"has made absolutely no difference," children told Dame Rachel de Souza, the Children's Commissioner, about the UK's Online Safety Act, according to evidence she gave to the House of Lords Communications and Digital Committee.
Dame Rachel de Souza on children's experience
More than a year after the Online Safety Act's key child protection duties took effect, Dame Rachel de Souza told MPs and peers that young people reported little understanding of the legislation or how it was intended to change their online experiences. She said children told her the law "has made absolutely no difference" to their ability to access harmful content online. De Souza described being "really cross" that there was no hard evidence showing the OSA had meaningfully changed how social media platforms operate, and argued the law had "not been flexible enough" and had not "kept up with the time."
Ofcom, section 393(1) of the Communications Act 2003, and risk assessments
De Souza said she planned to exercise her statutory powers to compel Ofcom to provide copies of the safety risk assessments submitted by technology companies, after the regulator refused to share them with her. She told the committee Ofcom had declined disclosure despite her role as "the most senior safeguarding person in this country for children," and had signalled it would resist disclosure even if she invoked those powers.
The legal constraint De Souza cited is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies. De Souza asked the committee for assistance, framing access to those risk assessments as critical to judging whether the OSA had produced effective safety mechanisms.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe proposed Meta settlement and design-focused measures
De Souza contrasted the UK's legislative approach with recent legal pressure in the United States, which she said had pushed Meta toward significant child safety concessions. The proposed Meta settlement — described in evidence she referenced — would see, without an admission of wrongdoing, "Zuckercorp" introduce measures including two-hour daily limits for users under 18 on Facebook and Instagram, prompts intended to discourage endless scrolling, restrictions for use during school hours and at night, and the option for children to opt out of algorithmically ranked feeds. De Souza highlighted that those concessions would directly address the platform design features UK politicians had urged regulators to tackle — features she said the OSA emphasised too little, favouring content moderation over design controls.
Ofcom's recent interventions: Grok 'nudifying' furore and age verification investigations
De Souza acknowledged that Ofcom "has materially upped its presence in the tech regulation landscape during the past year," citing interventions at the height of the Grok nudifying furore and the regulator's "sprawling list of investigations into pornography companies allegedly violating age verification requirements." Nevertheless, she argued Ofcom had too often reacted to harms rather than anticipated them, and called for the regulator to "use its teeth," impose "some big fines," and act before new harms become entrenched.
When The Register asked Ofcom to respond, a spokesperson said: "We work closely with the Children's Commissioner and share her objectives to ensure children are safe online." The spokesperson also noted: "In December, we published our analysis of risk assessments from the first year of the Online Safety Act being in force, and the improvements we expected to see from platforms. Our action has resulted in material improvements being made to risk assessments, ensuring that tech companies must implement all measures necessary to address the risks identified on their sites and apps." The statement reiterated legal limits: "We are subject to laws that mean we're restricted in what information we can disclose relating to businesses."
What this means for children, Ofcom, and UK politicians
- Children: According to De Souza, many young people say the OSA has had no perceptible effect on their day-to-day online exposure to harmful material, and they remain worried about new harms "around AI" and "nudifying apps."
- Ofcom: The regulator is publicly defending its record, pointing to December's published analysis and claimed improvements to risk assessments, while facing calls from De Souza to disclose those assessments to allow independent scrutiny and to act more proactively.
- UK politicians: De Souza urged lawmakers to be "really strong and direct" in empowering Ofcom and to consider evolving legislation so it can deliver protections comparable to those emerging from US legal pressure on platforms.
De Souza's testimony framed a central friction: compulsory company risk assessments exist, but legal disclosure limits and disagreement over enforcement and regulatory scope leave the value of those assessments contested. Her public readiness to invoke statutory powers, and her call for politicians to give Ofcom clearer authority and willingness to use fines and other powers, sets distinct lines of debate for the committee conducting the inquiry into the OSA's implementation and impact.



