Cybersecurity 7 min read
What the Online Safety Act changed, and what it did not
Ofcom fined a suicide forum £950,000, then reported that it had exhausted every legal route to collect it. Three years of Online Safety Act enforcement.
In May 2026 Ofcom fined the provider of a suicide forum £950,000. On 20 July 2026 it reported that the money had not arrived, that the forum’s block on UK visitors is the fullest extent of what can be achieved under the Online Safety Act, and that all possible legal routes under the Act have now been exhausted.
That is not a regulator which failed to act. It is one which acted to the end of its statutory powers and found the end closer than the harm. Almost nothing useful about the first three years of this Act is in the headline penalty, which is a fine of £18 million or 10% of qualifying worldwide revenue, whichever is greater.
The enforcement ledger, as published
Ofcom’s update of 13 October 2025 sets out the shape of the caseload. Since March 2025, when the first codes became enforceable, the regulator had launched five enforcement programmes and opened 21 investigations into the providers of 69 sites and apps. On that day it issued updates on eleven of them.
The outcomes fall into four groups.
Some services complied under pressure. Two file-sharing services, 1Fichier and Gofile, were identified as raising serious compliance concerns and both deployed perceptual hash-matching to detect and remove child sexual abuse material, which is one of the core measures in the illegal harms codes. Ofcom’s wording is careful and worth keeping: it will not be taking further action against either service at this time. Nothing was closed. A regulator that gets a control deployed without issuing a penalty has done its job, and this is the outcome the Act was built to produce.
Some ignored the regulator, and that is what the small numbers are for. 4chan did not respond to a request for its illegal content risk assessment, nor to a second about its qualifying worldwide revenue, and was fined £20,000 plus £100 a day until it answered. In December 2025 Ofcom did the same to a file-sharing service, also £20,000 with the daily accrual.
Some failed a substantive duty and paid for it on a different scale. Ofcom’s age assurance enforcement programme records a run of confirmation decisions through the winter and spring: £1,350,000 against 8579 LLC on 20 February 2026, £1,000,000 against AVS Group Ltd on 4 December 2025 across eighteen adult sites, £800,000 against Kick Online Entertainment, £600,000 against the provider of fapello.com, £500,000 against Youngtek Solutions and £80,000 against First Time Videos LLC. Most of them were fined a second time, at between £5,000 and £100,000, for not answering the information request that came with the investigation. AVS took £50,000 on that count, and has since put a new age assurance process on every site the investigation covered.
And some left. Krakenfiles, Nippydrive, Nippyshare and Nippyspace all responded by geoblocking UK users rather than implementing the codes, and Ofcom closed those cases while reserving the right to reopen them if the block comes down.
Whether that counts as success depends on what you thought the Act was for
Geoblocking is the outcome nobody wrote into the impact assessment and it is now a routine result. If the objective was to reduce the likelihood that someone in Britain encounters illegal material on a given service, a UK block achieves it completely and immediately, at no cost to the regulator. If the objective was to raise the standard of the services people use, a block is a failure dressed as a win: the demand does not disappear, and the compliant alternative may not exist.
The suicide forum is where that argument stops being abstract. Ofcom found illegal suicide content on it throughout the investigation, including instructional guides the provider had itself pinned or reposted, found in May 2026 that the geoblock already in place was neither effective nor consistently applied, fined the provider £950,000 and directed it to comply. The forum then made the block work. The fine fell due on 12 June and was not paid.
What Ofcom published on 20 July 2026 is the part worth reading twice. It cannot apply for a court order blocking UK access, because business disruption measures require ongoing non-compliance as well as risk of harm, and the block is now working. It cannot get such an order for non-payment of a fine alone. It considered a conditional order that would take effect automatically if the block came down, and found the Act provides no mechanism for one. Neither Ofcom nor a UK court can shut the site down globally, because the Act reaches only a service’s operation in the UK or as it affects UK users.
That is the design working as drafted rather than a gap in effort, and Ofcom is now working with government on whether the business disruption powers can be strengthened. This is a jurisdictional regime with a jurisdictional remedy, and the aggregate effect over a decade will be a slightly different internet in Britain rather than a safer one everywhere.
The dates that actually bound services
The compliance sequence is public and it explains why the enforcement looks the way it does. Ofcom’s timetable runs as follows. Illegal content risk assessment guidance and the first codes were published on 16 December 2024, with risk assessments due by 16 March 2025 and the illegal content codes coming into force on 17 March. Children’s risk assessment guidance and the first Protection of Children codes were published on 24 April 2025, assessments were due by 24 July, and those codes came into force on 25 July. Separately, duties on age assurance for publishers of pornographic content were commenced by government on 17 January 2025.
Two things follow. First, the illegal content codes have been in force under eighteen months and the children’s codes barely a year, and the first year of a duty of this shape goes on establishing who is in scope and whether they have done the paperwork, which is what the information requests and the £20,000 fines are. Second, a service’s exposure is dominated by whether it did a documented risk assessment, not by whether a piece of content slipped through. The Act regulates process.
The penalties are two different instruments and they get confused
There are two enforcement tracks here, priced two orders of magnitude apart, and the £20,000 figures that got most of the coverage belong to the less interesting one.
Failing to respond to a statutory information request is a procedural breach. It is dealt with quickly, at a level calibrated to compel an answer rather than to punish harm, and it accrues daily until the answer arrives. That is what the two £20,000 penalties are, and they are working as designed: they are a lever, not a verdict.
Failing a substantive safety duty is the other track, and by the middle of 2026 it has produced six-figure and seven-figure penalties against pornography providers and one against a suicide forum. The gap between £20,000 and £1,350,000 is not inconsistency. It is the difference between not writing back and not doing the thing.
The Act also carries powers that have nothing to do with money. Sections 144 to 147 let Ofcom apply to a court for service restriction orders, requiring providers of ancillary services such as payment processing, search listings and advertising technology to withdraw support, and access restriction orders, requiring internet access providers and app stores to restrict access to the service itself. Those are the instruments that would matter against an operator with no UK presence and no intention of engaging. The suicide forum case is the first published occasion on which Ofcom has explained why it could not reach for them, and the reason was that the statutory grounds were not met.
What it does not do
It does not make Ofcom an arbiter of individual posts. The regulator has said so directly, in the announcement establishing its own advisory committee: its role does not involve deciding on individual posts or accounts, or requiring specific pieces of content to be taken down.
It does not create a general duty about lawful content that adults find objectionable. Those provisions came out of the Bill in November 2022, and what remains is a duty to enforce your own terms of service. The consequence for misinformation specifically is worked through in the misinformation playbook written in 2020.
And it does not only apply to the large platforms. Scope follows function, not size. A user-to-user service is a user-to-user service whether it has ten million accounts or a comments section on a specialist forum. A British organisation running a community, a support forum, a marketplace with messaging or a review section is inside this regime and a good number of them have not noticed.
What a compliance function should be watching
Three things, none of them content.
The fees regime, which opened for notification between December 2025 and April 2026 for providers meeting the qualifying worldwide revenue threshold. Being liable for fees is the moment an obligation acquires a finance owner.
Categorisation, because the additional duties on category 1, 2A and 2B services, including transparency reporting, sit on thresholds set in secondary legislation rather than in the Act, and a service can cross one without any change to what it does.
And the risk assessment record itself, because it is the document the regulator asks for first, it is the document providers have now been fined for not producing, and it is the only artefact that demonstrates the process the Act actually regulates.
The rest of the regulatory picture, including where the Act sits alongside the incoming cyber resilience regime, is covered under cybersecurity. Britain’s own supply of compliance technology, which has grown almost entirely on the back of this legislation, is examined in Britain’s safety tech sector grew up in public.
Coming up on three years after Royal Assent, the Act has produced a working process regulator, a set of safety measures deployed by services that would not otherwise have bothered, several million pounds of penalties against pornography providers, a list of services that solved the problem by leaving, and one fine of £950,000 that may never be collected from a site linked to deaths in this country. All of those are effects. Only the second is the one that was advertised.
Sources
- Ofcom, Important dates for Online Safety compliance, published 17 October 2024, last updated 2 December 2025 ofcom.org.uk
- Ofcom, Ofcom issues update on Online Safety Act investigations, 13 October 2025 ofcom.org.uk
- Ofcom, Ofcom fines file-sharing service £20,000, 17 December 2025 ofcom.org.uk
- Ofcom, Ofcom fines porn company £1million for not having robust age checks, 4 December 2025 ofcom.org.uk
- Ofcom, Enforcement programme into age assurance measures by services publishing pornographic content, updated 2026 ofcom.org.uk
- Ofcom, Online suicide forum investigation and review of enforcement powers, 20 July 2026 ofcom.org.uk
- Online Safety Act 2023 legislation.gov.uk