Q & A with Thomas Rudkin
Thomas Rudkin from Farrer & Co is the author of new title Navigating the Online Safety Act: A Practical Guide.
This will be included in our Cyber Law online service.
Who will benefit from reading this book?
The book will benefit anyone with an interest in the Online Safety Act 2023 (OSA), whether lawyer or layperson, and whether they seek an overarching understanding of its key provisions or signposts towards the detail. It is designed for a wide readership including companies operating services within scope, legal and other professionals working in relevant areas of law and policy, individuals seeking to understand their rights online, public officials responsible for technology regulation and organisations concerned with child safeguarding.
As it would not be feasible for a single book to address every provision in exhaustive detail, it adopts a thematic structure which focuses on the elements of the OSA likely to be most significant in practice. It will be of particular use in cutting through the 'noise' around the OSA to identify in clear and concise terms what it actually does and does not do, as well as saving readers (who don't have time or the inclination to do so) from the mammoth task of ploughing through the OSA's 366 pages plus accompanying regulations and guidance.
What is one of the biggest challenges that comes along with the Online Safety Act?
The sheer scale and ambition of the OSA has necessitated three implementation stages, of which we are currently in the third. This has meant that, while the OSA received Royal Assent in October 2023, many of the provisions which were designed to provide enhanced protection for users against the riskiest (ie largest) services, have remained on ice. This is partly due to the scale and complexity of the issue of 'categorisation': large tracts of the OSA hinge on the question of whether a particular platform falls into one of the three categories envisaged in the OSA, and if so, which one. This is because, whilst all regulated providers are subject to the core baseline provisions (such as illegal content and child-safety obligations), those providers which fall into one of the categories are deemed riskier and hence are subject to extra, more onerous duties.
From the start, the criteria for the category thresholds, such as number of users and functionality, were controversial and subject to legal challenge. It was only very recently, on 30 June 2026, when Ofcom finally published its long-awaited Register of categorised services, that providers had confirmation of whether they were 'categorised' at all and if they were, which category they were in. It is only now therefore that categorised services are able to move towards compliance with their additional transparency, accountability and user-protection duties (and even then, consultation is still taking place about the Codes and Guidance for the additional Category 1 duties). The scale and ambition of the OSA has therefore clearly come at the expense of speed, albeit we are now seeing the OSA juggernaut finally pulling beyond the regime of baseline duties to enhanced regulation of the largest and most influential platforms.
Are there any trends in this area that practitioners will want to be aware of?
There is obviously a current trend towards much stronger protection of children in the online sphere, as evidenced by the government announcing in June 2026 that it plans to bring in a social media ban for under 16s. Policy debate has therefore shifted beyond merely protecting children from certain content (as per the OSA's current provisions) to deciding that children should not be permitted to use particular online services at all. New regulations under the OSA enacting the ban are expected to be laid before Parliament by the end of 2026 with implementation targeted for spring 2027. Hence age assurance looks set to become an even more important area of scrutiny and dispute under both the OSA and the data protection regime. The focus on age assurance is leading to a convergence of legal and regulatory regimes, meaning that lawyers advising platforms may find themselves having to co-ordinate advice not only across the OSA and data protection, but also across privacy, consumer protection and human rights.
Does Navigating the Online Safety Act: A Practitioner’s Guide cover any topics not covered by the Online Safety Act?
Whilst the book adopts a thematic structure that focuses on the elements of the OSA likely to be of most significance in practice, it does also identify gaps in the new legislation, for example the fact that the OSA does not directly regulate disinformation (the deliberate dissemination of false information in order to manipulate public opinion, generate discord or cause emotional, political or economic harm). There is a lack of any obligation on platforms to take down disinformation which does not amount to a criminal offence, and disinformation itself is not defined as a harmful category of content. The only potentially applicable substantive offence is the new 'false communications' offence which criminalises the knowing dissemination of false content likely to cause non-trivial psychological or physical harm. However, this provision is narrow in scope, targeting individual malicious actors rather than the broader spread of disinformation as well as failing to address the common scenario where harm is economic or reputational rather than physical or psychological. As a result, the book touches on existing legal tools which, in scenarios where an individual is the subject of false material, do offer some recourse when challenging disinformation online, including defamation and data protection rights such as the 'right to be forgotten' and the GDPR principle that personal data must be accurate.
