Ofcom has penned an open letter to the UK’s online service providers, reminding them of their obligations under the Online Safety Act in light of concerning genAI chatbots lurking on the web.
The letter, signed by group director for online safety Lindsey Fussell, cited ‘multiple incidents of online harm’ involving genAI, such as the death of an American teenager who had developed a relationship with a chatbot based on a Game of Thrones character, and chatbots which had been created to act as ‘virtual clones’ of real people and deceased children, including Molly Russell and Brianna Ghey.
The regulator said that the incidents had raised questions about how UK law will apply to the use of genAI technology by platforms operating in the country, which includes tech firms like OpenAI, Meta, Microsoft, and Google, as well as a host of smaller developers.
Under the provisions of the Online Safety Act, platforms which allow for ‘user-to-user services’ are subject to Ofcom regulation, which in the context of genAI can include sites or apps that allow users to share text, images or videos generated by chatbots with other users, or that allow users to upload or create their own genAI chatbots to share.
That includes services that provide tools for users to create chatbots that mimic real and fictional people which can be submitted to a chatbot library for others to interact with.
Fussell’s letter highlighted that any AI-generated text, audio, images or videos that are shared by users across such services are considered user-generated content and will be regulated in the same way as human-generated content.
For example, AI created deepfake material is regulated no differently to human-generated material, whether that content was created on the platform where it is shared or has been uploaded by a user from elsewhere.
“Where the above scenarios apply to your service, we would strongly encourage you to prepare now to comply with the relevant duties,” wrote Fussell.
“For providers of user-to-user services and search services, this means, among other requirements, undertaking risk assessments to understand the risk of users encountering harmful content; implementing proportionate measures to mitigate and manage those risks; and enabling users to easily report illegal posts and material that is harmful to children.”
The regulator pointed online providers towards its draft Codes of Practice to help user-to-user and search services meet these duties and protect users from risks posed by Generative AI.
Recommended
- Scottish First Minister Urges Tech Firms to Tackle Online Hate
- Can the Online Safety Act Help Quell UK Unrest?
- Bluesky Signups Surge in UK After Government Spat with Elon Musk
Among the measures Ofcom recommends are having a named person accountable for compliance with the Online Safety Act, having a content moderation function, using highly effective age assurance methods, and the introduction of easy to use reporting and complaints processes.
The regulator is due to publish its final Illegal Harms Risk Assessment Guidance and Codes of Practice in December, after which the first mandatory duties for service providers will begin to take effect, although the first major milestone for sites and apps is to complete an Illegal Harms Risk Assessment, which they will need to do by mid-March 2025.
Warning platforms of the risks for failing to meet the regulations, Ofcom’s letter said that it was ready to take enforcement action, which could include issuing fines.





