Every AI product demos its safety features in short, clean conversations. Kids don't have short, clean conversations. They have hundred-message marathons over weeks, and the documented record shows a consistent shape: protections that hold at message ten give ground by message three hundred.
Three forces work on the guardrail at once. Length: the longer a conversation runs, the more the system's behavior is shaped by the conversation itself rather than its original rules. Rapport: role-play, personas, and accumulated context give the system reasons to stay in character instead of breaking it to refuse. And persistence: a kid with unlimited time will rephrase, reframe, and retry, and the record shows the machine eventually meeting them partway.
None of this requires a kid trying to break anything. Erosion happens to innocent marathon users too: the companion that would never discuss a topic in week one discusses it in week six, because week six's conversation is built on a thousand messages of accumulated character. The safety demo tested the front door. Kids live in the house.
The parental takeaway is a calibration shift: a platform's safety claims describe its best case, not your kid's actual usage pattern. Judge tools by their worst documented hour, not their launch-day screenshot.
[PULL-FROM-DATABASE: Case ___ ] one-line documented summary
[PULL-FROM-DATABASE: Case ___ ] one-line documented summary
[PULL-FROM-DATABASE: Case ___ ] one-line documented summary
Full record, methodology, and sources: the AI & Kids database.
Cap session length, not just screen time. The risk profile of message 400 is not the risk profile of message 40. Long unbroken sessions with one AI are their own category, and the family agreement should treat them that way.
Spot-read the deep water. If you review chats, don't just skim the start. The erosion pattern means the character of a conversation weeks in can be unrecognizable from its opening. Check the recent pages.
Teach the pattern itself. Older kids can hold this idea: the rules you tested on day one are not the rules the system follows on day forty, so your own judgment has to be the guardrail that doesn't erode. That reframe makes them the safety feature.
Words for the conversation: the is-AI-alive script for younger kids, the companion script for teens, and the jailbreak entry in the Decoder if that word has come up.