United Kingdom - Online Safety Act (2023)

Online Safety Act 2023

United Kingdom

RAI-GB-NA-ONLSA20-2023
Effective: October 26, 2023
In Force(In Force)
ActGovernance and OversightRisk ManagementEnforcement and Penalties
Export PDF

The Online Safety Act 2023 establishes a statutory duty of care for providers of user-to-user and search services accessible in the UK, requiring measures to address illegal content and protect children from content that is legal but harmful. Ofcom is designated as the principal regulator with enforcement powers including fines up to £18 million or 10% of qualifying worldwide revenue, and the Act was given Royal Assent on 26 October 2023. (legislation.gov.uk)

Summary

The Online Safety Act 2023 (OSA) is primary UK legislation creating a comprehensive regulatory framework for online content and platform safety. Its central design is to impose duties on providers of "user-to-user" services and search services available to people in the UK: duties to identify, assess and mitigate risks of illegal content, safety duties specifically aimed at protecting children from content that is legal but harmful, and transparency and record-keeping obligations. Ofcom (the Office of Communications) is given powers to consult on, publish, and enforce codes of practice and guidance; to require information and records; to impose sanctions including substantial monetary fines; and in the most serious circumstances to seek court-ordered business disruption measures such as access or service restriction orders. ([legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2023/50/2024-08-23?utm_source=openai))

The Act sets out two broad classes of obligations: (a) "illegal content" duties, requiring providers to prevent the presence and spread of defined categories of criminal content (for example child sexual exploitation and abuse material, terrorism content and other listed offences) and (b) "safety duties" focused principally on protecting children from exposure to harmful but lawful content, with duties calibrated by service type and risk profile. Providers must carry out regular illegal-harms risk assessments and, for services that may be accessed by children, children’s access and age-assurance assessments. Ofcom must issue codes of practice and guidance to expand on statutory duties and to set out recommended measures and minimum expectations. ([gov.uk](https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer?utm_source=openai))

Important operational features of the regime include tiering and designation powers (Ofcom may designate services by category and apply proportionate supervisory approaches), extensive transparency reporting and publication duties, new or widened criminal offences related to communications (including additions to sexual offences such as intimate image abuse), and mechanisms for independent review and appeals. The Act leaves some matters to secondary legislation and to Ofcom’s codes (which are subject to parliamentary laying procedures), so full operational details have been phased in through Ofcom’s consultations and the statutory laying of codes and guidance; key enforcement phases for the illegal-harms duties were implemented in late 2024 and early 2025. ([ofcom.org.uk](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/important-dates-for-online-safety-compliance?utm_source=openai))

The regime is notable for strong enforcement tools and high fines (the greater of £18 million or 10% of qualifying global revenue), the ability to pursue service- and business-level remedies, and the potential for criminal liability of individuals (senior manager liability) in specified circumstances. The Act interacts with other UK and international regimes (for example the Digital Economy Act 2017, parts of which are repealed, and EU measures such as the Digital Services Act), and has prompted intense stakeholder debate over freedom of expression, privacy (particularly encryption issues), and the technical feasibility of some duties. Implementation has been incremental: Ofcom published core illegal-harms codes and guidance in December 2024 and began enforcement activity and oversight in early 2025, with staged deadlines for risk assessments and children’s assessments in March–April 2025. ([legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2023/50/2024-08-23?utm_source=openai))

Full article

Read full text ↗

Overview

The Online Safety Act 2023 creates a statutory framework to improve online safety by imposing duties on providers of user-to-user and search services available to people in the United Kingdom. It introduces two principal strands of duties: (1) duties to address illegal content and criminal activity on regulated services; and (2) duties to reduce risks that legal content presents to children. The Act designates the communications regulator Ofcom to develop codes of practice, supervise compliance and enforce the regime with a range of tools including information notices, penalties and, in extreme cases, court-ordered service or access restrictions. For the enacted text and explanatory notes see Legislation.gov.uk - Online Safety Act 2023 (enacted). ([legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2023/50/2024-08-23?utm_source=openai))

Definitions

The Act defines key regulated entities and concepts including "user-to-user services" (those that enable user interaction and content sharing), "search services" (that generate search results for user queries), and the categories of content captured by the illegal-content duties (explicitly enumerated types of criminal content). The Act also establishes duty-holders and service categories for proportional supervision (e.g., designations and categories of services). Many technical terms (for example, what constitutes a "service likely to be accessed by children") are clarified through Ofcom guidance and codes of practice. ([legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2023/50/2024-08-23?utm_source=openai))

Governance and Institutional Framework

The Act places Ofcom at the centre of governance: Ofcom must consult the public and stakeholders when developing codes, may issue guidance to providers, and is empowered to require information, investigate services, and take enforcement action. The Secretary of State retains narrowly defined powers to direct Ofcom in exceptional circumstances (public policy, national security or public safety), and Parliament exercises oversight via the statutory laying procedure applied to Ofcom’s codes and guidance. Ofcom has also described its supervisory approach — combining targeted oversight of high-risk or large services with broader transparency duties — and has scaled up team capacity and expertise to implement the regime. For Ofcom’s implementation materials and timeline see Ofcom - Important dates for Online Safety compliance. ([ofcom.org.uk](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/important-dates-for-online-safety-compliance?utm_source=openai))

Key Focus Areas

The Act’s substantive focus areas include: preventing and removing illegal content (such as child sexual exploitation and abuse material, terrorism-related content, fraud, and other enumerated offences); protecting children from exposure to harmful but lawful content through age assurance and children’s access assessments; promoting safer design and safer recommendation systems; ensuring transparent terms of service and public reporting about safety measures; and enabling effective reporting, redress and researcher access in appropriate circumstances. The illegal-harms duties are risk-based and require providers to carry out regular assessments, implement proportionate mitigation measures, and keep records. The Act also expands communications offences (e.g., intimate image abuse) and enables coroner information requests backed by Ofcom’s enforcement powers in defined circumstances. These provisions have been the subject of intense public debate over free expression, privacy and encryption. ([gov.uk](https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer?utm_source=openai))

Implementation Framework

Implementation is phased and depends heavily on Ofcom’s codes and guidance. The Act requires Ofcom to consult, publish draft codes, lay them before Parliament and then issue final codes after any parliamentary consideration. Providers are required to complete illegal-harms risk assessments, children’s access assessments and, where applicable, implement highly effective age assurance measures. Ofcom’s codes also set recommended measures and baseline expectations according to risk-tiering (e.g., low/medium/high risk services), and services must designate an accountable individual or senior executive responsible for compliance. Ofcom has published enforcement guidance and templates to help providers comply and has initiated supervisory activities targeting services perceived as high-risk. See Ofcom’s explanatory materials at Ofcom - Countdown to a safer life online. ([ofcom.org.uk](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/countdown-to-a-safer-life-online?utm_source=openai))

Monitoring and Evaluation

Ofcom’s monitoring approach combines proactive supervision (targeted reviews of high-risk services), requests for information and records, periodic reviews of published transparency statements, and formal enforcement investigations where required. The Act creates statutory record-keeping and reporting duties and enables Ofcom to require disclosure of risk assessments and to publish findings where appropriate. Ofcom has signalled an ongoing enforcement programme and a rolling review of risk assessments and provider responses, and intends to publish transparency guidance and findings on compliance. Audits, follow-up inspections and escalation to civil or (in limited cases) criminal sanctions form part of the evaluation toolkit. ([committees.parliament.uk](https://committees.parliament.uk/writtenevidence/140786/html/?utm_source=openai))

Penalties, Liability, and Appeals

The Act equips Ofcom with a range of enforcement powers: monetary penalties of up to £18 million or 10% of qualifying worldwide revenue (whichever is greater); remedial or compliance orders; and the ability to seek court orders that may disrupt business models (for example, blocking access or requiring withdrawal of payment/advertising services). In specified child-safety circumstances, failure to comply with an Ofcom confirmation decision may create a criminal offence attracting penalties including imprisonment for individuals (senior managers) and fines for organisations, where consent, connivance or neglect is established. Providers may appeal Ofcom decisions through the courts; the Act preserves judicial review and specified appeal routes for enforcement decisions. ([committees.parliament.uk](https://committees.parliament.uk/writtenevidence/140786/html/?utm_source=openai))

Relationship to Other Instruments

The Online Safety Act interacts with a range of domestic and international instruments. It repeals parts of the Digital Economy Act 2017 (notably previous age verification provisions), updates and supplements communications offences under the Communications Act 2003 and Sexual Offences Act 2003, and operates alongside data protection law (including the UK GDPR and Data Protection Act). Internationally, it sits in the same policy space as the EU Digital Services Act (DSA) and other jurisdictions’ measures to govern platform safety, and providers operating across borders will often face parallel compliance obligations. For the enacted text and related explanatory notes see Legislation.gov.uk - Online Safety Act 2023 (enacted). ([legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2023/50/2024-08-23?utm_source=openai))

International Alignment

Policymakers have emphasised the need to align outcomes with international frameworks while maintaining UK-specific priorities (notably child protection and criminal content enforcement). The OSA shares objectives with the EU’s DSA—risk assessments, transparency and enforcement tiers—but differs on some scopes and mechanisms. Global platforms must therefore reconcile multiple overlapping obligations; Ofcom has engaged internationally and notes cross-jurisdictional cooperation may be necessary for evidence-gathering, takedown and enforcement. The Act’s technical and human-rights implications (including encryption and freedom of expression issues) have prompted debate with international stakeholders and civil society. ([ofcom.org.uk](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/important-dates-for-online-safety-compliance?utm_source=openai))

Implementation Timeline

EventDate
Royal Assent (Online Safety Act 2023)2023-10-26
Ofcom publishes illegal harms codes and risk assessment guidance (laid in Parliament)2024-12-16
Start of enforcement window / codes come into force (illegal harms)2025-03-17
Deadline for providers to complete illegal-harms risk assessments2025-03-16
Ofcom enforcement programme launch (monitoring selected services)2025-03-01

Note: many obligations were phased in via Ofcom’s codes and guidance; providers should consult Ofcom’s official timeline for service-specific obligations and dates. ([bills.parliament.uk](https://bills.parliament.uk/bills/3137/news?utm_source=openai))

Sources and References

SourceType
Online Safety Act 2023 (Legislation.gov.uk) - enacted text and explanatory notesPrimary Source
Ofcom - Important dates for Online Safety compliancePrimary Source
GOV.UK - Online Safety Act explainerPrimary Source
House of Commons Library - Implementation of the Online Safety ActPrimary Source

Requirements for a company

What an organisation has to do under United Kingdom - Online Safety Act (2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

11
  • Address illegal content and criminal activity on your service.Providers of user-to-user and search services accessible in the UK.
  • Carry out regular risk assessments for illegal content.Providers of user-to-user and search services accessible in the UK.
  • Implement proportionate measures to mitigate illegal content risks.Providers of user-to-user and search services accessible in the UK.
  • Reduce risks that legal content presents to children.Providers of user-to-user and search services accessible in the UK.
  • Conduct children’s access assessments and implement age assurance measures.Providers of user-to-user and search services likely to be accessed by children.
  • Designate a senior individual responsible for compliance.Providers of user-to-user and search services accessible in the UK.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Promote safer design and safer recommendation systems.Providers of user-to-user and search services accessible in the UK.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Kingdom - Online Safety Act (2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of user-to-user and search services accessible in the UK.Address illegal content and criminal activity on your service.
duties to address illegal content and criminal activity on regulated services
Mar 17, 2025Critical
2Providers of user-to-user and search services accessible in the UK.Carry out regular risk assessments for illegal content.
The illegal-harms duties are risk-based and require providers to carry out regular assessments
Mar 16, 2025Critical
3Providers of user-to-user and search services accessible in the UK.Implement proportionate measures to mitigate illegal content risks.
implement proportionate mitigation measures
Critical
4Providers of user-to-user and search services accessible in the UK.Reduce risks that legal content presents to children.
duties to reduce risks that legal content presents to children.
Critical
5Providers of user-to-user and search services likely to be accessed by children.Conduct children’s access assessments and implement age assurance measures.
protecting children from exposure to harmful but lawful content through age assurance and children’s access assessments
Critical
6Providers of user-to-user and search services accessible in the UK.Designate a senior individual responsible for compliance.
services must designate an accountable individual or senior executive responsible for compliance.
Critical
7Providers of user-to-user and search services accessible in the UK.Comply with Ofcom's codes of practice and guidance.
Ofcom’s codes also set recommended measures and baseline expectations
Critical
8Providers of user-to-user and search services accessible in the UK.Keep records of illegal-harms risk assessments and mitigation measures.
keep records
Important
9Providers of user-to-user and search services accessible in the UK.Ensure transparent terms of service and public reporting about safety measures.
ensuring transparent terms of service and public reporting about safety measures
Important
10Providers of user-to-user and search services accessible in the UK.Enable effective user reporting, redress mechanisms, and researcher access.
enabling effective reporting, redress and researcher access in appropriate circumstances
Important
11Providers of user-to-user and search services accessible in the UK.Maintain evidence of all assessments, decisions, tests, and remedial measures.
Providers should maintain evidence of all assessments, decisions, tests, and remedial measures as Ofcom may request these records.
Important
12Providers of user-to-user and search services accessible in the UK.Promote safer design and safer recommendation systems.
promoting safer design and safer recommendation systems
Recommended

© Regulations.AI · updated on 13-Jun-2026