Skip to content
UK OSAOfcomage assurancechildren's safetyrisk assessment

UK Online Safety Act Duties for Children's Services

Children's access assessment, children's risk assessment, the Protection of Children Codes and highly effective age assurance, with Ofcom's 2025 deadlines.

Landfall ยท Published 5 September 2026

The Online Safety Act 2023 gives Ofcom the job of regulating user-to-user and search services accessible from the UK, and it reserves a distinct set of duties for services likely to be accessed by children. Those duties became enforceable in 2025. This article sets out the sequence a service goes through: the children's access assessment, the children's risk assessment, the safety duties that follow, Ofcom's Protection of Children Codes, and the requirement for highly effective age assurance where the most harmful content is involved. It is written for the product, privacy and trust-and-safety leads who have to turn those duties into work.

Which services are in scope

The Act covers user-to-user services, where users can encounter content generated by other users, and search services. A service is in scope if it has links with the UK: a significant number of UK users, the UK as a target market, or content that presents a material risk of significant harm to UK users. Size does not remove a service from scope; it changes which code measures Ofcom expects. Ofcom's fines can reach 18 million pounds or 10 percent of qualifying worldwide revenue, whichever is higher.

Step one: the children's access assessment

Under sections 35 and 36, every in-scope service must assess whether it is possible for children to access the service and, if so, whether the child user condition is met, meaning that a significant number of users are children or the service is likely to attract them. A service can only conclude that children cannot access it if it uses age assurance that is highly effective at preventing them. A statement in the terms of service that users must be 18 does not count.

Ofcom published its guidance on children's access assessments in January 2025 and expected services to complete the assessment within three months, by April 2025. A service that concluded it was likely to be accessed by children then moved to the next step; a service that concluded otherwise must keep the assessment under review and repeat it if anything changes. Ofcom has said it expects most services to be in scope.

Step two: the children's risk assessment

Sections 11 (user-to-user) and 28 (search) require a suitable and sufficient children's risk assessment, kept up to date. The assessment identifies the risk of children in different age groups encountering harmful content, the nature and severity of that harm, how the design and features of the service affect it, and how the service's own systems, such as recommender systems, contribute.

The Act defines the content in scope. Primary priority content harmful to children, in section 61, covers pornographic content and content that encourages, promotes or provides instructions for suicide, self-harm or eating disorders. Priority content harmful to children, in section 62, covers abusive or hateful content, bullying, content depicting serious violence, dangerous stunts and challenges, and content encouraging the self-administration of harmful substances. Non-designated content that presents a material risk of significant harm is also caught.

Ofcom published its children's risk assessment guidance alongside the Protection of Children Codes in April 2025, and children's risk assessments were due by 24 July 2025. The assessment must be recorded, and section 23 record-keeping duties apply to it.

Step three: the safety duties and the codes

Sections 12 and 29 set the safety duties protecting children. For user-to-user services the core duty has two limbs: prevent children of any age from encountering primary priority content, and protect children in the age groups judged to be at risk from priority content and non-designated harmful content. The Act also requires the service to consider the age groups of its users, to have clear terms explaining how children are protected, and to give users a way to report content and complain.

The Protection of Children Codes set out the measures Ofcom recommends for meeting those duties. Following the code measures is one way to comply; a service can take alternative measures but must record why they are at least as effective. The child protection duties came into force on 25 July 2025, the day after the risk assessment deadline. The codes cover, among other things, safer recommender feeds for children, faster content moderation for harmful content, support for children who encounter it, and governance measures such as a named accountable person.

Highly effective age assurance

Section 12 requires a user-to-user service to use age verification or age estimation, or both, to prevent children from encountering primary priority content, and the method must be highly effective at correctly determining whether a user is a child. Ofcom's guidance describes the criteria: technically accurate, robust, reliable and fair. Methods Ofcom considers capable of being highly effective include photo identification matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services, open banking and email-based age estimation. Self-declaration, and payment methods that do not require the user to be an adult, are not.

Where a service does not restrict primary priority content, highly effective age assurance is the expectation across the service. Where it does restrict such content behind a gate, the assurance applies at the gate. Either way, the service must still meet the children's duties for the rest of the content. The age assurance comparison sets out the methods and their data costs.

A worked example

Hollowbrook, a fictional company, runs a hobbyist forum for tabletop games with 200,000 UK monthly users. It has no age gate. The access assessment concludes that children can access the service and that it is likely to attract them, since school-age players are a visible part of the community. The risk assessment finds a low risk of primary priority content but a real risk of bullying in direct messages and occasional violent imagery in user uploads. The team adopts the code measures: direct messages from non-connections off by default for accounts that identify as under 18, a reporting flow that routes bullying reports to a moderator within a set time, and a hash-matching filter on uploads. Since it does not host primary priority content, it decides not to gate the whole service, records that reasoning, and schedules the risk assessment for annual review and after any feature change that affects content discovery.

How Landfall helps

Landfall holds the Act's children's duties as structured obligations with section references, including the access assessment, the risk assessment, the safety duties, age assurance and record keeping, and maps them onto a project once the questionnaire establishes UK links and the presence of user-generated content. Answers about content types and about the age assurance in place decide whether the highly effective age assurance items fire and whether the primary priority content limb applies. Each item keeps its citation, so a reviewer can trace it to the section and to Ofcom's code measure. Browse the obligations in the UK Online Safety Act explorer, and read the UK AADC checklist for the data protection side of the same product.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

What is a children's access assessment?
Under sections 35 and 36 of the Act, every in-scope service must assess whether children can access it and, if so, whether a significant number of users are children or the service is likely to attract them. Only highly effective age assurance supports a conclusion that children cannot access the service.
When were the children's duties enforceable?
Ofcom expected children's access assessments by April 2025, three months after its January 2025 guidance. Children's risk assessments were due by 24 July 2025, and the safety duties protecting children, with the Protection of Children Codes, came into force on 25 July 2025.
What is primary priority content harmful to children?
Section 61 names pornographic content and content that encourages, promotes or provides instructions for suicide, self-harm or eating disorders. A user-to-user service must prevent children of any age from encountering it, using highly effective age assurance where such content is allowed.
Does a service have to follow Ofcom's codes?
Following the code measures is one way to comply and gives a safe route. A service may take alternative measures but must record why they are at least as effective. Either way the risk assessment and the record-keeping duties apply.

Sources

For informational purposes only. This guide is summary-level, informational writing โ€” not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations