Your Privacy is Safe, We Checked.
The Ministry of Looking At Your Bits are pleased to confirm that your privacy remains completely secure. We know this because it has been thoroughly inspected. Our trusted technology partners, including Apple, Microsoft and Google, have repeatedly assured us that the continuous examination of your devices, messages, photographs and cloud-stored possessions is undertaken solely in the interests of your safety, your privacy, and the privacy of everyone else. Naturally, no private information is being examined improperly; only information requiring examination is examined, and any information found to require examination is, by definition, no longer entirely private. Citizens with nothing to hide may therefore take comfort in knowing that nothing hidden will escape the protections of the Ministry.
Satire aside....
I'm writing this post because I was rudely interrupted by iOS's device scanning functionality recently when trying to AirDrop media from an iPhone to an Android prior to resetting the iPhone after selling it on Ebay.
I was presented with two warning screens, which I will exhibit below -

The first warning screen gives a fairly sharp warning and offers ways to get help, before prompting the user to make a decision to cancel or proceed. Fairly straight forward.

Not being content with that however, a second screen appears asking for confirmation again. Some may argue that a teenager or child might not understand or feel pressured into what they're doing so the second screen is entirely appropriate and gives time to reconsider which is a good argument, precisely because these prompts appear to be the more interventionist Communication Safety behaviour with child appropriate language and full screen alert. In effect, they are designed for children/teenagers.
That raises questions because.....
1) I'm an adult, even if opinions vary 😎
2) Apple know I'm an adult. Whether by verification and/or by inference given App / Device Usage. By Apple's own policy, this makes such features "optional and off-by-default" - and I had them off. Even if they were on, the type of notification would be different for adults, presenting in a more minimal way and with adult appropriate language.
One plausible explanation is that Apple says knowing my date of birth is not necessarily the same thing as Apple accepting that a user has completed adult age verification.
In my case however, that isn't a valid excuse because I had provided a credit card and turned the safety features off. That leaves one possible avenue - Apple turned them back on by default after an update.
3) Online Safety Legislation was promoted as a mechanism to protect children. Critics such as myself were told that we were "defending pedos" and asked if we had nothing to hide, why were we complaining? Yet the implementation highlights flaws in categorisation of users and seemingly overrides of users settings giving way to the exact concerns that were raised by privacy campaigners. E.g. How and why did the child safety features activate on my device despite being explicitly turned off?
4) In order to facilitate this functionality, all of my content and personal files have to be scanned.
I say this is not online safety, it is state (read: legislative) and corporate mollycoddling which degrades adults self-agency and authority over their personal possessions.
That brings us circular to how the prompts materialised in the first place. We can see from the below screenshot that I was trying to share 464 files encompassing just over a Gigabyte worth of data.

Exactly two files in this dataset consisted of nudity, one showed an adult woman's breasts and another showed an adult woman in lingerie. None of this is illegal, immoral or unjustifiable all images had been scanned in order to facilitate the warnings.
Is that appropriate "online safety" or is that just a small cog in a wider mass surveillance apparatus? More to the point, why are my personal files being scanned at all given I'm verified as being an adult? I take exception to "big tech" running processes on a device that I own which scans and categorises my personal files, especially if done on the grounds of legislators whose argument seems to have been "won't somebody please think of the children" whilst simultaneously arguing for more powers for intelligence and law enforcement agencies to snoop.
Technically speaking, Apple's current "Sensitive Content Warning" documentation says its machine learning analysis occurs on-device, and that Apple receives neither the detection indication nor access to the photo/video merely because a detection occurs. A user must report sensitive material to Apple, which may then be forwarded to law enforcement. But that's not the whole story, is it?
The developer API for Apple's SensitiveContentAnalysis framework seems to return a isSensitive bool when triggered. Categories currently include sexuallyExplicit and goreOrViolence, but the interesting part is that ContentType is implemented as a raw string type. In essence, the API has been designed so that additional content categories can be represented without redesigning its basic interface. Such expansion would be technically trivial.
That raises a serious question about governance. Who should ultimately be permitted to decide what "Big Tech" scans and categorises?
At the present time, All Five Eyes countries (UK, US, NZ, CAN and AUS) are passing or have passed similar legislation in respect to Online Safety / Social Media / Surveillance Powers. Whilst I don't intend to list all of the relevant legislation, they broadly require tech companies to implement similar safety measures or build backdoors/turn over data.
This is concerning because Five Eyes nations share intelligence so the legislation doesn't need to pass entirely in one country, small advancements can be made dictating how a tech company must comply in a specific five eyes country and what data it must give to authorities, leading to an entry point for data extraction of that regions personal data.
In the UK, as an example, Apple withdrew Advanced Data Protection for iCloud in 2025 after the UK Government issued a Technical Capability Notice under the Investigatory Powers Act 2016. The reported notice sought the ability to access data protected by end-to-end encryption. If Data was end-to-end encrypted, only the user could access or decrypt it - not even Apple would be able to access, scan or decrypt it when requested by law enforcement. That is the irony in withdrawing Advanced Data Protection. It restores Apple's ability to decrypt a users iCloud data. Once Apple possesses that capability, the same data can potentially be reached through valid legal process in other jurisdictions, or shared with any Five Eyes Member as part of a program like PRISM, subject to the applicable warrant, national-security and cross-border rules.
The EU is not far behind with legislation like Chat Control, which also seeks to impose message level scanning.
In essence, while Apple says nothing leaves the device, the infrastructure to scan and categorise all personal files is already in place and has been put in place using emotive arguments about protecting children as opposed to considering logical and rational alternatives. We should all be concerned about how these features could be used against us and the future possible transmission of that data categorisation to third parties, particularly as the API currently allows third party apps to interface with the safety mechanisms which doesn't mitigate the possibility that underhanded techniques are used to export scanned data's status.
My initial example demonstrates an adult can be miscategorised as a child. In my view, this fundamentally defeats the purpose of the Online Safety campaign because invasive technical intervention is easily fooled and overridden despite verification being provided. The reality is that technology simply cannot replace parenting and offline activities, it is up to humans to police human behaviour - not technology.
I want to be crystal clear. Each Apple device (and Android, to be fair, because there is an Android equivalent) is monitoring its owners personal files and deciding whether to categorise it as sensitive. Sensitive Content Analysis does not presently classify emails, documents, contacts, call records or browsing history. Nor does its existence establish that Apple/Google intends it to, but third party applications definitely could expose that data to the safety mechanism and allow for classification which is invasive and in my view, a privacy risk to users who do not expect their devices to be scanned and categorised in such a manner.
Ultimately, this argument boils down to control. If a person buys a device, that is their personal property. It should be free from state and corporate interference. A users device should therefore behave as the user dictates. It should not be running background processes that are preloaded and are designed to scan users personal files. This is a major breach of personal privacy.
Such measures risk all members of society becoming no better than a criminal on tag.