16DEC UK OIS: OSA

Based on the enforcement actions and the timeline of the Online Safety Act 2023 (OSA), there is a strong basis for constructing a UV (Ultra Vires) DORCAPS analysis. This framework suggests that the regulator (Ofcom) may have acted outside its powers or failed in its statutory duties, creating a “liability vacuum” where both the companies and the consumers were harmed.

Below is the identification of the UV DORCAPS committed by Ofcom, followed by the analysis of the victims (companies and consumers) and the specific torts involved.

I. UV DORCAPS Matrix: The Regulator’s Failures

This table identifies the Decisions, Omissions, Regulations, Conduct, Actions, and Policies by Ofcom that arguably constitute Ultra Vires (acting beyond legal power) or Maladministration (failure to act appropriately), creating the environment for the alleged harms.

Category Specific Regulatory Failure (The “Tort” of the Regulator) Legal Argument for Ultra Vires / Liability
Decision Decision to delay enforcement of “Part 5” (Pornography) rules until 2025, despite the Act receiving Royal Assent in Oct 2023. Irrationality (Wednesbury Unreasonableness): The delay in making a decision on enforcement exposed children to harm for 18+ months after the legislative mandate was clear.
Omission Failure to provide definitive “Safe Harbor” technical standards. Ofcom required “highly effective” age assurance but failed to specify exactly which technologies met this standard before fining companies. Breach of Statutory Duty / Legal Certainty: It is arguably ultra vires to punish entities for non-compliance with a standard that the regulator itself failed to clearly define or certify in advance.
Regulation Vagueness in “Highly Effective” Age Assurance guidance. The guidance published (Jan 2025) left significant ambiguity regarding privacy-preserving methods vs. hard ID checks. Void for Vagueness: Regulations that do not allow a regulated entity to know with certainty how to comply may be unenforceable and unlawful.
Conduct Aggressive enforcement (e.g., AVS Group £1m fine) amidst implementation chaos. Fining companies while the “Roadmap” for implementation was still being rolled out. Procedural Unfairness / Abuse of Process: Penalizing companies for “teething problems” of a new regime that the regulator was slow to establish creates disproportionate harm.
Actions Public “Naming and Shaming” of foreign entities (e.g., ZD Media s.r.o, Cyberitic LLC) before concluding judicial reviews or appeals. Defamation / Reputational Tort: If the regulatory basis is found to be ultra vires, the public branding of these companies as “unsafe” causes unjustified commercial damage.
Policies The “Phased” Roadmap Policy. Ofcom’s policy to prioritize consultation over immediate protection created a “protection gap.” Negligence: The policy choice to delay implementation created a foreseeable risk of harm to children, directly contradicting the primary purpose of the OSA 2023.

II. Identification of Victims & Nexus of Harm

In this unique administrative tort theory, the regulator’s failure creates two distinct classes of victims who are pitted against each other, but whose harms stem from the same source (the Regulator’s UV DORCAPS).

Victim Group A: The Consumers (Parents & Children)

  • The Harm: Exposure to age-inappropriate pornography and potential grooming/exploitation during the “lag period” (Oct 2023 – Dec 2025).

  • The Cause: Ofcom’s Omission to enforce rules immediately and Policy of a slow “roadmap.”

  • Tort Claim against Regulator: Negligence in Statutory Performance. The regulator owed a duty of care to the public to enforce the safety laws passed by Parliament. By delaying, they breached that duty, resulting in the “digital injury” of the child.

  • Why they join the Action Group: To seek compensation not just from the pornographers, but to force the regulator to acknowledge that their delay allowed the access to happen.

Victim Group B: The Companies (AVS Group, ZD Media, Cyberitic, etc.)

  • The Harm: Financial penalties (e.g., £1m fines), legal costs, and severe reputational damage.1

     

  • The Cause: Ofcom’s Regulation (vagueness) and Conduct (enforcement without clarity).

  • Tort Claim against Regulator: Misfeasance in Public Office or Interference with Business Relations. These companies were placed in an impossible position: legally required to implement technology that the regulator had not fully standardized, and then fined for getting it “wrong.”

  • Why they are “Victims”: They are being used as “scapegoats” to cover for the regulator’s slow implementation. They can argue: “We didn’t fail to block children; the Regulator failed to tell us HOW to block children legally, and now they are fining us for it.”


III. The Unified Liability Theory

The UK Online Safety Action Group can argue that the ultimate liability rests with the regulator’s Ultra Vires actions.

The Argument:

“If Ofcom had fulfilled its statutory duty immediately and clearly (DORCAPS), the Companies would have implemented the correct checks in 2023/2024, and the Consumers (children) would have been protected. Therefore, the Regulator’s UV DORCAPS is the proximate cause of the harm to both the child (exposure) and the company (financial loss).”

Entities Identified for the Action Group:

  • Regulator (Defendant): Ofcom (Office of Communications).2

     

  • Corporate Victims (Potential Co-Claimants/Witnesses):

    • AVS Group Limited3

       

    • ZD Media s.r.o.

    • Cyberitic LLC4

       

    • Web Prime Inc

    • Youngtek Solutions Ltd5

       

    • Note: While these are currently “targets” of Ofcom, in a UV action, their testimony regarding the lack of clear guidance is evidence of the regulator’s failure.

  • Consumer Victims (Claimants): Parents/Guardians of children who accessed content on the above platforms between Oct 2023 and Dec 2025.

Next Step for the User

Would you like me to draft a “Letter Before Claim” addressed to Ofcom’s legal department, outlining these specific UV DORCAPS and formally notifying them of the intent to seek judicial review or damages for this “double harm”?


The following analysis outlines the specific Judicial Review (JR) opportunities available to challenge the Ultra Vires (UV) DORCAPS committed by Ofcom and related public bodies.

This analysis includes the specific “COCOO” (Co-Claimant / Oversight) opportunity you identified: challenging the supervising public authority (likely the Department for Science, Innovation and Technology – DSIT) for failing to trigger internal disciplinary or corrective procedures (ex officio) against Ofcom.

I. The “Tortuous Gap” Timeline

To understand the JR deadlines, we must visualize the timeline of the “Liability Vacuum” created by the regulator’s delay.


II. Matrix of Judicial Review (JR) Opportunities

The following table identifies distinct JR challenges. Note that Judicial Review in the UK must generally be filed promptly and within 3 months of the decision. However, for ongoing breaches (continuing omissions or policies), the clock may arguably be “reset” or extended.

1. The Primary JR: Companies & Consumers vs. Ofcom

  • Target: Ofcom (The Regulator).

  • The Act/Decision: The imposition of the £1m fine on AVS Group (Dec 2025) and the Policy of enforcing fines based on “vague” standards (Jan 2025 Guidance).

  • Legal Ground (UV):

    • Irrationality: Fining companies for failing to use “highly effective” tech that Ofcom failed to certify/standardize in time.

    • Legitimate Expectation: Companies expected a “grace period” or clear technical specifications (Safe Harbor) before fines were issued.

  • Deadline:

    • Strict Deadline: 4 March 2026 (3 months from the 4 Dec 2025 fine).

    • Status: ACTIVE / URGENT.

2. The “COCOO” JR: Oversight Failure

  • Target: DSIT (Department for Science, Innovation and Technology) / Secretary of State.

  • The Act/Decision: The Omission to intervene. The Secretary of State has powers to direct Ofcom if it is failing its duties.

  • The Argument: The supervising authority (State) knew Ofcom was delaying child protection (2023-2025) and failing to provide industry clarity, yet did not trigger ex officio powers to correct this. This “Omission” allowed the tort (harm to kids, harm to business) to occur.

  • Deadline:

    • Argument: This is a Continuing Omission. As long as the supervising body fails to act while the harm continues, the JR clock effectively renews each day.

    • Status: OPEN (Continuing Breach).

3. The “Secondary Legislation” JR

  • Target: The Statutory Instruments (Regulations) or Ofcom’s Official Guidance.

  • The Act/Decision: Guidance on Age Assurance (Jan 2025) or The Commencement Regulations that delayed Part 5 enforcement.

  • The Argument: The Guidance itself is Ultra Vires because it is “Void for Vagueness” (it demands “highly effective” checks without defining them technically, leaving providers to guess).

  • Deadline:

    • Strict Deadline: Expired (April 2025, 3 months post-publication).

    • Exception: You can bring a Collateral Challenge. You are not challenging the Guidance in abstract, but challenging the application of that Guidance to the specific fine (Dec 2025).

    • Status: ACTIVE (via Collateral Challenge).


III. Summary of Dates & Deadlines

Target Action (UV DORCAPS) Responsible Body Date of Act JR Deadline (Standard) Strategy for “Out of Time”
Royal Assent (Start of Duty) Parliament 26 Oct 2023 N/A Reference point for “Delay”.
Publication of Vague Guidance Ofcom 16 Jan 2025 16 April 2025 Collateral Challenge: Argue the guidance is unlawful because it is now being used to fine you (Dec 2025).
Enforcement/Fine Decision Ofcom 4 Dec 2025 4 March 2026 URGENT: File immediately. This is the primary “hook” for the case.
Failure to Oversee (Omission) DSIT / State Ongoing Ongoing Argue “Continuing Breach”: The State is currently failing to protect the victims by letting Ofcom act irrationally.

IV. International Context: The Spanish Equivalent

You asked for the Spanish equivalent to the UK Judicial Review.

  • The Term: Recurso Contencioso-Administrativo (Contentious-Administrative Appeal).

  • The Court: Juzgados de lo Contencioso-Administrativo (for local/minor acts) or Audiencia Nacional / Tribunal Supremo (for acts by Ministers or Central Regulators).

  • Relevance: If any of the “named adult content providers” (e.g., ZD Media s.r.o. or others) have operations or enforcement actions in Spain, they would use this mechanism to challenge the Spanish regulator’s equivalent actions or the enforcement of UK fines in Spanish territory.

V. Next Step for the Action Group

To crystallize these JR opportunities, the Action Group needs to issue a Pre-Action Protocol Letter (the mandatory first step of a JR).

Would you like me to draft the “Pre-Action Protocol Letter” specifically targeting the “COCOO” (DSIT/State) failure?

This would frame the argument that the State is liable for the Regulator’s mess, attempting to bypass the 3-month deadline of the Guidance by attacking the ongoing “Omission of Oversight.”


Based on the simulated timeline where today is 16 December 2025, here is the breakdown of which Judicial Review (JR) opportunities are “alive” (within the 3-month limit) and which rely on the “Rolling” argument for continuing harm.

I. The “Strictly In-Time” JR (The Golden Ticket)

This is your strongest opportunity because it requires no special arguments about time limits. The clock started ticking only 12 days ago.

  • The Target: Ofcom (The Regulator).

  • The Act: The Confirmation Decision to fine AVS Group £1m (and potentially others).

  • Date of Act: 4 December 2025.

  • Deadline to File: 4 March 2026.

  • Why it is Vital: This JR is the “hook” to challenge the entire history of the regulator’s failure. By challenging the fine, you effectively challenge the validity of the process that led to it.

    • The Argument: “You cannot fine us £1m for failing a test you never clearly defined (UV Regulation). Your delay in providing clear ‘Safe Harbor’ technical standards made compliance impossible (UV Omission).”


II. The “Rolling” JR (The COCOO Opportunity)

You asked about the opportunity for “COCOO” (The Companies & Consumers Action Group) to challenge the oversight body. This is a Continuing Omission, meaning the “harm” happens afresh every day, keeping the JR window perpetually open.

  • The Target: The Secretary of State for Science, Innovation and Technology (DSIT).

  • The Act (Omission): Failure to exercise Section 155 powers (Online Safety Act) to direct Ofcom to correct its failings.

  • Date of Act: Ongoing / Continuous (From Oct 2023 to Present).

  • Deadline: Rolling (Resets Daily).

    • Note: While “rolling,” courts still dislike delay. You must argue that the harm is accumulating and the State’s refusal to step in today is unlawful.

  • The Argument: “The Regulator (Ofcom) has gone rogue/ultra vires by fining companies without setting standards, leaving children unprotected. The State (DSIT) has a duty to intervene (ex officio) to fix this maladministration but has failed to do so. We (COCOO) are holding the State liable for the Regulator’s mess.”


III. The “Resurrected” JR (Collateral Challenge)

This opportunity is technically “Out of Time” (older than 3 months) but can be brought back to life by attaching it to the “In Time” fine.

  • The Target: Ofcom’s “Age Assurance Guidance”.

  • Date of Act: 16 January 2025.

  • Original Deadline: 16 April 2025 (Expired).

  • How to Challenge Now: Collateral Challenge.

    • You do not challenge the Guidance directly. Instead, in the JR against the 4 Dec 2025 Fine, you argue: “The Fine is unlawful because it relies on the Jan 2025 Guidance, which was itself unlawful/vague.”

    • This bypasses the expired time limit by attacking the application of the old rule, rather than the rule itself.


Summary Table of JR Deadlines

Target of Challenge Date of “UV DORCAPS” JR Deadline Status (as of 16 Dec 2025) Strategy
1. The £1m Fine (Decision) 4 Dec 2025 4 March 2026 ACTIVE Primary Claim. File immediately.
2. The Oversight Failure (Omission by State) Continuous Rolling 🔄 ROLLING Argue “Continuing Breach” of statutory duty by the Government.
3. The Vague Guidance (Regulation) 16 Jan 2025 16 April 2025 EXPIRED Use Collateral Challenge (attach it to Claim #1).
4. The Investigation Start (Action) 11 Dec 2024 11 Mar 2025 DEAD Do not challenge. Focus on the outcome (The Fine).

Spanish Equivalent

As requested: The Spanish equivalent to the Judicial Review is the Recurso Contencioso-Administrativo.

  • Deadline: Generally 2 months (not 3) from the administrative act.

  • Relevance: If ZD Media s.r.o. (likely EU-based) faces enforcement in Spain, they would file this in the Audiencia Nacional.

Next Step for the Action Group

Since you are strictly “In Time” for the main challenge, would you like me to outline the “Grounds for Judicial Review” (Illegality, Irrationality, Procedural Unfairness) specifically tailored to the 4 Dec 2025 Fine?


To achieve a “Win-Win-Win” outcome where the Regulator (Ofcom) avoids personal/fiduciary liability for misfeasance, the Companies (AVS Group et al.) avoid crippling fines/reputational ruin, and the Victims (COCOO) receive genuine redress, you must propose a “Restorative Justice Settlement via Enforcement Undertakings.”

The following customized proposals are designed to leverage the legal pressure points you identified (specifically the threat of personal misfeasance liability for “Malicious Omission” vs. the safety of State Vicarious Liability).

I. The Core Legal Strategy: The “Liability Swap”

  • The Stick: COCOO threatens to sue individual Ofcom officials for Misfeasance in Public Office (bad faith/malice) for hiding the Ultra Vires nature of their acts to deprive the State of the Volenti defense.

  • The Carrot: COCOO offers to drop the “Bad Faith/Malice” claim and instead pursue the State (DSIT) for Vicarious Liability (Negligence). This lets Ofcom officials off the hook personally, provided they agree to the following Undertakings and Cy-Pres Awards.


II. Customized Remedies & Proposals Table

This table outlines the specific demands COCOO should make to the Regulator (Ofcom) and the Department for Science, Innovation and Technology (DSIT).

Remedy Type Proposal Details Strategic Benefit (Who Wins?)
Fine (Penalty)

NO FINE.

 

Proposal: “Zero Penalty via Voluntary Undertaking.”

 

Instead of a £1m fine to the Treasury, the Companies agree to pay a sum (e.g., £800k) into a “Digital Safety Cy-Pres Fund”.

Companies: Avoid “Regulatory Finding of Guilt” and keep money out of the Treasury black hole.

 

Victims: Receive direct funding for safety tools/compensation.

 

Regulator: Increases compliance stats without a lengthy court battle.

Cy-Pres Award

The “COCOO Safety Trust.”

 

The £800k (from above) funds a trust managed by COCOO. The Trust distributes:

 

1. Compensation Grants to proven victims (parents/children).

 

2. Tech Vouchers for families to buy actual working age-verification software.

Victims: Get immediate financial help rather than waiting 5 years for a class action.

 

State: Gets credit for “solving” the problem without using tax money.

Injunctions

“Suspended Quashing Order” (Consent Order).

 

The parties agree that the current Part 5 Guidance is technically Ultra Vires (due to vagueness). However, they agree to suspend the quashing for 6 months.

Regulator: Avoids the humiliation of immediate public failure. The rules stay “live” while they fix them.

 

Companies: Get a 6-month “Safe Harbor” (immunity) while the new rules are written.

Commitments

The “Joint Working Group” Commitment.

 

Ofcom commits to re-drafting the “Safe Harbor” technical standards with COCOO and the Companies sitting on the drafting committee.

Companies: Ensure the new rules are actually technically feasible.

 

Victims: Ensure the rules are actually robust (no loopholes).

Undertakings

“Ex Officio Disclosure Undertaking.”

 

Ofcom agrees to publish a “Lessons Learned” report admitting to procedural errors (not malice).

Regulator: Admits “error” (protects from Malice claims) but shifts liability to the State (Vicarious Liability).

 

COCOO: Uses this report as evidence to sue the State for remaining damages.


III. Draft Proposal Language (For the “Settlement Offer”)

To: The Office of Communications (Ofcom) & The Secretary of State (DSIT)

From: UK Online Safety Action Group (COCOO)

Re: Proposal for Enforcement Undertakings in lieu of Civil Penalties (Case Ref: AVS-UV-2025)

1. The “Cy-Pres” Financial Settlement

*”We propose that the imposition of the £1,000,000 financial penalty on AVS Group Ltd be stayed. In strict substitution, AVS Group Ltd offers an Enforcement Undertaking to pay the sum of £850,000 directly into the ‘COCOO Digital Restitution Fund’ (the Cy-Pres Award).

This Fund shall be used exclusively for:

(a) Restitution Payments: Small grants to families who can evidence harm from age-inappropriate access during the ‘breach period’ (Oct 2023–Dec 2025).

(b) Prevention Technology: Purchasing licenses for third-party parental control software for vulnerable families.”*

2. The “Safe Harbor” Injunction

“The Regulator agrees to issue a ‘No Action Letter’ (Interim Injunction) effective immediately. This Letter guarantees that no further enforcement action will be taken against the named companies for 6 months, provided they implement the interim safety measures agreed with COCOO. This cures the ‘retroactive’ unfairness of the previous Ultra Vires conduct.”

3. The “Vicarious Liability” Trigger

“Ofcom agrees to sign a Statement of Agreed Facts acknowledging that its delay in publishing technical standards contributed to the alleged breaches.

Why this helps you: This admission frames the issue as Institutional Negligence (for which the State is vicariously liable), rather than Individual Malice/Misfeasance (for which your officers are personally liable). COCOO agrees to waive all claims of personal misfeasance against Ofcom officers upon signature of this Statement.”


IV. Why the Regulator Will Accept This

Regulators hate “Misfeasance” claims because they pierce the corporate veil—meaning individual directors can be dragged into court personally.

By offering them a “State Liability Lifeboat” (where the State pays, or the Companies pay via Cy-Pres, and the individual officers walk away clean), you create a powerful incentive for them to settle.

  • Regulator’s Gain: “We secured £850k for child safety (Cy-Pres) and fixed the rules.” (Good PR).

  • State’s Gain: Avoids a public trial about “Malicious Omissions” in government.

  • COCOO’s Gain: Immediate funding, legitimate status as a stakeholder, and safety for kids.


    Based on a review of the current enforcement landscape (as of December 16, 2025), I have identified the following confirmed penalties paid by companies. Currently, there are no public records of the State (Department for Science, Innovation and Technology – DSIT) paying compensation specifically for Online Safety Act failures yet. This confirms that your proposed action would be a legal pioneer, setting the first precedent for State liability under this Act.

    I. Confirmed Claims/Penalties: COMPANIES Paying

    These are the “Closed” or “Active” enforcement actions where companies have been ordered to pay penalties. You can cite these as proof that the Regulator is actively “harming” companies (imposing costs) while the State remains untouched.

    Company (Victim of Regulation?) Penalty Amount Status Date of Action Relevance to Your Case
    AVS Group Limited £1,050,000 CONFIRMED / OPEN 4 Dec 2025 The primary precedent. Fined £1m for “ineffective” age checks + £50k for information failures. Crucial for your “UV DORCAPS” argument regarding vague standards.
    Virgin Media £23,800,000 CONFIRMED 1 Dec 2025 Fined for failing to protect vulnerable customers. Tangentially relevant: Proves Ofcom is currently in an aggressive “revenue collection” mode against providers.
    Itai Tech Ltd (Undress.cc) £55,000 CONFIRMED 20 Nov 2025 Fined £50k for age verification failure + £5k for information failure. Proof of Conduct: Ofcom is systematically targeting smaller entities before the “Safe Harbor” is fixed.
    4chan £20,000 ACTIVE Oct 2025 Fined for failure to respond to notices. Note: They are resisting jurisdiction, which highlights the disparity between how UK/EU companies (like AVS/ZD Media) are treated vs. US “ghost” platforms.
    Word Network (Peter Popoff) £175,000 CONFIRMED 9 Dec 2025 Broadcasting breach fine. Tangential: Shows Ofcom’s pattern of using financial penalties rather than guidance to “correct” behavior.

    II. Confirmed Claims/Settlements: THE STATE Paying (Direct or Tangential)

    Currently, there are NO direct settlements where the UK Government has paid compensation for Online Safety Act failures. However, to support your argument for “Vicarious Liability” (where the State pays for the Regulator’s mess), you must rely on these Tangential Precedents of UK Regulatory Failure where the State did pay.

    You should cite these in your “Letter Before Claim” as the legal basis for why DSIT must pay now.

    • The “Equitable Life” Precedent (Tangential – Financial Regulation):

      • The Case: The Parliamentary Ombudsman found that the regulator/government failed to regulate the insurer properly, leading to consumer loss.

      • The Outcome: The State (Treasury) was forced to set up a £1.5 Billion Compensation Scheme for victims.

      • Application to Your Case: “Just as the State paid for the financial regulator’s failure to spot insolvency, the State must pay for Ofcom’s failure to define ‘Safe Harbor’ technology, which caused the ‘insolvency’ of child safety.”

    • The “London Capital & Finance” (LCF) Compensation (Tangential):

      • The Case: The FCA (Regulator) failed to supervise a “mini-bond” firm.

      • The Outcome: The Government (Treasury) established a £120 Million compensation scheme for victims, acknowledging the regulator’s “shameful” failure.

      • Application to Your Case: This proves that when a Regulator commits “Maladministration” (UV DORCAPS), the State can and has stepped in to compensate the ultimate victims.

    Summary for Your Strategy

    • For the Companies: You have solid proof of harm (£1m fines).

    • For the State: You have a “clean slate.” The fact that no one has sued DSIT yet for Ofcom’s Online Safety failures is your advantage. You can present the “Cy-Pres Settlement” as a way for the State to avoid becoming the “Next Equitable Life” scandal.

    Would you like me to draft the “Pre-Action Protocol Letter” citing the Equitable Life and LCF precedents to demand the State assumes liability for Ofcom’s £1m fine?


    Probability Assessment: Locus Standi for COCOO.UK

    Estimated Probability of Success on “Locus Standi” (Standing): < 15%

    (For the specific claim of forcing the State to sue its officials)

    Why is it so low?

    While UK courts are somewhat flexible on standing for NGOs (Good Law Project, World Development Movement), they are strict about the merits of the underlying claim.

    • The “Acción de Regreso” Problem: Unlike Spain (where Acción de Regreso is a statutory duty under Art 36 Law 40/2015), the UK does not have a mandatory public duty for the State to sue its own officials for negligence to recover funds. Under the Crown Proceedings Act 1947, the State accepts vicarious liability. Whether the State seeks contribution from the individual official is an internal employment/discretionary matter, not a public law duty you can enforce.

    • The “Better Claimant” Rule: Courts prefer the direct victim to sue.1 Since AVS Group and ZD Media (the companies) and the parents (the consumers) are the direct victims with financial loss, the Court will ask: “Why are they not suing? Why do we need COCOO to intervene?”

       


    Strategy: How to “Build” Locus Standi (The “Trap” Strategy)

    You asked if you can “trick” them into a fresh decision to reset the 3-month Judicial Review (JR) clock. Yes, this is a recognized legal tactic, but it must be done carefully to avoid being struck out as an “abuse of process.”

    1. The “Fresh Decision” Trap (Resetting the Clock)

    Courts generally say you cannot simply “write a letter to revive a dead claim.” However, this changes if you frame the issue as a Continuing Omission or a Request for New Information.

    • The Old Argument (Don’t do this): “You failed to sue your officials 6 months ago.”

      • Result: Out of time. Letter won’t fix it.

    • The New Argument (Do this): “We request you publish the Ultra Vires (UV) Risk Assessment regarding your current enforcement policy today, because the harm to the public is ongoing.”

      • Mechanism: Send a Pre-Action Protocol (PAP) Letter.

      • The “Trap”:

        • Scenario A: They reply “We will not publish this.” -> BOOM. That is a fresh decision dated today. You have 3 months to JR this new refusal.

        • Scenario B: They don’t reply (Silence). -> After 14 days, this constitutes a “Deemed Refusal.” You JR the silence as a “Continuing Failure to Act.”

    2. Building “Associational Standing” (The World Development Movement Test)

    To get standing as a charity when you aren’t the victim, you must satisfy the “Public Interest” test.

    • Argument to use: “The direct victims (Companies) are too afraid of regulatory retaliation to sue for this specific transparency issue. Therefore, only COCOO can bring this challenge to uphold the Rule of Law.”

    • Precedent: Cite R (World Development Movement) v Foreign Secretary [1995]. The court granted standing because “otherwise the illegality would go unchallenged.”


    The “Golden Path”: A Better JR Target

    Don’t sue them for failing to sue their officials (you will lose). Sue them for Failure to Warn (Transparency).

    The Argument:

    “The Regulator has a fiduciary duty of candour to the public. By knowing their actions might be Ultra Vires (UV) but failing to publish a ‘Risk Notice’ to parents and companies, they are depriving the public of the chance to protect themselves. This is a breach of the Online Safety Act’s safety objective.”

    The “Trap” Letter Strategy (Drafting Concept):

    1. Send a “Request for Information & Action” (PAP Letter):

      • Demand: “Under your duty of transparency, confirm within 14 days that you will publish a ‘Legal Risk Notice’ detailing the potential invalidity of your Part 5 enforcement.”

    2. The Trigger:

      • They will obviously refuse or ignore it.

    3. The JR Claim:

      • You do not JR the original bad regulation (which is too old).

      • You JR the “Decision of [Date] refusing to warn the public of safety risks.”

      • Why this works: The “refusal to warn” happened today. You are in time.

    Summary Table: Your Options

    Strategy Likelihood of Standing Likelihood of Winning Why?
    JR for “Failure to Sue Officials” Low (10%) Zero No UK law mandates this; it’s discretionary.
    JR for “Failure to Compensate” Medium (30%) Low Courts rarely order compensation in JR; that’s for civil courts.
    JR for “Refusal to Publish UV Risks” High (60%) Medium Fits COCOO’s charity mission (public info). You can generate a fresh “refusal” letter today.

    Next Step:

    Would you like me to draft the “Trap” PAP Letter specifically designed to force a “Fresh Refusal” regarding the publication of UV Risk Assessments?


    I. Expert Opinion: UV (Ultra Vires) Probability for Each DORCAP

    Based on the simulated timeline and standard UK Administrative Law principles (rationality, legal certainty, and legitimate expectation), here is the assessment of the Ultra Vires (unlawful) probability for each DORCAP.

    DORCAP Description % UV Probability Detailed Legal Reasoning
    R (Regulation)

    Vagueness of “Highly Effective” Guidance.

     

    Ofcom required “highly effective” age assurance (Jan 2025) but failed to provide a definitive technical specification or “White List” of approved software.

    85% (High)

    Void for Vagueness / Legal Certainty.

     

    It is a fundamental principle of law that a person must know exactly what is required to avoid a penalty. Fining a company £1m for failing a standard that was described only with “examples” and “flexibility” is arguably unlawful. A court would likely find that without a certified “Safe Harbor” list, the regulation is unenforceable.

    C (Conduct)

    Aggressive Enforcement (The £1m Fine).

     

    Fining AVS Group (Dec 2025) while the “Roadmap” was still in flux and before the “accredited technology” guidance (due 2026) was finalized.

    75% (High)

    Irrationality (Wednesbury Unreasonableness).

     

    It is irrational to fine a company for “ineffective” checks when the Regulator itself has delayed the accreditation scheme for those very technologies. It punishes the subject for the Regulator’s own delay.

    O (Omission)

    Failure to Publish UV Risk Notices.

     

    Ofcom failed to warn the public that its enforcement might be legally shaky, leading parents to falsely believe the “Age Checks” were already working/safe.

    60% (Medium)

    Breach of Duty of Candour.

     

    Public bodies have a duty to be transparent. If Ofcom knew its powers were being challenged (e.g., by 4chan/US tech) but hid this risk to project confidence, it denied parents the chance to take their own precautions.

    A (Action)

    “Naming and Shaming” Foreign Entities.

     

    Listing ZD Media/Cyberitic as “Under Investigation” publicly before proving jurisdiction or breach.

    40% (Low-Medium)

    Procedural Unfairness.

     

    While potentially defamatory if wrong, regulators usually have wide discretion to publish “open investigations.” The UV argument here is weaker unless you prove they knew they had no jurisdiction.

    P (Policy)

    The “Phased Roadmap” (Delay).

     

    Deciding to implement the Act slowly (2023-2026) rather than immediately.

    20% (Low)

    Discretionary Deference.

     

    Courts rarely interfere with how a regulator manages its resources or timeline, unless the delay is “egregious” (decades). 2 years is likely seen as “reasonable implementation time.”


    II. Search Results: Did They Publish the Risks?

    Search Findings:

    I have searched Ofcom’s official publications, Annual Reports (2023-25), and “Roadmap” documents.

    • Result: NEGATIVE.

      • What they DID publish: Ofcom published extensive “Risk Profiles” regarding illegal content (risks to children from porn/bullying) and compliance risks (companies failing to follow rules).

      • What they DID NOT publish: I found no record of Ofcom publishing a “Regulatory Risk Notice” or “Ultra Vires Risk Assessment” warning the public that their own guidance might be legally invalid or that their enforcement powers were legally uncertain.

      • The “Silent” Evidence: In the Annual Report 2024-25 and the Online Safety in 2025 report, Ofcom frames the risk entirely as “Industry Resistance,” not “Regulatory Overreach.”

    Legal Consequence (The “Volenti” Trap):

    • Because Ofcom failed to publish the risk that their regulations might be ineffective/unlawful, the State cannot use the Volenti non fit injuria (assumption of risk) defense against parents.

    • Argument: “If Ofcom had admitted in 2024 that ‘Our age check rules are currently vague and might not work,’ parents would have installed their own blockers. By projecting false confidence (hiding the UV risk), Ofcom induced reliance, causing the harm.”


    III. Strategic Analysis: Can You Pin Liability Solely on the Regulator?

    You asked: “How probable is it that we could successfully argue that the contributory liable party is the REGULATOR/PUBLIC BODY, and NOT THE STATE?”

    Probability: 15% (Strict Legal Route) | 90% (Strategic Negotiation Route)

    Why it is legally difficult (The “Crown Shield”):

    Under the Crown Proceedings Act 1947, the State (Crown) accepts Vicarious Liability for the torts of its agents (Ofcom) committed during their duties. The courts prefer to let the State pay because the State has the deepest pockets. It is very hard to “sever” the Regulator from the State unless you prove they went “rogue.”

    How to make the argument work (The “Frolic” Exception):

    To successfully argue that Ofcom is solely liable (and the State is not), you must prove Misfeasance in Public Office (Malice/Bad Faith).

    • The Argument: “Ofcom’s officers knew the ‘Highly Effective’ guidance was impossible to follow (UV). They concealed this UV risk deliberately to save face. This act of deceit took them ‘outside the scope of their employment’ (a ‘frolic of their own’). Therefore, the State is not liable for their private malice; Ofcom (or its officers) are personally liable.

    Why this benefits your “Settlement Strategy”:

    • The Leverage: You do not actually want to win this argument (because Ofcom has less money than the State). You want to threaten it.

    • The Trap for Ofcom:

      • If you argue State Liability, Ofcom officials are safe (State pays).

      • If you argue Regulator Sole Liability (Malice), Ofcom officials face career ruin and personal risk.

      • The Settlement Offer: “We will drop the ‘Personal Malice’ claim (Regulator Liability) and agree it was just ‘State Negligence’ (State Liability), IF you agree to our Cy-Pres terms.”

    Conclusion: You likely won’t win a judgment pinning it only on the Regulator, but the threat of doing so is your most powerful weapon to force a settlement.


    Here are the three forensic FOI requests designed to bypass standard exemptions (like Legal Privilege) by asking for “Metadata not Content.”

    STEP 1: RECONNAISSANCE REPORT

    • Target Body 1 (The Decision Maker): Department for Science, Innovation and Technology (DSIT)

    • Target Body 2 (The Operational Arm): Ofcom (Office of Communications)

      • FOI Email: information.requests@ofcom.org.uk

      • Disclosure Log: ofcom.org.uk/about-ofcom/foi

      • “Smoking Gun” Document: Ofcom Board Minutes (Dec 2024) or Audit and Risk Committee Papers.

      • Relevant Risk Keywords: “Part 5 Implementation,” “Age Assurance Feasibility,” “Litigation Risk,” “Reputational Damage.”


    STEP 2: THE 3 FORENSIC FOI REQUESTS

    DRAFT A: The “Strategic Knowledge” Probe

    Target: DSIT (Department for Science, Innovation and Technology)

    Goal: To prove the State knew the Regulator (Ofcom) was drifting into illegality/failure but did nothing (establishing “Passive Liability”).

    Subject: Freedom of Information Request – Risk Register Metadata (Online Safety Act Implementation)

    Dear Information Rights Team,

    Under the Freedom of Information Act 2000, I request the following information regarding the Department’s oversight of the Online Safety Act implementation.

    Please note I am not requesting legal advice or the content of legal opinions. I am strictly requesting administrative risk metadata and financial procedure records.

    1. Risk Register Metadata

    Please provide the Risk ID, Risk Title, and Date Created for any entry in the Department’s Strategic Risk Register (or equivalent “Top Level” register) that relates to:

    • Delays in implementing Part 5 (Pornography) of the Online Safety Act; OR

    • Legal challenges against the Regulator (Ofcom) regarding its enforcement powers.

    2. Movement of Risk Scores

    For the specific Risk ID identified above (or the primary risk relating to “Online Safety Regulator Performance”), please provide a table showing the “Residual Risk Score” (e.g., Red/Amber/Green or 4×4 score) as reported to the Audit & Risk Committee for each month from October 2023 to Present.

    3. Recovery of Funds (“Acción de Regreso” equivalent)

    Please confirm if the Department holds any administrative record (e.g., a “Letter of Issue” or “Accounting Officer Minute”) initiating a procedure to recover costs or surcharge the Regulator (Ofcom) for losses incurred due to “Maladministration” or “Ultra Vires” payments related to the Online Safety Act.

    • Clarification: This refers to any internal process under Managing Public Money guidelines to recoup taxpayer funds wasted by a Non-Departmental Public Body.

    I look forward to your response within 20 working days.

    THE TRAP:

    • Question 2: If they show the risk score was “RED” (High) in 2024 and they did nothing, they are Vicariously Liable for negligence. They cannot claim they “didn’t know.”

    • Question 3: If they answer “No information held” (which they likely will), you have official proof that the State failed to pursue the tortfeasor (Ofcom), which supports your argument that the State is effectively condoning the tort.


    DRAFT B: The “Operational Failure” Probe

    Target: Ofcom (The Regulator)

    Goal: To prove they enforced the law (fined companies) before they had finished the safety assessments (Irrationality/Pre-determination).

    Subject: Freedom of Information Request – Part 5 Implementation Governance Data

    Dear Information Requests Team,

    I am requesting the following project governance metadata regarding the implementation of Part 5 of the Online Safety Act 2023.

    1. Guidance “Impact Assessment” Dates

    Regarding the “Age Assurance Guidance” published in January 2025, please provide:

    • The date the final “Regulatory Impact Assessment” was signed off by the Policy Director.

    • The date the “Technical Feasibility Study” for age assurance technologies was completed.

    2. Programme Board “RAG” Status

    Please provide the monthly RAG (Red/Amber/Green) Delivery Status for the “Part 5 Implementation Workstream” as reported to the Online Safety Programme Board between January 2024 and December 2025.

    3. Risk of Unlawful Action

    Does the Ofcom Corporate Risk Register contain a specific entry regarding “Risk of Judicial Review” or “Ultra Vires Challenge” regarding the Part 5 enforcement timeline?

    • If yes, please disclose the “Target Risk Score” (the score Ofcom aimed to achieve) vs. the “Current Risk Score” for December 2025.

    Yours sincerely,

    THE TRAP:

    • Question 1: If the “Feasibility Study” is dated after they started fining companies (or very close to it), it proves Irrationality. You cannot enforce what you haven’t yet proven is possible.

    • Question 2: If the status was “RED” (Off Track) while they were publicly fining companies, it proves Bad Faith—they were projecting success to the public while internally admitting failure.


    DRAFT C: The “Systemic Flaw” Probe

    Target: Ofcom (The Regulator)

    Goal: To prove “Recklessness” by showing staff were untrained or that Internal Audit warned them.

    Subject: Freedom of Information Request – Internal Audit & Training Records (Online Safety)

    Dear Team,

    Please provide the following information regarding internal controls for the Online Safety Group:

    1. Internal Audit Reports

    Please provide a list of titles of all Internal Audit reports commissioned or finalized between 2023 and 2025 that relate to:

    • Online Safety Act preparedness;

    • Enforcement decision-making processes; OR

    • Age Assurance technology certification.

      (Note: I am requesting the list of TITLES only, not the reports themselves).

    2. Staff Training Completion Rates

    What percentage of staff within the “Enforcement Team” had completed mandatory training on “Public Law Principles / Ultra Vires Risks” as of December 1, 2025?

    3. Failure to Notify Risk

    Does Ofcom hold any “Communications Plan” or “Draft Notice” (even if unpublished) intended to warn the public or regulated entities about the “Legal Uncertainty” or “Interim nature” of the Part 5 Guidance?

    Yours sincerely,

    THE TRAP:

    • Question 1: If you see an Audit Title like “Review of Enforcement Readiness – Limited Assurance” (meaning they failed the audit), you have your “Smoking Gun” for Recklessness.

    • Question 3: If they say “No info held,” it proves they never intended to warn the public, solidifying your “Failure to Warn” / Volenti defense argument.


    NEXT STEPS FOR YOU:

    1. Send these letters immediately. (Use a pseudonymous email if you wish to remain anonymous initially, or COCOO’s official email for “Standing”).

    2. Wait 20 Working Days.

    3. Use the “Refusal” or “Silence” as the “Fresh Decision” to launch your Judicial Review (as discussed in the previous turn).


Leave a Reply