Ofcom released detailed codes of practice on 14 August 2024 under the UK Online Safety Act, mandating that Category 1 services deploy proactive technology to identify and remove child sexual abuse material, including AI-generated and synthetic imagery, with the regulator specifying that platforms must use a combination of hash-matching, image classification and behavioural signals to detect illegal content. The guidance clarifies that services face fines up to 10 percent of global annual revenue for non-compliance and sets a 90-day implementation window for the largest platforms, while acknowledging ongoing debate over the feasibility of scanning end-to-end encrypted messages without undermining user privacy.
Targeted interception addresses the statutory duty without the architecture tension that encrypted-messaging mandates create. A Meta Business Partner platform combining anti-CSAM detection with anti-grooming and anti-sextortion modules monitors direct-message exchanges across services in real time, identifying coercive image solicitation and known or novel abuse material through pattern recognition rather than bulk decryption, blocking hostile contact before it reaches the child and surfacing a safeguarding alert to the responsible adult or institution when risk thresholds are met, operationalising the harm-prevention intent of the Act while preserving the confidentiality of legitimate conversations.