Online safety compliance adds cost and complexity

Online safety compliance adds cost and complexity

Online services report substantial compliance work under Britain’s safety regime. Ofcom’s first business survey highlights staffing, technology, and financial pressures as companies implement duties under the Online Safety Act.


Online businesses are committing additional staff, technology, and management resources to meet the UK’s online safety requirements, with a new Ofcom study highlighting the operational burden involved in implementing the regime.

The regulator’s Online Safety Business Survey examined 125 micro, small, medium, and large services whose employees have responsibility for online safety.

The sample included user-to-user platforms, services providing access to pornographic content, and search services that fall within the scope of the Online Safety Act.

More than half of participants reported that the relevant requirements had been fully or mostly implemented within their organisations. Common responses included risk assessments, age-assurance measures, changes to content moderation, and the development of new systems and processes.

Ofcom also examined the financial and organisational barriers businesses encountered. Resource and cost constraints featured prominently, alongside challenges associated with understanding requirements and adapting existing operations.

The regulator cautioned that the survey should not be read as statistically representative of every service covered by the Act. The respondents provide evidence of how a diverse group of regulated businesses is responding, but the research cannot establish compliance levels across the entire market.

The range of businesses affected by online safety regulation is unusually broad. Large platforms may have dedicated trust and safety, legal, engineering, and compliance teams, while smaller services may need to distribute similar responsibilities across much leaner organisations.

The obligations can therefore create different operating consequences even where the underlying regulatory duty is similar. A new safety control may require legal interpretation, product changes, engineering capacity, moderation processes, record-keeping, risk analysis, and continuing monitoring.

Age assurance illustrates that complexity. Introducing stronger checks can involve technology procurement and implementation, but businesses must also consider user experience, data handling, accuracy, and how the control fits into existing customer journeys.

Content moderation raises a different set of questions. Services need processes for identifying, escalating, reviewing, and acting on prohibited or harmful material while maintaining evidence that their systems operate as intended.

Online safety is consequently becoming an operational governance function rather than a narrow legal compliance project. Product design and technology investment now intersect more directly with regulatory risk, customer experience, and the cost of running a service.

Compliance spending may include specialist staff, external legal advice, technical services, moderation capacity, and changes to internal systems. Some of those costs are recurring rather than one-off, particularly where risks must be reassessed or controls monitored over time.

The impact is likely to be more visible at smaller businesses, where regulatory work competes with product development and commercial investment for limited resources. A requirement absorbed by a large platform’s existing compliance infrastructure may force a smaller operator to create an entirely new process.

There are also consequences for product roadmaps. Engineering time allocated to age assurance, reporting tools, moderation systems, and regulatory record-keeping is capacity that cannot simultaneously be used for commercial product development.

That does not make the spending discretionary. As enforcement develops, services face regulatory risk if their systems and processes fail to meet the statutory requirements applying to them.

Ofcom’s survey does not determine whether individual respondents are compliant, and the regulator explicitly warns against using the findings for that purpose. Instead, it provides an early view of the work businesses are undertaking as statutory duties move from policy into daily operations.

The implementation phase changes the economics of regulation because requirements begin influencing hiring, procurement, product design, risk management, and the allocation of management attention across services of different sizes.

Over time, businesses will have a clearer picture of which controls become standard practice and where compliance costs stabilise. The initial evidence suggests online safety is already developing into a permanent operating function for many regulated services rather than a temporary implementation programme.



  • ENRC dispute with SFO and Dechert settles

    ENRC dispute with SFO and Dechert settles

    ENRC has settled litigation linked to Britain’s abandoned corruption investigation. The confidential agreement with the Serious Fraud Office and Dechert closes a long-running dispute over conduct surrounding the former criminal probe.


  • Battery cyber-risk model puts billions in focus

    Battery cyber-risk model puts billions in focus

    Battery storage cyber-risk modelling puts multibillion-pound UK exposure in focus. Centrii’s GRIDLOCK analysis estimates sharply different attack risks under alternative security postures, although its headline probabilities and financial losses are simulated scenarios rather than forecasts.


  • Online safety compliance adds cost and complexity

    Online safety compliance adds cost and complexity

    Online services report substantial compliance work under Britain’s safety regime. Ofcom’s first business survey highlights staffing, technology, and financial pressures as companies implement duties under the Online Safety Act.