How UK digital policy performs control while engineering deeper dependency on the platforms it claims to regulate
The UK government speaks the language of digital sovereignty while systematically building its opposite. Across encryption policy, platform regulation, identity infrastructure, and competition law, the pattern is consistent: the appearance of control, the reality of deeper dependency.
This is not a partisan problem. The legislative foundations were laid under Conservative governments from 2016 onwards. They have been inherited, accelerated in some cases, and in no case substantively revised by the current Labour administration. Both parties share the same diagnosis — Big Tech is too powerful — and have pursued remedies that, on close inspection, leave Big Tech considerably more powerful than before, while UK citizens pay the cost.
Academic research published in Internet Policy Review diagnosed the structural failure precisely: the UK's online safety regime suffers from what researchers now term regulatory capacity capture — not the traditional form in which a regulator is captured by the industry it oversees through lobbying or revolving-door appointments, but a subtler and more pervasive variant in which the state becomes dependent on platforms to regulate platforms, borrowing their expertise, their taxonomies, and ultimately their framing of what constitutes harm. The result is a system that is technically active and substantively ineffective.41
What follows is an examination of four areas where that ineffectiveness has produced concrete, measurable outcomes — not through malice, but through a regulatory posture that consistently mistakes motion for progress.
"Drawing from 33 elite interviews, this study develops a capacity-based approach to analyse the emergent regulatory system for online safety in the UK. By examining the capacity constellations of government and platform actors, the research reveals critical deficiencies in the UK government's capacity to regulate platforms, presenting challenges to regulation and increasing the risk of regulatory capture."
Regulatory capacity capture: The United Kingdom's online safety regime — Internet Policy Review (peer-reviewed). policyreview.info/articles/analysis/regulatory-capacity-capture01 The Encryption Betrayal
In January 2025 the Home Office served Apple with a technical capability notice under the Investigatory Powers Act 2016.1 Court documents later confirmed its scope: not the data of a named suspect, but access to the encrypted iCloud data of Apple users worldwide. The following month Apple removed Advanced Data Protection — its end-to-end encryption for iCloud backups, photos, notes and messages — from all UK users rather than build the capability the notice demanded.30
The government did not gain access to any data. Apple's architecture made compliance structurally impossible without rebuilding the system from the ground up. The company's response was rational: rather than weaken its encryption globally, it withdrew the feature from the market that demanded the weakening. UK users lost one of the most significant privacy protections available on a consumer cloud platform. The state gained nothing except the ability to say it had tried.
What happened next is the part most accounts stop short of, and it is the most revealing. Apple challenged the notice at the Investigatory Powers Tribunal. The Home Office asked the Tribunal to keep the case entirely secret — not merely its contents, but the fact of its existence and the identity of the parties. In April 2025 the Tribunal refused, in terms worth quoting: "We do not accept that the revelation of the bare details of the case would be damaging to the public interest or prejudicial to national security.33" The public learned that the British state had demanded worldwide access to a US company's encrypted data because a court declined to help conceal it. Privacy International and Liberty, with two individual claimants, brought parallel complaints challenging the lawfulness and the secrecy of the notice regime itself.31
Then the pressure that moved the government came from outside it. In August 2025 the US Director of National Intelligence announced that the UK had agreed to drop its demand for access to American citizens' data. Not a parliamentary vote, not a select committee, not a judicial review brought by a UK citizen — an intervention by a foreign government protecting its own nationals. The Home Office then issued a second, narrower notice, reportedly targeting British users alone. The demand was not withdrawn. It was reduced to the population with no comparable advocate.34
That is where matters still stand. Apple filed a fresh claim against the replacement notice in July 2026 and has said it remains unable to restore the feature; the Tribunal's timetable runs into December 2026.32 Advanced Data Protection has now been unavailable to UK users for more than eighteen months. British citizens hold, uniquely among comparable jurisdictions, a diminished version of a protection their government fought in secret to remove — and the only relief obtained so far was obtained on behalf of Americans.
- 2016Investigatory Powers Act passedCreates the technical capability notice: a power to compel a company to maintain the ability to assist with state access to data.
- December 2022Advanced Data Protection launches in the United StatesEnd-to-end encryption extended to iCloud backups, photos and notes. Apple itself cannot read the data.
- February 2023Rolled out worldwide, including the UKUK users hold the same protection as users in the EU, US, Canada and Australia.
- January 2025Home Office serves a technical capability noticeCourt documents later confirmed its scope: access to encrypted iCloud data of Apple users worldwide, not those of a named suspect.
- February 2025Apple withdraws the feature from UK usersRather than weaken encryption globally, Apple removes it from the market demanding the weakening. The state obtains no data.
- April 2025Tribunal refuses blanket secrecyThe Home Office had asked that even the existence of the case and the identity of the parties be withheld. The Investigatory Powers Tribunal declined.
- August 2025United States intervenesThe US Director of National Intelligence announces the UK has agreed to drop its demand for access to American citizens' data.
- Autumn 2025A second, narrower noticeReportedly targeting British users alone. The demand is not withdrawn — it is reduced to the population with no comparable advocate.
- July 2026 → December 2026Litigation continuesApple files a fresh claim against the replacement notice and states it still cannot restore the feature. The Tribunal's timetable runs into December 2026.
The Investigatory Powers Act was passed under Theresa May, then Home Secretary, in 2016. The technical capability notices it enables have been exercised under both Conservative and Labour administrations. The current government has not amended the legislation, proposed reform, or acknowledged the concrete harm to UK users that resulted.1 When the original notice became untenable it did not withdraw the demand; it issued a narrower one and continued to defend it in a tribunal it had asked to sit in secret.
What makes this failure particularly significant is what Apple had actually built. Unlike Google, whose business model is fundamentally predicated on data collection, Apple had invested in an architecture that genuinely limited its own access to user data. On-device processing, differential privacy, tokenised payments that never exposed card data to merchants, Advanced Data Protection — these were not marketing claims. They were real engineering decisions that cost Apple data leverage it could have monetised.
Apple's App Tracking Transparency framework, which required explicit user consent for cross-app tracking, reduced Meta's advertising revenue by an estimated $10bn in the year following its introduction.36 The UK's regulatory response to a company that had cost Meta ten billion dollars in surveillance revenue — by giving users more control — was to dismantle its best privacy feature. The signal sent to every other platform: investing in genuine user privacy provides no regulatory advantage. It may make you a target.
The coherent regulatory position would have been to use Apple's architecture as the floor — to mandate that Google, Meta, and others meet the same standard. Instead, the floor was removed. The extractive players faced no equivalent pressure on their actual surveillance practices. The one structural market incentive pointing in the right direction was penalised out of existence.
02 The Identity Trap: Sovereignty as Managed Dependency
Dawn Foster's Lean Out63 identified the mechanism a decade before it became this visible in digital policy: when institutions adopt the language of reform, the first question worth asking is who benefits from the framing. Child safety, in Meta's hands, is doing exactly the work Foster described.
While attacking encryption on one side, the government was simultaneously constructing a centralised identity architecture on the other — and doing so with the enthusiastic support of the very platforms that digital regulation is supposed to constrain.
The Online Safety Act 2023, passed under the Conservative government and implemented under Labour, mandates age verification for platforms hosting adult content.2 The broader UK Digital Identity and Attributes Trust Framework, developed across both administrations, is building the infrastructure for a national digital ID system. Both are presented as child protection and consumer safety measures. Neither is straightforward when examined for its structural consequences.
The most instructive detail in the age verification debate is not who opposes the legislation — it is who supports it. Meta — whose platforms have faced repeated parliamentary scrutiny for inadequate child safety, algorithmic amplification of harmful content, and documented mental health impacts on minors — has been among the most active advocates for mandatory age verification globally. Understanding why requires looking at what happened in the United States, where the strategic logic has been argued in public.
In March 2025 Utah became the first state to enact an App Store Accountability Act, requiring Apple and Google to verify the age of every app store user and to obtain parental consent before a minor downloads an app. Meta, X and Snap issued a joint statement welcoming it: parents want "a one-stop-shop to oversee and approve the many apps their teens want to download, and Utah has led the way in centralising it within a device's app store.56" Sixteen states had introduced comparable bills within months.55
Neither side of the resulting fight disputes its shape. Meta's public position is that app stores should check identification the way a liquor store does. Apple and Google's position is that they are the mall, not the liquor store. Apple's counter-proposal — a Declared Age Range API that hands developers a coarse age band rather than making the app store itself the verifier — is a dispute over precisely one question: who becomes the identity layer, and who merely queries it.
How that legislative wave was assembled is considerably less transparent. Bloomberg reported in July 2025 that Meta was helping to fund the Digital Childhood Alliance — the coalition of conservative child-safety groups that has been the most visible advocate for app-store age verification in state legislatures — citing three people familiar with the arrangement.57 Neither Meta nor the alliance confirmed the funding directly; Meta acknowledged only that it had "collaborated with" the group, whose executive director puts its membership at more than a hundred organisations. A Louisiana state senator has since pressed the alliance on its industry ties.
The structural incentive does not depend on any particular figure for what was spent. The obligation lands on the operating system; the benefit accrues to every app able to query it. Meta receives a verified age signal without building the verification system, maintaining it, or carrying the liability for holding the underlying identity data — while the compliance burden and the infrastructure cost sit with its two largest competitors. That is the arrangement, and it was argued for on the record.
The UK context is different in its legislative mechanism but identical in its structural logic. If biometric or government-linked identity becomes the authentication layer for access to digital services, whoever processes or federates that identity becomes critical national infrastructure. That is a more durable commercial position than social graphs or advertising revenue, both of which are eroding. Google and Meta do not need to remain your preferred platform. They need to be the layer your bank, your employer, your school, and your government trust. Age verification, framed as child protection, is the mechanism for achieving that position — and it is being built with taxpayer funding and parliamentary approval, by the very companies whose failure to protect children on their existing platforms created the political pressure for the legislation in the first place.
Digital sovereignty, properly understood, means individuals and institutions controlling their own data, their own infrastructure, and their own identity — with no single point of commercial or state revocation. Digital ID, as currently constructed, inverts every one of those principles. The state issues the credential. A private vendor processes it. The platform accepts or rejects it. The citizen is a passive participant in a system they do not control and cannot audit. That is not sovereignty. That is a permission system with government branding — and the companies writing the terms of that permission are the same ones regulation was supposed to constrain.
| Scheme | Who issues the credential | Who can sit in the verification path | Can the citizen see who used their identity? |
|---|---|---|---|
| United KingdomDigital verification services trust framework — in development | Government sets the framework; certification is performed by independent certifying bodies. | Certified providers, public or private sector, across identity, attribute, orchestration, holder and component roles. | No general facilityNo citizen-facing record of identity use is published as part of the framework. |
| EstoniaID-card, Mobile-ID, Smart-ID | The state, through the Police and Border Guard Board. | Predominantly state infrastructure; Smart-ID and Mobile-ID involve private operators. | YesThe Data Tracker on eesti.ee has let any eID holder review queries against their personal data since 2017. |
| IndiaAadhaar | The state, through UIDAI. | UIDAI, reached via authentication agencies that include private entities. | PartialUIDAI publishes authentication history covering the last six months, up to 50 records at a time. |
| AustraliamyID, formerly myGovID | The state, through the Australian Taxation Office. | Government-operated, alongside accredited providers under the national Digital ID system. | Not establishedNo equivalent citizen-facing usage log was identified in the public documentation. |
03 The Steam Case: The Action the Regulator Did Not Bring
The most significant challenge to platform pricing in the UK during this period was not brought by a regulator. It was brought by a private citizen. In June 2024, Vicki Shotbolt filed a collective action against Valve Corporation at the Competition Appeal Tribunal; the Tribunal certified it on 26 January 2026, on behalf of up to 14 million UK consumers, with damages provisionally estimated at up to £656m. It is a standalone claim under section 47B of the Competition Act 1998. There is no CMA decision behind it, because there is no CMA case.8
The substance is not Steam's commission rate, though it is frequently mischaracterised that way. The claim centres on Valve's alleged use of price parity obligations — wide Most Favoured Nation clauses that prevent developers and publishers from selling their games more cheaply on competing platforms. If a game is on Steam, the developer cannot offer it for less on GOG, Humble Bundle, or any other storefront. That locks the price floor at whatever Steam charges, regardless of any platform's commission rate, and denies competitors the one lever — price — that might let them attract publishers and build share.
The legal theory is coherent, and it is not a private invention. The CMA has a track record of scrutinising MFN clauses — it fined ComparetheMarket £17.9m in 2020 for similar practices in home insurance, though that decision was later overturned on appeal.12 A dominant platform using vertical restraints to entrench its position is textbook competition analysis. Which raises the obvious question: if the theory is sound and the conduct was visible for years, why did it take a campaigner and a litigation funder to put it in front of a tribunal?
That is the point, and it is a sharper one than the misreading it replaces. This is not a story about a regulator picking the wrong target. It is a story about enforcement happening around the framework rather than through it. The conduct was identified, the case was built, the class was certified — and the state's competition regulator was not party to any of it. Meanwhile the adjacent restriction at Apple and Google is anti-steering rather than price parity — developers restrained not from pricing lower elsewhere, but from telling users that cheaper options exist, which reaches much the same price the customer actually sees. The European Commission fined Apple €500m over those provisions under the Digital Markets Act in 2025. In the UK they sit inside conduct requirements still under consultation.9 A framework that depends on private claimants to reach conduct this visible is not a framework operating at capacity. It is one being substituted for.
The strongest objection to the selection argument is the CMA's mobile platforms work, and it deserves stating at full strength. Under the Digital Markets, Competition and Consumers Act 2024, the CMA opened Strategic Market Status investigations into Apple and Google in January 2025 and confirmed both designations on 22 October 2025 — covering their mobile operating systems, native app distribution, and browsers and browser engines. The regulator found substantial, entrenched market power and a position of strategic significance in each case. The designations run for five years.27 This is not a letter, and it is aimed squarely at the two companies this article argues have been left alone.
It does not, however, rescue the timeline or the mechanism. The DMCCA received Royal Assent eight years after the Investigatory Powers Act and five years after the Online Harms White Paper. Designation is not a remedy — it is permission to begin writing remedies, and the conduct requirements that will actually bind Apple and Google are still being consulted on, with the designated firms, after the CMA's own timetable slipped. The honest summary is not that the UK does nothing about Apple and Google. It is that nine years of legislative development produced a framework which, at the point of its first real domestic test, was still deciding what its rules would be — and which writes those rules in consultation with the firms whose conduct they govern. That is regulatory capacity capture operating exactly as the Internet Policy Review research describes it.
| Platform | The restriction | UK regulator action | Who did act, and with what result |
|---|---|---|---|
| ValveSteam | Wide MFN price parity obligations, alleged: a game on Steam cannot be sold more cheaply elsewhere. | NoneNo Competition Act investigation into Valve appears on the CMA case register. | A private claimant. Collective action certified by the Competition Appeal Tribunal in January 2026, up to 14m consumers, up to £656m. |
| AppleApp Store | Anti-steering, not price parity: developers restrained from telling users cheaper options exist. | DesignatedStrategic Market Status, October 2025. Conduct requirements still under consultation. | The European Commission — €500m under the Digital Markets Act, 2025. US courts struck down the provisions in Epic v Apple. |
| GooglePlay | Comparable steering and in-app payment restrictions. | DesignatedStrategic Market Status, October 2025. Conduct requirements still under consultation. | Obligations under the EU Digital Markets Act; litigation in the United States. |
| AmazonMarketplace | Price parity across Marketplace: sellers barred from listing lower prices on other channels. | Yes — 2012The OFT opened a formal investigation in October 2012. | Amazon ended the policy across the EU on 30 August 2013. The OFT then closed the case as no longer an administrative priority — no finding was ever made. |
04 The X Problem: A Live Test the Framework Failed
In the summer of 2024, the UK had the closest thing possible to a controlled experiment in platform regulation. The Southport stabbings triggered a wave of far-right disorder that spread across English cities. Extremist content, coordinated disinformation, and inflammatory commentary flooded social media. And X's owner, Elon Musk, posted directly into that environment: "Civil war is inevitable."
The UK government condemned the post. Prime Minister Starmer's spokesperson called it unjustified. The Technology Secretary described Musk as "accountable to no one."44 The DCMS urged platforms to act. And Ofcom — the regulator responsible for enforcing the Online Safety Act, the centrepiece of the UK's platform regulation programme — published an open letter asking platforms to please consider stopping the harm.
Ofcom could not take enforcement action. The Online Safety Act's illegal harms codes were not yet in force. The powers the government had been building since 2016, legislating since 2023, and implementing since then, were not operational at the moment they were most needed. A year later, research that led Ofcom to find a "clear connection" between social media posts on X and the eruption of the riots — and found that the same hateful content was still circulating with scant moderation.43
The framework's opening act was modest: the first financial penalty under the Online Safety Act went to 4chan in late 2025 — £20,000 for failing to respond to an Ofcom information request — followed by £50,000 against an AI "nudification" site operating without age checks. Nine years of legislative development produced a framework whose first act was a five-figure fine against a fringe imageboard.15
Enforcement has since escalated sharply, and the escalation deserves to be recorded accurately. In February 2026 Ofcom fined 8579 LLC, the operator of dozens of adult sites, £1.35m for failing to implement age verification — the largest penalty yet under that part of the regime19 — with a further £50,000 for withholding requested information and daily penalties accruing. In March 2026 it issued 4chan a further £520,000 across three breaches; 4chan has refused to pay.20 In May 2026 it fined the operator of a US-based suicide forum linked to more than 160 deaths £950,000 for failing to assess and mitigate the risk of UK users encountering illegal content.18 These are not trivial sums, and anyone arguing the Act has no teeth is no longer describing the record.
But look at what the teeth have closed on. Every one of those penalties landed on a pornography operator, an imageboard, or an unnamed forum — small, foreign-operated, legally manageable, and possessing no lobbying relationship with the British state. The platform with the greatest UK reach, whose owner amplified inflammatory content during the worst civil disorder in a generation, has been fined nothing. The pattern is not absence of enforcement. It is enforcement that reliably finds the targets least able to resist it.
The European Union's Digital Services Act, by comparison, opened formal proceedings against X in December 2023.22 The Commission issued preliminary findings of non-compliance in July 2024 — covering recommender systems, content moderation transparency, and verified account operation. The UK, in the same period, was consulting on codes of practice.23
This is the selection problem made precise. A platform whose owner amplified inflammatory content during active civil disorder, which had gutted its professional moderation infrastructure, and which the government's own ministers said was "accountable to no one" — faced a letter. A platform operating a contested but legally coherent price parity policy — faced a private claimant, because no regulator took it up. The regulatory energy is not merely insufficient. It is systematically misallocated relative to harm.
- October 2023Online Safety Act passedRoyal Assent. The illegal harms codes are not yet in force.
- July–August 2024Southport and the riotsDisorder across English cities. X's owner posts "civil war is inevitable".44
- August 2024Ofcom publishes an open letterNo enforcement power is available. The codes are not in force.
- March 2025Illegal harms codes come into forceSeven months after the disorder the Act becomes enforceable.
- Late 2025First penalties£20,000 against 4chan; £50,000 against an AI nudification site.
- January 2026Investigation into X openedOver Grok generating undressed images. Still unresolved. The standalone Grok service falls outside the Act.
- February–May 2026Penalties escalate£1.35m against 8579 LLC; a further £520,000 against 4chan; £950,000 against a suicide forum.
- December 2023Formal DSA proceedings opened against XTwo months after the UK's Act received Royal Assent, and eight months before the riots.
- July 2024Preliminary findings of non-complianceCovering recommender systems, moderation transparency and verified account operation — issued during the same summer as the UK disorder.
The obvious objection to this analysis is that enforcement frameworks require time. The OSA passed in October 2023; its illegal harms codes did not come into force until March 2025. Ofcom openly declared 2025 its "year of enforcement" and has since opened 21 investigations covering 69 sites and apps.21 You cannot fairly blame a regulator for failing to enforce a law that was not yet enforceable.
This is a reasonable point, but it is also a devastating one. The IPA was 2016. The Online Harms White Paper was 2019. The OSA was 2023. The illegal harms codes came into force in March 2025. Nine years elapsed between the government identifying the problem and possessing enforceable powers to address it — during which the platform landscape transformed, Musk acquired Twitter, dismantled its moderation infrastructure, and used it to amplify disorder during the worst civil unrest in a decade. The implementation timeline is not an excuse for the riot failure. It is precisely the indictment.
The second objection is that Ofcom is now moving, and that is true. But the test case is instructive. On 12 January 2026 Ofcom opened an investigation into X over the use of its Grok chatbot to generate undressed images of real people, including sexualised images of children. That investigation remains open, and X has since implemented measures. The revealing detail is what Ofcom told Parliament alongside it: it cannot investigate the standalone Grok service at all, because of how the Online Safety Act relates to chatbots.17 The Information Commissioner's Office opened its own parallel investigation in February 2026 precisely because the gap exists.
That is the indictment in its final form. Nine years of legislative development produced a framework which, confronted with the harm it was built to address, arriving through a technology that did not exist when drafting began, discovered that the harm sat outside its scope. The framework's credibility will be determined by what it does with X, not by the letter it sent in August 2024 — and on the current evidence the answer is that the most consequential part of the conduct is not something it is empowered to reach.
05 The Language of Sovereignty, the Practice of Dependency
Digital sovereignty is a legitimate policy objective. The argument for it is structurally sound: a country whose critical communications, identity systems, payment infrastructure, and public data flows are entirely dependent on foreign-controlled commercial platforms has a genuine national security exposure. This is not a fringe concern. It is why the EU has invested substantially in Gaia-X sovereign cloud infrastructure, why multiple governments examined Huawei's role in 5G networks with serious intent, and why European procurement frameworks are being redesigned to create conditions for domestically controlled alternatives.
But the UK is not pursuing digital sovereignty in any operationally meaningful sense. Foster's Lean Out named this structural pattern before it migrated into digital policy: sovereignty language, like inclusion language before it, functions as a legitimising frame for arrangements that serve existing concentrations of power. The UK is using the language of sovereignty to describe a policy programme that deepens platform dependency at every structural point, while performing the appearance of control through high-visibility enforcement actions that change very little.
Removing Advanced Data Protection does not advance digital sovereignty. It removes a citizen's ability to control who accesses their data. Digital ID processed by Meta and Google does not produce sovereign identity infrastructure. It makes foreign private companies the gatekeepers of national civic participation. Leaving platform pricing to private claimants while X faces a letter does not create a fairer digital market. And sovereignty at the national level requires something the UK has not built: open, auditable authentication infrastructure it actually controls, encryption it actively protects, and procurement rules that prevent critical identity systems from being outsourced to the companies regulation is supposed to constrain.
06 The Opportunity — With Honest Caveats
The European Union is building something substantively different. The Digital Markets Act creates binding interoperability obligations. GDPR enforcement has imposed real costs on extractive data practices. The AI Act establishes risk-stratified obligations that reward transparent, auditable systems. The direction is coherent in a way UK digital policy currently is not.
But the EU's execution deserves honest assessment. The Atlantic Council's 2026 review of European digital sovereignty concluded that Gaia-X — the flagship Franco-German effort to build a federated European sovereign cloud — has had limited success, producing mainly a series of standards and labels rather than a transformation of the commercial landscape.46 Mario Draghi's 2024 report on EU competitiveness effectively conceded defeat in this area, concluding that it is "too late for the EU to…develop systematic challengers to the major US cloud providers.47" Three US companies supply around 65% of the EU cloud market; EU-headquartered providers hold under 16%. Across digital products, services and infrastructure more broadly, the EU depends on non-EU suppliers for over 80%. European AI startups raised $12.8bn in venture funding in 2024, against $80.7bn in the United States.51 The gap is not narrowing.
None of this invalidates the market signal. IDC's Worldwide Digital Sovereignty Survey found around 30% of European organisations using sovereign cloud in 2023 and 2024; by 2025 that had risen to 40%, with a further 31% planning to adopt it.48 The stated motivations are the instructive part. The top three are exposure to extraterritorial data requests, compliance with European directives including NIS2, DORA, the Cyber Resilience Act and the AI Act, and baseline data privacy and security — in that order. Gartner expects worldwide sovereign cloud infrastructure spending to reach $80bn in 2026.50 Procurement frameworks increasingly reward providers that can demonstrate genuine data sovereignty and minimal external dependency. That is a real commercial opportunity regardless of whether Gaia-X delivered on its ambition — because the demand is growing even as the supply-side efforts have stumbled.
The companies best positioned to capitalise are those building for this demand: federated identity systems, portable data architectures, open protocols, auditable infrastructure, minimal-dependency deployment models. These properties are becoming commercially valuable in the EU market in a way they have not been historically. And the UK, under its current regulatory posture, is making itself a harder place to build that category of company — while doing almost nothing to address the infrastructure conditions that would make it easier.
The island of Ireland sits at a notable junction. Dublin has existing European tech infrastructure and direct EU regulatory proximity. Belfast has talent, cost base, and — through Northern Ireland's dual-market arrangements — access to both regulatory environments. The combined region could, with coherent policy intent, anchor a generation of sovereignty-aligned technology companies building for the market the EU's regulatory direction is creating. Whether Westminster's current trajectory makes that easier or harder is a question UK digital policy should be asking. It is not.
— What a Different Framework Would Look Like
This is not a partisan argument. The Investigatory Powers Act was Theresa May's. The Online Safety Act was Johnson's and Sunak's. The Digital Identity Trust Framework was designed across multiple Conservative administrations. Labour inherited all of it and continued without substantive revision. The failure is structural, not electoral.
It is also not an argument that the EU's approach is straightforwardly superior. Europe's regulatory density has concentrated markets rather than disrupted them. PwC's survey of 200 executives at US multinationals found 68% budgeting between $1m and $10m on GDPR readiness alone53 — a cost a large firm absorbs and a new entrant cannot, which is how compliance regimes tend to entrench the incumbents they were written to discipline. The EU has produced no cloud or foundation-model champion at US scale. Gaia-X did not become the sovereign cloud. The honest case for learning from the EU's direction is not that their execution has been clean, but that their regulatory environment creates conditions — interoperability obligations, data portability rights, meaningful enforcement — that reward the right kind of architecture even when the sovereign infrastructure projects themselves have disappointed.
Here, concretely, is what a different UK framework would look like — not as aspiration, but as three specific policy reversals:
First, protect encryption as a security baseline. Amend the Investigatory Powers Act to prohibit technical capability notices that require weakening end-to-end encryption in consumer cloud services. Use Apple's architecture as the mandatory floor — the standard others must meet — not a ceiling to be removed. Frame this explicitly as a national security measure, because it is: weakening encryption for state access weakens it for everyone else too.
Second, require open, auditable identity standards and prohibit single-vendor identity infrastructure for civic functions. Any identity layer used to access government services, healthcare, or financial products must be built on interoperable open standards with no single commercial point of failure or revocation. The specific standard exists: eIDAS 2.0, the EU's Digital Identity Wallet framework, is built on selective disclosure and zero-knowledge proofs, which allow age or identity to be verified without revealing the underlying personal data. Its reference implementation is open source, every member state must offer a certified wallet by the end of 2026, and its architecture gives no platform a persistent hold on the credential. The UK renewed its EU data adequacy decision in December 202552 — alignment with eIDAS 2.0 is technically feasible and politically available. Mandate it as the baseline before any commercial processor is approved for civic identity functions. Meta and Google may participate as verified nodes in that architecture. They may not own it.
Third, align enforcement with documented harm through statutory mechanism, not institutional preference. The OSA enables fines up to 10% of global revenue.2 The first penalty was £20,000. Introduce a statutory requirement that Ofcom publish an annual enforcement ratio report comparing each major platform's UK monthly active reach against enforcement actions taken and penalties issued. Make disproportionality visible and require the regulator to explain it publicly. That is not a guarantee of better enforcement — but it makes systematic misallocation accountable in a way it currently is not.
Sir Humphrey would recognise the current arrangement immediately. It has all the appearance of vigorous action: comprehensive legislation, expanding institutional capacity, a year-of-enforcement announcement, ongoing consultations. It has, in practice, produced a system in which the companies most in need of regulation are the ones designing the infrastructure the regulation depends on, and the framework's most significant test was met with a letter.
That is not a regulatory framework. That is an arrangement. And arrangements, unlike frameworks, tend to serve the people who made them — which in this case, more often than not, are the platforms the framework is supposed to constrain.
References and Sources
- Investigatory Powers Act 2016 (c.25). UK Parliament. ↩legislation.gov.uk/ukpga/2016/25
- Online Safety Act 2023 (c.50). UK Parliament. ↩legislation.gov.uk/ukpga/2023/50
- Digital Markets, Competition and Consumers Act 2024. UK Parliament.legislation.gov.uk/ukpga/2024/13
- UK Digital Identity and Attributes Trust Framework: Alpha v0.4 (2023). Dept. for Science, Innovation and Technology.gov.uk/government/collections/uk-digital-identity-and-attributes-trust-framework
- Regulation (EU) 2022/1925: Digital Markets Act. European Parliament and Council.eur-lex.europa.eu/eli/reg/2022/1925/oj
- Regulation (EU) 2022/2065: Digital Services Act. European Parliament and Council.eur-lex.europa.eu/eli/reg/2022/2065/oj
- Regulation (EU) 2016/679: General Data Protection Regulation.eur-lex.europa.eu/eli/reg/2016/679/oj
- CMA case register — no Competition Act investigation into Valve Corporation is listed. ↩gov.uk/cma-cases
- European Commission: Commission finds Apple and Meta in breach of the Digital Markets Act — Apple fined €500m for breaching the anti-steering obligation. 23 April 2025. ↩ec.europa.eu/commission/presscorner
- OFT: Amazon ends its Marketplace price parity policy across the EU, 30 August 2013, following a formal investigation opened in October 2012; the OFT closed the case as no longer an administrative priority, without a finding.
- CMA: Amazon — investigation into anti-competitive practices.gov.uk/cma-cases
- CMA: price comparison website — use of most favoured nation clauses (ComparetheMarket). Penalty of £17.9m, November 2020; set aside by the Competition Appeal Tribunal on appeal in 2022. ↩gov.uk/cma-cases
- Competition Appeal Tribunal Case No 1640/7/7/24: Vicki Shotbolt Class Representative Limited v Valve Corporation — standalone private collective action under s.47B Competition Act 1998, not a CMA enforcement case. Filed 4 June 2024; certified 26 January 2026.catribunal.org.uk
- Ofcom Enforcement Bulletin — Online Safety Act confirmed decisions (updated 2025).ofcom.org.uk/online-safety
- Ofcom: Confirmation Decision — 4chan. Fixed penalty £20,000. October 2025. National Law Review analysis. ↩ofcom.org.uk/online-safety
- Ofcom: Launch of investigation into X over Grok sexualised imagery. 12 January 2026.ofcom.org.uk
- Ofcom: Update on the investigation into X and the scope of the Online Safety Act — the standalone Grok service falls outside Ofcom’s remit. 2026. ↩ofcom.org.uk
- Ofcom: Fine of £950,000 against the provider of an online suicide forum. 13 May 2026. ↩ofcom.org.uk
- Ofcom: £1.35m penalty against 8579 LLC for age assurance failures, the largest to date. 23 February 2026. ↩uktech.news
- Ofcom: further £520,000 in penalties against 4chan across three breaches. 19 March 2026. ↩helpnetsecurity.com
- Ofcom: update on Online Safety Act investigations — 21 investigations covering 69 sites and apps. ↩ofcom.org.uk
- European Commission: Formal DSA proceedings against X. December 2023. ↩ec.europa.eu
- European Commission: Preliminary DSA findings against X. July 2024. ↩ec.europa.eu
- Irish Data Protection Commission: Meta Platforms Ireland — Final Decision, €1.2bn fine. May 2023.dataprotection.ie
- CMA: Apple’s mobile platform — Strategic Market Status investigation, final decision 22 October 2025. gov.uk/cma-cases/apples-mobile-platform
- CMA: Google’s mobile platform — Strategic Market Status investigation, final decision 22 October 2025. gov.uk/cma-cases/googles-mobile-platform
- CMA: Confirmation that Apple and Google have strategic market status in mobile platforms. October 2025. ↩gov.uk/government/news
- ICO Enforcement Register 2018-2024.ico.org.uk/action-weve-taken/enforcement
- K&L Gates: 2025 — Ofcom's Year of Enforcement. November 2024.klgates.com
- Apple: Advanced Data Protection — UK Withdrawal Statement. February 2025. ↩apple.com/newsroom
- Privacy International: Apple TCN challenge — complaints before the Investigatory Powers Tribunal on the lawfulness and secrecy of the technical capability notice regime. ↩privacyinternational.org
- Liberty: Liberty and Privacy International complaint against the Government’s "backdoor" access to Apple data to be heard by Tribunal. 2025. ↩libertyhumanrights.org.uk
- Investigatory Powers Tribunal, judgment of 7 April 2025 (Singh J and Johnson J) rejecting the Home Office application for blanket secrecy in Apple Inc. v Secretary of State for the Home Department; reported by Computer Weekly, which also confirmed the worldwide scope of the original notice from court documents. ↩
- Computer Weekly reporting on the Home Office’s replacement technical capability notice (autumn 2025), the US intervention of August 2025, and Apple’s fresh claim against the replacement notice filed in July 2026. (Publication blocks automated retrieval; verify in a browser.) ↩
- Apple: Platform Security Guide 2024.apple.com/privacy
- Lotame: The Impact of ATT on UK Advertisers, 2022. (Estimated $10bn Meta revenue impact, earnings calls Q2-Q4 2021.) ↩lotame.com
- Valve Corporation: Steam Revenue Share documentation.partner.steamgames.com
- Esports Legal News: Attack on Steam — £656m UK lawsuit analysis, MFN clause explanation. March 2026.esportslegal.news
- CREATe: Parity and Power — Steam's Antitrust Reckoning in Wolfire v. Valve. July 2025.create.ac.uk
- X Corp: Trust and Safety headcount reductions, Oct-Dec 2022. The Verge; Bloomberg; Reuters.
- Regulatory capacity capture: The United Kingdom's online safety regime. Internet Policy Review (peer-reviewed). ↩policyreview.info/articles/analysis/regulatory-capacity-capture-united-kingdoms-online-safety-regime
- ITIF: Comments before the UK CMA regarding Digital Markets Competition Regime — regulatory capture concerns. July 2024.itif.org
- CCDH / Ofcom: Research on social media content and 2024 UK riots. Byline Times July 2025. ↩bylinetimes.com
- CNBC: UK government response to Musk "civil war is inevitable" post; Ofcom unable to act. August 2024. ↩cnbc.com
- Fortune Europe: Musk "accountable to no one" — Technology Secretary Peter Kyle. August 2024.fortune.com
- Atlantic Council: Digital Sovereignty — Europe's Declaration of Independence. 14 January 2026. ↩atlanticcouncil.org/in-depth-research-reports/report/digital-sovereignty-europes-declaration-of-independence
- Draghi, M. (2024): The Future of European Competitiveness. European Commission. September 2024. ↩commission.europa.eu/topics/eu-competitiveness/draghi-report_en
- IDC: Digital Sovereignty in Europe in 2025 — Worldwide Digital Sovereignty Survey; sovereign cloud adoption at 40% of European organisations in 2025, a further 31% planning adoption. ↩idc.com
- IDC: European CISO priorities in 2026 — AI agents, platformization, and sovereignty.idc.com
- Gartner: worldwide sovereign cloud IaaS spending forecast to total $80bn in 2026. February 2026, as reported. ↩ciodive.com
- Dealroom, via TechCrunch: AI venture funding in 2024 — $12.8bn raised by European AI startups against $80.7bn in the United States. February 2025. ↩techcrunch.com
- European Commission renewal of the UK data adequacy decisions, 19 December 2025, extending adequacy to 27 December 2031. ↩hunton.com
- PwC: GDPR Preparedness Pulse Survey, 2017 — 200 CIOs, CISOs and other C-suite executives at US multinationals; 92% rated GDPR a top data-protection priority, 68% budgeted $1m–$10m on readiness and 9% over $10m. ↩pwc.com — GDPR Pulse Survey (PDF)
- InCountry: The EU's Data Sovereignty Framework — EuroStack 2025, cloud market statistics.incountry.com
- Utah SB 142: App Store Accountability Act (2025). Utah State Legislature. ↩le.utah.gov/~2025/bills/static/SB0142.html
- TechCrunch: New Utah law makes app stores responsible for age verification — includes the Meta, X and Snap joint statement. March 2025. ↩techcrunch.com
- Birnbaum, E.: Meta Clashes With Apple, Google Over Child Age Check Legislation. Bloomberg, July 2025 (syndicated) — Meta funding of the Digital Childhood Alliance, per three people familiar with the arrangement. ↩insurancejournal.com
- CNBC: Age-verification tools spread across US — persistent identity verification trajectory. March 2026.cnbc.com
- Biometric Update: Meta adopts k-ID OpenAge reusable age verification credential. December 2025.biometricupdate.com
- DCMS Select Committee: Online Safety and User Harm. Evidence Sessions 2021-2023.parliament.uk
- Zuboff, S. (2019). The Age of Surveillance Capitalism. Profile Books.
- Doctorow, C. (2023). The Internet Con: How to Seize the Means of Computation. Verso.
- Foster, D. (2016). Lean Out. Repeater Books. ↩
- Schneier, B. (2023). A Hacker's Mind. W.W. Norton.
- Floridi, L. (ed.) (2015). The Onlife Manifesto. Springer Open.
The views expressed are those of the author in a personal capacity. uRadical is an independent software consultancy.