Matthew Lloyd Davies at Pluralsight explores a threat to enterprise environments that could invalidate architectural security

Earlier this year, the UK government unveiled new plans that Big Tech companies like Apple and Google must activate built-in features or implement technical solutions to detect and block sexually explicit images for children. While the proposals demonstrate a long-awaited mandate on tech companies to take steps to protect children online, for security teams, the implications raise enterprise security risks.
The plan, which will require on-device or client-side scanning protections, has been criticised in the cyber-security community, warning the mandate could undermine privacy. On top of concerns expressed by Signal and the British Computer Society, over 400 security and privacy experts already called on lawmakers to halt the development of mandatory age-verification checks. They say it removes a key tool of data defence, with increased storing and sharing of sensitive personal information that could lead to large-scale leaks and hacks. It follows a similar thread: can devices be trusted to process information with external inspection?
If software is required to scan content before it is encrypted or transmitted, it could introduce new attack surfaces and weaken the privacy and integrity that businesses depend on to protect intellectual property and confidential information.
As technology providers work towards the September deadline, businesses should prepare for changes that could affect the confidentiality, trust and governance of managed devices. They must equip teams with the necessary skills to evaluate potential risks that client-side scanning could cause, adapting security strategies where necessary.
The greatest risk posed by mandatory on-device scanning is the disruption of trust architecture on which enterprise security depends. Modern mobile security frameworks, including mobile device management (MDM), endpoint protection and zero-trust access controls, are built on the assumption that the operating system functions as a controlled and trusted layer. Enterprises use this trusted foundation to enforce security policies and verify the integrity of managed devices.
Introducing a government-mandated scanning capability beneath or alongside that trusted layer could fundamentally change the security model. If an additional privileged component can inspect device content, the integrity of the operating system can no longer be assumed, making the security controls that sit above it less reliable. This structural change to the trust boundary that underpins enterprise mobile security creates new opportunities for exploitation if the capability is ever compromised or repurposed.
The consequences extend beyond security architecture into day-to-day enterprise operations. The underlying issue is not privacy, which is what the government’s plan is concerned with, but architecture. A scanning capability at the operating system level could sit outside the boundaries that enterprise security teams are able to govern, disrupting security processes that organisations rely on to verify whether endpoints remain in a trusted state.
Government-mandated device-level scanning capabilities could also create the potential for compliance failures, particularly in highly regulated sectors where organisations must demonstrate control over how sensitive data is processed and monitored. If the scanning capability operates outside the managed work profile used by enterprise MDM platforms, it remains effectively invisible to IT administrators. As a result, security teams could have no practical mechanism to audit its behaviour or control how it acts with secure data. This could also affect device attestation - the process by which MDM platforms verify a device is in a known, trusted state - which could cause managed devices to be flagged as non-compliant and blocked from corporate resources.
In an environment where visibility and assurance are fundamental principles of cyber-defence, introducing a privileged component that falls outside enterprise oversight creates a blind spot that weakens, rather than strengthens, organisational security.
While intended to improve online safety, client-side scanning protections raise significant concerns for organisations. Because it requires privileged access to device content and is widely considered incompatible with true end-to-end encryption, it could weaken security, increase the risk of sensitive data exposure, and force organisations to navigate difficult trade-offs between compliance and protecting critical systems. The lack of clear exemptions for legally privileged healthcare and financial data may also leave regulated sectors facing uncertainty over how to meet competing legal obligations.
Organisations cannot afford to treat this proposal as a policy issue alone. Security leaders should already be engaging with the compliance and governance issues it raises, assessing how any mandated changes to mobile operating systems could affect device trust, regulatory obligations and existing security controls.
This also means investing in the skills needed to assess security risks at the architectural level, rather than simply responding to threats after they emerge. Security teams will need a deeper understanding of operating system security models, trusted execution environments, encryption, endpoint architecture and mobile device management, enabling them to evaluate how changes to core platform designs could affect an organisation’s overall security posture.
Building these capabilities will help organisations make informed decisions about adopting new technologies, understand the implications of regulatory changes, and identify potential weaknesses before they become exploitable. As trust increasingly becomes embedded within the architecture itself, having teams with the expertise to assess and challenge these foundations will be just as important as the security tools used to defend them.
As tech companies prepare ahead of the September deadline, it’s important for organisations to assess the wider architectural consequences for their enterprise environments. This is not solely a privacy versus safety conversation. On-device scanning capabilities could weaken the trusted computing model on which modern mobile security is built. As a result, organisations must be prepared for the possibility of new vulnerabilities to emerge. Security teams operating with reduced visibility will require new ways of working.
While it is absolutely right that we, as an industry, find ways to better protect children online, it cannot come at the cost of weakening the security foundations that organisations rely on every day. The challenge for policymakers and technology providers is not just to implement new safeguards, but to do so without eroding the trust that underpins the wider digital ecosystem.
Matthew Lloyd Davies is Principal Security Author at Pluralsight
Main image courtesy of iStockPhoto.com and ismagilov
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543