TEARDOWN Published 25 September 2026 at 09:09. Evidence-based. Source-cited. No sponsored content.

Ofcom's own guidance says a chatbot that only talks to you, one on one, is not covered by the Online Safety Act at all. Parliament gave ministers the power to close that gap five months ago and it still has not been used.

4 out of 5 stars4/53 documented mistakes in this teardownHow ratings work

Estimated reading time: 7 minutes

The Palace of Westminster, home of the Houses of Parliament, London.
The Palace of Westminster, Houses of Parliament, London, 6 April 2010. Photo: Hartmut Schmidt Heidelberg / Wikimedia Commons, CC BY-SA 4.0.

In short. Ofcom's own explainer on AI chatbots, still live and unrevised since it was published on 18 December 2025, sets out three conditions that together put a chatbot beyond the Online Safety Act's reach: it only talks to the one user, it does not search the web, and it cannot produce pornography [1]. That is the exact shape of the case Ofcom's own 2024 open letter cited as a reason to write to the industry in the first place: "the tragic death of an American teenager who had developed a relationship with a chatbot" [2]. Parliament has since given ministers a way to close the gap. The Crime and Policing Act 2026 inserted a new power into the Online Safety Act on the day it received Royal Assent, 29 April 2026, letting the Secretary of State make regulations to cover exactly this kind of harm [3]. Almost five months on, no regulations have been made, the only legal deadline attached to the power is a duty to report "progress," not deliver a fix, and the government's own newest guidance to families, updated last week, still gives no date for closing the gap at all [4] [5]. Three documented mistakes: four stars.

Ofcom's job under the Online Safety Act is to make online services protect the people who use them, and its enforcement toolkit includes fines for platforms that fail their duties [1]. Its guide to AI chatbots, published in December 2025 to explain how that regime applies to the technology, opens by naming the harm plainly: reports of chatbots that "imitate real people, including people who have died," and reports "of cases where chatbots have encouraged people to harm themselves or even take their own life" [1]. Then it explains where the law actually reaches.

Three conditions, one carve-out

The Act, Ofcom's guide says, covers three kinds of AI chatbot service: a "user-to-user service" where people can share what the chatbot produces with other users; a "search service" that draws on more than one website or database; and any service, chatbot or otherwise, that can generate pornographic material [1]. Then, in its own words: "Some chatbots or the content they produce are not covered by the Online Safety Act. For example, chatbots are not subject to regulation if they: Only allow people to interact with the chatbot itself and no other users; Do not search multiple websites or databases when giving responses to users; and Cannot generate pornographic content" [1]. A companion-style chatbot, the kind a person talks to privately and nobody else sees, meets all three conditions for being outside the Act. Ofcom's guide adds that "any changes to these powers would be a matter for government and Parliament," and that Ofcom is "supporting the UK Government as it considers possible changes" [1].

That framing traces back to an open letter Ofcom sent the industry over a year earlier, on 8 November 2024, which the December 2025 guide links to as "a more detailed explanation" [1]. That letter opens: "we have seen multiple incidents of online harm that have involved the use of Generative AI... These include the tragic death of an American teenager who had developed a relationship with a chatbot based on a Game of Thrones character" [2]. The letter's own account of what the Act covers is the same three categories: chatbots shared with other users, including "group chat" functionality and chatbots submitted to a public library for others to use; search tools drawing on multiple sources; and pornographic content generators [2]. A private, one-to-one relationship with a single chatbot persona, the case the letter itself cites, is not a user-to-user service, is not a search service, and does not generate pornography. By the regulator's own definitions, in the regulator's own founding document on the subject, that is the exact case the Act does not reach.

The claims, tested

The claim What we found Verdict
Ofcom's guide, live and unrevised since 18 December 2025: a solo, non-searching, non-pornographic chatbot is "not subject to regulation" [1] The same page's cited open letter uses a private chatbot relationship as its lead example of the harm the Act is meant to address [2] The founding example and the current carve-out describe the same kind of chatbot
"Any changes to these powers would be a matter for government and Parliament" [1] Parliament acted: the Crime and Policing Act 2026 inserted section 216A into the Online Safety Act, letting the Secretary of State make regulations "for or in connection with the purposes of minimising or mitigating the risks of harm... presented by... illegal AI-generated content" and "the use of AI services for the commission or facilitation of priority offences," in force at Royal Assent, 29 April 2026 [3] The power Ofcom's page describes as hypothetical has existed, usable, for almost five months
The Act now gives ministers a route to close the gap The only deadline attached to it is a duty to report "progress... towards making regulations," due "no later than 31 December 2026," waived only if draft regulations are laid first [4] No regulations have to exist by any date, only an update on how the work is going
The government's newest public guidance on child online safety, updated 18 September 2026, sets out a fixed timetable for protecting children online [5] For the under-16 social media ban, the same document is precise: "the first set of Regulations will be laid before the end of the year, and the changes should be implemented in Spring 2027." For AI chatbots, the same document offers "regular breaks," still being designed "with experts," and says the government "will consider" banning the worst offenders, with no date for either [5] One flagship child-safety measure has a date. The one this site can trace to a teenager's death does not

The mistakes, counted

The chatbot Ofcom names as the harm is the chatbot its own rules do not reach (1). Ofcom's December 2025 guide sets three tests for a chatbot falling inside the Online Safety Act, and a private, one-to-one companion chatbot fails all three: nobody else sees the conversation, it does not search the web, and it does not generate pornography [1]. The open letter that same page cites as its own explanation named a case matching that description as a reason for writing to industry at all [2]. Neither document has been updated to explain how the harm and the carve-out fit together, or whether they were ever meant to.

A working power has sat unused for five months (2). Section 216A of the Online Safety Act, inserted by the Crime and Policing Act 2026, is not a provision awaiting commencement. It came into force the day the Act received Royal Assent, 29 April 2026, alongside the reporting duty in section 249 [3] [4]. Unlike other parts of the same Act, including three new priority offences this site found still waiting for a commencement order in September, ministers do not need to wait for a statutory instrument to start using this one. No regulations under section 216A have been made or laid before Parliament in the time since.

No date exists for closing the gap, only a date for reporting on it (3). Section 249 requires a progress report by 31 December 2026, "unless a draft of a statutory instrument containing regulations" is laid first [4]. That is a duty to say how the work is going, not a duty to finish it. The government's own fact sheet on child online safety, revised as recently as last week, mirrors that gap: a firm timetable for the under-16 social media ban, and for AI chatbots specifically, only breaks "still being worked out" and a ban that remains something officials "will consider" [5].

Credit where due

Ofcom's December 2025 guide is candid about its own limits. It does not claim the Act covers more than it does, and it says plainly that closing the gap is a matter for government and Parliament, not the regulator [1]. Parliament has, in fact, moved: section 216A is a genuinely broad power, covering illegal AI-generated content and the use of AI services to commit or facilitate priority offences, and it commenced without delay, unlike several other Crime and Policing Act provisions this site has already found still waiting for a start date [3]. The problem documented here is not that nobody has acted. It is that the two things that have happened, a candid admission of a gap and a broad power to close it, have not yet been joined up by a third: a regulation that actually does it.

Verdict

Four stars, from three documented mistakes. Ofcom told the industry in 2024 that a teenager's death, in a private relationship with a chatbot, helped prompt its letter. It told the public in December 2025 that a chatbot exactly like that one sits outside the Online Safety Act's reach. Parliament gave ministers the power to fix that in April 2026, on the day the law was signed. Nobody has used it, the only deadline in force is for a report rather than a remedy, and the government's own newest guidance to families, updated last week, still cannot say when that changes.

Sources

  1. AI chatbots and online regulation - what you need to know, Ofcom, published 18 December 2025, checked 25 September 2026.
  2. Open letter to UK online service providers regarding Generative AI and chatbots, Ofcom, published 8 November 2024.
  3. Crime and Policing Act 2026, section 248, legislation.gov.uk.
  4. Crime and Policing Act 2026, section 249, legislation.gov.uk.
  5. Fact sheet: New rules to protect children online, GOV.UK, updated 18 September 2026.
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail