Artifact GuideUK Online Safety ActRegulated Service Scope

UK Online Safety Act Regulated Service Scope

The Act regulates UK-linked user-to-user and search services under Part 3 and UK-linked services that publish provider pornographic content under Part 5.

Scope follows the service's functions and content flows. Exempt functions, mixed services, and separate provider-pornography duties must be recorded rather than collapsed into one product-wide label.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is a regulated user-to-user service, a regulated search service, or a UK-linked service that publishes or displays provider pornographic content. For Part 3, identify the user-to-user or search functionality, establish a UK link, and apply Schedules 1 and 2. For Part 5, identify pornographic content published or displayed by the provider and apply that Part's separate UK-link and age-verification rules.

Section 1

What should teams decide about Regulated Service Scope under the UK Online Safety Act?

For a user-to-user service, ask whether content generated, uploaded, or shared by one user may be encountered by another. For a search service, ask whether the internet service is or includes a search engine. A combined service can contain both, and the Act can apply different duties to each regulated part.

A Part 3 service must have links with the United Kingdom, fall outside the relevant Schedule 1 exemption, and not be a service described in Schedule 2. The UK link can arise from significant UK use, targeting the UK market, or UK access combined with reasonable grounds to believe the relevant content presents a material risk of significant harm to people in the United Kingdom.

Part 5 is different: it covers a service with UK links when pornographic content is published or displayed by the provider. User-uploaded pornography on a Part 3 service and provider pornographic content can therefore engage different provisions and age-assurance duties.

Once scope is established, assign duties to the correct service part. Core Part 3 duties include illegal-content risk assessment and safety duties, children's access assessment, content reporting, complaints, freedom-of-expression and privacy protections, and records. Child-safety and categorised-service duties depend on later tests.

  • Inventory posts, comments, reviews, uploads, sharing, group spaces, messaging, public search, and provider-published content.
  • Identify the provider entity and the regulated part; outsourcing hosting, moderation, or age assurance does not by itself transfer the provider's duties.
  • Apply Schedules 1 and 2 paragraph by paragraph and record conditions, exceptions, and any functionality that remains regulated under Part 3 or Part 5.
  • Keep provider pornographic content separate from regulated user-generated content in the scope record.
Section 2

Who should own Regulated Service Scope, and what evidence should prove the decision?

Product and engineering should document how users create, upload, share, encounter, and search content. The provider's legal or regulatory owner should apply the Act to those facts and approve the boundary between regulated, exempt, and out-of-scope functions.

A useful scope record contains the provider entity, service map, user permissions, search sources, UK-link evidence, Schedule 1 analysis, provider-content analysis, decision date, reviewer, unresolved points, and specific reassessment triggers.

  • Name one accountable provider-side owner and one reviewer with access to the service facts.
  • Attach dated user journeys, permissions, architecture notes, UK user evidence, market targeting, and the text of every exemption relied on.
  • Explain partial-scope decisions at feature level so later risk assessments cover the correct content and users.
  • Reassess before launching a new user-content, messaging, search, pornography, or UK-market function.
Section 3

Which edge cases should teams check before relying on a Regulated Service Scope decision?

Common boundary errors include treating all messaging as exempt, assuming comments or reviews are too limited to count, treating an entire combined product as one service, and using company size as a scope threshold.

The Schedule 1 descriptions are conditional. For example, one-to-one live aural communication is different from text, recorded audio, group communication, or a service that adds other user-to-user functionality.

  • Check whether comments and reviews are limited to provider-published content and whether the service provides any additional user-to-user functionality outside Schedule 1 paragraph 4.
  • Check whether a search engine searches one site, selected topic-specific sources under a relevant arrangement, or the wider public web; the category threshold exception for some vertical search is not a general Part 3 exemption.
  • Check internal-business, public-body, and education or childcare conditions instead of applying a sector-wide exclusion.
  • Treat child access and categorisation as follow-on duty tests, not reasons to exclude a Part 3 service.
Section 4

How should teams implement the service-scope decision?

Produce one approved service-scope memo with a separate conclusion for every relevant service part. Link each in-scope part to its illegal-content assessment, children's access assessment, safety controls, reporting and complaints procedure, and record-keeping owner.

If the service relies on an exemption, record the feature constraints that keep it within the exemption. A later design change can remove that factual basis even when the product name and provider remain the same.

  • Use the applicability test to reach the initial decision and the service-scope-and-categorization guide to map any threshold analysis.
  • Assign a named owner to each in-scope service part and each exemption constraint.
  • Keep the scope record with the risk assessments so Ofcom-facing evidence uses the same service boundary.
  • Review after any material change in functionality, users, UK availability, market targeting, or provider-published pornography.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Primary source for scope, service-specific duties, records, and Ofcom's regulatory powers.
legislation.gov.uk
Referenced sections
  • Separate scope and duties for services publishing or displaying provider pornographic content.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.