Australia’s eSafety Commissioner published a report on October 2, 2026, comparing child-safety practices at services behind Roblox, Fortnite, Minecraft and Steam. The assessment covers information about safeguards from October 1, 2025, through March 31, 2026, and describes differences in content detection, age checks, report handling and information sharing.

What Australia’s gaming-safety report examined

The report drew on information providers supplied under transparency notices issued on April 1, 2026. It assessed Roblox, Epic Games’ Fortnite, Mojang Studios’ Minecraft, and Valve’s Steam and Steam Chat. The findings concern the assessment period, not a continuous measure of how the services perform today.

How the services’ safety measures differed

The findings describe different approaches to reviewing content and detecting harm. Epic Games reviewed every Fortnite Island before it became accessible. Roblox used tools to detect harmful user-created Experiences after publication; eSafety reported that Roblox Image Auto-mod had a 51% recall rate for detecting violence and child sexual exploitation and abuse material in images on the service. Recall measures how much of the targeted material a tool identifies. That figure applies to the specified image-detection tasks, not to every safety measure on Roblox.

For Minecraft, eSafety reported that users who declared themselves to be 18 or older could access third-party servers that Mojang did not proactively moderate. Mojang used proactive scanning and user reports to identify high-risk third-party servers.

eSafety said Valve was the only assessed provider not using hash-matching tools across Steam and Steam Chat. Hash matching compares digital fingerprints to identify known material. Steam Chat also lacked proactive detection of harm in text or voice chats, including community group chats, apart from a URL-detection tool that mainly blocked scams.

Age checks depended on the feature and market

During the assessment period, Epic Games and Mojang offered child-account protections but generally relied on users to declare their own ages. Users who declared themselves adults could access some higher-risk features without additional checks. During that period, Valve relied on self-declared ages and did not collect age-related information.

The report also describes later, market-specific measures. Roblox began stronger age assurance in Australia on December 3, 2025, restricting selected higher-risk features to users identified as adults. From September 9, 2026, Valve required credit-card verification for Australian users accessing R18+ games.

Report handling and information sharing

For a defined category of automated reports, eSafety said Epic Games took 18 hours and 53 minutes to assess reports of unconfirmed child sexual exploitation and abuse material and activity—the longest time among the assessed providers. That measure excluded reports involving grooming and sexual extortion; it does not describe Epic’s response time for every type of report.

The report also found differences in industry information sharing. Mojang and Roblox took part in information-sharing initiatives; Roblox shared signals with Lantern and worked directly with Discord on trends in child safety and violent extremism. Valve did not participate in the assessed initiatives. Epic received some external URLs but did not participate in Lantern or share relevant child sexual exploitation and abuse signals through similar initiatives.

What a transparency notice means

eSafety said issuing a transparency notice does not, by itself, mean that a provider has deficient safety practices or indicate the regulator’s view of the provider’s compliance. The report presents the regulator’s assessment of practices described for the covered period.