Related news and insights
Recent news articles and thought leadership
According to Ofcom’s research, most parents impose some form of restriction on their children’s gaming habits, however many remain concerned about online safety issues. These concerns principally relate to their children interacting with unknown players, encountering violent or otherwise age-inappropriate material and being on the receiving end of in-game abuse or ‘trolling’.
At its core, the guidance encourages parents to take steps in three stages: review the safety settings currently configured on their children’s gaming devices and accounts; have regular conversations with their children about their online gaming habits; and update parental controls in light of what they find.
Interestingly, Ofcom urges parents to verify that the correct date of birth is registered on their child’s accounts. This is important because the UK Online Safety Act’s (“OSA”) requirement to use highly effective age assurance (meaning ID matching, open banking etc.) does not generally extend to mainstream gaming services. This obligation can only trigger where a regulated provider permits “primary priority content” on its service (such as pornographic or suicide-related content), which most gaming platforms do not. In the absence of that obligation, Ofcom is asking parents to step in and ensure a false date of birth has not been used, which is a well-known shortcoming of relying on self-declared age.
Where a player’s true age is reflected on their account, platforms will usually tailor the experience accordingly. For instance, by gating certain social or communication features, disabling loot boxes or filtering out age-inappropriate content such as 18-rated titles. Ofcom also reminds parents that there is a breadth of parental controls available to them. These include the ability to restrict friend requests and messaging, limit playtime and in-game spend, and adjust privacy controls.
In short, Ofcom is encouraging parents to take a proactive approach in order to help foster a safe online environment for their children. This will be welcomed by the industry, as it signals some recognition by the regulator that responsibility for children’s online safety does not rest solely with platforms, and that parents, too, have a role to play in managing their children’s gaming experiences.
This guidance arrives at a time when the UK Government is pursuing further legislative measures to protect children in online gaming. As we reported on here in June this year, the Government has announced plans to restrict high-risk features, including the ability for strangers to contact under 16s. For 16 to 17 year olds, that feature is to be switched off by default. Draft regulations are expected before the end of this year, with implementation from Spring 2027.
Separately, on 28 August 2026, Ofcom issued an open letter to all in-scope service providers, emphasising that existing obligations under the OSA remain fully in force even in light of the Government’s announced reforms. The letter makes clear that Ofcom expects compliance with current illegal content and children’s safety duties, stating it will “not hesitate to take enforcement action if services fail to comply with their existing safety duties.”
The new parental guidance is a signal that gaming is moving up Ofcom’s agenda. To date, the regulator’s enforcement activity under the OSA has generally concentrated on higher risk services (such as pornography services, suicide forums, social media and file sharing services) and on the deployment of highly effective age verification. This latest publication suggests that the games sector is increasingly in Ofcom’s sights.
Video game companies should ensure they have assessed whether they are in scope of the OSA. Typical features which bring games services in scope include in-game chat, usernames, player profiles, leaderboards, guilds, clans and discussion forums. In its guidance for online video games, Ofcom adopts a broad interpretation of the OSA’s scope, confirming that manipulation of player profiles, avatars, objects, and the environments themselves, are forms of regulated user-generated content.
Companies that are in scope should be: completing or updating their risk assessments and child access assessments; ensuring they have implemented (and recorded in writing) the safety measures set out in Ofcom’s Codes of Practice (or demonstrating that their alternative measures meet the required standards); and complying with other OSA obligations, such as reporting CSEA content.
Companies that are in scope of the OSA should also consider whether their services fall within the scope of the EU Digital Services Act (“DSA”), and in particular, whether they might constitute a hosting service or an online platform. Where they are in scope, there are opportunities to align compliance across these regimes. For example, by using data from DSA Transparency Reports to feed into OSA risk assessments, or by building a content reporting tool that satisfies the requirements of both the DSA and Ofcom’s Codes of Practice.
Platforms that have not already done so may also wish to consider how they can deliver tailored age-appropriate experiences (as opposed to uniform experiences across the userbase).
Finally, while these are relatively new legal frameworks and there remains room for interpretation in how these obligations apply to games services, companies should resist the temptation to wait for greater clarity before acting. Regulators expect to see evidence of genuine, documented compliance efforts. Having a record of the steps taken will place companies in a stronger position if or when Ofcom makes contact.
Recent news articles and thought leadership