The Online Safety Act (OSA) is the United Kingdom’s flagship online-safety statute. It became law on 26 October 2023 with the declared aim of making the UK “the safest place in the world to be online.” It imposes duties on user-to-user services, search platforms, and pornography providers, scaled by user base and risk, and is enforced by Ofcom, which can issue fines or take business-disruption measures against non-compliant companies.
Child-protection duties
The Act’s child-safety core is the Protection of Children Codes, in force from 25 July 2025. Covered services must assess risks to children, mitigate exposure to content that is legal but harmful to children, such as eating-disorder or hateful material, provide age-appropriate tools and settings, and make their terms understandable to children. Services hosting pornographic content must implement “highly effective age assurance” to prevent children’s access. Age assurance and Assessing age assurance technologies examine what such systems can and cannot deliver.
A recurring criticism is that the Act’s categories fit generative AI poorly, leaving its coverage of AI chatbots and AI-generated content uncertain.
Early enforcement and effects
By March 2026, Ofcom had issued 16 fines totalling nearly £4 million, including £450,000 against 4chan for not protecting children from online pornography.
The Internet Matters Online Safety Act report, the first substantial family-level evaluation, found the early changes visible and broadly welcomed but the harms persistent: 49% of children reported a harmful experience in the month before the survey, and 32% had bypassed an age check within two months, mostly by low-tech means.
Widening scope
The Act’s perceived gaps have driven further proposals. The government opened its “Growing up in the online world” consultation in March 2026, and in June 2026 it announced a social media ban for under-16s, to take effect in spring 2027, alongside a midnight-to-6am curfew and off-by-default autoplay and infinite scroll for 16- and 17-year-olds. The Fortune Gen Alpha age-verification report carries the May 2026 announcement of intent alongside the survey evidence it was answering. The debate now parallels France’s under-15 ban and Australia’s under-16 prohibition. Less harmful social media sets out the proportionality case a blanket ban must make, and Do under-16 social-media bans reduce measured harm tracks the outcome evidence.
July 2026 circumvention package
In mid-July 2026 the government published Children’s circumvention behaviours online, its commissioned study of how children bypass age checks, and announced the policy response alongside it. The headline decision was negative: the government decided not to limit VPNs, despite pressure to treat them as the enforcement gap. Responsibility moved to platforms instead, which must take robust steps to detect and prevent underage circumvention, with Ofcom and the ICO reporting by October 2026 on how VPN-based evasion can be detected.
The same package extended protection beyond the under-16 ban. Sixteen- and seventeen-year-olds get default social media curfews from midnight to 6am, and persuasive features such as autoplay and personalized infinite feeds switch off by default. The government also announced mandatory breaks for under-18s using AI chatbots and a review with health regulators of whether therapy chatbots giving minors unverified mental-health advice should be banned.
BBC reporting on the announcement gathered mixed expert reaction. Campaigners such as Ellen Roome, who believes her son died in an online challenge, criticised the opt-out design as too weak. Prof Sonia Livingstone (LSE) warned that a curfew could harm vulnerable children by cutting off nighttime access to support, while Dame Rachel de Souza (children’s commissioner) said young people want protection from addictive design, not a ban. Social media analyst Matt Navarra dismissed the measure as “a mildly annoying settings prompt with a government press release attached.” The October Ofcom and ICO report is the next dated checkpoint in this package.
Built on 5 sources (5 external).
Working out connections…
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (143 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "Kimi K3", "label": "Kimi K3 (80%)", "lines": 115, "share": 0.8041958041958042}, {"model": "Kimi K2.6", "label": "Kimi K2.6 (18%)", "lines": 26, "share": 0.18181818181818182}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (1%)", "lines": 2, "share": 0.013986013986013986}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}