If you’ve noticed more age checks before you can access certain apps, sites suddenly asking to verify your date of birth with a selfie or ID, or platforms pulling content they’d previously ignored, that’s not a coincidence — it’s the Online Safety Act taking effect.
For something that dominates headlines, the Act itself is widely misunderstood. Some people think it bans anonymous accounts. Others think it only affects children. Some assume it gives the government direct control over what individuals can post. Very little of that is accurate, and the gap between the headlines and the actual legal text has left a lot of confusion about what’s actually changed and who it applies to.
This guide sets out what the Online Safety Act actually requires, who has to comply with it, what it means practically for adults and children using the internet in the UK, and where its real limits are.
What Is the Online Safety Act?
The Online Safety Act 2023 received Royal Assent in October 2023 and has been rolling out in phases since, with the Act’s various duties becoming legally enforceable at different points through 2024 and 2025. It’s regulated by Ofcom, the same body that oversees UK broadcasting and telecoms.
The core idea behind the Act is straightforward, even if the mechanics are complex: it places legal duties on online platforms — not individual users — to reduce the risk of harmful content reaching people, particularly children, and to give users more control and clearer accountability when things go wrong.
Importantly, the Act does not create a general list of banned words or opinions for individuals to follow. Its duties fall on the companies running platforms — social media sites, search engines, messaging services, gaming platforms with user interaction, and pornography sites — not on what an ordinary person is personally allowed to type.
Who the Act Actually Applies To
The Act applies to any service with a significant number of UK users, or that targets the UK market, regardless of where the company is based. This is a deliberately wide net, and includes:
- Social media platforms — Instagram, TikTok, X, Facebook, Snapchat, and similar services
- Search engines — including Google and Bing
- Messaging services with public or semi-public elements, such as group functionality
- User-to-user platforms more broadly, including forums, gaming platforms with chat features, and some dating apps
- Pornography sites, which face specific, stricter age-verification duties
Ofcom categorises services based on size and risk, with the largest and highest-risk platforms (“Category 1” services) facing the most extensive obligations, including transparency reporting and additional protections around content that’s legal but potentially harmful to adults.
Small platforms are not automatically exempt — even a modest UK-based forum has basic duties under the Act if it allows user-generated content, though the scale of what’s expected is proportionate to the platform’s size and risk profile.
The Core Duties Placed on Platforms
At the heart of the Act are two broad categories of duty, both centred on risk assessment and mitigation rather than a fixed list of banned content.
Illegal content duties require all in-scope platforms to assess the risk of illegal content appearing on their service — this covers things like child sexual abuse material, terrorism content, content encouraging self-harm or suicide, and content facilitating fraud — and to put in place proportionate systems to prevent it appearing, or remove it quickly once identified.
Child safety duties go further for services likely to be accessed by children, requiring platforms to assess and mitigate risks specific to under-18s, including harmful content that isn’t necessarily illegal for adults to see — such as content promoting eating disorders, or extreme violence that falls short of the criminal threshold.
Platforms are also required to provide clear and accessible reporting tools, so users can flag harmful content and expect a genuine response, rather than a complaint disappearing into a void. Larger platforms face additional duties around transparency, including publishing information about how their systems work and reporting to Ofcom on their compliance.
Age Verification: What’s Actually Required
This is the part of the Act that’s had the most visible, day-to-day impact, and it’s worth being specific about what it actually requires.
Services that host pornography, or other content likely to be harmful to children, must use “highly effective” age assurance to prevent children from accessing it. This is a higher bar than the old-style “click to confirm you’re over 18” checkbox, which the Act specifically treats as inadequate on its own.
In practice, this has led to platforms adopting methods like:
- Facial age estimation, using a photo or short video to estimate age
- Verification through a third-party ID check or credit card
- Confirmation through an existing account with an age-verified provider
This is why some adult users have started encountering age checks on platforms that previously required none — the requirement isn’t limited to explicitly adult sites; it extends to any part of a mixed-content platform where children might otherwise reasonably access harmful material.
A fair criticism worth acknowledging: privacy advocates have raised legitimate concerns about how age-verification data is stored and by whom, and the Act’s effectiveness depends heavily on platforms implementing these checks properly rather than treating them as a box-ticking exercise. Ofcom has published guidance on acceptable methods, but enforcement is still maturing as of 2026.
What This Means for Free Speech and Legal Content
This is the most contested part of the Act, and it’s worth separating the legal reality from the political debate.
The Act does not create new categories of illegal speech for individuals — content that was legal to post before the Act remains legal now. What’s changed is the obligation on platforms to assess risk and, for the largest platforms, to give adult users more visibility and control over content that’s legal but that they might not want to see, such as an option to filter out certain types of content from their own feed.
Critics argue that platforms, faced with regulatory risk, may over-remove borderline content to avoid liability — a phenomenon often called “over-removal” or a chilling effect. Ofcom’s guidance explicitly warns against this and requires platforms to have regard to freedom of expression when designing their systems, but whether individual platforms strike that balance well in practice varies, and it remains an active area of scrutiny and complaint.
If you believe content has been removed unfairly, most platforms are required to provide an appeals or reporting mechanism specifically for this — it’s worth using that route directly with the platform before assuming it reflects a legal requirement rather than a platform’s own moderation decision.
What Parents and Individual Users Can Actually Do
Report harmful content directly to the platform first. Every in-scope platform is required to have a functioning reporting system. Screenshot the content and note the date, since some material may be removed before a wider complaint is resolved.
Escalate to Ofcom if a platform isn’t meeting its duties. Ofcom doesn’t resolve individual pieces of content, but persistent failures to have adequate systems in place can be reported and may feed into wider enforcement action against a platform.
Use platform-level parental controls alongside the Act, not instead of it. The Act raises the baseline for platforms, but it doesn’t replace the value of app-level parental controls, screen time limits, and ongoing conversations with children about what they’re seeing online — the legal duties sit on top of, not in place of, that.
Report illegal content, like child sexual abuse material or terrorism content, to the police or the Internet Watch Foundation directly, rather than relying solely on a platform’s internal process, particularly where the content suggests an immediate risk to someone’s safety.
(If your situation involves a child being targeted or groomed online specifically, it’s worth reading a more detailed guide on reporting online grooming and getting immediate support, since the process and urgency differ from a general content complaint.)
Frequently Asked Questions
Does the Online Safety Act ban anonymous accounts? No. The Act does not require platforms to ban anonymity or force real-name verification for general use. What it does require, for the largest platforms, is that adult users be given tools to reduce contact from unverified or anonymous accounts if they choose to use them — it’s an optional control for users, not a ban on anonymity itself.
Can I be prosecuted for something I post under the Online Safety Act? The Act’s main duties are placed on platforms, not individual users, so it doesn’t generally create new criminal offences for ordinary posts. However, it does strengthen and clarify some existing offences, such as those relating to cyberflashing and encouraging self-harm, which individuals can still be prosecuted for under the relevant criminal law.
Why am I suddenly being asked to verify my age on sites I’ve used for years? This is a direct result of the Act’s age-verification requirements, which apply to platforms hosting pornography or other content that could be harmful to children — even where that content is only part of a wider, mixed-content platform. Simply clicking a checkbox to confirm your age is no longer considered adequate under the law.
Does the Online Safety Act apply to platforms based outside the UK? Yes. The Act applies to any service with a significant number of UK users or that specifically targets the UK market, regardless of where the company is legally based or headquartered. This is why platforms based in the US or elsewhere have still had to adapt their systems for UK users.
What should I do if a platform removes my content unfairly? Most in-scope platforms are required to provide a clear appeals process for content moderation decisions — start there, referencing the specific post and the platform’s own community guidelines. If the platform has no functioning appeals process at all, that itself may indicate a failure to meet its duties under the Act, which can be reported to Ofcom.
Key Takeaways
The Online Safety Act shifts legal responsibility onto platforms, not individuals, requiring them to assess and reduce the risk of illegal content and to protect children from material that could cause them harm. Its most visible effect so far has been stricter age verification, particularly around pornography and mixed-content platforms, but its duties extend much further into how platforms handle reporting, transparency, and risk more broadly.
If you’re dealing with harmful content right now, report it directly to the platform first and keep a record of what you’ve reported and when. If a platform consistently fails to act, Ofcom’s reporting route is there specifically for that pattern of failure, not for resolving individual pieces of content.

