When Ofcom fined US-based internet forum 4chan more than £520,000 for alleged breaches of the UK Online Safety Act (OSA), it looked like another major enforcement action in the regulator’s increasingly active approach to online safety.
But it has evolved into something much bigger.
4chan has refused to pay, arguing that as a US company with no UK staff, assets or infrastructure, Ofcom has no practical ability to enforce the penalty. The dispute has now escalated into legal proceedings in the US, with 4chan and Kiwi Farms asking a US federal court to prevent Ofcom from enforcing the OSA against American companies.
The outcome could become one of the first major tests of how far national digital regulation can reach across borders.
The real question isn’t the fine
The £520K penalty has attracted headlines, but it may be the least significant part of the dispute.
Collecting regulatory fines from overseas companies has always been difficult where those businesses have no assets or legal presence in the enforcing country. Even if Ofcom pursues enforcement through US courts, there is no guarantee American judges would recognise or enforce a UK regulatory penalty.
The real power lies elsewhere. Like many modern digital laws, the OSA gives regulators tools that go beyond financial penalties. Where companies refuse to comply, Ofcom can ultimately seek court orders requiring internet service providers or other supporting businesses to restrict access to services in the UK.
That is a growing trend in digital regulation. Rather than relying solely on fines, governments are using market access as their most effective enforcement tool.
If companies want access to users in a jurisdiction, regulators now expect compliance with local rules, regardless of where the company itself is based.
A growing trend across digital regulation
The OSA is not unique. The EU’s Digital Services Act already applies to many platforms operating outside Europe if they provide services to EU users. The EU AI Act follows a similar model, applying not only to organisations established within the EU but also to providers and deployers whose AI systems affect people in the European Union.
The UK’s Online Safety Act uses a comparable approach. A platform does not need UK offices or employees to fall within scope. Having a significant number of UK users or targeting the UK market may be enough.
This reflects a broader shift in regulation. Governments are focusing less on where a company is located and more on where its services are used. For multinational technology companies, that means compliance obligations can arise simultaneously under multiple legal regimes that may not always align.
The challenge of cross-border enforcement
The 4chan dispute also exposes one of the biggest unresolved questions in global digital regulation.
National regulators can legislate with extraterritorial effect, but enforcing those laws against overseas businesses remains legally and practically challenging.
US constitutional protections around free speech differ significantly from the UK’s Online Safety Act. The legal claim filed by 4chan and Kiwi Farms argues that Ofcom’s actions interfere with rights protected by the First Amendment and seeks a permanent injunction preventing the regulator from enforcing UK law in the US.
Whatever the US courts decide, the case illustrates the growing friction between different legal systems attempting to regulate the same global internet.
That tension is unlikely to disappear. As more countries introduce AI regulation, online safety laws and platform governance rules, businesses operating internationally will increasingly find themselves navigating overlapping, and sometimes conflicting, requirements.
Should UK businesses care?
It would be easy for organisations outside the social media world to dismiss the dispute as an unusual case involving controversial internet forums. But the underlying regulatory principle applies well beyond online platforms.
The Online Safety Act, the EU AI Act, GDPR and other digital laws all demonstrate that regulators are increasingly willing to assert jurisdiction over overseas organisations where local users are affected.
For UK businesses operating internationally, this has important implications.
A UK organisation developing AI products may find itself subject to the EU AI Act if those systems are placed on the EU market or used by people in the EU. Likewise, overseas businesses offering services to UK users may face obligations under the Online Safety Act even without a UK office.
Compliance can no longer be viewed through the lens of a company’s headquarters alone. Businesses need to understand where their customers, users and markets are and which regulatory regimes follow them there.
A preview of future regulatory battles?
The dispute between Ofcom and 4chan may ultimately be remembered less for whether a £520K fine is ever collected than for what it reveals about the future of digital regulation.
As governments seek to regulate global technology companies, enforcement will increasingly depend on access to markets, platforms and users rather than simply issuing financial penalties.
For regulators, that may prove to be a far more powerful lever.
All this is another reminder for businesses that digital compliance is becoming inherently international. Whether complying with the UK’s Online Safety Act, the EU AI Act or other emerging technology laws, organisations must be prepared for a world where regulatory obligations increasingly cross borders, even when their offices do not.
Don't miss our Guide to the Online Safety Act
Read it here →