Americans reported losing $2.1 billion to scams that started on social media in 2025, according to the FTC. That's one slice of the harm a platform must answer for, and why every operator needs to understand Trust and Safety.

Trust and Safety is the organizational function that keeps online platforms safe to use. It sets the rules for what people can post, then enforces them through written policy, automated detection, and human review across text, images, video, and chat. It differs from content moderation, which is just one of its functions; Trust and Safety is the whole set.

There's now a legal floor under this work: the EU Digital Services Act and the UK Online Safety Act impose binding duties on the platforms they cover, both detailed below. If you have users in the UK or in Europe, you have obligations that can leave you liable to legal action if you miss them.

Trust and Safety at a glance

Trust and Safety is broader than any single team or tool. The essentials:

  • Trust and Safety spans six functions: account integrity, fraud, content moderation, child safety, platform manipulation, and regulatory compliance.
  • Content moderation is a single function within Trust and Safety, easily mistaken for the whole.
  • Automated detection handles the volume of violations; human reviewers handle the hard calls.
  • The EU Digital Services Act and UK Online Safety Act now make Trust and Safety a legal duty for online platforms, backed by real financial penalties.
  • A Trust and Safety function is judged on safety outcomes first: how much harm it catches, how fast, and how reliably.
  • Trust and Safety exposes human moderators to disturbing material as a routine part of the job, so protecting their welfare is part of running the function well.

Why is Trust and Safety important?

Trust and Safety matters because any platform that lets people post, message, or transact will eventually be used to cause harm.

A dating platform that tolerates romance scams loses its daters, and a game that ignores grooming risk loses parents' permission for their kids to play.

Counterfeits drive buyers off a marketplace, and unchecked harm brings regulators to the door. The threats never sit still, so it stays a matter of active, ongoing management.

Where did Trust and Safety come from?

Trust and Safety didn't arrive fully formed. It took its legal shape from a late ‘90s court fight, got its name from e-commerce, and only later organized into a profession. In 1995, a New York court held in the Stratton Oakmont, Inc. v. Prodigy Services Co. case that a platform moderating its forums could be treated as the publisher of what users posted.

Congress answered in 1996 with Section 230 of the Communications Decency Act, which shielded platforms from that liability while leaving them free to moderate. Then, in 1999, eBay put a name to the practice, using "trust and safety" in a press release for its SafeHarbor anti-fraud program.

For its first decade the work was mostly invisible, and the job barely had a name. In 2020, the Trust and Safety Professional Association and the Trust and Safety Foundation launched together, giving the field a professional body and a shared curriculum.

What does Trust and Safety do?

Trust and Safety does several distinct jobs under one umbrella, and they divide into six functions:

  • Account integrity: Keeping accounts genuine, and stopping fake sign-ups, bots, takeovers, and impersonation.
  • Fraud: Catching scams, payment fraud, and deceptive schemes aimed at users or the business itself.
  • Content moderation: The judgment calls on what users post, and what stays up, comes down, or gets restricted, across text, images, video, and audio.
  • Child safety: Protecting minors from exploitation, detecting child sexual abuse material, and disrupting grooming, usually alongside law enforcement.
  • Platform manipulation: Countering coordinated inauthentic behavior, spam networks, and influence operations that game the system.
  • Regulatory compliance: Meeting the legal duties that now govern platforms, from transparency reporting to risk assessment.

How is Trust and Safety different from content moderation?

Trust and Safety is the whole discipline; content moderation is one function within it. Treating the two as synonyms is the field's most common misconception.

Trust and Safety is the wider set: why those rules exist, how they're enforced, and everything else that keeps people safe.

You can moderate content well and still miss a fraud ring, a manipulation campaign, or a child safety threat that never shows up as one removable post. Getting the difference right shapes who a platform hires, what tools it buys, and how it answers to regulators. For the mechanics of moderation, our content moderation guide goes deeper.

What does the law require of platforms?

Any platform operating across multiple markets has to contend with the region’s legal requirements. The markets with the most impact are the US, UK, and EU, and the shape of your obligations in each is quite different.

The US: Section 230 and a patchwork of state-level regulations

Trust and Safety law in the US looks nothing like the DSA or the UK Online Safety Act. There is no single comprehensive federal statute imposing an omnibus duty of care on platforms. The bill that comes closest, the Kids Online Safety Act, has repeatedly passed one chamber and stalled over censorship concerns, and its 2026 House version dropped the duty of care entirely.

Instead, US law is a liability shield plus narrow carve-outs for specific harms: Section 230 of the Communications Decency Act, 47 U.S.C. § 230, shields platforms from liability for user content and is not itself a moderation duty.

The clearest live federal duty is the TAKE IT DOWN Act: covered platforms must remove non-consensual intimate imagery, including "digital forgeries" generated with AI, within 48 hours of a valid request. The FTC has enforced this since May 2026.

However, DSA and OSA-style design duties are emerging at the state level, and they are contested. California's SB 976 limits "addictive feeds" to minors without parental consent and was partly upheld in 2025; its Age-Appropriate Design Code Act, AB 2273, went further and has been mostly enjoined.

The EU Digital Services Act (DSA)

The EU Digital Services Act, Regulation (EU) 2022/2065, became fully applicable on 17 February 2024, and for a Trust and Safety function, it turns good practice into a legal obligation.

Most of the DSA’s duties map onto work good teams probably already do:

  • Article 14 wants clear terms and conditions
  • Article 16 requires notice-and-action so users can report illegal content
  • Article 17 needs a statement of reasons whenever you remove or restrict something
  • Articles 20 and 21 add internal complaints and out-of-court dispute settlement
  • Article 22 formalizes trusted flaggers, and Article 24 sets transparency reporting

The biggest services carry more responsibilities, though. Under Articles 34 and 35, very large online platforms (VLOPs) and search engines must assess and mitigate systemic risks, from illegal content to harms to fundamental rights. The enforcement isn't decorative: Articles 52 and 74 cap fines at up to 6% of annual worldwide turnover.

Our complete guide to the DSA walks through each duty in detail.

The UK Online Safety Act (OSA)

The UK Online Safety Act 2023 imposes a duty of care: platforms owe users a legal duty to manage specific risks.

For user-to-user services, Part 3, Chapter 2 sets those duties (sections 7 to 23). That covers illegal content duties (sections 9 to 10) and children's safety duties for services likely to be accessed by minors (sections 11 to 13). Search services get parallel duties under Chapter 3 (sections 26 to 30), Part 4 adds transparency reporting (sections 77 to 78), and Part 7 hands Ofcom its enforcement powers (sections 130 to 151).

Why does the Act reach the boardroom? The penalties. Under Schedule 13 of the OSA, Ofcom can fine a platform the greater of £18 million or 10% of qualifying worldwide revenue.

This is the record-keeping we're built to support: the statements of reasons, transparency data, and audit trails that these laws ask platforms to produce. We support those obligations; we don't make a platform compliant, which comes down to what the platform actually does.

How does a Trust and Safety function actually work?

A Trust and Safety function runs the same loop everywhere: write the rules, detect what breaks them, judge the hard cases, and log every decision.

  • Policy: Written rules set what's allowed and what follows a breach, applied through a policy engine.
  • Detection: Multi-model detection scans content as it's posted, flagging violations across text, images, video, and audio at a volume no team could match by hand.
  • Human review: People take the flags that need context. Automation narrows the queue; a person still makes the call.
  • Audit trail: Every action is logged, so a platform can show its work to regulators and keep the record that compliance reporting needs.

That human review step carries a cost that the vendor brochures skip. Moderators and investigators look at the material everyone else is spared: child sexual abuse, graphic violence, exploitation, and self-harm.

Doing that day after day takes a real toll, and it's the strongest case for pairing automation with human judgment. Automating the clear-cut violations means reviewers see less of the worst, itself a safety outcome. Our guide to Trust and Safety teams breaks down who does what.

How do you test your Trust and Safety coverage?

Trust and Safety gaps don't open inside a function; they open in the seams between them. To find them before an incident or a regulator does, ask a plain question of each of the six functions and mark your honest answer as covered, partial, or absent:

  • Account integrity: Are your accounts genuine, with fake sign-ups, bots, and takeovers blocked?
  • Fraud: Are you catching scams and payment fraud early?
  • Content moderation: Are user posts reviewed and actioned across every format?
  • Child safety: Are minors protected, with grooming and child sexual abuse material caught?
  • Platform manipulation: Are coordinated manipulation and spam networks countered?
  • Regulatory compliance: Do you own your DSA and Online Safety Act duties?

For any function you can't mark as covered, name what's missing: no owner, no detection, or nowhere to escalate. A platform with a mature moderation queue and no named owner for platform manipulation has a gap exactly where coordinated abuse lives. The finished scorecard maps where harm has no owner, the real input to any build versus buy decision: fund the absent functions before the loudest team.

What does Trust and Safety look like in practice?

Trust and Safety is easy to describe and hard to run at scale. Our Star Stable case study shows the loop in motion. The children's game moderates tens of millions of chat messages a month across 14 languages, returns decisions in under 50 milliseconds, and saw roughly a 50% improvement in accuracy at launch.

That reach and speed are the baseline which any gaming platform's content moderation is measured against. The team's own read was understated, but says a lot given all the moving parts to consider: Senior Producer and Localisation Lead Estella Corbellini called it "a pain-free launch." 

Frequently asked questions about Trust and Safety

What does a Trust and Safety team do?

A Trust and Safety team writes the rules, detects violations through automation and human review, investigates fraud and abuse, handles reports and appeals, and reports to regulators. In practice, that means policy writers, moderators, investigators, data scientists, and engineers working as one function.

What is a digital Trust and Safety platform?

A digital Trust and Safety platform runs the separate functions inside one system, changing two things: enforcement stays consistent across every format, and every decision lands in one evidence trail regulators can follow. Build or buy is the real question. It supports compliance reporting; it does not make a platform compliant.

What is Trust and Safety in tech?

Trust and Safety in tech is the discipline as technology companies practice it: keeping platform users safe. That sets it apart from the same phrase used for a rideshare support desk. Inside a tech company, it's an operating function with policy, tooling, headcount, and a line to the board.

How do you build a scalable Trust and Safety program?

A scalable Trust and Safety program starts by mapping harms to the six functions, then deciding for each whether to build, buy, or outsource. Scale comes from automating the clear-cut volume so human judgment goes where context decides the call.

Look at your biggest gaps first, then think about tools

Understanding the full remit of Trust and Safety matters because harm hides in the seams between the six functions. So the first move in standing up or scaling this function is to test your coverage across all six, finding which one has no owner before buying any software.

Then tooling has a job to do. Checkstep's content moderation platform brings multi-model detection, policy management, human review workflows, and full audit trails into one system. It supports Digital Services Act and Online Safety Act reporting rather than promising to make the problem disappear.

To pressure-test your own coverage against your specific harms, languages, and compliance obligations, book a demo to talk it through with our team.

Discover our Solution for T&S Leaders