On 1 September, England's Children's Commissioner sat down in front of a House of Lords committee and said the quiet part of this whole series out loud.
Giving evidence to the Communications and Digital Committee's inquiry into the Online Safety Act, Dame Rachel de Souza reported that the children she speaks to say the Act has made "absolutely no difference" to what they can reach online. That is the efficacy verdict part six predicted and part ten expected Britain to earn, now delivered not by a campaigner or a security architect with an axe to grind, but by the statutory advocate for the nation's children, to a select committee, on the record.
I could stop there and call it a modest, grim vindication. But the far more important thing she said is the part that should worry you whatever you think of the ban, because it is not about whether the law works. It is about whether anyone is allowed to find out.
"Pretty furious"
De Souza told the committee she could not properly judge the Act's efficacy at all, because Ofcom has refused to share the child-risk assessments the platforms are obliged to file — the documents in which each service sets out the harms it poses to children and what it proposes to do about them. She said she was, in her own word, "pretty furious" about it, and that she now intends to use the compulsion powers her own office holds to force disclosure that the regulator would not give voluntarily (MLex).
Sit with the shape of that. The single richest source of evidence about whether this regime protects children — the platforms' own accounts of the risks and the mitigations — exists. It has been collected. It sits in a filing cabinet at Ofcom. And the person Parliament appointed to speak for children cannot read it without threatening to subpoena her own government's regulator.
A law built to be unmarkable
Here is the structural point, and it is the one I want to leave you with, because it outlasts any single ruling or survey.
The evidence of whether the Online Safety Act works is confidential by design. Under section 393 of the Communications Act 2003, information Ofcom obtains about a particular business may not, as a rule, be disclosed while that business is trading — and breaching that duty is a criminal offence carrying up to two years in prison. There are exceptions, for Ofcom's own functions and for other authorities carrying out theirs, and the Commissioner will presumably argue her way through them. I want to be precise: no one has said Ofcom cited section 393 as its reason, and I am not claiming it did. The point is architectural, not forensic. The confidentiality is the default. The disclosure is the exception you have to fight for. We have built a child-safety regime in which the platforms mark their own homework, hand the marked paper to a regulator, and the regulator files it somewhere the public — and, until she raises the statutory stakes, the Children's Commissioner — is not permitted to see.
Compare that with the one part of this story where we did get to see the numbers. The reason part six could score the pornography age gate honestly — the VPN surge, the third of users who opted out on day one, the traffic that flowed to the sites that ignored the law — is that some of that data leaked out around the edges: providers boasting, a newspaper investigating, Ofcom's own opt-out figure surfacing. It was never handed over as a matter of course. When the state builds the machine and then classifies the diagnostics, the only efficacy data you get is the data someone was willing to volunteer or a journalist managed to prise loose. That is not accountability. That is marketing with a right of reply.
What I keep saying about controls
As a security architect I assess a control by two questions: what does it prevent, and what does it introduce. There is a third question underneath both, and it is the one this episode exposes: can you even measure it? A control whose effectiveness cannot be independently audited is not a control. It is a claim wearing a control's uniform. "Highly effective age assurance" is the term part ten told you to watch; the word doing the work in it is effective, and effectiveness is precisely the thing the regime has arranged to keep from the people asked to trust it. You cannot manage what you cannot measure, and you certainly cannot consent to it.
The other side, honestly
Confidentiality here is not simple villainy, and I will not pretend it is. A platform's risk assessment can contain genuinely sensitive material: the mechanics of its safety systems, the gaps an attacker would exploit, commercially valuable detail about how the service actually works. Publish all of it, unredacted, and you hand a manual to exactly the people who abuse children online. Section 393 exists for reasons that predate this row and are not disreputable. And Ofcom is a young regulator under enormous load, wary of being sued by companies with limitless legal budgets. None of that is stupid.
But notice what the reasonable case defends and what it does not. It defends keeping the raw assessments out of open publication. It does not defend refusing the Children's Commissioner — a fellow statutory office, bound by her own duties of confidence — a supervised look at whether the law is working. "We cannot show anyone, not even her, whether children are safer" is not a redaction policy. It is an accountability vacuum, and the fact that it takes compulsion powers to fill it is the story.
The pattern this completes
Regular readers will see where this sits. Part thirteen argued that nobody sought the public's consent before building the machine — that asked plainly, across every party, Britain said it would not trust the state with the keys to its private life. This is the same failure one turn further on. First they did not ask whether we agreed to it. Now they will not show us whether it works. Consent withheld at the front door; evidence withheld at the back. A government confident its regime protected children would be publishing the proof in bar charts. A government that answers "you are not cleared to know" has, without meaning to, reviewed its own policy for you.
What changes for you
For the household, nothing moves, and by now that is almost the running joke of this series: the advice at the foot of every instalment is the advice here. Keep doing the device-level things that travel with the child, and treat your identity documents as precious when any service asks you to prove your age, because whether that verification is working is, it turns out, none of your business.
For the argument, this is the accountability half of the case I have been making on the technical side all along. The law moves determined users out of reach at exactly the moment it moves the evidence out of reach — and asks for your trust in the same breath as it declines to earn it. Dame Rachel de Souza is right to be furious, and right to reach for her powers. I will be watching what those risk assessments say if she prises them loose, because a regime that has to be compelled by its own children's champion to reveal whether it protects children has already answered the more important question.
This is part fourteen of Regulating the Teen Internet. The companion to it is part thirteen, on the consent nobody sought; the practical, do-it-this-weekend guide for parents is part eight, and it stands whatever any regulator will or will not show you.