Ofcom has published updated regulatory guidance for the use of artificial intelligence by online services that are subject to the Online Safety Act. Released on 4 October 2026, the guidance is intended to help platforms, app stores and other service providers adopt AI systems for content moderation, age assurance and personalised safety interventions while meeting the regulator’s standards for transparency, auditability and human oversight.
What the guidance says
The document clarifies the regulator’s expectations across three core areas. First, services must be able to demonstrate how AI tools make safety-related decisions, including what training data and performance metrics were used. Second, Ofcom says firms should maintain human-in-the-loop arrangements for high-risk decisions and make clear when automated systems take action. Third, regulated companies will be expected to keep auditable logs and to provide regular reporting to Ofcom on system performance, bias testing and safety outcomes.
Although the guidance does not impose new primary legislation, it tightens the operational requirements that Ofcom will use when assessing compliance under the Online Safety Act. The regulator makes clear that the adoption of AI does not reduce a service’s legal responsibilities to prevent illegal harms and to protect children and vulnerable users.
Why Ofcom updated the guidance now
Ofcom says the update responds to rapid changes in AI capability and to evidence from its engagement with industry, civil society and technical experts. In recent months, the regulator has highlighted the growing use of generative models and automated moderation tools across major platforms, and it points to the increased potential for both improved safety outcomes and new forms of error or unfairness.
Regulatory officials framed the guidance as an effort to provide firms with clearer pathways for safe innovation. Ofcom emphasises that properly governed AI can improve the speed and scale of harm detection, for example by helping identify coordinated abuse or criminal networks, while preserving avenues for human review where errors would cause serious consequences.
Practical expectations for industry
Key operational measures set out by Ofcom include mandatory documentation of model development lifecycles, independent third party audits for higher risk systems, and procedures for rolling back or constraining models that show unexpected behaviour in production. The guidance also asks firms to publish plain language notices describing when automated systems are used, and to give users accessible routes for human review.
Ofcom underscores the need for age assurance that respects privacy and proportionality. The guidance suggests a risk based approach, where the strictness of verification and the reliance on AI should match the nature and severity of potential harms in a given service.
Reaction from industry and safety advocates
Industry groups welcomed clearer rules of the road but warned about implementation costs and the need for international alignment. Several technology trade associations noted that auditability and third party assessment requirements are workable but will require investment in tooling and skilled personnel.
Child safety and digital rights groups said the guidance is a necessary step but pressed for strong enforcement and independent oversight to ensure firms do not rely on opaque automation to evade accountability. Advocates also called for publicly accessible summaries of third party audits so users and researchers can assess harms and biases in deployed systems.
What this means for UK AI policy
The guidance deepens Ofcom’s supervisory role under the Online Safety Act and signals that the UK is moving from high level principles to operational expectations for firms using AI in services that reach children and general audiences. It complements broader UK government work on sectoral AI governance, including health, finance and national security, and positions Ofcom as a front line regulator for online safety where AI is being deployed at scale.
For platforms and startups, the message is clear: AI can be a force multiplier for safety, but it must be demonstrably governed. Firms that cannot show how their systems work, who designed them and how they are tested, should expect closer scrutiny and potential regulatory action.
Ofcom said it will monitor implementation and may set further technical guidance or enforcement expectations as it gathers evidence from regulated services in the coming months.





