A Year of Enforcement, and Unintended Consequences

July 25th, 2026 marks one year since the Online Safety Act's landmark child safety duties came into force in the UK. The anniversary offers a natural checkpoint to ask what has actually changed since platforms were required to implement age verification, content moderation, and child protection measures under threat of regulatory action.

The numbers tell part of the story. Ofcom, the UK's communications regulator, has opened 30 investigations into platforms over the past year, and issued fines in the region of £4 million GBP for statutory violations. Those figures suggest a regulator willing to use its enforcement powers, but they also raise a harder question: has the Online Safety Act achieved its intended goal of protecting children online, or has it produced side effects that its architects didn't anticipate?

Age Verification Tools Under Scrutiny

One of the most visible unintended consequences has been the scramble by platforms to deploy age verification and age-inference systems, often built quickly and with limited public scrutiny. These tools are meant to keep children away from harmful content, but they've introduced new privacy tradeoffs of their own.

A clear example of this tension is Ofcom's own investigation into TikTok's biometric age-inference tool. Regulators are examining whether the platform's age-inference system actually meets the standards required under the Online Safety Act. The irony is notable: a law designed to protect user safety has prompted the rollout of biometric scanning technology that itself raises data protection concerns. Users are effectively being asked to trust that facial or behavioral analysis used to estimate their age is accurate, proportionate, and not being repurposed or retained beyond its stated function.

This pattern, where compliance mechanisms create new privacy exposure, is at the heart of what critics call the Act's unintended consequences. Age verification requires collecting some form of identifying data, whether that's a government ID, a credit card check, or biometric analysis. Each of those methods creates a new dataset, a new attack surface, and a new point of failure that didn't exist before the law took effect.

The VPN Uptick and What It Signals

Among the more telling behavioral shifts over the past year has been a documented uptick in VPN usage in the UK. This isn't surprising. When platforms restrict access based on age verification, geographic location, or content moderation policies, some users respond by routing around those restrictions entirely.

This matters for two reasons. First, it suggests that a portion of the Act's intended safeguards may be less effective than assumed, since a VPN can mask a user's actual location or apparent identity, complicating the accuracy of geographic or behavioral age-inference tools. Second, it signals a broader public discomfort with the tradeoffs the Act has introduced. People aren't necessarily trying to access harmful content; many are simply uncomfortable handing over biometric data or ID verification to access ordinary services, and a VPN offers a straightforward way to sidestep that requirement.

Privacy advocates have pointed to this as evidence that the Act, whatever its child safety intentions, has nudged a meaningful slice of the population toward tools and behaviors that reduce their overall visibility online, not because they have anything to hide, but because they'd rather not be scanned, verified, or logged simply to browse the internet.

What This Means For You

If you're a UK internet user, the past year has likely changed how you interact with certain platforms, even if you haven't noticed every mechanism behind it. Age verification prompts, biometric checks, and stricter content gates are now part of the landscape. If you've found yourself reaching for a VPN more often, you're not alone, and it's worth understanding what a VPN can and can't do in this context: it can mask your location and IP address, but it won't necessarily prevent a platform from asking for age verification through other means.

It's also worth paying attention to how platforms handle the data collected during age verification. Look for clear retention policies and understand whether biometric data is processed locally or sent to third parties.

Actionable Takeaways

As the Online Safety Act enters its second year, a few practical steps can help you navigate the changes:

  • Review the privacy policies of platforms that require age verification before submitting ID or biometric data.
  • If you use a VPN to manage access restrictions, choose a reputable provider with a clear no-logs policy.
  • Stay informed about regulatory actions like Ofcom's investigations, since they often reveal which platforms are handling verification data responsibly and which aren't.
  • Advocate for transparency by supporting calls for clearer disclosure on how age verification data is stored and used.

The Online Safety Act was built to protect children, and enforcement activity shows regulators are serious about that mission. But its first year also shows that safety and privacy don't always align neatly, and staying informed is the best way to protect both.