Computer & Communication Industry Association
PublishedJune 18, 2026

How the UK social media ban might come unstuck

Responsible companies are working hard to deliver age-appropriate experiences for children through strong defaults with parental oversight. The question is not whether to act, but the right role for regulation in ensuring this is applied consistently, and how the UK can make growing up online safer in a way which is workable and achieves its core goals in practice. 

Unfortunately, the measures announced earlier this week by the UK Government, while undoubtedly reflecting good intentions, will need a lot of work to meet that bar. Ministers should be very careful about preventing teenagers from engaging with digital services which, for many of them, are a valued way to learn new skills, discover new interests, and stay in touch with friends and family. Blanket restrictions will stifle access to age-appropriate experiences with proper parental controls, encouraging children to seek out riskier unregulated alternatives.

The UK Government has moved very quickly from the conclusion of its “National Conversation” to announce sweeping new regulations, including a social media ban for under 16s; blocking specific features for under 16s; restrictions on time use and romantic or sexual chatbots for under 18s; and time use regulation for under 18s. While there is political pressure to move quickly, there are reasons why changes of this sort are normally given time and careful consideration: it is very easy to produce severe unintended consequences.

Details are only starting to emerge and we will return to this question in the coming weeks and months, but based on what we have seen so far there are some obvious pitfalls which Ministers will have to address. While the scale and severity of these issues varies, they will all matter to communities of thousands or millions of users and deserve proper attention.

This is the most basic question and has already led to some confusion with reports, since rejected by Ministers, that certain smaller platforms will be excluded. Ministers have talked about the criteria as if they are simple, mechanical tests for which services are in and out. In Australia though, the basis for the new UK criteria, the process is more akin to the designation process that we have seen for other digital regulations, with these criteria supporting a self-assessment of whether a service should be in scope with the eSafety Commissioner (presumably Ofcom in the UK) making a final decision.

There is a real dilemma here: include every service that meets these criteria and expect rapid UK-specific compliance and engineering work that few companies will be able to deliver, and you could make it very hard for smaller services. If every service isn’t included, there will be a real risk of under 16s drifting into a long tail of smaller social media services without the controls that exist in the mainstream services used today. This is sadly a consequence of adopting blanket measures that can’t embrace the nuance in the risks associated with different services and features in different contexts.

The Government has said that the new rules “layer up” rather than replace any element of the OSA, particularly Part 3 which is in large part focused on user-to-user services such as social media and protecting children. There would still be 16 and 17 year old users for whom the child protection provisions will still be relevant. However the idea that companies will face all of the same regulatory burdens relating to under 18 users when most of the 13-18 age range has been banned from accessing their services seems like it will inevitably mean a lot of wasted effort, with potential impacts on the scope for particularly smaller or newer services to justify investments in age-appropriate services for 16 and 17 year olds. 

At the moment, some of the services in scope for this regulation can be accessed without an account. This is allowed under the Australian ban, which is a ban on having an account, and can be important in practice when you have, for example, content embedded on a web page. The Government claims that it is broadly mirroring the Australian approach but a ban on offering services that could be accessible to under 16s would make this illegal in a way it would not be over there. The treatment of logged-out access is important, was not considered in the consultation, and deserves proper attention.

This is related to the wider issue that the more sensitive to specific age differences an age verification process has to be, assuming the same degree of confidence in the final outcome, the more challenging it will become for users to complete. The more demanding the final implementation of age assurance is in the implementation of these announcements, the greater the costs for adult users and risks to user privacy.

The Government has not published any meaningful evidence on why the specific features chosen here were included in the list as default-off. These choices seem arbitrary without a transparent, evidence-based process.

Livestreaming services, for example, vary considerably from service to service, between different use cases and based on the safety architecture developed in response to those service-specific features. Blanket restrictions on live streaming as a category will produce unintended consequences by missing that nuance.

The Government says that 16 and 17 year olds will be able to turn these features back on once they are “educated about the risks” but it remains unclear if this is something users will be able to do themselves, whether it will require parental approval or something else. 17 year olds able to vote or serve their country, but not by default engage with a Minecraft livestream seems very hard to justify.

The intent is supposed to be addressing concerns about a cliff edge when users are exposed to many digital services for the first time at 18, without the controls applied to services for under 18s at the moment. This concern is still relevant for social media and so it is not clear why the Government felt the right solution was additional controls in these areas specifically.

There are chatbots where the express purpose of the service is to simulate romantic or sexual relationships. It does not seem controversial to say that these are not suitable for children. However the Government has also said that while access to general purpose AI chatbots will not be age gated, features in these services that allow sexually explicit interaction must be restricted to over 18s. If this is not defined carefully, it could mean that any chatbot which a user can convince to simulate a romantic relationship is in breach of the regulation, even if it requires quite a lot of effort and expertise. Any company offering AI services in the UK would need to satisfy itself and evidence to the regulator that it had taken the steps expected to prevent this kind of use, or it being accessed by under 18s.

If the requirement is drawn too broadly, the compliance burden could fall on general purpose services that were never the intended target, with costs that newer and smaller providers in particular would struggle to justify. That would sit awkwardly with the Government’s own ambition for the UK to be the fastest adopter of AI in the G7. The goal should be rules that are proportionate and workable, so that genuinely harmful services are caught without deterring legitimate ones. 

With the best will in the world, there is not unlimited capacity in the trust and safety ecosystem (in companies and the government) that will need to deliver all this change at the same time as implementing the OSA, let alone the demands of other Government initiatives and other jurisdictions and doing its underlying job of protecting users against novel threats.

Just taking these latest announcements and the OSA into account, the next year will include an expansive policy update within a month; the OSA categorisation register being published; implementation of Category 1 / 2A / 2B OSA duties; the response to the OSA additional safety measures consultation; the conclusion of the three month timeline for “meaningful steps” towards blocking the taking and receiving of nude images; implementation of the OSA additional safety measures; an Ofcom statement on strengthening its codes; the Ofcom assessment of how it should apply HEAA to these new powers; the statutory OSA “harmful to children” report; the Online Information Advisory Committee first report; the first regulations for these new measures laid and voted in both Houses of Parliament; the Ofcom statutory report on app store harms; the social media ban coming into force; further regulation laid in Parliament on functionality and AI measures; and OSA finalised categorised duties, policy statements and transparency reports.

Those are just the measures for which we have firm timelines. There is also the laying of the second wave of regulations, bringing into force measures other than the social media ban; any policy outcome of the nude images deadline; measures pushed to the July update such as potential changes to the digital age of consent; transitional arrangements for existing under 16 account holders; and any new funding, fees and fines regime.

To put it mildly, this is a lot of complicated work in a political environment where there can sadly be a political incentive to criticise any delays as organisational failures or worse. In some cases that might be true. In other cases it might reflect a sensible caution when forcing changes to services enjoyed by millions. So many deadlines falling one after another will be a huge challenge for all the organisations involved, particularly challenging for smaller services, and increase the risk of problems in execution.

Ofcom will play an important role in much of the activity described above. The Government has already signalled that it aims to resource the regulator to deliver. Does this mean funding from HM Treasury, or increased levy funding? For a similar service, many companies will pay more to Ofcom to support online safety regulation in the UK under the OSA than to the Commission for the entire EU under its Digital Services Act.

The Government has also signalled that it intends for Ofcom to enforce these new requirements. It is not clear whether this enforcement will involve new sanctions, or be tied to the existing OSA regime.

There may be a temptation to make use of the existing Qualifying Worldwide Revenue (QWR) approach for any fees and/or fines. Unfortunately, as it is defined in Ofcom’s guidance, QWR imposes a disproportionate burden on diversified businesses, or companies where only part of their footprint is in the UK, as they are exposed to fees and/or fines based on economic activity that is outside the OSA’s scope. These problems could be exacerbated if the new regulations take a similar approach.

The Prime Minister gave examples of services that would be exempt: YouTube Kids; Lego Play; and Google Classroom.

If the Government overfits its exemptions to those services as they exist now, companies will not be able to expand their scope to support other activities that under 16s and their parents value (e.g. additional educational content). There will not be a level playing field between different digital services that did or did not happen to already have an exempt service in place that the Government felt it could not ban.

On the other hand, if the Government allows appropriate flexibility and is clear to the regulator that these kinds of exceptions should be clear, functional and based on a balanced consideration of risks and benefits. Then it can be an opportunity to mitigate some of the obstacles to legitimate, valued activity and expand the scope of the age-appropriate experiences available to British under 16s.

Social media as defined in the Government’s announcements is important to many young people. In some instances, they have used it to share memories, music, art and more. In many cases they will have done so and found it a positive experience with no expectation that content would be deleted. There could be real frustration and upset if it is simply lost when their accounts are presumably closed.

The Government has indicated they are aware of this issue, but they need to have a plan. They cannot simply demand that companies solve what may be a complicated and UK-specific engineering requirement to an unrealistic timetable.

The Government has said that it wants to ban under 16s exchanging messages, but not multiplayer gaming. This may be easier said than done. There is a large library of older games that included some kind of ability to exchange messages (normally text) with other players. Companies would have to either require people to prove their age before playing multiplayer games, or deactivate that text chat feature.

The most popular multiplayer games and social media services already have age controls on contact with strangers, with parental approval required to relax those restrictions. For games that may be years or even decades old, but still with active fanbases and new players, there is not going to be the engineering capacity to make the changes this regulation requires. There will be a temptation to simply take those games off the market.

There is already a controversy around older games becoming unplayable when publishers cease to support them. Another wave of games being withdrawn or having multiplayer features deactivated will make that worse.

There is a reason why governments consult before implementing new regulations. The recent “National Conversation” covered all kinds of topics at a necessarily high level and did not outline policy options to anything like the normal level of specificity. Some of the measures proposed now were not included at all. It is not obvious that it intends or has time to go through a proper consultation process for the measures announced this week. That will mean less of the input that will help resolve the kinds of issues that I’ve described in the rest of this article. 

While it is early to talk about lawsuits, consultations also have an important role in showing that the Government has followed due process and thereby mitigating legal risk. There have already been multiple lawsuits over the Australian ban. These measures are more ambitious and onerous. Rushing the policy process and not considering important impacts is the fast route to judicial reviews that could be avoided with a calmer and more open process.

For all the volume of this week’s announcements, many of the specifics that will determine the overall impact have not yet been published. So much of what will determine whether this package works, the default settings for 16 and 17 year olds; the treatment of what the earlier consultation called “persuasive” features and time use for under 18s; the digital age of consent; and what to do about circumvention, has been deferred to the paper the Government has promised in July.

That is a great deal of weight to place on a single document, expected within weeks, which has not itself been consulted on and which will land in the same crowded window as the first wave of Online Safety Act categorisation. If it remains light on detail, the unresolved questions set out here pass straight into legislation largely unanswered. If it is substantive, and engages them honestly, it is the first real opportunity to get the detail right. Either way, the July update deserves at least as much scrutiny as the headline measures this week, and we will return to it when it arrives.

Matthew Sinclair

Senior Director, CCIA UK
Matthew Sinclair is an economist with 15 years experience working in public policy. He has worked on digital policy and strategy as an economic consultant for a wide range of organisations including the UK Government, the EU institutions and major media and technology companies.
Article

The Supreme Court Expands Privacy Rights to More Squarely Encompass Your Digital Footprint

When police cannot identify a suspect, they increasingly turn to technology companies rather than witnesses. The Supreme Court confronted one of the most aggressive versions of this practice in Chatri...
  • Privacy
Article

In Pictures: European AI Roundtable on Copyright – Fuelling Creativity in the AI Age 

On 2 June 2026, the Computer & Communications Industry Association (CCIA Europe) hosted the latest edition of its European AI Roundtable in Brussels. The event brought together EU policymakers, le...
Article

The DMA Security Paradox: Balancing Openness and User Safety in the Mobile Age

More than two years into enforcement of the Digital Markets Act (DMA), one of its most difficult challenges is becoming increasingly clear: how can digital ecosystems be opened to greater competition ...
Article

Functional App Stores Aren’t a Tax

Two “studies” this week discussed in the Daily Mail purport to show a large imposition on consumers. They describe almost all the costs associated with running an app store -- including keeping us...
  • Digital Economy