UK's Online Safety Act (OSA): A Mixed Future
- Discuss Diglett

- Apr 21
- 8 min read
This article is co-authored by Luo Xuhong and Cathleen Ong. Cover image by Cathleen Ong.
When King Henry VIII passed the Statute of Proclamations in 1539, who’s to say that he could foresee its far-reaching impact, now stretching over nearly half a century to present-day London and its problems? Even though times may have changed, the tension between the government’s role in executing policy and the Parliament’s in debating on it persists. Today, the United Kingdom finds itself in yet another predicament, this time concerning the Online Harms Regulation and its proposed amendments.
UK's Online Harms Regulation and its Sidekicks

The United Kingdom Online Safety Act (OSA) was passed into law in 2023 as a well-intended landmark law to protect the safety of those in online spaces. However, the OSA is at present facing a multitude of issues, which have only been exacerbated as a result of technology and its swift advancements.
Conceptualised as a regulatory framework to keep UK child users from harmful online content, the OSA sets out a list of legal duties that providers of online services (to UK users) must abide by. Failures to comply may attract stiff financial penalties of up to 10% of qualifying worldwide revenue, or £18 million and in the most severe cases, an Ofcom (short for the Office of Communications, UK's communications regulator) directive to block access to the offending site.
Requirements set out in the OSA broadly apply to the majority of “user-to-user services” that host and allow users to interact with user-generated content e.g. social media sites, instant messaging sites and “search services” i.e. search engines (collectively known as ‘Part 3 services’). Importantly, OSA requirements apply to all service providers with UK users even if the platforms themselves may be located overseas.
All user-to-user service providers must first carry out an illegal content risk assessment to determine the risk of their platforms being used to facilitate select illegal activity including CSAM, terrorism and promoting or facilitating suicide. Crucially, the OSA requires providers to adopt a proactive safety-by-design approach rather than relying upon any existing content moderation mechanisms and takedowns alone. More specifically, providers must demonstrate that they have implemented specific measures to mitigate the risk of such illegal content appearing on their platforms.
In line with the OSA’s aim of enhancing protection of child users, the act identifies a list of Primary Priority Content (s.61), namely pornography and content promoting self-harm, eating disorders and suicide. A 2nd list of Priority Content (s.62) identifies abusive content, bullying and content depicting or encouraging serious violence or injury.

Additionally, all providers of Part 3 services must also carry out a separate children’s access assessment (‘CAA’) to determine whether UK child users are able to access the service and whether a significant number of UK child users are likely to be attracted to use the service. If so, providers must implement appropriate safety measures (such as age assurance measures) to ensure that child users are prevented from accessing the harmful but otherwise legal content outlined in the Primary Priority Content and Priority Content lists.
While the OSA was feasible in theory, in reality, it tends to censor the wrong social media posts, on top of using inappropriate approaches to do so. The problems which the Act has faced has culminated in over 550,000 people’s signing of a petition to repeal or at the very least amend the OSA.
The first issue which has individuals unsettled lies in the age authentication policies which the Act effectively imposes on social media companies. Rather than genuinely regulating pornographic content for all ages, these apps restrict under 18s’ access to all types of content in order to avoid legal liability. The current legal parameters for age access remain unelaborated, which has led to platforms and third-party vendors collecting more data than necessary as an economic incentive – or to avoid compliance costs.
Age-verification seems like a simple and straightforward solution that the majority of online platforms (apart from social media sites) would naturally adopt to meet OSA’s demands - upload some form of ID or biometrics to prove one’s age is a process that takes a matter of seconds. Yet, present tools to prove age are deeply flawed.

Privacy and data security issues remain the most serious concern. Third-party age assurance vendors differ vastly in quality and security standards; while the largest online platforms can outsource age verification to reputable firms, the same can hardly be said for smaller platforms without similarly deep pockets. The September 2025 Discord data breach reveals that a poorly-planned rush to implement age verification does more harm than good. Additionally, document-based verification is inherently discriminatory against the marginalised populace such as those without valid identification, of which there were an estimated 2 million in the UK as of 2024.
The accuracy of such services remains a concern as well. A LexisNexis study found that 58% of UK adults did not trust mobile apps to accurately identify an individual aged 16-21 to enforce age-based restrictions on goods and services. High failure rates are also apparent amongst people with disabilities. At present, it is clear that mandating age verification for online content only serves to create a new barrier that potentially denies Internet access to the most vulnerable.
Further, the OSA’s definition of a removable post, which follows as “reasonable grounds”, has rendered it such that platforms are handed wide-ranging discretion rather than given clear legal rules. This has more often than not the unnecessary removal of legitimate speech, suppressed minority communities especially like LGBTQ+. Faced with the threat of a hefty fine amounting to 10% of qualifying worldwide revenue or a blockage of services in the UK, most would rather play it safe. The vague and uncalibrated wording of the legislation has consequently led to calls for a clearer path to appeal in respect of platforms to genuinely assess legality, and amendments.
Concerns over potential government overreach aren’t entirely unfounded either. In the US, legislation with stated aims of protecting children from harmful content online have included broad and nebulous terms that have gone far beyond their original intentions. Take Wisconsin’s S.B. 130 and Texas’ S.B. 12 as examples - by introducing expansive terms referring to content that is “harmful to minors”, conservative lawmakers in both states have sought to broadly restrict youth access to online content such as sex education materials and gender identity content. It is certainly not a stretch to foresee a similar situation repeating itself in the UK at some point in the future.
Grok and the Era of AI Chatbots
The fallout over the Grok scandal, where users were able to prompt X’s chatbot to generate nonconsensual sexualised images of individuals, has spotlighted another major loophole in the OSA. Drafted in 2022-3 in an era when AI chatbots were still in their infancy, the OSA’s illegal content duties were not applicable to AI chatbots that did not allow for interactions with other users i.e. one could only converse with the chatbot itself and not with other users through the chatbot. Moreover, chatbots that lacked the function to search for information across multiple websites would also fall outside of the OSA’s purview as they were not classified as “search services”.
All of this is set to change with the upcoming OSA amendments proposed by the Keir Starmer government.
"No platform gets a free pass" - Keir Starmer, Prime Minister of the United Kingdom
The Room Where it Happens
Under pressure to act fast, Labour has put forth 2 amendments that would allow future governments to quickly update legislation and keep up with tech advancements (so that another Grok-style incident would never occur again).
The first amendment to the Crime and Policing Bill empowers any single senior government minister to amend the OSA for the purposes of “minimising or mitigating the risks of harm to individuals” presented by illegal AI-generated content.
Meanwhile, the second amendment for the Children’s Wellbeing and Schools Bill would accord an even more significant power upon ministers, proffering them the ability to alter any piece of primary legislation to restrict children’s access to “certain internet services”.
So what is the power which a legislation with the Henry VIII clause holds? Well, this clause enables ministers to amend or repeal a provision in an Act of Parliament utilising secondary legislation. While these changes can be subjected to judicial review, and other forms of parliamentary scrutiny, it overall transfers immediate decision-making rights to the executive.
Now, understanding the OSA and its proposed amendments in context, even a plain Jane can point out the most glaring issue with this situation – the overwhelming power which it grants to government officials. With the relative instability of democratic governments today, future governments may be polarisingly different from the ruling party, and have a completely different direction for the policies on AI (and views on what content children should not be allowed to access, for that matter). Therefore, many citizens oppose this move, especially since future leaders down the road would have the opportunity to appropriate or abuse the accorded power.
Additionally, prior to the enactment of this clause, perhaps the Parliament needs to make further consideration as to the interests of its people. As observed from the UK government’s reaction post Brexit, resultant literature reviews stipulate that the most ideal preparatory steps includes the organisation of a robust pre-legislative stage which encourages public engagement. On this front, Keir Starmer has simultaneously opened an expansive public consultation in conjunction with the ongoing debates.
Needless to say, even in spite of the theoretical steps being executed, what remains an issue is the timing at which these amendments have been introduced. The first amendment was introduced following the passage of the powers through the House of Lords’ Report Stage, while the second was only proposed after the House of Commons were reviewing the suggested changes from the House of Lords. This effectively means that parliamentarians were stripped from the opportunity to refine legal terminologies and raise their principled and practical concerns amongst others. More significantly, backbenchers as well as those from the opposition are limited by the tight schedules.
In reality, the current amendments on the floor clearly signal the issues which the Parliament faces – that of necessitating enhanced scrutiny in relation to secondary legislation and how the current government handles its time.
One step at a time
Significant backlash over the OSA is a clear sign that blunt solutions may do more harm than good. The record-breaking 550000 signatories of the petition to repeal the OSA reveals heightened public interest in online safety law that affects vast swathes of the populace - clearly an issue that should not be resolved by secondary legislation alone. Take it slow, Keir Starmer.
References
Clifton, M. (2026, March 9). UK eyes sweeping powers to regulate tech. POLITICO. https://www.politico.eu/article/uk-eyes-sweeping-powers-to-regulate-tech-without-parliamentary-scrutiny/
English, R. (2021, September 7). Henry VIII powers v Parliament. Counsel Magazine. https://www.counselmagazine.co.uk/articles/henry-viii-powers-v-parliament
Fava, L. (2026, March 2). The risks addressed by child online safety regulation. Pinsent Masons. https://www.pinsentmasons.com/out-law/guides/risks-addressed-child-online-safety-regulation
Fieldhouse, E., & Scott, R. (2025, January 24). Almost 2 million people in the UK didn’t have the right ID to vote in 2024. The Conversation. https://theconversation.com/almost-2-million-people-in-the-uk-didnt-have-the-right-id-to-vote-in-2024-246270
Kouroutakis, A. (2020). The Henry VIII powers in the Brexit process: justification subject to political and legal safeguards. The Theory and Practice of Legislation, 1–19. https://doi.org/10.1080/20508840.2020.1820660
LexisNexis. (2025a, October 13). Online safety—UK/EU comparison. https://www.lexisnexis.co.uk/legal/guidance/online-safety-uk-eu-comparison
LexisNexis. (2025b, November 18). The Online Safety Act 2023—a quick guide. https://www.lexisnexis.co.uk/legal/guidance/the-online-safety-act-2023-a-quick-guide
LexisNexis. (2026, March 26). The Online Safety Act 2023. https://www.lexisnexis.co.uk/legal/guidance/the-online-safety-bill
LexisNexis Risk Solutions. (2025, July 25). Many Consumers Unconvinced about Age Verification Apps as Compulsory Checks Come into Force for Some Online Content. https://risk.lexisnexis.co.uk/about-us/press-room/press-release/20250725-idv-checks-concerns
Novik, M. (2026, February 16). UK to tighten online safety laws to include AI chatbots. Financial Times. https://www.ft.com/content/15917aa4-2d40-49be-85c3-da395b16e7f1?syn-25a6b1a6=1
Ofcom. (2025a, April 25). Protecting children from harms online - A summary of our decisions. https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/statement-protecting-children-from-harms-online/main-document/a-summary-of-our-decisions.pdf?v=396673
Ofcom. (2025b, May 28). Online Safety Act Explained: Q&A. https://www.ofcom.org.uk/siteassets/resources/documents/online-safety/information-for-industry/other/online-safety-act-explained-qa-web.pdf?v=409647
Ofcom. (2025c, December 18). AI chatbots and online regulation – what you need to know. https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/ai-chatbots-and-online-regulation-what-you-need-to-know
Open Rights Group. (2025, December 10). Briefing: Online Safety Act Parliamentary Petition Debate. https://www.openrightsgroup.org/publications/briefing-online-safety-act-parliamentary-petition-debate/
Rindala Alajaji. (2025, December 8). 10 (Not So) Hidden Dangers of Age Verification. Electronic Frontier Foundation. https://www.eff.org/deeplinks/2025/12/10-not-so-hidden-dangers-age-verification
Simmons & Simmons. (2026, January 15). Grok, generative AI and the UK Online Safety Act. https://www.simmons-simmons.com/en/publications/cmkfjc1xl0030v4tklthq0jn3/grok-generative-ai-and-the-uk-online-safety-act
Tanner, B., & Lee, N. T. (2025, July 9). Children’s online safety laws are failing LGBTQ+ youth. The Brookings Institution. https://www.brookings.edu/articles/childrens-online-safety-laws-are-failing-lgbtq-youth/
Taylor, J. (2025, October 7). Proof-of-age ID leaked in Discord data breach. The Guardian. https://www.theguardian.com/games/2025/oct/07/discord-data-breach-proof-of-age-id-leaked
UK Government and Parliament. (2025, October 22). Petition: Repeal the Online Safety Act. https://petition.parliament.uk/petitions/722903
UK Government Department for Science, Innovation and Technology. (2026, March 2). Growing up in the online world: a national consultation. GOV.UK. https://www.gov.uk/government/consultations/growing-up-in-the-online-world-a-national-consultation




Comments