Europe Industry compliance

UK redraws teen messaging lines

For product, compliance, trust-and-safety, and messaging teams operating in the UK, the practical issue is that regulators are no longer looking only at platforms as a whole. They are isolating messaging-related functions such as direct messages from strangers, livestream interaction, and default protections for minors. In recent UK proposals, core messaging services such as WhatsApp and Signal remain outside the under-16 social media ban, but mixed platforms with social and messaging features are moving into a stricter compliance perimeter.

Published:07/13/2026 Updated:07/13/2026

1. Regulatory focus

The current UK direction is not a blanket ban on every communications service. It is a functional approach: services with public distribution, algorithmic feeds, stranger contact, and livestreaming are being prioritized for control. Recent reporting indicates that core messaging services such as WhatsApp and Signal are currently excluded, while mixed environments that combine social discovery and private messaging are moving into scope. Stranger DMs on youth-facing platforms, default protections for users aged 16 to 17, and restrictions on intimate or companion-style AI chat are all part of the next implementation layer, with Ofcom expected to shape the age-assurance assessment path.

2. Business impact

For OTT providers, gaming-social products, community apps, and conversational services, the operational risk is shifting from service labeling to feature labeling. If a product combines account identity, recommendation systems, groups, and one-to-one messaging, it will be harder to rely on a simple communications-service exemption. The real questions become whether strangers can initiate contact, whether minors are discoverable by default, how support or promotional messages interact with youth protections, and what evidence the business can produce during a regulator or platform-risk review. That affects product design, onboarding logic, logging, appeals handling, and regional rollout sequencing.

3. Operating recommendations

The best near-term move is not to wait for final statutory text but to build a UK messaging compliance matrix now. Map each feature separately: stranger DMs, group invites, livestream chat, bot conversations, support messages, and marketing touchpoints. For each, define age thresholds, default settings, escalation owners, and audit evidence. Split controls for under-16 users versus 16-17 users, prepare a documented source of age signals, design reduced-contact rules for minor accounts, and implement manual review plus false-positive appeal paths. If the service positions itself as a basic communications tool, keep written evidence showing why discovery, public amplification, and high-risk social features are limited.

Frequently Asked Questions

If our product has DMs but is not a social platform, could it still be targeted?
Yes. The issue is not only category labeling but the feature stack. If the service enables discovery, stranger contact, group amplification, or livestream interaction, regulators may treat it as higher risk even if messaging is not the core business. Compliance scoping should be done feature by feature, not only by product label.
Could support or order messages be unintentionally blocked by youth protections?
Yes, especially if the system does not separate transactional traffic from social messaging. Create distinct classes for OTPs, order updates, fraud alerts, and human support responses, each with documented triggers. Youth controls should include allow-listed service flows, or blanket restrictions may disrupt login, payment, and post-sale operations.
Should we deploy age assurance now or wait for Ofcom guidance?
You do not need to switch on the heaviest form of verification everywhere immediately, but you should build age-signal governance now. Document lawful signal sources, confidence tiers, correction paths, and minimum-retention rules first. Then map which features need estimation, which need stronger checks, and which can rely on safer defaults.
This article is for informational purposes only and does not constitute legal advice.

Related products

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch