1. Executive summary
The Children's Commissioner for England, Dame Rachel de Souza, told the House of Lords Communications and Digital Committee that the UK's Online Safety Act (OSA) has made "absolutely no difference" to children's ability to access harmful content, more than a year after the Act's key child protection duties took effect. She criticised the legislation's focus on content moderation over platform design features, said Ofcom has been reactive rather than anticipatory on emerging harms (specifically AI and "nudifying" applications), and announced she will use statutory powers to compel Ofcom to disclose platforms' safety risk assessments — which Ofcom has indicated it will resist, citing section 393(1) of the Communications Act 2003. No CVEs, named threat actors, or exploitation activity are involved; this is a policy and regulatory-effectiveness item. Direct operational risk to EMEA financial services is low, but it signals a UK regulatory environment trending toward more aggressive information-compulsion powers and heavier expectations on platform design controls — relevant context for firms operating consumer-facing digital channels.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The Online Safety Act sits outside the DORA/NIS2/UK NIS 2018 reference scopes supplied for this advisory; the item concerns child-safety regulation of consumer platforms, not ICT incident management, incident classification/reporting, resilience testing, or ICT third-party risk for financial entities. UK NIS 2018 OES/RDSP duties are not implicated by any fact in this item.
3. Technical analysis & attack chain
This is a policy/regulatory item; there is no attack chain, vulnerability, or threat actor to analyse. The mechanics of the dispute, from the source facts only:
- The core allegation. De Souza told the Lords Communications and Digital Committee inquiry into the OSA's implementation that children report the Act has made "absolutely no difference" to their access to harmful content, and that young people have little understanding of the legislation or how it was meant to change their online experience.
- Design vs. content. Her central criticism is that the OSA targets moderation of harmful content rather than potentially harmful platform design features (addictive design, algorithmic ranking). UK politicians had pushed for controls on such features through the OSA or separate legislation; none has materialised.
- The evidence gap. She stated there is no hard evidence the OSA has meaningfully changed how social media platforms operate, and contrasted this with the US, where legal pressure produced Meta's proposed $18 billion settlement in a child safety case — under which Meta, without admitting wrongdoing, would introduce two-hour daily limits for under-18s on Facebook and Instagram, anti-scrolling prompts, school-hours and night-time use measures, and an opt-out from algorithmically ranked feeds.
- The disclosure standoff. De Souza plans to exercise statutory powers to compel Ofcom to provide copies of the safety risk assessments submitted by technology companies. Ofcom has refused to share them and indicated it would resist disclosure even if compelled. The stated obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions; disclosure is possible with the business's consent or via statutory gateways under section 393(2). Ofcom's public response confirms it is "subject to laws that mean we're restricted in what information we can disclose relating to businesses," and notes it published its own analysis of first-year risk assessments in December.
- Regulatory posture. De Souza acknowledged Ofcom's interventions over the past year — including action during the Grok "nudifying" controversy and investigations into pornography companies over age verification requirements — but accused it of reacting to harms rather than anticipating them, particularly on AI and nudifying apps, and called for "big fines" and stronger political empowerment of the regulator. She also criticised Ofcom's child safety codes as reading like technical documents for technology companies rather than protections designed for children.
Confidence caveat: This account is single-sourced (The Register's reporting on the Committee evidence session). The Children's Commissioner's characterisations of Ofcom's effectiveness and of the OSA's impact are her testimony, not independently corroborated findings within this material; Ofcom disputes the framing in its quoted statement.
4. Mitigation & containment
No technical containment applies. Process-level actions for clients, prioritised by relevance:
- P1 (within 24h): No action required. This item does not affect any client system, service, or supply chain.
- P2 (within 72h): UK-headquartered or UK-operating firms with consumer-facing digital channels (banking apps, trading platforms, embedded finance, fintech onboarding flows) should brief legal/compliance on the trajectory evidenced here: a senior UK statutory officeholder moving to compel regulator-held corporate risk assessments, and explicit political pressure for regulators to "use their teeth" and impose "big fines." Assess whether any algorithmic or engagement-driving design features in your own customer-facing products (personalised feeds, gamified savings/investment features, push-notification cadence targeting younger users) could attract equivalent design-based scrutiny under other regimes.
- P3 (within 7 days): For firms with social-media or platform dependencies (marketing channels, customer-support presence on Meta properties), note the proposed Meta settlement terms — under-18 daily time limits, algorithmic-feed opt-out, school-hours/night-time restrictions — as they may alter the reach and timing of social-channel customer engagement if implemented.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- The Register, "UK's Online Safety Act has made 'absolutely no difference,' kids say," https://www.theregister.com/security/2026/09/03/uks-online-safety-act-has-made-absolutely-no-difference-kids-say/5293893, 2026-09-03
8. Adverse Trace position
Low severity, low direct client impact: this is a UK policy and regulatory-governance item with no vulnerability, actor, or exploitation component, and no DORA/NIS2/UK NIS obligation is triggered by its facts. Its value to EMEA financial services clients is directional — it evidences (a) a UK regulatory culture shifting toward compelled disclosure of corporate risk assessments and anticipatory rather than reactive supervision, and (b) growing cross-regime pressure on platform design rather than content, which will shape expectations on any client operating engagement-driven consumer products. The Commissioner's effectiveness claims are single-sourced testimony and contested by Ofcom; treat them as political assessment, not verified outcome. We will monitor the House of Lords Committee inquiry, any section 393 disclosure litigation between the Commissioner and Ofcom, and the finalisation of the proposed Meta settlement for implications relevant to client consumer channels.
Published via PulseTrace — Adverse Trace threat intelligence.