What UK law actually requires — extending “three regimes, one news diet”
The rest of this section already establishes that platforms carry no impartiality duty, unlike broadcasters, and that Ofcom’s Online Safety Act powers reach harm, not plurality. Everything below is the detail behind that line, not a revision of it.
Platforms and search
No impartiality duty
Not covered by the media ownership rules and not subject to any impartiality duty, despite being used for news by six in ten UK adults. The Online Safety Act gave Ofcom powers over harm, not over the plurality of what people see.
Recommender systems are a named legal threshold, not an afterthought
A regulated user-to-user service is Category 1 if it has more than 34 million average monthly UK users and uses a content recommender system; or more than 7 million average monthly UK users, uses a content recommender system, and lets users forward or share content with each other. A "content recommender system" is one of the two legal threshold conditions for the entire Category 1 tier — not an incidental detail of platform regulation, but one of its two load-bearing tests.
Category 1 services currently listed (11): Facebook, Instagram, Pinterest, Quora, Reddit, Roblox, Snapchat, TikTok, WhatsApp, X, YouTube.
Ofcom’s own statutory guidance, quoted directly. “Our evidence, for example, indicates that if not properly tested and deployed, content recommendation systems may amplify hateful content if they are optimised for user engagement.”
What is live now, and what is still in consultation
Online Safety Act implementation timeline, as of 7 September 2026| Date | Duty | Status |
|---|
| 16 Dec 2024 | Illegal-content Codes of Practice & Risk Assessment Guidance published — recommender systems named as an explicit risk factor | In force |
|---|
| 16/17 Mar 2025 | Illegal-content risk assessment duty and safety-measures duty live for all in-scope services | In force |
|---|
| 24/25 Jul 2025 | Children’s risk-assessment duty and Children’s Codes safety-measures duty liveDates corroborated by multiple independent legal-commentary sources, not independently re-verified against Ofcom’s own statement page in this research pass. | In force |
|---|
| 30 Jun 2026 | Register of categorised services (Category 1 / 2A / 2B) publishedDetermines which platforms carry Category 1’s extra duties, once those duties are finalised. Register last updated 14 Aug 2026 — check before long-term reuse. | In force |
|---|
| 10 Jul 2026 → | Draft Category 1 Code of Practice (user empowerment, identity verification, complaints) — the duties that would most directly target algorithmic amplification, not just risk-assessment paperworkConsultation closes 2 October 2026; final version expected mid-2027 at the latest. | Consultation open |
|---|
| Autumn 2026 (expected) | Updated Codes covering AI / automated moderation tools | Upcoming |
|---|
As of 7 September 2026: the illegal-content risk-assessment duty (including its explicit recommender-systems risk factor) and the children’s risk-assessment/codes duty are both live and enforceable now. The categorisation register is published, but the extra duties that attach specifically to Category 1 status — the ones that would reach algorithmic amplification directly, rather than via a risk-assessment paperwork exercise — are still in draft and consultation, not yet final or in force.
What has not (yet) been found. No confirmed Ofcom enforcement action specifically targeting a platform’s recommender system — as opposed to risk-assessment paperwork, age assurance, or generated content — has been found in this research as of 2026-09-07. This is stated as "not found," not "does not exist": it is exactly the kind of live regulatory fact that can change without notice, and should be re-checked directly against Ofcom’s enforcement pages before being relied on.
A second regulator, a second legal theory: the ICO and children’s data
ICO Children’s Code, Standard 12, quoted directly. “If you are using children’s personal data to automatically recommend content to them based on their past usage/browsing history then you have a responsibility for the recommendations you make. This applies even if the content itself is user generated... Data protection law doesn’t make you responsible for third party content but it does make you responsible for the content you serve to children who use your service, based on your use of their personal data.”
In February 2025 the ICO opened an investigation into how TikTok processes 13–17-year-olds’ personal data in its recommender systems, and issued an information notice requiring TikTok to provide information. TikTok has appealed the notice to the First-tier Tribunal on "special purposes" (journalistic/artistic) grounds, and — as of the ICO’s own most recent update, 1 December 2025 — is not required to comply while that appeal is unresolved. This is an open investigation with an unresolved procedural dispute, not a completed finding about TikTok’s recommender system, and the position will have moved on since the research date.
Recommender systems shown to children are regulated twice, by two different regulators, on two different legal theories: the Online Safety Act treats them as a systemic-risk factor a platform must assess and mitigate (Ofcom); the UK GDPR’s Children’s Code treats them as personal-data processing a platform is directly responsible for (ICO). Neither regime gives any UK regulator a duty over the plurality or viewpoint-diversity of what an algorithm shows a user — that is the gap lib/media-orientation.ts’s REGULATORY_ASYMMETRY already names, and nothing found in this research closes it.