UK Online Safety ActCompliance Hub

UK Online Safety Act Scope, Duties, and Implementation

Decide whether a service is covered, which provider duties apply, which deadlines have passed, and what evidence Ofcom can expect under the UK Online Safety Act 2023.

By Sorena AIBased on UK OSA, GOV.UK, Ofcom, and ICO materialsUpdated 24 July 2026
Implementation focus
UK OSA
Scope and exclusions
Part 3 covers UK-linked user-to-user and that are not exempt for the relevant functionality. Part 5 separately covers UK-linked services publishing or displaying .
Live deadlines
Existing in-scope Part 3 services faced the 16 March 2025 illegal-content risk-assessment deadline, 16 April 2025 children's access-assessment deadline, and, where likely accessed by children, 24 July 2025 children's risk-assessment deadline. The related safety duties took effect on 17 March and 25 July 2025. New or changing services must use event-based timing, not copy those historic dates.
Evidence and enforcement
Treat issued Ofcom codes as a statutory compliance route, not the only lawful design. If a provider uses different measures, it must keep the required record and show how those measures meet the underlying duties.
Formal categories
Ofcom published the first Category 1, 2A, and 2B register on 30 June 2026 and updated it on 10 July 2026. Use the registered service part for additional duties; an internal threshold calculation or inclusion on the emerging Category 1 list is not formal categorisation.

Use the timeline for legal status and dates, then follow the grouped guides from scope to duties, evidence, and regulator readiness.

Key dates
26 Oct 2023
Act passed
16 Mar 2025
Illegal risk deadline
24 Jul 2025
Child risk deadline
30 Jun 2026
First category register
What you can decide faster
Scope and service model
Map user-to-user, search, and provider-pornography functionality; apply the UK-link test; then check Schedule 1 and other service-specific exemptions.
Duty sequencing
Separate duties that apply broadly from duties triggered by likely child access, provider pornography, or Ofcom categorisation.
Ofcom readiness
Keep risk assessments, control decisions, terms enforcement, complaints, records, and information-notice responses tied to the affected service.
Illegal harms
Child safety
Age assurance
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 21, 2026
Updated
Jul 16, 2026

The Act covers more than social media. It can reach UK-linked and , including providers based outside the UK, plus services that publish . Core Part 3 duties do not depend on company size or formal categorisation. Start with service scope and exemptions, then apply the risk, child-access, content, and category tests in order.

Online Safety Timeline

Key dates for UK OSA implementation

Distinguish Royal Assent and commencement instruments from Ofcom codes, completed assessment deadlines, enforceable duties, and the first category register published on 30 June 2026 and updated in July.

Loading timeline...
Recommended reading path

Choose the next Online Safety Act decision

New to the Act? Start with service scope and the UK-link test. If scope is already documented, move directly to risk and child-access assessments, implementation evidence, deadlines, or Ofcom readiness.

1

Start here: service scope and classification

Identify the regulated service, relevant UK links, exempt or disapplied functionality, and formal category status before assigning duties to a service part.

2

Risk assessments and safety duties

Work through illegal-content risk, children's access, children's risk, age assurance, and any additional duties that depend on the service or Ofcom category.

3

Implementation, complaints, and evidence

Translate the assigned duties into risk records, moderation and complaints processes, terms enforcement, age-assurance decisions, owners, and review triggers.

UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
Read guide
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
Read guide
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
Read guide
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
Read guide
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
Read guide
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
Read guide
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
Read guide
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
Read guide
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
Read guide
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Read guide
4

Deadlines, reporting, and enforcement

Separate completed implementation milestones from ongoing duties, then prepare records for category-specific submissions, transparency reporting, Ofcom information powers, enforcement, and privacy-regulator overlap.

Next step

Assign the applicable Online Safety Act duties and evidence

Record the regulated service, UK link, exemptions, child-access result, risk assessments, applicable codes or alternative measures, formal category status, owners, and review triggers in one assessment record.

What this unlocks
  • Scope the assessment to a named provider, service, and relevant service functionality.
  • Assign each applicable duty, control decision, evidence request, and review checkpoint to an owner.
  • Use cited research to resolve unresolved scope, timing, category, and interpretation questions.
  • Reassess after material changes to service functionality, users, risks, controls, Ofcom codes, or formal category status.
UK Online Safety Act compliance hub preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.