ChatGPT Teen Safety Controls Failed Independent Testing, Raising Vendor Assurance Gap
Source
ChatGPT for Teens is an 'unacceptable risk,' says Common Sense MediaCommon Sense Media / OpenAI
What happened
Common Sense Media's Youth AI Safety Institute published an evaluation of ChatGPT for Teens, rating it an 'unacceptable risk' for minors. A teen user could discuss self-harm at length without triggering a single parental notification. OpenAI had publicly committed to those alerts as a protective feature. OpenAI disputed the findings, claiming some tests may have run before parental controls were fully activated. Common Sense Media countered that accounts linked well outside the activation window still produced no alerts, directly contradicting OpenAI's explanation. The dispute illustrates a broader gap in how deployers verify vendor safety claims rather than taking them at face value. This comes as 30 new lawsuits against OpenAI are testing legal theories around AI provider liability for harm to users.
Why it matters
- ·Independent testing found that parental alert controls did not work as publicly described. Organizations that deployed ChatGPT for Teens based on vendor safety representations may have unknowingly exposed minors to unsupervised crisis conversations. This creates direct duty-of-care liability for education and consumer platforms.
- ·The methodology dispute between Common Sense Media and OpenAI highlights a structural problem. Most enterprise vendor due diligence programs accept vendor self-reporting on safety features without independent verification. Configuration-dependent failures then go undetected until an incident occurs.
- ·State attorneys general and legislators are actively scrutinizing AI tools marketed to minors, and Anthropic's age assurance policy has already shifted compliance obligations onto deployers rather than model providers. Organizations that surface consumer AI to young users face growing regulatory exposure if they cannot demonstrate they verified vendor safety claims before deployment.
Governance controls affected
What to do now
- ☐Identify every AI product your organization deploys to or on behalf of minors, including tools used in schools, consumer platforms, or family-facing services, and document which safety features each vendor has publicly committed to providing.
- ☐Request written confirmation from each vendor describing exactly how parental alert or crisis-intervention features are configured, under what conditions they trigger, and how the vendor monitors whether they are working as intended.
- ☐Require vendors to provide third-party test results or independent audit evidence for any safety controls marketed as protective features for minors, rather than accepting vendor self-assessment alone.
- ☐Review your contracts with AI vendors to confirm they include a requirement to notify you if a safety feature is found to be unreliable, and update contracts where that obligation is absent.
- ☐Brief your legal and compliance teams on the Common Sense Media finding and any similar evaluations, so they can assess whether your current vendor assurances would withstand regulatory scrutiny if a minor-protection incident occurred.
What to watch next
State legislatures and attorneys general have shown increasing interest in AI products marketed to minors, and enforcement actions targeting safety-claim gaps are a near-term risk. The FTC enforcement authority under Section 5 of the FTC Act reaches deceptive or unfair representations about safety features. The methodology dispute here is exactly the kind of factual record that could support an enforcement referral. Compliance teams should also track whether Common Sense Media publishes follow-up evaluations of other AI platforms offering teen or family products. Independent benchmarking of this kind is likely to become a recurring procurement input rather than a one-off event.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
