What parental controls actually block
Short answer
Parental controls reliably block known adult sites, app installs and purchases, and they enforce time and bedtime rules. They do not reliably stop contact from strangers inside apps you have approved, content shared in private messages, or anything reached through a friend's unfiltered device. The largest reported risk to children now arrives through direct messages, which is exactly where category filters do not operate.
Parental controls are better than their reputation suggests. They are also solving a smaller problem than most parents assume when they switch them on.
Worth being precise about the boundary, because the gap is where the harm actually happens.
What they do reliably
Category filtering against known adult sites works. App install and in-app purchase gating works. Time limits and bedtime enforcement work, in the sense that the device does what it is told.
If the worry is a nine-year-old stumbling onto pornography through a search result, controls address that fairly well. That was the dominant risk model when this software was designed, and the software still reflects it.
What they miss
The risk has moved into messages, and filters do not read messages.
The National Center for Missing & Exploited Children reported more than 50,000 reports of financially motivated sextortion in 2025, averaging 137 a day, up from more than 36,000 in 2024. NCMEC also recorded 1.4 million reports of online enticement in 2025, a 156% rise on the previous year. The pattern is consistent: an approach through a fake account on a mainstream platform, a request for an image, then immediate demands for money.
Every step of that happens inside an app a parent has already approved. There is no blocked category. No filter fires, because nothing is being filtered.
Three other gaps worth naming:
- The friend’s phone. Controls are per-device. A locked-down phone next to an unlocked one is a locked-down phone in name only.
- Content sent, not sought. A filter evaluates what a child requests. It has no view on what arrives unrequested in a group chat.
- The bypass. Older children find workarounds, and the workaround is usually simpler than parents expect. Several reviewers who test these products for a living make bypass difficulty an explicit criterion, which tells you how routine it is.
Why this is uncomfortable
The honest reading is that controls are strong against accidental exposure and weak against deliberate contact, and deliberate contact is the category doing the serious damage. NCMEC has said it is aware of at least three dozen teenage boys in the United States who died by suicide after being targeted in these schemes.
That is not an argument for removing controls. Accidental exposure is real and worth preventing. It is an argument against treating the toggle as the end of the work.
What closes the gap
The thing that actually protects a child in a message thread is the child. They are the only party present.
Which means the practical work is conversational rather than technical:
- Tell them, in plain terms and before it happens, that an image request from anyone is a stop signal — including from someone they believe they know.
- Make clear, explicitly, that if it goes wrong they will not lose the phone for telling you. Fear of confiscation is the main reason children handle these situations alone, and handling it alone is where the harm compounds.
- Practise the sentence they would use to get out of it. Knowing a rule and having words ready are different kinds of preparedness.
Controls buy time while a child learns that. They do not do the learning.