❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 July 2026IT Security

Examining the Unintended Consequences of the Online Safety Act

24 July 2026 at 07:43

The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.

The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content.Β 

One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.Β Β 

Today, we’re examining the unintended consequences of the Act… 

Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: β€œOfcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.”

Uptick in VPN UsageΒ 

For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPN’s 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July.Β 

Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out β€˜free’ or not reputable VPNs, posing a significant security risk: β€œThe biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users don’t seek out reputable providers – they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.”

Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: β€œPeople engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, it’s still going through a server somewhere, and most people don’t stop to think about who’s operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.”

A Lack of Measurable Outcomes?Β 

But is the ban on children accessing adult sites actually working? Some experts argue that there’s no hard evidence to back it up.

Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said:Β  β€œOfcom’s recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.”

Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: β€œStats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of Β£4 million GBP. Unfortunately they have also identified β€˜enforcement gaps’ where AI and algorithmic content are concerned.”

β€œThis item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at Β£55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a Β£520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they aren’t performing particularly well.”

Examining Data Storage and Verification System Security

Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: β€œFor many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.”

Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: β€œThe biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now we’ve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. That’s strengthened online safety, but it’s also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.”

So what should age verification providers be doing?

Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: β€œBusinesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.”

On Trust and Risk

The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: β€œContent moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. That’s a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and it’s had almost no public discussion compared to the technical side of compliance.”

β€œOrganisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,” Ward noted.Β 

Β 

The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.

Before yesterdayIT Security

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

23 July 2026 at 11:09

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.

The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

23 July 2026 at 08:42

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.

The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.

OpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceΒ 

22 July 2026 at 03:48

OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality.

The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceΒ  appeared first on SecurityWeek.

Cisco Launches Low-Cost AI Models for Source Code Security

21 July 2026 at 13:44

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed β€˜Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: β€œBritain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

β€œIncoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued.Β 

Dray Agha, Senior Manager of Security Operations at Huntress, added: β€œSmart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

β€œSafely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a β€˜middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: β€œThe UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

β€œThe UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said: Β β€œIf the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

β€œThe biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, β€œthe Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

❌
❌