On 10 July 2026, Ofcom published a package of draft materials as part of the third phase of its implementation of the Online Safety Act (the “Act”). While the Act already imposes baseline duties to tackle illegal content and to protect children (where a service is likely to be accessed by them) on all regulated user-to-user and search services, the 10 July package provides a set of additional duties targeted at the UK’s largest and most widely used online services.
The package is comprised of three connected strands:
- The Register of Categorised Services. Ofcom published its long-awaited register, formally designating services across Category 1, Category 2A, and Category 2B, together with a list of “emerging” Category 1 services.
- Consultation: Draft Fraudulent Advertising Codes of Practice (Category 1 and 2A): The draft codes of practice set proposed measures for how the largest user-to-user and search services should tackle paid-for fraudulent advertising.
- Consultation: Draft Additional Duties Code of Practice and Guidance (Category 1 only): The draft codes of practice and associated guidance address user empowerment and identity verification, protections for certain public-interest content, terms of service, complaints, and freedom-of-expression and privacy assessments.
This post focuses on the third strand—the additional duties for Category 1 services.
I. Which services are affected?
The additional duties apply only to “Category 1” services. A regulated user-to-user service qualifies for this designation if (1) it uses a content recommender system and has more than 34 million average monthly active UK users; or (2) it has more than 7 million such users, uses a content recommender system, and provides functionality allowing users to forward or share regulated user-generated content.
As part of the package announced on 10 July, Ofcom published a register of categorised services, which designates eleven platforms as Category 1 services. The register also designated certain services as “emerging Category 1 services,” which generally consist of services that meet 75% of the applicable user-number condition and at least one relevant functionality condition. These services do not have additional duties under the Act.
II. User Empowerment: Providing Adult Users with Greater Control
User empowerment duties under the Act aim to give adult users of Category 1 services greater control over the content they see and the users with whom they interact (via optional user identity verification).
A) Suitable and Sufficient Assessments
The Act requires Category 1 providers to offer features that allow adult users to reduce their likelihood of encountering, or be alerted to, specified categories of lawful but potentially harmful material. To comply, providers must assess the likelihood of adult users encountering three specific categories of “relevant content”: suicide and self-harm content; eating disorder content; and abuse and hate content, including abusive content targeting people by reference to race, religion, sex, sexual orientation, disability or gender reassignment, and content inciting hatred against people with those characteristics. The draft guidance provides further descriptions of these categories of content. Notably, Ofcom’s definitions of these categories closely track the corresponding categories under its existing guidance on content harmful to children—so providers of services likely to be accessed by children may be able to leverage existing systems and processes for their user empowerment duties (in the draft guidance, Ofcom signals that this is its intent).
Ofcom’s draft guidance proposes a four-stage process for “suitable and sufficient” assessments. Under the proposal, a provider should (1) identify and understand the relevant content; (2) assess the likelihood that adult users will encounter each category of relevant content; (3) decide and record which Code measures (or alternative measures) it will implement; and (4) report, review and update its assessment. The draft guidance indicates that existing Category 1 providers would be expected to complete their first assessment within three months after Ofcom publishing its final guidance.
B) Proportionate User Controls
On the basis of the assessment, providers must offer proportionate user controls. The proposed Code measures focus on providing user-selected features rather than requiring broad content removal. For example, reflecting the requirement in section 15(5) of the Act, proposed Measure ADU A1 recommends that providers not only set default positions for each control feature offered, but also give registered adult users the ability, “at the earliest possible opportunity”, to retain or change the default settings.
The Code also recommends certain content-specific controls (e.g., controls that allow a user to exclude relevant content from a feed or apply an alert or blur to it). In addition, proposed Measure ADU A5 recommends that providers within scope have systems and processes that enable users to report content which they suspect is relevant content. Finally, the draft Code proposes certain content-agnostic tools. For example, these measures would enable registered adult users to block or mute individual accounts, and to disable comments on their own posts.
In addition, providers must offer all UK adult users the option to verify their identity if identity verification is not already required to access the service. Verification is optional for the user, and the regime does not create a mandatory real-name policy for general internet use. Ofcom explains that the identity verification duties arose from concerns that anonymity has led to greater online abuse, and the aim is to mitigate this risk by enabling users to filter out non-verified users.
The Act specifies that the verification process “may be of any kind (and in particular, it need not require documentation to be provided).” Ofcom proposes that platforms design their verification schemes around four core principles:
1. Relevance: the attributes being checked are relevant to the purpose(s) of the verification scheme;
2. Reliability: the identity verification offered is reliable, so that providers can have confidence that users actually have the attributes they claim to have;
3. Inclusivity: the identity verification process is inclusive, so that no adult user is unduly excluded from being able to verify; and
4. Clarity: the process is clear, so that users understand what identity verification means in practice on the service.
Providers must also supply a filtering tool that adults can activate to manage their exposure to unverified users. The draft Code recommends the tool achieve two outcomes: preventing unverified users from interacting with the adult user’s content, and reducing the adult user’s exposure to content generated by unverified users. Ofcom advises that the tool should only apply to functionalities where it would tangibly benefit users, and not in a way that “would materially interfere with the core offering of the service.”
III. Safeguards for News, Journalism, and Democratic Debate
Although the Act does not make public interest content immune from moderation, the Act introduces procedural protections to prevent platforms from arbitrarily removing such content. It outlines three distinct categories: news publisher content, journalistic content, and content of democratic importance. Volume 3 of Ofcom’s proposal sets out how providers should comply with the required procedural protections, as well as their duties to conduct and publish assessments of the impact of safety measures on free expression and privacy.
With respect to news publisher content, the Act imposes a prior-notification process for recognised news publisher content. The guidance provides proposed approaches for recognising such content and what the notification process should entail. To support the notification procedure, Ofcom suggests that providers establish a mechanism through which recognised news publishers can identify themselves in advance, as this would help providers identify protected content before taking a moderation decision.
Providers are also required to use proportionate systems and processes to take into account the importance of free expression of journalistic content and content of democratic importance when making content-moderation decisions. These requirements do not prevent providers from taking actions against such content, but they do require that they not unduly restrict their availability. Ofcom proposes several measures in this regard, including by recommending that the provider’s means and methodologies be specified in internal documentation, and that providers give individuals working in content moderation training and materials about the importance of these types of content.
For journalistic content, providers would, in addition, have to establish dedicated and expedited complaints procedures. Where an expedited complaint concerning journalistic content is upheld, the draft Code recommends that the provider act swiftly to reinstate the content or reverse the relevant action against the user. For content of democratic importance, providers must ensure their moderation systems operate consistently across political viewpoints.
Finally, the Act requires providers to conduct and publish assessments on the impact of safety measures and policies on free expression and privacy, and Ofcom’s package includes guidance to help providers comply. Among other things, the guidance proposes a four-step process for carrying out these impact assessments, and explains how providers can make the publication of these assessments clear and accessible.
IV. Enforcing Providers’ Terms of Service
Sections 71 and 72 of the Act require Category 1 providers to use proportionate systems and processes to ensure that specified decisions impacting users—including removing or restricting regulated user-generated content and suspending or banning users—are taken only where they are consistent with the platform’s own published terms of service, subject to certain statutory exclusions. Providers must apply their terms consistently when taking specified actions and must take any specific disciplinary action prescribed by those terms.
Ofcom’s draft Code proposes two measures: (1) a requirement that providers include certain provisions in their terms of service regarding user empowerment, content of democratic importance, journalistic content, and complaints; and (2) a requirement that certain aspects of terms of service be clear and accessible, taking into account findability, layout and formatting, language, and usability.
The draft Terms of Service Guidance provides additional colour to how providers can comply with these terms of service and complaints handling duties. Among other things, the draft guidance advises that terms detailing prohibited conduct be highly specific—enough so that any user could reasonably judge whether a piece of content or type of behaviour is prohibited or allowed on the service. In addition, if a provider uses automated content moderation, Ofcom suggests that providers can improve consistency between those automated decisions and their written policies by balancing precision and recall appropriately and assessing the technology’s performance against benchmarks.
Ofcom’s draft Code also provides measures for complaints, as providers are required to enable users and affected persons to make complaints about non-compliance with certain duties. Ofcom recommends that complaints be handled by individuals or teams with appropriate expertise and sufficient authority to provide an effective remedy. Ofcom does not propose a fixed period for resolving ordinary complaints, although separate expedited requirements apply to complaints concerning journalistic content.
V. Related Development: DSIT’s Latest Response to Growing Up in an Online World Consultation
Ofcom’s package sits alongside a parallel workstream by the Department for Science, Innovation and Technology (“DSIT”). Following its “Growing Up in an Online World” consultation, which closed on 26 May 2026 and drew more than 116,000 responses, DSIT published a progress statement on 15 June 2026 and set out the next tranche of measures expected to follow (see our prior blog here).
On 15 July, DSIT provided some additional details regarding additional measures that will be taken, including:
- for 16- and 17-year-olds, default overnight restrictions for social media services—with alerts and push notifications muted between midnight and 6am—and default restrictions on design features such as autoplay and personalised recommender feeds. 16- and 17-year-olds will be able to change these default settings;
- for under-18-year-olds using AI chatbots, regular breaks. DSIT committed to working with experts on how frequent and how long breaks would be; and
- measures to address services that provide “dangerous, misleading, or unverified mental health advice,” which may include banning chatbots that pose a serious threat to children.
In addition, DSIT revealed that it has decided based on stakeholder feedback not to ban or age-gate VPNs. DSIT nevertheless committed to ensuring that these tools are not misused to undermine child safety protections, such as age assurance mechanisms.
VI. Next Steps
The consultation on the draft Code and guidance closes at 5 pm on 2 October 2026, with final decisions expected by mid-2027. Following the Parliamentary process, the final Code will come into force 21 days after it is issued.
With respect to the additional measures announced by DSIT, the government plans to lay regulations before Parliament within 12 months of its 15-July statement (after which they must be approved by both houses).
Trainee solicitor Erin Lynch kindly assisted with the drafting of this article.
Recent Comments