The Online Safety Act 2023 gives Ofcom the job of regulating user-to-user and search services accessible from the UK, and it reserves a distinct set of duties for services likely to be accessed by children. Those duties became enforceable in 2025. This article sets out the sequence a service goes through: the children's access assessment, the children's risk assessment, the safety duties that follow, Ofcom's Protection of Children Codes, and the requirement for highly effective age assurance where the most harmful content is involved. It is written for the product, privacy and trust-and-safety leads who have to turn those duties into work.
Which services are in scope
The Act covers user-to-user services, where users can encounter content generated by other users, and search services. A service is in scope if it has links with the UK: a significant number of UK users, the UK as a target market, or content that presents a material risk of significant harm to UK users. Size does not remove a service from scope; it changes which code measures Ofcom expects. Ofcom's fines can reach 18 million pounds or 10 percent of qualifying worldwide revenue, whichever is higher.
Step one: the children's access assessment
Under sections 35 and 36, every in-scope service must assess whether it is possible for children to access the service and, if so, whether the child user condition is met, meaning that a significant number of users are children or the service is likely to attract them. A service can only conclude that children cannot access it if it uses age assurance that is highly effective at preventing them. A statement in the terms of service that users must be 18 does not count.
Ofcom published its guidance on children's access assessments in January 2025 and expected services to complete the assessment within three months, by April 2025. A service that concluded it was likely to be accessed by children then moved to the next step; a service that concluded otherwise must keep the assessment under review and repeat it if anything changes. Ofcom has said it expects most services to be in scope.
Step two: the children's risk assessment
Sections 11 (user-to-user) and 28 (search) require a suitable and sufficient children's risk assessment, kept up to date. The assessment identifies the risk of children in different age groups encountering harmful content, the nature and severity of that harm, how the design and features of the service affect it, and how the service's own systems, such as recommender systems, contribute.
The Act defines the content in scope. Primary priority content harmful to children, in section 61, covers pornographic content and content that encourages, promotes or provides instructions for suicide, self-harm or eating disorders. Priority content harmful to children, in section 62, covers abusive or hateful content, bullying, content depicting serious violence, dangerous stunts and challenges, and content encouraging the self-administration of harmful substances. Non-designated content that presents a material risk of significant harm is also caught.
Ofcom published its children's risk assessment guidance alongside the Protection of Children Codes in April 2025, and children's risk assessments were due by 24 July 2025. The assessment must be recorded, and section 23 record-keeping duties apply to it.
Step three: the safety duties and the codes
Sections 12 and 29 set the safety duties protecting children. For user-to-user services the core duty has two limbs: prevent children of any age from encountering primary priority content, and protect children in the age groups judged to be at risk from priority content and non-designated harmful content. The Act also requires the service to consider the age groups of its users, to have clear terms explaining how children are protected, and to give users a way to report content and complain.
The Protection of Children Codes set out the measures Ofcom recommends for meeting those duties. Following the code measures is one way to comply; a service can take alternative measures but must record why they are at least as effective. The child protection duties came into force on 25 July 2025, the day after the risk assessment deadline. The codes cover, among other things, safer recommender feeds for children, faster content moderation for harmful content, support for children who encounter it, and governance measures such as a named accountable person.
Highly effective age assurance
Section 12 requires a user-to-user service to use age verification or age estimation, or both, to prevent children from encountering primary priority content, and the method must be highly effective at correctly determining whether a user is a child. Ofcom's guidance describes the criteria: technically accurate, robust, reliable and fair. Methods Ofcom considers capable of being highly effective include photo identification matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services, open banking and email-based age estimation. Self-declaration, and payment methods that do not require the user to be an adult, are not.
Where a service does not restrict primary priority content, highly effective age assurance is the expectation across the service. Where it does restrict such content behind a gate, the assurance applies at the gate. Either way, the service must still meet the children's duties for the rest of the content. The age assurance comparison sets out the methods and their data costs.
A worked example
Hollowbrook, a fictional company, runs a hobbyist forum for tabletop games with 200,000 UK monthly users. It has no age gate. The access assessment concludes that children can access the service and that it is likely to attract them, since school-age players are a visible part of the community. The risk assessment finds a low risk of primary priority content but a real risk of bullying in direct messages and occasional violent imagery in user uploads. The team adopts the code measures: direct messages from non-connections off by default for accounts that identify as under 18, a reporting flow that routes bullying reports to a moderator within a set time, and a hash-matching filter on uploads. Since it does not host primary priority content, it decides not to gate the whole service, records that reasoning, and schedules the risk assessment for annual review and after any feature change that affects content discovery.
How Landfall helps
Landfall holds the Act's children's duties as structured obligations with section references, including the access assessment, the risk assessment, the safety duties, age assurance and record keeping, and maps them onto a project once the questionnaire establishes UK links and the presence of user-generated content. Answers about content types and about the age assurance in place decide whether the highly effective age assurance items fire and whether the primary priority content limb applies. Each item keeps its citation, so a reviewer can trace it to the section and to Ofcom's code measure. Browse the obligations in the UK Online Safety Act explorer, and read the UK AADC checklist for the data protection side of the same product.