Featured Article: PM Warns X It Could Lose The Right To Self Regulate

UK Prime Minister, Sir Keir Starmer, has warned that Elon Musk’s X could lose the “right to self regulate” after its Grok AI tool was linked to the creation and circulation of illegal sexualised imagery, prompting a formal Ofcom investigation and an accelerated UK government response.

Background

The controversy centred on X, formerly Twitter, and its AI chatbot Grok, developed by xAI. In early January, multiple reports and user complaints highlighted that the Grok account on X had been used to generate and share digitally altered images of real people, including women being undressed or placed into sexualised scenarios without their consent. Some of the reported material involved sexualised images of children, raising concerns that the content could meet the legal definition of child sexual abuse material.

In several cases, individuals said large volumes of sexualised images had been created using the tool, with content spreading rapidly once posted. Campaigners argued that the integration of AI image generation directly into a social platform significantly increased the speed and scale at which this form of abuse could occur.

The issue fed into a wider debate about AI-generated intimate image abuse, sometimes referred to as nudification or deepfake sexual imagery. While the sharing of such material has long been illegal in the UK, ministers argued that generative AI had transformed the threat by lowering the technical barrier to abuse and increasing the likelihood of mass distribution.

The Warning

The political response escalated on Monday 12 January 2026, when UK Prime Minister Keir Starmer addressed Labour MPs at a meeting of the Parliamentary Labour Party. During that meeting, Starmer warned that X could lose the “right to self regulate” if it could not control how Grok was being used. He said: “If X cannot control Grok, we will – and we’ll do it fast, because if you profit from harm and abuse, you lose the right to self regulate.”

The warning came on the same day that Ofcom confirmed it had opened a formal investigation into X under the Online Safety Act, citing serious concerns about the use of Grok to generate illegal content.

On 15 January, Starmer reinforced his position publicly on X. In a post shared from his account, he wrote: “Free speech is not the freedom to violate consent. Young women’s images are not public property, and their safety is not up for debate.”

He added: “I welcome that X is now acting to ensure full compliance with UK law – it must happen immediately. If we need to strengthen existing laws further, we are prepared to do that.”

The timing was deliberate, as the warning coincided with mounting pressure on the government to demonstrate that recently passed online safety laws would be enforced decisively, including against the largest global platforms.

Why Grok Became A Regulatory Flashpoint

Grok’s image generation capability was not unique in the AI market, but its deployment inside a major social platform raised specific risks. For example, because Grok was embedded directly into X’s interface, images could be generated and shared within the same environment. This reduced friction between creation and publication, increasing the likelihood that harmful material could circulate widely before being detected or removed.

Ofcom said it made urgent contact with X on 5 January and required the company to explain what steps it had taken to protect UK users by 9 January. While X responded within that deadline, the regulator concluded that the situation warranted a formal investigation.

Ofcom said there had been “deeply concerning reports” of the Grok account being used to create and share undressed images of people that may amount to intimate image abuse, as well as sexualised images of children that may constitute child sexual abuse material.

What Losing The Right To Self Regulate Would Mean

Losing the right to self regulate would carry serious consequences for X.

Under the Online Safety Act, platforms are expected to assess the risks their services pose and put effective systems in place to prevent users in the UK from encountering illegal content. Ofcom does not moderate individual posts and does not decide what should be taken down.

Instead, its role is to assess whether a platform has taken appropriate and proportionate steps to meet its legal duties, particularly when it comes to protecting children and preventing the spread of priority illegal content.

Starmer’s warning made clear that if X is judged unable or unwilling to manage those risks through its own systems, the government and regulator are prepared to intervene more directly, shifting the balance away from platform-led oversight and towards formal enforcement.

In practical terms, that could mean e.g., Ofcom imposing specific compliance requirements, backed by legal powers, rather than relying on X’s own judgement about what safeguards were sufficient.

For example, under the Act, Ofcom can issue fines of up to £18 million or 10 per cent of qualifying worldwide revenue, whichever is greater. In the most serious cases of ongoing non-compliance, it can apply to the courts for business disruption measures.

These measures can include requiring payment providers or advertisers to withdraw services, or requiring internet service providers to block access to a platform in the UK.

What Is Ofcom’s Investigation Examining?

Ofcom said its investigation would examine whether X had complied with several core duties under the Online Safety Act. For example, these include whether X had adequately assessed the risk of UK users encountering illegal content, whether it had taken appropriate steps to prevent exposure to priority illegal content such as non-consensual intimate images and child sexual abuse material, and whether it had removed illegal content swiftly when it became aware of it.

The regulator is also examining whether X properly assessed risks to children and whether it used “highly effective age assurance” to prevent children from accessing pornographic material.

Suzanne Cater, Ofcom’s Director of Enforcement, said: “Reports of Grok being used to create and share illegal non-consensual intimate images and child sexual abuse material on X have been deeply concerning.”

She added: “Platforms must protect people in the UK from content that’s illegal in the UK, and we won’t hesitate to investigate where we suspect companies are failing in their duties, especially where there’s a risk of harm to children.”

While Ofcom acknowledged changes made by X, it has said the investigation remained ongoing and that it was working “round the clock” to establish what went wrong and how risks were being addressed.

The Response

X and xAI (Elon Musk’s AI company behind Grok) reportedly responded by tightening controls around Grok’s image generation features and publicly setting out their compliance position.

For example, X said it had introduced technical measures to stop the Grok account on the platform from being used to edit images of real people in revealing clothing, including swimwear. These restrictions apply globally and cover both free and paid users.

The company also said it had limited image creation and image editing via the Grok account on X to paid subscribers only, arguing this would improve accountability where the tool is misused.

In addition, X said it would geoblock, in jurisdictions where such material is illegal, the ability to generate images of real people in underwear or similar attire. xAI confirmed it was rolling out comparable geoblocking controls in the standalone Grok app.

Alongside these changes, X was keen to say it has zero tolerance for child sexual exploitation and non-consensual intimate imagery, and that accounts found to be generating or sharing such content would face enforcement action, including permanent suspension.

That said, at the same time, Elon Musk criticised the UK government’s response, suggesting it amounted to an attempt to restrict free expression. UK ministers rejected that characterisation, maintaining that the action was about enforcing criminal law and protecting people from serious harm, not limiting lawful speech.

The Government’s Legal And Policy Response

The regulatory pressure on X was matched by swift legislative action from the UK government. For example, Liz Kendall, the Technology Secretary, told MPs that the Data (Use and Access) Act had already created an offence covering the creation or request of non-consensual intimate images, but that the offence had not yet been brought into force.

She said the offence would be commenced that week and would also be treated as a priority offence under the Online Safety Act. Kendall described AI-generated sexualised images as “weapons of abuse” and said the material circulating on X was illegal.

She also said the government would criminalise the supply of tools designed specifically to create non-consensual intimate images, targeting what she described as the problem “at its source”.

Kendall rejected claims that the response was about limiting lawful speech, saying it was about tackling violence against women and girls.

Wider Implications For Platforms, AI Tools, And Users

It seems this case has become one of the most high-profile tests of the Online Safety Act since its duties came into force. It all means that for X, the risks include financial penalties, enforced changes to how Grok operates in the UK, and long-term reputational damage if the platform is seen as unsafe or slow to respond.

For other platforms and AI providers, the episode is also likely to send a clear signal that generative tools embedded into social systems will be scrutinised under UK law, regardless of where the technology is developed.

For businesses that use X for marketing, customer engagement, or recruitment, the dispute raises questions around brand safety, platform governance, and the risks of operating on a service under active regulatory investigation.

Also, at a regulatory level, the case shows that Ofcom is prepared to pursue major global platforms and to use the full range of powers available under the Online Safety Act where serious harm is alleged.

Challenges And Criticisms

Despite the technical changes and legislative pushback, it seems this episode has exposed a number of unresolved challenges and points of criticism. For example, one of the clearest tensions is between political pressure for rapid enforcement and the need for legally robust regulatory processes. Ministers have urged Ofcom not to allow investigations to drift, while the regulator has repeatedly stressed that it must follow the formal steps set out in the Online Safety Act.

There are also questions about the effectiveness of narrowly targeted technical controls. For example, critics have pointed to Grok’s earlier design choices, including permissive modes that encouraged provocative or boundary-testing outputs, as contributing to misuse. From that perspective, restricting specific prompts or image categories may address symptoms rather than the underlying incentives built into generative AI tools.

Also, age assurance, i.e., methods used to verify whether a user is a child or an adult, remains a significant area of concern. Ofcom has highlighted the need for “highly effective” protections for children, but deploying such systems at scale continues to raise questions around accuracy, privacy, and user trust.

What Does This Mean For Your Business?

The dispute around X and Grok seems to have clarified how far the UK government is prepared to go when online platforms are judged to be falling short of their legal duties, particularly where new AI tools are involved. The warning issued by the Prime Minister was not just rhetorical, and underlined a willingness to move beyond cooperative regulation if a platform cannot demonstrate that it understands and controls the risks created by its own systems.

For UK businesses, the case is a reminder that platform risk is no longer just a reputational issue but also a regulatory one. Organisations that rely on X for marketing, customer engagement, recruitment, or public communication should know that they are now operating on a platform under active regulatory scrutiny. That raises practical questions around brand safety, governance, and contingency planning, especially if enforcement action leads to service restrictions or further operational changes.

Also, the episode sets a precedent for how AI features embedded within digital services are likely to be treated under UK law. Ofcom’s investigation, alongside the government’s decision to accelerate legislation, signals that generative AI will be judged not only on innovation but on real world impact.

For platforms, AI developers, regulators, and users alike, the expectations are now clear. Companies rolling out generative AI tools are expected to build in safeguards from the outset, respond quickly when misuse occurs, and show regulators that risks are being actively managed, not simply acknowledged after the fact.

Company Check : Ofcom Investigates BT and Three Over 999 Call Failures

Ofcom has opened formal investigations into BT and Three following separate UK-wide mobile network failures this summer that left some customers unable to connect 999 emergency calls.

Two Major Outages

The investigations centre on two major outages, one affecting Three customers in June and another impacting BT and EE customers in July, both of which disrupted basic voice services across large parts of the country. Ofcom said it is examining whether the companies took sufficient steps to prevent the incidents and to protect access to emergency services, which are treated as a critical national function under UK telecoms regulation.

What Happened During The Summer Outages?

The first incident occurred on 25 June, when thousands of customers on the Three network reported being unable to make or receive voice calls. The outage was nationwide and affected not only Three customers but also users on virtual operators that rely on its infrastructure, including ID Mobile. While mobile data services largely remained available, voice calls failed to connect, including calls to emergency services.

Three later said the problem was triggered by “an exceptional spike in network traffic” caused by a third-party software configuration change. The company acknowledged that the disruption affected access to 999 services and informed Ofcom at the time.

A second incident followed on 24 and 25 July, when customers on BT and its mobile network operator EE reported similar problems. In this case, BT attributed the disruption to a software issue that affected call interconnection between networks. As a result, some customers were unable to make or receive calls, including calls to emergency services, despite having signal on their devices.

Ofcom said both incidents caused UK-wide disruption and affected millions of mobile users across the two networks.

Why 999 Call Failures Raise Regulatory Stakes

While mobile outages are not uncommon, failures that prevent access to emergency services significantly increase regulatory scrutiny. For example, under UK law, telecoms providers have specific obligations to ensure that 999 and 112 calls can be made reliably, even during periods of network stress or partial failure.

Ofcom said providers must take “appropriate and proportionate” measures to identify risks to their networks and to plan for scenarios that could compromise availability, performance or functionality. These duties extend beyond preventing outages altogether and include effective monitoring, rapid response and mitigation when failures occur.

In announcing the investigations, Ofcom said it would assess “whether there are reasonable grounds to believe that BT and Three have failed to comply with their regulatory obligations”.

The regulator has not suggested that enforcement action is inevitable, but it does have the power to impose financial penalties, require remedial changes to network design or processes, or issue formal directions if breaches are found.

Network Resilience

Ofcom has placed increasing emphasis on network resilience in recent years, particularly as the UK becomes more reliant on mobile connectivity for essential services. For example, its Network and Service Resilience Guidance sets out expectations for how providers should design and operate networks to reduce single points of failure and limit the impact of incidents.

The guidance states that firms are expected to “identify and reduce the risks of disruption” and to take steps to prevent “adverse effects arising from any such compromises”. Where outages do occur, providers are expected to respond quickly, communicate clearly with customers and learn lessons to reduce the likelihood of recurrence.

Commenting on the investigations, Ofcom said: “The importance of connectivity cannot be underestimated. People rely on their mobile phones to stay in touch, to work, and to contact the emergency services.”

The regulator has made clear that customer impact, including the duration and scale of disruption, will be a central factor in assessing whether obligations were met.

Industry Reaction And Company Responses

Both companies have said they are cooperating fully with the investigation. A spokesperson for BT Group said the company apologised to customers affected by the July incident and would “co-operate fully with Ofcom throughout the investigation”. BT has previously said the outage was caused by a software issue rather than a hardware failure, and that services were restored once the fault was identified.

Three UK said it had engaged openly with Ofcom since the June outage and would continue to do so. The company said the disruption followed a third-party software configuration change that led to unexpected traffic levels on its voice network.

Ofcom has previously made clear that outages can still occur even where networks are designed with resilience in mind, but that providers are expected to have robust processes in place to detect faults quickly, limit their impact, and identify lessons that reduce the risk of similar incidents in future.

The regulator’s guidance stresses that compliance is not limited to preventing failures outright. It also includes effective planning, monitoring and response when services are disrupted, particularly where access to emergency calls is affected.

Previous Enforcement Action

The investigations also take place against a backdrop of previous enforcement action in the sector. For example, back in July 2024, BT was fined £17.5 million after Ofcom found a “catastrophic failure” in its emergency call handling service had prevented around 14,000 999 calls from connecting during a ten-hour outage in June 2023.

Three has also previously been fined by Ofcom. In 2017, the company was ordered to pay £1.9 million after a network failure in 2016 left customers without service. Ofcom concluded at the time that the disruption could have been prevented with better planning and safeguards.

More recently, Three’s UK operations merged with Vodafone to form VodafoneThree, creating the UK’s largest mobile network with around 27 million customers. While the summer outage occurred before the merger was completed, the investigation comes at a sensitive time as the combined business works to integrate networks and systems.

Why The Issue Matters More Now

The timing of the outages has heightened concern because mobile networks are increasingly treated as critical infrastructure. As the UK progresses with the digital landline switchover, many households and vulnerable users are becoming more dependent on mobile connectivity for emergency communication.

Ofcom has repeatedly warned that resilience expectations apply not just to traditional landlines but to all networks that support access to emergency services. The regulator has also highlighted the need for additional safeguards for users who rely on telecare systems, personal alarms or medical monitoring that may depend on voice connectivity.

Government guidance has echoed these concerns, with ministers previously stating that communications providers have statutory obligations to ensure networks are “appropriately resilient”.

What Ofcom Will Examine Next

Ofcom said its investigations will focus on the facts surrounding each incident, including how the faults arose, how quickly they were detected, and what steps were taken to restore services and protect emergency calling. It will also examine whether risk assessments, change management processes and contingency planning were adequate.

The regulator has not set a public timetable for completing the investigations and outcomes could range from no further action if compliance is found, through to enforcement measures if breaches are identified.

What Does This Mean For Your Business?

The investigations place renewed focus on how mobile networks are operated, governed and tested in practice, particularly where basic voice services are relied on for public safety rather than convenience. For Ofcom, the outcome will help clarify how existing resilience rules are being applied in real incidents and whether further intervention is needed to ensure emergency access is protected as networks become more complex and software-driven.

For telecoms providers, the cases highlight how resilience is being judged across the full lifecycle of network management, from configuration changes and third-party dependencies through to detection, response and communication. The fact that both incidents involved software-related failures rather than physical damage is likely to be closely examined, especially as automation and network virtualisation play a growing role in UK mobile infrastructure.

There are also wider implications for UK businesses that depend on mobile voice services for operational continuity, safety procedures and customer contact. For example, prolonged or widespread loss of calling capability, even where data services remain available, can disrupt frontline operations, lone worker safety and emergency escalation processes. The investigations may prompt organisations to recheck how resilient their own communications arrangements are, particularly where mobile phones are the primary or sole method of contact.

For consumers, emergency services and vulnerable users, the cases reinforce why mobile networks are now treated as critical infrastructure rather than optional utilities. As the digital landline switchover continues and reliance on mobile connectivity deepens, the tolerance for failures affecting 999 access appears to be narrowing. How Ofcom responds, and what it requires of operators as a result, is likely to shape expectations around network reliability and accountability well beyond these two incidents.

Featured Article : Ofcom Fines Virgin Media £23.8 Million

Ofcom has fined Virgin Media £23.8 million after finding that the company’s move to digital landlines left thousands of vulnerable telecare customers at direct risk of harm.

What Ofcom Has Decided

On 1 December 2025, Ofcom announced that it had imposed a £23.8 million penalty on Virgin Media for serious failings during its programme to migrate customers from traditional analogue landlines to digital services.

Why?

The regulator’s investigation concluded that, between August 2022 and December 2023, Virgin Media’s handling of telecare users breached its consumer protection obligations. For example, under Ofcom’s rules, telecoms providers must have clear and effective policies to ensure the fair treatment of customers whose circumstances make them vulnerable.

In practice, Ofcom found that Virgin Media failed on two major fronts. First, it did not properly identify and record telecare customers, which created significant gaps in its screening and support processes. Second, it disconnected some known telecare users who did not respond to the company’s contact attempts about the digital switchover, despite the risks that disconnection posed.

Those disconnections prevented telecare alarm devices from reaching monitoring centres in an emergency, leaving affected users in potentially unsafe situations. Ofcom said this put thousands of vulnerable people at direct risk of harm.

Four Weeks To Pay

Virgin Media must pay the £23.8 million fine within four weeks. The amount reflects a 30 per cent reduction in recognition of the company’s decision to admit liability, cooperate with Ofcom’s investigation and enter a formal settlement process.

Why Telecare Users Were So Exposed

Telecare systems are widely used by elderly, disabled or otherwise vulnerable people who rely on an emergency pendant or wristband to call for help. When activated, the device connects via the user’s landline to an alarm monitoring centre or a designated carer. Any break in that connection, therefore, can have severe consequences for anyone experiencing a fall, sudden illness or another emergency.

Transition

The UK’s telecoms sector is currently transitioning from the ageing public switched telephone network, the copper based PSTN, to digital IP based voice services. The PSTN is now considered beyond its intended lifespan and increasingly unreliable, which is why the digital upgrade is underway across the industry.

For most households, the change is relatively straightforward. For telecare users, however, migration must be handled with greater care. Telecare devices may not work correctly if not fully tested on digital lines, and power outages can affect digital services unless appropriate backup solutions are in place. For this reason, Ofcom has repeatedly stressed that telecoms companies must identify, protect and support these users throughout any transition.

How Virgin Media’s Switchover Went Wrong

Virgin Media first alerted Ofcom to a series of “serious incidents” involving telecare customers in November and December 2023. These reports triggered a formal investigation into whether the company had systemic issues in its migration process.

Over a period of roughly sixteen months, Ofcom found that Virgin Media’s approach had exposed vulnerable users in several ways. For example, significant numbers of telecare customers were not correctly identified in Virgin’s internal systems, meaning they were not flagged for the additional support required during migration.

Ofcom also found that Virgin Media disconnected some telecare users who did not respond to letters, emails or calls about the switchover. These disconnections went ahead even though the company was aware of the risks this created for users who depended on working landlines for emergency assistance.

During its remedial work, Virgin Media contacted 42,991 identified telecare customers to support them through migration. This figure gives a sense of the scale of the telecare customer base that the company needed to re-assess once the issues came to light.

What Virgin Media Says In Its Defence

Virgin Media has accepted Ofcom’s findings and the pretty substantial fine. The company has emphasised that the majority of migrations were completed without issue, but acknowledges that it did not get everything right for telecare users.

A spokesperson said the company recognised the problems that occurred and had since addressed the issues identified by Ofcom. Virgin Media has also highlighted the broader context, stating that the move to digital phone lines is essential because analogue lines are becoming less reliable and are increasingly difficult to maintain.

Reviews And Improvements

The company says it’s carried out an end to end review of its digital migration processes and introduced a “comprehensive package of improvements”, including:

– Better targeted communications for telecare users.

– Additional in home support during the switchover.

– Extensive post migration checks.

– Manual reviews of customer records to identify additional telecare users.

– A new policy that keeps non engaging telecare customers in a continuous engagement process rather than disconnecting them.

Virgin Media also says it is working with government, Ofcom and local authorities on a national awareness campaign to help improve understanding of the digital switchover and the specific needs of telecare users.

Virgin Media Customers

For most customers, the fine itself doesn’t change day to day services, since the money will go directly to the Treasury. However, the wider questions relate to whether Virgin Media’s updated processes are now strong enough to prevent a recurrence and whether customers, particularly those responsible for the care of vulnerable people, can have confidence in the company’s revised safeguards.

Businesses that rely on landlines for safety critical systems are likely to now be paying close attention to these developments. For example, telecare is the highest risk category, but many organisations still have legacy analogue dependencies, including alarm systems, lift phones, payment terminals and monitored entry systems. As the Virgin Media case shows, identifying those dependencies early is essential to ensure continuity during migration.

How Significant Is This Penalty?

The penalty sits among Ofcom’s larger fines in recent years. It is smaller than the £50 million fine issued to Royal Mail in 2018 and the £42 million penalty imposed on BT in 2017, but it is one of Ofcom’s largest decisions involving consumer protection rather than competition or technical service breaches.

What sets this case apart, however, is its focus on vulnerability and safety. Ofcom has made clear that the digital switchover cannot be treated as a purely technical exercise, particularly where safety critical devices are involved. Providers must be able to demonstrate that they have identified every customer who relies on telecare or similar services and that they have a safe, verified plan for migrating them.

Implications For Rivals And The Wider PSTN Switchover

The decision arrives during a complex national transition. Telecoms providers, government and industry bodies have agreed new charters and non voluntary migration checklists designed to strengthen protections for vulnerable customers. These include new expectations around individual risk assessments, enhanced contact attempts and safeguards before any disconnection can take place.

Other major providers have already had to revise their own migration plans in response to concerns about telecare reliability. The Virgin Media case is likely to intensify scrutiny across the sector, as Ofcom has made clear that it will not hesitate to take enforcement action if providers cannot demonstrate that vulnerable customers are being safeguarded.

Questions And Criticisms

The decision has raised several points of debate. For example, one relates to the absence of direct compensation, since the fine goes to the Treasury rather than to affected customers or local authorities who may have had to respond to incidents during the switchover. Ofcom’s role in this case is enforcement rather than redress, which means affected users will not receive direct financial support through this process.

Another issue is whether the failures identified at Virgin Media point to a broader challenge for the sector. Telecare providers, charities and parliamentary committees have continued to highlight confusion about responsibilities during migration, particularly where equipment manufacturers, care providers and telecoms companies all play different roles in keeping telecare services working.

There are also concerns that awareness among small businesses and property managers remains low. For example, even organisations not directly involved in health or social care may still rely on analogue lines for alarms, access systems or monitoring equipment without realising the implications of the switchover. The Virgin Media enforcement action is likely to prompt renewed calls for clearer guidance, more proactive industry communication and closer coordination with equipment suppliers.

What Happens Next?

Virgin Media has already paused and redesigned parts of its migration process. The company is now operating under updated policies, a revised engagement model for telecare users and closer regulatory oversight.

Ofcom is continuing to issue guidance on how providers should handle the remainder of the PSTN switch off. This includes expectations around vulnerability assessments, business continuity planning and coordination with emergency services, local authorities and telecare operators.

The case is likely to remain a reference point for months to come as organisations, regulators and telecoms companies navigate the final stages of the UK’s shift to digital landline services.

What Does This Mean For Your Business?

This enforcement decision leaves the sector with a clearer sense of what regulators expect during the remainder of the switchover. Virgin Media’s failings were specific, but the underlying challenges are shared across the industry, particularly the difficulty of mapping analogue dependencies and ensuring that every vulnerable user is identified before any change goes ahead. The scale of the fine signals that Ofcom is prepared to act when those responsibilities are not met, which will shape how major providers approach their own migration plans over the next year.

The case also demonstrates why UK businesses should pay closer attention to their remaining reliance on analogue systems. Many organisations have digitalised most of their operations but still depend on a single lift line, alarm system or monitored entry point that uses outdated infrastructure. The disruption experienced by telecare users shows how easily those hidden dependencies can be overlooked and why forward planning is essential. For sectors such as housing, healthcare, facilities management and retail, the risks are not only technical but operational and reputational.

For telecare users, charities and local authorities, the decision provides reassurance that regulators are watching and treating these risks seriously. It also highlights how fragmented responsibilities have made safe migration more complicated. Telecoms providers can update their own processes, but the safety of vulnerable customers also depends on the readiness of equipment manufacturers, monitoring centres and care providers. The outcome may drive more coordinated planning across these groups, which has often been missing.

The broader lesson for the sector is that the digital switchover is not simply a matter of replacing one network with another. It is an exercise in risk management that requires precise data, careful customer engagement and a full understanding of how different services interact with the telecoms network. Virgin Media has now rebuilt much of its process, but the scrutiny it faced is likely to set new expectations for every provider involved in the transition.

As the migration continues, the focus will shift to whether the safeguards now put in place are strong enough to prevent a repeat of the problems uncovered here. The coming months will show whether the industry can maintain the pace of digital upgrade while keeping vulnerable customers protected and giving businesses and public sector bodies the certainty they need to manage their own critical systems.

Company Check : Businesses Choose Proxies As VPNs Face Rising Scrutiny

A growing number of UK companies are moving away from VPNs and adopting proxy services instead, while regulatory pressures and changing business needs reshape the digital tools used for online operations.

Regulatory Drivers Behind the Shift

The trigger for this apparent trend has been the UK’s Online Safety Act, which came into force on 25 July 2025. The law requires platforms hosting user-generated content to carry out risk assessments, enforce strict age verification, and prevent users from bypassing restrictions. Ofcom, the regulator tasked with enforcement, has flagged VPNs as a potential loophole in these measures. This has left businesses increasingly wary about relying on them, even though the government has said there are no immediate plans to ban VPN services outright.

VPN usage in the UK has nevertheless surged in the wake of the Act. For example, figures show Proton VPN sign-ups rose by 1,800 per cent and Nord Security registrations climbed by 1,000 per cent in the days following the new rules, while VPN apps dominated the UK App Store rankings. However, what once looked like a straightforward privacy tool has now become a focal point for regulators. Companies that rely on VPNs for tasks such as market research, competitive analysis, or data collection are finding themselves exposed to new risks of compliance problems and potential scrutiny.

Proxy Demand Surge

This uncertainty has pushed many businesses to explore alternatives. Proxies, which route traffic through an intermediary server without encrypting it in the same way as a VPN, have emerged as a preferred option for a growing range of enterprises. Data from Decodo, a global proxy provider, shows UK proxy users have increased by 65 per cent since the Act was introduced, with proxy traffic rising by 88 per cent.

Industry leaders suggest this is not just a temporary workaround but a reflection of a more deliberate strategy. “Companies around the globe are getting smarter about how they operate in highly competitive landscapes. Instead of just picking the most popular tools, they’re choosing what actually works best for them,” said Vytautas Savickas, CEO at Decodo.

Examples of Proxy Providers

Several proxy companies now leading the market for UK businesses. For example, Oxylabs and Bright Data are recognised for their scale, offering millions of residential, datacentre, mobile and ISP IP addresses worldwide, including large UK pools. Decodo, formerly Smartproxy, has become popular for its balance of affordability and ease of use, while Webshare provides reliable service and even a free tier for smaller tasks. SOAX specialises in city-level targeting across the UK, making it useful for location-sensitive operations, while IPRoyal and Rampage Proxies are seen as accessible entry-level choices. Together, these firms illustrate how far the proxy market has developed, offering tools that range from budget options to enterprise-grade services.

How Much Do Proxies Cost?

Obviously, pricing for proxies varies depending on type, usage volume and provider. Just as an example, however, at the lower end, services like Rampage Proxies start around $1 per gigabyte for residential proxies, while SOAX charges about $3.60 per gigabyte on smaller plans, dropping to closer to $2.50 for high-volume commitments. Enterprise providers such as Oxylabs and Bright Data are typically in the $3–$4 per gigabyte range. In practical terms, this means a small business might spend £100–£300 per month, with medium-sized operations budgeting £300–£1,000, and large enterprises paying upwards of £1,200. By contrast, business VPNs usually charge per user, between $7 and $18 a month, which is cost-effective for secure team access but less suited to the high-volume, region-specific tasks where proxies are increasingly used.

Technical and Strategic Benefits

One reason proxies are becoming more attractive is the greater level of control they provide. VPNs typically encrypt traffic and route it through a single tunnel, which is valuable for privacy but less useful for certain business functions. Proxies, on the other hand, allow more granular routing and customisable access. This means organisations can target data collection by location, test region-specific websites, or monitor competitors without triggering the same kinds of red flags that VPN use often does.

For example, in eCommerce, proxies are being used for price tracking and ad verification, ensuring that online campaigns appear correctly in different regions. In finance and fintech, they help detect fraudulent activity by simulating access from multiple jurisdictions. In digital marketing, SEO teams rely on proxies to monitor search results from specific countries.

As Gabriele Verbickaitė, Product Marketing Manager at Decodo, explained: “More organisations in the UK are investing time in understanding the tools that power secure and efficient online operations. Most companies test out different solutions, providers, and do their research on proxies and VPNs, and they’re also making more informed, strategic choices.”

Innovative Proxy Types

It should also be noted here that the technology itself has matured rapidly. For example, modern proxy services are no longer niche or unstable tools but come bundled with enterprise-grade security features and user-friendly platforms. Companies can now choose from residential proxies, which mimic the IP addresses of home users, also mobile proxies, which use cellular networks, ISP proxies, which combine stability with speed, and datacentre proxies, which are optimised for scale and performance.

This variety gives firms options that align with their specific objectives. Residential and mobile proxies, for example, are harder to detect and block, making them useful for ad verification or web scraping. ISP and datacentre proxies, by contrast, are better suited to tasks requiring speed and high volumes of data. Vaidotas Juknys, Head of Commerce at Decodo, said: “UK businesses are quickly adopting proxy services, moving beyond simple VPNs to more advanced setups that offer greater control over their online activity. It’s no longer just about staying private – performance and reliability are now just as important.”

Security Trade-Offs

However, despite their appeal, proxies are not without risks. The key difference is that proxies do not encrypt traffic in the same way that VPNs do, leaving data potentially more exposed to interception or monitoring. For businesses dealing with sensitive information, this can create vulnerabilities if additional protections are not in place.

Free or poorly managed proxies pose even greater concerns. Studies have shown that many free proxy services are either unstable or actively malicious. Research published last year (University of Maryland and the Max Planck Institute for Informatics) found that only around 34.5 per cent of free proxies tested were active, with many exposing users to adware, credential theft, or malware. For this reason, security experts warn that firms should treat proxies as part of a broader, layered security strategy rather than a like-for-like replacement for VPNs.

At the same time, critics note that the rapid adoption of proxies could create its own regulatory flashpoints. Just as VPNs are being scrutinised for their role in bypassing restrictions, widespread proxy use may eventually attract similar attention. Privacy campaigners argue that this arms race between regulation and circumvention tools risks undermining trust in digital services altogether.

Some Key Challenges and Criticisms

The transition also raises some practical challenges. For example, businesses must ensure that the proxy providers they use have robust security and compliance standards. Unlike VPNs, which are relatively standardised, the proxy market is fragmented, with varying levels of reliability and transparency among providers. Companies that depend heavily on proxies for data-driven decision-making could find themselves exposed if those services are blocked, blacklisted, or compromised.

Another criticism is that while proxies offer technical advantages, they do not necessarily solve the deeper issues driving regulation in the first place. The Online Safety Act was designed to protect children and reduce harmful content online, yet businesses adopting proxies to sidestep VPN concerns may only be shifting the problem rather than addressing it.

These concerns highlight the complexity of the issue. On one side, businesses need practical tools to compete globally, collect data, and operate efficiently. On the other, regulators are pushing for tighter oversight of digital access, with VPNs and now proxies caught in the middle of the debate.

What Does This Mean For Your Business?

The evidence suggests that the move from VPNs to proxies is more than just a passing reaction to regulation. For UK businesses, proxies appear to offer some real operational advantages, from accurate regional targeting to resilience against restrictions that can disrupt data-driven work. Sectors such as eCommerce, finance and digital marketing are already embedding these services into their daily operations, treating them not as optional extras but as essential infrastructure. For many firms, the ability to monitor competitors, verify advertising, or track prices across multiple markets has become too important to risk on tools that may fall under heavier regulatory pressure.

However, the shift also carries unavoidable trade-offs. For example, proxies may deliver speed and flexibility, but they do not provide the same encryption and privacy protections as VPNs, which creates a different risk profile. This is forcing companies to rethink their wider security strategies and balance operational performance with robust safeguards. For regulators, the trend signals another layer of complexity, as proxy use could undermine some of the very protections that the Online Safety Act was intended to enforce.

What this means for UK businesses is that digital infrastructure decisions are no longer simply about cost or convenience. For proxy providers, the surge in demand represents an opportunity to cement their place in the enterprise market, but it also brings responsibility to deliver reliable, transparent and secure services. For policymakers, the growth of proxies underscores the difficulty of regulating technologies that adapt faster than legislation.

The result is a more finely balanced environment, where businesses gain new capabilities but also face new scrutiny. Proxies may now be the tool of choice for many UK firms, but their adoption highlights wider questions about how companies, regulators and consumers can navigate the shifting ground of online access and digital control.

Tech News : Ofcom Mandates Age Checks for Online Adult Content

The UK communications regulator, Ofcom, has announced robust new measures to prevent children from accessing online pornography (plus other potentially harmful content), a key component of the Online Safety Act.

By July

These new regulations will require websites and apps to implement highly effective age assurance systems by July 2025, marking a significant step towards creating a safer digital environment.

What Kind of Websites and Apps Will The New Regs Apply To?

Ofcom says its new regulations will apply to websites and apps that host pornographic content, including those that publish their own material and platforms with user-generated content, such as social media, tube sites, and cam sites. The rules will extend to services that allow harmful content and are likely to be accessed by children. Also, they cover platforms with user-to-user or search functionalities where children may encounter inappropriate material. These categories are defined under the “Part 3” and “Part 5” provisions of the Online Safety Act.

What’s The Problem?

Children in the UK are encountering explicit material online at alarmingly young ages. For example, research from the Children’s Commissioner for England shows that among those who have seen online pornography, the average age of first exposure is just 13. Alarmingly, more than a quarter of children (27 per cent) encounter explicit content by the age of 11, and one in ten as young as nine!

This pervasive exposure poses significant risks to children’s mental health and understanding of relationships, consent, and self-worth. However, despite these dangers, it seems that many platforms have operated without adequate safeguards, allowing harmful material to reach young users with ease.

As Melanie Dawes, Ofcom’s Chief Executive, puts it: “For too long, many online services which allow porn and other harmful material have ignored the fact that children are accessing their services. Today, this starts to change.”

Also, up until now, it seems that self-declared age verification methods, such as ticking a box to confirm your age, have proven ineffective. Platforms frequently treat all users as if they are adults and fail to provide meaningful barriers to prevent children’s access to explicit content.

A New Era of Online Safety

To tackle this issue, Ofcom has published detailed guidance for implementing effective age assurance measures as mandated by the UK’s Online Safety Act (passed in October 2023). These measures form a cornerstone of the Act, which aims to make online platforms accountable for their content.

What the new Ofcom regulations will mean for the platforms include:

– Immediate action for pornographic services. Platforms hosting their own pornography (‘Part 5’ services) must start introducing robust age checks immediately.

– Measures for user-generated content. Social media platforms and other user-to-user services (‘Part 3’ services) that allow user-generated pornography must implement highly effective age checks by July 2025.

– Children’s risk assessments. All user-to-user and search services likely to be accessed by children must complete a children’s access assessment by April 2025, with detailed risk assessments required by July.

What Is ‘Highly Effective’ Age Assurance?

Ofcom defines “highly effective” age assurance as methods that are accurate, robust, reliable, and fair. These methods must go beyond basic checks and address technical and practical challenges to ensure children cannot bypass safeguards.

For example, approved technologies include:

– Photo ID matching. Verification using government-issued identification.

– Facial age estimation. Analysing users’ facial features to estimate age.

– Open banking and credit card checks. Ensuring users’ ages align with financial account requirements.

– Mobile network age verification. Checks conducted through mobile operators.

– Digital identity services. Systems leveraging verified digital identities.

Self-Declaration Methods No Longer Acceptable

Critically, methods like self-declaration of age and payment processes not requiring proof of adulthood are no longer deemed acceptable. Also, platforms must ensure explicit content is not visible to users during the verification process and prevent efforts to circumvent the age assurance system.

A Gradual Rollout with Broad Implications

Ofcom says the introduction of these measures will roll out incrementally, with adults beginning to notice changes in how they access certain services. For example, platforms may require users to upload ID, verify through biometric data, or use credit card checks.

As Ofcom’s CEO, Melanie Dawes, says: “As age checks start to roll out in the coming months, adults will start to notice a difference in how they access certain online services. Services which host their own pornography must start to introduce age checks immediately, while other user-to-user services – including social media – which allow pornography and certain other types of harmful content will have to follow suit by July at the latest.”

While these measures aim to protect children, Ofcom has also emphasised the importance of balancing privacy rights for adults. Notably, a survey by Yonder Consulting found that 80 per cent of UK adults support the implementation of age assurance measures to prevent children’s exposure to pornography.

How Will It Be Enforced?

To enforce compliance, Ofcom has launched an enforcement programme targeting platforms that fail to engage or comply with the new requirements. Non-compliance could result in fines and other penalties.

Benefits of the New Rules

Clearly, a key benefit of the new rules should be to protect children from harmful online content and the hope is that by mandating robust age checks, platforms can significantly reduce the likelihood of children encountering explicit material, promoting safer and healthier online experiences.

Also, as regards safeguarding children, these measures appear to reinforce the UK’s leadership in the tech-safety sector. For example, according to research by Paladin Capital and PUBLIC, the UK accounts for 23 per cent of the global safety tech workforce, with 28 per cent of safety tech companies based in the UK. The introduction of age assurance measures is, therefore, expected to stimulate further innovation and growth within this burgeoning industry.

Julie Dawson, chief regulatory and policy officer at age verification platform Yoti, emphasised the importance of the guidance, saying: “It is essential for creating safe spaces online. Age assurance must be enforced across pornographic sites of all sizes, creating a level playing field and providing age-appropriate access for adults.”

Challenges and Criticisms

Despite the obvious benefit of protecting children, privacy and rights campaigners have raised significant concerns about Ofcom’s new age verification regulations under the Online Safety Act, warning of potential risks to privacy, security, and user rights. For example, The Open Rights Group (ORG), a digital rights advocacy organisation, has been vocal in highlighting these issues. Abigail Burke, ORG’s Programme Manager for Platform Power, has stated, “Age verification technologies for pornography risk sensitive personal data being breached, collected, shared, or sold.”

The ORG has also pointed to similar proposals that were abandoned in Australia due to privacy and security concerns, suggesting that the UK should carefully consider these issues to avoid unintended consequences. Civil society groups have similarly criticised Ofcom for allegedly prioritising changes suggested by the tech industry over recommendations from privacy advocates to strengthen the codes.

Campaign group Big Brother Watch has also highlighted risks associated with age assurance methods, including data breaches, digital exclusion, and the erosion of online privacy. They argue that while protecting children online is essential, many age verification technologies could create new vulnerabilities, particularly around data security.

Some critics have also drawn attention to unintended consequences observed in similar initiatives elsewhere. For instance, when Louisiana introduced age verification laws for pornography sites, traffic to regulated platforms dropped by 80 per cent. However, users did not stop accessing explicit material and instead migrated to less-regulated and potentially more harmful corners of the internet.

This sentiment has also been echoed by Aylo, the parent company of Pornhub, which has criticised the measures as “ineffective, haphazard and dangerous.” The company warned: “These people did not stop looking for porn; they just migrated to darker corners of the internet that don’t ask users to verify age. In practice, the laws have just made the internet more dangerous for adults and children.”

These criticisms highlight the tension between enhancing online safety for children and preserving individual privacy rights in the digital realm. While the regulations aim to protect vulnerable users, critics argue that their implementation must be carefully managed to avoid creating new risks or driving harmful behaviours underground.

Looking Ahead

Ofcom’s guidelines are a step forward in addressing the long-standing issue of children’s exposure to harmful online content. By enforcing robust age assurance, it’s hoped that the measures can foster a safer online environment while balancing privacy considerations for adults.

As the July 2025 deadline approaches, the challenge will lie in ensuring that platforms adopt these measures effectively, without creating unintended consequences or compromising user rights. With rigorous enforcement and collaboration between regulators, platforms, and the safety tech industry, these changes could redefine online safety in the UK.

What Does This Mean For Your Business?

The introduction of Ofcom’s age verification regulations could be a pivotal moment in the effort to create a safer digital environment, particularly for children. By requiring websites and apps to implement robust age assurance systems, the UK aims to address the significant risks posed by children’s exposure to harmful online content, ensuring they are protected during formative years.

The potential benefits are clear, i.e. stronger safeguards for children, a reduction in exposure to inappropriate material, and a reinforcement of the UK’s leadership in tech-safety innovation. These measures signal progress in holding platforms accountable for their content and prioritising the safety of vulnerable users. As Julie Dawson of Yoti points out, creating “safe spaces online” is essential, and the consistent enforcement of age assurance can help achieve this goal.

However, this ambitious undertaking is not without its challenges. Privacy and rights campaigners have raised (valid) concerns about the risks of data breaches, digital exclusion, and the potential erosion of online privacy. The possibility of unintended consequences, such as users migrating to less-regulated corners of the internet, further complicates the picture. Critics, including Aylo and Big Brother Watch, have emphasised the need for careful implementation to avoid exacerbating existing risks.

For platforms, the regulations will demand a shift in how they manage user access and content. Implementing robust age verification systems will likely require significant investment in new technologies, such as photo ID matching or facial age estimation. Smaller platforms, in particular, may face challenges in meeting these requirements without external support or resources. Also, platforms must carefully balance compliance with privacy concerns to maintain user trust, particularly as adults begin to notice changes in how they access services.

Advertisers, too, will need to adapt. Platforms that introduce age verification systems may see shifts in user demographics, potentially affecting audience reach and targeting strategies. Advertisers that rely on platforms hosting adult content may need to navigate a changing landscape where regulated and unregulated spaces coexist, with a heightened emphasis on compliance and ethical advertising.

The success of these regulations will, therefore, ultimately depend on how well they balance the protection of children with the rights and privacy of all users. Ofcom’s approach, which allows space for technological innovation while setting clear standards, provides a solid foundation. However, ongoing dialogue and collaboration between regulators, platforms, advertisers, and advocacy groups will be essential to address concerns and adapt to unforeseen challenges.

As the July 2025 deadline draws closer, the spotlight will remain on how platforms respond to these requirements, how advertisers adjust their strategies, and how effectively Ofcom enforces the new rules. If managed successfully, the hope is that these measures could set a global benchmark for online safety, shaping a digital landscape where safety, privacy, and commercial interests coexist harmoniously.

Featured Article : Children Hide Online Life From Families

New research by the Children’s Commissioner for Wales, Rocio Cifuentes, has revealed that only 1 in 4 children in Wales tell their families about their online life.

Survey 

The survey about online safety was conducted in June 2024 to inform Cifuentes’s response to Ofcom’s consultation on its widening powers relating to the Online Safety Act (2023). The results were drawn from responses given by 1284 children and young people between the ages of 7 and 18, from 16 local authorities.

Only 28 Per Cent Tell Their Families 

The most telling statistic coming from the results of this survey is that just one in four (28 per cent) of children said they talk a lot to their family about what they do online.

Apps That Made Them Unsafe 

The survey also revealed that 29 per cent of children who listed apps that made them feel unsafe or unhappy mentioned Roblox, followed by YouTube (17 per cent), and Snapchat (12 per cent).

Roblox 

Roblox is a “virtual universe app” where users play a wide variety of games (and create games within Roblox) and chat with others online.

The concerns shared about Roblox (by children as young as 8) were about ‘toxic and rude’ users, ‘aggressive behaviour’, the ability to have conversations with strangers, being ‘scammed’, and also experiences of racial discrimination. Some commentators have noted that the fact that Roblox is user-generated could explain why there may not be the same degree of rigour applied to age ratings as content made by commercial companies.

In recent years, several concerns have been raised about Roblox. For example, there are worries about child safety, including the presence of inappropriate content and the potential for online predators to interact with children. The platform’s monetisation practices have also come under scrutiny, with critics arguing that the in-app purchase system may encourage excessive spending by children. Also, there are concerns about the exploitation of young developers who create content for Roblox, often without receiving fair compensation.

Privacy issues with Roblox have been another concern among some commentators, particularly regarding the handling of the personal information of young users. Fears about excessive screen time and the potential for gaming addiction among children have also been frequently highlighted.

Despite these concerns, Roblox continues to be a popular platform and it should be noted that Roblox has many positive aspects and initiatives aimed at improving safety. For example, it offers a platform for creativity and learning, thereby allowing users to develop programming and game design skills while fostering a sense of community and social interaction globally. The platform also provides robust parental controls, enabling parents to manage their children’s interactions and limit access to certain features or content.

Other positive aspects of Roblox are that it employs a dedicated team and automated systems for content moderation to swiftly detect and remove inappropriate content. Safety features such as age-appropriate settings, restricted chat functions for younger users, and regular safety updates help are also used to create a safer environment for children, plus Roblox supports developers with incentives and educational resources to help them succeed and monetise their creations fairly.

It’s also important to acknowledge that Roblox was not the only platform noted by children in the survey as making them feel unsafe but may be one that parents know less about than YouTube and Snapchat.

Concerns Not Taken Seriously 

One other worrying statistic revealed by the survey is that when children reported concerns directly with an online platform, only 32 per cent said they felt their concerns had been taken seriously.

Parents Warned to Look Closely at App Parental Controls

Publishing the results of the survey ahead of the school summer holidays, the Children’s Commissioner for Wales urged parents to look closely at information on parental controls, app content, and age requirements.

Rocio Cifuentes MBE said: “Online apps can give children fantastic opportunities to be creative, to express themselves, and to connect with their friends. But there are dangers too, and I know that keeping up with everything young people do online can feel daunting for parents and carers. Ahead of the summer holidays, where children are likely to spend more time on screens, it feels especially important that parents are equipped with the knowledge they need.  

“Luckily, there’s comprehensive and clear information out there from people like the NSPCC, and the Welsh Government, that I’d encourage all parents to read. Knowing more about parental controls, how to approach conversations about usage, age requirements, and the content of the app could go a long way to keeping your child safe and happy when they’re online.” 

Three Quarters Feel Safe 

It’s also important to acknowledge that despite the important findings about how unsafe some children feel online, the survey also found that the majority (76 per cent) of children said they feel happy and safe online. Also, children and young people most commonly said that if they saw something online that made them upset or worried, they would tell their parents, report it to the platform, or tell another family member.

Screen Time – A Worry For Teachers 

Teachers in Wales have also expressed concerns about the impact children’s screen time has on their education, with some seeing the impact of tiredness amongst pupils due to late-night gaming.

What Does This Mean For Your Business? 

The findings from the Children’s Commissioner for Wales have significant implications for businesses operating in the app and online platform sectors. The survey highlights what could be described as a critical disconnect between children’s online experiences and parental awareness, which creates both challenges and opportunities for your business.

The fact that only 28 per cent of children discuss their online activities with their families shows a need for apps and platforms to pay more attention to transparent communication and user safety. This means not only ensuring robust parental controls and safety features but also actively educating both parents and children on their usage. Platforms like Roblox, YouTube, and Snapchat (all-too-frequently cited for making children feel unsafe) should take these concerns seriously and enhance their safety protocols. By doing so, they may be able to build more trust and foster a safer environment that encourages more open discussions between children and parents about their online activities.

Also, the concerns raised online about Roblox, ranging from interactions with strangers to racial discrimination, highlight the importance of stringent moderation and user education. This could mean investing in advanced content moderation technologies and employing dedicated teams to swiftly address inappropriate behaviour and content. Emphasising the ethical treatment of young developers and ensuring fair compensation can also enhance a platform’s reputation and attract a more engaged, loyal user base.

Privacy issues are another critical area that demands attention. With increasing scrutiny on how personal information is handled, businesses like app makers must implement robust privacy policies and practices. Clear communication about these measures can reassure parents and guardians, fostering a safer and more trustworthy environment for young users.

The survey finding that only 32 per cent of children feel their concerns are taken seriously by platforms is worrying and clearly presents an opportunity for businesses to improve their customer service and support systems. By implementing responsive and empathetic customer service practices, platforms could enhance user satisfaction and trust. Creating easy-to-use reporting mechanisms and ensuring that user feedback may also lead to tangible changes can demonstrate a genuine commitment to user safety and well-being.

Thankfully, the survey results also suggests that while there are substantial concerns, the majority of children feel happy and safe online. This indicates that there is a solid foundation upon which to build. By continuing to innovate and implement best practices in safety and moderation, businesses can not only address current issues but also enhance the overall user experience.

The key takeaway, therefore, is the importance of balancing safety and creativity. Platforms should continue to offer engaging, creative opportunities for young users while maintaining a strong commitment to their safety and well-being.

Tech News : EE and Plusnet Customers To Get Refund From BT

After an Ofcom investigation that found BT didn’t give clear and simple information to customers who signed up to deal with its subsidiaries EE and Plusnet, BT has been told it must refund early exit fees and let existing affected customers walk away penalty-free.

What Happened? 

Under new consumer protection rules, known as ‘General Conditions’ (GCs), that came into force in June 2022, phone and broadband companies, of which BT is both, must give consumers and small businesses the details of a contract, as well as a summary of its key terms, before they sign up. These details must include the price, the length of the contract, the speed of the service, and any early exit fees.

UK Telecoms regulator, Ofcom, says that it opened an investigation into BT after it received information that two of BT’s wholly-owned subsidiaries, EE and Plusnet, may not have been providing the required documents to some customers.

The Findings 

Ofcom says its investigation revealed that since the introduction of the new rules on 17 June 2022, EE and Plusnet made more than 1.3 million sales without providing customers with the required contract summary and information documents. Ofcom found evidence that 1.1 million customers were affected by this between 26 June and 30 September 2023, i.e. they were not given contract information before they signed up as is required under the new rules.

Other key findings by Ofcom were that:

– Despite telling Ofcom in February 2022 that it was confident the deadline to meet the new rules would be met, evidence showed that BT knew as early as January 2022 that some of its sales channels would not meet the deadline.

– In some cases, BT deliberately chose not to comply with the rules on time.

– Ofcom says that whereas other providers dedicated the resources required to meet the implementation deadline for the new rules, BT may have saved costs by not doing so.

– Some sales channels are still non-compliant, and BT is still not providing the required information at the right time to some customers.

The Outcome 

The outcome of Ofcom’s findings in this case are that:

– Ofcom has issued a £2.8 million fine to BT, although this includes a 30 per cent discount as a result of BT’s admission of liability and its completion of Ofcom’s settlement process.

– The 1.1 million customers affected have been given the opportunity to request the information and/or cancel their contract without charge.

– For those customers who left BT before the end of their contract and were charged an early exit fee, BT must refund those early exit fees, and let existing affected customers walk away penalty-free.

Other Action 

Other actions that BT has been instructed to take by Ofcom in relation to this case include:

– Identifying and refunding any affected customers who may have been charged for leaving before the end of their contract period, within five months of Ofcom’s decision.

– Within three months, contacting the remaining affected customers who are still with BT and have not already been contacted, to offer them their contract information and/or the right to cancel their contract without charge.

– Amending remaining sales processes that are still non-compliant within three months of Ofcom’s decision.

Unacceptable 

Ofcom’s Enforcement Director, Ian Strawhorne, said: “When we strengthened our rules to make it easier for consumers to compare deals, we gave providers a strict timeline by which to implement them. It’s unacceptable that BT couldn’t get its act together in time, and the company must now pay a penalty for its failings.”  

Also, Rocio Concha, Director of Policy and Advocacy for consumer organisation ‘Which?’ said: “It’s absolutely right that Ofcom is fining BT for not providing EE and Plusnet customers with clear contract information before they signed up – as some people will have been hit with pricey exit fees they never should have faced.” 

What Does BT Say? 

BT has been reported as saying that it is sorry, will “implement the remedial actions” required by Ofcom and has “taken steps to proactively contact affected customers and arrange for them to receive the information and be refunded where applicable.” 

What Does This Mean For Your Business? 

Ofcom’s ruling against BT is a reminder to telecoms companies and service providers about the importance of compliance with the latest regulatory requirements. For BT, this incident highlights the critical need for transparency and accountability in customer communications, especially in a competitive market where trust is paramount. The £2.8 million fine (which some commentators say should have been higher) and the mandated refunds are examples of the financial and reputational risks associated with non-compliance.

For other providers, this case is a cautionary tale that emphasises the need to adhere to consumer protection rules and the potential consequences of failing to do so. It also shows that companies that decide to push boundaries in their marketing campaigns must think more carefully about these strategies, ensuring that their promotional activities do not leave customers in the dark about what they are signing up for. In an industry where bundling services into complex contracts is common, maintaining clarity and simplicity within customer interactions is still essential to avoid regulatory scrutiny and potential penalties.

For customers, this case may see them benefit (a little) from increased regulatory oversight and assurances that providers must comply with clear guidelines, thereby helping them make more informed decisions about their service contracts. Also, the knowledge that you can exit contracts without penalty in cases of non-compliance should be reassuring and help consumers from being unfairly trapped in agreements they did not fully understand.