Jump to content

Wikilegal/UK OSA Litigation Explainer: ID Verification

From Meta, a Wikimedia project coordination wiki

Introduction

[edit]

It’s a common misconception that the recent UK legal action brought by a Wikipedian and the Wikimedia Foundation, concerned the UK Online Safety Act’s child safety requirements (set out in OSA s.12(3), plus a few others). It did not.

Instead, our case highlighted a future (2027) requirement for some sites - the so-called "Category 1" sites - to also deploy widespread "identity verification", globally. That is different to age gating. Read on for more background and a detailed explainer, or skip to the end for a handy summary table.

WMF's UK litigation was about the OSA's "Category 1 duties" (due to apply from 2026-2027), not about current child safety duties

[edit]

The OSA's child safety requirements mostly came into force this year (2025), and resulted in many sites and services requiring UK users to prove they are not minors. Unfortunately, our court case took place at the same time as OSA s.12 started to roll out. Also, our case relates to other OSA provisions that jeopardise privacy, free speech and site usability. The timing was coincidental, but it has led to certain things getting conflated.

The UK OSA is a very expansive law that imposes a wide diversity of requirements, not just around child safety.  For example, the UK government aims to use the OSA to also regulate sites that “influence online discourse” even if they pose little to no child safety risks (see para 49 of the judge’s ruling in our case). That’s what our case was about.

Our court action was motivated by (inter alia) OSA s.15(10) and s.64. By 2027, these will also require some services (the “Category 1” apps and/or websites) to let UK users shield themselves from uploads and "interaction" from anonymous users, anywhere in the world. In other words, the Category 1 duties include an “anonymous user disempowerment" clause. The officials that created it felt that anonymous users are harder to control, and therefore more likely to act in unacceptable ways: they’re harder to investigate, prosecute or sue. Those officials explained that "Removing the ability for anonymous trolls to target people on the biggest social media platforms will help tackle the issue at its root, and complement the existing duties in the Online Safety Bill and the powers the police have to tackle criminal anonymous abuse."

Whatever one might think about how useful this would be on social media (and whether it's justifiable to impose it on them, rather than just let people choose to use services that offer this feature), it causes particular problems if it’s applied to something that isn’t a social media site, like Wikipedia. That happens if the UK adopts overbroad service categorisation rules. Anonymity and user-to-user interaction have been core to Wikipedia since day one - nearly 25 years ago. Users rely on privacy to stay safe, even when posting from warzones or under authoritarian governments. And constantly reviewing and improving other people’s contributions is the very essence of Wikipedia. This means that OSA section 15(10) could prevent good faith editors from “interacting” with content posted by UK users, including to improve article content, fight vandalism, etc. We would not want, for example, a dictator hiring someone in the UK to (re)write their Wikipedia article, then blocking anyone “unverified” (which means the vast majority of the Wikipedia userbase, worldwide) from removing, improving or updating it.

Category 1 duties don't just risk disempowering communities, they will also have serious privacy consequences around the world

[edit]

We think those upcoming Category 1 duties, including the identity verification one, are also likely to be a lot more burdensome and privacy intrusive for users. This is not well-understood in current discussions about the OSA.

For example, if we contrast the Category 1 "identity verification" duty against current OSA-related age gating requirements:

  • S.12(3) (age gating): some age gating (age assurance) methods require you to upload a photo in which you look older than a child. Once that is done, the site should be able to delete the selfie you submitted. More robust checks might be needed in borderline cases, but ultimately the site is just confirming a datapoint you share with billions of other people (are you above or below a particular age threshold), before letting you proceed.
  • S. 15(10) and s.64 (anonymous user disempowerment): discriminating against anonymous users is specifically the point of these future duties, so unless we’re wrong in our reading of them, OSA s.15/64 identity verification would require your username to be durably linked to something identifying you "off-platform" / “in real life”, such as a government ID, bank account, Google/Apple account, etc. And this would presumably have to be stored for as long as you’re using that user account (otherwise you can’t be as easily sued/investigated/prosecuted).

Category 1 duties deliberately target specific sites based on their popularity, not harm

[edit]

Sections 15 and 64 (anonymous user disempowerment), along with a large number of other new "Category 1" duties, will apply to a relatively small cluster of services: around 10 - 30 services that get designated as "Category 1" services.

Under the current (2025) iteration of the Categorisation rules (which we tried to convince a judge were unlawful due to their irrational design, and their likely consequences for human rights), Category 1 status is mostly based on a crude metric of their popularity in the UK. The UK government thinks this popularity means the operator of the platform (the entity regulated by the OSA) “influences online discourse”. Smaller, high-risk sites were deliberately excluded from possible Category 1 status. That decision attracted significant criticism from Parliament and observers.

In contrast, section 12(3) (child safety, potentially age gating) applies to tens or even hundreds of thousands of sites; whether or not s12(3) actually requires age verification depends on actual risk factors, such as whether they routinely carry pornography.

Summary

[edit]

To sum up the difference:

OSA anonymous user disempowerment duties OSA Child Safety (incl. age gating) duties
One of several “Category 1 duties” motivating our recent (2025) judicial review. Not relevant to the recent (2025) judicial review
Relevant OSA sections S.15(9), s.15(10), s.16(7) (clarifies that users worldwide either need to submit to ID verification or face disempowerment), s.64 S.12 (except s.12(14))
Entry into force 2027 (expected) 2025
Users whose rights are at risk Users anywhere in the world (see s.16(7)) UK users
Requirements If UK users decide to enable the new “disempower anonymous users” option, then anonymous users worldwide will lose the ability to improve/remove or otherwise “interact” with content that the UK users post on the site.  Things that anonymous users themselves post will also be suppressed, on pages viewed or searched for by those UK users. On higher risk sites, UK users are denied access to specific types of content (e.g. pornography) until they show they are not under-age.  Other functionality (e.g. direct messaging) may also be disabled for them.

It’s very understandable that many people are confusing these two very different sets of requirements - the UK OSA imposes an abnormally wide range of requirements, in very convoluted ways. There is more to say about all the other Category 1 requirements, perhaps in a future Wikilegal post.