Social media, misinformation and harmful algorithms: Government response

This is a House of Commons committee special report, including a government response to an earlier committee report.

Third Special Report of Session 2024–26

Author: Science, Innovation and Technology Committee

Related inquiry: Social media, misinformation and harmful algorithms

Date Published: Friday 17 October 2025

Download and Share

Contents

Third Special Report

The Science, Innovation and Technology Committee published its Second Report of Session 2024–25, Social media, misinformation and harmful algorithms (HC 442), on 11 July 2025. The Government and the Ofcom responses were received on 18 September 2025, and both are appended below.

Appendix 1: Government response

Introduction

The government is grateful to the House of Commons Science, Innovation and Technology Select Committee for their report on “Social Media, Misinformation and Harmful Algorithms”. The report examines the challenges posed by social media algorithms in amplifying harmful and misleading content, and highlights the importance of upholding public safety, free expression, platform accountability, user control, and transparency in shaping the UK’s approach to online safety.

We take seriously the Committee’s recommendations and acknowledge the challenges posed by misinformation on social media platforms, especially when amplified through platform business models and design.

Accordingly, this response outlines a variety of legislative and non-legislative measures implemented across government to address the factors contributing to the spread of misinformation and disinformation. These initiatives include the regulatory provisions introduced by the Online Safety Act 2023, as well as ongoing efforts to enhance media literacy. Multiple approaches have been, and continue to be implemented to address the issues related to misinformation and disinformation, while also maintaining the utmost consideration towards freedom of speech.

This document presents the government’s reply to the Committee’s report, which identifies several issues requiring consideration. The structure of this paper aligns with the Committee’s recommendations and outlines the government’s responses to the points raised. The responses to the Committee’s recommendations are as follows:

Misleading and harmful content on social media

Recommendation of the Committee: We welcome Ofcom’s consultation on a ‘crisis response protocol’ for companies to follow in response to events such as the 2024 unrest. The protocol should directly address misinformation by including all online services at risk of contributing to the spread of false or harmful information, including large online social media, search and messaging services; those with smaller user numbers but high-risk profiles; and others, such as generative AI platforms. In establishing the mechanism, Ofcom should acknowledge the different ways in which different services operate. Following our Principle 2, it should hold platforms responsible for: decelerating the spread of harmful misinformation without censoring lawful speech; ensuring substantial and continuous engagement with law enforcement and government bodies; giving users control over the content they see; and providing transparency around their actions.

The government believes that Ofcom is best placed to consider this recommendation. As the independent regulator, Ofcom has the discretion to determine which measures are included in its consultation process. However, the government acknowledges that any measures proposed in the codes must be designed for the purpose of compliance with the relevant duties. Consequently, these measures must align with those duties, including where they pertain to the definitions of regulated providers and content.

The OSA takes a proportionate and risk-based approach to online harms, primarily addressing content that is illegal or harmful to children. Its framework establishes foundational safeguards to protect users on in-scope services from illegal material online and implements measures to prevent children from accessing harmful age-inappropriate content.

We agree with the Committee that, following the public disorder in summer 2024, it is appropriate that providers are given clear guidance on how to respond to crises that may lead to the rapid spread of illegal content online. In June 2025, Ofcom launched consultations on new measures to inform future iterations of its codes of practice. These include proposals for a crisis response protocol, which would outline additional actions for providers during periods of heightened risk such as real-time monitoring, direct engagement with law enforcement, and post-crisis reviews.

These measures are intended to apply not only to large providers assessed as medium risk, but also to any provider of any size identified as high risk for terrorism, threats, abuse, harassment, or foreign interference. Ofcom’s approach will reflect the operational differences between providers, in line with the principle of proportionality embedded in the Act.

As implementation of the OSA progresses, evaluating the effectiveness of its provisions remains a key priority for the government. This includes ensuring that actions which are illegal offline are addressed adequately online, while safeguarding freedom of expression. As set out in the government’s manifesto, we will continue to assess whether further steps are needed to strengthen the framework in future.

Misleading and harmful content—beyond the 2024 unrest

Recommendation of the Committee: There is a shortfall in data needed to accurately analyse the scale of the problem and identify policy solutions. In line with our Principle 4, the government should commission a large-scale research project into how far social media recommendation systems spread, amplify, or prioritise harmful content. This should be undertaken by a group of credible independent researchers, bringing diverse perspectives, with full access to the inner functions of the systems that major platforms use to algorithmically recommend content, including the private, external, and third party data used to train their systems; the user, content and engagement attributes the algorithms rely on and how these are weighted, and the objectives the algorithms are optimised for; where user interactions reinforce future recommendations; and any curation rules or interventions that influence promotion or suppression of content. We expect full cooperation from all major services that employ recommendation algorithms.

The government believes that the quickest way to fill the shortfall in data is through Ofcom. Ofcom’s role as the UK’s independent online safety regulator means it is best placed to exercise judgement about whether research into the operation of providers’ content recommender systems should be undertaken.

This research can then inform decisions about whether relevant providers should implement particular safety measures, to reduce the risk that content recommender systems lead to users being served content that the government has specified as being illegal content, or harmful to children. To note, Ofcom has already set out in its OSA codes of practice that online platforms should take or use certain measures to reduce the risk that their recommender systems lead to users encountering illegal content via their service, and to also reduce the risk that children encounter content that is harmful to them. Furthermore, it is consulting on additional measures on these matters for the codes.

Supplementary to its powers for getting platforms to implement safety measures in relation to content recommender systems, Ofcom’s information-gathering powers under the OSA mean that it is uniquely well-positioned to investigate providers’ internal workings and systems and processes, including their content recommender systems.

The OSA confers powers on Ofcom to enable it to access the information it needs in order to exercise any of its online safety functions or carry out research into online safety matters. Under these powers, Ofcom can require information from relevant third parties, as well as providers themselves. It can remotely view information about the operation of systems and processes, including tests of algorithmic systems. It can interview employees, require a company to assist a skilled person in preparing a report (and pay for the report to be produced), and carry out audits on services to assess compliance and risks. All of these information-gathering powers can apply to information about providers’ algorithms.

Beyond this, a framework will be designed to support independent research into online safety matters. Currently, access to online harms data is only directly available to independent researchers at the discretion of tech companies and researchers have cited technical and procedural barriers which prevent high-quality research. Provisions in the Data (Use and Access) Act empowers the Secretary of State to create a framework for independent researchers to access online safety data, giving researchers a legislative footing to conduct their online safety research. Improved access to online safety data will enable more comprehensive research into online safety risks, as well as the effectiveness of providers’ processes to mitigate risks to users as part of meeting their OSA duties. This will inform future online safety interventions, such as updates to Ofcom’s codes of practice, and contribute to a safer online experience for UK users.

Recommendation of the Committee: Based on the research described above (in recommendation 2), the government should publish conclusions on the level and nature of harm that these platforms promote through their recommendation systems. Following our Principle 3, if significant harm is found, the responsible online services should publish the actions they will take to address these harms. Ofcom should be given the power to serve penalty notices to services that fail to comply, either 10% of the company’s worldwide revenue, or £18 million, whichever is higher.

The government believes that, together with the above recommendation, Ofcom is best placed to consider this recommendation as online safety regulator.

Under the OSA, regulated providers have enforceable duties to carry out risk assessments, with Ofcom able to verify and substitute findings as appropriate. This includes an assessment of the risk of relevant users encountering illegal or harmful-to-children content by means of the algorithms used by the service. Providers also have duties to take proportionate steps to reduce the risks that users encounter illegal content, or that children encounter content that is harmful to them. The OSA sets out that providers are required to take proportionate steps relating to their design and operation of their services to reduce these risks. This includes steps that relate to their content recommender systems.

Ofcom publishes the steps that providers can take to fulfil their duties.

As set out in the recommendation above, Ofcom has extensive powers to research matters relating to online safety. It has extensive powers to gain access to information from providers on these matters, including about algorithms. Therefore, Ofcom is well-placed to carry out research into providers’ content recommender systems, in relation to the risk that these systems may push illegal content or content that is harmful to children.

In addition, Ofcom is best placed to set out steps that different kinds of providers should take, where evidence suggests that their content recommender systems may increase the levels of risk that users will encounter illegal content or that children will encounter content that is harmful to them.

Ofcom issued its codes of practice for the OSA illegal content duties and child protection duties in March and July this year, respectively. The duties are now in effect. Ofcom’s codes already set out measures providers can take in relation to their recommender systems.

Ofcom’s illegal harms codes include measures on pre-testing recommender systems for illegal and harmful content. The protection of children codes include measures to mitigate the risk of recommending harmful content to children and to give children more control over the content they are recommended.

Ofcom has committed to developing these codes iteratively. In June this year, Ofcom published proposals for additional measures for the OSA codes. It is consulting on these proposals currently. These include additional measures that where there are indicators that a piece of content might be illegal or harmful to children, service providers should exclude it from relevant recommender systems unless and until it has been reviewed.

Where providers fail to comply with their duties (including where these apply to their recommender systems), Ofcom can and is empowered to undertake enforcement actions, including imposing fines on companies of up to £18 million or 10% of their qualifying worldwide revenue.

Recommendation of the Committee: Following our Principles 2 and 3, the government should compel social media platforms to embed tools within their systems that identify and algorithmically deprioritise fact-checked misleading content, or content that cites unreliable sources, where it has the potential to cause significant harm. It is vital that these measures do not censor legal free expression, but apply justified and proportionate restrictions to the spread of information to protect national security, public safety or health, or prevent disorder or crime.

The government is committed to a safer online world and we urge providers to counter the spread of mis- and disinformation on their services. The government recognises that online misinformation has the potential to cause real-world impacts and undermine public trust in the information environment. However, tackling this issue is extremely complicated. We need to be honest that you cannot eliminate all harmful content online and a balance must be found with freedom of expression – a critical fundamental right. We recognise that mis- and disinformation is a broad, and cross-cutting issue, and we therefore think the most appropriate response is to directly address the most prevalent and concerning harms associated with it.

The OSA takes a proportionate approach by focusing on the worst kinds of mis- and disinformation – that which is illegal or harmful to children. This means companies are required to tackle illegal disinformation content on their services and protect children from certain harmful mis- and disinformation. The OSA will also hold Category 1 services to account over the enforcement of their terms of service, including terms related to mis- and disinformation.

The OSA requires services to undertake risk assessments for illegal content, which includes illegal mis- and disinformation. These risk assessments include assessing the risks posed by algorithms. Services then need to take effective steps to mitigate identified risks. For example, Ofcom’s codes of practice include measures for certain providers which run tests on their algorithms, according to which they must produce and analyse safety metrics about the risks of serving illegal content.

It is also important to note that improved media literacy builds resilience to misinformation, fosters critical thinking and promotes respectful online behaviour. The OSA updated Ofcom’s media literacy duties: requiring Ofcom to raise awareness of the nature and impact of mis- and disinformation, enhance public understanding of how to stay safe online and help the public understand the impact of harmful content and online behaviour. We welcomed Ofcom’s first three-year media literacy strategy, ‘A Positive Vision for Media Literacy’, published in October 2024. The strategy sees teacher training as key to improving media literacy and aims to support ongoing professional development to equip educators with the right knowledge and tools to foster media literacy in schools.

The government also notes that most of the major social media platforms already employ fact-checking mechanisms as part of their content moderation strategies within the UK. These systems typically involve partnerships with independent fact-checking organisations and the use of automated tools to identify potentially misleading content. Where content is found to be false, providers will often algorithmically deprioritise it—reducing its visibility in users’ feeds—to limit its spread. While these practices vary across services the government supports efforts that build on these existing approaches, provided they are proportionate, transparent, and designed with regard for the importance of users’ right to lawful free expression

Recommendation of the Committee: As per Principle 4, users should have more control over the content that is pushed to them online. Government should mandate all online services with a content recommendation algorithm to give the user a ‘right to reset’, which would delete all data stored by their recommendation algorithm, in the manner that users can clear their cookie history. This option should be displayed prominently on the platform’s main feed or homepage.

The government is committed to ensuring that individuals have a say over the content they are presented by recommendation algorithms and in how their personal data is processed. While no single piece of UK legislation provides a specific ‘right to reset’ as recommended by the Committee and we would not want to be overly prescriptive in how organisations engage with their end users, the government believes that there are existing powers and protections that collectively deliver a proportionate approach to the Committee’s objective.

Whilst the OSA does not seek to restrict adult users’ access to legal content, it will require regulated services to have clear and accessible Terms of Service (ToS). Where the ToS of Category 1 services, set out what kinds of legal content for adults they don’t accept on their platforms, they are required to apply these terms consistently and transparently so that adult users can have greater assurance of the kind of experience they will have on a service.

Category 1 services are also required to offer adult users, at the earliest possible opportunity, optional and proportionate “easy to access” features. These features, if applied, will limit their engagement with certain types of legal content, including that which encourages suicide, self-harm or eating disorders, and material that is abusive or incites hate based on certain protected characteristics. These services must include clear and accessible provisions in their terms of service specifying which control features are offered and how adult users may take advantage of them. These duties are designed to empower adult users to have more autonomy over their online experience, and we expect them to be in effect from early-mid 2027.

Ofcom is the independent regulator of the OSA and can take robust enforcement action against those failing to fulfil their duties, including issuing large fines and business disruption measures.

On top of these duties, the OSA will deliver greater platform accountability and trust through its transparency framework. Ofcom must require Category 1, 2A and 2B services to publish annual transparency reports. The contents of the reports is at Ofcom’s discretion but can include information about the platform’s algorithms. These reports will be made public, enabling users to make informed decisions and keep providers accountable. The OSA also provides Ofcom with a robust suite of information gathering powers which will help ensure it can access the information it needs to understand how companies are fulfilling their duties. Under these powers, Ofcom can require the provider to conduct an empirical test or demonstration, to observe how the algorithms function in practice. These powers should help Ofcom and members of the public to understand how platform algorithms work, enabling more informed decision making and protective actions.

In addition to the OSA, UK data protection legislation provides individuals with a range of specific rights in relation to their personal data. These rights enable individuals to have a degree of control over how their personal data is used and, in some cases, could help users control their recommendation algorithms and content promoted to them by online services.

For instance, the UK GDPR gives individuals the right to object to the processing of their personal data in certain circumstances. This right could be exercised by individuals, in some scenarios, to stop social media platforms from using their personal data to develop content recommendation algorithms. For example, an individual has the right to object to the processing of their personal data for direct marketing purposes, such as online advertising that is targeted to a particular user (e.g. based on browsing history, purchase history or login information).

Furthermore, an individual may also be able to exercise their ‘right to erasure’ (also known as the ‘right to be forgotten’) to have personal data erased by online services. If applicable, individuals could use this right to request that their personal data used in content recommendation, such as browser history or behavioural data, be deleted by an online service.

While the UK’s data protection framework does not provide individuals with a specific ‘right to reset’, these existing rights do give users meaningful control over how their personal data is used to personalise content. When taken together, the OSA and UK GDPR provide citizens with significant influence over how recommendation algorithms affect them.

Recommendation of the Committee: In line with our Principle 1 of tackling amplified misinformation, the government should compel platforms to put in place minimum standards for addressing the spread of misleading content online. More information is needed on the merits of different approaches to this. The government should commission research into the relative benefits of independent third-party fact- checkers, crowd-sourced context provision, and AI driven detection of misinformation, using researchers who are independent, bring diverse perspectives on the issue, and have full access to the data of these systems. The research should enable Ofcom to offer guidance on the most effective method, or combination of methods, to address misinformation.

The government shares the Committee’s concerns regarding the amplification of misleading content online and agrees that more evidence is needed to assess the merits of different approaches to tackling misinformation.

The government engages with social media companies to make clear their responsibility to keep users safe. We are closely monitoring changes to fact checking models and how they might impact UK users. We agree on the importance of research and evidence in this area and are currently looking at where we can build our evidence base on these issues.

On AI driven detection of misinformation, the government ran the Deepfake Detection Challenge last year, bringing together academic, industry and government experts to develop innovative and practical solutions focused on detecting synthetic media.

More widely, provisions inserted by the Data (Use and Access) Act empower DSIT’s Secretary of State to create a framework for independent researchers to access online safety data, which will – once implemented - give researchers a legislative footing to conduct their online safety research in the future.

The Online Safety Act and the spread of misleading and harmful content

Recommendation of the Committee: The broad scale—and serious impact—of misinformation online requires greater transparency and accountability from the government. In line with our Principle 1, the government should submit an annual report to Parliament on the state of misinformation online, tracking trends and issues from the year, and setting out successes and failures in addressing them.

The government agrees that routine scrutiny and accountability are important and continues to provide regular updates on this work through existing parliamentary channels, such as questions in the House and Ministerial appearances before relevant Select Committees. This serves to ensure routine scrutiny and proportionality of the government’s response to misinformation, including where it concerns the UK’s national security.

Given the government’s focus on UK national security, an annual report on the online information environment and impact of UK-led mitigations would risk exposing vulnerabilities and could hinder future operations.

Recommendation of the Committee: In line with Principle 5, transparency, the government should introduce duties for platforms to undertake risk assessments and reporting requirements on legal but harmful content, such as potentially harmful misinformation, with a focus on the role of recommendation algorithms in its spread.

The OSA’s duties will deliver greater transparency and accountability from providers, ensuring Ofcom is well informed, adult users are empowered, and companies are publicly held to account for keeping their users safe online. The strongest protections in the framework are for children, and services which are likely to be accessed by children are required to take measures to protect them from harmful content including that which doesn’t meet the criminal threshold.

Under the current framework, the OSA compels Ofcom, the independent regulator, to require categorised services to produce annual transparency reports on safety related issues and the experiences of their users. The contents of these reports are at Ofcom’s discretion, but may include information about the incidence and dissemination of illegal content, content that is harmful to children and content subject to the user empowerment duties. They may also include information about the systems and processes a provider operates to deal with certain types of content, including the provider’s algorithms.

Under the OSA, Ofcom also have information gathering powers which they can use to require providers to enable Ofcom to observe how their algorithms function - these powers should help keep providers accountable and enable adult users to make more informed decisions about what platforms they want to use.

The OSA focuses on empowering adult users to make more informed choices about the services they use and the content they engage with. The OSA requires Category 1 services to have clear and accessible Terms of Service (ToS). Where these set out kinds of legal content for adults they don’t accept on their platforms and or circumstances in which they may ban or suspend a user. Category 1 services are required to enforce these terms, applying them consistently and transparently so that adult users can have greater assurance of the kind of experience they will have on a service. This means if a company’s ToS say that harmful misinformation content is not permitted, they should have the systems and processes to remove such content when it is reported to them by users. Although Category 1 services are required to enforce these ToS, it is ultimately their decision what legal content they do or do not allow on their platforms, reflecting the sort of space they want to create for their users. This will enable greater transparency about content, enabling adult users to make more informed choices about the services they use.

The OSA’s user empowerment duties will also ensure that adult users have greater assurance of the kind of experience they will have on a service, by requiring providers to empower adult users of Category 1 services to choose whether or not to engage with legal content that encourages, promotes or provides instructions for suicide, self-harm and eating disorders, and content that is abusive, or incites hate, on the basis of race, religion, sex, sexual orientation, gender reassignment or disability.

Recommendation of the Committee: To ensure true responsibility from platform companies, as per Principle 3, Ofcom and DSIT should confirm that services are required to act on all risks identified in risk assessments, regardless of whether they are included in Ofcom’s Codes of Practice.

The Online Safety Act establishes duties on providers to carry out ‘suitable and sufficient’ risk assessments in primary legislation. The primary legislation establishes a wide range of risks that providers need to assess for, such as risks that users will encounter certain kinds of harmful content via the service. The Government can update these risks, through changes to the underlying kinds of content and offending that providers have duties for. However, providers are not generally obliged to identify risks beyond the matters that primary legislation stipulates. This is an important safeguard to give regulatory certainty to providers and protect against regulatory overreach and arbitrary enforcement.

Subsequent to their risk assessments, providers have wide-ranging duties to take proportionate steps to protect their users. These duties are proportionate to the findings of their risk assessments and the size and capacity of the provider among other matters. Ofcom sets out in codes of practice steps that different kinds of providers with different risk levels can take to fulfil their duties. Again this is an important safeguard for regulatory certainty. It gives providers direction about how far they need to go to mitigate identified risks, where a lack of such direction could affect users’ rights and Ofcom’s ability to enforce the duties effectively. Therefore the Act establishes that Ofcom needs to create robust and comprehensive codes of practice that ensure providers offer greater protection to UK users, while also giving these providers clarity.

Ofcom has now published its codes of practice for the illegal content duties and children’s duties under the OSA regime. These recommend that all providers – including small providers with low risk levels - should take steps to deal with illegal content and to protect children on their service. These steps are comprehensive and cross-cutting. For example, they set out that providers should put in systems for moderating content. The expectation will be that relevant providers implement these in such a way that they operate effectively and deliver protections for UK users from relevant risks, including where these manifest through different kinds of features or functionalities.

Ofcom has stated that it intends to develop its codes of practice iteratively. In line with this, on 30 June Ofcom published various proposals for new measures for the OSA codes, for public consultation. These include additional steps that relevant providers should take in relation to live-streaming, recommender systems, use of proactive scanning technology, and crisis response.

Recommendation of the Committee: The Online Safety Act does not do enough to address the risks posed by small platforms due to its exclusive focus on size. Ofcom should create an additional category to cover ‘small but risky’ platforms, based on analysis of the role that harmful smaller platforms can play in the online ecosystem, interacting with the recommendation algorithms of large platforms to spread harms such as misinformation, and disinformation campaigns. This regulation of small platforms should be in line with our Principles 1, 3 and 5.

The government does not presently agree with the Committee’s recommendation to create an additional category to cover ‘small but risky’ providers. As you are aware, thresholds for Category 1 (large user-to-user services), 2A (large search services) and 2B (other categorised user-to-user services) were approved by Parliament and came into force on 27 February 2025.

The government decided not to specifically bring small but risky providers into scope of the categorisation regulations on the basis that there was no way to do so without capturing hundreds of small, low-risk providers as a result. The additional duties on categorised services would also not bring about significant benefits on such services. For example, the duties which require providers to enforce their terms of service and give users who want to avoid harmful content more choice, would have limited effect on small but risky services where the service is unlikely to prohibit harmful content and users’ are actively seeking content of concern out.

The government is cognisant that there are services that may not be categorised that play a role in the dissemination of harmful mis- and disinformation online. The government is confident that the current duties placed on small but risky providers, - to carry out risk assessments, and then to establish proportionate systems to tackle illegal content and protect children from harmful content - will have a positive impact. Ofcom’s Codes are also explicitly designed so that small, but high-risk services will be expected to use greater protections than services that pose less risk. Ofcom has already launched an investigation into a suicide forum for suspected non-compliance of its duties. Ofcom has also established a dedicated small but risky taskforce which is actively targeting high risk services and developing further workplans based on high priority themes (such as terror, suicide, hate and offences directed against women and girls).

The government will keep the categorisation process under review.

Disinformation Campaigns

Recommendation of the Committee: Foreign interference and disinformation campaigns, with use of technology such as bots and AI, put UK citizens at risk. The possibility that some of the divisive messages and deceptive content spread by users—and amplified by algorithms—last summer were part of such an influence operation is deeply concerning. In order to tackle amplified disinformation, identified by Principle 1, the government and Ofcom should collaborate with platforms to identify and track disinformation actors and the techniques and behaviours they use to spread adversarial and deceptive narratives online.

Through the National Security Act 2023, the government has legislated to provide the security services and law enforcement agencies with the tools they need to deter, detect, and disrupt modern-day state threats, including foreign interference. The Foreign Interference Offence has also been added as a priority offence in the Online Safety Act, requiring all in-scope companies to take action against a range of state-linked disinformation and interference online. Companies have a legal duty to take systemic action to prevent users from encountering material that amounts to foreign interference and minimise how long any such content is present on their services. This means that social media platforms, search engines and other apps and websites allowing people to post their own content have to identify and minimise their users’ exposure to state-backed attempts to undermine our democratic, political and legal processes.

In addition, the Foreign Influence Registration Scheme introduced under the National Security Act will strengthen the resilience of the UK political system against covert foreign influence and provide greater assurance around the activities of designated foreign powers or entities where there is a national security risk.

The government engages constructively with social media platforms whilst being clear about their responsibility to deal with harmful content. DSIT has strong relationships with the major platforms which have the largest reach in the UK. The department engages with them on issues, emerging narratives, or events that may lead to a heightened risk to public safety or national security.

Ofcom is the independent regulator for the Online Safety Act and is best placed to consider what further evidence it requires for effective enforcement of OSA duties relating to the Foreign Interference Offence.

Recommendation of the Committee: Responsibility for tracking foreign disinformation campaigns appears to be split between several departments, including DSIT. This suggests that the Intelligence and Security Committee’s 2020 characterisation of countering Russian influence operations as a “hot potato”, passed between different bodies, has not been addressed. To meet our Principle 1, the government should clarify which department has ownership over tracking and countering online narrative operations. It should consider consolidating responsibility within a single entity, for example the National Security Online Information Team, or establishing a clear chain of command, and in its response to this report the government should set out the actions it intends to take in this regard.

The department recognises the importance and value of a whole of government approach to this cross-cutting issue. The bringing together of expertise is reflected in how effectively all departments, including the Home Office, Cabinet Office and FCDO, currently collaborate to tackle online foreign disinformation campaigns.

Within this cross-Whitehall approach, the department’s National Security Online Information Team (NSOIT) leads the government’s operational response to information risks, including mis- and disinformation, to UK audiences, focusing on those which present a public safety or national security risk.

The government will continue to build on expertise across government through existing structures, including the Defending Democracy Task Force and Joint Election Security Preparedness Unit, to ensure that departments continue to work effectively and collaboratively to counter foreign interference and protect UK democracy.

Recommendation of the Committee: The NSOIT is an important tool in protecting citizens from disinformation and needs appropriate scrutiny. Government should place NSOIT on a statutory footing and bring it under the remit of the Intelligence and Security Committee, to ensure that our Principle 1 is being effectively and safely pursued, in line with Principle 2.

The government welcomes the Committee’s acknowledgement of the important role played by the National Security Online Information Team (NSOIT) and agrees on the importance of appropriate scrutiny to ensure this work is transparent and accountable.

NSOIT carries out its functions in compliance with all relevant legislation and ensures that freedom of expression is respected. This is demonstrated by NSOIT’s privacy notices, which are accessible to the public on Gov.uk. Further, the department continues to engage with correspondence, Freedom of Information Act requests and Subject Access Requests from parliamentarians and members of the public on the team’s activities.

The work of NSOIT is also subject to DSIT ministerial oversight and parliamentary scrutiny through existing channels such as questions in the House and appearances before Select Committees. For example, in March 2025, the department gave evidence in front of the National Security Strategy (Joint Committee) on the UK’s ability to deter foreign interference and defend elections from attacks. DSIT will continue to ensure transparency of and accountability for the team’s work.

Generative AI

Recommendation of the Committee: To protect citizens from the AI-exacerbated spread of misinformation and harm, the government should pass legislation that covers generative AI platforms, bringing them in line with other online services that pose a high risk of producing or spreading illegal or harmful content. Following the Principles identified by this report, this legislation should require generative AI platforms to: provide risk assessments to Ofcom on the risks associated with different prompts and outputs, including how far they can create or spread illegal, harmful or misleading content; explain to Ofcom how the model curates content, responds to sensitive topics and what guardrails are in place to prevent content that is illegal or harmful to children; implement user safeguards such as feedback, complaints and output flagging; and prevent children from accessing inappropriate or harmful outputs.

The government does not presently agree with the Committee’s recommendation for additional legislation in this regard. Doing so prior to full implementation of the OSA would complicate and undermine this process. The OSA lays the foundation for strong protections against illegal content and harmful material for children online, including content which is AI generated.

AI generated content is already regulated under the OSA in the same way as ‘real’ content, i.e. where it is shared on an in-scope user-to-user or search service and constitutes either illegal content or content which is harmful to children. The largest user-to-user services will also need to enforce their terms of service, including in relation to AI generated content.

Generative AI services that allow users to share content with one another or that search live websites to provide search results, are regulated under the online safety regime. In scope generative AI search or user-to-user services are required to assess the risk of harm to users from illegal content on their services and implement measures to manage and mitigate this risk. Where services are likely to be accessed by children, they will be required to take action to protect them from harmful content. Additionally, providers who publish pornographic content on their services must prevent children from accessing that content. This includes sites and apps that use, or allow users to use, Generative AI to generate pornographic material. Ofcom, as the independent regulator of the online safety regime, published an open letter on 8th November 2024 on how the OSA applies to Generative AI tools and providers.

We continue to keep online safety under review. The government is committed to keeping young people safe online and we will act to address emerging AI harms. Nothing is off the table when it comes to keeping children safe.

Alongside our work on online safety, the AI Security Institute (AISI) was set up to equip governments with a scientific understanding of AI’s risks so governments can act quickly to protect people’s safety and security. The Institute focuses on emerging AI risks with serious security implications, including the potential of AI to enable criminal activity. Additionally, AISI is investigating how highly capable AI systems can be used to manipulate, persuade, deceive, or subtly influence humans, and developing methods to measure these impacts. AISI recently published the first large scale study of its kind looking into the levers of political persuasion in conversational AI.

AISI uses novel scientific methods to understand the risks of the most cutting-edge AI systems and is the first state-backed Institute in the world to have already conducted safety evaluations on frontier AI models.

Following the launch of the UK’s AISI, we have seen similar organisations spring up around the globe – this is a clear testament to the UK’s approach. Through the AISI network and relationships with our international partners, the government is collaborating on how to tackle the shared challenges from AI. The Action Summit in Paris in February 2025 reinforced the Government’s commitment to international collaboration on the risks of frontier AI being used to generate mis/disinformation and threats online.

Recommendation of the Committee: Principle 5 is crucial for addressing potential harms from generative AI, as there is currently a serious shortfall in transparency and oversight of the platforms and systems that allow users to create AI-generated content. The government should require providers of generative AI services to provide information to those carrying out independent research into online safety. This should include data such as platforms’ internal decision-making processes, training datasets, optimisation objectives, safety mechanisms and guardrails on outputs.

The government recognises the challenges that researchers face when seeking to obtain online safety data for research. As previously mentioned, the government has powers to create a new framework for researchers to access online safety data. The framework will be informed by a robust evidence base, including a report by Ofcom exploring existing access, barriers, and how greater access might be achieved which was published in July 2025. Improved access to online safety data will enable more comprehensive research into online safety risks, as well as the effectiveness of providers’ processes to mitigate risks to users as part of meeting their online safety duties.

As set out in the previous recommendation, generative AI services that allow users to share content with one another or that search live websites to provide search results, are regulated under the online safety regime.

The online safety regulatory framework confers a range of powers on Ofcom which will help ensure it can access the information it needs to understand how companies are fulfilling their duties. This includes a power to require a report from a skilled person about a regulated service. A “skilled person” is an individual, organisation, body of persons or association of persons that appear to Ofcom to have the skills necessary to prepare a specific report. This may include technical experts as well as independent researchers. This power will enable Ofcom to utilise the expertise of external experts (skilled persons) to help understand how companies are meeting their regulatory obligations. It may be used to assist Ofcom in identifying and assessing non-compliance or to help develop Ofcom’s understanding of the risk of non-compliance or ways to mitigate such risk where a provider appears to be at risk of failing to comply with a relevant requirement.

Ofcom will also have the power to conduct audits which it can use to assess potential non- compliance with regulatory requirements and to build an understanding of the risk associated with a service. Ofcom will also be able to require a provider to allow an authorised person to remotely view certain types of information, where it is proportionate to do so. This includes remotely observing the carrying out of empirical tests. This is a standard method for understanding algorithms and which involve taking a test dataset, running it through an algorithmic system, and observing the output.

Additionally, and as set out in the above recommendation, The AI Security Institute take’s a leading role in testing frontier AI models for potential risks both pre and post deployment, allowing the government to stay ahead of risks and capabilities as they emerge.

Recommendation of the Committee: To effectively tackle amplified misinformation as per Principle 1, the government should work with relevant experts and platforms to develop technology that automatically detects AI-generated media, meeting mis/disinformation at its source. It should mandate all generative AI platforms, and platforms that employ generative AI technologies, to automatically label AI-generated media with metadata and visible watermarks that cannot be removed.

As previously mentioned, government already engages with relevant experts to understand the potential for identifying AI-generated content, particularly where it constitutes harmful content. We are working with partners to investigate the potential for detecting AI-generated content to support transparency of synthetically generated content, this includes assessing both evidence on the feasibility of technical solutions and levers to ensure that these technologies are developed and deployed in a beneficial way.

Together with Home Office, we ran the Deepfake Detection Challenge to understand how government, academia and industry can work together in the development of innovative and practical solutions to detect synthetic media. The Challenge examined existing capabilities and identified gaps requiring innovative approaches and novel solutions. Follow-up work from the challenge is underway. We continue to explore solutions that enable users and institutions to determine what media is real and what is AI-generated, this is a key part of tackling a wide range of AI risks.

Ofcom are also undertaking research to assess the merits and limitations of different measures to identify deepfakes, including watermarking tools, provenance metadata schemes, AI labels, and context annotations. While the findings are not new rules or expectations for tech firms, they can be used to guide providers or those deploying these tools to help identify deepfake content. Ofcom’s research will also inform their future policy development and supervision of regulated services under the Online Safety Act.

Digital Advertising Market

Recommendation of the Committee: Tackling online harm means addressing the principles that incentivise and monetise its spread. In line with Principle 3, responsibility, the government should create a new arms-length body—not funded by industry—to regulate and scrutinise the process of digital advertising, covering the complex and opaque automated supply chain that allows for the monetisation of harmful and misleading content. Or, at the least, the government should extend Ofcom’s powers to explicitly cover this form of harm, and regulate based on the principle of preventing the spread of harmful or misleading content through any digital means, rather than limiting itself to specific technologies or sectors.

The government acknowledges the concerns raised about the lack of transparency in the online advertising ecosystem and we continue to review the regulatory landscape in this area, including the options available to address the identified issues. The Online Advertising Taskforce, chaired by the Minister for the Creative Industries, Arts and Tourism, is also working to increase transparency and accountability, in particular as it relates to illegal advertising and increasing protections for children from adverts for products and services which are illegal to be sold to them. We are closely monitoring the implementation of the Online Safety Act to identify areas we can build on it.

Recommendation of the Committee: To tackle the incentive behind amplified misinformation—namely, the monetisation of harmful content—there should be clear and enforceable standards for digital advertising market processes, as well as advertising content. Following our Principles 1, 3 and 5, government should ask the Advertising Standards Authority to establish comprehensive guidelines for 59 all actors within the digital advertising ecosystem and supply chain. These should be informed by the UN’s 2024 Guiding Principles for Information Integrity and developed in consultation with civil society, academics, experts, industry and policymakers. It should be designed to remove incentives for algorithmic acceleration of harmful or misleading content whilst upholding freedom of expression; ensure advertisers can avoid harmful content; and ensure transparency in technologies with public safety implications, such as digital advertising.

The Advertising Standards Authority is an industry self-regulatory body which is independent of government, although it performs some statutory functions under contract to Ofcom. Government works closely with the ASA, including through the Online Advertising Taskforce, to draw on its expertise and discuss matters related to trust and transparency in the online advertising ecosystem. The ASA’s current remit is to regulate the content of advertising to ensure it is legal, decent, honest and truthful. Targeting of advertising that is for age- restricted products, and setting standards for processes in the digital ecosystem would be outside that remit.

The Gold Standard is a certification scheme run by the Internet Advertising Bureau (IAB UK) that seeks to improve the digital advertising landscape through the implementation of standards for buyers and sellers of digital media space. Its purpose is to create a safe and responsible ecosystem, work towards greater consumer safety online, and increase business and consumer trust in online ads. The Working Group of the Online Advertising Taskforce is concerned with promoting awareness and uptake of the Gold Standard.

Recommendation of the Committee: The internet, and social media, could not operate without digital advertising. Given its implications for public safety, as per Principle 5, there needs to be heightened transparency in the market processes of online advertising. Government should mandate ‘Know Your Customer’ checks for participants in the programmatic advertising supply chain, as exists in other large markets. The government should also ensure that platforms disclose full ad campaign data, and allow independent third-party audits and vetting of ad exchange supply partners.

Digital Advertising is a core component supporting growth of the Advertising sector, as outlined in the Government’s Creative Industries Sector Plan published on 23 June 2025. While we acknowledge that there are concerns around trust and transparency in the Online Advertising ecosystem, it is important that any measures taken to address those concerns are carefully considered and do not unduly undermine the value that advertising brings to the wider Creative Industries and many other businesses across the economy. We will explore options for ‘Know Your Customer’ checks alongside other possible interventions, including our continued work with the Online Advertising Taskforce, to address any harms linked to digital advertising.

Recommendation of the Committee: There are insufficient disincentives for bad practice in the digital advertising market. Bad actors can exploit the ecosystem, monetising harmful content through major platforms. Following Principle 3, Ofcom should be empowered to give penalty notices to platforms when they allow harmful content to be monetised through their services. These penalties should be based on a formula that considers: the severity of harm, the amount of revenue the publisher received, the amount of revenue the platform received, and the number of individuals that encountered the harmful content. The revenue generated from these penalties should be used to support victims of online harms.

The Online Safety Act introduces duties for in-scope services to implement proportionate systems and processes for mitigating risks to users’ safety. Regulated services are required to monitor how effective these systems and processes are. Accordingly, Ofcom will judge the systems and processes that platforms have in place to address content captured under the Act’s safety duties, and take enforcement action where proportionate systems and processes are not in place, including by requiring certain steps or imposing fines via penalty notices. Under the regime, Ofcom does not make judgements on, or serve penalty notices in response to, individual pieces of content. To equip Ofcom with the powers this recommendation proposes, there would need to be an associated duty on platforms to tackle the monetisation of harmful content; this would necessitate defining ‘harmful content’, i.e. that which falls out of scope of the current duties but still has the capacity to cause harm to users. Imposing penalties in relation to individual pieces of content where providers haven’t been made aware of them could also have broader implications for policies designed to ensure the efficient functioning of the internet by providing limited protections to essential internet intermediary services.

Appendix 2: Ofcom response

Committee recommendation: We welcome Ofcom’s consultation on a ‘crisis response protocol’ for companies to follow in response to events such as the 2024 unrest. The protocol should directly address misinformation by including all online services at risk of contributing to the spread of false or harmful information, including large online social media, search and messaging services; those with smaller user numbers but high-risk profiles; and others, such as generative AI platforms. In establishing the mechanism, Ofcom should acknowledge the different ways in which different services operate. Following our Principle 2, it should hold platforms responsible for: decelerating the spread of harmful misinformation without censoring lawful speech; ensuring substantial and continuous engagement with law enforcement and government bodies; giving users control over the content they see; and providing transparency around their actions. (paragraph 19)

We are currently in the consultation period for the crisis response protocol measure and welcome the committee’s input. We plan to publish our final statement next year and will keep the committee updated.

A crisis can exacerbate the risks of both online and offline harms. During a crisis there may be an increase in both the volume of illegal content and of content harmful to children, and the risks such content poses in catalysing offline harm, including the risk that services will be used to commit and/or facilitate a priority offence.

Our proposed crisis response measures are intended to help online service providers quickly stop illegal content and content harmful to children from spreading on their services. When a crisis occurs we assess that these proposed measures will help providers plan for such scenarios, and by extension, reduce the volume of such content proliferating online. Without a plan in place for identifying and responding to crises, valuable time may be lost while providers attempt to establish whether a crisis has been initiated, assemble relevant personnel, and develop their response in an ad-hoc and reactive manner.

There are three main elements to the proposed recommendations:

  • First, providers should have a crisis response protocol in place. This should include monitoring indicators, to identify when a crisis has been initiated, and set out how the provider will stand up a crisis response team. It should also include systems and/or processes identified by the provider to address the risk of an increase in certain types of illegal content or content harmful to children on the service during a crisis.
  • Second, providers should conduct a post-crisis analysis, keeping a written record of these assessments. A post-crisis analysis should drive improvement in providers’ systems and processes for dealing with a crisis and identify gaps within the provider’s wider trust and safety systems and processes. This will also mean we can formally request this report if necessary for the performance of our regulatory functions.
  • Third, large service providers should have a dedicated communication channel available to law enforcement during a crisis. This would improve the speed and reliability of information exchange during crises, enabling enable faster risk mitigation from providers and aiding the coordination of public safety efforts at scale.1

We’ve proposed that the crisis response measures should apply to:

  • large2 user-to-user services that are at medium risk, and;
  • user-to-user services of any size that are at high risk of any one of the following harms:
    • within priority illegal harms – terrorism, hate, harassment / stalking / threats / abuse and foreign interference;
    • within priority content harmful to children – abuse and hate, and violent content.

Our proposals are based on evidence which shows the role of both large and smaller user-to-user services in the proliferation of illegal content and/or content harmful to children during crises. We have selected the applicable harms because, based on our assessment of the evidence, we considered that the content associated with these harms is more likely to be relevant in a crisis.

In our consultation we set out our provisional assessment of the impact of the proposal on human rights, including freedom of expression. In general, the proposed measures recommend that services have a crisis response protocol in place. They are not prescriptive about how content should be moderated during a crisis. Because of this, we considered that the measures do not have a direct negative impact on users’ freedom of expression. However, we recognised that a potential outcome of the proposed measures (depending on what providers put in their policy) is that providers may implement a crisis response protocol which prioritises speed of moderation over accuracy, which may result in a heightened risk of false positives and over-removal of content, including highly protected speech. Our rights assessment discussed a number of safeguards and other mitigations that are relevant (e.g. allowing users to appeal). Noting that services have discretion about what to put in their crisis response protocols (which need not necessarily involve a higher tolerance for false positives), we provisionally concluded that any interference to users’ rights to freedom of expression is proportionate.

Our powers, and these proposals, relate to the specific harms in scope of the Online Safety Act (OSA). As we discussed in the evidence session, the OSA does not identify disinformation or misinformation as harms that need to be addressed by online services. However, where disinformation or misinformation amounts to the categories of illegal content or content harmful to children covered by the OSA, then services will need to take action. For example, misinformation might constitute illegal hate content in certain circumstances, such as content that includes hate based on false information. Content of this kind would be addressed by the proposed crisis response protocol.

Category 1 services will also have a duty to use proportionate systems and processes to ensure that taking down or restricting access to content, and suspending or banning users, is only carried out in accordance with their terms of service. They must consistently enforce any provisions in their terms of service related to these actions. This includes where they have provisions which are relevant to misinformation and disinformation. These duties will apply once the process of categorising services, and consulting on codes of practice regarding these duties, is complete.

With respect to users’ control over the content they see, there are several duties and measures in our codes of practice which are relevant. Our Protection of Children code recommends that large and risky user-to-user services enable children to give negative feedback on content that is recommended to them, which is taken into account in how content is recommended to them in future. The aim of this measure is to give children more control so they encounter fewer recommendations of content they have signalled they would like to see less of, which could include various types of harmful content and misinformation.

In addition, relevant service providers will also be responsible for giving users more control over the content they see and providing transparency on their activities as part of phase 3 of Ofcom’s implementation of the OSA. All categorised service providers will be required to produce transparency reports referring to topics which may include their governance and risk management processes, safety systems, service design and the design and operation of algorithms which affect how content is recommended to users. We will issue annual transparency notices to all categorised service providers requiring them to publish certain information, and can tailor these notices to individual services.

In addition, Category 1 service providers will also need to offer tools to adult users that enable them to reduce the likelihood of encountering certain types of content, be alerted to the presence of such content, and filter out non-verified users. These duties apply to legal content that incites hatred or is abusive, and legal suicide, self-injury and eating disorder content.

Committee recommendation: There is a shortfall in data needed to accurately analyse the scale of the problem and identify policy solutions. In line with our Principle 4, the government should commission a large-scale research project into how far social media recommendation systems spread, amplify or prioritise harmful content. This should be undertaken by a group of credible independent researchers, bringing diverse perspectives, with full access to the inner functions of the systems that major platforms use to algorithmically recommend content, including the private, external, and third party data used to train their systems; the user, content and engagement attributes the algorithms rely on and how these are weighted, and the objectives the algorithms are optimised for; where user interactions reinforce future recommendations; and any curation rules or interventions that influence promotion or suppression of content. We expect full cooperation from all major services that employ recommendation algorithms. (paragraph 29)

Although this is a recommendation for Government, we explain below how our research programme, including on recommender systems, may support this recommendation and contribute to any further research of this kind.

We have invested in an extensive programme of research to inform our Online Safety work, which we publish regularly on the Ofcom website. We continue to broaden our multidisciplinary evidence base to keep up to date as technologies evolve. More information about our research programme and our areas of interest for future research can be found in our Online Safety Research Agenda.

Research relevant to the Committee’s recommendation includes:

We recognise the sector-wide need for further research. We identified recommender systems as a priority area for future research in our Online Safety Research Agenda. By publishing these areas of interest, we hope to inspire the wider academic and research community to consider how best to achieve our shared research goals.

We are also currently exploring using the avatar research method to better understand the types of content being served to users’ social media platforms, following our pilot study to test the feasibility of the method.

Committee recommendation: Based on the research described above (in paragraph 29), the government should publish conclusions on the level and nature of harm that these platforms promote through their recommendation systems. Following our Principle 3, if significant harm is found, the responsible online services should publish the actions they will take to address these harms. Ofcom should be given the power to serve penalty notices to services that fail to comply, either 10% of the company’s worldwide revenue, or £18 million, whichever is higher. (paragraph 30)

Although this is a recommendation for Government, we set out below some of our measures relating to recommender systems. We agree that recommender systems are a key vector of harm, both with respect to the dissemination of illegal material, and exposure of children to content harmful to them. Both the OSA and our codes contain several requirements designed to hold platforms to account for the operation of their algorithms.

First, the OSA gives services a duty to carry out risk assessments, which includes an assessment of the risk of users encountering illegal content by means of the algorithms used by the service.

Second, our Illegal Harms code says that certain user-to-user services should collect safety metrics when testing their recommender systems. This will help these services to better understand whether adjustments to the design of their recommender systems might contribute to the risk of their users encountering illegal content, therefore promoting a safety by design approach to the operation of algorithmic systems.

Third, our Protection of Children code includes measures for user-to-user services which operate a recommender system, and which pose a higher risk of harmful content (as defined by the OSA):

  • They should configure their recommender systems to filter out the most harmful content from children’s feeds and reduce the visibility of other harmful content.
  • Large services should also enable children to provide negative feedback on content that is recommended to them, giving them more control over the content in their feeds

Fourth, in June we proposed additional measures specifying that where there are indicators that a piece of content might be illegal, service providers should exclude it from recommender systems unless and until it has been reviewed. We are currently consulting on these proposals.

Now that the codes are in force, we have launched a monitoring and impact programme focused on protection of children from legal but harmful content, primarily focused on the biggest platforms where children spend most time. Through this work, we will be scrutinising these platforms’ practical actions to keep children safe including how effectively they have configured their algorithms so that children do not encounter harmful content, and drawing on our technology capability to deepen our understanding of their content recommender systems, and the role they play in exposing children to harmful content. We are continuing to build our evidence base of children’s online experiences through our programme of quantitative and qualitative research. We also have a statutory requirement to review and report by next October on the incidence on regulated services of content that is harmful to children, the severity of harm that children in the UK suffer, or may suffer, as a result of that content, and whether and how we think it is appropriate to make changes to the primary priority and priority content categories.

Committee recommendation: To ensure true responsibility from platform companies, as per Principle 3, Ofcom and DSIT should confirm that services are required to act on all risks identified in risk assessments, regardless of whether they are included in Ofcom’s Codes of Practice. (paragraph 49)

The safety duties in the OSA require providers to take proportionate steps to mitigate the risk of harm to their users, resulting in high expectations for the largest and riskiest providers to address the risk of harm from illegal content. All services must carry out a suitable and sufficient illegal content risk assessment and, if likely to be accessed by children, a children’s risk assessment.

The OSA states that providers will be deemed to be compliant with their safety duties if they adopt the measures in the codes that are relevant to their service – this is known as the ‘safe harbour’. The codes set out the measures that we are satisfied are proportionate, having assessed their impact on harm, regulated services and users’ rights, for service providers to address their risks. Our codes are segmented based on size, and in some cases risk level, so that riskier services, whether large or small, have to work harder to keep users safe. Some may choose to implement alternative measures.

It is not possible within the framework of the OSA to recommend a measure that asks a service to remove all risks. We cannot assess the impact and proportionality of a measure if we do not know what compliance with it would entail.

However, we believe that the risk assessment practice outlined in our Risk Assessment Guidance, combined with the governance measures in our codes, will ensure that services cannot ignore significant unmanaged levels of risk. Our guidance sets out steps to help providers understand the inherent risk posed by the functionalities, design and operation of their service, and consider the residual risks faced by users after existing controls; after completing their illegal content risk assessment, service providers should have assigned residual risk levels to each kind of priority illegal content and other illegal content. They need to take steps to mitigate the actual risk to users identified in their assessment for each of these. Services with a duty to carry out a separate children’s risk assessment must also assign risk levels to each kind of primary priority content, priority content and non-designated content.

These risk assessments should give firms a comprehensive understanding of all their risks. The corporate governance and accountability measures in our codes will ensure they act on them. They require services to have the structures and processes to identify, monitor and manage risks of harm as appropriate, including effective senior oversight and accountability for risk management.

Some services may choose to go further to mitigate risks to users, for example by following other kinds of guidance like Ofcom’s draft Guidance on a Safer Life Online for Women and Girls which focuses on practical and ambitious steps providers could take to reduce the risks from online gender-based harm.

Committee recommendation: The Online Safety Act does not do enough to address the risks posed by small platforms due to its exclusive focus on size. Ofcom should create an additional category to cover ‘small but risky’ platforms, based on analysis of the role that harmful smaller platforms can play in the online ecosystem, interacting with the recommendation algorithms of large platforms to spread harms such as misinformation, and disinformation campaigns. This regulation of small platforms should be in line with our Principles 1, 3 and 5. (paragraph 50)

We disagree that the OSA does not do enough to address the risks posed by small platforms. The main measures in the OSA apply to all services in scope, including small but risky services. Since 17 March, all services in scope of the OSA need to have safety measures in place to address illegal content and conduct. The Illegal Harms Codes of Practice specify:

  • All services need to remove illegal content swiftly when they’re aware of it, have effective complaints systems, and a named senior person accountable for compliance.
  • The codes require riskier firms to do more – regardless of their size – including having adequate training, performance targets and codes of conduct for staff working on user safety, and gathering evidence of growing illegal activity.
  • Services that pose a high risk of grooming, also irrespective of size, should have features which make it harder for perpetrators to contact children. Similarly, the codes state that file- sharing services face a particular risk of misuse by people who wish to share image-based CSAM, and therefore services who are at high risk of having such content, should deploy hash matching technology to detect this content.

Furthermore all services, regardless of size, that allow pornography or other harmful content (such as suicide, self-harm and eating disorder content), have to use highly effective age assurance (HEAA) to prevent children from encountering it. This duty took effect on 25 July 2025. All services hosting pornography had to implement HEAA by that date.

Last year we established a taskforce to drive compliance on small but risky services. These services, despite having relatively low reach (under or around 1% of the UK population as active monthly users), pose unacceptable risks to user safety, because of their features, functionalities and/or user behaviours. These include pro-suicide forums and file sharing services dedicated to uploading child sexual abuse material (CSAM). The taskforce is focused on holding these small but high-risk platforms accountable for compliance with their duties.

The taskforce’s work includes building a robust evidence base of harm through triaging complaints, analysing industry data, assessing law enforcement intelligence, understanding businesses models, and importantly for this area – analysing the role individual small services play in the wider network of services where harm happens. Using cutting edge research and analytical techniques, our analysts have mapped the universe of services to identify which small services play a disproportionate role in facilitating harm. All this work enables the taskforce to focus on the highest-risk services and push for fast action where it matters most.

To date, the taskforce has engaged with more than thirty of the highest risk services, and will be expanding to take on additional high-risk services. Direct interventions from the taskforce have led to improvements in protection for people in the UK. The taskforce will continue to drive compliance on these small but risky services, through targeted action.

While the committee’s recommendation to create a new category of service is a matter for Government, we do not think that an additional category would add significantly to our ability to regulate small risky services within the framework of the existing legislation. Adding further obligations specifically on small but risky services would be a matter for Parliament.

Committee recommendation: Foreign interference and disinformation campaigns, with use of technology such as bots and AI, put UK citizens at risk. The possibility that some of the divisive messages and deceptive content spread by users—and amplified by algorithms—last summer were part of such an influence operation is deeply concerning. In order to tackle amplified disinformation, identified by Principle 1, the government and Ofcom should collaborate with platforms to identify and track disinformation actors and the techniques and behaviours they use to spread adversarial and deceptive narratives online. (paragraph 58)

We recognise the risk that foreign interference in the UK can pose, both to society as a whole and individuals. Our analysis published at the end of 2024 highlighted a variety of ways in which these risks can manifest. This includes state-sponsored disinformation campaigns designed to interfere in elections, hack and leak operations, efforts to target diaspora communities in the UK, and interference operations targeting people based on their protected characteristics.

We have seen well-evidenced examples of campaigns of this kind as a result of careful analysis by platforms and independent experts. But it is often challenging for providers of regulated services to identify individual items of content, in real-time, as foreign interference. Under the Act, they must have reasonable grounds to infer a link between the content and a foreign state. Potential perpetrators can make this attribution more difficult by co-opting commercial bot networks, digital marketing companies, individual accounts and local content creators.

We are working to better understand indicators that platforms could use to detect likely foreign interference. Analysis of large-scale large data sets and use of proactive technology to detect patterns associated with some forms of foreign interference behaviour could be effective in some cases in identifying content amounting to offences quickly and at scale, alongside relevant knowledge of the political or geopolitical context. However, as tactics used may not be exclusive to those engaging in foreign interference, platforms will need to take care only to act in cases where they have reasonable grounds to infer it has happened, or else risk unjustified restrictions of free expression.

Our existing Codes of Practice contain several cross-cutting measures that are designed to apply across all illegal harms, and will help mitigate risks of foreign interference . Our ‘first-edition’ Codes include that:

  • Service providers should do a thorough risk assessment and put in place appropriate governance arrangements to track and manage risk.
  • Providers of user-to-user services should have a content moderation function to review and assess suspected illegal content. It should also allow for the swift take down of illegal content.
  • High risk service providers should appropriately resource and train their content moderation teams.
  • Service providers should operate easy to use reporting and complaints systems.
  • Services providers should have clear internal policies for operating notable user or paid-for verification schemes (where those exist) and improving transparency for users about what verified status means in practice. This may help users to assess whether a user posting content is authentic or impersonating a high-profile individual or organisation.

All these measures should be applied to illegal foreign interference, when services identify it.

We will also continue to engage with experts to improve our understanding of how foreign interference can manifest online and appropriate responses to it.


Footnotes

1 Please note: A provider is not usually required to accept the opinions of a third party as to whether content is illegal content. Only a judgment of a UK court is binding on it in making this determination. See 1.66 of the Illegal Contents Judgement Guidance.

2 In our Illegal Content user-to-user Codes of Practice we define ‘large’ as a service which has more than 7 million monthly active United Kingdom users.