The 25th July 2026 marks one year since the Online Safety Actβs landmark child safety duties came into force, making it a natural moment to assess whatβs changed, whatβs worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.
The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content.Β
One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.Β Β
Today, weβre examining the unintended consequences of the Actβ¦Β
Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: βOfcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.β
Uptick in VPN UsageΒ
For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPNβs 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July.Β
Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out βfreeβ or not reputable VPNs, posing a significant security risk: βThe biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users donβt seek out reputable providers β they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.β
Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: βPeople engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, itβs still going through a server somewhere, and most people donβt stop to think about whoβs operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.β
A Lack of Measurable Outcomes?Β
But is the ban on children accessing adult sites actually working? Some experts argue that thereβs no hard evidence to back it up.
Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said:Β βOfcomβs recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.β
Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: βStats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of Β£4 million GBP. Unfortunately they have also identified βenforcement gapsβ where AI and algorithmic content are concerned.β
βThis item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at Β£55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a Β£520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they arenβt performing particularly well.β
Examining Data Storage and Verification System Security
Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: βFor many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.β
Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: βThe biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now weβve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. Thatβs strengthened online safety, but itβs also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.β
So what should age verification providers be doing?
Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: βBusinesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.β
On Trust and Risk
The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: βContent moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. Thatβs a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and itβs had almost no public discussion compared to the technical side of compliance.β
βOrganisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,β Ward noted.Β
Β
The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.