Ministers embraced the ‘world’s safest phone’. Then it unravelled

This article is an on-site version of our Inside Politics newsletter. Subscribers can sign up to get the newsletter delivered every weekday. If you’re not a subscriber, you can still receive the newsletter

Good morning. I remember the moment at school, maybe in 2014, when Snapchat took over. It was like someone flipped a switch and we all obediently downloaded the app that would grow to become the default venue for image-sharing.

A 2022 survey of British 14- to 18-year-olds found that on Snapchat, nudes were typically first shared in one-to-one chats and could then be forwarded with “a couple of clicks” into group chats of up to 100 people. Among those who had sent a nude, 24 per cent of girls and 9 per cent of boys said a recipient had subsequently sent it to others without permission.

A lot of the policy thinking around digital harms has moved on in recent years to reflect this new reality, where platform design has made our interactions more intense, extreme and large scale — and where savvy young people circumvent restrictions.

Rather than relying on apps to police harmful content, governments now want to intervene at the operating system level, so guardrails can get ahead of whichever app breaks on to the scene.

That is why Keir Starmer in June presented an ultimatum to tech companies: install child nudity-blocking software in devices by September or face legislation and fines.

And there is no excuse for dithering, the government’s announcement implied. It said this tech had already been achieved by the British company SafeToNet. Ministers held up SafeToNet as proof point for the proposition that child safety can be built into phones universally and block nudity in real time.

But what appeared to the government to be an “oven-ready” fix is now running into difficulty, after the first smartphone to integrate SafeToNet technology was removed from sale following an investigation into the device’s safety risks. The HMD Fuse, sold by Vodafone, was launched last year as the “first smartphone that protects a child’s innocence by stopping nude content from being filmed, seen, shared and stored”. In January of this year, former ministers Peter Kyle and Jess Phillips starred in a video promoting the phone. Six months later, sales have been suspended.

In light of readers saying they enjoy a bit of investigation in Inside Politics, today I bring you the story of how this unfolded.

Inside Politics is edited by Darren Dodd today. Follow Stephen on Bluesky and Georgina on Bluesky. Read the previous edition of the newsletter here. Please send gossip, thoughts and feedback to [email protected]

‘The world’s safest phone’ broke down ‘in the space of half an hour’

There are not many companies that can count Kyle, Phillips, Rupert Lowe and Drew Barrymore among their advocates. SafeToNet can. On Tuesday, Barrymore, the Hollywood actor who has previously collaborated with phonemaker HMD, was appointed a director of SafeToNet. Anti-digital ID rightwinger Lowe is a shareholder.

Founded in 2013, SafeToNet has ascended to prominence this year thanks to the government’s expressed ambition to make Britain the world’s first country “where it is impossible for children to take, share or view naked pictures on their devices”. Back in 2020, the then culture secretary Oliver Dowden visited the company and witnessed it blocking explicit images at the device level. “I have seen the technology; there is no excuse anymore not to use it,” he said of built-in safety features in the Commons. That year Priti Patel had received on her request “advice for ministers to consider on promoting the use of SafeToNet”.

Freelance journalist Martin Calladine was first to dig into the finances of SafeToNet, which he called “the government’s favoured supplier of child safety software” because it is largely unrivalled and a convenient option if the government mandates manufacturers to install such software.

In 2024 it turned over £112 (!) in the UK, according to its latest accounts, with about 94 per cent of its revenue coming from German subsidiaries (largely a phone retail business) that SafeToNet partly owns. SafeToNet has lost more than £17mn in the past three years for which it has filed accounts, and in the latest filing, the group auditors said they could not give an opinion because the component auditors in Germany “have not allowed communication with us”.

(SafeToNet told the FT that the local audit of the German side had been delayed for reasons beyond the company’s control, so the group auditor couldn’t get the information needed within the statutory timeline, hence the disclaimer of opinion. SafeToNet has since changed these audit arrangements. “The company has prioritised investment in building and proving its technology ahead of immediate profitability,” it added.)

After the August 2025 launch of the HMD Fuse — as the “world’s safest phone” — Paul Moore, an independent security consultant, rushed to buy one and test it out. He broke it apart but discovered problems in “half an hour”. “It begs the question what due diligence the government has done before endorsing it if somebody like myself can find something like this,” he said.

How does HMD Fuse work?

HMD’s “HarmBlock+” system, the phone’s main safety feature, combines the tech from two companies, SafeToNet and Xplora:

  • SafeToNet’s HarmBlock AI classifier. This is embedded into the phone and works across the camera. It has been trained on “25mn appropriately sourced images”. If it classifies an image as nudity, it covers the screen with an overlay. If it identifies nudity in the camera feed, an overlay blocks the camera view within a second.
  • Xplora, another child safety company, provides the parental control service which lets parents “pair” their own device with the HMD Fuse phone. They can then manage app access and screen time, track their child’s location with updates every 24 seconds, and set “safe zones” that trigger alerts when the child enters or leaves them.
  • HMD provides the handset and operating system.

SafeToNet’s HarmBlock AI classifier. This is embedded into the phone and works across the camera. It has been trained on “25mn appropriately sourced images”. If it classifies an image as nudity, it covers the screen with an overlay. If it identifies nudity in the camera feed, an overlay blocks the camera view within a second.

Xplora, another child safety company, provides the parental control service which lets parents “pair” their own device with the HMD Fuse phone. They can then manage app access and screen time, track their child’s location with updates every 24 seconds, and set “safe zones” that trigger alerts when the child enters or leaves them.

HMD provides the handset and operating system.

Moore first found a security weakness in the HMD Fuse’s password-reset process in September 2025. HMD told the FT that after Moore raised the problem with its team, it “collaborated closely with Xplora and SafeToNet to deploy a fix” and, after rigorous testing, restored the service two days later.

Then, in July 2026, Moore discovered what he described as a different, serious flaw: an unauthorised person could potentially register as the guardian of another child’s handset and access its live location. According to Moore, the problem was that the pairing relied on the IMEI number, the unique serial code that identifies each handset. He said this number was predictable: part of the number was fixed and the rest could be systematically enumerated and plugged in. He said that meant he could “become the guardian of every child on the platform, which meant I basically had a live map of every child on the system at the time”. Moore alerted SafeToNet to the issue directly on July 5.

In response, HMD took the service offline on July 9, notified the Information Commissioner’s Office as required and launched its own investigation. HMD said it implemented security enhancements before restoring access for existing users on July 22. It said there was no evidence that anyone other than Moore had exploited the vulnerability, which it said concerned Xplora’s parental-control service.

HMD’s spokesperson added: “In agreement with our retail partners, we have temporarily paused sales of HMD Fuse while work on the permanent solution for new users is completed. Customers who have recently purchased a device and are unable to activate the service should contact us and we will assist them directly.”

“We completely understand parents’ concerns regarding this matter and sincerely apologise for any worry caused.”

Moore told the FT that this problem was down to the wider HarmBlock+ service implemented by HMD, not SafeToNet’s HarmBlock AI technology itself and his findings do not indicate weakness in SafeToNet’s product.

Moore nevertheless questioned how a phone marketed around child safety had reached consumers with such risks, saying the responsibility extended beyond HMD to Xplora and SafeToNet. “The fact nobody appeared to do any due diligence before promoting it is disgusting,” he said.

What do SafeToNet, Xplora and Vodafone say?

  • SafeToNet said the problem Moore identified concerned HMD Fuse’s parental control service rather than its own tech, “which continued to operate as intended on activated devices”, but it acknowledged it formed part of a wider child safeguarding product and that it has a responsibility to act when concerns arise. “When we became aware of the issues, we immediately escalated them with HMD, supported the investigation and remediation, supported the suspension of new device activations while outstanding issues were addressed, and took action on sales within our control,” it said.
  • Xplora said that as soon as information about the vulnerability came to light in July, Xplora worked closely with HMD engineers and introduced fixes on July 22, “with further continuous improvements since then to prevent any future vulnerabilities”.
  • A spokesperson for Vodafone said the company has paused sales of HMD Fuse while the reported issues are reviewed. Its promotional pages have also been taken off the site.

SafeToNet said the problem Moore identified concerned HMD Fuse’s parental control service rather than its own tech, “which continued to operate as intended on activated devices”, but it acknowledged it formed part of a wider child safeguarding product and that it has a responsibility to act when concerns arise. “When we became aware of the issues, we immediately escalated them with HMD, supported the investigation and remediation, supported the suspension of new device activations while outstanding issues were addressed, and took action on sales within our control,” it said.

Xplora said that as soon as information about the vulnerability came to light in July, Xplora worked closely with HMD engineers and introduced fixes on July 22, “with further continuous improvements since then to prevent any future vulnerabilities”.

A spokesperson for Vodafone said the company has paused sales of HMD Fuse while the reported issues are reviewed. Its promotional pages have also been taken off the site.

All this has huge consequences for our ambition of moving the protective layer upstream of Snapchat, TikTok or whatever comes next — a goal that seems to be continuing under Andy Burnham.

Politicians want to be seen to show enthusiasm and move quickly, but there is a risk they skip the harder, duller work. The HMD Fuse episode is a useful reminder that safeguards are only as strong as the weakest link in the chain. SafeToNet’s nudity-blocking software may have operated as intended, but that did not stop an issue elsewhere in the phone from creating a potentially serious risk. Stress-testing the software and surrounding system matters even more if the government wants to roll this out at scale.

It’s hard to conceive of just how much children’s social norms have changed, accelerated by the arrival of Snapchat’s “disappearing” photo function, which, as that 2022 study highlights, shaped young people’s behaviour and expectations of each other. In the early days of the internet, image-based child sexual abuse was largely focused on adult perpetrators — now US research has found 86 per cent of material involved in image-based child sexual abuse incidents is generated by young people themselves, with about a fifth of episodes involving an identified adult perpetrator. As the paper says, a technological solution or ban can only be part of the answer — alongside education around image sharing, peer pressure, consent and the harm experienced by victims. Using technology to enable a set of policy decisions should only raise the effort expended on due diligence.

Now try this

If you’re looking for a fancier non-alcoholic drink for dinner parties, I am enjoying Jin Jin, a cordial from Taiwan that is made from fermented fruit and vegetables. Somehow it ends up tasting pretty good!

Top stories today

  • Asylum seekers in hotels hit all-time low | The number of people claiming asylum in the UK declined by a fifth during Labour’s second year in government, according to official data. The number housed in hotels hit a record low in the second quarter.
  • Leaseholders triumph | Flat owners fighting to replace expensive or unresponsive management companies in their blocks have won a case in the UK’s highest court that strips freeholders of a powerful tool to derail resident-led takeovers.
  • Chain reaction | Mike Ashley, the retail billionaire behind Frasers Group. called Burnham’s high street revival plan “delusional” and “populist” in a letter to the prime minister seen by the FT.

Asylum seekers in hotels hit all-time low | The number of people claiming asylum in the UK declined by a fifth during Labour’s second year in government, according to official data. The number housed in hotels hit a record low in the second quarter.

Leaseholders triumph | Flat owners fighting to replace expensive or unresponsive management companies in their blocks have won a case in the UK’s highest court that strips freeholders of a powerful tool to derail resident-led takeovers.

Chain reaction | Mike Ashley, the retail billionaire behind Frasers Group. called Burnham’s high street revival plan “delusional” and “populist” in a letter to the prime minister seen by the FT.

Recommended newsletters for you

The Week Ahead — Start every week with a preview of what’s on the agenda. Sign up

Newswrap — Our business and economics round-up. Sign up

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论