TLDR: The UK’s online safety regulator, Ofcom, has stated that AI chatbots, including those like ChatGPT, will be assessed individually under the Online Safety Act due to their complex nature. This announcement comes as platforms are urged to improve risk assessments for new priority offenses and clarifies the regulatory landscape for generative AI tools.
London, UK – November 11, 2025 – The UK’s online safety watchdog, Ofcom, has confirmed that it will address the regulation of artificial intelligence (AI) chatbots, such as ChatGPT, on a ‘case-by-case’ basis under the country’s Online Safety Act. This admission by the regulator highlights the ‘gray area’ these advanced generative AI tools currently occupy within the existing legal framework.
Mark Bunting, Ofcom’s online safety strategy director, emphasized this nuanced approach, indicating that the regulator is still actively examining how different types of chatbots should be categorized and treated under the Act. The clarification comes amidst growing calls from politicians and civil society groups for greater accountability and, specifically, mandatory age gating for these platforms.
In addition to outlining the individualized assessment for AI, Bunting issued a stern warning to several large online platforms. He stated that many would need to revise and update their previously submitted risk assessments, which have been deemed ‘weak or incomplete.’ These updated assessments must adequately reflect newly introduced ‘priority offenses’ under the Online Safety Act.
Ofcom has been actively working to integrate generative AI into its regulatory scope. An open letter published on November 8, 2024, reminded online service providers that generative AI tools, including chatbots and search assistants, may fall within the Act’s purview. The regulator provided examples of services that would be regulated, such as generative AI chatbots enabling users to share text, images, or videos with others (classified as ‘user-to-user services’), platforms allowing users to create and share their own AI chatbots, and generative AI tools that aggregate information from multiple sites (‘search services’).
The phased implementation of the Online Safety Act’s obligations throughout 2025 includes key deadlines for compliance. Providers of user-to-user and search services were required to complete illegal content risk assessments by March 16, 2025, and children’s access assessments by April 16, 2025. Furthermore, providers of pornographic content were mandated to implement highly effective age assurance measures by January 17, 2025.
Also Read:
- UK Employers Anticipate AI-Driven Workforce Reductions, Junior Roles Most Vulnerable
- Australia Unveils Comprehensive AI Plan for Public Service, Emphasizing Responsible Adoption and Skill Development
The urgency for clear regulation has been underscored by several distressing incidents involving generative AI. These include cases where users created chatbots to mimic real individuals or deceased children, raising significant concerns about online harm. Ofcom has clarified that any AI-generated content, such as deepfake fraud material, will be regulated in the same manner as human-generated content under the Act, emphasizing a content-agnostic approach to harm.


