Why the same six words can be an act of love or the opening move of abuse. A Tuteliq essay on the behavioural architecture of grooming, sextortion, mule recr...

A companion piece to Tuteliq's report The State of Kids' Online Slang 2026. The report maps the coded words; this essay is about the harder problem hiding beneath them.

TL;DR

  • "Can you keep a secret?" is one of the most common grooming phrases, and also one of the most common phrases in ordinary loving relationships. The words are identical. The harm is not in the words.
  • Three tactics do most of the work across grooming, sextortion, mule recruitment, and coercive control: secrecy, isolation, and boundary pushing.
  • Keyword filters cannot separate a birthday surprise from a predator setting a secrecy norm. Only conversation-level context can.
  • Since 25 July 2025 this is a legal problem too. Ofcom's Protection of Children Codes require in-scope services to detect grooming or face fines up to £18m or 10% of global turnover.

The numbers

Signal · 2025 figure · Source

--- · --- · ---

Reports of online enticement · 1,400,000+ (up 156% YoY) · NCMEC CyberTipline

Financially motivated sextortion reports · 50,000+ (over 130 per day) · NCMEC

Money mules who are under 30 · ~6 in 10 · National Crime Agency

Max fine under the UK Online Safety Act · £18m or 10% of global turnover · Ofcom

The phrase that does two jobs

"Can you keep a secret?" is a phrase most of us have said and heard in entirely ordinary circumstances. A parent whispers it before a birthday surprise, a friend shares something in confidence, a colleague trusts you with delicate news. In almost every context, it is harmless, even warm.

It is also one of the most commonly used grooming phrases in existence. That duality, the fact that the same six words can be an act of intimacy or the opening move of abuse, is the central technical problem in detecting harm in text. The scale is alarming, but the scale is not the story here. The mechanism is.

The three tactics

Grooming is a process, not a vocabulary. Three behavioural tactics do the load-bearing work, and each looks entirely benign at the level of a single message.

--- · --- · --- · ---

Secrecy request · Don't tell anyone about us, about this. · "People would misunderstand what we have." "This is a grown-up thing." "I can only keep talking to you if you keep this between us." · Indistinguishable from birthday surprises, therapy, ordinary teenage privacy.

Isolation · Those people in your life are bad for you; you don't really need them. · "I really understand you." "Your friends don't appreciate you like I do." "You can always come to me." · Identical to the language of a caring friend, mentor, or coach.

Boundary pushing · Just this once. Everyone does it. · Incremental requests, small yeses used as a platform for larger ones, returning to a no again and again. · Any single message reads as curiosity or ordinary persistence. The harm is the sequence.

Read one such message on its own and there is nothing to flag. A keyword search classifies "can you keep a secret?" as neutral almost every time, because in the overwhelming majority of cases, it is.

When warmth is a weapon

Isolation language is almost indistinguishable from the language of a good mentor. Spoken by a trusted adult to a struggling teenager, phrases like "I really understand you" are the words of support. Spoken by someone systematically severing a child's safety net, they are the machinery of abuse. Without context, they read identically. A model looking only at words sees warmth. The harm lives in intent and pattern, not vocabulary.

The pattern is the point

Boundary pushing is a property of a sequence, not a sentence. A perpetrator makes an incremental request, secures a small yes, and uses it as the platform for a larger one. When told no, they return again and again until the refusal wears down.

"Everyone does it" on its own is unremarkable peer-normalisation language heard in every school corridor in the country. But the fifth time it follows a clearly stated refusal, it is not peer normalisation anymore. That is invisible to anything that reads messages one at a time.

The architecture of harm

Here is the insight that reframes the whole problem. Secrecy, isolation, and boundary pushing are not specific to grooming. They are behavioural primitives that recur, almost unchanged, across entirely different categories of harm. The harm type changes. The tactic architecture does not.

--- · --- · --- · ---

Sexual grooming · "Keep this between us." · Undermining family, friends, teachers. · Escalating requests for images or meetings.

Sextortion · "Don't tell anyone or I release the images." · Shame as an isolation mechanism. · Incremental image demands preceding the threat.

Money mule recruitment · "Don't tell your bank, they'd flag it." · "You're the only person I trust with this." · "Earn £200 receiving one transfer" then many more.

Coercive control · "Don't tell anyone about us." · "Your family doesn't understand you." · "Just this once."

Three different harms, one shared tactic architecture. Any detection approach that treats them as separate vocabulary problems is solving the wrong problem three times over.

Europol has identified Instagram, Snapchat and encrypted messaging apps as routine money mule recruitment channels, dressed up as "money transfer agent" or "payment processor" roles and aimed squarely at 12 to 21 year olds. Sextortion offenders are adapting the same way, moving conversations quickly onto encrypted apps precisely to make detection and case-linking harder. That evasion is the tell. When a tactic is deliberately hidden, surface-level filtering was never going to catch it.

Why keyword detection fails

The academic foundations here are decades old and have never been more relevant.

--- · ---

Finkelhor (1984) · Precondition model: abuse is a staged process, not an event.

Craven, Brown & Gilchrist (2006) · Grooming is a taxonomy of tactics, not a vocabulary.

Olson et al. (2007) · Perpetrators establish anticipatory secrecy norms before any harmful interaction.

Whittle et al. (2013) · Grooming hides inside normal, legitimate use of social platforms.

The engineering dilemma is one of precision. Tune a system aggressively to catch all secrecy language and it drowns in false positives: birthday surprises, therapy conversations, ordinary teenage privacy all trip the alarm. Tune it narrowly to avoid that and it misses the harm it exists to catch.

Neither setting is acceptable. The gap between them is the core technical challenge, and it cannot be closed by adjusting a threshold on a word list. It can only be closed by understanding context.

Why this matters now

This has moved from a moral argument to a legal one. Since 25 July 2025, under the UK Online Safety Act, Ofcom's Protection of Children Codes require in-scope services to protect children from illegal harms, including grooming and coercive or controlling behaviour, or face enforcement with fines of up to £18 million or 10 per cent of global turnover. Ofcom has called 2025 its "year of action" and is now consulting on the role AI can play in detecting grooming.

The regulator is asking platforms the exact question this article poses: can you tell the difference between a phrase that looks harmful and a phrase that is harmful in context? A threshold-tuned keyword list cannot answer it. Only something that reasons across a whole conversation can.

Built with the people who know

At Tuteliq, our detection is not built on keyword lists or surface-level pattern matching. It is built on the behavioural architecture of harm: tactics, co-occurrence, sequence, and the crucial difference between a phrase that looks harmful and a phrase that is harmful in context.

That understanding has been built with:

  • Academics who have spent their careers studying grooming, financial crime, and coercive control.
  • Professionals on the front line of child protection, law enforcement, and financial crime prevention.
  • People with lived experience of these harms, whose knowledge of how this actually sounds cannot be replicated by any model trained on theory alone.

The result is a system that knows "can you keep a secret?" from a parent is not the same thing as "can you keep a secret?" from a stranger who has been steadily isolating a child from everyone who might have noticed. That is not a small technical distinction. It is the entire problem.

References

Craven, S., Brown, S., & Gilchrist, E. (2006). Sexual grooming of children: Review of literature and theoretical considerations. Journal of Sexual Aggression, 12(3), 287–299.

Financial Action Task Force (FATF). (2019). Professional Money Laundering. FATF, Paris.

Finkelhor, D. (1984). Child Sexual Abuse: New Theory and Research. Free Press, New York.

Home Office. (2015). Controlling or Coercive Behaviour in an Intimate or Family Relationship: Statutory Guidance Framework. HM Government, London.

Levi, M., & Handley, M. (2016). Money mule typologies and the recruitment of intermediaries in financial crime. In Studies on financial crime facilitation and laundering.

Olson, L. N., Daggs, J. L., Ellevold, B. L., & Rogers, T. K. K. (2007). Entrapping the innocent: Toward a theory of child sexual predators' luring communication. Communication Theory, 17(3), 231–251.

Stark, E. (2007). Coercive Control: How Men Entrap Women in Personal Life. Oxford University Press, New York.

Whittle, H., Hamilton-Giachritsis, C., Beech, A., & Collings, G. (2013). A review of young people's vulnerabilities to online grooming. Aggression and Violent Behavior, 18(1), 62–70.

Contemporary data sources

  • National Center for Missing & Exploited Children (NCMEC). CyberTipline data, 2025.
  • Europol. Guidance on money mule recruitment channels and tactics.
  • National Crime Agency (NCA). Money muling guidance and estimates.
  • Ofcom. Protection of Children Codes of Practice under the Online Safety Act, 2025.

Read the companion report

The State of Kids' Online Slang 2026 maps the coded words this essay explains. 367 terms, 14 categories, source-verified. → tuteliq.ai/reports/kids-online-slang-2026

Get Started Free · Read Documentation · View Pricing