Midnyte

Online Safety Act

Does the Online Safety Act apply to my app?

The question almost every founder asks is whether they are too small to be caught. The answer is no, and it is worth knowing exactly why, because the pages saying otherwise are usually confusing scope with something else entirely.

There is no size exemption

Not a user threshold, not a revenue threshold, not a headcount threshold. Three places in the primary material say so:

Where the size numbers you have seen come from

There are real thresholds in this regime. None of them is about whether the Act applies to you:

ThresholdWhat it actually decides
7 million monthly UK usersWhether you are a “large service” for the purpose of which Code measures apply to you
34m / 7m / 3m UK usersWhether you are categorised (Category 1, 2A, 2B) and pick up additional duties
£250m qualifying worldwide revenueWhether you have to pay Ofcom a fee

Every one of those sits downstream of being in scope. A service with eleven users is in scope and is simply a small, probably low-risk one. The register of categorised services lists about forty names; Ofcom estimates the number of providers in scope is over a hundred thousand.

Whether your product is a user-to-user service

Section 3(1) defines it as an internet service by means of which content generated directly on the service by one user may be encountered by another user. Section 3(2) adds the part that catches people out: the sharing need only be possible. It does not have to happen, and the proportion of the service given over to it is irrelevant.

So a product with user accounts and any of comments, messaging, profiles, uploads, reviews or a shared workspace is a user-to-user service, even if the feature is minor and even if nobody has used it yet.

The two exemptions a normal software product might actually meet

Schedule 1What it covers
Paragraph 4 — limited functionalityUsers can communicate only by commenting or reviewing the provider’s own content, sharing those comments, or reacting to them. Narrow, and lost the moment you add direct messages or user-to-user file sharing.
Paragraph 7 — internal business serviceThe provider is the business, the content serves internal business purposes, and it is available only to a closed group — employees, officers, authorised contractors. An internal tool qualifies. The same tool sold to customers does not.

The others are narrower still: email only, SMS only, one-to-one voice calls only, public bodies and education providers.

And being outside the UK does not help by itself. Section 4(5) brings in a service with a significant number of UK users or that targets the UK as a market; section 4(6) brings in a service merely usable here where there are reasonable grounds to believe in a material risk of significant harm to UK users.

The deadlines have already passed

This is not a regime arriving next year. If you are in scope, you are late.

DeadlineDuty
16 March 2025Complete the illegal content risk assessment
17 March 2025Illegal content Codes in force — the safety duties bite
16 April 2025Complete the children’s access assessment
24 July 2025Complete the children’s risk assessment, if children’s duties apply
25 July 2025Protection of Children Codes in force
7 April 2026Duty to report detected CSEA content to the National Crime Agency begins

What a small, low-risk service actually has to hold

Ofcom publishes a short list for services that have assessed themselves as low risk. It is genuinely short, and the first item is the one people skip:

Ofcom has also said it is not setting out to penalise small, low-risk services trying to comply in good faith, and that it will usually give a provider the chance to put things right before formal action. That is a posture, not an exemption, and the same page says in-scope services will need to take steps to comply.

The penalties, and what people are actually being fined for

Maximum penalty, Schedule 13 paragraph 4(1)
£18m or 10%

Whichever is greater of £18 million and 10% of qualifying worldwide revenue. Where there is no accounting period, the maximum is £18 million.

Now the more useful observation. Look at what Ofcom has actually fined providers for since enforcement began, and the pattern is not what the headline number suggests: a clear majority of the penalties published through 2025 and 2026 are for failing to respond to Ofcom’s statutory information requests — in several cases a £20,000 penalty plus a daily rate, entirely separate from anything about content.

That is the realistic risk for a small company, and it is the cheapest one in the world to avoid. Open the letter. Reply by the date on it. The companies that have been penalised for content failures were, almost without exception, also ignoring correspondence.

Sources. Definitions and scope: Online Safety Act 2023, Part 2 (sections 3 to 5) and Schedule 1. Penalties: Schedule 13, paragraph 4(1), via section 143. Deadlines: Ofcom, important dates for Online Safety compliance, last updated 24 August 2026. Duties for small and low-risk services, and the record-keeping requirement: Ofcom’s compliance guide and its guidance on illegal content duties, last updated 25 June 2026. Enforcement: Ofcom’s online safety industry bulletins and enforcement updates, published October 2025, March 2026 and June 2026. All retrieved 9 October 2026. The characterisation of the fine pattern is my reading of Ofcom’s published penalties, not an Ofcom statistic — Ofcom publishes no cumulative total. This is a description of published material, not legal advice.

Not sure whether you are in scope?

Tell me what your product lets one user do that another user can see. That single sentence usually settles it — and if you are in scope, the first steps are smaller than the Act makes them sound.

Start here →