An admission, not a discovery
Testifying to the House of Lords Communications and Digital Committee on September 15, 2026, Ofcom's director of enforcement, Suzanne Cater, told peers that "realistically the majority" of the more than £7 million in Online Safety Act (OSA) fines levied on 11 providers remain unpaid. Ofcom's Oliver Griffiths added that enforcement so far has concentrated on smaller pornography-industry firms, with the largest single penalty — £1.35 million against 8579 LLC in February 2026, plus a further £50,000 for ignoring an information request — still the high-water mark (Ofcom; The Register). This is not really a new discovery. It's a public acknowledgment of a structural problem the Act's fine regime was always going to run into: a UK regulator's penalty is only as good as its ability to reach the defendant's money.
Steelmanning the case for tougher enforcement
The strongest response to this story is not "Ofcom is overreaching" — it's the opposite. Children's Commissioner Dame Rachel de Souza told The Register on September 3, 2026 that children say the OSA "has made absolutely no difference" to their exposure to harmful content, and that she is "pretty furious" Ofcom won't share platform risk assessments with her office despite her statutory child-safeguarding role (The Register). DSIT Secretary of State Liz Kendall has separately pressed Ofcom in writing to move faster, telling the regulator it has the government's "full backing to use all its powers" and that delays risk undermining protections for women and girls (GOV.UK). If the regime's fines aren't being paid, the instinct in Westminster will be to conclude Ofcom needs bigger hammers, not fewer.
That instinct is understandable but points at the wrong target. Non-payment isn't evidence that fines are too small — Ofcom hasn't disclosed how many firms it has even tried to collect from in full, and the £950,000 penalty against an offshore suicide-forum operator, unpaid since May 2026, was already large by the standards of this enforcement strand. The problem is jurisdictional, not arithmetic.
Where the Act's design breaks down
Ofcom's own evidence to the Committee spells out the mechanism. Business-disruption measures — court orders compelling UK ISPs to restrict access to a site — can only be sought where non-compliance is ongoing; they cannot be used purely to force payment of a debt that's already been assessed. In the suicide-forum case, Ofcom said it had "used the powers we've been granted to the fullest extent possible," resulting in a UK access block for most users, while the underlying £950,000 debt sits uncollected because the operator holds no UK assets a court can attach (Digit.fyi). A blocking order punishes UK users' access; it does nothing to a foreign bank account.
Ofcom now says it will pursue senior-manager personal liability and register unpaid penalties as judgment debts — the latter a standard civil-recovery tool, but one that still depends on the debtor holding assets somewhere a UK judgment can reach. Against firms deliberately structured offshore with no UK presence, a judgment debt is a filing cabinet entry, not a payment.
The enforcement gradient runs backwards
This is where Open Rights Group's long-standing critique of the OSA's compliance architecture becomes relevant, even though it was written about a different symptom. ORG has argued that the Act's duties fall hardest on small, UK-based, often volunteer-run services — forums, hobbyist communities — who are reachable, respond to Ofcom's information notices, and either comply expensively or shut down, while resourced but evasive operators, frequently offshore and in the adult or extremist-content space, treat fines as a cost of doing business they can simply decline to pay (Open Rights Group). The practical enforcement gradient the OSA has produced is nearly inverted: compliance pressure is heaviest on operators least likely to cause serious harm, and lightest — in the sense of actually being collectible — on the offshore actors the Act's most serious provisions were written for.
What proportionate reform looks like
None of this argues for weaker rules on the content that plainly should be restricted — pro-suicide forums and unverified pornography sites accessible to children are exactly the harms the OSA was built to address, and Ofcom's caution about overusing blocking powers is itself appropriate; unilateral network-level blocking is a blunt instrument with real speech costs, and reserving it for genuine ongoing non-compliance rather than debt collection is the right call, not a loophole to close by force. But raising headline fine ceilings or expanding personal criminal liability for UK-based senior managers will mostly deter compliant UK operators and investors weighing whether the UK is a sane place to run a platform, while doing nothing to the offshore operators the £7 million was actually aimed at. The more proportionate fix is boring: mutual legal assistance and cross-border enforcement cooperation — following the money through payment processors and hosting providers, as tax and sanctions enforcement already do — rather than a domestic-liability arms race that punishes the reachable while the unreachable remain untouched.
Ofcom's admission is a useful correction to a common assumption in UK tech policy: that a bigger fine automatically means better enforcement. Against defendants with no UK assets, it doesn't mean enforcement at all.