The region is building online safety architecture faster than it has ever built anything digital, and measuring almost none of what that architecture delivers to the people inside it.
On 29 June this year, Singapore’s Online Safety Commission opened for business, giving victims of online harms a dedicated route to relief and putting Singapore among the small handful of countries with a government agency built specifically for the job.
The first phase covers five of the most severe harms: online harassment, doxxing, online stalking, intimate image abuse, and image-based child abuse, and six online service providers have been prescribed additional obligations.
It follows the Online Safety (Relief and Accountability) Act, passed in November 2025.
It is a real milestone, and it arrived considerably faster than most of us working on these questions three years ago expected.
It is also, for the moment, an institution operating without a way to tell anyone whether it works.
That is not a criticism of the Commission, which is six weeks old.
It is a description of the entire region.
Across Southeast Asia, we (Singaporeans) have become very good at legislating what platforms must do and almost entirely uninterested in measuring what users actually get, and the gap between those two things is where the credibility of the whole project will eventually be decided.
I have a particular vantage point on this.
In 2023, I was appointed to the #TechHacks: Digital Well-Being Youth Panel, convened by the National Youth Council and the Ministry of Culture, Community and Youth under Forward Singapore, as part of a new attempt to give young people a seat at the policymaking table rather than a slot on a feedback form.
Before that, I spent four years on the other side of the counter, in trust and safety and content policy operations at Meta, Tinder and Amazon, where user reports landed in queues I helped run.
The panel wanted to know whether Singapore’s new safeguards were reaching young people at all, so we commissioned Milieu Insight to conduct a nationally representative survey of 1,000 Singaporeans aged 16 to 34, comprising 26 questions, balanced by age, gender, and race, fielded from 9 to 19 May 2024.
Confidence survives right up to the point of contact.
What came back describes a cliff.
Sixty-seven per cent of respondents knew redress mechanisms existed on social media services. Sixty per cent were satisfied with how easy it was to find information about them. Fifty-four per cent were satisfied with their availability.
Then, among the 301 respondents who had actually used one after being harmed, 16 per cent found it effective.
Approval holds up beautifully in the abstract and collapses the moment anyone touches the system.
That is not apathy, and it is not ignorance either.
Among those who knew the mechanisms existed and chose not to use them, 43 per cent said they were not sufficiently invested in the matter, 42 per cent had little or no confidence in the reporting mechanism, and 37 per cent thought the mechanisms were simply insufficient.
Two of the three leading reasons are verdicts on the system rather than statements about the user, and the Government’s own published response to the youth panels records the underlying finding plainly enough: young people often perceive redress mechanisms as ineffective because there is frequently no feedback or update after a report is made.
Behaviour follows the verdict, and here is where the numbers stop being abstract.
Thirty-six per cent of respondents had personally been a victim of online harm at least once.
Of those, 39 per cent reported it to the platform, and 61 per cent simply blocked or deleted the person who did it.
The most common response to being harmed online in Singapore is to make the other party vanish from view and carry on, which is a private workaround that leaves no record, generates no data, and tells the platform and the regulator precisely nothing.
A further 58 per cent of all respondents had watched harm happen to someone else, so the lesson that reporting is not worth the trouble travels well beyond the people who tested it.
The block button, not the reporting flow, is what redress actually looks like from where most young Singaporeans sit.
None of that surprised the panel.
We had spent months in consultations, and we broadly expected the numbers to land where they did.
What surprised me was the shape of what we were measuring: an architecture that is almost entirely reactive, dependent on a harmed person filing a report into a system that most of them have already concluded will not respond.
The proactive half detecting and preventing harm before it reaches anyone- barely registers in the framework at all, and the survey is a fairly direct account of what happens when you build a reactive system that the people it was built for do not trust.
Who pays for the gap?
The moment from those twelve months I still think about came from a fellow panel member who lives with a disability.
Online harm, he pointed out, is never distributed evenly; it falls hardest on people who are already vulnerable offline, because the same characteristics that make someone a target in a room make them a target in a comment thread.
The point is not novel; the UN makes it about children generally, but it lands differently when the person making it is describing his own inbox.
If the median young Singaporean, the one with no particular reason to be singled out, already finds redress unreliable, then for those in marginalised groups the same broken mechanism is not merely inconvenient.
It is a second harm layered on the first, and it compounds.
That reframed the survey for me.
A 16 per cent effectiveness rating is a policy problem for the general population and something closer to an equity failure for everyone else, and it is invisible in every metric currently collected, because the people it fails hardest are precisely the ones least likely to file the report that would generate a data point.
Why the queue does not answer
The policy literature tends to explain unanswered complaints as a matter of scale: too much content, too few reviewers, imperfect automation.
That is true, and it is not the whole story.
The structural reason, which is obvious from inside the industry and rarely stated outside it, is that trust and safety sits on the wrong side of the ledger.
Platforms understand its importance and say so sincerely; they also treat it as a cost centre, a function that consumes money rather than generates it.
Functions on that side of the ledger get optimised for cost per case, not for whether the person on the other end came away whole.
Proactive investment and the work that stops harm before anyone has to report it are the first things to be trimmed, because their return is a harm that never happened and therefore never appears in anyone’s numbers.
This is not a story about bad intentions.
It is a story about incentives, and incentives do not shift because a regulator asks nicely.
They shift when something a company cares about becomes contingent on the outcome.
Right now, in every ASEAN market, nothing is.
Transparency reporting measures the wrong thing.
It would be wrong to cast Singapore as the laggard here; it is the regional leader by a distance.
IMDA’s Code of Practice for Online Safety, issued in July 2023, requires designated social media services; Facebook, HardwareZone, Instagram, TikTok, X and YouTube, to give users clear information about their safety measures and to file annual online safety reports, which IMDA publishes, and IMDA now layers its own Online Safety Assessment Report on top, grading how comprehensive and effective those measures are.
Very little else in ASEAN comes close.
But look at what that machinery captures, and at what happened when we asked for more.
Our third recommendation was that Singapore adopt an accountability-based approach that would keep platforms answerable for how they handle online harms, a consensus position across the panel, and not, whatever else it was, an aggressive one.
We were explicit that ownership here is shared: government has to legislate and enforce, industry has to invest ahead of the harm rather than behind it, and young people themselves have to keep feeding back, researching and building from the ground up rather than waiting to be consulted.
The Government supported the intent and responded by describing the Code of Practice, under which designated services submit annual reports on the measures, systems, and processes they have implemented, and by pointing to the Online Safety Commission, which is still being drafted.
It also conceded that while the services had baseline user safety measures in place, there were areas for improvement, among them responding more quickly to user reports.
That exchange is the argument of this article in miniature.
Reports about measures, systems and processes are, by construction, platform accounts of platform behaviour.
They are a description of what a company has built, not a record of what happened to the people who used it.
The limits of self-description surface in the regulator’s own findings: in its 2025 assessment, IMDA disclosed that it had detected four cases of child sexual exploitation and abuse material on Instagram, originating from or targeting Singapore users, that were not proactively detected and removed until IMDA flagged them.
The regulator was finding what the platform’s systems had missed, which is exactly the distance between reported process and delivered outcome, and no annual report organised around measures will ever close it.
If I have one regret from the panel’s year, it is that our sharpest asks for transparency about which data both government and industry should put into the open, and in what form, were the ones that thinned out most on the way to the final recommendations.
They were the hardest to specify, and the easiest to soften, and softening them is why an accountability recommendation could be answered with a description of a reporting regime already in place.
That is a fair outcome for a first attempt, and the Prime Minister’s undertaking that youth recommendations would be seriously considered was honoured in substance.
It is still the piece I would go back and fight for.
The same omission, three ways
Widen the lens and the omission repeats in different costumes.
Malaysia’s Online Safety Act 2025, in operation since 1 January 2026, is on paper the most demanding instrument in the region on responsiveness: licensed providers must mitigate exposure to harmful content, publish user safety guidelines, maintain reporting and user-assistance mechanisms and prepare an Online Safety Plan, with reports acknowledged within roughly an hour, initially assessed within twelve, and harmful content removed within about a day, and fines of up to RM1 million for missing those clocks.
Nothing in the framework requires anyone to publish how often the clocks are actually met.
Indonesia has gone another way entirely.
Ministerial Regulation No. 9 of 2026, made under PP TUNAS and phased in from 28 March this year, keeps under-16s off platforms assessed as high-risk, permits 13- to 15-year-olds to access medium-risk services with parental consent, and requires electronic system providers to filter harmful content and to offer an accessible reporting mechanism.
The heavy lifting falls to age assurance and parents, and Indonesian commentators have already posed the obvious question: why does the work of fixing these systems fall to children and their families rather than to the companies that designed them?
Vietnam’s Decree 147, in force since December 2024, does mandate reporting, but the reports flow inward.
Platforms above the traffic threshold file annual and ad hoc returns to the ministry and remove flagged content within 24 hours of notification.
The state learns what it wants to know; the user learns nothing.
Three approaches, one shared blind spot. In each case, somebody holds information about how the system performs: the platform, the ministry, occasionally the regulator. In none of them does the person who was harmed ever find out whether people like them get anywhere.
What would close the gap?
1. Publish outcome data, not just measures.
Regulators should require and then publish a short, standard set of figures per platform and harm category: complaint volumes, resolution rates, median times to first response and to resolution, and appeal outcomes.
Ofcom’s transparency regime, the EU’s Digital Services Act and Australia’s periodic transparency notices have already established that this is administrable rather than theoretical.
The objection from industry will be that resolution rates invite gaming and compare systems that are not comparable, and there is something in it, but IMDA already grades these six services against one another in public, so the comparison is being made regardless, just based on what platforms say about themselves rather than what users experience.
Publish the denominators alongside the rates, let platforms annotate their own figures, and the gaming problem becomes a footnote rather than a reason to know nothing.
2. Measure user confidence independently, and keep measuring it.
Platform-supplied data will never tell a government whether people trust the system; only asking them will.
The panel recommended an annual survey on the state of online harms among young Singaporeans, designed to complement existing instruments such as MDDI’s Online Safety Poll rather than duplicate them.
The Government recognised the value of consistent data and said it would study further whether such a survey is feasible and complementary.
Two years on, with a new Commission now taking real cases, that study should conclude.
An equivalent instrument at ASEAN level would be worth more still, for the straightforward reason that nothing of the sort exists anywhere in the region.
3. Keep young people in the process, not in the consultation.
A panel convened once and dissolved after twelve months produces a snapshot; standing roles inside the bodies that write and review these codes produce a signal that keeps arriving.
Singapore has made a start: a youth representative from the panels now sits on the Media Literacy Council, and the Government has said it will continue to look for other meaningful platforms for youth participation.
The case for extending that pattern is not sentimental, and it is well established in the participation literature: continuous involvement builds ownership that one-off consultation does not.
The gap our survey found was invisible to policymakers precisely because it lives in the behaviour of people who never file a report, and you cannot commission that finding out of a system whose only input is reports.
The last piece
None of this should be read as an argument that Southeast Asia is doing too little.
Between Singapore’s new Commission, Malaysia’s statutory duties and Indonesia’s age framework, the region has built more online safety architecture in three years than in the previous fifteen, and the direction of travel is right.
The argument is narrower and more awkward: we are building the architecture without instrumentation.
We can state, to the hour, how quickly a platform in Malaysia must respond.
We cannot state, in any ASEAN market, what share of complaints ends in a resolution the complainant accepted, which is the only number that would tell us whether any of it is working.
Two years after our fieldwork, that survey remains, as far as I can establish, the only nationally representative reading of youth confidence in online redress anywhere in the region.
That is not a boast about the panel; it is an indictment of how little anyone is looking.
A regime that publishes what platforms do but never what users get is asking the public to take its effectiveness on trust, and among the young people it was built to protect, that trust has already been spent.
They are not waiting for the system to answer. They are reaching for the block button, and they have been for years.
***
Luo Chen Jun (C.J.) is Partnerships Manager at Common Purpose Asia Pacific, working with government, corporate and non-profit partners across Singapore, Hong Kong, India and Australia. He previously worked in trust and safety and content policy operations at Meta, Tinder and Amazon, and in digital and grants governance at Singapore’s Ministry of Culture, Community and Youth. He served on the #TechHacks: Digital Well-Being Youth Panel and on the UNCRC International Relations Workgroup at the Ministry of Social and Family Development.
Disclosure. The author was a member of the #TechHacks: Digital Well-Being Youth Panel (November 2023 – November 2024), convened by the National Youth Council and the Ministry of Culture, Community and Youth under Forward Singapore, and is named as a panel member in the Government’s published response to the youth panels. He joined MCCY as a Senior Manager in grants governance in May 2024, midway through the panel term, and left the public service in June 2025. He previously held trust and safety and content policy roles at Meta, Tinder and Amazon. His current employer delivers programmes in partnership with the National Youth Council. The survey discussed here was commissioned through the National Youth Council by the panel of which the author was a member and fielded by Milieu Insight, which has approved its use here; the full deck is available from the author on request. No part of this article draws on non-public information from any current or former employer. The views expressed are the author’s own. This article has not been published elsewhere.
References
On Singapore’s Online Safety Commission and the Online Safety (Relief and Accountability) Act 2025:
Lee, L.Y. (2025) ‘Singapore Parliament passes online harms Bill after more than eight hours of debate’, The Straits Times, 5 November. (Accessed: 18 August 2026).
Ministry of Law and Ministry of Digital Development and Information (2026) ‘The Online Safety Commission begins operations on 29 June 2026’. Singapore: MinLaw, 28 June. (Accessed: 18 August 2026).
On the #TechHacks: Digital Well-Being Youth Panel and its findings:
Ang, S. (2024) ‘Youths to get a say in policymaking, with 2-3 panels to be set up this year’, The Straits Times. (Accessed: 18 August 2026).
Milieu Insight (2024) #TechHacks Digital Well-Being Youth Panel Survey. Commissioned via the National Youth Council, Singapore. Fieldwork 9–19 May 2024, n = 1,000, aged 16–34, nationally representative by age, gender and race. Deck available from the author on request.
Ministry of Culture, Community and Youth and National Youth Council (2025) Youth Panels: Government’s Response to Recommendations. Singapore: MCCY and NYC. (Accessed: 18 August 2026).
Raguraman, A. (2024) ‘Youth’s policy recommendations will be seriously considered: PM Wong’, The Straits Times, 24 August. (Accessed: 18 August 2026).
Shafeeq, S. (2025) ‘Govt to implement youth proposals on financial resilience, S-E Asian opportunities, among others’, The Straits Times. (Accessed: 18 August 2026).
On Singapore’s platform regulation and transparency framework:
Infocomm Media Development Authority (2023) Code of Practice for Online Safety – Social Media Services. Singapore: IMDA, in effect 18 July 2023. (Accessed: 18 August 2026).
Infocomm Media Development Authority (2026) Online Safety Assessment Report 2025: Designated Social Media Services. Singapore: IMDA. (Accessed: 18 August 2026).
On regional regulation — Malaysia, Indonesia and Vietnam:
Aminanto, M.E. and Pitaloka, D. (2026) ‘Indonesia’s age-restriction policy for social media access needs more than just a decree’, GovInsider, 17 March. (Accessed: 18 August 2026).
Buchanan, K. (2026) ‘Indonesia: Regulation introduces age restrictions for social media platforms’, Global Legal Monitor. Washington, DC: Library of Congress, 12 March. (Accessed: 18 August 2026).
Rahmat Lim & Partners (2026) ‘Online safety in Malaysia: what you should know about the Online Safety Act 2025 and its subsidiary legislation’, 23 January. (Accessed: 18 August 2026).
Tilleke & Gibbins (2025) ‘A closer look at Vietnam’s Decree 147 on internet services and online information’, 20 February. (Accessed: 18 August 2026).
On transparency and outcome measurement in comparable jurisdictions:
eSafety Commissioner (2025) Basic Online Safety Expectations: Transparency Report on Child Sexual Exploitation and Abuse and Sexual Extortion — Periodic Notices, August 2025. Canberra: Australian Government. (Accessed: 18 August 2026).
Ofcom (2024) Ofcom’s Approach to Implementing the Online Safety Act. London: Ofcom, 17 October. (Accessed: 18 August 2026).
Turillazzi, A., Taddeo, M., Floridi, L. and Casolari, F. (2023) ‘The digital services act: an analysis of its ethical, legal, and social implications’, Law, Innovation and Technology, 15(1), pp. 83–106. DOI: 10.1080/17579961.2023.2184136. (Accessed: 18 August 2026).
On youth participation and online harms to children:
Lansdown, G. (2018) Conceptual Framework for Measuring Outcomes of Adolescent Participation. New York: UNICEF. (Accessed: 18 August 2026).
United Nations (n.d.) ‘Child and youth safety online’, Global Issues. (Accessed: 18 August 2026).
(QOB)




