Online Safety Act duties: what platforms must do now

Online Safety Act duties: what platforms must do now under the Online Safety Act 2023

In short: Online Safety Act duties apply in layers, as at 28 August 2026: every regulated service must assess and manage illegal content risk (Online Safety Act 2023, ss 9, 10, 26 and 27), services likely to be accessed by children are subject to children’s duties (ss 11, 12, 28 and 29), user-to-user services must report CSEA content (s 66), and categorised services must produce transparency reports (s 77).

By Rob Bratby, Managing Partner, Bratby Law. Recognised in the Lexology Index as a Thought Leader for data privacy and protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A provider that has established its service is regulated under the Online Safety Act 2023 must then identify which obligations apply to it, and every substantive duty set is now enforceable. The scope question, whether the Act applies at all, is worked through in does the Online Safety Act apply to my service; the duty side is what online safety compliance actually requires of a regulated service, as the law stood on 28 August 2026.

Illegal content duties for every regulated service

Every provider of a regulated user-to-user or search service must carry out a suitable and sufficient illegal content risk assessment (ss 9 and 26). A user-to-user provider must take proportionate measures to prevent users encountering priority illegal content and to mitigate the risks its risk assessment identifies, minimise the length of time any priority illegal content is present, and swiftly take down any illegal content once alerted to it or otherwise aware of it (s 10(2) and (3)). Since 29 June 2026 the same section has required systems designed to take down content covered by an intimate image content report, and substantially similar content, as soon as reasonably practicable and no later than 48 hours after the report (s 10(3A) and (3B), inserted by the Crime and Policing Act 2026, with search equivalents in s 27(3A) and (3B)). A search service’s duties operate on search results rather than takedown: it must mitigate and manage the risks its risk assessment identifies and minimise the risk of individuals encountering priority illegal content, and other illegal content it knows about, in search content (s 27(2) and (3)). These duties have been enforceable since 16 and 17 March 2025, following Ofcom’s illegal harms statement of 16 December 2024 and the Illegal Content Codes of Practice, which set out the measures Ofcom recommends for compliance. A user-to-user provider must also keep a written record of every risk assessment and of the code measures it has taken, record how any alternative measures amount to compliance, and review compliance regularly and after any significant change to the service’s design or operation (s 23); section 34 applies equivalent record-keeping and review duties to search services.

Children’s duties: access assessments, risk assessments and age assurance

Every regulated user-to-user and search service must complete a children’s access assessment (ss 35 to 37), and a provider may conclude that children cannot access its service only where age verification or age estimation means children are not normally able to access it (s 35(2)). A user-to-user service likely to be accessed by children must carry out a children’s risk assessment (s 11) and comply with the children’s safety duties (s 12), with search equivalents in sections 28 and 29, enforceable since 24 and 25 July 2025 under Ofcom’s Protection of Children statement and codes. A provider that identifies primary priority content that is harmful to children on its service must use highly effective age assurance to prevent children of any age encountering it (s 12(4) and (6)), unless its terms of service prohibit that kind of content for all users (s 12(5)). Ofcom has published a non-exhaustive list of methods capable of being highly effective, including open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation; self-declaration is not among them. A provider that publishes its own pornographic content is under the parallel Part 5 duty (s 81), in force since 17 January 2025, and the age assurance it uses must meet the same highly effective standard. Age assurance processes personal data, so a provider must satisfy UK GDPR obligations alongside the Act; the data protection practice page covers that interaction.

CSEA reporting and fees

Every provider of a regulated user-to-user service, whatever its size, must report detected and unreported child sexual exploitation and abuse content to the National Crime Agency (s 66), in force since 7 April 2026 under the Commencement No 7 Regulations (SI 2026/262); CSEA reporting that contains materially false information is an offence under section 69 where the person knows it is false or is reckless as to whether it is. And a provider whose qualifying worldwide revenue meets the £250 million threshold in SI 2025/1204 must notify Ofcom and pay fees, unless exempt because its UK referable revenue is below £10 million; the 2027/28 notification window closes on 30 September 2026, per Ofcom’s fees pages. The fees regime is examined in who pays for Ofcom’s online safety regulation.

Additional duties for categorised services

A service on Ofcom’s register of categorised services, published on 30 June 2026 under the threshold conditions in SI 2025/226, is subject to obligations beyond the base set. Each Category 1, 2A and 2B service must produce an annual transparency report in response to an Ofcom notice, containing the information the notice specifies, submitted and published by the dates it sets (s 77). A Category 1 service must also keep written records of its user empowerment assessments and supply each record to Ofcom (s 23(9) and (10)). Ofcom is consulting on further duties for categorised services, including a fraudulent advertising code of practice consultation published on 10 July 2026, and services on the emerging Category 1 list are not subject to additional duties. Ofcom has also added crisis-response measures to the codes, covered in the Ofcom crisis response protocol, and the announced under-16 social media ban would add access restrictions by regulation under section 214A, analysed in the under-16 social media ban post.

Ofcom enforcement

Ofcom may fine a non-compliant provider up to the greater of £18 million and 10 per cent of qualifying worldwide revenue (Schedule 13, para 4), and the courts may make service restriction orders against ancillary services such as payment providers and advertisers (s 144) and access restriction orders against internet access services and app stores (s 146). A senior manager named in a response to an information notice commits an offence under section 110 where the entity commits an information offence and that individual has failed to take all reasonable steps to prevent it; senior manager liability was extended from 30 September 2025 to cover deletion of information. Ofcom enforcement is well past the preparatory stage: on 28 August 2026 Ofcom reported formal investigations involving more than one hundred apps and online services over eighteen months and fines exceeding £6 million, in its supervision and compliance statement. Ofcom also runs open enforcement programmes on age assurance in the adult sector, illegal content risk assessments and children’s risk assessments. Where Ofcom opens an investigation or serves an information notice, the investigations and enforcement support page sets out how that work is scoped.

DutyWho must complyProvisionEnforceable or due from
Part 5 pornography age assuranceProviders publishing their own pornographic contentOSA s 8117 January 2025
Illegal content risk assessmentAll regulated user-to-user and search servicesOSA ss 9, 26Due by 16 March 2025
Illegal content safety dutiesAll regulated user-to-user and search servicesOSA ss 10, 2717 March 2025
Children’s access assessmentAll Part 3 servicesOSA ss 35 to 37Due by 16 April 2025
Children’s risk assessment and safety dutiesUser-to-user services likely to be accessed by children (search: ss 28, 29)OSA ss 11, 1224 and 25 July 2025
CSEA reporting to the National Crime AgencyRegulated user-to-user servicesOSA s 667 April 2026
Fees notification and paymentProviders at or above £250m qualifying worldwide revenueOSA Part 6Charging year from 1 April 2026
Transparency reportsCategory 1, 2A and 2B servicesOSA s 77On Ofcom notice, annually

Viewpoint

In my view the record-keeping duties in section 23 decide the outcome of an Ofcom investigation, because they are what Ofcom can inspect. The substantive duties are outcomes-based and contestable; a missing written record of a risk assessment, or of why an alternative measure amounts to compliance, is a bare fact. Ofcom’s open enforcement programmes on illegal content risk assessments and children’s risk assessments test exactly that documentation, and in its supervision and compliance statement of 28 August 2026 Ofcom set out a supervision model already operating at volume. A provider that treats the written record as the primary compliance artefact, reviewed on each significant product change as section 23(6) requires, is in a defensible position when the information notice arrives. Good safety engineering does not substitute for the record.

Frequently asked questions

What are the illegal content duties under the Online Safety Act?

Every regulated user-to-user and search service must carry out an illegal content risk assessment (ss 9 and 26). A user-to-user service must prevent users encountering priority illegal content, minimise the time it is present and take down any illegal content it is alerted to or otherwise aware of (s 10), including intimate image content within 48 hours of a report since 29 June 2026; a search service must minimise the risk of users encountering illegal content in search content (s 27). The duties have been enforceable since 16 and 17 March 2025.

Do small services have duties under the Online Safety Act?

Yes. The illegal content duties, the children’s access assessment, the section 23 record-keeping duties and CSEA reporting apply to every regulated service of the relevant type, with no size threshold. Size matters only to categorisation, which adds transparency reports and other obligations for Category 1, 2A and 2B services, and to fees, which apply from £250 million of qualifying worldwide revenue.

What records must a provider keep under the Online Safety Act?

Under section 23 a provider of a regulated user-to-user service must keep a written record of every illegal content and children’s risk assessment, of the code measures it has taken, and of how any alternative measures amount to compliance, and must review compliance regularly and after any significant change to the service. A Category 1 service must also record its user empowerment assessments and supply Ofcom with copies of its risk assessment and user empowerment records (s 23(9) and (10)).

What happens if a provider does not comply?

Ofcom enforcement can end in a penalty of up to the greater of £18 million and 10 per cent of qualifying worldwide revenue (Schedule 13), court orders restricting payment, advertising and app store services (ss 144 to 146), and criminal liability for information offences, including for a named senior manager under section 110. As at 28 August 2026 Ofcom reports fines exceeding £6 million and investigations involving more than one hundred services.


For advice on Online Safety Act duties, risk assessments or an Ofcom investigation, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts