News · January 22, 2025 · Daily Junction Editorial Team · 10 min
The Online Safety Act 2023 comes into force in 2025, imposing sweeping duties on tech platforms to protect users from illegal content and harmful material. Ofcom can fine companies up to £18 million or 10% of global revenue, and even block services that fail to comply. But will it make the internet safer, or drive encryption underground?
The United Kingdom's Online Safety Act 2023, which comes into force in stages throughout 2025, represents the most ambitious attempt by any democracy to regulate the internet. The law imposes sweeping legal duties on social media platforms, search engines, messaging apps, and online services to protect users—especially children—from illegal and harmful content. Ofcom, the communications regulator, gains unprecedented powers to fine companies up to £18 million or 10% of global revenue, block non-compliant services, and even pursue criminal charges against senior executives.
Supporters say the Act will finally hold Big Tech accountable for the harms facilitated by their platforms: child sexual abuse, terrorist radicalisation, fraud, harassment, and the mental health crisis among young people. Critics warn it threatens privacy, free speech, and encryption, and could force tech companies to abandon the UK market rather than comply with unworkable demands. As implementation begins, the stakes could not be higher.
The Online Safety Act creates a duty of care framework, placing legal responsibility on platforms to keep users safe. The obligations vary depending on the type of service and the risks it poses.
Every platform accessible in the UK must take proactive steps to prevent and remove illegal content, including:
Platforms must use proactive technology (such as AI content moderation, hash-matching databases, and user reporting systems) to detect and remove illegal content quickly. They cannot wait for users to report it. Failure to comply can result in fines up to £18 million or 10% of global turnover, whichever is higher.
Services likely to be used by under-18s—including social media, gaming platforms, messaging apps, and video-sharing sites—must implement child safety measures:
Ofcom's codes of practice, published in November 2024, specify that platforms must assess the risk of children accessing their service and implement "highly effective" age assurance if that risk is significant. This applies even to services not explicitly designed for children, such as pornography sites and social media platforms with 18+ terms of service but known child users.
The largest platforms—those with over 7 million UK users or "high-risk functionalities" like live streaming or algorithmic recommendation—are designated Category 1 services and face additional duties:
Crucially, platforms cannot remove legal content posted by adults unless it violates their own terms of service. The Act does not create new speech restrictions for adults, but it does require platforms to give users control over what they see.
Ofcom becomes the online safety regulator, with powers that dwarf its traditional broadcasting and telecoms remit. The regulator can:
These powers are extraordinary. No other regulator in the UK can unilaterally block access to a global service or criminally prosecute executives for regulatory non-compliance. The government argues such powers are necessary to force compliance from tech giants that have ignored voluntary codes for years. Critics warn they create a chilling effect and risk being weaponised against platforms that displease the government.
The most controversial aspect of the Act is its treatment of end-to-end encryption. Messaging apps like WhatsApp, Signal, and iMessage encrypt messages so that only the sender and recipient can read them—not even the platform provider can access the content. This protects privacy and security but also prevents platforms from scanning messages for child abuse material.
The Act does not explicitly ban encryption. However, it requires platforms to use "accredited technology" to detect and remove CSAM, even in private messages. Ofcom's draft codes suggest this could include client-side scanning, where messages are scanned on the user's device before encryption, or machine learning systems that detect abuse patterns without reading content.
The problem: no such technology currently exists that can reliably detect CSAM without breaking encryption or creating unacceptable false positives. Cryptography experts, including the UK's own GCHQ, have stated that client-side scanning fundamentally undermines encryption by creating a backdoor that can be exploited by malicious actors or authoritarian governments.
WhatsApp, Signal, and Apple have warned they will withdraw from the UK market rather than comply with requirements that break encryption. In July 2024, Signal's president Meredith Whittaker said: "We will not undermine the security and privacy of our users, even if it means shutting down in the UK."
The government insists that technology will be developed to square this circle, and that Ofcom will only require scanning if it is technically feasible and proportionate. But the standoff remains unresolved, and legal challenges are expected once Ofcom issues final codes in early 2025.
The Act's child safety duties require platforms to implement age verification or age assurance to prevent children accessing harmful content. This has sparked fierce debate about privacy, effectiveness, and unintended consequences.
Proposed methods include:
Each method has drawbacks. Photo ID verification is accurate but creates honeypots of sensitive data—databases linking real identities to online accounts, vulnerable to breaches or government surveillance. The 2024 hack of age verification provider Yoti, which exposed 2.3 million users' ID documents, illustrated this risk.
Facial age estimation is less invasive but highly inaccurate, especially for people of colour, and can be spoofed with photos. Credit card checks exclude young people and can be bypassed with parents' cards. Third-party services add friction and cost.
Privacy campaigners warn that mandatory age verification will normalise digital ID systems, eroding anonymity and enabling mass surveillance. Civil liberties groups argue it will push young people to unregulated platforms or VPNs, making them less safe.
The government counters that children are already being harmed by unrestricted access to pornography, violent content, and predatory adults, and that age verification is a proportionate response. Ofcom's codes allow platforms to choose their method, but require it to be "highly effective"—a standard that may force platforms toward the most invasive options.
While the Act does not criminalise new categories of speech for adults, critics warn it will lead to over-removal of legal content. Platforms, facing massive fines for failing to remove illegal content, will err on the side of caution, taking down borderline material that might be legal but risky to host.
This is already happening under voluntary content moderation. Platforms routinely remove legal political speech, satire, and journalism because automated systems cannot distinguish context. The Act's proactive duties will intensify this, as platforms deploy more aggressive AI moderation to avoid liability.
There are also concerns about "legal but harmful" content. While the Act allows adults to choose their own filters, the government's definition of harmful content is broad and subjective. During the Bill's passage, ministers suggested it could include content promoting "harmful" political views or "misinformation". Though these provisions were removed after backlash, the framework remains vulnerable to future expansion.
Index on Censorship, a free speech charity, warned in September 2024 that the Act "creates a template for authoritarian governments to demand censorship under the guise of safety". If the UK can require platforms to remove legal content or break encryption, what stops China, Russia, or Saudi Arabia demanding the same?
Tech companies are scrambling to comply with the Act's April 2025 deadlines. Meta (Facebook, Instagram, WhatsApp) has announced £100 million investment in UK content moderation and age verification systems. Google is developing age assurance for YouTube. TikTok is piloting facial age estimation.
However, smaller platforms and startups face existential challenges. The compliance costs—legal advice, content moderation systems, age verification, transparency reporting—are prohibitive for companies without Big Tech's resources. Many are likely to geofence the UK, blocking British users rather than complying.