and abuse or to violence material or activity. The fewer indicators used, the more likely it is that perpetrators can return and continue to carry out harms such as child sexual exploitation and abuse, sexual extortion, and activity which promotes, incites or instructs in matters of crime or violence.

  • Where Mojang Studios, Roblox and Epic Games used multiple indicators to detect users who had re-registered (or attempted to) with new details after being banned or suspended for child sexual exploitation and abuse or violence material and activity related offences, Valve used minimal (a small number of) indicators for detecting such users.

The level of age assurance was highly variable across the different services. If services do not know the age of their users, they cannot apply appropriate age-based protections that help guard against harms such as child sexual exploitation and abuse, sexual extortion, and activity which promotes, incites, or instructs in matters of crime or violence.

  • Despite having a range of protections in place for child accounts, Epic Games and Mojang Studios relied on users to self-declare their age at sign up to play Fortnite and Minecraft. Players who self-declared as 18 or older were able to access some high-risk features without additional age assurance checks, including:
    • chats with players self-declared as 18 or older which would not be subject to Epic Games’ default suite of safety tools for private text chats that include children  
    • access to chat with players of all ages (other than child accounts) which had communications features off by default on Minecraft
    • access to unmoderated Minecraft servers hosted by third-parties, which can be higher risk for unlawful and harmful activity.
  • During the report period, Valve relied on users to self-declare their age at sign up for both Steam and Steam Chat and did not collect any age-related information at all.*
  • From 3 December 2025, Roblox started using more robust age assurance measures, including limiting access to certain high-risk features on the service to Australian users identified as 18 years and older (irrespective of the self-declared age of the user). These measures followed eSafety’s engagement with Roblox on its obligations under Australia’s Online Safety Codes and Standards.

Some of the service providers took longer than others to respond to user and automated reports of specific harms. This can leave users exposed to serious harms for longer when platforms are aware that users are at risk.

  • On average, Mojang Studios had longer median times to respond to user reports of unlawful and harmful activity on Minecraft compared to other providers.
  • Across all the service providers, Epic Games took the longest time (18 hours and 53 minutes) after receiving automated reports of unconfirmed child sexual exploitation and abuse material and activity other than grooming and sexual extortion to assess whether these reports were violative.

The service providers varied in their approach to resourcing trust and safety teams. Having teams with sufficient capacity and expertise to address a range of online harms – and a working knowledge of various languages and cultural specificities – is essential to maintain a safe environment for users.  

  • Epic Games had the highest ratio of trust and safety staff to end-users, and reported having a specialist investigative team of five full-time investigators and three contracted investigators globally, who addressed all reports of high-harm risk, including sexual extortion and grooming.  
  • Mojang Studios had a limited number of human moderators, even taking into account its reliance on Xbox and Microsoft trust and safety teams to address issues. Mojang Studios’ moderators also did not operate in any language commonly spoken in Australia apart from English.
  • Unlike the other service providers, Valve had no dedicated trust and safety staff other than content moderators and engineers.

 

* The Age-Restricted Material Codes create new obligations which primarily focus on preventing children’s access or exposure to age-inappropriate content, including high-impact violence, across the 8 sections of the online industry. Under the App Distribution Services Online Safety Code (Class 1C and Class 2 Material), companies including Valve are required to ensure that from 9 September 2026, games on their stores that are classified R18+ are not able to be purchased or downloaded by Australian children. As of 9 September 2026, Valve started to require users in Australia to provide credit card verification to access R18+ games.

 

eSafety research and resources

This report follows eSafety’s previous research into children and online gaming in 2024, which found that:

  • 89% of children aged 8 to 17 had played online games in the past year.
  • 79% have played a multiplayer online game with others.
  • 40% have played online with people they did not know offline.

To support families, eSafety offers a range of gaming and online safety resources, including eSafety Gaming Toolkit, which provides practical advice on Getting Started, Gaming Together, Going Online, Playing with Others, How to Manage Money in Games and Sharing Safely. The toolkit also includes tailored support for children with disability and neurodivergent gamers.

Additional resources include eSafety’s gaming club guide for schools, being neurodivergent online, and research on the online gaming experiences of young people with disability.

Parents and carers can also access resources for kids and young people, including Mighty Heroes, an interactive game that helps children build online safety skills. Playing games together can be a great way to connect with your child, open conversations about their experiences online and help them to understand online safety.

About transparency notices

Under section 49(2) of the Act, eSafety can give periodic notices requiring service providers to report at regular intervals on their compliance with the Expectations.

Under section 56(2) of the Online Safety Act 2021 (the Act), eSafety can give non-periodic notices requiring service providers to report on their compliance with the Expectations.

Under section 20 of the Online Safety (Basic Online Safety Expectations) Determination, eSafety can request certain information from a service provider by written notice and a provider is expected to comply with the request within 30 days after the notice of request is given.

Published reports by eSafety

Read more responses to transparency notices on: