final logo red (RGB)

 

Communications and Digital Committee 

Uncorrected oral evidence: The Online Safety Act: implementation and impact

Tuesday 15 September 2026

2.15 pm

 

Watch the meeting 

Members present: Baroness Keeley (Chair); Baroness Caine of Kentish Town; Viscount Colville of Culross; Baroness Elliott of Whitburn Bay; Baroness Fleet; Lord Holmes of Richmond; Lord Kirkhope of Harrogate; Lord Knight of Weymouth; Lord Storey; Lord Tarassenko.

Evidence Session No. 2              Heard in Public              Questions 18 - 51

 

Witnesses

Mark Bunting, Director, Online Safety Strategy Delivery, Ofcom; Suzanne Cater, Enforcement Director, Ofcom; Oliver Griffiths, Group Director, Online Safety, Ofcom.

 

USE OF THE TRANSCRIPT

  1. This is an uncorrected transcript of evidence taken in public and webcast on www.parliamentlive.tv.
  2. Any public use of, or reference to, the contents should make clear that neither Members nor witnesses have had the opportunity to correct the record. If in doubt as to the propriety of using the transcript, please contact the Clerk of the Committee.
  3. Members and witnesses are asked to send corrections to the Clerk of the Committee within 14 days of receipt.

21

 

 

Examination of witnesses

Mark Bunting, Suzanne Cater and Oliver Griffiths.

Q18            The Chair: Good afternoon, everyone, and welcome to this meeting of the Communications and Digital Committee. Today we are holding our second evidence session in our inquiry on the Online Safety Act. The Act established Ofcom as the UK’s online safety regulator, so I am very pleased that we have representatives from Ofcom here today at this early stage of the work. Thank you all for joining us. Could I start by asking each of you to introduce yourself and your role at Ofcom?

Oliver Griffiths: Good afternoon. Thank you very much for the opportunity. I am the group director for online safety at Ofcom.

Suzanne Cater: Good afternoon from me. I am director of enforcement at Ofcom, with primary responsibility for enforcing the Online Safety Act.

Mark Bunting: I am the director of strategy delivery in Ofcom’s online safety group and I am responsible for our overall strategic direction.

Q19            The Chair: The Online Safety Act, as we know, was passed in 2023. Could you explain which parts of the Act are now in effect and what remains to be implemented?

Oliver Griffiths: I am very happy to do that. I will pass over to Mark, who has been overseeing this work. As a quick introduction, we see three major pieces of work that we are balancing. The first is the implementation of the Act; we are getting relatively close to the end on that. The second is driving compliance with the Act, and I look forward to going into detail on that. The third is the social media ban and related new duties that are going to be coming Ofcom’s way. Our job is to balance those three.

Mark Bunting: I will try to go through it fairly briefly, and then would be happy to take follow-up questions. The committee will be aware that there are three major planks to the Online Safety Act: duties regarding illegal harms, duties regarding the protection of children from certain types of legal material and particular duties applying to categorised services.

Our judgment, when the Act was passed in late 2023, was that the priority was to bring the duties into force as quickly as possible. The Act required us to write codes of practice for illegal harms and protection of children in order to do that. The first focus of our work was to bring those duties into force. That took around 18 months from passage of the Act. There is a statutory deadline, which we met, to bring the protection of children codes into force. Since early 2025, those duties have been in force and we have been able to take action against them.

A third part of the Act, as the committee will be aware, was delayed as a result of Wikimedia’s judicial review of the categorisation process, which completed last summer. That has been slower than our original road map intended. We published the register of categorised services last summer and a consultation on the duties that apply to categorised services. That consultation is about to conclude.

The final thing I will say is that the Act has been amended since the original passage, particularly through the Crime and Policing Act, for example, which brought in new priority offences. We have also been implementing those. The new offences relating to cyber stalking and serious health harm came into force earlier this summer. We will be publishing proposals on the 48-hour takedown duty for non-consensual intimate imagery later this year.

That is where we are. By around the middle of next year we would expect to complete that work on categorised services. The other big thing that has changed more recently is the Government’s new plans for online safety, including the social media ban and possible regulation of AI services. I am sure that we will come back to that, but we are talking to the Government at the moment about the implications of that for our work programme and resources.

Q20            The Chair: We will move on to that in just a moment. To be clear, do you have the date when the regime will be fully operational set in the timetable?

Mark Bunting: Our current programme envisages the duties on categorised services all being in force in the middle of 2027. That would be the point at which the initial set of duties are fully in force. As I say, that is subject to ongoing discussions with the Government about how we sequence that with other work that is coming.

Q21            The Chair: Let us go on to that. What impact, if any, will the Government’s plans to introduce a social media plan for under-16s have on your timetable?

Oliver Griffiths: To step back from this, we were fully loaded in terms of the amount of work we had to do before the social media ban was announced. We have recognised how important this is and moved staff to work directly on the social media ban since that announcement earlier in the summer. It is clear that, without extra staff and funding, something will have to give.

So we were very pleased to have the Government’s commitment back in June that they would provide extra funding so that we were able to balance both of these. We submitted a detailed business plan on that in July and we are in detailed discussions with the Government at the moment. That is on both the funding and sequencing, because there is a big body of work, as Mark was setting out. We will be looking to then set out a road map by the end of this year, so a revision in terms of how we are able to deliver all of the bits. Our view is that this is doable, as long as it is resourced and sequenced right.

Q22            The Chair: What lessons has Ofcom learned from implementing the first two phases of the Act? How are those lessons shaping your approach to the additional category 1 duties now under consultation?

Mark Bunting: There are a few things that I would say. We have learned a lot more about the process of consultation. As I said, because we were keen to begin the process of bringing the duties into force so quickly, we published our initial proposals about regulating illegal harms very shortly after the Act passed. At that point we had not had much time to engage with industry or to use our formal information-gathering powers to understand current practice, or indeed to engage with civil society about what campaigners and expert bodies thought was possible.

Although I think it was the right judgment to try to bring the duties into force as quickly as possible, we have learned more about how we engage effectively with stakeholders, in both industry and civil society, as we go through the process of making policy. For example, the work on women and girls and the guidance that we published last year was done in a very collaborative way—at least we felt it was very collaborative—with the women’s sector and regulated services, so that we could understand and push further through that policy work than we had been able to initially. We are taking the same approach, where we can, to the duties on categorised services. For example, on transparency reports, we have had a lot of conversations with civil society about what information they would find useful to see in the public domain. That is one area.

The second area I would emphasise is the impact of what is known as the safe harbour in the Act. We will probably come back to this, so I will not say too much about that now. The extent to which the codes of practice act as a kind of framework for companies to comply with the Act has become clearer to us. That can be very positive, because the codes give clear indications to companies about what they need to do to comply, but they can also be limiting. If it is too straightforward for companies to demonstrate that they take all the steps in the codes, they are deemed compliant with the duties.

The Chair: We have a question we can come on to.

Mark Bunting: We will come back to that.

Q23            The Chair: In our first evidence session, we had the Children’s Commissioner, who clearly is the most senior safeguarding person in the country for children. That is why we had her at our first session. She told us that she had requested to see the risk assessments that online services must now produce and that Ofcom would not provide them. Are you able to give us any further detail on that?

Oliver Griffiths: We have worked very closely with the Children’s Commissioner, who has been running a panel of children for us, which has been a very important input into our policy-making. Generally, we have really valued the insights that they have been able to provide from lived experience.

On this particular point, we have not received a formal request to make the risk assessments available to them. The important thing here is that, under Section 393 of the Online Safety Act, we have a requirement that we need to get the consent of a company before we are able to share it with a third party. We are very happy, if the Children’s Commissioner wants to provide us with a formal notification that they would like this, to then liaise with the companies and see whether they are prepared to release.

The Chair: That is important. Clearly there are some crossed lines, because she said to us that she asked to see the risk assessments and that you said no, which I have to say surprised me. I think that it surprised all of us.

Oliver Griffiths: We have not received a formal request, no.

The Chair: If you receive a formal request from the Children’s Commissioner to see the risk assessments, you will be prepared to let her see those.

Oliver Griffiths: We will go to the companies and check that they are happy for that information to be shared with a third party, which is the obligation we have under the Online Safety Act. Absolutely, we will follow that process.

Baroness Caine of Kentish Town: Was there an informal approach made about that request?

Oliver Griffiths: There have been discussions going on with the teams for months.

Q24            Lord Storey: Good afternoon. Has the Online Safety Act made children and adults in the UK safer online? I have two supplementary questions.

Oliver Griffiths: This is the fundamental question, is it not? We are here to make life safer online. We are absolutely focused on making sure that we are driving significant change.

We think that there has been really big change that we have seen in the sectors that are covered by the Online Safety Act. We published a business survey earlier this week that was looking at 125 companies, and this ranged from small to large. They were saying that 76% of them had completed a risk assessment, that 44% of them had implemented changes so were coming into compliance with the Act and that 59% felt that they had fully or substantively implemented the requirements. That was an interesting dip into it. We have 100,000 services that are in scope of the Act.

The thing that has been most visible has been the step up in the use of highly effective age assurance. This was from July of last year when the requirement came into place. We have seen some of the very big services put age gates in place. That includes Reddit, X and Discord, for example.

If you look across the pornography sector, which is a real blight for children—the ease with which they are able to access pornographic material—we have highly effective age assurance being taken up across what is a very large sector. All of the top-10 porn services now have age gates in place. Three-quarters of the top 100 have age gates in place or have chosen to geoblock from the UK. We have seen a 23-fold increase in the number of age checks that are going on across a sample of 32 companies that we looked at. We think that this is substantively reducing the amount of porn that children are able to see.

Some of the stuff that has been much less visible has been the choice that a number of services have made to geoblock their services. This is when we get in touch often to inform a company of its obligations under the Online Safety Act—and this can be through enforcement as well—and that company then chooses to block UK access to their sites. This happened on a very prominent suicide forum, for example. It has also happened on a range of file-sharing sites, which we were very concerned about in terms of the prevalence of child sexual abuse material there, and on some that had legal but harmful material in terms of violent conduct and so forth. We have seen that happening, broadly.

Where we have been certainly less content has been with some of the large services most used by children. We were pleased earlier in this year to have some commitments secured from X, on hate and terror takedown times, and from Meta and Snap, particularly on grooming. We think that those are going to be very important as they come through on those particular services. Generally, when you look at our tracking indices on this, we are underwhelmed by the overall effect so far. This is a one-way ratchet that is going to be building up over time, and we are confident that the commitments that we have seen from some of the big services and the continuing momentum that we have is going to make a significant change over time.

Q25            Lord Storey: I was interested that you said about the fundamental question, because I think we were quite shocked when the Children’s Commissioner said to us that the Act has made “absolutely no difference”. How do you respond to that comment?

Oliver Griffiths: We share the frustration. We are looking to make a really significant cultural change here across a number of companies that have acted with impunity for a long time. These are corporate cultures that have built up over decades. When you look at the fundamental architecture that is set up in the Act, this is one of driving corporate change. This is why the approach into it has been via risk assessments rather than taking down content; it is about making sure that incentives for leaders are changed. I am afraid that that is something that takes a degree of time, especially when it is spread over the broad set of sectors that we have. I absolutely share the frustration. I came into this job to make sure that we are making life better, especially for children, but we are still at an early point in this journey.

Mark Bunting: To build quickly on that, we have seen steps along the road, but there is still a long way to go to the destination. To give you one example, Oliver was mentioning the work we have done with some of the biggest services on protecting children earlier this year. Some of those firms have made very positive commitments to make it harder for strangers to approach children, but we are not yet sure that they have good enough ways of identifying who the children are who are using their services. Therefore, you can change one system but, if you are not changing the whole system, you are not achieving the goal. There is still a long way to go.

Q26            Lord Storey: Should we, as a society, be allowing tech companies to operate if they cannot guarantee—never mind “safer”—the safety of children online? It is as simple as that.

Oliver Griffiths: This is what the Act was primarily aimed at. Society has said absolutely that there is not freedom to operate in this space. If you look at initiatives such as the social media ban, there is a sense that there needs to be an intervention to address a problem that is there. The Act itself, of course, put duties on the companies; it is clear that that is where the duty lies for them. I think society does not accept that companies are able to act in the way they are at the moment.

Q27            Lord Storey: Will there come a time when we would say, “We are fed up of trying to take down various sites”—or whatever you call them—“Quite frankly, we are going to have to take you down. We will not allow you to operate in the UK because you cannot guarantee the safety of our children”?

Oliver Griffiths: Is the “you” in that question the social media sites?

Lord Storey: Yes.

Oliver Griffiths: Yes, and I think we will come on later to the enforcement process we go through. As it stands, if we suspect a company to be in breach, we can launch an enforcement case against it. If it does not then come into compliance with the Act, at the end we have the option to have a business disruption measure. That will stop their access to the UK. Obviously that is not taking down the site internationally. The territorial reach of this Act goes only as far as the UK—we are very clear about that—but we have that opportunity to have a business disruption measure applied via a court.

Q28            The Chair: You mentioned the children’s panel that the commissioner is running. There is a very large number of children who she is communicating with about this. Through her feedback to you, do you think that there is any evidence that a child’s real-life experience online has actually improved?

Oliver Griffiths: There is good anecdotal evidence that things are moving in the right direction. We have a very significant monitoring and evaluation programme that we have put in place so that we are tracking exactly those sorts of questions. It is not just a case of seeing what changes have been made by the services, but also the actual lived experience of people as it moves through.

I certainly think that we are moving in the right direction on this. This is against a background where we have seen the proliferation of AI over the last couple of years, which in many ways has been sucking things the other way. It has become much easier to create and disseminate child sexual abuse material, for example. We are seeing a whole range of ways where harms can be supercharged. Certainly I think that, on the scales, the Online Safety Act is making a significant impact, but we also have an environment where AI is supercharging a number of the harms itself.

Q29            Baroness Caine of Kentish Town: You are talking about social media. I am particularly interested in gaming in this context. Could you reflect on what progress you feel you have made in that area?

Oliver Griffiths: I will start briefly and then, Mark, turn over to you. There have been a number of gaming services that have introduced age gates themselves—so Xbox, for example, and Steam as well. It is an important area of focus for us. It has not been absolutely front and centre for us, just to be clear, in that obviously we need to prioritise as we go through. Social media and the protection of children through that has been higher on the list.

Mark Bunting: Our main focus there has been on the interactions between different users of these games. In particular, with services such as Roblox, we have evidence of those platforms being used by people who wish children harm. The controls that we have recommended there, in terms of age verification and ensuring that adults cannot approach children they do not know, have been effective.

There are broader issues with gaming that are not necessarily captured by the duties that we have to uphold—for example, violence in games and screen time. There are a whole host of questions that may not have been uppermost in the debate when the Act was first passed or, at any rate, were not captured by the scope of the legislation. In that sense, our engagement with gaming maybe is a little narrow, but we have tried to focus on the issues where we think we can make a difference. As I said, things like Roblox have been a really important service for us.

Q30            Viscount Colville of Culross: In your submission to the committee you have said that you would like there to be targeted reforms of the OSA. These include reviewing the safe harbour provision. You, Mark, said that it limits the compliance of companies. Would you like to see safe harbour taken out of the Act if we were going to amend it?

Mark Bunting: This is a really important issue and not one that I can give you a simple answer to. There are some complicated issues to weigh up. The original legislation in effect created two parallel frameworks, almost. There is the risk-based component where companies have to assess risks and take steps to mitigate them. Then there are the codes of practice and the safe harbour. The challenge that we see—and a number of stakeholders highlighted the same challenge—is that, if companies do all the things in our codes of practice, they are deemed to be compliant with the Act, even if they still have risks that have not been adequately addressed through those measures.

That is a tension with the safe harbour. It causes us problems because it does not then give us a locus to go back to them and say, “What about this problem that you have acknowledged and still haven’t done anything about?”, or at least we can do that only in a voluntary, supervisory way; we cannot enforce.

The reason that I cannot give you a very straight answer is because that system was put in place to give companies legal certainty about what they needed to do in order to comply. That legal certainty is also important to our ability to enforce against them. If we are not clear with companies about what they need to do to come into compliance, it is very hard for us to successfully bring investigations against them. The Act was trying to have its cake and eat it, so to have this very broad risk-based framework that also creates legal certainty for companies.

We would be in a stronger position if there were a duty on companies to mitigate all the risks in their assessment, even if that required them to take steps beyond the codes of practice. But we would have to be really clear that that would not be an easy journey to enforce, and therefore it is not necessarily a quick route to big fines or concluding investigations, but it gives us more scope to engage with firms. I think, particularly for the biggest services, that more flexibility in the way in which we engage them on the risks in their assessment would be helpful in being able to hold them to account.

Q31            Viscount Colville of Culross: Why would it be so difficult for you to be able to enforce this against these companies that have not actually mitigated?

Mark Bunting: Suzanne might want to say a little more about this. Simply, enforcement is easiest when there is a clear requirement and we can point at what a company is doing and show that there is a gap. Age verification is relatively straightforward—it is not always straightforward—in the sense that it is a clear duty to use these tools to keep under-18s off your platform. We can look at the technology that they are using and it is a quick test, relatively: are they using one of our approved forms of age assurance or not?

The sorts of obligations that I am talking about here would be much broader. It would be to do everything reasonable to address risks. In that phrase—“do anything reasonable”—is room for a very lengthy and litigious debate with companies about whether they are in fact doing everything that is reasonable. That is why the tension would arise for us in enforcing that broad duty. I am not saying that that is a bad idea, but I am saying that those are the issues that we reflect on when we think about reform in this area.

Q32            Viscount Colville of Culross: Would it help if we looked at Schedule 4 to the Act, in which, when it comes to the principles on which the codes of practice are drafted, you look at whether the measures are proportionate? Many of the people I have spoken to—campaigners who are concerned about this—have said that that should be replaced by a duty of care, which would mean that, for any new products that were created, the providers would have a duty of care to make sure that they did not harm the users. That seems like quite a clear target for you to enforce.

Mark Bunting: I do not think that the word “proportionate” is the problem there; it is the nature of the safe harbour and the codes of practice. However, there are other problems in Schedule 4 and I am very appreciative of the committee looking at this area. For example, Schedule 4 also says that our codes of practice have to contain clear and detailed steps that companies must take. Again, the phrase “clear and detailed” puts the onus back on us to specify what the specific action is that a company has to take, rather than putting the onus on the company to take the steps that they need to take to address the problems that they are encountering. We think that that is an area that the Government might want to think about too.

Viscount Colville of Culross: That means that, in order to enforce, you have to prove that, in every single case where the code has been relied on, they have breached it. Therefore, it is very difficult for you to enforce.

Suzanne Cater: The way the codes of practice work, as we said, is as a safe harbour. One challenge is to make sure that the codes are accessible and applicable to the huge range of services that are in scope. As Mark said and you pointed out, we have the proportionality, all the measures we recommend have to be technically feasible and they have to be clear and detailed. That is trying to strike a balance with having a clear rule that we can assess a company against in saying, “You are not taking this measure”, or “You are not taking it effectively”, which would then take them outside of the safe harbour. At that point, you go back to the basic duty and say, “Are you taking proportionate measures to protect children from harm?”, or whichever duty you are looking at.

A duty of care obligation is definitely an alternative way of doing it. Again, you would have the desire, particularly in such a large sector with such a huge number of very small services, to make sure that the parameters of what that means are set out quite carefully. I suspect you might come up against the same challenges again. Certainly with the safe harbour approach, we are finding from the enforcement perspective that the largest services probably have a lot of quite sophisticated measures in place, but they are not necessarily enough to actually address the harm that may be occurring on their service. They will argue very vociferously that they are within that safe harbour, so we cannot take further enforcement action against them. It is a challenge.

Q33            The Chair: Building on from the duty of care approach, we quite often hear cited and understand the principle of safety by design. How important is that in all the points you are making about enforcement? It goes back to the question that Lord Storey asked. It is not unreasonable for us to expect platforms and providers of services to be safe by design, particularly around children. Is that something that you are working on? How are you giving that effect in what you are doing?

Mark Bunting: It is absolutely linked to this discussion. There are a couple of angles to it. In one sense, the Act is all about safety by design, because we are not a content regulator and we do not tell the companies when an item of content, an account or whatever it is should be taken down. All our focus is on how they designed their services and put in place the right trust and safety frameworks and governance around their services to mitigate risk.

Safety by design is right at the heart, but it is limited by this point about the safe harbour. The concept of safety by design is exactly as you have described it: it is about designing a service to remove risk as far as possible. It is never going to be possible to remove all risk from the types of services that we are talking about here, but we think that, in the end, the codes of practice and the approach to them put all the weight on Ofcom to identify what companies need to change. The sentiment of safety by design, which I completely agree with, is that the onus should be on the companies to identify what they need to do to address risk.

Q34            Baroness Fleet: Following on from that, in August you said that many large well-resourced companies are “not yet doing enough” to make people safer online. As you know, the Molly Rose Foundation in June this year argued that teenagers’ overall exposure to “high risk suicide, self-harm, depression or eating disorder content” on major social media platforms has “barely changed” in the previous year. That is pretty condemning of the effectiveness of the Act and its implementation.

What is your reaction, particularly to the specific claims of the Molly Rose Foundation, which we believe we can trust? Do you disagree with what it said or do you feel that you do not have the powers to actually enforce what the large majority of sensible people want to have enforced? What is stopping you going further faster? It cannot just be a matter of money and people.

Mark Bunting: I will pick up those specific points and Oliver might want to come back on the broader questions. As regards suicide and self-harm content, this touches on another really important and not always well-understood aspect of the Act, which is about our ability to require them to use proactive monitoring tools to identify certain kinds of harmful content. Companies, as the committee is aware, have two main ways of responding to harm. They can receive reports and complaints and then take action retrospectively, or they can use tools to proactively identify certain types of content and remove it before users are exposed to it, which clearly is preferable.

Some of the firms tell us that they do use these automated tools, but we have not yet seen data from them to help us assess their effectiveness. We are currently consulting on requirements to use these tools more widely.

The challenges in this area are about the tension between use of those tools and users’ privacy and freedom of expression. Because of concerns about privacy and freedom of expression, the Act set out that we could require those tools only when we were convinced that they met certain thresholds for accuracy and effectiveness. We are gathering evidence to try to stack up that case and will be saying more about that once we have finalised our consultation this autumn. We think that those tools are key to dealing with the challenge that you have identified, but it is not clear in the Act that companies have to use them.

Baroness Fleet: That seems to be a fairly fundamental flaw in the Act and your ability to implement it.

Mark Bunting: We talked a little bit about this area in our submission, in the section about proactive tech. It is not a part of the legislation that has had a huge amount of discussion. We think it is right that we should have to think carefully before we require use of these tools, because they are very intrusive in that they require all material to be scanned by social media firms as it is uploaded. However, we think that the case for that is strong and, as I say, we are working on our proposals in this area at the moment. I think we will have more to say about it before the inquiry is concluded.

The Chair: We have some more questions about enforcement, particularly around the suicide forum, which I will come to. We will come on to Baroness Elliott’s question about the speed of reaction.

Q35            Baroness Elliott of Whitburn Bay: We have heard from stakeholders that Ofcom’s approach to tackling emerging harms has been very slow, reactive and not flexible enough, basically. Why has it been difficult for Ofcom to identify new technologies and harms and to respond to them quickly? Why is it so sluggish?

Oliver Griffiths: I can start off on that one; Suzanne may want to come in with more detail. Take the example of Grok on X at the beginning of this year, which suddenly burst on to the scene over the Christmas period. We were on to it extremely quickly and had launched an investigation within two weeks. That is a good example of where a clear new harm emerged, at scale, and we felt the need to move on it extremely quickly.

What we take in general are the 140 or so priority offences that are set out in the Act, which sets out our harms. We are in constant dialogue with government on emerging areas. We were very early in saying that we thought that chatbots were not properly covered by the Act as it was going through. We have that policy dialogue going on. We are always looking to see where we can get the best intelligence on where harms are emerging. We have very close links with law enforcement, for example. We were talking about the Molly Rose Foundation earlier, and there are a lot of other civil society groups. We are making sure that we are a repository for that data and intelligence, which can drive us in terms of what we focus on strategically and the particular cases that we take on. To go back to the Grok case, that was evidence that, when things are really blowing up, we have that ability to move quicklyquicker than our international peers.

Q36            Baroness Elliott of Whitburn Bay: We have had some information from stakeholders. Sir Jeremy Wright recently said in a Westminster Hall debate that he does not find in the Act support for the idea that we have to know something will work before we try it. Is that the approach you take? Will that not make you miss things?

Oliver Griffiths: Would you mind expanding on that?

Baroness Elliott of Whitburn Bay: There is a feeling coming through from stakeholders that everything has to be proved beyond any doubt before you will start to take action. You have to prove that what you are going to do will work before you start to do it. Is that the approach you are taking? Is that not a bit sluggish and going to keep you constantly behind the curve?

Oliver Griffiths: We, as an organisation, recently published our risk appetites. On legal, we have an open risk appetite. We do not want to make sure that we are absolutely certain that everything is going to work before we are prepared to take action.

I would also point out that we are operating in a highly litigious environment. We currently have judicial reviews being run against us on our fees regime, twice, by Meta. We have a raft of services that are bringing judicial reviews against us for trying to collect data so that we can monitor and evaluate what is happening with the regime. We have four services that are appealing to the Upper Tribunal in terms of our categorisation register, which we published in July.

We absolutely are looking to drive change in the best way we can. We want to use all the opportunities we have. We have all come to work to make this happen, but, if we run unnecessary risks, we are going to get absolutely clobbered legally by deep-pocketed individuals and firms. We need to make sure that we have got the balance right. We are also learning as we go. I do not want to claim that anybody is an expert at online regulation yet. This particular regime has been running for 18 months, and we are very keen to learn as we go.

Q37            Baroness Elliott of Whitburn Bay: Why do you think that it is coming across from the stakeholders we have heard from that you are slow to react? For instance, the CEO of the Molly Rose Foundation identified issues with “Ofcom’s agility in identifying and responding to new harms”, describing your approach as “slow and reactive”. The Children’s Commissioner likewise said that Ofcom has not been “getting ahead of the harms”. Why do you think there is that perception, if you are telling me that that is not what you are doing? That is coming from various people; it is not one person.

Oliver Griffiths: Sure. My observation is that the Act is extraordinarily broad. It applies to more than 100,000 services. We need to focus on particular areas to make any progress. If we spread ourselves thinly across all of the 140 or so priority offences, nothing is going to happen. We can have a great press release and say that we are doing a particular thing, but we are not going to be able to drive systemic change in particular areas.

When we are focusing on particular harms and areas of concern, there are inevitably other things that are not our particular focus. They all matter a tremendous amount, but that is not where we are going to be putting our organisational focus at that particular time. The time will come, I hope, for those things, but the very process of choosing means that there are certain areas where we are not going to be able to put much focus at this point.

Q38            Lord Kirkhope of Harrogate: You have a bit of a problem and a perception difficulty here. What you are telling us all sounds utterly reasonable, but the view of an awful lot of peopleat least the perception they have of youis that you simply do not use your teeth; I think that was the term used by the Children’s Commissioner. I do not want to get into any dental analogies at this point, but there is a feeling that you are not using the powers that you have in an aggressive enough way.

In a way, I am pointing slightly towards Ms Cater here, who is your enforcement officer and a lawyer. Is it because you are confined by the legal process that you do not behave in a more proactive way? I would use the word “aggressive”, but perhaps that is not the right word. Is it to do with the law? Is it to do with your reluctance to get into fights with others? You made a suggestion a moment ago that you have to be very careful because people take action; judicial reviews and all sorts of other things are hitting you. I want to know whether you think that you have enough going for you that you can do what you are supposed to doand do it in a sufficiently busy and noisy way that you redeem yourselves and get a better perception, as well as getting some action.

Suzanne Cater: I can take that. I would start by saying that I fully agree with that. We have to use our teeth. I will avoid dental analogies, as requested, but we need to do that; that has always been a significant part of our strategic approach.

I absolutely agree that there is a perception problem. Enforcement is a critical part of any regulatory regime, but even more so in this scenario where it is entirely new, there is no precedent nationally or internationally, and we are dealing with a sector that has never been regulated and is incredibly unwilling to be regulated and come into compliance. The purpose of my team’s role is to act as that incentive to make services change their behaviour and to make the senior leaders of those services change their behaviours. They need to believe that Ofcom will take action. They need to believe that Ofcom will impose meaningful penalties that will hurt and will also make services elsewhere in the sector sit up and take notice. I absolutely agree on that.

Where I would respectfully disagree, in terms of the sense of us, is on whether we have used our teeth. I think that we are using our teeth. We are very active in using our enforcement powers, though not all of them yet. I absolutely accept that. We have a strong toolkit of powers. For these first 18 months, we have definitely focused on using our more conventional powers: our duties to obtain information and the enforcement powers. There is a bit of learning to walk before we run on that, and that is an area of focus for us.

To run through a couple of statistics, we have opened six enforcement programmes so far under the regime, including one just last week that is focusing on the deployment of hash-matching technology to prevent the spread of non-consensual intimate imagery, which is obviously a huge priority for us. We have opened 40 formal investigations over the past 18 months, covering more than 100 different services. The first of those was opened into a suicide forum just a couple of weeks after the illegal content duties came into force.

Some of those earlier investigations were focused on smaller services with more straightforward breaches. That was quite a strategic choice for us, but we are seeing our portfolio shift now. We have three very significant and complex investigations open at the moment. Oliver has mentioned the investigation into X and the issue of Grok gen AI generating illegal content and sharing that on X. We also have an investigation into Telegram and the measures it has in place to prevent the spread of child sexual abuse material, and into TikTok. We have imposed £7 million in penalties so far.

I can see you want to come back in. I absolutely agree with you that this is something we need to do more of. As we look into the near future, we are starting to build up to using the rest of those powers and increasing the aggressiveness. One example, if I may, is that we are starting to use the senior management liability power, which I know people have been very keen for us to use. We are starting to bare our teeth a bit towards that criminal liability side as well, which will start to make a real difference.

Q39            Lord Kirkhope of Harrogate: As one lawyer to another, I ask a simple question. You claimed in that US suicide forum case that you had run out of legal routes. I am interested in whether you are saying that the tools that are available to you to be nasty, including your dental toolsyour teeth or whateverare inadequate to do what you feel you have to do. Somewhere in this system, I believe, there are inadequacies; I want to find out from you where they are.

Oliver Griffiths: Quickly, before I pass back to Suzanne, it is important to have a sense of scale here as well. We have been the most active of any international regulator in this space. Part of the frustration, which we share, is that these things take time. If you look internationally, whether at the EU, Australia or the litigation in the US, these are all taking two or three years. We want to be significantly quicker than that, but we are at that stage in the life cycle where we have launched a lot of this stuff and it has not come in to land just yet. On business disruption measures, you are absolutely right: there is stuff that is not working there.

Suzanne Cater: I would answer that in two parts, if I may. One is that there is a situational challenge in the sense that not only are we regulating this huge sector, but a lot of them are small services based overseas and with no assets in the UK. That makes enforcement really challenging. We have seen—it has been publicly flagged; I know that it is a concern—that some services have not been paying their penalties. We are taking active steps to pursue that, register judgment debts in the UK and investigate where their assets may be, but we have to be realistic about the challenges of getting such judgment debts registered and acknowledged in overseas jurisdictions. That is an automatic limitation.

That brings me on to the business disruption measures. We have found them very difficult, mainly because we may apply to the court for business disruption measures only where there is evidence of ongoing non-compliance. Where a service, as with the suicide forum we investigated, withdraws from UK jurisdiction, it is no longer within our jurisdiction. The duties of the Act apply only when the service operates in the UK. That was where we felt we could not go any further with that service.

Similarly, we have seen services that may have come into compliance, which is obviously what we want to see; we want to see them come into compliance. Take some of the adult sites, for example. In response to our enforcement, they have brought in effective age checks but then not paid the penalty. Because there is then no ongoing non-compliance, we are not able to apply for business disruption measures on the basis that they have not paid their penalty; that would be incredibly helpful.

Q40            Viscount Colville of Culross: I want to take you back to the suicide forum. There has been a huge amount of concern. You, Suzanne, have just raised the problem of the suicide forum having withdrawn to outside our territoriality. I also understand that the reason why you have not been able to pursue the forum is because children have been using VPNs, which means that you do not have the capacity to deal with them. However, I am interested that the Australian eSafety Commissioner has now demanded that gating against VPNs should be a fundamental requirement for providers. When we started the Online Safety Act, there was no technology for age verification. As a result of the Online Safety Act, as you have already said, the companies created this technology. Should the Act be amended so that we can force companies to deal with the problem of VPNs for underage users?

Oliver Griffiths: This is a fundamental political decision that will certainly sit outside our remit. We have seen that VPN usage certainly went up when we put age gates in place in July last year, but not to such an extent that we feel that there are whole sections of society that are walking around the Act. In Australia, they were saying that, of the children who were not complying with the ban, about 8% were using VPNs at the time. You can also see how this could become a bigger issue over time. The Government were actively considering whether they would make any recommendations on VPNs in the summer. That needs to be in the right forumthe Government liaising with experts in Parliament on itand we will absolutely get on with what we are told to do.

Q41            The Chair: That is good to know. You mentioned in passing to Lord Kirkhope’s question the £7 million of penalties that have been imposed so far. Can you tell us how much has been paid of that £7 million? How much has actually been collected?

Suzanne Cater: I do not have a figure to hand. I am certainly happy to follow up. I know that we had another payment this week, which was great. Realistically, the majority has not been paid.

The Chair: Okay. If you could let us have the figure, that would be helpful.

Suzanne Cater: We would be very happy to do so.

Oliver Griffiths: Suzanne mentioned earlier that there have been different stages of our enforcement and the early stage has very much been on the smaller, largely pornography, sites. As time goes on and we move on to the bigger sites, which have business assets in the UK, this issue, as a proportion of our fines, is going to reduce over time. It looks acute at the moment but, over time, as we are fining the bigger companies if they are in breach of the Act, this will be less of an issue.

Q42            Baroness Caine of Kentish Town: I wanted to return to two issues. One was that you were talking about time for culture change and leadership and people realising their responsibilities. That is in a massively fast-moving set of industries where, frankly, from what you are saying, people are not necessarily engaging with that long-term culture change path. That being the case, do you think that that is the right approach, or are there other approachesincluding the enforcement area and making those enforcement costs a much harder and harsher route?

Also, in so doing, would that money help you with the level of resources you need to regulate the sector? One thing you were indicating earlier was that you do not have the resource level, in your view, to deal with the scale of the problem that you are being charged with. That is something I have been asking about at various meetings.

Oliver Griffiths: I absolutely agree with you that the culture is the thing in the end here. We fundamentally need to change incentives in the boardroom. This is where the growth of international regulation in this area—Canada recently announced that it is moving into this space—alongside the litigation in the US, in particular, is going to start making a really significant change. You no longer have a trust and safety team coming up to tell you that safety really matters; you have your CFO and strategic risk team telling you that you are having to provision for hundreds of billions of damages. That fundamentally starts to change things.

I was talking to an executive who was drawing the analogy with data protection. This was something, if you roll the clock back a generation, that was not being taken seriously in the boardroom. Suddenly, you had the combination of big fines and much higher awareness. I hope that that is a useful analogy for us as well. To your point, that absolutely has to be accompanied by financial penalties for companies, which will really make them sit up and notice. If we expect that this is going to happen organically, we will be disappointed.

Q43            Lord Knight of Weymouth: Before I move on to my question, I want to touch on the VPN issue. Back in 2023, when the Bill was going through this House, I tabled an amendment on the use of VPNs to evade age verification. The Minister replied at the time that, for Clause 11(16) to address the concerns around age assurance and age verification, the provider would have to account for the use of VPNs as a way of working around the age verification. If the provider concluded that the VPN could be used to evade their age verification and age assurance, the clause would not apply. Do you now agree with the Minister, as he was then, in that summary position?

Oliver Griffiths: I might delegate to Mark, who was around at the time; I am afraid that I was not.

Mark Bunting: Might I ask you to explain the Minister’s reply?

Lord Knight of Weymouth: The Minister said, in essence, that, in order to satisfy you that their age verification and age assurance measures were sufficient, the provider would have to account for the use of VPNs by children to get round the age verification measures.

Mark Bunting: I will say a quick word, then Suzanne might want to pick up on how we have engaged on this in practice. What I do not think they need to do under the terms of the Act is prevent users using VPNs to access their service. I do not think that there is any obligation in the Act that would amount to that. We have certainly provided guidance to firms and taken action against firms when they have encouraged people to use VPNs as a way of getting round our restrictions. I do not think that there is anything in the Act that would require providers to—

Q44            Lord Knight of Weymouth: If they perceived that a VPN had been used, in the same way that, if I use a VPN to try to buy tickets for Arsenal Football Club when I am overseas, I cannot do it because they can see that it is a VPN, should they prevent access to the service?

Mark Bunting: This gets to the point that Oliver was making earlier. This is a bigger claim than we can give you an opinion on today. VPN use is very widespread for all sorts of purposes. We use VPNs in our corporate environment every day. The question of whether there should be legislation to require firms to prevent access by VPNs is one that would need a bigger debate. It would be a significant intervention.

Q45            Lord Knight of Weymouth: I had better move on to the question that I am teed up to ask. The recent settlement by Meta in the US courts was eye-catching as far as I am concerned, first, because of the sum of money that it was willing to settle on and pay over a number of years. It considered that affordable$18 billion, was it? Has that changed the game for you in terms of the amount of money that you pursue when you take enforcement action?

Oliver Griffiths: It certainly changes the game, as I was saying earlier, in that it brings this into people’s eyeline in the executive suites when they are thinking about safety. For us, the level of penalties that we are going to be able to impose is determined by the Act as 10% of qualifying worldwide revenue. We have just been through that process with our fees regime, in terms of determining what that qualifying worldwide revenue is across all these big companies, so we now have those numbers there. The process that we will go through is working within that 10% limit here. Suzanne and the team have developed a detailed series of metrics on how you determine what those numbers are, but I do not think that we are going to be swayed by the figure of $18 billion.

Sorrythere is one point I should have got back to on this. Unfortunately, we do not get to spend it. Any fines that we levy go back to the Treasury. We are funded, as of this financial year, by the companies themselves. We are not a draw on the public purse, but we do not get to keep any of the penalties that we levy.

Q46            Lord Knight of Weymouth: Let me continue on what was eye-catching. It was also eye-catching that this was very much about the system design of the Meta platforms, rather than individual items of content and the harm that was related to them. That felt like an advance on the regime that we created in the Online Safety Act. The settlement did not get to the algorithms and algorithmic harm, but it got to quite a lot of other harms. Is that instructive for you in terms of whether we got the regime right?

Mark Bunting: I would say a couple of things on that. A lot of what was agreed in the Meta settlement, when it comes to preventing harmful contact between adults and children or between systems to prevent exposure to certain types of content, is very consistent with the framework of the Act and the codes of practice that we have. The one area where it went significantly beyond what the Online Safety Act does is in dealing with features and functionalities that are about not the type of content but the volume of consumption—that is, the amount of screen time or the addictive effect of the platforms. Those things featured in the parliamentary debates—we will both remember thosebut the Act did not, in the end, bring them into scope.

Q47            Lord Knight of Weymouth: Do you think that it should, if it were improved?

Mark Bunting: These are judgments, in the end, for the Government and Parliament.

Lord Knight of Weymouth: You have a job to try to make things safer for children; that is why you get up in the morning.

Oliver Griffiths: Yes, but it is interesting. The Government have made quite a few commitments, have they not? The ban goes further, but the commitments that they have on curfewing look quite similar. There are bits on time limits that I do not think have been part of the debate so far.

It is interesting that this is one company, and it has made commitments for between five and 10 years. This is not even in perpetuity. You were one of the important architects of the Act. I would not be too tough on the Act. There is something fundamental here about building an approach to risk and dealing with it that I do not see at present in the settlement with Meta.

Q48            Lord Knight of Weymouth: You lead me on to my penultimate question. Do you see a way of getting this to apply here in the UK? Do you see a way of getting the elements of this settlement to apply across the piece to the large social media platforms, not just Meta?

Oliver Griffiths: Our formal powers are those that are bound by the Online Safety Act. As you saw earlier in the year, we called out some of the really big social media companies, saying that we thought that it was an outrage, to be honest, that they were not policing their minimum age properly. We do not have the power to enforce that, but we have the power to encourage people to go further. We would certainly be encouraging firms to go further than their firm legal obligations under the Online Safety Act. I would say to everybody, “Please, we are all trying to drive better safety outcomes here. If you have committed in one jurisdiction, we would be very keen for you to commit in this one as well”.

Q49            Lord Knight of Weymouth: This is my final question—honest. To me, it looks like taking legal action on the basis of harm caused to individuals puts the platforms in a much more difficult position than taking them to court on the basis of compliance with a regulatory regime that Parliament has established. This takes us back to where we were with Viscount Colville: whether we would be better getting rid of the codes and the legal certainty, which I understand, and going after recklessness, in respect of harm to individuals, and pursuing platforms on the basis of their recklessness in the way that we do in the real world in health and safety, employment rights and some of those other areas where the duty of care applies.

Oliver Griffiths: My quick response to that—I hope that this has been a theme throughout—is that we all really want to see change happen really quickly. I still feel that we will look back on this as having been the very early days of the regime. There are real dangers of throwing babies out with bathwater at this particular point. There are a number of targeted interventions that could be made to improve it. The Government have ideas that are going to augment the Online Safety Act as it stands. We also do not have the same culture of civic litigation and class action in the UK. I cannot see it quite having the same impact. The fundamental idea of putting the duty on the company and making sure that there is enough incentive for it to live up to that is a good principle. We will do all we can to prosecute it. As I continue to say, we are still quite early in this.

Q50            Lord Tarassenko: I get the very nice job of asking the final question. Before that, thank you for answering comprehensively for more than an hour. This is both an easy and a hard question. I am aware—it would be good to leave this to one side, perhaps—that you are having discussions with the Government about AI, chatbots, how to bring AI services into the scope of the Act and so on. Leaving that aside, I will ask you this question individually; you are not allowed to give the same answer as one of the other two, so we should get three answers. What single change to the Online Safety Act would make the greatest difference to your ability to deliver an effective online safety regime?

Mark Bunting: I would look at how we could more effectively bring that sense of pressure and commitment on companies to address all the risks that they have identified, linked to the duty of care concept. That would need very careful thinking, and I would not separate it from the regulatory regime. Empowering us to have that engagement, particularly with the big firms, so that there is really comprehensive engagement on the totality of their risk assessment and risk management processes, is the area that I would be interested in exploring.

Q51            Lord Tarassenko: Very quickly, before I go to the other two, presumably you have looked at the Australian digital duty of care legislation. Is that something that would help fulfil what you have just been discussing?

Mark Bunting: We would need to think quite carefully about how we could put that alongside the framework that already exists in the Act. I do not think that this is a quick fix. It would need careful thought by better lawyers than me in terms of how you would structure that. That is one model that we would want to look at.

Suzanne Cater: I would go back to the business disruption measures, which are a very big focus in my world. They are the strongest enforcement tool that we have. As we have already discussed today, we have found some real, practical challenges in deploying that in anger, which has been as frustrating for me as it has been for the general public. I will not rehearse the specific changes—we can come back to you if you want any more detail on them—but some amendments to make it work in a more practical way would make a big difference to us.

The Chair: We would very much like you to write back to us; that would be helpful.

Lord Tarassenko: We have been discussing this area, so anything you can let us have in writing would be helpful.

Oliver Griffiths: Under the rules, I am not allowed to use Suzanne’s example. I would make the point that this is quite narrow and specific, in terms of change. Mark’s one involves a lot of debate; it would be extremely helpful to have the committee’s support on that narrow area. I would go for proactive technology and making it easier for us to force companies, quite a long way down the chain, to use proactive tech so that they have more control over the content that is being served up to users.

The Chair: We have run over time, I am sorry to say, but I thank you very much for sticking with us. We have had some very useful discussions and got through quite a lot in our time today. Thank you very much for joining us.