top of page

Rapid sign-up, autoplay & infinite scroll: Livestreaming’s Safety Problem Starts With the Product Brief

4 hours ago
4 min read

Ofcom’s latest audit of livestreaming services is not principally a story about settings menus. It is evidence of a deeper product-management choice: platforms have made the routes to attention, interaction and spending highly visible, while making many safety actions comparatively easy to miss.


That distinction matters commercially as much as it matters regulatorily. In live environments, there is no leisurely period in which a user can consider their options. The experience is immediate, social and often emotionally charged. A safety control that is technically available but hidden behind an icon, a submenu and several additional clicks is not equivalent to one that is present at the moment a risk occurs.


Ofcom’s behavioural audit, published on 9 September, looked at the user journeys on Instagram, TikTok, Twitch and YouTube. It found recurring design patterns: rapid sign-up, autoplay, prominent live prompts, frictionless set-up for creators, visible reactions and gifting, and safety tools that were often less prominent or more effortful to use.


The regulator is explicit that this is a snapshot rather than a verdict on every service or journey. Even so, its central finding is difficult for product teams to dismiss. Safety is shaped by the whole choice architecture, not by the mere existence of a reporting button.


In a live service, the most prominent path is usually the path users take.


Engagement has been designed as the default


The business logic of livestreaming is understandable. Live indicators, recommendations, chat, reactions and creator feedback all reduce the distance between viewing and participation. They make an audience feel present rather than passive. For platforms, that can support watch time, creator retention and commercial activity.


Ofcom’s work shows why those features need to be assessed together. Landing pages commonly used autoplay and infinite scroll; visual cues drew attention to live content; and interaction or gifting tools sat immediately within the viewing experience. In some cases, gifting involved an intermediate currency, adding distance between the decision to spend and the amount being spent.


The same momentum was evident for creators. Once eligibility requirements were met, going live could require only a small number of steps. Moderation options could be passed over, while performance summaries reinforced views, followers, likes and progress towards monetisation.


None of these individual features is inherently improper. The issue is cumulative. If every feature that advances participation is salient and every feature that enables caution is optional, buried or delayed, the platform is no longer neutral about the choices it is making easier.


For brands and agencies using live formats, the lesson is relevant too. A campaign’s immediate engagement figures may reveal little about whether an environment gives audiences meaningful control, particularly younger users. Suitability cannot be reduced to a list of prohibited content categories. It increasingly includes the way a service directs attention and behaviour.


Defaults send a stronger message than guidance


The audit found that creators’ initial settings could normalise low protection. Across the services examined, public visibility was generally the default for livestreams. On two services where this could be verified, moderation tools defaulted to the least restrictive option.


A young person viewing a live video feed on a smartphone while an adult sits nearby


This is where the gap between policy and experience becomes most visible. A platform may publish comprehensive guidance, offer blocking, reporting and moderation features, and still place the practical burden on a user who is trying to manage a fast-moving live interaction. Ofcom found that reporting could take users away from the livestream and involve several steps, while one service alone had an immediately visible report button on its mobile app.


That design has an evidence problem as well as a safety problem. If reporting is arduous, fewer incidents may be reported. Fewer reports can then make a platform’s internal picture of harmful activity look cleaner than the actual user experience. The result is a weak feedback loop: the same architecture that can discourage protective action also limits the intelligence needed to improve it.


Product telemetry should therefore not be treated as self-explanatory evidence of safety. Teams need to ask which incidents go unreported, where users abandon reporting journeys, whether younger audiences can locate protections unaided, and how defaults affect behaviour across different groups.



Regulation is moving from content to functionality


The timing is significant. The Government plans to restrict under-16s from creating livestreams and to switch off livestreaming and stranger-contact functions by default for 16 and 17-year-olds, with the first regulations expected before the end of 2026 and implementation anticipated in spring 2027.


That is a move towards regulating risky functions and persuasive design, not simply individual pieces of content. It changes the questions senior leaders should put to product, trust-and-safety and commercial teams. It will not be enough to show that a policy exists or that a user can find a control after a problem occurs.


They will need to demonstrate how the service behaves before the harm: what it recommends, which settings it applies by default, when it asks for age assurance, whether it interrupts risky momentum, and how quickly a viewer or creator can regain control.


This is a more demanding standard because it makes safety a design constraint from the product brief onwards. But it also offers a clearer route to durable trust. Consumers are increasingly adept at recognising the difference between a feature built to be used and one supplied largely for compliance.


A better brief for live experiences


The practical response is not to make every live interaction cumbersome. Overcorrection can damage legitimate communities, creators and commercial activity. It is to apply friction selectively where the downside of speed is high, and to reduce friction where protection is needed.


That means testing safety routes with the same seriousness applied to conversion funnels. Can a new creator understand moderation choices before going live? Can a viewer report a problem without losing the context required to explain it? Are spending prompts more prominent than safeguards? Do age-based restrictions genuinely change the experience, or merely signal that a feature exists?


These are research questions, not only legal questions. They call for observational testing, behavioural data, qualitative work with relevant age groups and ongoing review of defaults—not a one-off compliance assessment.


Ofcom’s audit makes the commercial implication plain. Livestreaming platforms will be judged not only on what their terms prohibit, but on what their interfaces encourage. The companies that recognise that early can build live products in which participation and protection are not competing afterthoughts.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page