← Back to home

Safe AI for Kids: How to Choose One (and What to Avoid)

A practical guide for parents of 3–9 year-olds

Short answer: safe AI for kids exists, but general-purpose AI isn't it. A purpose-built children's app can be genuinely safe when the design is right, and this guide explains what "safe" actually means, the red flags to walk away from, and a seven-point checklist you can use to judge any AI app before handing it to your child.

Why "is AI safe for kids?" is the wrong first question

The AI isn't the thing that's safe or unsafe. The product built around it is. The same underlying model can power a wide-open chatbot that will answer anything, or a carefully fenced companion that only tells gentle stories and points your child back to you for anything that matters. When you're evaluating a kids' app, you're really evaluating the guardrails, the privacy practices, and how much control you keep as the parent.

The 7 things that make a kids' AI app actually safe

Here's the checklist I used looking for something for my nephews. Safe AI for kids is not one property an app either has or lacks; it is these seven decisions, and a trustworthy app should clearly make all of them:

How to actually check each of those seven

A checklist is only useful if you can test it in ten minutes on the sofa, before your child ever opens the app. Here is how to check each one without taking anyone's word for it.

  1. Test the boundary. Ask the app something it should refuse: a question about a news event, or to look something up online. A bounded app will say it cannot, or steer back to what it does. An open chatbot in a friendly costume will try to answer.
  2. Test the screening in both directions. Type something a little sad, like "I feel lonely today". You are checking two things: that the app responds gently rather than clinically, and that it points toward a grown-up rather than settling in to counsel your child itself.
  3. Look for where the hard moments go. Any app that will discuss self-harm, dieting or family conflict with an eight-year-old on its own has made a decision you probably disagree with. The right answer is always to hand it back to you.
  4. Read the privacy policy for the word "retain". Not "we care about your privacy". Search the page for what happens to voice recordings and photos specifically, and how long they are kept. If it does not say, assume they are kept.
  5. Check the app's own store listing for a privacy label. Both Apple and Google now require developers to declare what they collect. Compare that declaration against the privacy policy. If they disagree, believe the stricter one and then ask why they differ.
  6. Find the transcript before you hand over the phone. If you cannot locate a full history of what your child said and heard within a minute of installing, it either does not exist or it is summarised. A summary is not a transcript.
  7. Try to change a setting as the child would. Hand yourself the app as if you were seven. If you can reach billing, delete history, or turn off limits without meeting a PIN or a maths question, so can they.

What actually goes wrong

Most parents worry about the wrong thing first. The fear is usually that a chatbot will say something explicit. That does happen, and filters catch most of it, but the failures that have caused real harm are quieter and harder to filter.

Attachment. An app designed to maximise time-on-app can make a child feel it is their closest friend. This is not an accident of the technology; it is a design choice, and it is the reason companion apps built for adults have drawn regulatory attention. For a six-year-old, who has not yet learned that a warm voice does not mean a real relationship, it is a much bigger deal than a filtered swear word.

Secrecy. Any system that says "this is just between us", even playfully, has taught a child a pattern you spend years teaching them to resist. This is the single line I would walk away over.

Confident wrongness. Language models state guesses in the same tone as facts. An adult discounts that automatically. A child taking the app as an authority does not, which matters most when the question is about their own body, a medicine, or something frightening they heard at school.

Quiet data collection. The advertising SDK is the version everyone knows about. The subtler one is a voice recording kept "to improve the service": your child's actual voice, on someone else's server, indefinitely.

What the law actually requires

You do not need to read the regulations, but knowing what they demand makes it much easier to spot an app hoping you will not check.

In the United States, COPPA covers services directed at children under 13. It requires verifiable parental consent before collecting personal information, a plain description of what is collected, and a way for you to review or delete it. In the EU, GDPR sets the rules on processing children’s data. In the UK, the Age Appropriate Design Code goes further: privacy settings must default to the most protective option, and nudging children toward weaker settings is explicitly not allowed. The Code is UK law, issued by the Information Commissioner’s Office, and has no direct EU equivalent.

Apple adds its own layer. Apps in the Kids Category may not send personal or device information to third parties, and Apple says they should not include third-party analytics or third-party advertising, with narrow exceptions for analytics that identify nothing about the child. Purchases and links out of the app must sit behind a parental gate. This is stricter than the law and it is why the Kids Category is a genuinely useful signal on a store listing: a developer has agreed to constraints that make some ordinary business models impossible.

What none of that guarantees is that an app is good. Compliance is a floor. Every genuinely useful thing in the checklist above (the transcript, the boundary, where hard moments go) is a choice the developer made beyond what any regulator required.

Does the right answer change with age?

Yes, more than most apps admit, and it is why an app claiming to serve four-year-olds and fifteen-year-olds equally is making a claim worth doubting: the design choices that protect a four-year-old are not the ones a teenager needs.

A three- or four-year-old cannot read, cannot type, and has no framework at all for “this is a character, not a person.” Everything has to be spoken, sessions are five or ten minutes, and the anti-attachment design matters more here than at any other age. At this age it is a shared activity, not something to hand over.

A five- or six-year-old is sounding words out rather than reading fluently, so voice is still the interface that works. The questions get harder without getting inappropriate, and the first boundary tests appear, usually as a game rather than a challenge.

A seven-year-old asks the endless “why” questions and starts testing boundaries deliberately, including the app’s. This is the age at which you find out whether a boundary is real, because they will go looking for it, eleven different ways.

An eight- or nine-year-old reads independently, will notice when an answer is evasive, and may be bringing questions from the playground that they are not ready to ask you. This is where “redirect to a trusted grown-up” earns its keep. It is not a dodge, it is the app declining a conversation it has no business having.

We have written this out year by year: 3, 4, 5, 6, 7, 8 and 9. If your child cannot read yet, start with voice AI for pre-readers.

Red flags to walk away from

How WimziPal is built against this checklist

WimziPal is a bounded, parent-supervised AI companion for children aged 3–9: not an open chatbot. Your child picks an animated buddy and talks to it out loud. Every message is screened on the server both ways, voice and photos are never stored, there are no ads and no data sold, and you can read the full transcript of everything your child heard. Settings sit behind a parental PIN, and you set the daily limit. You can read the full breakdown on our child safety page.

Want to see a safe kids' AI in practice?

Every buddy is free, with over 130 activities to try. You read every word.

Free to download · free chats to try · meet all 17 buddies →

Questions parents ask

At what age is an AI app appropriate for a child?

There is no single answer, but the honest version is that it depends far more on the app than the child. A bounded, voice-first companion with a transcript is reasonable from around three, used alongside a parent at the youngest ages and more independently by seven or eight. An open-ended chatbot is not appropriate at any age under thirteen, which is why the general-purpose assistants set that as their own minimum.

Will an AI friend stop my child talking to me?

It can, and that is the risk worth taking seriously. A well-built kids' app is designed to do the opposite: to hand the important conversations back to you rather than absorb them. Look for whether the app redirects to a grown-up on anything that matters, and whether you can read what was said. If both are true, it behaves more like a picture book than a confidant.

Is ChatGPT safe for kids?

It is not built for them. OpenAI's own terms set a minimum age of thirteen, and the product has no age tuning, no parent-visible history, and no boundary on subject matter. It is an excellent adult tool being asked to do a job it was not designed for.

How do I know whether an app is really COPPA compliant?

Compliance is self-declared, so the claim itself proves little. What you can check: whether the privacy policy names what is collected and for how long, whether there is a real parental consent step rather than a tick-box, and whether the store privacy label matches the policy. A developer who has actually done the work usually says so specifically, not in a badge.

What should I do before handing over the phone?

Use it yourself for ten minutes first, with the seven tests above. Set the daily limit before your child ever sees the app, not after. And read the first transcript, not to check up on your child, but to see for yourself what the app actually says when nobody is watching.

Related reading