Techmeme Ofcom Review: Ian Cheshire Confronts a Big Tech Enforcement Gap
- Sophie Larsen
- 5 hours ago
- 12 min read
Ofcom Chair Ian Cheshire has launched a wide-ranging review as the regulator confronts a growing gap between its duties and enforcement capacity. The techmeme Ofcom story matters because Cheshire is questioning whether the watchdog has enough people, expertise, and authority to police global platforms.
Cheshire told the Financial Times that Ofcom would need more resources as it assumed broader responsibilities for online safety and Big Tech. His review will examine how the organization should operate after years of expanding mandates, according to the Ofcom review report.
This is not simply an incoming chair reorganizing departments. Ofcom must now convert a complex rulebook into investigations, evidence requests, platform changes, and penalties that withstand legal challenges.
That transition creates the central conflict. Parliament expects faster protection from online harms, while regulated companies face intrusive and technically demanding compliance obligations. Ofcom must enforce those rules without becoming slow, inconsistent, or careless about privacy and lawful expression.
Cheshire took office in June 2026 after leading major British companies and chairing Channel 4. He inherited an institution regulating communications networks, broadcasting, spectrum, postal services, and online platforms.
The new online safety mandate places Ofcom against companies with global reach, specialized legal teams, and detailed knowledge of their own systems. The regulator’s credibility will depend less on publishing guidance and more on proving that its interventions change measurable outcomes.
Techmeme Ofcom Coverage Points to an Institutional Redesign
Cheshire’s review recognizes that Ofcom’s old operating model no longer matches the job Parliament has assigned it.
The review is described as wide-ranging because the pressure extends beyond one department or enforcement case. Ofcom needs to reconsider its staffing mix, internal decision-making, technical capabilities, priorities, and relationship with the government.
Its traditional responsibilities remain substantial. The regulator still oversees telecom competition, broadcasting standards, radio spectrum, postal services, and consumer issues across the United Kingdom.
Online regulation adds a different kind of workload. Ofcom must evaluate recommendation systems, moderation processes, age-assurance methods, search results, risk assessments, and platform governance across thousands of services.
These systems change faster than broadcast schedules or telecom pricing structures. A platform can alter an algorithm, launch a generative AI feature, or shift its moderation policy before a conventional investigation concludes.
Cheshire entered the role with direct questions about this mismatch. During his May 2026 parliamentary hearing, lawmakers said Ofcom employed about 1,800 people, including approximately 450 working on online safety.
Only 70 to 80 of those online safety employees reportedly focused on compliance and enforcement. Cheshire did not endorse that distribution as permanent.
He said the team’s profile should change as Ofcom moves from constructing regulatory frameworks toward testing compliance. He also framed resourcing as a consequence of strategy, rather than a substitute for it.
His questions were practical: What does successful enforcement look like, how should success be measured, and what work remains undone because resources are limited? The appointment hearing provides an unusually clear preview of his review.
That sequence matters. Hiring more people without establishing enforcement priorities can produce additional process but little public impact. Understaffing enforcement, however, leaves detailed codes with no credible threat behind them.
Ofcom also needs different expertise from the teams that created its initial guidance. Investigators require forensic technical skills, litigation preparation, economic analysis, and access to reliable platform data.
The regulator must decide which cases deserve intensive intervention. It cannot investigate every service, content incident, or design decision with equal depth.
That requires a risk-based enforcement model. Ofcom must focus on services where potential harm, user reach, compliance failures, and opportunities for wider deterrence justify the resources involved.
The review therefore represents more than administrative maintenance. It is a test of whether Ofcom can become an operational technology regulator while preserving its existing responsibilities.
If Cheshire changes staffing, governance, and performance measures together, the regulator can build a clearer enforcement chain. If the review only rearranges reporting lines, the capacity problem will remain.
The Online Safety Act Has Moved From Rulemaking to Enforcement
Ofcom now faces the harder phase of the Online Safety Act, proving that formal duties produce safer systems and defensible enforcement decisions.
The Online Safety Act became law in October 2023, but its obligations arrived through a phased implementation. Illegal-content duties became enforceable before key child-safety requirements took effect in July 2025.
Those earlier stages demanded consultations, risk registers, codes of practice, and extensive guidance. The next stage requires Ofcom to examine actual platform behavior and pursue companies that fall short.
The law applies to regulated user-to-user services and search services accessible in the United Kingdom. That reach includes large social platforms, search engines, gaming services, forums, dating platforms, and pornography websites.
Companies must assess relevant risks and establish systems designed to reduce users’ exposure to covered harms. Child-facing services carry additional responsibilities concerning harmful content and age assurance.
Ofcom can request information, open formal investigations, impose penalties, and seek business-disruption measures in serious cases. Maximum penalties can reach £18 million or 10 percent of qualifying worldwide revenue, whichever is greater.
Large theoretical penalties create leverage, but they do not guarantee fast compliance. Ofcom must gather evidence, identify the responsible legal entity, interpret technical systems, and follow fair procedures.
Some regulated providers operate outside the United Kingdom. Others have limited assets, obscure ownership, or little incentive to cooperate with a British regulator.
Large platforms present the opposite problem. They have substantial resources, complicated product architectures, and lawyers prepared to challenge regulatory interpretations that affect global operations.
Ofcom has already moved beyond publishing rules. By July 2026, it said it had opened 23 investigations involving providers of 88 adult services.
The regulator reported that 73 percent of those services either introduced age assurance or blocked access from the United Kingdom. It had fined seven providers operating 24 sites.
Those results show that enforcement can change company behavior. They also reveal its limits because blocking British users is sometimes easier than building compliant systems.
Age checks demonstrate the scale of implementation. A sample of 32 services completed more than 69 million checks between July and December 2025, according to Ofcom.
That total was 23 times greater than during the preceding six months. By June 2026, 64 of the 100 most popular pornography services had deployed age assurance.
Another 10 had blocked British users. Yet Ofcom still found services without effective checks, alongside migration toward sites offering easier access.
The regulator’s data showed the proportion of children encountering highly effective checks rose from 25 percent to 43 percent between July 2025 and January 2026. That is progress, but it is not comprehensive coverage.
Ofcom also found that 33 percent of first-page Google results in its test led to pornography sites without age checks or equivalent protections. The figure reached 54 percent for Bing.
This illustrates why platform regulation cannot remain confined to the most visible content providers. Search engines, app stores, operating systems, and device makers influence how users discover and access services.
Ofcom’s age-check findings consequently called for a whole-system response. Google and Microsoft agreed to work with the regulator on search discovery problems.
That broader approach increases the institutional burden. Each added layer requires different evidence, technical knowledge, and legal analysis.
The techmeme Ofcom report arrives at the point where implementation numbers are becoming available. Cheshire must now decide whether the regulator is organized around the risks those numbers expose.
Big Tech’s Resources Meet Ofcom’s Enforcement Capacity
The primary contest is between Ofcom’s public mandate and the operational advantage held by the global companies it regulates.
Big Tech companies control the systems, data, and technical context that Ofcom needs to assess compliance. Regulators often begin with an information disadvantage.
A platform can explain that its internal classifier, ranking model, or age-inference system performs well under selected conditions. Ofcom must determine whether that claim holds across real users and foreseeable attempts at evasion.
Age inference estimates a user’s age from behavior or account signals. It differs from methods requiring a document, payment credential, facial estimate, or third-party verification.
The distinction became important when Ofcom expressed serious doubts about age-inference methods used by major social platforms. It said some systems might fail to identify significant numbers of children.
In July 2026, Ofcom opened an investigation into TikTok’s approach. The regulator said companies relying on age inference needed compelling evidence that their methods were highly effective.
That case shows the kind of expertise Cheshire’s review must address. Investigators need to evaluate datasets, error rates, demographic performance, evasion risks, and the consequences of false classifications.
Companies also change their systems continuously. A regulatory finding based on one product version can lose relevance after a design update.
Ofcom therefore needs repeatable access to evidence instead of one-time demonstrations. It must understand how a safety control behaves after deployment, not only how it performs in a controlled test.
The same problem applies to recommendation systems. A platform might remove prohibited content after receiving a report while its ranking system continues directing users toward similar material.
A credible investigation must connect policy, product design, user behavior, and measurable exposure. That work consumes more technical and legal resources than reviewing a written moderation policy.
Big Tech can also challenge how Ofcom funds this oversight. The Online Safety Act requires certain regulated companies to support the regulator’s online safety costs through fees.
Ofcom finalized its charging principles in March 2026. Eligible providers had to register and supply information for the initial charging year.
The online safety fees create a logical funding mechanism because regulated companies generate much of the supervisory workload. They also create disputes over eligibility, revenue calculations, cost allocation, and proportionality.
A regulator funded through industry fees still needs strict independence. Companies should not receive softer treatment because they contribute more money, nor face arbitrary costs unrelated to their regulatory burden.
The tension becomes sharper when enforcement budgets depend on estimates of future work. A major investigation can require specialists, external advice, litigation preparation, and extended monitoring.
Cheshire has indicated that resources should not prevent fundamental compliance work. His review must translate that principle into a budget and staffing model that can survive unpredictable cases.
The regulator also needs enough capacity to resist strategic delay. A company can answer information requests narrowly, dispute definitions, or challenge procedural decisions without directly refusing cooperation.
Each exchange consumes time. If Ofcom lacks parallel investigative capacity, one complex company can slow attention to other high-risk services.
At the same time, speed cannot justify weak evidence. A rushed penalty that fails on appeal can damage Ofcom’s authority and make later interventions harder.
The best response is not simply a larger headcount. Ofcom needs specialized teams, reusable investigative methods, clear escalation rules, and technology that helps analysts preserve evidence across changing services.
Staffing must also reflect the enforcement cycle. Policy specialists remain necessary, but more personnel may need to move toward compliance testing and formal investigations.
That change would mirror Cheshire’s parliamentary observation that a regulator’s profile should shift after its frameworks are established. The review will reveal whether he intends a genuine transfer of institutional weight.
More Resources Will Not Resolve Every Ofcom Risk
A stronger Ofcom can enforce more consistently, but greater capacity also raises harder questions about privacy, speech, measurement, and regulatory restraint.
Supporters of tougher enforcement argue that online duties have little value without visible consequences. Parents, child-safety organizations, and lawmakers have criticized the pace of action against harmful services.
That criticism intensified in July 2026. The House of Lords Communications and Digital Committee launched an inquiry into the Act’s implementation, enforcement, and impact.
The committee said serious concerns had been raised that the regime was ineffective. Its chair, Baroness Keeley, argued that any law is only as effective as its enforcement.
The parliamentary inquiry will examine both Ofcom’s performance and possible weaknesses in the legislation. Written submissions remain open until September 7, 2026.
That inquiry puts Cheshire under immediate pressure. His internal review must produce answers while Parliament conducts an external assessment of the same enforcement system.
Yet calls for more action come from opposing directions. Safety advocates often want faster intervention, while privacy and civil-liberties groups question age checks and content controls.
Age assurance can require users to disclose identity information, payment details, or facial data. Even privacy-preserving providers create questions about data handling, error rates, accessibility, and exclusion.
Companies may respond conservatively when legal boundaries remain uncertain. They might limit lawful content, apply age gates too broadly, or withdraw services rather than accept regulatory risk.
Those outcomes matter because the Act regulates systems, not merely individual illegal posts. Changes intended to reduce one harm can affect access to health information, political discussion, sexuality resources, or anonymous participation.
Ofcom must therefore measure more than enforcement volume. Counting investigations and penalties cannot establish whether users are safer or whether compliance measures remain proportionate.
The regulator needs outcome measures tied to exposure, repeat violations, circumvention, and response speed. Those measures should account for unintended effects.
Ofcom’s age-assurance data offers a useful beginning. It measured deployment, user encounters, visit duration, search pathways, and service migration instead of counting published guidance.
However, the regulator produced much of that evidence itself. Independent researchers and Parliament should be able to scrutinize methods without gaining access to sensitive user data.
There is also a risk of confusing visible activity with effective enforcement. A long list of small investigations can consume resources while leaving the largest systemic risks untouched.
Conversely, focusing only on famous platforms can overlook smaller services where dangerous material is concentrated. A risk-based regulator must balance reach, severity, and enforceability.
The Act’s international scope adds another uncertainty. Penalties are most credible against companies with British operations, assets, or a strong commercial interest in the market.
Enforcement against uncooperative overseas operators may require court orders, access restrictions, or intervention from payment and advertising partners. Those steps raise separate proportionality questions.
Cheshire’s business background can help with organizational design, budgets, and accountability. It does not automatically resolve the technical and rights-based disputes embedded in online safety regulation.
A parliamentary committee reviewing Cheshire’s appointment highlighted this concern. It welcomed his leadership experience but encouraged him to improve his knowledge of online safety legislation quickly.
Ofcom confirmed his appointment on June 11, 2026. Its leadership announcement emphasized his experience at Channel 4, Barclays UK, and Kingfisher.
His review should therefore be judged by its operational detail. Broad promises about efficiency or public protection will not establish whether Ofcom can investigate complex platforms fairly.
The critical questions concern decision rights, staffing allocations, evidence standards, technical recruitment, and public performance measures. Those choices will determine whether additional resources improve outcomes.
The techmeme Ofcom headline captures a regulator asking for institutional renewal. The skeptical view is that a larger regulator can still fail if its objectives remain unclear or contradictory.
Three Signals Will Show Whether Cheshire’s Review Works
The next test is whether Cheshire converts a broad review into measurable enforcement capacity before political expectations expand again.
The first signal is Ofcom’s response to the parliamentary inquiry. The Lords committee is examining whether implementation failures come from Ofcom, the Act, or both.
Its September 7 evidence deadline gives companies, researchers, safety groups, and rights advocates a chance to document practical problems. That record should clarify where staffing gaps are genuine and where legislation creates uncertainty.
A detailed Ofcom submission would strengthen Cheshire’s case for reform. It should identify operational constraints without treating every disappointing outcome as a funding problem.
If Ofcom publishes clear measures of success, the review will look like an accountable redesign. Vague requests for more resources would weaken confidence.
The second signal is Ofcom’s October assessment of effective age checks for users over 16. The regulator plans to deliver that work to Parliament before possible restrictions begin in 2027.
This assessment will test whether Ofcom can set technically credible standards while acknowledging privacy, accuracy, and accessibility tradeoffs. It will also affect social platforms, device makers, and app stores.
A useful assessment should distinguish methods by risk and context. It should address false classifications, evasion, data minimization, and independent testing.
If the assessment supplies measurable criteria, it will support Cheshire’s claim that resources should follow defined outcomes. If it relies on broad language, enforcement disputes will continue.
The third signal is progress in active investigations, especially the TikTok age-assurance case. Ofcom must show that it can evaluate a large platform’s technical evidence and reach a defensible conclusion.
The outcome matters beyond TikTok. Other services will use it to understand what “highly effective” means and how much proof Ofcom expects.
A well-supported decision would strengthen deterrence even without a large fine. A prolonged case with little public explanation would reinforce concerns about enforcement capacity.
Readers should also watch the staffing consequences of Cheshire’s review. The most meaningful change would be a larger share of online safety personnel assigned to compliance, investigations, and technical testing.
A simple increase in total employees would reveal less. The essential question is whether expertise reaches the points where Ofcom challenges platform claims.
Companies operating in Britain should prepare for more systematic evidence requests. Product teams may need clearer records connecting risk assessments, design choices, testing results, and post-launch monitoring.
Developers should expect safety controls to become auditable product features. A policy document alone cannot show how an age gate, recommender, reporting tool, or classifier behaves under real conditions.
Enterprise buyers also have a stake. Vendors increasingly embed messaging, communities, generative AI, and user-generated content into business software.
Those features can create regulatory exposure even when online safety was not part of the original product category. Buyers need to understand how suppliers document risks and handle regulator requests.
Knowledge workers tracking these developments face another problem: the evidence is scattered across guidance, investigations, parliamentary hearings, and company responses. A structured knowledge base can preserve decisions and source material as rules evolve.
The larger lesson is that online safety regulation has entered its institutional phase. Parliament has written the duties, and Ofcom has produced much of the initial framework.
Now the regulator must prove that it can inspect changing technical systems, prioritize serious risks, and withstand resistance from well-resourced companies. It must do so without treating privacy or lawful expression as secondary concerns.
Cheshire’s review creates a clear benchmark. Ofcom should emerge with defined outcomes, specialized enforcement capacity, and public measures that connect regulatory action to user safety.
The techmeme Ofcom story will remain important if the review changes how the regulator works. Otherwise, it will become another acknowledgment that Britain assigned a large digital mandate without building the machinery to deliver it.
Watch the parliamentary evidence, the October age-assurance assessment, and the first major technical enforcement decisions under Cheshire. Together, they will show whether the review closes Ofcom’s capacity gap or merely describes it.