Foundry4

Cybersecurity 6 min read

The misinformation playbook written in 2020

Britain tried four things against pandemic misinformation. One survived into statute, and it is not the takedown power everybody spent three years arguing over.

Four things were tried against pandemic misinformation in Britain, and it is worth being precise about which of them made it into law, because the answer is counter-intuitive and it governs what a platform operating here has to do now.

The four were: label the claim, demote it in the ranking, promote an authoritative alternative alongside it, and remove it outright. Government added a fifth activity of its own, a unit inside Whitehall monitoring and referring content to platforms. Six years later, exactly one of those five appears as a duty in the Online Safety Act, and it is none of the ones that generated the argument.

The Royal Society got there first, and was largely ignored at the time

On 19 January 2022, while removal was still the assumed remedy, the Royal Society published its report on the online information environment and advised against relying on content removal to deal with harmful scientific misinformation. Its reasoning was not a free-speech argument dressed up as evidence. It was that there is little evidence removal limits the harm, that it can push the material into places that are harder to reach, and that it can deepen exactly the distrust in institutions that made the material persuasive in the first place.

The alternatives the report set out are worth restating because they became, without much acknowledgement, the actual British policy. Demonetise. Prevent viral spread rather than delete the post. Regulate the recommender system. Annotate with fact-check labels. And build population-level resilience through what the report called lifelong information literacy, with particular attention to older adults.

Notice the structural feature these share. Not one of them requires anybody to adjudicate whether a claim is true. They act on distribution, on money and on the reader, not on the proposition. That is why they survived and removal did not.

The report also put a number on the thing everyone was arguing about, and the number was smaller than the argument. Polling commissioned for it found around one in twenty British respondents disputed the scientific consensus on vaccine safety and on climate change. That is not nothing, and set against a UK population the Office for National Statistics put at 69.3 million in mid-2024 it is a lot of people. It is also not the picture of a country overrun, and it should have changed the shape of the policy discussion more than it did. A response calibrated to a majority problem, applied to a minority one, produces collateral damage in proportion to its reach.

Nobody can tell you whether any of it worked

This is the part usually skipped. There is no counterfactual. The interventions were deployed at global scale, simultaneously, without control groups, alongside a vaccination programme, a public information campaign and a series of national lockdowns. Any claim that labelling reduced belief in a false claim, or that removal increased distrust, is an inference from observational data collected during the least controlled period in modern British public life.

That is not an argument for doing nothing. It is an argument for preferring interventions that are cheap, reversible and do not require an institution to be right, which is precisely the list the Royal Society arrived at from a different direction. It is also the reason the section 152 committee is a more sensible instrument than it looks. Its output is advice and evidence rather than adjudication, and advice can be revised when the evidence changes.

What is and is not in the Act

On 28 November 2022 the government dropped the “legal but harmful” duties for adults from what was then the Online Safety Bill, saying it was taking out any incentive for firms to over-remove lawful content. What replaced it was the arrangement ministers called a triple shield: illegal content must go, content prohibited by a service’s own terms must be enforced against, and adults get tools to control what they see. A service’s duty in respect of lawful misinformation is therefore a duty to apply its own published rules, whatever those rules happen to say.

Two provisions of the eventual Act touch misinformation directly, and both are narrower than their names suggest.

Section 179 creates a false communications offence. Read the elements. The sender must know the information is false, must intend to cause non-trivial psychological or physical harm to a likely audience, and must have no reasonable excuse. All three, together. That is a criminal provision aimed at a person deliberately trying to hurt someone with a lie, and it is not, and was never going to be, a general instrument against people who are sincerely wrong on the internet. It is triable summarily and it came into force at the end of January 2024.

Section 152 requires Ofcom to establish an advisory committee on disinformation and misinformation, to include people representing users, people representing providers and people with relevant expertise, and to publish a report within eighteen months of the committee being established, and periodic reports after that. Ofcom established the Online Information Advisory Committee on 28 April 2025, chaired by Lord Allan of Hallam, appointing five members for three-year terms beginning on 1 May 2025, with a first meeting on 16 May. Its statutory report therefore falls due in the closing months of 2026.

A committee and an offence with three cumulative conditions. That is the whole of it. Ofcom set out the limit of its own role in the same announcement, saying that its job under the Act does not extend to deciding on individual posts or accounts, or to ordering that any particular thing be removed.

The playbook that actually transferred

What the 2020 exercise proved was operational rather than epistemic, and the useful lessons are the unglamorous ones.

Ranking beat classification. Deciding whether a specific claim about a specific treatment was false required expertise that did not exist at the speed or volume required, and the expertise that did exist changed its mind repeatedly and correctly as evidence arrived. Deciding that a piece of content was being shared unusually fast by accounts with no history required no medical judgement at all, and could be done in seconds. Every durable intervention in this field acts on the second signal.

Friction beat deletion. Adding a step before a forward, capping how many recipients a message can reach at once, or asking somebody whether they have read the article they are about to share are all interventions that cost the sharer a second and cost the platform nothing in adjudication. They are also close to invisible in the political argument, which is why they were left alone while removal absorbed all the attention.

Provenance beat rebuttal, at least in principle. A rebuttal arrives after the claim, reaches a fraction of the audience and is mostly read by people who already agreed. A durable record of where a piece of content came from travels with the content itself, and it carries the same advantage ranking does: establishing that an image came from a particular camera at a particular time is a question of fact about the artefact, not a judgement about the world. Whether any provenance scheme achieves the coverage it would need to matter is an open question and should be reported as one.

And the intervention with the best evidence base is the slowest one. The Royal Society’s information literacy recommendation was the least reported line in its report and is the only one whose effects would be expected to persist after the incident that prompted it.

What this means for an organisation running a platform in Britain

If you operate a service where users can post to each other, you now have illegal-content duties and, if children are likely to access it, children’s safety duties. You do not have a duty to be right about anything else, and Ofcom is not going to tell you to remove a post. What you do have is a duty to enforce your own terms of service consistently, which means the terms are now a compliance document rather than a marketing one, and the enforcement records behind them are evidence.

That is a lighter regime than the one debated in 2020 and a heavier one than most services realise they are inside. The enforcement picture as it has actually developed is set out in what the Online Safety Act changed, and what it did not, and the broader regulatory landscape sits under cybersecurity.

The thing the 2020 emergency really established was that the fastest available lever in an information crisis is the ranking function, that it belongs to a handful of private companies, and that no British statute since has attempted to regulate it directly. Six years of argument about takedown left the actual mechanism untouched.

Sources

  1. Royal Society, Royal Society cautions against censorship of scientific misinformation online, 19 January 2022 royalsociety.org
  2. Online Safety Act 2023, section 179 (false communications offence) legislation.gov.uk
  3. Online Safety Act 2023, section 152 (advisory committee on disinformation and misinformation) legislation.gov.uk
  4. Ofcom, Ofcom establishes Online Information Advisory Committee, 28 April 2025 ofcom.org.uk
  5. DCMS, New protections for children and free speech added to internet laws, 28 November 2022 gov.uk
  6. Office for National Statistics, Population estimates for the UK, mid-2024 ons.gov.uk