Safety & Design
Safety by design
Building protections into a product from the start, such as who can see a child's chat, instead of adding a safety setting after people get hurt.
- Businesses
- Policymakers and staff
What parents should know
Safety by design means the safe path is the one the product starts with. A parent account, a limit that is already on, and a record an adult can read are design choices. A kids mode bolted onto a general chatbot later is a patch. Ask which one you are buying.
On this page
What is safety by design?
A patch reacts. A design decision chooses the default before launch: who creates the account, what the child can publish, what the model will not do, and who is told when something looks like distress. NIST's AI risk work treats these as controls you plan, test, and keep, not as a footer on a marketing page.
For children's products, safety by design overlaps age-appropriate design and privacy by default. The protective setting should not depend on a parent finding a submenu. If the child can open a second account you cannot see, the safe default on the family profile does not cover that other login.
Why safety by design matters
Harms that show up in the news were often possible on day one. Companion apps that parents cannot open, public uploads with no approval, and chats used to train models are design outcomes. They are expensive to unwind after a million accounts exist.
Buyers, including schools and brands, should ask for the default, not the promise. What is on when nobody changes a setting? Who is the account holder? What happens in distress, and what does the product refuse to do, such as calling emergency services on its own?
How it shows up in practice
- A new child profile starts with a parent as the owner and public sharing off.
- Topic limits exist before the first scary chat, not only after a complaint.
- A general chatbot adds a kids toggle that does not show parents the transcript.
- A company writes down the distress path, including what it will not automate.
How HeyOtto helps
Safety by design means the protective path is the default, not a patch added after harm. HeyOtto starts as a family product: a parent creates the account for ages 8–18, and the child does not self-enroll. There are no ads. Chats are not sold and are not used to train other models. Public sharing waits for parent approval. Distress produces an alert and crisis resources in the chat, and HeyOtto does not auto-contact emergency services.
- Under 13, verifiable parental consent is part of setup.
- Topic limits and tool permissions are per child.
- Public sharing of a project waits for parent approval.
For families
Try freeFAQs
Is a kids mode safety by design?
Only if the kids mode is the product, with a parent account and a record you can read. A toggle on a general bot, with the same hidden chats, is a patch. Ask who creates the login and who can open the transcript.
What should be true on day one?
A parent or school as the adult, limits that start on, no ads aimed at the child, and a written path for distress. HeyOtto starts with the parent account, no ads, and alerts that do not call emergency services by themselves.
Does safety by design mean nothing can go wrong?
No. It means the foreseeable harms were designed for, tested, and given an adult a way to see what happened. Guardrails miss prompts. You still want the transcript.
Who is this for besides parents?
Brands and venues that want to offer AI to kids, and policymakers comparing a default with a disclaimer. The design question is the same. What happens when nobody opens the settings?
Sources
Last reviewed September 26, 2026. This entry is reviewed twice a year.
