Artifact GuideUKIllegal Content Duties Explained

UK Online Safety Act Illegal Content Duties Explained

Regulated user-to-user and search services must assess illegal-content risks, keep a written record, and use proportionate systems and processes to protect people in the UK.

User-to-user and search duties are not identical. Classify the service first, then map the latest risk assessment to the safety, reporting, complaints, terms, record-keeping, and review controls that apply.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
19

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

If a user-to-user or search service is regulated under Part 3 of the Online Safety Act 2023, the provider must complete and record an , keep it current, and use its findings to choose proportionate safety measures. The user-to-user rules focus on preventing , reducing the use of the service for priority offences, and swiftly removing once the provider becomes aware of it. Search services instead focus on reducing the risk that illegal content appears in or through search results. The duties have applied since 17 March 2025; new or materially changed services must assess risk on the timetable set by the Act and Ofcom guidance.

Section 1

What do user-to-user services have to do?

Section 10 requires proportionate measures in the design or operation of a regulated user-to-user service to prevent people from encountering , mitigate and manage the risk that the service is used to commit or facilitate a priority offence, and mitigate and manage the risks of harm identified in the latest assessment.

The provider must also use proportionate systems and processes designed to minimise how long remains on the service and to take down any swiftly after becoming aware of it. Awareness of non-priority illegal content therefore matters, but the Act does not turn every breach of platform rules into illegal content.

The measures can concern governance, service design, algorithms, user access, content moderation, user support, and staff policies. The provider's terms of service must explain how users are protected from , describe relevant proactive technology, remain clear and accessible, and be applied consistently.

  • Map each priority offence and any relevant non-priority offence to the features, user journeys, and evidence that create or reduce risk.
  • Set moderation performance targets that match the assessed risk, then retain testing, staffing, training, quality, and escalation records.
  • Give users and affected persons an accessible route to report and make the complaints required by sections 20 and 21.
  • When judging whether content is , consider all relevant information reasonably available and apply the section 192 test for offence elements and possible defences.
Section 2

How are the search-service duties different?

Section 27 does not impose the user-to-user service's duty to take down hosted content. A regulated search service must take proportionate steps to mitigate and manage the risks of harm identified in its latest assessment and use proportionate systems and processes to minimise the risk that users encounter or other the provider knows about.

Controls may include removing or down-ranking results, changing predictive-search or ranking behaviour, stopping monetisation, and directing users to support. The exact control depends on risk and technical control over the search engine. The provider must publish a clear, accessible statement explaining its illegal-content policies and relevant proactive technology, and it must apply those policies consistently.

A combined service needs separate analysis. Its user-generated-content functions follow the user-to-user duties, while its search engine follows the search duties.

  • Document which entity has direct control over search operations and which results, suggestions, rankings, or indexes it can change.
  • Assess separately from known non-priority illegal content, then connect each finding to a search-specific control.
  • Provide content-reporting and complaints routes under sections 31 and 32, including routes for affected persons who are not search users.
  • Keep the public policy statement aligned with actual ranking, removal, reporting, complaints, and proactive-technology practices.
Section 3

How should the risk assessment drive controls and evidence?

The assessment is the control baseline, not a one-off filing. For an existing in-scope service, the first illegal-content assessment was due by 16 March 2025 and the safety duties applied from 17 March 2025. A service that later enters scope must follow the statutory timing rules. Every provider must keep the assessment current, review it when Ofcom changes a relevant risk profile, and assess a significant design or operational change before launch.

Sections 23 and 34 require providers to keep a written record of each assessment and of measures taken or used to comply with specified duties. If the provider does not follow a measure recommended in an applicable Ofcom code, the record must explain what alternative measure it uses and how that measure complies.

Following an applicable code's recommended measures gives the statutory treatment described in section 49. A provider may use alternative measures, but it remains responsible for meeting the underlying duty and must give particular regard to freedom of expression and privacy.

  • Scope record: service type, provider entity, UK-links test, exemptions considered, user base, and product boundaries.
  • Assessment record: offence-by-offence evidence, risk factors, likelihood, impact, vulnerable groups, algorithms, business model, existing measures, and residual risk.
  • Control record: code measure or alternative, accountable owner, implementation evidence, testing result, performance indicator, exception, and review date.
  • Change record: launches, recommender or ranking changes, new messaging or sharing functions, acquisitions, market expansion, and updated Ofcom risk profiles.
Section 4

What should a provider do next?

Start with a documented scope decision. Then complete the assessment using the current Ofcom risk profiles, approve a control plan, update user-facing terms or statements, and test reporting and complaints from the perspective of both users and affected persons. Assign legal interpretation of offence elements separately from operational moderation ownership.

Do not close the work because content was removed in one case. The Act regulates systems and processes: governance, prevention, detection, ranking, moderation, reporting, complaints, records, and review must work together and remain proportionate to the current risk.

Must a provider remove every item reported as illegal?

No. A report is evidence to assess, not a legal conclusion. The provider must apply section 192 using all relevant information reasonably available and ask whether there are reasonable grounds to infer the offence elements and no reasonable grounds to infer a defence. If the provider becomes aware that content is illegal, a user-to-user service must take it down swiftly. A search service must minimise the risk that users encounter known through search results.

Does following Ofcom's code automatically cover every illegal-content duty?

Following the recommended measures in an applicable code gives the statutory treatment set out in section 49 for the duties those measures address. The provider must still identify which codes and recommendations apply, implement them as specified, and keep the underlying assessment and records current. A provider may use alternative measures, but it must show that they meet the Act and must consider freedom of expression and privacy.

Do small services have to complete an ?

Yes, if the service is a regulated Part 3 service. The baseline risk-assessment duty is not limited to categorised or large services. Size and capacity can affect what measures are proportionate, but they do not remove the duty. The provider should first check the service definitions, UK links, and Schedule 1 exemptions.

  • Confirm whether the feature is user-to-user, search, or part of a combined service before assigning a duty.
  • Use the latest assessment to select code measures or document why an alternative meets the same statutory duty.
  • Test the full path from detection or report to decision, action, notification where promised, complaint, correction, and retained evidence.
  • Escalate uncertain offence classifications, possible defences, novel service features, and any gap between published policy and actual practice.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for service scope, illegal-content assessments and safety duties, reporting and complaints, records, codes, content definitions, and provider judgements.
legislation.gov.uk
Referenced sections
  • Official explanation of the distinct user-to-user and search duties, reporting and complaints duties, records, and content-status judgements.
legislation.gov.uk
Referenced sections
  • Binding user-to-user safety duties, including prevention, mitigation, content-removal, terms-of-service, and proportionality requirements.
legislation.gov.uk
Referenced sections
  • Binding rules for provider judgements about whether content is illegal, including the information, offence elements, and possible defences to consider.
legislation.gov.uk
Referenced sections
  • Binding duty to complete and keep up to date an illegal-content risk assessment for a search service.
legislation.gov.uk
Referenced sections
  • Binding search-service safety duties, including risk mitigation, encounter minimisation, public statements, and proportionality.
legislation.gov.uk
Referenced sections
  • Binding relationship between the duties, code measures, alternative measures, freedom of expression, and privacy.
legislation.gov.uk
Referenced sections
  • Binding duty to complete and keep up to date an illegal-content risk assessment for a user-to-user service.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.