Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The UK Online Safety Act 2023 makes online safety a legal compliance obligation, not just a platform policy choice. It gives Ofcom powers to require regulated services to assess and reduce risks, and to penalise serious failures. Major platforms and search providers can fall within its reach when they serve people in the UK—even if their provider is based abroad—but the duties depend on the service and its features, not simply on whether a company is called “Big Tech.”

What is the UK Online Safety Act?

The Online Safety Act 2023 is the UK’s statutory framework for regulating online services’ handling of illegal content and content harmful to children. It received Royal Assent on 26 October 2023. The Department for Science, Innovation and Technology describes it as giving social-media companies and search services legal duties to protect users from illegal content and content harmful to children.

The Act also established Ofcom’s online-safety regulatory role. Instead of prescribing one moderation method for every website or app, the framework requires regulated providers to understand the risks associated with their services and take measures to meet their duties. Ofcom’s 2025 sector assessment described the change as requiring “a fundamental shift in how firms develop their products and run their services.”

Which companies and services are covered?

Coverage turns on the kind of service, its connection to the UK, and the relevant statutory definitions and thresholds—not a company’s size or fame alone. The framework covers qualifying user-to-user services, search services and other regulated services with links to the UK. A provider headquartered overseas can still be in scope if its service has the required UK link.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That means a large social platform or search provider may have UK obligations even if it is based in the United States or elsewhere. But not every service offered by a well-known technology company necessarily faces the same duties. Secondary legislation laid on 16 December 2024 set thresholds for Category 1, 2A and 2B services; the category a service falls into matters because additional duties apply to certain categories.

“Big Tech” is therefore a useful description of the companies likely to attract attention, but it is not the Act’s legal test. Whether a particular product is covered depends on the service’s design, function, UK links and applicable thresholds.

What must regulated services do?

The Act’s core obligations focus on systems and processes: providers must assess relevant risks, take steps to reduce them, and deal with illegal content in accordance with their duties. The law lists more than 130 priority offences. Ofcom’s codes and guidance set out recommended measures, including risk assessment, governance and technical controls.

  • Assess risk: providers need to identify how their service could be used for illegal activity and, where relevant, how children could encounter harmful content.
  • Put safeguards in place: measures should respond to the service’s risks. Ofcom’s recommended measures are not a universal requirement to deploy any one technology across all services.
  • Respond to illegal content: the government says services must reduce the risk of being used for illegal activity and take down illegal content when it appears, in line with their duties.
  • Document decisions and cooperate: Ofcom can require information. Its compliance guide says statutory responses should be accurate, complete and timely, making records of risk assessments and decisions practically important.

For some high-risk file-sharing services, Ofcom cites automated perceptual-hash matching to identify and remove child-sexual-abuse material. This is an example of a measure Ofcom recommends in particular circumstances, not a blanket technology mandate for every platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can Ofcom enforce the law?

Ofcom can require information and investigate whether regulated providers are meeting their duties. For serious cases, its 2024 compliance guide gives a maximum penalty of £18 million or 10% of qualifying worldwide revenue, whichever is greater. The revenue-linked ceiling means exposure is not limited to a fixed fine, although it is a maximum rather than an automatic penalty.

In its 17 March 2025 announcement, Ofcom said platforms had to start putting measures in place to protect people in the UK from criminal activity and launched an enforcement programme. That programme required certain large services and smaller high-risk services to submit risk assessments by 31 March 2025; Ofcom warned that inadequate or late responses could lead to enforcement. Ofcom’s 2025 sector summary also reported enforcement activity involving more than 80 pornography websites that year. That is a figure from its 2025 reporting, not a standing count.

For providers, the practical implication is that compliance involves more than publishing a policy. They need to be able to show how they identified risks, chose safeguards, assigned responsibility and responded to Ofcom’s requests.

What are the key implementation dates?

Ofcom’s published timetable describes a phased rollout. The dates below reflect the milestones identified in the cited Ofcom materials; they do not mean that every duty applied to every service on the same day.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date Milestone What it means
26 October 2023 The Act received Royal Assent. The Online Safety Act became law.
16 December 2024 Secondary legislation setting Category 1, 2A and 2B thresholds was laid. Service categorisation is relevant to additional duties.
16 March 2025 Ofcom’s timetable set the deadline for regulated services to complete illegal-content risk assessments under the first codes and guidance. Providers needed to assess illegal-content risks under that initial stage.
31 March 2025 Risk-assessment submission date for services in Ofcom’s March enforcement programme. This applied to certain large services and smaller high-risk services covered by that programme.
7 April 2026 Ofcom’s timetable listed this date for the duty requiring regulated user-to-user services to report detected and unreported child-sexual-abuse content to the National Crime Agency, subject to applicable regulations. The timetable date has passed; the duty’s application is subject to the relevant regulations.

Age assurance, children’s access assessments and additional duties for categorised services are also part of the staged framework. Their precise requirements depend on the applicable rules and guidance; providers should use Ofcom’s current materials to establish which duties apply to a particular service.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why is it described as a crackdown on Big Tech?

The Act gives a regulator enforceable powers over services used in the UK, including services provided by overseas companies. Its combination of risk-assessment duties, systems requirements, information notices, transparency expectations and potentially revenue-linked penalties makes it more than a voluntary code of conduct. In that sense, it contributes to a wider international push to make technology companies accountable for foreseeable harms connected to their products. The European Union’s Digital Services Act is another prominent part of that broader regulatory trend, though the regimes are distinct.

The “crackdown” label should not obscure how the law works: it does not impose identical controls on every major technology company. Duties vary by service type, risk, features and, for some obligations, category thresholds. Nor does the existence of a legal duty by itself establish that a particular company has broken the law; that is a compliance question for Ofcom to assess.

What are the concerns about privacy, speech and encryption?

Government presents the law as a way to protect users from illegal content and children from harmful material. Civil-liberties groups and technology companies have raised concerns about privacy, freedom of expression, age verification and the possible effect of safety rules on end-to-end encryption. These are contested questions about how safeguards are designed and enforced, rather than proof that every regulated service must weaken encryption or verify every user’s age in the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Act’s risk-based structure makes implementation important: services must meet their applicable duties, while Ofcom’s guidance and enforcement determine how those obligations are applied in practice. Readers evaluating a specific platform or feature should distinguish the law’s stated duties from a company’s particular implementation and from criticism of that implementation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.