Kids Say Online Safety Act Changed Nothing. They're Probably Right.
England's Children's Commissioner Dame Rachel de Souza has delivered a fairly damning verdict on the Online Safety Act: children across the country told her it has made absolutely no difference to their ability to find harmful content online. More than a year after the legislation's child protection provisions came into force, most young people don't even know the law exists, let alone feel any benefit from it.
De Souza made these comments at the opening session of the House of Lords Communications and Digital Committee's inquiry into how the OSA is actually working in practice. Spoiler: not especially well.
Her central criticism is that the legislation obsesses over content moderation while largely ignoring the way platforms are designed to keep users hooked. UK politicians made noise about tackling addictive features, either through the OSA or separate bills, but nothing concrete materialised. Meanwhile, US litigation managed to do what Westminster apparently couldn't.
Meta's proposed $18 billion settlement in an American child safety case would, without the company admitting any wrongdoing, introduce two-hour daily caps for under-18s on Facebook and Instagram, add friction to stop endless scrolling, restrict use during school hours and overnight, and let younger users opt out of algorithmically ranked feeds. That last point lands directly on concerns de Souza and others in the UK have been raising for years.
Her reaction to all this was blunt. The OSA, she said, had 'not been flexible enough' and had failed to keep pace. She wants Ofcom and lawmakers to extract comparable commitments from platforms operating here, whether the current legislation supports that or not.
On Ofcom itself, de Souza was pointedly unimpressed. She said she intends to use her statutory powers to compel the regulator to hand over the safety risk assessments that tech companies submitted under the OSA. Ofcom has refused to share them, citing section 393(1) of the Communications Act 2003, which limits what the regulator can disclose about information gathered through its regulatory work. Disclosure is possible if the company consents or a specific legal gateway applies, but neither appears to be happening here.
'I'm pretty furious about that,' de Souza said, which in civil servant language is roughly equivalent to flipping a table. She asked the committee for support in pressing the matter, arguing that if she can't see what risks the platforms actually identified, there's no way to assess whether any of the resulting safety measures are fit for purpose.
To be fair to Ofcom, it hasn't been entirely dormant. It waded into the Grok nudifying scandal, and it has opened a string of investigations into pornography platforms allegedly flouting age verification rules. De Souza acknowledged this, and also noted that the current US administration's hostility toward tech regulation has made it harder for UK politicians to give Ofcom the political cover it needs to go after big platforms aggressively.
Still, her overall view is that Ofcom reacts to harms rather than anticipating them, which is precisely the wrong posture when dealing with an industry that moves fast and breaks things by design.
'When I talk around the country to children, what's worrying them are things around AI, things around the nudifying apps,' she said. 'There are new harms, and we need Ofcom to be getting ahead of those. I don't think they are.'
She also had a go at Ofcom's child safety codes under the OSA, describing them as technical documents clearly written for the platforms rather than protections designed with children in mind. Her ask: use all available powers, issue some significant fines, and stop waiting for harms to become normalised before acting.
Ofcom's response was predictably measured. A spokesperson pointed to the risk assessment analysis published in December, said the regulator's actions had produced 'material improvements,' and noted the legal restrictions on what it can publicly disclose about company information. Which is all fine as far as it goes, but doesn't really address whether any of it has made children safer online.
If the kids themselves are saying nothing has changed, that's probably the most honest assessment available.