UK Online Safety Act Scope, Duties, and Implementation
Decide whether a service is covered, which provider duties apply, which deadlines have passed, and what evidence Ofcom can expect under the UK Online Safety Act 2023.
Use the timeline for legal status and dates, then follow the grouped guides from scope to duties, evidence, and regulator readiness.
The Act covers more than social media. It can reach UK-linked and , including providers based outside the UK, plus services that publish . Core Part 3 duties do not depend on company size or formal categorisation. Start with service scope and exemptions, then apply the risk, child-access, content, and category tests in order.
Key dates for UK OSA implementation
Distinguish Royal Assent and commencement instruments from Ofcom codes, completed assessment deadlines, enforceable duties, and the first category register published on 30 June 2026 and updated in July.
Choose the next Online Safety Act decision
New to the Act? Start with service scope and the UK-link test. If scope is already documented, move directly to risk and child-access assessments, implementation evidence, deadlines, or Ofcom readiness.
Start here: service scope and classification
Identify the regulated service, relevant UK links, exempt or disapplied functionality, and formal category status before assigning duties to a service part.
Risk assessments and safety duties
Work through illegal-content risk, children's access, children's risk, age assurance, and any additional duties that depend on the service or Ofcom category.
Implementation, complaints, and evidence
Translate the assigned duties into risk records, moderation and complaints processes, terms enforcement, age-assurance decisions, owners, and review triggers.
Deadlines, reporting, and enforcement
Separate completed implementation milestones from ongoing duties, then prepare records for category-specific submissions, transparency reporting, Ofcom information powers, enforcement, and privacy-regulator overlap.
Compare regimes or answer a focused question
Use the DSA comparison for cross-regime scoping, or go to the FAQ hub when you already know the question that needs a direct answer.
Assign the applicable Online Safety Act duties and evidence
Record the regulated service, UK link, exemptions, child-access result, risk assessments, applicable codes or alternative measures, formal category status, owners, and review triggers in one assessment record.
- Scope the assessment to a named provider, service, and relevant service functionality.
- Assign each applicable duty, control decision, evidence request, and review checkpoint to an owner.
- Use cited research to resolve unresolved scope, timing, category, and interpretation questions.
- Reassess after material changes to service functionality, users, risks, controls, Ofcom codes, or formal category status.
