UK publishes its online safety legislation plans: tech companies will face fines of up to £18M or 10% of annual revenue if they fail to moderate illegal content
Financial Times
Context & Ripple Effects
The UK has been building toward this for three years: a [[a:918608|parliamentary committee first proposed fining social media firms over unremoved extremist content]] back in 2017, and the 2019 whitepaper then sketched a 'code of best practice' that even floated extending liability to tech executives themselves.
Today's plans convert those sketches into concrete numbers — £18 million or 10% of annual revenue per breach — which puts the proposal on par with GDPR-style revenue-linked penalties rather than symbolic fines, and sets up the legislation that will pass through Parliament in subsequent years.
First-order effects
Platforms operating in the UK, including the Facebooks and Twitters named in earlier parliamentary scrutiny, now face a quantified downside — up to £18M or 10% of annual revenue — for failing to moderate illegal content, making content-moderation spend a board-level risk item.
The plans shift the enforcement question from 'should there be fines?' to 'who measures compliance?', pointing toward the regulator-led oversight model that later coverage shows landing on Ofcom.
Second-order effects
Compliance costs scale with headcount of harmful-content review, not revenue, so the 10%-of-revenue ceiling hits mid-size platforms proportionally harder than giants — pressuring consolidation or exit from the UK market among firms that cannot amortize moderation infrastructure.
Vendors of automated detection and moderation tooling gain a regulated buyer base, since platforms facing revenue-linked penalties have direct financial incentive to buy down their exposure.
Third-order effects
A revenue-linked penalty regime for illegal content establishes distribution-layer liability as the default regulatory instrument — the same structure later amendments extended to specific categories like CSAM removal under Ofcom enforcement.
If the pattern holds, platform governance converges across jurisdictions on turnover-based fines plus a designated regulator publishing codes of practice, effectively ending the era of self-regulated content moderation.
The trend: Platform accountability is moving from voluntary codes to statutory, revenue-scaled fines enforced by national regulators, with the UK's plan as an early template.
The Government has appointed Ofcom as the regulator for online harms in the UK. Next year, we'll set our initial thinking on our approach to this new role. But for now, this article can help to answer your questions about what this could mean in future: https://www.ofcom.org.uk/.…
How will you do this @Ofcom when you think that women & @ALLIANCELGB are hateful for standing for the rights of women & children & the rights of lesbians, gays & bis? How the hell will you protect us? How will you stop the grooming of young non conforming children & adolescents? …
NEWS: We will legislate to tackle #onlineharms 🔵 Tech firms will have a legal ‘duty of care’ to users 🟣 Ofcom to get tough new enforcement powers 🟡 Platforms will need to protect users from a range of harms from terrorism to self-harm content https://www.gov.uk/... https://twitte…
New #OnlineHarms laws will protect children and adults alike from despicable internet content — from hate speech and posts promoting self harm to terrorist propaganda. Read more: https://www.gov.uk/... https://twitter.com/...
Bland, bureaucratic, dangers to free speech: • Ofcom will be the Internet Speech Regulator. • Speech that poses unspecified risks will be removed • Not mentioned here, but apparently private messages in scope, and message encryption under attack https://www.theguardian.com/ ...
I, for one, look forward to helping companies ensure that theirs terms and conditions are “robust”. I don't know what that means, as it's not a legal term, but it sounds fun.
We're helping to keep you #SafeOnline. Our new #OnlineHarms laws will mean all websites must tackle illegal content like child abuse imagery, while tech giants must also protect users from harmful posts such as those promoting eating disorders. Read: https://www.gov.uk/... https:…
There's a lot in here which seems like it's there to make these rules looks *really, really tough*. But also a lot left vague. Which does mean there's a risk that the rules could manage the rare double whammy of being both draconian and ineffective. https://www.theguardian.com/ .…
NEWS: Today we announce we will legislate to tackle #onlineharms 🔵 Tech firms will have a legal ‘duty of care’ to users 🟣 Ofcom to get tough new enforcement powers 🟡 Platforms will need to protect users from a range of harms from terrorism to self-harm content
On a *very* quick skim of the online harms response, it's big (well, sort of) on ideas, and less so on how on earth it's actually going to work for any of the obliged companies.