MPs say Online Safety Act misses legal but harmful disinformation
The Online Safety Act does not cover the algorithmic amplification of misleading content that is harmful but not illegal, MPs on the Science, Innovation and Technology Committee said in a report published on 11 July 2025.

The committee's report points to the previous summer's riots in the UK. It says they were partly driven by online misinformation and hateful content after fatal stabbings at a children's dance class in Southport. Those posts, MPs say, were amplified by recommendation algorithms on social media platforms.
The Online Safety Act received royal assent in October 2023. The provisions requiring social media companies to protect users from illegal content came into force in March 2025. The committee warns the law still fails to address the algorithmic amplification of what it calls "legal but harmful content". That leaves the public exposed to a repeat of last summer's crisis. The Register reported the committee's findings on 11 July 2025.
155 million impressions on X
The numbers in the report are stark. Between 29 July and 9 August 2024, false or unfounded claims about the Southport attacker racked up 155 million impressions on X. Across social media, the false name was seen 420,000 times, with a potential reach of 1.7 billion people. The committee said algorithmic tools promoted it directly, pushing it into X's "Trending in the UK" and TikTok's "Others searched for" features.
Dame Chi Onwurah MP chairs the Science, Innovation and Technology Committee. She said the legislation "just isn't up to scratch" and that the government needs to go further to tackle misinformation that causes harm but does not cross the line into illegality. "Social media companies are not just neutral platforms but actively curate what you see online, and they must be held accountable," she said. The committee urged the government to adopt five principles as the foundation of future regulation, ranging from protecting free expression to holding platforms accountable for content they put online.
How the false claims spread in the first place is documented in detail. CNBC reported on 9 August 2024 that within hours of the Southport knife attack, which killed three young girls, false information about the attacker's name, religion and migration status gained significant traction. Hannah Rose, a hate and extremism analyst at the Institute for Strategic Dialogue, told CNBC that a post on X falsely named the perpetrator as "Ali al-Shakati", rumored to be a migrant of Muslim faith. By 3 p.m. the following day, she said, the false name had over 30,000 mentions on X alone.
Other false claims shared on social media said the attacker was on an intelligence services watchlist, that he came to the UK on a small boat in 2023, and that he was known to local mental health services, according to ISD's analysis cited by CNBC. Police debunked the claims the day after they first emerged, saying the suspect was born in Britain. By then the narrative had already gained traction. Far-right groups began organising anti-migrant and anti-Islam protests, including a demonstration at the planned vigil for the girls who had been killed. The unrest escalated into days of riots, with attacks on mosques, immigration centres and hotels housing asylum seekers.
How the platforms pushed the false name
Social media did not merely host the falsehoods. According to ISD's Rose, accounts with hundreds of thousands of followers, and paid-for blue ticks on X, shared the false information. The platform's algorithms then pushed it to other users. "For example when you searched 'Southport' on TikTok, in the 'Others Searched For' section, which recommends similar content, the false name of the attacker was promoted by the platform itself, including 8 hours after the police confirmed that this information was incorrect," Rose told CNBC. ISD's analysis showed algorithms worked in a similar way on other platforms such as X, where the incorrect name of the attacker was featured as a trending topic.
Joe Ondrak is research and tech lead for the UK at Logically, a tech company developing artificial intelligence tools to fight misinformation. He told CNBC the false claims functioned as "catnip" to groups already hostile to migration. "It's not a case of this false claim goes out and then, you know, it's believed by everyone," he said. The reports instead act as "a way to rationalize and reinforce pre-existing prejudice and bias and speculation before any sort of established truth could get out there."
The false claims also reached Telegram, which Ondrak said consolidates narratives and exposes increasing numbers of people to "more hardline beliefs". He described claims being funneled through what he called the post-Covid milieu of Telegram, including channels that were initially anti-vaccine and were later co-opted by far-right figures promoting anti-migrant topics. In response to a request for comment by CNBC, Telegram denied that it was helping spread misinformation. Its moderators were monitoring the situation and removing channels and posts calling for violence, which are not permitted under its terms of service, Telegram said.
At least some of the accounts calling for participation in the protests could be traced back to the extreme right wing, according to analysis by Logically, including some linked to the banned right-wing extremist group National Action, which was named a terrorist organisation in 2016 under the UK's Terrorism Act. Ondrak also noted that many groups that had previously circulated false information about the attack had started walking it back, saying it was a hoax.
As the riots continued, X owner Elon Musk weighed in with controversial comments about the violent demonstrations on his platform, prompting pushback from the UK government. The country's courts minister called on Musk to "behave responsibly". TikTok and X did not immediately respond to CNBC's request for comment. On the Wednesday after the worst of the disorder, thousands of anti-racism protesters rallied in cities and towns across the UK, far outnumbering recent anti-immigrant protests.
Ofcom told platforms not to wait
The UK has an Online Safety Act meant to fight hate speech, but at the time of the riots it was not yet in force and, CNBC noted, may not be enough to guard against some forms of disinformation. The media regulator Ofcom issued a letter to social media platforms saying they should not wait for the new law to come into force, and the UK government also said social media companies should act.
The committee's report goes further than the regulator's nudge. MPs argued that platforms need to be held responsible for the algorithmic spread of misleading or deceptive content that can radicalise and harm users, and that the Online Safety Act fails to address this point. "It is imperative that we regulate and legislate these technologies based on the principles set out in this report, harnessing the digital world in a way that protects and empowers citizens," the report said. During the hearings leading up to it, the committee heard a range of interpretations of UK law, betraying a lack of clarity from Ofcom and the civil service over whether the Online Safety Act covers misinformation at all.
The Southport case is not the only example of disinformation being produced for money rather than conviction. A BuzzFeed News investigation, reported in partnership with the Reporter in Taiwan, found that since 2011 at least 27 online information operations had been partially or wholly attributed to PR or marketing firms, 19 of them in 2019 alone. It described a worldwide industry of "black PR" firms ready to deploy fake accounts, false narratives and pseudo news websites for clients.
One of them, the Israeli firm Archimedes Group, created networks of hundreds of Facebook pages, accounts and groups around the world. It boasted on its website that it would "use every tool and take every advantage available in order to change reality according to our client's wishes". For an election in Mali it managed a fake fact-checking page that claimed to be run by local students. In Tunisia it ran a page titled "Stop a la Desinformation et aux Mensonges". In Nigeria it ran pages advocating for and against the same politician, former vice president Atiku Abubakar. Researchers postulated that the pro-Abubakar page "was likely designed to identify his supporters in order to target them with anti-Abubakar content later".
Nathaniel Gleicher, Facebook's head of cybersecurity policy at the time, told BuzzFeed News that "the professionalization of deception" is a growing threat. "Companies grow up that basically build their business model around deception," he said. Cindy Otis, a former CIA officer and author of True or False: A CIA Analyst's Guide to Spotting Fake News, said information operations by nation-states like Russia and Iran had provided "a playbook for individuals and groups that are financially motivated to enter this space".
In the UK, the immediate question is whether the law catches the kind of content that preceded the riots. The committee's answer, in effect, is that it does not. The false name was legal speech, promoted by recommendation systems, and seen 420,000 times. The Online Safety Act's illegal content duties, in force since March, do not reach it. That is the gap MPs want closed.
Sources
3- 01UK Online Safety Act 'not up to scratch' on misinformation, warn MPsEN
- 02Online disinformation sparked a wave of far-right violence in the UKEN
- 03Disinformation For Hire: How A New Breed Of PR Firms Is Selling Lies OnlineEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.