Britain's Online Safety Act was sold as the law that would finally make foreign websites answer to UK rules. On 21 July 2026 the regulator enforcing it conceded that, in its most serious case so far, it has run out of moves. Ofcom closed its enforcement action against the US-based operator of a suicide forum, saying a geo-block on UK visitors is "the fullest extent of what can be achieved under the Online Safety Act". The £950,000 fine it issued in May remains unpaid.
What Ofcom actually said about the Online Safety Act
The case was the first of its kind under the Act. The forum, which the Molly Rose Foundation links to 164 deaths in the UK and which has been named in multiple coroners' reports, was fined in May 2026 for failing to protect UK users from illegal content. The payment deadline of 12 June passed with nothing received. Then the enforcement path simply closed.
- The fine: £950,000, unpaid, with no realistic route to collect it from a foreign operator.
- The block: after Ofcom identified gaps, including a mirror domain that stayed reachable, the operator tightened its geo-block itself.
- The catch: once the block was fixed, the legal basis for asking a court to order UK ISPs to block the site fell away, and non-payment of a fine is not by itself grounds for such an order.
Ofcom also stated plainly what the block does and does not do. Geo-blocking, it said, does not fully remove the risk of harm, "especially for individuals who choose to access sites through VPNs", while the vast majority of UK users who do not mask their location can no longer reach the site. A very small number of already registered users, it added, still get through from the UK for technical reasons the regulator does not attribute to the operator.
Why Ofcom's failure is structural, not a one-off
Strip away the specifics and the shape of the failure is familiar. A regulator with domestic powers meets an operator with no UK presence, no UK assets and no incentive to pay. Fines assume someone to bill. Access restriction orders assume a target that is still legally in breach. Fix the technical breach, ignore the invoice, and the statute runs out of tools.
That is why the outcome matters far beyond one forum. The Act's deterrent rests on the assumption that non-compliant foreign sites can ultimately be blocked at the network level in the UK. This case shows the assumption failing in the exact scenario the law was written for, and Ofcom has now opened a review of its own business disruption powers as a result. Samaritans called the outcome a missed opportunity to show that breaches will be punished.
The VPN question Britain keeps circling back to
Here is the part that will follow this decision around. A regulator has now put on record that its strongest available remedy is a country-level filter, and that the filter is undone by a tool millions of people use for ordinary reasons. Every previous UK debate about restricting VPNs has ended with the government stepping back: in July it decided not to restrict VPNs and called them legitimate privacy tools, after an earlier consultation on age verification for VPN services and a period when the Lords backed banning VPNs for under-16s alongside social media limits.
An enforcement failure this visible is exactly the material that reopens those debates. The argument writes itself: the law works, the filter works, the only gap is the tunnel. It is a bad argument, because the same tunnel protects journalists, domestic abuse survivors, business travellers and anyone on a hostile network, and because a country that filters at the VPN layer ends up rebuilding the machinery it criticises elsewhere. Pavel Durov has spent a year arguing that child protection is the packaging for broader censorship powers, and cases like this are how the packaging gets refilled.
Enforcement is drifting toward the network layer everywhere
The UK is not alone in discovering that the site itself is the hardest thing to reach. Enforcement keeps sliding down to the parts of the internet that are inside national jurisdiction: providers, resolvers, infrastructure and, increasingly, the people who explain how any of it works. In France a court kept 197,000 euros frozen over social media posts explaining a DNS workaround. The pattern is consistent: when the target is out of reach, pressure moves to whatever is in reach.
One technical point is worth stating precisely, because the whole case turns on it. Geo-blocking is a location check, not a safety mechanism. It asks which country an address appears to be in and answers yes or no, treating everyone behind that address identically regardless of who they are, what they need or why they are online. A regulator that can only require a location check is not really regulating the content; it is regulating a lookup. That is the gap Ofcom has now documented in its own words, and no amount of enforcement pressure on connectivity tools turns a lookup into protection.