Grades 5-8 Online Safety
Online & AI Safety for Teens
Simple rules. Real risks. Smart habits.
You probably use your phone for much more than messaging. You may shop online, use Apple Pay or a debit card, log into school accounts, use AI tools, join Discord servers, play games, scan QR codes, post photos, sell things, buy tickets and communicate with people you have never met in person.
That independence is normal. It also means that online safety is no longer just about not talking to strangers. It is about protecting your accounts, money, identity, privacy and judgment.
Monthly Newsletter
Subscribe to our monthly newsletter
Our newsletter may include practical resources on AI and cybersecurity, updates from our nonprofit partners, community stories and Donate Foundation news.
What changes in middle school
Online safety is about protecting your accounts, money, identity, privacy and judgment before a scam, fake message or risky AI output pushes you to react.
Smart Habits
Simple rules for real online risks
Rule 1
Lock Your Accounts
A stolen social account can become a way to reach your friends. A compromised email account can be used to reset passwords for other services.
- Use long, unique passwords.
- Do not reuse the same password everywhere.
- Turn on multifactor authentication (MFA/2FA).
- Never give another person a one-time verification code.
- Keep your phone and devices updated.
CISA specifically recommends strong passwords, MFA, recognizing phishing and keeping software updated as core online-security habits.
Rule 2
Think Before You Tap
Phishing is not limited to badly written emails. It can look like:
- A text about a package
- A school or account warning
- A QR code
- A "free" giveaway
- A fake job or collaboration offer
- A message from a hacked friend's account
- A fake login page
- A payment request
- A link promising an exclusive item, game reward or ticket
Before entering a password or payment information, ask: Did I expect this? Why do they need me to act now? Can I open the official app or website myself instead of using this link? That last step is one of the easiest ways to break a scammer's script.
Rule 3
Protect Your Money
If you have your own card or payment app, you are also a potential target for financial scams.
Never share your complete card details, PINs, banking passwords, verification codes or account recovery codes.
Be extra cautious when someone asks you to pay using gift cards, crypto or other difficult-to-reverse methods.
Seeing money in a screenshot is not the same as actually receiving money. Check your real banking or payment app.
Rule 4
Guard Your Identity
Pieces of information that seem harmless can become useful when combined:
- Your school
- Your birthday
- Where you work
- Your sports schedule
- Your home neighborhood
- A photo of a student ID
- A picture of a new driver's permit
- Your live location
Think about what your posts reveal when someone sees them together rather than one at a time. Also check location sharing and app permissions periodically.
Rule 5
Learn the Red Flags of Manipulation
Modern scams often target your emotions before they target your account. Watch for:
- Urgency: "Do this now."
- Secrecy: "Don't tell anyone."
- Pressure: "If you really trust me..."
- Fear: "You're in trouble unless..."
- Flattery or romance: "You're different from everyone else."
- Reward: "You won."
- Isolation: "Your friends/parents won't understand."
- Moving platforms: "Let's take this conversation somewhere private."
One red flag does not automatically mean something is a scam. Several together are a reason to stop.
Rule 6
AI Is Useful - Not Automatically True
Generative AI can help brainstorm, explain ideas, organize notes, write code and create images.
But fluent language is not proof of accuracy. AI can:
- Invent facts or sources
- Confidently give incorrect answers
- Reproduce bias
- Misunderstand context
- Generate convincing fake content
For important information, verify the answer using reliable sources. Never paste sensitive personal, school, financial or health information into an AI tool unless you know the tool is approved for that information. California's current school guidance emphasizes data privacy, responsible use, academic integrity and human-centered learning when AI is used in education. UNESCO similarly frames AI literacy as learning how to evaluate AI critically and engage with it responsibly.
Rule 7
Deepfakes Changed What Proof Means
A photo is not automatically proof. Neither is a screenshot, voice message, video, social profile, caller ID or AI-generated image.
AI makes impersonation easier.
If a message involving money, threats or a serious emergency appears to come from someone you know, verify through another channel. Call the person. Message them through a number you already have. Ask something the impersonator would not know. Pause before reacting.
Rule 8
Private Images Can Become a Tool for Blackmail
If someone pressures you to send a private image, threatens to publish an image, demands money or claims to already have something embarrassing about you:
- Do not keep negotiating.
- Do not assume paying will make the problem disappear.
- Save evidence if you safely can, block/report the account and tell a trusted adult.
You are dealing with a manipulation problem, not a problem you have to solve alone. The FBI and NCMEC both maintain specific resources for young people and families dealing with sextortion and online exploitation.
Rule 9
Use AI Honestly
AI can be a useful tool without becoming a shortcut around learning.
Know your school's rules. If AI assistance needs to be disclosed, disclose it. If an assignment is supposed to show your own reasoning, do your own reasoning.
Do not use AI to impersonate another person, create fake or humiliating images, bully someone, manufacture evidence or spread information you know is false.
The fact that something is technically possible does not make it harmless.
Donate Research Insight
Scams are designed to make you react
A sophisticated scam does not necessarily look suspicious. Many attacks are built around human behavior, not around breaking through sophisticated technology.
The goal may be to create just enough fear, urgency, attraction, trust or excitement to get you to act before you verify.
Some large-scale online scam operations are part of organized criminal ecosystems, including industrialized scam centers documented by international law enforcement. You are not necessarily dealing with one random person typing messages from a bedroom.
PAUSE - VERIFY - ASK FOR HELP
A ten-second pause can interrupt a carefully designed manipulation attempt.
If Something Goes Wrong
Stop the damage quickly
Save
Do not delete everything immediately. When appropriate, take screenshots.
Secure
Stop responding, block and report the account, change compromised passwords and check connected accounts and payments.
Tell
Tell a trusted adult, school staff member or other appropriate authority.
Getting caught by a convincing scam does not mean you were stupid. The important part is stopping the damage quickly.
Learn More
Download the printable teen safety flyer
This guide was developed by the Donate Foundation team based on our research into cybersecurity, social engineering and responsible AI use and informed by public guidance from CISA, FBI, California Department of Education, NCMEC/ NetSmartz, UNICEF and UNESCO.
Stay Connected
Subscribe to our monthly newsletter
Our newsletter may include practical resources on AI and cybersecurity, updates from our nonprofit partners, community stories and Donate Foundation news.
Explore Next
More safety guidance from Donate Foundation
Donate Foundation Mission
Safety resources are one part of helping families find trusted support.
Donate works with reviewed U.S. nonprofit partners supporting women, children and families. If this guide was useful, you can also explore current nonprofit stories and see where verified community support is needed.
Explore fundraising stories