The Online Safety Act and social media: what's changing
The Online Safety Act 2023 places legal duties on online services, social media included, to tackle illegal content and protect children from harmful material, enforced by Ofcom through phased rules. Age assurance for services likely to be accessed by children is the most discussed measure. Obligations vary by size, type and content; Ofcom's guidance is the authoritative source.
If you have followed UK tech news, you will have seen the Online Safety Act described as everything from a long-overdue protection for children to a threat to privacy and encryption. The truth is more mundane and more complicated than either headline: it is a large, ambitious piece of legislation, rolled out in phases, that changes the legal obligations of online services in ways that are still settling.
This piece is a plain-English overview of what the Act does and what is changing, written for people who want to understand it rather than argue about it. Two honest caveats first: I run a small social network, so I have a practical interest in this regulation, and I am not a lawyer. Nothing here is legal advice, and for the current, precise position on any service, Ofcom’s official guidance is the source that matters, not this article.
What the Online Safety Act is
The Online Safety Act 2023 is UK law that imposes “duties of care” on a wide range of online services, social media platforms, search services, and sites hosting user-generated content, to make them safer for users, and especially for children. Ofcom, the communications regulator, is responsible for enforcing it, and it has been issuing codes of practice and guidance in stages rather than all at once, which is why the picture has evolved over time.
Broadly, the duties fall into a few groups: tackling illegal content (such as content related to terrorism or child sexual abuse), protecting children from legal-but-harmful material, and giving users tools and transparency. The exact obligations on any particular service depend on what kind of service it is, how big it is, and what content it carries, which is why blanket statements about “what the Act requires” are usually too simple.
What is actually changing
A few of the most significant and most discussed changes, in general terms.
Illegal-content duties. Services are required to assess the risk of illegal content and take proportionate steps to prevent and remove it. This is one of the foundational duties and applies broadly across in-scope services.
Child-safety duties and age assurance. Services likely to be accessed by children face duties to protect them from harmful content, which in some cases involves “age assurance” or age verification, methods to establish whether users are adults. This has been particularly prominent for pornography sites and for content judged harmful to minors, with requirements coming into force during 2025. Age assurance is among the most debated parts of the Act, because of its implications for privacy and for how ordinary users access services.
Transparency and user tools. Larger services face additional duties around reporting, transparency, and giving users control over the content they see. The heaviest obligations fall on the biggest platforms, with a tiered approach intended to be proportionate to size and risk.
Because implementation is phased and ongoing, precisely which duties are live, and for whom, is exactly the kind of detail that changes, and exactly the kind of thing to check with Ofcom rather than to take as settled from any article, including this one.
The genuine debate
It would be dishonest to present the Act as uncontroversial, so here, briefly and even-handedly, is the disagreement.
Supporters argue it is a necessary and overdue response to real harms, particularly to children, that the largest platforms failed to address voluntarily, and that legal duties with a regulator behind them are the only thing that reliably changes corporate behaviour. Critics raise concerns about privacy, particularly around age verification and its data implications, about possible effects on encryption and free expression, and about the compliance burden on smaller services, which may struggle with obligations designed with giant platforms in mind. Both sets of concerns are held sincerely by serious people, and the right balance between protecting users and preserving privacy and expression is genuinely contested. This article does not adjudicate it; it notes that the debate is real.
What it means for smaller and private services
A point of particular relevance, kept general. The Act’s scope and its tiered approach mean that obligations are intended to be proportionate, with the heaviest duties on the largest, highest-risk platforms. Smaller and private services still need to understand and meet their applicable obligations, but the framework is meant to scale with size and risk rather than imposing identical requirements on everyone. What any specific service must do is a matter for that service to determine against Ofcom’s current guidance, and it is not something a general article can or should state definitively.
Where 142 fits
A brief and honest note, flagged as coming from the company I run. 142 is a small, private, subscription network, designed and built in Europe, with no public content, no algorithmic amplification, no advertising and no brands or creators, which is a very different risk profile from a large public platform optimising for reach. We take our regulatory obligations seriously and work to meet the ones that apply to us, while being candid that, like any service, our specific compliance position is determined against the current rules rather than asserted in marketing. I will not overclaim here: the responsible thing is to say that we treat user safety and our legal duties as real commitments, and to point anyone wanting the authoritative position to Ofcom. The broader thinking behind 142’s design, privacy, no amplification, no ads, is in our guide to private social networks and our guide to social media without ads.
Summary
The UK’s Online Safety Act 2023 places legal duties on online services, including social media, to tackle illegal content and protect children from harmful material, enforced by Ofcom through phased rules. Among the most discussed measures is age assurance for services likely to be accessed by children, particularly around pornography, with requirements arriving during 2025. The Act is large, still rolling out, and applies differently by size, type and content, so the precise obligations on any service are best checked against Ofcom’s current guidance rather than taken as settled. The debate around it, safety versus privacy and expression, is real and sincerely held on both sides, and this overview describes it rather than resolving it.
frequently asked questions
What is the Online Safety Act?
It is UK law (the Online Safety Act 2023) that places legal "duties of care" on online services, including social media, search and user-generated-content sites, to protect users from illegal content and to protect children from harmful material. Ofcom enforces it through codes of practice issued in phases rather than all at once.
What does the Online Safety Act require social media to do?
In general terms, to assess and reduce the risk of illegal content, to protect children from harmful material (sometimes via age assurance), and, for larger services, to meet transparency and user-tool duties. The precise obligations depend on a service's size, type and content, so blanket statements are usually too simple; Ofcom's guidance has the specifics.
What is age assurance under the Act?
Age assurance refers to methods for establishing whether users are adults, required for some services likely to be accessed by children, and prominent for pornography and content harmful to minors, with requirements coming into force during 2025. It is among the most debated parts of the Act because of its privacy implications and effects on how users access services.
Is the Online Safety Act controversial?
Yes. Supporters see it as a necessary, overdue protection for users and especially children; critics raise concerns about privacy (notably age verification), encryption, free expression, and the compliance burden on smaller services. Both views are sincerely held, and the balance between safety and privacy is genuinely contested rather than settled.
Does the Act apply to small or private social networks?
The Act's scope is broad but its approach is tiered and meant to be proportionate to size and risk, with the heaviest duties on the largest, highest-risk platforms. Smaller and private services still need to meet their applicable obligations, but the framework is designed to scale. What any specific service must do is determined against Ofcom's current guidance.
Where can I find the official, current rules?
Ofcom, the UK regulator responsible for the Act, publishes the authoritative codes of practice and guidance, and these are updated as implementation proceeds. Because the rules are phased and evolving, Ofcom is the source to rely on for the current position, rather than any general article, which can date quickly.