Any organisation whose digital service reaches children in both the United Kingdom and the European Union now answers to two regulators with two rulebooks. Ofcom enforces the UK Online Safety Act. The European Commission and national Digital Services Coordinators enforce the EU Digital Services Act. Both are in active enforcement. Both carry penalties large enough to change board behaviour. And both ask a question that is easy to state and hard to answer: can you show that your service is safe for the children who use it?

What is the difference between the UK Online Safety Act and the EU Digital Services Act for children?

The Online Safety Act imposes specific, code-backed duties on services likely to be accessed by children: assess the risk of harm, use highly effective age assurance where content is harmful to children, and comply with Ofcom's Protection of Children Codes. The Digital Services Act imposes a general duty on all online platforms accessible to minors to ensure a high level of privacy, safety and security, with detailed Article 28 guidelines from the Commission setting out what that means in practice, and heavier systemic obligations on the very largest platforms. The UK regime is more prescriptive; the EU regime is broader and more principles-based.

The UK Online Safety Act

Ofcom's Protection of Children Codes of Practice have been in force since 25 July 2025. Services that are likely to be accessed by children must have completed a children's risk assessment and implemented the safety measures in the codes. The headline duties are:

  • Highly effective age assurance wherever a service allows content that is harmful to children, including pornography, self-harm and suicide content, and eating disorder content. Self-declaration does not count.
  • Safer algorithms and feeds so that harmful content is filtered out of children's recommendations rather than merely removed after the fact.
  • Effective reporting and complaints that children can actually use, with responses that happen.
  • Named senior accountability for children's safety.

Penalties reach £18 million or 10 per cent of qualifying worldwide revenue, whichever is higher, and Ofcom can seek business disruption measures against non-compliant services. Ofcom has opened investigations and issued fines in its first year of enforcement, so the regime is not theoretical.

The EU Digital Services Act

Article 28 of the Digital Services Act requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security for minors. On 14 July 2025 the European Commission published guidelines on how to meet that duty. They cover age assurance that is proportionate to risk, default-private accounts for minors, limits on features that drive compulsive use, protection from harmful recommender systems, and the availability of parental controls. Very large online platforms carry further systemic risk-assessment and mitigation duties, including specific attention to the rights of the child.

Enforcement is shared. The Commission supervises the largest platforms directly. For everyone else, the Digital Services Coordinator in the country where the service is established leads, which is why Ireland's Coimisiún na Meán supervises so many services for the whole Union. Fines reach 6 per cent of worldwide annual turnover.

Where the regimes converge

For a child-facing service, three things are now required on both sides of the Channel:

  1. A documented risk assessment that specifically considers children. Ofcom calls it a children's risk assessment. The Commission expects it under Article 28 and, for large platforms, under the systemic risk provisions.
  2. Age assurance proportionate to the harm. The UK sets a higher bar of "highly effective" for the most harmful content. The EU asks for proportionality and points towards the Union's age verification framework. A service built to the UK standard will generally satisfy the EU standard for the same content; the reverse is not always true.
  3. Safety by design in feeds, defaults and features. Both regimes have moved beyond content takedown to how the service is built.

Where they diverge, and why it matters

  • Prescription versus principles. Ofcom's codes tell you what to do; the Commission's guidelines tell you what good looks like. Organisations used to one style can under-deliver on the other.
  • Scope. The Online Safety Act reaches user-to-user and search services with links to the UK, including small ones, with duties scaled to size and risk. The Digital Services Act's Article 28 applies to online platforms, with the heaviest duties reserved for very large platforms.
  • Regulatory posture. Ofcom is a single regulator with a public enforcement programme. The EU runs a network of national coordinators plus the Commission, with more variation in speed and priorities.
  • The AI question. Neither instrument was written for generative AI or AI companions, but both are being read to cover them. Ofcom has been explicit that chatbots and generative features in user-to-user services fall within the Act. The EU's separate AI Act adds obligations for high-risk systems, including AI used in education, though the timing of those obligations has been the subject of a proposed deferral. The safest assumption is that a child-facing AI feature will be assessed under all three.

What this means for organisations that are not platforms

Most NGOs, schools, health providers and public bodies are not "services" under either Act. They are affected all the same. The platforms they use to reach children are changing their defaults, age gates and feature sets under regulatory pressure. The organisations that fund and inspect them are starting to expect the same discipline: a written assessment of digital risk to children, evidence from providers, and a safeguarding policy that covers online and AI risk.

A child-rights approach is the most durable way to meet both regimes and the expectations that follow them. The UN Convention on the Rights of the Child and General Comment 25 ask you to understand the risks children face, to balance protection against participation and privacy, and to document your reasoning. Those are also the three things Ofcom and the Digital Services Coordinators will ask to see.

Frequently asked questions

Does a service that complies with the UK Online Safety Act automatically comply with the Digital Services Act? No. There is significant overlap, and a service built to Ofcom's Protection of Children Codes will usually meet the substance of Article 28, but the EU regime has its own documentation, transparency and coordination requirements, and very large platforms carry additional systemic duties.

Who is the regulator for the Digital Services Act in my country? Each member state has designated a Digital Services Coordinator. For services established in Ireland, which includes many of the largest platforms, it is Coimisiún na Meán. The European Commission supervises very large online platforms and search engines directly.

Does either regime apply to AI chatbots used by children? Ofcom has said that generative AI features within user-to-user or search services are in scope of the Online Safety Act. Under EU law, chatbots on an online platform fall within the Digital Services Act, and the AI Act adds obligations depending on the system's risk classification.

What is "highly effective" age assurance? Ofcom's term for age checks that are technically accurate, robust, reliable and fair. Methods such as photo-ID matching, facial age estimation and open banking can qualify. Self-declaration and general contractual restrictions do not.

What should a child-facing organisation do first? Map which services reach children and in which jurisdictions. Complete a children's risk assessment that satisfies the stricter regime. Ask every platform provider for evidence of its own compliance. Write down what you found and what you changed.

Regulatory details cited here are accurate as of September 2026 and should be checked against Ofcom and the European Commission before being relied on in a compliance decision.

Work with Maryam

Looking for expert guidance on child safeguarding, online safety, or AI governance? Maryam and the Child Safe ME team are here to help.

Get in Touch