Bonum Certa Men Certa

The UK's Online Safety Act (OSA) Discourages Technological Entities, Including Free Software Projects, Being Based in or Near the UK

posted by Roy Schestowitz on Nov 16, 2025

TL;DR: the legal firm we’ve engaged has sent us a memo indicating that in their opinion we can reasonably argue we do not have sufficient links to the UK for the Online Safety Act to be applicable to us.

2+ years ago we moved everything to the UK despite the system here being hostile towards investigative journalism and despite free speech being relatively limited (compared to some of our European neighbours; on the global scale and in the international context the UK is fairly well ranked).

RSF

Notice how many European countries are ranked better than the UK.

We were fully aware of these limitations; we have no regrets, we only regret not moving sooner because it seemed both desirable and inevitable.

When it comes to IRC hosting, we never had any serious speech restrictions imposed upon us by the UK. Yesterday was a fairly vibrant day in our IRC network:

Last week

4.5 years ago Libera.Chat was born and it's still doing fairly OK as a refuge for Freenode escapees/orphans. But a few weeks ago it explained why the UK gives it some "chills". We'd like to reproduced this here (CC BY-NC-SA), as we think it touches some good points: (the more substantial part starts in the second paragraph below)

The good advice

First of all, a massive thank you to everyone who donated since our last post. Our income on Liberapay has roughly quadrupled from what it was before the post. We have also had people reach out to us for large one-time monetary and hardware donations. Your support is truly appreciated!

And now for a followup from our last post. TL;DR: the legal firm we’ve engaged has sent us a memo indicating that in their opinion we can reasonably argue we do not have sufficient links to the UK for the Online Safety Act to be applicable to us. They also believe we would be at low risk of attempted enforcement action even if Ofcom does consider us to be in-scope for the OSA. We will continue to ensure that this is the case by keeping internal estimates of our UK user base and by continuing with our current efforts to keep Libera.Chat reasonably safe. We have no plans to institute any ID requirements for the forseeable future.

If that’s all you wanted to know, then feel free to stop here. However, we feel it’s in the best interest of online communities like ours for us to summarise the advice we were given in hopes that it will be useful to others. This is not legal advice from us to you. This advice was provided to Libera Chat as an assessment of our specific case. We accept no responsibility if you decide to apply advice given to us to your own online service.

Why does this even matter?

You might be asking why we’ve even bothered to get legal advice on this matter. Libera Chat (the non-profit that runs the Libera.Chat IRC network) is based in Sweden. Our bank is Swedish, and we do not rely on any UK-based payment providers. We have a few servers in the UK, but they can be migrated on short notice. In other words, the British government has relatively little authority over us. The most damaging action they can reasonably take is to instruct internet service providers in the UK to deny access to us.

Relatedly, some online communities have decided that they want to minimise the authority the British government has over them. In response to critical analyses of the OSA pointing out its potential for regulatory overreach, some online communities have taken the understandable precaution of entirely blocking access from known UK IP addresses, thus cutting off any reasonable argument that they somehow have links to the UK (more on that later).

The end result is the same: a denial of service to people in the UK solely because of the country they live in. It’s not an insurmountable barrier to access in either case, but it shouldn’t be necessary for individuals in the UK to look into censorship-defeating proxies just to engage with free software developers and peer-directed projects that choose to have a community on our IRC network. It doesn’t serve our users, it doesn’t serve our communities, and it doesn’t serve the UK open source movement. Therefore, it’s in everyone’s best interest for us look into what’s necessary to keep things from getting to the point where users in the UK cannot access Libera.Chat, and that means getting guidance on the OSA.

Who does the OSA apply to?

As the OSA is fairly vague in its definitions, Ofcom has significant latitude in deciding where the thresholds are for whether an organisation meets certain criteria or not. Ofcom also hasn’t been forthcoming with its opinions on where those thresholds are, so there are relatively few hard guarantees about the applicability of the OSA. Still, there is a strong argument that while we definitely meet one of the criteria for the OSA to apply to us, we do not meet the other.

The OSA applies to online service providers that provide a regulated service and have links to the UK. We unarguably provide a regulated service because Libera.Chat is a so-called U2U service, i.e. it “allows ‘user-generated content’ to be encountered by another user of the service”. This is an incredibly broad class of services. Some exceptions are made for user content that is posted in relation to service content (e.g. the comment section of a blog) and a few other service types, but none of them reasonably apply to us. Every chat service, forum, federated social media server, or code forge counts as a regulated service, and therefore meets one of the criteria for the OSA to apply to them.

So be it. What about our links to the UK? To quote the memo:

An online service provider has “links to the UK” for the purposes of the OSA if any one or more of the following apply:

  • the service has a “significant number of UK users”
  • UK users form a “target market” of the service; or
  • the service is capable of being used by individuals in the UK, and there are reasonable grounds to believe that there is a material risk of significant harm to individuals in the UK presented by the content generated by the service.

One factor that does not automatically give us links to the UK is the fact that we have staff members in the UK. Curiously, employees of the service provider who do not engage with that service as users are actually excluded for the purposes of determining whether a service has a “significant number of UK users”. Our staffers are also users, but our UK staffers make up an insignificant portion of our user base.

Speaking of which, the memo implies that “significance” in this context is interpreted as being relative to the population of the UK, not relative to the user base of the service. We have seen risk assessments that take the other interpretation and consider their UK user base to be “significant” because it makes up a large portion of their overall user base, but the advice we received suggests we should not use this interpretation. The exact fraction of the UK’s online population that must use a given service to be considered “significant” is unknown, but based on our counsel’s observations of Ofcom’s previous regulatory actions, it appears to be much higher than our internal estimates of how large our UK user base is.

The “target market” criterion is meant to capture services with a low number of UK users that target the UK specifically. While our target market (people interested in using an IRC-based platform for discussing free software or other peer-directed projects) is inclusive of UK users, it isn’t specifically for them. Our network is predominantly English-speaking, but we do not promote, direct, or tailor our service to UK users in particular.

Finally, there is no atypical material risk of significant harm to individuals in the UK presented by the messages on Libera.Chat. We block spam and client exploits. We are proactive in ensuring that our network’s acceptable use policy is upheld. We do not tolerate incitement to violence, doxxing, or defamation. And finally, we do not provide file hosting that can be used to distribute pornographic or sexual abuse media, though when we sought legal advice from the firm, we acknowledged the existence of DCC as a commonly-supported mechanism for transferring files using an IRC network to establish a peer-to-peer connection.

In the coming weeks, we will be finalising a statement similar to this risk assessment that we can provide to Ofcom should we ever be contacted by them about the OSA.

What if the OSA does apply to us?

While it is our opinion that the OSA does not apply to us, Ofcom might disagree, and appealing that disagreement would likely involve further legal expenses. So, what is the risk that Ofcom would decide to try to impose fines or other regulatory penalties on us?

For the time being, services like ours do not appear to be Ofcom’s priority. Currently, according to our legal sources, the focus appears to be file and image hosts that are at high risk of being used to transmit sexually-explicit depictions of minors. IRC has been used as a way to facilitate piracy, but those days are generally in the past thanks to more attractive options. Even if they weren’t, using Libera.Chat for this purpose is risky. We prefer to exercise the minimum power necessary to keep the network clean, but that doesn’t mean we don’t have the tools necessary to proactively stop the network from being used for piracy or CSAM distribution.

We have also been reassured that Ofcom is very likely to contact us with concerns before attempting any sort of action against us. There are some classes of concerns that we would certainly be willing to hear out, and we do prefer a constructive approach to problem resolution where possible. We’re confident that there isn’t anything for them to be reasonably concerned about, but we are willing to engage with good-faith reports of potential abuse of our service.

Will Libera.Chat ever require my ID?

We have no plans to require users to provide us with proof of identity and will take every reasonable measure to avoid requiring it. The justification for us to compromise the privacy of our users given the content we forbid on Libera.Chat is not adequate, and the risk of material harm should an identity verification mechanism compromise our users’ privacy far outweighs the plausible harms caused by not having such a system. Such violations of privacy aren’t hypothetical; another chat platform recently was affected by a data breach that potentially exposed the legal identities of tens of thousands of its users.

That said, it’s conceivable that legislation will be created that could apply to us and could force us to identify or spy on our users. If that happens, we will evaluate our options once drafts of such legislation reach a point where they can conceivably pass. Until then, we hope that the general public will remain vocally opposed to such attempts at overreach. Popular opposition stalled Chat Control earlier this month. There will probably always be efforts to compromise the free internet, but their success is not inevitable.

In short, OSA would complicate things for them. But they're not based in the UK and won't obey the sorts of expectations that come from there.

In Sweden, however, they might have Chat Control 2. "There will probably always be efforts to compromise the free internet," they say, "but their success is not inevitable."

They have patience, they'll keep trying. We'll keep watching. Here in the UK they also try to mandate back doors inside everything (even stuff made outside the UK).

We remain 100% free of article censorship; in the past we had to mute Garrett for legal reasons [1, 2] (he's defaming many people in the IRC network of this site and changes the topic to sex etc.) and we'll soon know what the Court says about his online behaviour. █

Other Recent Techrights' Posts

Slop-Posting is a New Form of S---posting
We recently caught several more "linux" sites (with "linux" in their domain name) turning to slop
 
Creditors beware: VMS Enterprises Ltd vs Brexit Party (Reform UK Party Ltd)
Reprinted with permission from Daniel Pocock
Techrights Turning 20 Next Month
Our image is under attack, our finances are constantly under attack and so on
Links 01/10/2026: "Meat Proxies" and "Japan’s Far Right Is Courting Young Voters"
Links for the day
Red Hat Being Phased Out of Existence (Like Many Other Companies That IBM Bought)
The "Red Hat" brand (and badge) is being dissolved some more today [...] IBM is imploding 'creatively'.
IBM Layoffs Cover-up
thelayoff.com is censoring threads
"Restricted Boot" Garrett's State is Now Implementing Kill Switches (Just What We've Warned About All Along)
The underlying concept is hardly new
Brett Wilson LLP Has Had No Annual Report in 16 Months
A cynic might hint that they try to hide something
Reform UK last minute accounts filing
Reprinted with permission from Daniel Pocock
Gemini Links 01/10/2026: "Babel With Better Hardware", Software Input That's Slop, and DWeb Cascadia 2026
Links for the day
Today is D-Day at Red Hat and People Leave in Droves
They said there would be "bluewashing", we're mostly seeing people announcing they're leaving
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 30, 2026
IRC logs for Wednesday, September 30, 2026
Gemini Links 30/09/2026: Fish Leather, Slop Formation, and ROOPHLOCH
Links for the day
In a Lot of Europe (or EU) Android (With Linux) is Bigger Than Windows
For example in Greece
EPO Cocainegate: Lots of Money (Over a Million Euros) for Cocaine Addicts, Not for Children With Special Needs
Next month we'll bring out some more Campinos scandals
High Court victory: Nigel Farage is 'the Company's own candidate'
Reprinted with permission from Daniel Pocock
It Took GNOME's Code of Conduct Committee (CoCC) Over 8 Months to Realise CoC Reports Went Into /dev/null/
It would be ironic if the blunder's culprits were punished for it, would it not?
Links 30/09/2026: Microsoft "OpenAI Ignored Employees’ Warnings About Safely" and "Pentagon Personnel Agency Data Breach Impacts 3 Million People"
Links for the day
The Register MS "Events" As Paid Spam That Promotes and Keeps Afloat Hype About Slop
This dreary sort of media reads like a soup of words, i.e. like the thing it is advertising
Digital Independence in the UK and in Western Europe
We have the technical capacity and skilled personnel to achieve this
IBM's Anderon as a Mass Layoffs Ritual With a Bailout (From US Taxpayers to IBM) and Other Perks
Like those empty promises in the first term of the Cheeto dictator
Gemini Links 30/09/2026: David Bowie, Web Rendering Proxy, Ink and Letters, Gemlog Nostalgia
Links for the day
EPO Annual General Meeting (AGM) Will Speak of Financial State of the EPO's Union
Their work is needed because the EPO breaks the law
Rust Causes Upgrade Issues in Ubuntu
They could just keep GNU coreutils in place (nothing was broken about it) and avoid Microsoft's back doors and TPMs
Losses From Slop Are "Investment", Hundreds of Billions in Debt Are "Growth Opportunity", Layoffs Are "Great to See", and Loss of Business Means "We Need a Slowdown" (for "Safety")
Microsoft is removing staff, as investment is apparently the act of shrtinking
Brigading Against Women - Part XII - Toxic Masculinity, Hunting Women, Will Code for Sex
Who says things like these?
The Microsoft Lunduke Slop Problem
Microsoft Lunduke does not support Software Freedom; he serves to discredit many ideas championed by Free software or ideals articulated which are apolitical for the most part
Links 30/09/2026: "Understanding the LLM Bubble" and "Florida Senate Threatened Legal Action Against Newspapers"
Links for the day
It Looks Like Mass Layoffs at "Nordcloud, an IBM Company" Today (a Day Ahead of Red Hat)
Expect the same from Red Hat next
British Prime Minister Recognises Social Control Media as National Cohesion Problem
one has to wonder if addiction to social control media is not compatible with peace
The Future Isn't Social Control Media (Nothing Will be Left of It, Not Even Archives)
"Error code: 502 Bad Gateway"
GNU/Linux Usage in China is Increasing
China is leaving Microsoft and Windows behind
43 Years of GNU and GAFAM's (Especially Microsoft's) Attacks On It
GNU is very widely used (when people say "Linux commands" they typically mean "GNU programs"), hence it's being attacked a lot
CDMAG Covers Free Software, New Magazine From Decent People
If enough people accessed their site, they would not rely on social control media (third parties, censorship platforms)
Brigading Against Women - Part XI - An Abject Lack of Social Skills (and Not Knowing How to Handle Women)
GGG enjoy - if that's the right term - very bizarre or esoteric sex life
Gemini Links 30/09/2026: Accelerationism, "The Billionaire is Wrong", Rant About LLM-generated Support E-mails
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 29, 2026
IRC logs for Tuesday, September 29, 2026
Black Brit on "Pictures Comparing Me to a Monkey" Because of Brett Wilson LLP Client
"Like Firm, Like Clients..."
President of the EPO Should be Kicked Out, Not Have His Term Terminated in 2028
The President is facing more scandals soon
David Gordon at The Register MS Keeps Feeding the Pyramid Scheme With Fake Articles That Say "AI" Dozens of Times
How can such a publisher still be taken seriously?
The Local Staff Committee The Hague (LSCTH) at the EPO Explains the Working Conditions and Crisis of Plunder (Less for Workers, a Lot More for Dictators Who Refuse to Leave Leadership Roles)
Next week will be epic
EPO Will Stop Working for 10 Days to Protest Against 'Cocaine King' and His Assault on Democracy, Lawfulness, Transfer of Power at EPO
Strikes, work stoppage, all rolled onto one
IBM Brings Avalanche to Red Hat October 1st 2026 (Thursday)
IBM is turning up the heat on staff
Links 29/09/2026: Mass Layoffs at Microsoft and Backlash Over Data Center Policy of Microsoft
Links for the day
Techrights is International
There are many sites that focus on local communities or nations. We're not one of those sites.
5 Years Ago (September 29, 2021) Richard Stallman's Talk in Ukraine Noted
Let's hope the war will end soon
Links 29/09/2026: Acceleration, Morale, and ROOPHLOCH 2026
Links for the day
Links 29/09/2026: "Scam Altman Is Driving Drunk" and Anthropic Lies About Slop Usage
Links for the day
Brigading Against Women - Part X - When Actions of American Men Are Not Judged by Other American Men
"There is not the slightest suggestion that either Dr or Mrs Schestowitz did anything to invite or deserve it. They are both clearly and justifiably angered, dismayed, distressed and hurt by it."
European Patent Office (EPO) Series: A Source of Pride for Portugal?
In this part our focus returns to the main theme of this series, namely the current reappointment campaign of the EPO President, as we consider whether Campinos can still expect to enjoy the same level of support from the Portuguese political establishment as he did during the earlier stages of his career
Computers Freeze Because of UEFI Restricted Boot
damage is also done to computers running Windows
It is Very Expensive to Slow Down Techrights
Garrett's expensive hearing (costing the British taxpayers about 120,000 pounds; he doesn't live here and does not pay tax here) slowed us down for a few days, but we've picked up the pace since
Linux Has Conquered Mobile, But Desktops and Laptops Matter More
When people say the desktop "doesn't matter" they seem to be missing the point that workplaces use desktops (or laptops) and a lot of the work gets done not on skinnerboxes but "workstations" or terminals
Brigading Against Women - Part IX - "What Are You, a Racist?"
Because behind every strong man is a strong opinion?
Gemini Links 29/09/2026: "Digital Sabbath", Starting a GemCapsule, and Sterrenkijker 1.1.0
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 28, 2026
IRC logs for Monday, September 28, 2026