Giving evidence to the House of Lords Communications and Digital Committee's inquiry into the Act's implementation, de Souza said young people had little understanding of the legislation or how it was intended to change their online experiences.
Central to de Souza's criticism was the legislation's focus on moderating harmful content rather than addressing potentially harmful platform design features. UK politicians had pushed for controls covering such features, either through the OSA or separate legislation, but none has materialised.
De Souza contrasted the UK's approach with the US, where legal pressure recently pushed Meta toward significant child safety concessions. Without admitting wrongdoing, Meta proposed an $18 billion settlement in a US child safety case, introducing two-hour daily limits for users under 18 on Facebook and Instagram, prompts to discourage endless scrolling, and measures addressing use during school hours and at night. The proposal would also let children opt out of algorithmically ranked feeds.
Discussing the proposed Meta settlement, de Souza said the OSA had 'not been flexible enough' and had not 'kept up with the time.' She argued that Ofcom and lawmakers should seek results comparable to those achieved through the US legal system, even if that required the legislation to evolve.
De Souza also said she planned to exercise her statutory powers to compel Ofcom, the OSA's regulator, to provide copies of the safety risk assessments submitted by technology companies. The commissioner said Ofcom had refused to share the assessments with her, despite her position as 'the most senior safeguarding person in this country for children,' and had indicated that it would resist disclosure even if she invoked those powers.
'One thing I did want to ask this committee was for your assistance in this matter, because I am planning to use my powers,' de Souza said. 'If we cannot even see the risk assessments that may well have put these [safety] mechanisms into place, or may not have, how on earth can we judge the efficacy of it? So I'll leave that one with you, but I'm pretty furious about that.'
The obstacle is section 393(1) of the Communications Act 2003, which restricts Ofcom's disclosure of information obtained through its regulatory functions. Ofcom may disclose such information if the business concerned consents or if one of the statutory gateways in section 393(2) applies.
Asked whether compelling tech companies to complete risk assessments was enough to ensure meaningful change or whether further legislation was needed, the Children's Commissioner said 'we need a few things,' including for Ofcom to 'use its teeth.'
Ofcom has materially upped its presence in tech regulation during the past year, stepping in on multiple occasions, including during the Grok nudifying furore and through investigations into pornography companies allegedly violating age verification requirements. De Souza acknowledged all of this.