Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The UK’s Online Safety Bill received Royal Assent on 26 October 2023, becoming the Online Safety Act 2023. Rights groups warned that its powers could pressure messaging services to scan private communications or weaken end-to-end encryption. The Act does not impose an immediate blanket ban on encryption, but its technology-notice regime remains the central privacy dispute as implementation continues.
What Royal Assent changed
Royal Assent ended the bill’s passage through Parliament and converted it into the Online Safety Act 2023. It did not, however, bring every obligation into force on the same day. Many duties depended on commencement arrangements, Ofcom’s codes of practice and staged implementation.
The Act created a regulatory framework for online services rather than a single rule applying identically to every website or app. Ofcom is responsible for implementing and enforcing much of the regime.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What the Online Safety Act covers
The main regulated categories are:
- User-to-user services, where users can publish or share content with other users.
- Search services, which help users find information online.
- Services likely to be accessed by children, subject to the relevant statutory tests and duties.
- Certain pornography providers and other services falling within the Act’s categories or thresholds.
- Services based outside the UK where they have the required UK connection or affect UK users.
Depending on the service, providers must assess risks, maintain safety systems, deal with illegal content, protect children from specified harms, provide reporting and complaints routes, meet transparency obligations and in some circumstances use age-assurance measures. The Act also created or amended offences including threatening communications, false communications, cyberflashing and encouraging or assisting serious self-harm. The government’s overview is available in its Online Safety Act explainer.
#1 Best Overall
Why rights groups focused on encryption
End-to-end encryption is designed so that the sender and recipient control the keys needed to read a message. The service provider generally cannot read the content while it is being transmitted.
That creates a technical tension with routine content scanning. A provider cannot preserve a strict model in which only the sender and recipient can access message content while also giving a third party or a provider-controlled system ordinary access to inspect that content.
Critics therefore warned that the Act could create pressure for services to introduce measures such as:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute- Client-side scanning before a message is encrypted.
- Scanning after content is decrypted on a user’s device.
- Other detection systems that alter the service’s existing security architecture.
Open Rights Group and Big Brother Watch criticised the potential impact on privacy and encrypted communications. Open Rights Group told Ofcom that services including WhatsApp, Signal and Element had indicated they might consider withdrawing from the UK if encryption were compromised. Such warnings show how providers perceive the risk; they do not prove that the Act requires any particular company to leave or to scan messages.
Critics’ concerns extend beyond the content of individual messages. They argue that scanning could create new attack surfaces, expose private communications to automated errors, enable mass surveillance or encourage “function creep” into areas beyond the original purpose.
Rank #2
What the law actually empowers Ofcom to do
Ofcom must produce codes of practice addressing duties relating to illegal content and child safety. Providers can use methods different from those recommended in a code, provided they meet their legal obligations. However, the code may be taken into account by Ofcom or a court when assessing compliance.
Technology notices are a separate and particularly controversial mechanism. Subject to statutory conditions and procedures, Ofcom may require a regulated service to use accredited technology to identify terrorism content or child sexual exploitation and abuse material.
This is not the same as an automatic power to decrypt everyone’s messages. The important distinctions are:
- The Act creates a statutory power under specified conditions.
- Ofcom would need to follow the required legal process.
- A technology notice would concern a particular regulated service, not automatically every platform.
- The provider would then have to decide how to respond, including whether to alter its product, challenge the notice or potentially restrict UK availability.
The Act and its explanatory material require relevant regulatory measures to take account of privacy and freedom of expression. Those safeguards matter legally, but they do not by themselves settle the engineering question of whether a proposed scanning method can preserve confidentiality and security.
The government has maintained that the regime is technology-neutral, contains safeguards and does not create a general ban on end-to-end encryption. The more precise criticism is that a future notice could require technology that makes strict end-to-end encryption difficult or impossible to maintain.
The wider free-expression concern
Encryption is not the only objection. Rights organisations have also warned that broad safety duties may encourage platforms to remove lawful but controversial material to reduce regulatory risk. Automated moderation can produce false positives involving journalism, political speech, satire, sexual-health information or benign personal communications.
These concerns do not mean that every removal is required by the Act. Platforms may remove material under their own terms of service, even where the content is lawful. Nor are all online communications equivalent: public posts, private messages, metadata and message content present different privacy and regulatory questions.
Why supporters back the Act
The government and supporters argue that platforms have too often been slow or inconsistent in dealing with illegal material and foreseeable risks to children. They say providers should be required to identify risks, improve their systems and take action rather than waiting for individual complaints.
Supporters also point to stronger accountability, transparency requirements and enforceable duties. A risk-based framework can impose different expectations depending on a service’s size, design, audience and level of risk rather than applying identical controls to every provider.
The policy trade-off is therefore substantial: improving the detection of terrorism and child-sexual-abuse material while preserving secure private communication. Any detection system must be judged separately for technical reliability, privacy impact, security, proportionality, error rates, transparency and the ability of users to challenge mistakes.
Rank #4
What companies face
Enforcement can involve information requests, transparency obligations, risk-assessment and compliance requirements, financial penalties and, in serious cases, measures capable of disrupting a non-compliant service. The statutory framework also includes specified personal-liability provisions and criminal offences.
Contemporaneous reporting referred to potential fines of up to £18 million or 10% of annual turnover. The precise calculation depends on the statutory terminology and enforcement framework, so “turnover” should not be treated as interchangeable with terms such as qualifying worldwide revenue. Providers should consult Ofcom’s current enforcement guidance and the enacted legislation.
Small services may face different expectations from large, high-risk platforms, while overseas companies can still fall within scope if they serve UK users and meet the statutory connection tests.
What users should understand
- Royal Assent made the bill an Act; it did not mean every provision became enforceable immediately.
- The Act covers more than social media, including search services and certain pornography providers.
- It does not automatically require every encrypted messaging service to scan every message.
- A future technology notice could still create serious consequences for how an encrypted service operates.
- Age assurance, moderation and reporting requirements may affect how users access or interact with online services.
- A provider’s decision to change its product or withdraw from the UK would be separate from the Act’s enactment itself.
Timeline after Royal Assent
- 26 October 2023: The Online Safety Bill received Royal Assent and became the Online Safety Act 2023.
- December 2024: The government published the illegal-content codes and related explanatory material.
- 2025: Child-safety risk-assessment and code implementation milestones followed.
- 2026: The government published draft amendments and continued developing the illegal-content regime.
The official Online Safety Act collection records the current implementation material. Ofcom’s implementation roadmap explains why duties have been introduced in stages.
Recommended Free Tools
The bottom line on encryption
The Online Safety Act is a broad online-safety regime, not an explicit blanket encryption ban. Its most contentious feature is the possibility that Ofcom’s technology-notice powers could pressure a service to introduce scanning or another mechanism that changes the privacy and security properties of end-to-end encrypted communication. Whether that happens depends on future notices, technical feasibility, legal safeguards and providers’ responses.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

