Introduction to the Safety Act
The Online Safety Act 2023 was heralded by the Conservative Government as the solution for making Britain the “safest place to be online“. Coming into force on 26 October 2023, the act imposed sweeping new obligations on digital platforms – from major social networks to discussion forums and even hobbyist websites – to mitigate, identify and manage risks arising from illegal and ‘harmful’ content, especially for children. Providers that fail to comply face fines of up to £18 million or 10% of global turnover, and Ofcom, as the new regulator, has been granted far-reaching enforcement powers, including the ability to block entire sites from the UK.
But as the first deadline, 25 July 2025, has passed for compliance with stringent age verification and risk assessment requirements, the British public, civil rights advocates, and online communities are already seeing the sweeping and controversial impacts of this broad legislation.
Wikipedia’s legal challenge and threat of blocking UK users
Most notably, the Wikimedia Foundation, which runs Wikipedia, has mounted a High Court challenge against the act. The core of their concern is a requirement for “Category 1” platforms (over 7 million users) to enforce ID checks on both anonymous volunteer moderators and visitors. Wikimedia argues this would devastate volunteer privacy; the foundation is threatening headline-making blocks of UK users, and says the requirement would undermine Wikipedia’s global crowd-sourced openness. Without legislative changes, UK access could soon be capped or outright blocked – a preview of the chilling effect sweeping regulatory powers can have even on the world’s “most trusted” encyclopedia.
This regulation of Wikimedia in the UK is not an isolated case – Wikipedia has been censored or blocked for political, religious or control reasons, by governments in China, Iran, Myanmar, Pakistan, Russia, Saudi Arabia, Syria, Tunisia, Turkey, Uzbekistan, Venezuela, and Turkmenistan.
Political impact across the spectrum
The law’s impact has not fallen along traditional left-right lines. People of all political stripes have faced censorship, content restrictions, and account issues; protest footage from across the spectrum and discussions about government policy have both faced moderation or blocks. Rather than drawing a clear line between legitimate harm and protected speech, the act’s broad scope has enabled regulatory overreach and friction for communities of all kinds.
Impact on platforms and industry resistance
Bluesky, the decentralised social network, implemented age verification systems – including face, ID, and payment card checks – specifically for UK users, in order to comply with the act.
Apple has gone so far as to withdraw its most private security options, such as Advanced Data Protection for iCloud, and take legal action over UK government attempts to compel built-in decryption, citing user privacy and the global norm of secure, encrypted storage.
Circumvention of the requirements is widespread already
Unsurprisingly, a boom in Virtual Private Networks (VPNs) has followed the act’s enforcement, as savvy users turn to such tools to sidestep UK geo-fencing and age checks, where pretending to live in a different country by using a VPN gets around the UK requirement to age-verify. VPNs have been widely promoted, including via sponsored YouTube influencers and online communities, as an everyday tool to regain privacy and access. Innovative workarounds have proliferated – some Discord users have bypassed face verification by uploading a picture of a video game character as their ‘ID’. But the system is also rife with flaws: Discord users have reported suspensions even after submitting legitimate identification.
Reddit’s UK users now have to provide a government-issued ID or a selfie for third-party age verification companies just to view NSFW (Not Safe For Work) content, putting sensitive personal information into the hands of unregulated vendors. The Open Rights Group (ORG) has repeatedly sounded the alarm on these issues, highlighting the lack of any public register of age verification providers, the absence of enforceable privacy and security standards for ID holders, and the risk of data breaches and hacks.
Parliament petition and Government response
A public petition calling for the repeal of the Online Safety Act has gathered over 400,000 signatures to date, easily surpassing the 100,000 threshold to force parliamentary debate. The government response has been unyielding, reaffirming commitment to the act’s ‘proportionate’ ambitions and Ofcom’s tailored approach depending on service type and risk.
[…] The Government has no plans to repeal the Online Safety Act, and is working closely with Ofcom to implement the Act as quickly and effectively as possible […] Proportionality is a core principle of the Act and is in-built into its duties. […] Ofcom will take a sensible approach to enforcement with smaller services that present low risk to UK users, only taking action where it is proportionate and appropriate, and will focus on cases where the risk and impact of harm is highest.
International parallels – the EU, Ireland, Ukraine, Australia, and the US
The UK is not alone. Across the European Union, the Digital Services Act (DSA) now requires platforms to significantly step up content moderation and age verification. EU states are rolling out a prototype verification app to be tested in Denmark, Greece, Spain, France and Italy, and Ireland is already enforcing similar codes on platforms like X, Facebook, and TikTok. In Ukraine (an EU candidate country), residents will soon need to use the same sort of verification app for social media. The era of fully anonymous online use is dwindling.
Australia, for its part, is introducing sweeping age verification requirements for search engines and other services, potentially requiring biometric face scans or identity checks to access even Google, in a move strongly criticised for its privacy and inclusion implications, as not everyone has a mobile or credit card to verify. Meanwhile, the US Congress is debating the ‘Kids Online Safety Act’, with significant bipartisan support but also warnings of overreach and a legislative ‘arms race’ with Britain and Europe.
The coming struggle over privacy tools
Proposals from the UK Labour Party in 2022, and pressure to restrict or even ban VPNs, risk placing the UK in the company of authoritarian regimes – countries like China, Belarus, Iran, and Turkey – that criminalise private, encrypted internet access to maintain government control over dissent and information. As Freedom House and digital rights advocates have warned, bans or heavy restrictions on VPNs are classic markers of digital authoritarianism.
Platform regulation, not privacy erosion
Traditional social democratic parties in Europe (Party of European Socialists, Progressive Alliance, Socialist International) have been in favour of strong platform regulation, urging the robust enforcement of measures against disinformation and hate, while supporting democratic protections and transparency. They have called for effective, proportionate tools, but have not advocated bans on privacy reserves like VPNs, nor mass-identification regimes for ordinary citizens. Their focus remains on platform accountability, not mass surveillance.
Impact on the vulnerable: LGBTQ and marginalised communities
The ID requirement especially imperils LGBTQ+ users, and particularly trans or non-binary people, whose identity documents may reflect a deadname or the wrong gender marker. For such individuals, being forced to match an outdated or incorrect legal identity is a potential source of harassment, outing, or denial of service. Additionally, the expansion of backdoors, and mass scanning of private communications, introduce unacceptable surveillance risks for those who already face discrimination, both in the UK and globally.
Undermining encryption and the security of private communications will harm LGBTQ+ people. It will harm them in the UK, where their private data could be exposed, and worldwide, setting a precedent for mass surveillance…
Anonymity, freedom of expression, and Council of Europe guidelines
The Council of Europe has articulated a clear principle: anonymity is a legitimate protection of privacy and free expression. While member states can take proportionate measures to trace those responsible for criminal acts, they should not compromise the right to be anonymous online, or criminalise the use of protective tools like encryption, or anonymous remailers (mail forwarders). The Budapest Convention does not outlaw anonymous communication; rather, it affirms the need for proportionate safeguards, and upholds the positive obligation of the state to balance privacy with legitimate public goals. The same body’s protocols require criminalising hate speech, xenophobia and racism online, not anonymous speech as such.
About ten years ago (2015), the United Nations affirmed the right to privacy and freedom of expression online, emphasising that encryption and anonymity are vital protections for users, especially vulnerable groups such as journalists and minorities. The UK-based organisation ARTICLE 19 has been a strong advocate for these digital rights globally. The UN cautioned against measures that threaten these rights, such as mandatory identification or weakening encryption, stressing that any restrictions must be necessary, proportionate, and supported by due process. This stance was recently reinforced in UN General Assembly Resolution A/RES/78/213, which reiterates the promotion and protection of human rights in digital technologies.
Unintended consequences – parallel internets and unregulated risks
Attempts to regulate access inevitably drive determined users into ever more secretive and unregulated corners of the web. Young people who cannot access controversial material online will still encounter violence and adult themes on the news, television, films, or in video games. Meanwhile, the most determined gain access to harmful material using VPNs, moving to parallel ‘dark web’ spaces, or adopting cryptocurrencies – tools that are volatile and unregulated for purchases outside mainstream platforms. Already, such strategies and tools are being shared openly online.
Conclusion: safety or soft authoritarianism?
Britain’s Online Safety Act 2023 was conceived as a bulwark against harm to children, but its enforcement now looks increasingly like a digital crackdown: mainstream communities face obstacles, international sites threaten to block UK users, and millions rush to VPNs to restore their privacy. Countries around the world, both democratic and authoritarian, are watching and emulating these policies. Whether the next parliament dares to pause or revise course, or doubles down, may determine whether the UK joins a growing list of states championing digital safety at the expense of fundamental rights and vibrant, open online society.







