Summary
- Ofcom surveyed employees responsible for online safety at 125 services, with 59% saying their organisations had mostly or fully implemented the Act’s requirements.
- Fifty-eight per cent regarded the Act as expensive to implement, while 46% said its requirements were difficult to understand.
- Ofcom warns that the sample is not representative and cannot establish whether individual services are actually compliant with their legal duties.
Britain’s Online Safety Act is now visible inside companies as a collection of risk assessments, age checks, moderation systems, staffing costs, and governance processes, although new Ofcom research suggests that implementation remains uneven even among services already familiar with the law.
Ofcom surveyed employees with responsibility for online safety at 125 regulated or potentially regulated services between February and April, covering businesses of different sizes and services headquartered in the UK, elsewhere in Europe, and North America. Fifty-nine per cent said their organisation had mostly or fully implemented the Act’s requirements.
That figure needs careful handling because the research does not amount to a compliance scorecard. Ofcom says the sample is unweighted and not statistically representative of the wider population of services, while respondents were reporting their own organisation’s position rather than being independently assessed against the legislation.
Even with those caveats, the survey offers an unusually detailed view of the work being created by a regulatory regime estimated to cover more than 100,000 sites and apps. Rather than concentrating on policy intent, it asks what companies have changed, which systems they operate, and where implementation is consuming money and staff time.
Awareness is relatively high but not universal. Eighty-seven per cent said they had heard of the Act before the interview, while 80% believed their platform provided a regulated service. However, only 41% of those aware of the legislation said they knew “a lot” or “quite a lot” about it, and almost one in four had given relatively little thought to how it applied to their organisation.
Among the full sample, 44% said their organisation had made changes specifically because of the Act. That rose to half among respondents already aware of the legislation, while a quarter said no changes had been made and another quarter believed none were required.
Regulation becomes operational work
The clearest signs of implementation appear in age assurance, moderation, and risk assessment. Among services that said they had changed their operations because of the Act, 51% had introduced age-assurance methods and 40% had strengthened content moderation.
Across the full sample, 72% reported having a named person responsible for required risk assessments, while 67% said an illegal-content assessment had been completed and 53% reported an assessment of whether children were likely to access the service. The numbers show governance structures taking shape, although they also leave a sizeable minority where respondents did not report those processes.
Age assurance illustrates why simply asking whether a control exists can give an incomplete picture. Seventy-nine per cent of respondents said their service had a minimum-age requirement and 83% said users’ ages were checked in some form, but that total includes self-declaration, which Ofcom does not regard as age assurance under the Act.
Only 41% of all services reported using at least one method capable of being highly effective, such as facial-age estimation, photo identification combined with a selfie, or credit-card checks. Among services with a stated minimum age, 90% said they checked users’ ages, yet fewer than half reported using a method capable of meeting the regulator’s highly effective standard.
Content moderation is more established. Ninety-four per cent reported having moderation processes, with 90% using human moderators and 64% using automated tools. Sixty per cent combined both, suggesting that automation is supplementing rather than replacing human review across much of the sample.
Those changes sit inside the wider move that has taken the Online Safety Act from legislation into day-to-day supervision and enforcement, as Ofcom brings successive duties into effect and tests whether services have translated written requirements into operating controls.
Cost and complexity shape implementation
The research also shows why the same law can look very different inside a large platform and a micro business. Fifty-eight per cent agreed that the Act was expensive to implement, while 46% said its requirements were difficult to understand. Qualitative participants described long or technical guidance, uncertainty about scope, and difficulty determining which measures applied to a particular service.
Among organisations that had made changes, labour and financial costs were widespread. Forty-four per cent reported medium costs associated with staff understanding and deciding how to comply, 40% reported that level of labour cost for making service changes, and 36% cited financial costs associated with modifying the service. Around one-third reported a high or very high cost in at least one area.
The qualitative interviews show how those pressures can influence product and market decisions. Ofcom records one service temporarily shutting its UK operation while it prepared age assurance because it lacked the immediate technical resources, while another moved its user forum onto Facebook because it believed it could not afford the additional moderation burden.
Those examples do not establish that the law is disproportionate, nor does the research show whether the services had interpreted their duties correctly. They do show that compliance can alter product architecture, internal staffing, and decisions about which functions a company continues to operate itself.
That operational effect is likely to become more visible as Ofcom moves further into supervision. Survey responses can show what companies believe they have implemented, but investigations, information requests, and enforcement action will provide stronger evidence about whether those controls actually satisfy the law.
For now, the research captures an intermediate stage in which a substantial share of services say the regime is already embedded in their operations, while costs, understanding, and technical implementation remain inconsistent enough that Ofcom itself cautions against treating those claims as evidence of compliance.












