AI Regulation: ECRs' perspectives

Can we have a platform regulation without AI regulation?

Posted on    by
AI Regulation: ECRs' perspectivesBlog

Can we have a platform regulation without AI regulation?

By 25 June 2026July 7th, 2026No Comments

AI Regulation: ECRs’ Perspectives is a CREATe blog series featuring the work of early career researchers who are exploring the contemporary challenges of AI regulation.  Drawing primarily on research presented at the AI Regulation ECR Conference, while also including related work on AI regulation, each post provides concise and accessible insights into emerging legal and policy debates around artificial intelligence.

The series continues with a blog post by Sejal Chandak. Sejal holds a PhD from Queen’s University Belfast and is currently a Lecturer in Law at the University of the West of England. Her research interest lies is in the intersection of law, technology, politics and society and she is currently focusing on the governance of artificial intelligence (specifically chatbots), and regulatory frameworks for smart cities.

Can we have a platform regulation without AI regulation?

Context

Social media platforms are a part of our contemporary lives. For an international scholar like me, these platforms have made the daily connectivity with my friends and family back home possible. Access to internet and mobile phones have drastically increased in the last few decades (while also creating ‘digital exclusion’ for many). This access, however, has a price, and for the last few years the price has been extreme. Platforms have been promoting violence, sustained misinformation (Dennis & Lindberg 2025), targeted harassment and the developments in artificial intelligence (AI) have further compounded their destructive tendencies. We’re already witnessing misuse of AI chatbots to create deepfakes, amplification of violence against women, and grooming threats against children.

Many targeted legislative interventions around the globe are being rolled out to tackle the harmful realities created by social media platforms. This blog specifically looks at the Online Safety Act 2023 (OSA) and questions if, in the age of ‘AI-fication’, the platforms can be regulated without also regulating AI? The UK now has legislation in place to regulate internet services, however, there is no legislation specifically targeting AI. Platforms are adopting AI at an accelerating pace not only for content moderation but also for content creation. Users today are constantly interacting with various types of AI across platforms. Be it integrated AI-powered chatbots such as GrokAI and Meta AI, AI generated overviews with Google Search, or standalone AI platforms such as ChatGPT. In such a scenario, how effective can our platform governance be without also governing AI?

Legislative Developments

The initial development of internet platforms was aided through regulation. The immunity granted to the internet service providers in relation to user-generated content under Section 230 of the Communications Decency Act 1996 created the internet as we know it today. This shield was largely replicated through legislations, such as the EU’s E-Commerce Directive 2000 and now the Digital Services Act 2022; UK’s E-Commerce Regulation 2002; India’s Information Technology Law 2000, (albeit not as broad as in America). It also allowed the internet, and subsequently social media platforms, to grow and profit from any user-generated content. The profit-making motives of technology companies along with the legislative shield have meant that harmful, and often false, content has been amplified. The shield has created an environment of lack of accountability and responsibility, leading to several instances of violence and destruction in our society (House of Common UK Parliament, 2025).

The last few years have made it clear that platforms need to be made accountable and responsible for their services and tools. Extensive research proves that platforms’ algorithms have played a decisive role in what kind of content is amplified or ‘made viral’(Bauman and others, 2026; Huszar and others, 2021; Joe Whittaker and others, 2021). Due to the active role the systems play in promoting content, legislatures are now moving away from a self-regulatory model to a co-regulatory model. One of the countries to implement this co-regulatory model is the UK with its Online Safety Act 2023 (OSA). The Act creates statutory duties for platform providers to ensure that their platforms do not disseminate any ‘illegal content’ and that they have policies in place to remove such content.

The Online Safety Act and Platform Governance

The OSA was implemented in the UK in 2023 after a long and contested journey. The Act is currently the key legislation governing internet services in the UK. It imposes duties on internet platforms to identify risks of harms to users and to put in place measures to mitigate and manage those risks/harms. Such measures include conducting risk assessments (Sec 9), undertaking safety measures to protect users from encountering illegal content (Sec 10), and implementing effective and proportionate risk-mitigation plans (Sec 10). Risk assessments are the fundamental key under the Act to ensure user safety as the assessment exercise is meant for platforms to proactively recognise risks and put in place the measures to counter such risks.

The Act requires service providers to consider how their algorithms, design and operation of the service contribute to the reduction or increment of the identified risks (Sec 9 (5)). This is an important aspect of the law as it recognises that a platform’s choices and architecture can actively influence user behaviour and contribute to various harms. When we look at the implications of Sec 9 for AI, we understand that AI will be considered part of the design and architectural choices that a platform makes, and that platforms are now under a statutory duty to consider these choices while assessing the risks of harm to users in the UK.

The OSA is primarily applicable to user-to-user services, search services, and providers of pornographic content online. A user-to-user service is any service that one can use to create, share and encounter content shared by other users (Sec 3). Social media platforms such as Instagram or TikTok, music sharing platforms such as Spotify, online marketplaces such as Facebook marketplace, or gaming platforms can all be classified as a user-to-user service under the OSA. Such a classification imposes duties of care upon the platform providers under the Act. So, when these platforms use AI for content moderation or user interaction (like GrokAI), this usage needs to be a consideration for platform providers when they undertake risk assessments.

An important issue here is that the OSA does not directly regulate AI but requires platform providers to take under consideration the harmful impacts of AI on the users. Can such consideration be enough, when we know that AI does play a significant role not only in moderation, but also amplification and creation of content?

When we discuss harm, the Act operationalises that through ‘illegal content’. The OSA specifically targets harms arising from ‘regulated user-generated content’ (Sec 55) that can broadly fall in two categories (Sec 1):

  • Illegal content and activity
  • Content and activity that is harmful to children

Illegal content can be in the form of words, images, speeches or sounds and has been defined as any content that amounts to a relevant offence under the Act (Sec 59). Relevant offence encompasses any content relating to terrorism, child sexual exploitation and abuse, and content that encourages or assists in serious self-harm, threats to kill, harassment, stalking, drugs or psychoactive substances, and other offences (Sec 59 and Schedule 7). Illegal content has been extensively defined, and it is important to note that only content meeting the threshold of illegal content is regulated. Furthermore, the duty of platforms is not to remove all illegal content but have measures and systems in place to reduce the illegal content on their platforms (making OSA a system-based regulation) and hence reduce the harm to users. The Act also imposes heavy penalties for non-compliance, which can be up to £18 million or 10 percent of a platform’s worldwide revenue (Schedule 13).

These are the two broad parameters through which the OSA regulates platforms. We can see that while certain aspects of AI are being regulated, the larger question remains – can we really have strong platform regulation without also specifically targeting AI?

AI, Chatbots, Platforms and Online Safety Act

AI is not a new tool for platforms. For some time now, AI has been used for content moderation and, research shows, it is also used for content amplification. A fundamental shift has occurred due to the developments in the field of natural language processing since the release of ChatGPT in 2022. The new large language models (LLM), trained on billions of parameters and utilising transformer architecture (Vaswani and others , 2017), are extremely powerful. They are not only able to create high-quality content, but they can also improve recommendations, provide customer service and analytics for users and platforms.

These LLMs are powering the next phase of platform developments. LLM-powered chatbots such as ChatGPT, GrokAI have also become quite popular with users. Having been trained on the patterns in human language, these LLMs exhibit far more advanced capabilities to emulate human emotions and have human-like conversations with users (Surden, 2024). While this does not mean that the chatbot or LLM programme actually ‘understands’ or ‘has feelings’, the human-mimicking outputs are more likely to be believed, leading to personal and societal harms (Katoch & Sandhu, 2025). We very recently saw how users were able to manipulate GrokAI, an integrated chatbot on X (formerly Twitter) to generate digitally altered pictures of women and children. With AI, the existing risks from platforms to users have significantly increased and hence the questions about effectiveness of platform regulation for us in the UK.

There are a few ways that OSA does regulate certain aspects of AI use by platforms:

  1. AI as part of platform design and architecture: As discussed above, if and when AI has been integrated on a platform, that design choice will have to be reflected in the risk assessments that platforms undertake. Similarly, if an AI powered chatbot has been integrated on a ‘user to user’ service (E.g., GrokAI), it becomes part of the regulated service and the OSA is applicable to such chatbot services (OFCOM, 2026).
  2. AI services categorised as regulated service: If any AI platform can be defined under regulated services, the OSA will be applicable. For instance, Character.AI is a chatbot platform where user created chatbot avatars can interact with other users. This falls within the meaning of a user-to-user service and hence will be regulated under the OSA. Similarly, if an AI service/chatbot allows user generated pornographic material to be shared/encountered, it will be regulated under the OSA (OFCOM, 2026).
  3. Content created by AI: The OSA is indifferent to how a content was created by a user. If a user uses AI or chatbot to create content and it gets shared by a user, it will be categorised as user-generated content. If it meets the thresholds of illegal content, the platform is duty-bound to remove it.

However, the Act does leave out on regulating certain other aspects, which could essentially make platform regulation less effective in the UK:

  1. Standalone AI services: The OSA is only applicable to regulated services. In case an AI platform (e.g., ChatGPT) does not fall within the definition of these services, the OSA will not be applicable. This directly implies that there will be many platforms that will not be regulated in the UK as we lack specific AI regulations.
  2. Content created by AI: Two important parameters need to be met for OSA application – that content be shared with other users and that it meets the thresholds of illegal content. This implies that content generated by AI systems (e.g., ChatGPT) that cannot be shared with other users will not be regulated under the Act even if such content is harmful to users. Another associated issue here is the inability to assign intent behind the content. The OSA does not prescribe any intent on an automated tool, so the question in case of illegal content is who can we make liable? The user? The programmer? Or the company? The OSA was not targeting AI, hence these questions remain unanswered.

Platform regulations are an important issue of our time, but with the proliferation of AI such regulations might somewhat be ineffective if we do not regulate AI. The OSA is a strong piece of regulation that can easily be made fit-for-purpose for regulating the use of AI on internet platforms. Following are a few suggestions to meet the regulatory gaps identified:

  1. Expansion of regulated services: The OSA can be expanded to include standalone AI platforms (e.g., ChatGPT) and impose statutory duties of care. Having to undertake risk assessments would be beneficial for providers to recognise risks and implement systems in place to tackle those risks.
  2. Voluntary risk assessments: Service providers can voluntarily undertake risk assessments to build trust in their products and ensure that their services do not harm users or the society.
  3. Education: AI literacy and specifically understanding how LLMs work can be an effective tool to mitigate risks in our society. The better we as a society understand how AI and associated technologies work, the better we can insulate ourselves from the damage caused by such technologies.

The OSA is a new piece of legislation, and it will take us some time to gauge its impact. However, the risks that AI presents could potentially weaken the impact of this legislation. These concerns need to be considered to ensure that we, as a society, can benefit from this piece of legislation.

The series continues with the blog post “Can we CREATe a Pro-Consumer AI Regulation?” by Anna Katharina Suzuki-Klasen, in which she explores the benefits and drawbacks of some AI applications and considers if EU law is giving us consumers sufficient protection.