At London International Disputes Week 2026, Baker McKenzie and 11KBW hosted a panel on “Litigating Online Harms: Content, Courts and Corporate Responsibility”, featuring Sarah West (Baker McKenzie), Anya Proops KC (11KBW), Raphael Hogarth (11KBW), and Telha Arshad (Google).
Three years on from receiving royal assent, the Online Safety Act 2023 (“OSA”) is moving from implementation into enforcement, and disputes are beginning to emerge. Drawing on the panel’s diverse perspectives, the discussion explored early challenges to the Act, the evolving enforcement landscape and its interaction with overlapping regulatory regimes. This article sets out the key takeaways.
Challenging regulatory decisions: judicial review and appeals
The OSA imposes significant compliance burdens on in-scope services (estimated to be in the region of over 250,000 services) and Ofcom has some of the most robust powers amongst any UK regulator, as well as the ability to recover all of its £90m annual costs from the industry. It is therefore no surprise that several of the government and regulatory decisions connected with the OSA have already been subject to judicial review, with many others are anticipated in the coming year.
Most of the early challenges have focused on the framework itself, rather than specific decisions reached by Ofcom, and have therefore been brought through judicial review proceedings in the Administrative Court. Notable examples include a challenge brought by the Wikimedia Foundation and a Wikipedia user to the categorisation regulations, and the ongoing proceedings relating to the supervisory fee regulations.
As many readers will be aware, the Wikimedia litigation illustrates the high bar that applies in public law challenges. The Claimant’s case was that the categorisation criteria failed to reflect the policy objective of targeting platforms where content spreads “easily, quickly and widely” and risked subjecting Wikimedia to regulatory obligations designed for large social media companies. The Court considered that a degree of circumspection was required when reviewing regulations that had been informed by expert advice and approved by Parliament, and decided that the regulations were not so unreasonable as to justify intervention. The Court also dismissed the Claimants’ human rights challenge, on the basis that it was not yet clear that Wikimedia would even be classified as Category 1. Although the challenge was therefore unsuccessful, there were some important observations from the Court about the legal constraints on Ofcom’s future decision-making. The Court notably observed Wikipedia provides significant value for freedom of speech, without any form of threat to informed public discourse or other public interests. In that context, the Court noted that any decision significantly impairing Wikimedia’s ability to operate would, in the absence of justification, likely be unlawful as a breach of the right to freedom of expression.
The high bar that applies in claims for judicial review, or appeals on judicial review principles, does not mean that these are futile avenues of challenge. The panel observed that some cases may turn on statutory interpretation rather than irrationality, and that the commercial impact of certain decisions may justify litigation even where success is uncertain. Early cases can also provide valuable guidance on the boundaries of the regime and Ofcom’s powers.
Looking forward, certain challenges will be brought under the bespoke appeal process of the OSA to the Upper Tribunal (“UT”), which has specific procedural rules, including shorter deadlines for issuing the appeal and the absence of a permission stage for appeals by service providers. These appeals are determined by reference to judicial review principles, but there is still uncertainty about how the appeals will be case managed, including in relation to the exchange of evidence. Further, there is an ongoing review of the costs position, and whether the Tribunal Procedure Committee will adopt a ‘loser pays’ model for OSA appeals, rather than the UT’s usual approach of each party bearing its own costs.
Strategic considerations in bringing challenges
Importantly, decisions to litigate in this context are not driven solely by legal merits. As the panel discussed, companies must weigh the merits of the challenge against the implications for their ongoing relationship with Ofcom. Engagement with Ofcom may, in some cases, offer an alternative route to resolving issues, enabling concerns to be addressed informally and providing insight into Ofcom’s evolving interpretation of the regime. While litigation may strain that relationship, the extent of the impact will depend on the nature of the challenge. Public and media scrutiny is also a key consideration, particularly in a regime concerned with online harms, where reporting on even technical legal disputes may raise more emotive issues.
Enforcement, investigations and regulatory preparedness
Ofcom’s early enforcement activity has concentrated on the highest-risk services. That is a natural starting point for a regime still in its infancy. Enforcement is, however, expected to evolve as the regime matures.
Ofcom has already been prolific in its use of information notices, which enable Ofcom to compel platforms to produce any information relevant to its functions (including the ability to view the real time operation of algorithms on the service), with non‑compliance carrying serious financial penalties, and in some instances potential criminal liability.
As enforcement develops, Ofcom may reach for its sharpest investigatory tools, which include audits, skilled persons’ reports and compulsion of witnesses. The practical operation of some of these powers, however, has yet to be tested.
Against this backdrop, there is a growing emphasis on regulatory preparedness and anticipation of enforcement action. Companies should therefore be revisiting internal processes, including dawn raid and similar procedures, documentation practices, privilege considerations and senior management accountability. In a regime that turns on documented risk assessments and compliance decisions, internal record-keeping is likely to be central to any investigation, both in evidencing the steps taken and in shaping Ofcom’s assessment of whether those steps were reasonable and proportionate.
Overlapping regimes and the limits of private enforcement
A further complexity arises from the interaction between the OSA and other regulatory frameworks, particularly data protection law. Areas such as age assurance, including measures involving identity verification, illustrate the potential for overlapping, or even divergent, regulatory requirements. The OSA requires highly effective systems, which may involve the processing of significant volumes of personal data, or the use of ‘hard’ forms of ID, which can alienate vulnerable users or have broader privacy implications. As a result, the same compliance step may be subject to regulatory scrutiny from multiple legal perspectives and multiple regulators, creating a challenge for providers.
The OSA’s information-sharing framework also means that information provided to one regulator may, in certain circumstances, be shared with others, increasing the risk of the same material being assessed across different regulatory contexts. As the panel observed, the interaction between the OSA and regimes such as the EU Digital Services Act increasingly requires a coordinated approach to compliance, often necessitating advice from both UK and EU‑qualified counsel.
Finally, while the emergence of private law claims cannot be ruled out, the panel identified significant structural barriers. The OSA does not create a general private right of action. Its duties are framed at a systemic level, rather than being owed to individuals. This makes it difficult to translate breaches into traditional causes of action such as negligence or breach of statutory duty. Establishing causation may be particularly challenging, as harm typically arises from a combination of platform design, user behaviour and third-party content, rather than any single act attributable to the platform.
