Security News

Ofcom Struggles to Collect Online Safety Act Fines It Has Already Issued

The Register · 17 Sept 2026
Key Takeaway Australian SMBs relying on UK or overseas online platforms should be aware that regulatory fines don't always guarantee real accountability, so vet third-party services on their actual compliance record, not just their legal exposure.

Ofcom, the UK communications regulator, has revealed that most fines it has issued under the Online Safety Act (OSA) have not actually been paid. Enforcement director Suzanne Cater told a House of Lords committee that while a payment had come in recently, the majority of penalties remain outstanding. Ofcom has issued more than £7 million in fines to 11 service providers so far, mostly smaller companies in the pornography industry, with its largest penalty being £1.4 million.

Ofcom officials explained that its enforcement options are limited once a fine is issued. It cannot block a website globally, though it can ask UK courts to restrict local access or compel third parties like internet service providers to do so. Crucially, these disruption powers can only be used where non-compliance with the law continues, not simply to chase unpaid fines. Some companies have complied with content requirements but never paid their penalties, and recovering that debt becomes difficult if the business holds no assets in the UK.

Ofcom says it plans to shift focus toward larger companies, which it expects will make fine collection less problematic, and is starting to hold senior managers personally liable in some cases. Still, the admission highlights that regulatory penalties alone may not guarantee compliance from platforms operating offshore or with minimal UK presence.

Online Safety Act Ofcom regulation enforcement compliance
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.