NE Times
Technology

Ofcom Opens Formal TikTok Child-Safety Investigation Under Online Safety Act

Ofcom has opened a formal investigation into TikTok's duties to protect children under the Online Safety Act. Here is what the regulator is examining and what it could mean.

Rajan Mehta

Business & Technology Editor ·

4 min read
A teenager's hands holding a smartphone showing a vertical scrolling video feed, screen glow on their fingers
A teenager's hands holding a smartphone showing a vertical scrolling video feed, screen glow on their fingers · Illustrative image

Why it's trending

The investigation is one of the clearest tests yet of the UK's Online Safety Act and affects a platform used daily by millions of young people and families.

A major enforcement test begins

Ofcom has opened a formal investigation into TikTok's compliance with duties to protect children under section 12 of the Online Safety Act 2023. The case is important because the UK's online-safety regime is moving from codes and warnings into evidence-led enforcement against one of the world's largest platforms. Ofcom will use formal powers to obtain information and assess whether TikTok's systems prevent children from encountering priority harmful content. It will also examine whether the platform's age-assurance methods are sufficiently effective. Opening an investigation does not mean a breach has been established, and Ofcom says its first update is expected in October 2026.

What the regulator is worried about

The law requires services likely to be accessed by children to assess risks and operate proportionate safety systems. Ofcom's concern includes content connected with suicide, self-harm, eating disorders and pornography. The regulator is not asking whether TikTok removes every harmful post instantly, an impossible standard for any large platform. It is examining whether the platform's design, recommendation systems, reporting tools and age controls collectively meet legal duties. The distinction matters: online-safety regulation increasingly focuses on systems and processes, because harm can be amplified by algorithms even when individual pieces of content are difficult to classify.

Age inference is at the centre of the case

TikTok and other services use several signals to estimate whether an account belongs to a child. These may include a declared date of birth, behavioural patterns, content interactions, language, device information and automated age-inference models. The advantage is that users are not always required to upload identity documents. The weakness is that inference can be wrong, particularly when children copy adult behaviour or share devices. Ofcom has previously expressed concern that age-inference tools may fail to identify enough underage users. The investigation will test performance claims against evidence rather than accepting the existence of a tool as proof that the legal duty is met.

Why recommendations can create special risk

TikTok's defining feature is a highly personalised 'For You' feed. A user does not need to search actively for every video they see. If recommendation systems detect engagement with distressing or extreme material, they can unintentionally create a sequence that deepens exposure. Platforms say they interrupt repetitive recommendations, restrict sensitive content and direct users toward support. Regulators want to know how those protections operate for children in practice, including users whose age has been misidentified. The core question is not whether the technology can recommend engaging videos, but whether the same optimisation architecture recognises and reduces foreseeable harm.

TikTok's likely defence

TikTok has said it complies with UK law, enforces a minimum age, removes underage accounts and invests in age-assurance technology and safety teams. It can point to parental controls, restricted settings for younger teenagers and policies against content promoting self-harm. The company may argue that Ofcom's expectations must reflect technical uncertainty and the scale of user uploads. It may also challenge assumptions about how accurately any age model can work without intrusive identity checks. A robust defence will require data: detection rates, false positives, audit results, response times and evidence that safety interventions change what children actually encounter.

The privacy trade-off

Stronger age checks can protect children while creating new privacy risks. Requiring passports, facial scans or third-party verification may deter some underage access, but it also produces sensitive data and new targets for criminals. Age inference avoids direct identity documents but can involve extensive profiling. The Online Safety Act therefore forces regulators and companies to balance effectiveness, proportionality and data protection. Parents may want certainty that adult content is blocked, while adults may resist providing biometric information to access lawful services. There is no frictionless solution; the policy challenge is to use the least intrusive method that achieves reliable protection.

What enforcement powers look like

If Ofcom ultimately finds a breach, it can require remedial steps and impose significant financial penalties, potentially up to the statutory maximum linked to global revenue. The most important outcome may be operational rather than punitive. A settlement or enforcement notice could require TikTok to improve age testing, alter recommendation systems, produce independent audits or report safety metrics. Any decision would need to explain the evidence and legal reasoning, especially because it could set expectations for other platforms. TikTok would have routes to challenge an adverse decision. The case is therefore likely to influence the wider industry even before it reaches a final conclusion.

What parents and teenagers should understand

The investigation does not mean TikTok is being banned or that every child account is unsafe. It means the regulator has enough concern to examine whether legal duties are being met. Families can use existing controls, including restricted modes, family pairing, time limits and content-reporting tools, while remembering that settings cannot replace conversation. Teenagers should know that recommendation feeds are designed to hold attention and that repeatedly viewing upsetting content can train the system to show more. Schools and health services also need clear pathways for responding when online material appears connected to a young person's distress.

What happens next

Ofcom will gather evidence for at least several months and has indicated an update in October. The investigation could close without a breach finding, continue into formal enforcement or produce negotiated changes. Readers should be cautious about claims that the regulator has already proved wrongdoing. The broader significance is clear: the UK's online-safety rules are becoming testable obligations rather than voluntary promises. The outcome will help define how much evidence platforms must provide about algorithms and age controls, how regulators measure child protection, and whether a law written in general duties can change the day-to-day experience of young users.

Sources & verification

  • Ofcom - formal investigation notice (www.ofcom.org.uk)
  • Sky News - investigation coverage (news.sky.com)
  • Online Safety Act 2023 (www.legislation.gov.uk)

Filed under Technology · Written by Rajan Mehta