Artifact GuideUKRequirements

UK Online Safety Act Requirements

This page summarizes the UK Online Safety Act requirements in plain English: in-scope services must reduce illegal content risks, protect children from harmful and age-inappropriate content, give adults more control on Category 1 services, provide reporting and complaints routes, and meet Ofcom's record-keeping and enforcement expectations.

Requirements depend on the regulated service part, child-access result, content and risk, provider-pornography status, formal category, and current Ofcom instruments.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start by identifying the service and its regulated parts. All regulated Part 3 user-to-user and search services have illegal-content, children's access assessment, reporting, complaints, privacy, freedom-of-expression, record, and review duties. Child-accessible services, provider-pornography services, and formally categorised services have additional requirements.

Section 1

How should teams map UK Online Safety Act Requirements into owners, controls, and evidence?

For every regulated Part 3 service, complete and keep up to date an illegal-content risk assessment, implement proportionate safety systems and processes for the applicable user-to-user or search duties, provide content-reporting and complaints procedures, address freedom of expression and privacy, and keep the records required by sections 23 or 34.

Every Part 3 service must also complete a children's access assessment. If children are likely to access the service or a part of it, complete a separate children's risk assessment, implement the applicable protection-of-children duties, keep the assessment current, and record the measures and reviews.

A service with UK links that publishes or displays provider pornographic content falls under Part 5 and must use age verification or age estimation that meets the Act's effectiveness standard so children are not normally able to encounter that content. User-uploaded pornography on a Part 3 service must be analysed under the relevant Part 3 child-safety duties.

Formal categorisation adds requirements. Category 1 duties include user empowerment, identity verification, protections and procedures for specified content, terms, complaints, and assessments. Category 1 and 2A services have fraudulent-advertising and specified risk-record duties; Category 1, 2A, and 2B services can have transparency-reporting duties. Fee duties use a separate qualifying-worldwide-revenue threshold and exemptions. Confirm the current commencement, notice, and code for each deliverable.

  • Map each duty to the user-to-user part, search engine, provider-pornography service, child-accessible part, or registered category.
  • Treat as a statutory compliance route; record the rationale and evidence for any alternative measure.
  • Attach one accountable owner, control evidence, review trigger, and current source to every duty.
  • Separate binding law and issued codes from guidance, consultations, and draft additional-duty proposals.
Section 2

Who should own the UK Online Safety Act requirements, and what evidence should prove the decision?

The provider should assign one accountable executive or senior owner for the service-level program and named operational owners for scope, risk assessments, moderation, search, recommender systems, age assurance, reporting, complaints, terms, privacy, records, and regulator responses.

The evidence set should show the approved service boundary, assessments, risk-to-control mapping, code or alternative-measure rationale, implementation and testing, terms and user journeys, complaints outcomes, review dates, incidents, and any information supplied to Ofcom.

  • Keep separate records for the illegal-content and children's risk assessments even where they share evidence.
  • Use the same service boundary in the scope memo, risk records, category analysis, terms, and Ofcom responses.
  • Record why each control is proportionate to the risk, service size, capacity, design, and user base.
  • Reopen the duty map after a significant product change, new risk evidence, category entry, Ofcom notice, or updated issued code.
Section 3

Which edge cases should teams check before relying on a UK Online Safety Act requirements decision?

The most common mapping error is applying the right topic to the wrong service part. User-to-user and search duties use different statutory language, and provider pornographic content has a separate Part 5 regime.

Another error is treating categorisation as the start of compliance. Core Part 3 duties apply to regulated services whether or not Ofcom places them in Category 1, 2A, or 2B.

  • Do not assume all child-safety duties require the same age-assurance method; select controls from the risk and the exact statutory or code measure.
  • Do not assume compliance with an Ofcom code resolves UK GDPR, equality, consumer, intellectual-property, or other legal duties.
  • Do not treat an Ofcom template as mandatory wording unless the source says it is; the provider remains responsible for an accurate, complete record.
  • Escalate service-boundary, illegal-content, age-assurance, and category questions that cannot be resolved from documented facts.
Section 4

How should teams implement and maintain the requirements?

Build the requirements register in order: scope; illegal-content assessment; core safety, reporting, complaints, privacy, and record duties; children's access; child-safety duties; provider pornography; formal category; and any Ofcom notice or information request.

Existing-service deadlines in 2025 have passed. New or changed services must use the Act and Ofcom guidance's event-based timing, including assessment before significant changes and the applicable three-month periods after a service or duty comes into scope.

  • Use the checklist page to verify deliverables only after this duty map identifies what applies.
  • Track completed historic milestones separately from ongoing review, complaint, record, and control duties.
  • For a registered Category 1 or 2A service, capture Ofcom's current expectation to provide updated illegal-content risk-assessment records by October 2026.
  • Review the current Ofcom regulatory-documents page before relying on a code or guidance version.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding distinctions among service types, duties, content, child access, provider pornography, and categories.
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.