Does the Online Safety Act apply to my service?

In short: three tests answer “does the Online Safety Act apply to my service?” as at 28 August 2026: whether the service enables user-generated content, includes a search engine or publishes pornographic content (ss 3 and 80); whether it has links with the UK (s 4, or s 80(4) for pornography providers); and whether an exemption covers it in full (Schedule 1, or Schedule 9 for other services within Part 5).
A comments feature, a review widget or an in-app chat can be enough to bring a service within the Online Safety Act 2023. A service is regulated on what it does and on its links with the UK. A provider operating entirely from overseas is regulated on the same terms as one operating from London.
The three kinds of service the Act regulates
The Online Safety Act 2023 regulates three kinds of internet service: user-to-user services, search services and services publishing pornographic content, under section 3 and Part 5 of the Act. A user-to-user service is an internet service by means of which content generated, uploaded or shared by a user may be encountered by another user (s 3(1)). Content does not have to be shared with anyone: a functionality that allows sharing is enough (s 3(2)(a)), and the proportion of content that is user-generated is irrelevant (s 3(2)(b)). A retail site whose only user content is a review section, or a news site with a comments field, therefore meets the definition of a user-to-user service. Whether it is regulated then depends on its links with the UK and on the Schedule 1 exemptions (s 4(2)).
A search service is an internet service that is, or includes, a search engine (s 3(4)). A service that both hosts user-generated content and includes a search engine counts as a search service only where the user-generated content it enables is confined to the narrow categories in Schedule 1, and is otherwise a user-to-user service (s 3(5) to (7)). A regulated user-to-user service with a public search engine is a combined service (s 4(7)) and is subject to both sets of duties.
Publishing pornographic content is a separate route into the regime and does not depend on user-generated content. A service on which regulated provider pornographic content is published or displayed, which is not exempt and which has links with the UK within section 80(4), is a regulated service under Part 5 (ss 79 to 82 and s 4(4)(c)), even where it is neither a user-to-user nor a search service. The provider of such a service must use age verification or age estimation to ensure that children are not normally able to encounter that content, and the measure must be highly effective at correctly determining whether a particular user is a child (s 81(2) and (3)).
Links with the United Kingdom
A user-to-user or search service is regulated only if it has links with the UK, and a service can have them on either of two bases (section 4). Under section 4(5), a service has UK links where it has a significant number of UK users, or where UK users form one of its target markets. Under section 4(6), a service also has UK links where it is capable of being used in the UK and there are reasonable grounds to believe there is a material risk of significant harm to individuals in the UK from content on it. There is no establishment or place-of-business test on either basis. A provider with nothing in the UK beyond its users is within scope where those users are significant in number, and can be within scope under section 4(6) where they are not. For a Part 5 pornography service the UK-links test is section 80(4), which carries the section 4(5) limbs only.
The Schedule 1 exemptions and the section 55 carve-outs
Schedule 1 exempts services whose user-generated content is limited to specific low-risk kinds. A service where emails are the only user content is exempt (para 1), as are SMS and MMS services (para 2) and services offering only one-to-one live aural communications (para 3). A limited functionality service is exempt under paragraph 4: one where users can communicate only by posting comments and reviews on the provider’s own content, sharing those comments and reviews on a different internet service, expressing a view on the provider’s content or on such comments and reviews through likes, ratings or votes, or displaying identifying content. A news site or retail site whose users can do no more than that is exempt on this basis. Combinations of those content types are exempt under paragraph 5. Paragraph 6 removes all of these exemptions where regulated provider pornographic content is published or displayed on the service and the service has links with the UK within section 80(4): a Part 5 service cannot rely on the email or limited-functionality exemptions.
An internal business service is exempt under paragraph 7 where the service is an internal resource or tool for a business, the provider carries on that business, and access is limited to a closed group of officers, workers and persons they authorise. The exemption covers the corporate intranet and the enterprise collaboration tool, and extends to educational institutions. Services provided by public bodies exercising public functions are exempt under paragraph 9, and services provided by persons with legal responsibility for specified descriptions of education and childcare are exempt under paragraph 10 where provided for the purposes of that education or childcare; a person employed or engaged to provide the education or childcare qualifies for that exemption only where they are subject to safeguarding duties.
A regulated service keeps its regulated status, but emails, SMS and MMS, one-to-one live aural communications, comments and reviews on provider content and news publisher content are not regulated user-generated content (s 55(2)), so the Part 3 safety duties do not apply to them. The carve-out is confined to comments and reviews on content the provider itself publishes: on a marketplace whose listings are posted by users, the listings are user-generated content, so the Part 3 safety duties apply to reviews of them (s 55(6) and (7)).
The scope test, step by step
Scope depends, in order, on whether the service is an internet service; whether it enables user-generated content that another user may encounter (s 3(1)), includes a search engine (s 3(4)) or publishes provider pornographic content (s 80(2)); whether it has links with the UK, under section 4(5) or 4(6) for user-to-user and search services or under section 80(4) for a Part 5 service; and whether an exemption covers it in full, under Schedule 1 for user-to-user and search services or Schedule 9 for other services within Part 5 (s 80(3)). A regulated service is then classified as a user-to-user service, a search service, a combined service or a Part 5 service, and the classification determines which duties attach. Categorisation as Category 1, 2A or 2B adds further duties on top of the base set. Ofcom publishes a self-assessment tool for the scope steps, and the duties themselves are set out in more detail in what platforms must do now.
Categorisation: Category 1, 2A and 2B
Categorisation does not decide whether the Act applies; it decides which additional duties apply to a service that is already regulated. The threshold conditions are set by the Online Safety Act 2023 (Category 1, Category 2A and Category 2B Threshold Conditions) Regulations 2025 (SI 2025/226), measured by mean monthly active UK users over six months. Ofcom published its first register of categorised services on 30 June 2026 and last updated it on 14 August 2026. Ofcom has categorised eleven services as Category 1 (Facebook, Instagram, Pinterest, Quora, Reddit, Roblox, Snapchat, TikTok, WhatsApp, X and YouTube), four as Category 2A (Google Search, Bing, ChatGPT Search and one Facebook search engine) and twenty-four as Category 2B, a list that includes iMessage, Discord, Steam, Fortnite, eBay, Vinted, Airbnb, Mumsnet and Strava. Providers may ask Ofcom to remove a service from the register under section 96, and services on the emerging Category 1 list are not subject to additional duties (see s 97).
| Category | Threshold condition (SI 2025/226) | Register at 14 August 2026 |
|---|---|---|
| Category 1 (reg 3) | User-to-user service exceeding 34 million average monthly active UK users with a content recommender system, or exceeding 7 million with a content recommender system and a forwarding or sharing functionality | 11 services, including Facebook, TikTok, WhatsApp, X and YouTube |
| Category 2A (reg 4) | Search engine exceeding 7 million average monthly active UK users, other than a vertical search engine that only enables search of selected websites or databases on a specific topic and operates through arrangements relying on an API or other technical means | 4 services, including Google Search and Bing |
| Category 2B (reg 5) | User-to-user service exceeding 3 million average monthly active UK users with a direct messaging functionality | 24 services, including iMessage, Discord, Steam and eBay |
The duties and their commencement dates
A regulated service is subject to obligations that took effect in stages as Ofcom’s codes and guidance came into force. Every regulated user-to-user and search service must complete an illegal content risk assessment (ss 9 and 26) and comply with the illegal content duties (ss 10 and 27), enforceable since 16 and 17 March 2025 following Ofcom’s illegal harms statement of 16 December 2024 and the Illegal Content Codes of Practice. Every Part 3 service must also complete a children’s access assessment (ss 35 to 37), and a provider may conclude that children cannot access the service only where age verification or age estimation means children are not normally able to access it (s 35(2)). A service likely to be accessed by children must carry out a children’s risk assessment (s 11) and comply with the children’s safety duties (s 12), enforceable since 24 and 25 July 2025, and a provider that identifies primary priority content that is harmful to children on its service must use highly effective age assurance to prevent children of any age encountering it (s 12(4) and (6)), unless its terms of service prohibit that kind of content for all users (s 12(5)). Ofcom has identified open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation as methods capable of being highly effective; self-declaration is not.
Operational duties that apply well below the categorisation thresholds took effect in 2026. Every regulated user-to-user service must report child sexual exploitation and abuse content to the National Crime Agency under section 66, in force since 7 April 2026 under the Commencement No 7 Regulations (SI 2026/262); providing materially false information in purported compliance is an offence under section 69. And a provider whose qualifying worldwide revenue meets the £250 million threshold set by the Fees (Threshold Figure) Regulations 2025 (SI 2025/1204) must notify Ofcom and pay fees, unless exempt because its UK referable revenue is below £10 million, with the first charging year running from 1 April 2026 and the 2027/28 notification window closing on 30 September 2026 per Ofcom’s fees pages. The fees regime is examined on this site in who pays for Ofcom’s online safety regulation, and the codes’ crisis-response additions in the Ofcom crisis response protocol.
| Duty | Provision | Enforceable or due from |
|---|---|---|
| Part 5 pornography age assurance | OSA s 81 | 17 January 2025 |
| Illegal content risk assessment | OSA ss 9, 26 | Assessments due by 16 March 2025 |
| Illegal content safety duties | OSA ss 10, 27 | 17 March 2025 |
| Children’s access assessment | OSA ss 35 to 37 | Due by 16 April 2025 |
| Children’s risk assessment | OSA s 11 | Due by 24 July 2025 |
| Children’s safety duties | OSA s 12 | 25 July 2025 |
| CSEA reporting to the National Crime Agency | OSA s 66 | 7 April 2026 |
| Fees notification and payment (£250m threshold) | OSA Part 6 | Charging year from 1 April 2026 |
Enforcement
Ofcom may fine a non-compliant provider up to the greater of £18 million and 10 per cent of qualifying worldwide revenue (Schedule 13, para 4), measured against group revenue where group entities are jointly and severally liable (para 5). A named senior manager commits a criminal offence under section 110 where they fail to take all reasonable steps to prevent the entity’s information offences under section 109, a provision the Data (Use and Access) Act 2025 extended from 30 September 2025 to cover deletion of information. The courts may also make service restriction orders against ancillary services such as payment providers and advertisers (s 144) and access restriction orders against internet access services and app stores (s 146). On 28 August 2026 Ofcom reported, in its supervision and compliance statement, formal investigations involving more than one hundred apps and online services over eighteen months and fines exceeding £6 million, and in the same statement named open enforcement programmes on age assurance in the adult sector, illegal content risk assessments and children’s risk assessments.
The under-16 social media ban and section 214A
Section 70(2) of the Children’s Wellbeing and Schools Act 2026 inserted a new section 214A into the Act with effect from 29 April 2026, empowering the Secretary of State to make regulations requiring providers of specified internet services to prevent or restrict access by children of or under a specified age, including restrictions on functionalities such as stranger contact, livestreaming and location disclosure (s 214A(4)). The Secretary of State must exercise the power following the conclusion of the Growing up in the online world consultation (s 214A(9)). The Government announced on 15 June 2026 that social media will be banned for under-16s, and has said it intends to bring the measure to Parliament before the end of 2026, with protections expected to be in force in spring 2027. As at 28 August 2026 no regulations under section 214A have been made, so the ban is announced policy resting on an existing enabling power; until regulations are made, no provider is subject to any obligation under it. The mechanics of the announcement are analysed in the under-16 social media ban post on this site, and the wider platform child-safety context in the Meta child safety settlement analysis.
Viewpoint
A service moves into the regime, or into a heavier tier of it, when its functionality changes. A feature that lets users share content beyond their own comments and reviews ends the limited-functionality exemption. A public search engine turns the service into a combined service. A direct messaging feature on a service exceeding 3 million UK users meets the Category 2B threshold in SI 2025/226. On the register, iMessage, Steam and eBay appear on the Category 2B list beside the social networks. The scope analysis belongs in product governance, before any feature release that changes how users interact, and in regulatory due diligence on the acquisition of any consumer-facing digital service. Regulatory perimeter and market entry work is scoped on the same basis.
Frequently asked questions
Does the Online Safety Act apply to services based outside the UK?
Yes, where the service has links with the UK. Under section 4(5) of the Online Safety Act 2023 a service has UK links where it has a significant number of UK users or UK users form a target market, and under section 4(6) where it is capable of being used in the UK and there are reasonable grounds to believe that content on it presents a material risk of significant harm to individuals in the UK. There is no establishment test.
Is a website with a comments section covered by the Online Safety Act?
Usually not. Schedule 1, paragraph 4 exempts limited functionality services where users can communicate only through comments and reviews on the provider’s own content, likes, votes or ratings. A site whose user features go further, for example user-to-user replies detached from provider content, or sharing of content other than a user’s own comments and reviews, falls outside the exemption and is regulated if it has UK links.
What are the penalties for breaching the Online Safety Act?
Ofcom may impose a penalty of up to the greater of £18 million and 10 per cent of qualifying worldwide revenue (Schedule 13, para 4), seek court orders disrupting payment, advertising and app store services (ss 144 to 146), and prosecute information offences. A senior manager named in a response to an information notice commits an offence under section 110 where the entity commits an information offence and that individual has failed to take all reasonable steps to prevent it.
When does the under-16 social media ban take effect?
No date is set in law. The Government announced the ban on 15 June 2026 and intends to lay regulations under section 214A of the Online Safety Act 2023 before the end of 2026, with protections in force in spring 2027. As at 28 August 2026 no regulations have been made, so no under-16 ban is currently in force.
For advice on whether the Online Safety Act applies to your service, or on the duties that follow if it does, contact Rob Bratby at Bratby Law.
