Picture two enforcement letters leaving Ofcom's office.
The first goes to TikTok. It arrives at a London address, is read by an in-house legal team, escalated to a compliance function, and answered — because TikTok has offices that can be visited, executives who can be summoned, and UK revenue that can be fined up to ten per cent. Whatever you think of the company, the machinery of enforcement has something to grip.
The second letter is addressed to the operator of a Mastodon server. It needs to reach a volunteer — in Oregon, or Osaka, or a spare room in Jena — who runs a community of a few hundred people, funded by donations, administered after work. There is no legal team. There is no UK revenue. There is, in the sense the law understands, no there there.
One of these letters works. The government's teen internet rules — the curfew, the under-16 ban, the age checks — are written as though every platform receives the first kind. This piece is about everything that receives the second.
Federation, in plain English
If you have not met the fediverse: think of email. Nobody owns email. Your provider runs a server, mine runs another, and thousands of independent servers agree to speak a common language so that a message from one reaches any other. No single company can switch email off, change its rules, or answer a regulator's letter on its behalf.
Mastodon — and the wider fediverse it belongs to — is that model applied to social media. Thousands of independently run servers ("instances"), each with its own operator, its own rules and its own moderation culture, all speaking a shared protocol so their users can follow and message each other across servers. The non-profit that publishes the Mastodon software is a small German organisation; it makes the tool, but it no more controls the network than the authors of email software control your inbox. When the law asks "who is responsible for this platform?", the honest answer is: ten thousand different people, mostly volunteers, mostly elsewhere.
The law meets the volunteer
We do not need to guess how UK internet law lands on this world, because the Online Safety Act has already shown us — and the results should worry everyone who wants the teen rules to mean something.
Consider woof.group, a Mastodon instance that did what conscientious operators do: sat down and honestly assessed its OSA obligations. Around 740 active users, roughly one in eight of them British. Donation-funded, volunteer-run. Their conclusion, published in full, is a document I would put in front of any policymaker: the age assurance the Act demands would require paid third-party verification services, forking their software, and disabling federation itself — "essentially impossible" for a service of their kind, since even a perfectly compliant instance cannot verify the ages of users arriving through federation from the thousands of instances that check nothing. Their realistic options came down to blocking British users entirely, and they advised their UK members to export their data in case it came to that.
Now widen the lens. In March 2025, the day before OSA duties took effect, one volunteer operator shut down LFGSS and the Microcosm forum network — around three hundred British communities, some decades old, gone — because the compliance burden was not survivable for a person running community infrastructure as a labour of love. The cycling forums died. The hamster forum nearly did, and became a minor national story.
And 4chan — a site that has hosted some of the worst of the internet for twenty years? It ignored Ofcom entirely. The regulator fined it £520,000; its lawyers announced the fine would be "resisted in US federal court", framed the Act as extraterritorial censorship, and briefed the American administration, which has its own opinions about foreign regulators and American websites. As of this month, Ofcom is reduced to seeking American help to collect. Whatever happens in court, the lesson has been broadcast to every offshore operator: refusal is a viable strategy.
Put those three cases side by side and you get the enforcement inversion every security engineer eventually meets: a control that is only enforceable against the reachable punishes the conscientious and selects for the defiant. The British volunteer complies or dies. The American giant negotiates. The offshore recalcitrant ignores. The law's weight lands, with exquisite precision, on exactly the operators who were least of the problem.
What this means for the teen rules
Apply this to the ban and the curfew, and three consequences follow.
First, the ban list is a list of companies, and the fediverse isn't one. Bluesky is reportedly in scope — and Bluesky-the-company can indeed comply for the app it runs, though the open protocol beneath it is another matter. But Mastodon? There is no entity to serve, no revenue to fine, and — as woof.group demonstrated — no technical means by which even a willing instance could enforce age checks across a federated network. The rules will simply not run there.
Second, that gap sits directly downstream of the ban. Push millions of British teenagers off Instagram and TikTok next spring, and they do not evaporate; they go where the age checks aren't. Some will go to VPN-wrapped versions of the same apps, as part one predicted. Others will discover the federated and self-hosted world — which the law has, in effect, marked on the map for them as the unregulated zone.
Third — and this is the part I most want parents to hear — unregulated does not mean worse, but it absolutely does not mean safer. The mainstream platforms are imperfect, engineered for compulsion, and the subject of this entire series; they also employ thousands of trust-and-safety staff, scan for known child-abuse material, and answer subpoenas. A random fediverse instance is one volunteer with a moderation queue. Some instances are the best-governed communities on the internet — small, human-scale, genuinely cared for. Others are one absent admin away from being nobody's responsibility at all. The variance is the point: when your child moves from a platform you distrust to one you've never heard of, the risk hasn't gone — it has gone out of view.
Could federation be regulated at all?
Honestly? Not at the server layer. You cannot compel ten thousand volunteers in ninety jurisdictions, and attempting it produces only the inversion above. The workable pressure points are the same ones this series keeps arriving at: the device layer, where a parent-set age applies to every app and browser regardless of who operates the far end; and the app-store layer, where distribution of clients can be age-gated — imperfect, web access remains, but real friction at last. The government's plans currently use neither for the federated world. The honest position would be to say so: the ban will cover the mainstream, the fediverse will be beyond it, and the device in your child's hand is where the remaining line must be held.
What to do tonight, regardless
If your teenager mentions Mastodon, or an instance name you've never heard of, treat it exactly as you would a party at a house you don't know: ask whose house. Every instance has an about page listing its rules and its administrators — read it together; a well-run instance is proud of that page, and a shabby one is visible at a glance. Check whether direct messages and follows from strangers are open by default (the four-question audit from part two applies unchanged out here). And remember the variance rule: judge the instance, not the software — the same way you judge the house, not the street.
Next in the series: the dark routes — Tor, i2p, and what happens when there is no server to find at all.