Ofcom has issued its first formal enforcement guidance under the UK Online Safety Act, setting out how it will assess platform compliance with duties to prevent children from encountering illegal content including CSAM, grooming and sextortion. The regulator specified that services with more than 7 million users must implement proactive detection technologies by October 2026, with interim assessments beginning in September. Platforms face fines of up to 10 percent of global annual revenue for systemic non-compliance. Ofcom clarified that end-to-end encrypted services are not exempt and must deploy client-side or metadata-based safety measures that do not compromise encryption, a requirement that has drawn immediate pushback from Signal and WhatsApp, both of which have threatened to exit the UK market rather than implement scanning.
The challenge posed by the Act is not whether to protect children or preserve privacy but how to do both simultaneously. Detection that operates at the point of contact, analyzing behavioral patterns and metadata rather than decrypting every message, addresses the underlying harms the regulation targets without requiring blanket access to message content or user identity verification that would affect all users. Guardii's anti-grooming, anti-sextortion and anti-CSAM modules monitor children's direct messages in real time across Instagram, Snapchat, Discord, Roblox and other platforms, flagging hostile or abusive contact based on threat patterns and enabling parents, schools or authorities to intervene before harm escalates, an approach that aligns with the Act's proactive detection mandate while operating within the architecture of encrypted communication.