[Home](/)/[Resources](/resources)/Online Safety Act Connected Devices

United KingdomOnline SafetyConnected Devices

# UK Online Safety Act 2023: Implications for Connected Hardware and IoT Product Makers

The Online Safety Act 2023 does not regulate hardware — it regulates online services. But for any hardware company that operates a companion app, community platform, or user-generated content feature accessible to UK users, the Act imposes mandatory duties on illegal content, complaints handling, and children's safety. Understanding where your product ecosystem sits relative to the OSA's regulated service definitions is now a foundational compliance question for any connected hardware business.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fuk-online-safety-act-connected-devices)

At a glance

Act year

Online Safety Act 2023

Regulator

Ofcom

Max fine

£18m or 10% global turnover

Key service types

User-to-user and search services

## Online Safety Act concepts for connected hardware companies

### What the OSA Regulates — User-to-User and Search Services

The Online Safety Act 2023 regulates two categories of service: user-to-user (U2U) services (platforms where users can encounter content generated by other users) and search services. The Act imposes a graduated framework of duties depending on service type and reach. The critical question for a hardware company is whether the software ecosystem surrounding its device — companion app, device web portal, community forum, firmware update channel — constitutes a U2U or search service that is accessible to UK users. If it does, the OSA applies to that service regardless of where the provider is established.

### In-Scope vs Out-of-Scope — Where IoT Services Sit

Many IoT and connected hardware services fall outside the OSA's scope: one-to-one messaging services (device alerts sent directly to a single user), purely internal or intranet services, email services, SMS gateways, and services where no user-generated content is uploaded or shared with other users. A fitness tracker that sends data only to the individual user's own account is not a U2U service. A smart home platform where users can share automations, post in community forums, or leave product reviews visible to other users may well be a regulated U2U service. The boundary requires careful analysis of the specific service architecture.

### Category 1 and Category 2 Services — Designation Thresholds

The OSA creates a tiered system: all regulated services (Category 2A and 2B) must meet baseline duties; Category 1 services (the largest, highest-reach U2U platforms) face the heaviest obligations including transparency reporting and additional content duties. Ofcom will set Category 1 and 2 designation thresholds by secondary legislation. Most connected hardware companion apps will not reach Category 1 thresholds — but all regulated services, regardless of size, face the core illegal content duties and complaints mechanism requirements from the moment they are in scope.

### Illegal Content Duties — Mandatory for All In-Scope Services

Every regulated service — including small U2U services with minimal UK users — must identify and remove illegal content. The OSA's priority illegal content categories include terrorism, child sexual abuse material (CSAM), incitement to violence, and fraud-facilitating content. Services must conduct a risk assessment to understand the likelihood of encountering this content and implement proportionate systems and processes to mitigate that risk. For a hardware community forum or product review platform, this means content moderation procedures, takedown mechanisms, and a documented risk assessment — even if the practical risk is low.

### Age Assurance — Children's Safety Requirements

Where a regulated service is likely to be accessed by children, additional duties apply under the OSA. These include carrying out a children's risk assessment, implementing age assurance or age verification measures to prevent children from accessing harmful content, and applying default safe settings for child users. Ofcom's codes of practice will specify what age assurance is adequate. For hardware makers whose products are used by or around children — family smart speakers, children's tablets, educational IoT devices — this is a significant area to watch as Ofcom's guidance on proportionate age assurance develops.

### OSA vs PSTI Act 2022 — Two Separate Regimes for Connected Products

The Product Security and Telecommunications Infrastructure Act 2022 (PSTI Act) and its 2023 Regulations govern the physical device's cybersecurity: mandatory unique default passwords, vulnerability disclosure policies, and defined minimum security update periods — obligations on the manufacturer or importer of the device itself. The OSA governs the online service the device connects to: the platform, app, or community where user-generated content exists. Both may apply simultaneously to a connected product ecosystem. Compliance with one does not substitute for compliance with the other — a manufacturer must assess PSTI obligations for the hardware and OSA obligations for any accompanying online service independently.

## Building an OSA compliance programme for connected hardware

01

Map all software and service components associated with the hardware product — companion mobile app, web portal, cloud backend, community forum, review platform, firmware OTA channel — and assess each against the OSA definitions of 'user-to-user service' and 'search service' accessible in the UK.

02

For any service that may be in scope, determine whether the service is genuinely a U2U service (users encounter content generated by other users) or falls within an OSA exemption (internal service, one-to-one messaging, purely functional IoT data relay without UGC).

03

Assess the service's likely UK user base and track Ofcom's consultation on Category 1 and 2 designation thresholds — published at ofcom.org.uk. Most hardware companion services will be Category 2 if regulated at all, but the designation matters for understanding which specific obligations apply.

04

Conduct and document an illegal content risk assessment for every in-scope service. The risk assessment must consider the functionalities of the service, the user base characteristics, and the likelihood of encountering terrorism, CSAM, fraud, or other priority illegal content — and specify the mitigating measures implemented.

05

Implement a user complaints mechanism: in-scope services must provide users with a clear means of reporting illegal content and of complaining about the service's content moderation decisions. Document the complaints handling procedure and assign staff responsibility.

06

Designate a named senior manager with responsibility for OSA compliance. Ofcom can hold senior managers personally liable for failures to take steps to prevent non-compliance once Ofcom has issued a notice to the provider.

07

Review Ofcom's published Codes of Practice as they are issued — including the Illegal Content Codes and, when finalised, the Children's Safety Codes — and update your risk assessments, content moderation policies, and age assurance implementation accordingly. Keep records of all assessments and measures for potential Ofcom audit.

## Frequently asked questions

### Does the UK Online Safety Act apply to hardware companies?

The Online Safety Act 2023 does not regulate hardware products directly — it regulates online services. It applies to a hardware company if, and only if, that company operates a user-to-user service or search service that is accessible to users in the United Kingdom. A hardware company whose product connects only to its own servers, without any user-generated content being shared between users, is not in scope. A hardware company that operates a community platform, product review system, or user-generated content feature accessible to UK users is in scope for those services, regardless of where the company is incorporated.

### What is the difference between OSA obligations and PSTI Act obligations for connected devices?

They address entirely different aspects of a connected product. The PSTI Act 2022 and the Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023 impose obligations on the manufacturer or importer of the physical device: minimum default password requirements, a vulnerability disclosure policy, and defined security update support periods. These are product obligations — they govern what comes in the box, not what happens online. The OSA applies to the online service the device connects to — specifically any user-to-user or search service. A connected product company must assess both regimes independently.

### When does a companion app become a 'regulated service' under the OSA?

A companion app becomes a regulated service if it allows users to encounter content generated by other users in the UK — or if it functions as a search engine. A purely functional companion app that displays only the individual user's own data (sensor readings, device status, personal usage history) is not a U2U service. The app crosses into regulated territory when it adds features that allow user-generated content to be shared or encountered: community feeds, shared automations, public wishlists, product reviews visible to other users, public Q&A sections, or integration with social media content. The key question is whether User A can encounter content that User B created, in the UK.

### What are the penalties for non-compliance with the Online Safety Act?

Ofcom has significant enforcement powers under the OSA. For most failures to comply with OSA duties, Ofcom can impose financial penalties of up to £18 million or 10% of qualifying worldwide revenue — whichever is greater. For the most serious contraventions — including systemic failures by Category 1 services — penalties can reach £18 million or 10% of global turnover. Ofcom can also issue enforcement notices and business disruption measures, including requiring app stores or payment providers to withdraw services from a non-compliant provider. Senior managers who fail to take steps to prevent non-compliance after an Ofcom notice can face personal criminal liability and fines.

**Disclaimer:** Educational resource only. UK regulatory requirements change. Consult a qualified UK solicitor or compliance specialist before making decisions.

🇬🇧 UK roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/09-ukca-marking-for-electronics-products)[Prefer to read? Get the book — $24.99](/books/09-ukca-marking-for-electronics-products)

Related guides

*   [UK PSTI ActUK PSTI Act 2022: mandatory security requirements for consumer connectable products, statement of compliance, and OPSS enforcement from April 2024.](/guides/uk-psti-act-connected-products)
*   [UK GDPR for Connected ProductsUK GDPR applies to any connected hardware product collecting or transmitting personal data about UK users.](/guides/uk-gdpr-connected-products)
*   [UK NIS RegulationsThe UK NIS Regulations 2018 create supply chain obligations that affect hardware and IoT product suppliers to regulated sectors.](/guides/uk-nis-regulations)
*   [UK Cyber Essentials for Connected ProductsWhat Cyber Essentials certifies, and how it differs from PSTI product security rules.](/guides/uk-cyber-essentials-connected-products)
*   [UK AI and Product RegulationComplete guide to UK AI regulation for product manufacturers: current UK AI governance framework, AI Safety Institute, interact…](/guides/uk-ai-product-regulation)