
The design
Ofcom's job under the UK's Online Safety Act, as the regulator's own materials describe it as retrieved on 16 September 2026, is to make online services assess and reduce the risk of harm to users, particularly children. In a published open letter dated 8 November 2024, Ofcom set out how the Act applies to generative AI and chatbots specifically, prompted, the letter states, by reports including 'the tragic death of an American teenager who had developed a relationship with a chatbot' and by chatbots built to mimic real and deceased people. Ofcom's later guidance, published 18 December 2025, restates the same framework for chatbots directly.
What the evidence says
Both documents state that coverage under the Act turns on function, not on whether a product is marketed as a companion. A chatbot that lets users share its generated text, images or video with other users is a 'user-to-user service'; one that searches multiple websites or databases is a 'search service'; one that can generate pornographic material must use age assurance. Ofcom's letter states explicitly that a chatbot which only lets a person interact with the chatbot itself, without sharing to other users, multi-site search or explicit-content generation, sits outside these specific duties. Most one-on-one companion apps, on Ofcom's own account, fall into that excluded category unless they add sharing or search features.
What it asks of people
The Act's duties fall on providers: a risk assessment, proportionate mitigation measures, accessible reporting tools, a named person accountable for compliance, and highly effective age assurance where pornographic content is possible. It asks users for nothing beyond using whatever reporting tools a compliant service provides. The letter states the first Illegal Harms Risk Assessment deadline was mid-March 2025, a milestone that has since passed without this entry verifying any specific company's compliance record.
Privacy and safeguards
Ofcom states it can take enforcement action, including fines, against a covered service that fails its duties, but the letter and later guidance describe a framework, not a finding against any named company. Because coverage depends on features like sharing and search, a single-user companion chatbot's safety obligations under this specific regime may be narrower than a reader would assume from headlines describing the Act as covering AI chatbots broadly.
- Does the companion app in question let a user share the chatbot's generated output with other users, which would place it inside the Act's user-to-user duties?
- Has Ofcom named this specific company in any enforcement action, or only described the general framework that could apply to it?
- What safety obligations, if any, would remain if a companion app added no sharing, search or explicit-content features at all?
Ofcom's own account draws a line most coverage of AI chatbot regulation skips: the Online Safety Act reaches a chatbot because of what it lets users do with its output, not because of how closely it imitates a companion.
Sources & reading trail
Ofcom's own letter defining which chatbot and generative-AI features bring a service into scope of the Online Safety Act (user-to-user sharing, multi-site search, pornographic content) and which fall outside it, plus the compliance timeline.
Source published: 8 November 2024 · Retrieved: 16 September 2026
Ofcom's later guidance page restating the same scope test for chatbots under the Online Safety Act; retrieved via the Welsh-language version of the page, the only one that loaded, and cross-checked against the English open letter's substantively identical points.
Source published: 18 December 2025 · Retrieved: 16 September 2026
Product documents, regulator records and studies establish the entry; the design reading is AI Companions editorial analysis. This retrospective draft does not imply the site published on the event date.