Ofcom says it made online safety rules "as easy as possible" for small firms to follow. Its own survey found one porn site shut its UK operation down rather than work out how.
Estimated reading time: 7 minutes
In short. Ofcom commissioned STRAT7 Jigsaw to survey 125 regulated services, plus 10 qualitative interviews, on how they experience the Online Safety Act. Its own foreword says Ofcom has "worked to make online safety regulation as easy as possible to understand and achieve for all service providers, and have provided a number of tools and resources to promote compliance, particularly aimed at small firms" (page 3). The survey it commissioned to test that says otherwise: 46% agreed "the requirements were difficult to understand" and 58% agreed the Act was "expensive to implement" (page 8), with the qualitative arm finding guidance "viewed as unclear, overly burdensome, or excessively long and technical" (page 9). One porn site "temporarily shut down the UK site" rather than build age assurance in time; another "transfer[red] their user forum to Facebook" because it could not afford the moderation costs (page 9). Three documented mistakes: four stars.
The Online Safety Act "covers a very wide range of services, with more than 100,000 sites and apps in its scope, ranging from micro businesses to some of the biggest tech companies in the world," Ofcom's own foreword says [1]. To find out how that universe of services actually experiences the Act, Ofcom commissioned STRAT7 Jigsaw to run 125 quantitative interviews and 10 qualitative interviews with employees responsible for online safety at micro, small, medium and large services, fieldwork completed 2 February to 3 April 2026 (page 5) [1]. The research summary was published 2 September 2026, updated 3 September [2].
The claim the survey was supposed to support
Ofcom's foreword frames the research as evidence of work already done: "we have also worked to make online safety regulation as easy as possible to understand and achieve for all service providers, and have provided a number of tools and resources to promote compliance, particularly aimed at small firms" (page 3) [1]. The results section, four pages later, does not read like confirmation. Just over half of respondents, 58%, agreed the Act was "expensive to implement," and nearly half, 46%, agreed "the requirements were difficult to understand" (page 8) [1]. The qualitative interviews went further than a percentage can: "the qualitative interviews revealed several concerns, particularly around guidance that was viewed as unclear, overly burdensome, or excessively long and technical," with "ambiguity in the Act's scope, noting that it seemed primarily designed for social media platforms and did not always align neatly with their own operations" (page 9) [1]. Scepticism was not evenly spread: it was "largely driven by those providing 'pornography or reported risk' services, those headquartered in North America, and micro businesses" (page 8) [1], which is to say the smallest operators and the services Ofcom most needs to reach.
What "difficult to understand" looked like from inside a small firm
The report does not stop at attitudes. Its qualitative arm records what businesses actually did in response: "one service was paused, as the service stated they couldn't easily implement age assurance at that time for technical and resource reasons. This was a porn site with an international customer base, so they temporarily shut down the UK site while they prepared necessary changes to it. Another had to transfer their user forum to Facebook, as they felt they couldn't afford or resource the additional moderation requirements" (page 9) [1]. Neither of those outcomes is a service becoming safer under the Act. One withdrew its UK service; the other handed its users' moderation to a platform it does not control.
The cost figures behind those decisions are concrete, not estimated. "Around one in three claiming high or very high costs," Ofcom's own survey found, where "very high" is defined, in Ofcom's own words, as a cost that "threatened the long-term viability of the organisation" (page 11) [1]. The qualitative interviews put numbers on it: "one business noted that they needed to increase their use of third-party platforms, which led to an integration cost of $30-50k and ongoing costs of $5-10k per month, another mentioned that they had to pay for external legal advice" (page 11) [1]. And the survey's own data show where that cost lands hardest: "costs were highest for services that indicated their users had been exposed to illegal or harmful content or pornography services" (page 11) [1]. That is precisely the group the Act exists to bring into line. The evidence Ofcom collected shows that group is the one most likely to retreat rather than comply.
The guidance that created its own ambiguity
The confusion the qualitative interviews describe is not free-floating. Ofcom's own footnote explains why services find the rules "open to interpretation": "there is no requirement in the Act to set a minimum age limit or use highly effective age assurance to enforce any minimum age limit services choose to set" (page 10) [1]. A service can set a minimum age voluntarily, and nothing in the Act obliges it to enforce that self-set limit with a method Ofcom rates as effective. The survey's own numbers show what services actually did with that latitude: 79% set a minimum age requirement and 83% said they check users' ages in some form, but only 41% used a method "capable of being highly effective, such as photo ID with a selfie, facial age estimation, or credit card checks" (page 10) [1]. Most of the gap between "checks age" and "checks age well" is not a business ignoring the rules. It is a business following an Act that, by Ofcom's own footnote, does not require better than that for a voluntary limit, while Ofcom's guidance recommends exactly the methods the Act does not mandate.
The claims, tested
| Ofcom's own words | What the survey's own evidence shows | Verdict |
|---|---|---|
| Ofcom has "worked to make online safety regulation as easy as possible to understand and achieve for all service providers... particularly aimed at small firms" (page 3) [1] | 46% found the requirements "difficult to understand," 58% found the Act "expensive to implement," and the qualitative arm found guidance "unclear, overly burdensome, or excessively long and technical" (pages 8-9) [1] | The businesses Ofcom says it built this for do not experience it that way |
| "Very high" cost is defined as a cost that "threatened the long-term viability of the organisation" (page 11) [1] | One in three services reported high or very high costs, concentrated among services whose users had met illegal or harmful content (page 11) [1] | The highest cost lands on exactly the services Ofcom most needs to comply, not evenly across the sector |
| There is no requirement to use a highly effective method "to enforce any minimum age limit services choose to set" (page 10) [1] | 79% set a minimum age, 83% check it in some form, but only 41% use a method Ofcom rates as highly effective (page 10) [1] | The gap is the Act's own optional design, not services ignoring it |
The mistakes, counted
The "easy as possible" claim does not survive the survey Ofcom itself commissioned to test it (1). Ofcom's foreword, on page 3, says it has made compliance easy to understand and achieve, particularly for small firms. Its own results, on pages 8 and 9, show 46% found the requirements difficult to understand, 58% found the Act expensive to implement, and the qualitative interviews describe guidance that is unclear, overly burdensome and excessively long and technical.
The highest costs fall on exactly the services the Act most needs to reach, and the evidence shows some of them exiting rather than complying (2). Page 11's own data show costs concentrated among services whose users had already met illegal or harmful content or which host pornography. Page 9's qualitative interviews record the result in one case: a porn site with an international customer base temporarily shut down its UK operation rather than build age assurance in time, and another dropped its user forum onto Facebook rather than pay for moderation.
Ofcom's own footnote explains the ambiguity its survey then found (3). Page 10 discloses that the Act does not require a highly effective method to enforce a voluntarily-set minimum age. The same page's data show the predictable result: most services that set an age limit check it somehow, but fewer than half use a method Ofcom's own guidance rates as effective. That gap is the Act's design, described honestly in a footnote, not evidence of non-compliance.
Credit where due
This survey does not oversell what it found. Ofcom discloses, on page 3 and again on page 7, that the sample was not weighted and should not be read as statistically representative of the wider population of regulated services, and states plainly that "it is not possible to know which specific measures the surveyed services should be deploying, and so levels of compliance with measures such as highly effective age assurance cannot be determined" (page 3) [1]. It flags its own self-selection risk: organisations "that perceive themselves" a certain way may be more or less likely to take part (page 7) [1]. And it reports the positive findings too: 87% had heard of the Act, three in five said they had fully or mostly implemented its requirements, and 61% agreed it would "help to keep children safer online" (page 8) [1]. A regulator that commissions research capable of undercutting its own foreword, and then publishes it anyway, is doing something most of the documents on this site do not.
Verdict
Four stars, from three documented mistakes. Ofcom asked the businesses it regulates whether compliance was easy, and to its credit, published what they said even where it contradicted its own foreword. What the answers show is not a rounding error: nearly half found the rules hard to understand, a third are absorbing costs Ofcom's own survey defines as threatening their survival, and at least one business, faced with that arithmetic, simply switched its UK service off.
Sources
- Online Safety Business Survey: Research Summary (PDF), Ofcom, published 2 September 2026
- Online Safety Business Survey, Ofcom, published 2 September 2026, updated 3 September 2026