BlackTree Security · Infrastructure · Automation · AI

The UK Online Safety Act Has Become an Operating Model

The Online Safety Act is no longer a future policy argument. Since March 2025, regulated services have had to turn risk assessments into operating controls.

On 17 March 2025, the next phase of the United Kingdom’s Online Safety Act took effect. In-scope services were expected to have completed illegal-content risk assessments and to start applying measures that protect users from criminal content and activity.

Further protection-of-children duties followed on 25 July 2025. By 2026, Ofcom was supervising and enforcing a live regime rather than preparing one.

The law can apply outside the UK

The Act reaches user-to-user services, search services and certain services that publish or display pornographic content where there is a relevant connection to UK users. A provider does not escape scope merely because its company or infrastructure is located elsewhere.

File-sharing tools, forums, social platforms, messaging features, marketplaces, gaming services and dating products may all require analysis. The regulated feature can be only one part of a larger application.

The first task is therefore to map features rather than rely on the marketing description of the service.

Risk assessment must describe the actual service

An illegal-content assessment considers how users may encounter illegal material and, for user-to-user services, how the service may be used to commit or facilitate priority offences.

The assessment needs evidence about the product’s design, user base, recommendation systems, messaging, discoverability, reporting tools and moderation capacity. Copying a generic industry risk register is unlikely to explain how harm occurs on the service itself.

The assessment is not a one-time filing. It must be kept current and revisited before a significant design or operational change. A new livestreaming function, private-message feature or generative-AI tool can alter the risk profile before it alters revenue.

Codes of practice are not the only route

Ofcom’s codes describe measures providers can use to comply. A provider may choose alternative measures, but it must record what it chose and how those measures fulfil the relevant duties.

That makes engineering decisions part of the compliance record. If a provider rejects a recommended control because it would undermine encryption, privacy or accessibility, it needs a documented alternative, not silence.

Children’s safety changes identity and access design

Services likely to be accessed by children must assess risks to children and implement proportionate protections. Highly effective age assurance is required in specified contexts, including preventing children from accessing pornographic content.

Age assurance is not automatically the same as collecting identity documents. Different methods carry different privacy, security, exclusion and accuracy risks. The system should prove the necessary attribute with the least intrusive data compatible with the duty.

Teams must also consider recommendation systems, default settings, contact features, reporting, content controls and support for younger users.

Governance cannot end with trust and safety

Online safety touches product management, engineering, security, privacy, legal, moderation and executive oversight. A workable operating model should include:

  1. A register of regulated services and features.
  2. Written illegal-content and children’s risk assessments where applicable.
  3. Named owners for each safety measure.
  4. Evidence explaining alternative measures.
  5. Monitoring of effectiveness and residual risk.
  6. A pre-release safety review for significant product changes.
  7. Records of reports, decisions, appeals and systemic trends.
  8. Escalation routes for Ofcom information requests and enforcement.

Safety is now a lifecycle requirement

The deepest change is not that platforms must remove particular content. It is that foreseeable misuse must be considered during design, measured during operation and reassessed when the service changes.

That is familiar territory for security teams. Threat modelling, abuse cases, logging, incident response and control validation already exist. The Online Safety Act asks organisations to apply that discipline to harm caused through the service, not only attacks against it.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *