Regulation

The Ministry of Messages

Orwell gave us the vocabulary. Kafka drew the floor plan. On 15 July, Ofcom published the regulations.

Here is the short version, for the busy. Your telephone company will shortly be required by law to inspect the contents of your private text messages, check them against a list you will never see, and destroy the ones that match. Nobody has to tell you it happened. If the operator later works out it should not have done it, nobody has to deliver the message, and nobody has to have kept it. You are left with a right to challenge a decision you were never told about.

That reads like hyperbole. It is a summary. What follows is twelve pages, near enough, of receipts: rule numbers, paragraph references, and Ofcom's own words in Ofcom's own documents. The statement runs to 195 pages before you reach the separate guidance, the part that matters is buried in section 7, and the part that settles the argument is the legal instrument bolted on at the back, which is where I eventually found what this actually does. I make no apology for the length. If you read one section, make it the second.

On 15 July, Ofcom published its statement on combatting mobile messaging scams. I have read it, all of it, down to the legal instrument at the back, so that you do not have to, and I can report that somewhere in the drafting a perfectly sensible objective, namely fewer grandparents being fleeced by a fake parcel-delivery text, has been dressed up in the machinery of a surveillance state and sent out into the world with a straight face.

Regular readers will know two things about me. First, that I make my living in the dark compliance arts and have a weakness for a defined term, or, sometimes, for the wonderful world of the ordinary and natural meaning of an undefined one. Second, that I have said, repeatedly and at tedious length, that Ofcom is a child of Parliament. It does not wake up in the morning and decide to be sinister; it executes the will of a Government that would very much like to be seen to be Doing Something about fraud. So this is not a piece about a rogue quango. It is a piece about method, and about the quiet erosion of a principle that ought to survive contact with even the worthiest of causes.

Know Your Traffic

Let me start with the language, because Orwell would have. We already have KYC, Know Your Customer, which is sensible, and which we at Simwood do with rather more rigour than the rules demand. The statement now blesses us with a sequel, KYT, Know Your Traffic: an ongoing obligation to review account activity, monitor volume patterns, watch for new or unusual use of Sender IDs, and investigate what turns up.

I have no quarrel with any of that, and it is important to say why not. KYT attaches to A2P messaging only, the commercial channel, where businesses contract with providers to send appointment reminders and delivery updates. It is a duty about business traffic, it looks at behaviour, volumes, and patterns rather than at what anybody wrote, and we do it already. If the statement had stopped there, this would be a short and rather boring blog.

It does not stop there. There are two blocking duties in this statement, not one, and almost every summary I have read collapses them into each other. The difference between them is the whole point, so let me set them out precisely, from the instrument itself rather than the press release.

The envelope, not the letter

Here is the distinction that matters, and the one that keeps this blog honest. Everything Simwood does today to shun north of 5% of the calls on our network operates on behaviour and metadata. We look at invalid CLI, at dead-number ratios (our beloved UAP), at dialling patterns that no human hand produces, and at what our own systems flag when a suballocated number starts misbehaving. We look at the envelope, not the letter. We have never needed to steam open the correspondence to work out that something is a war-dialler.

Now watch the new rules draw exactly this distinction, and mandate both halves of it. A word on citation, because precision matters here and General Conditions are amended more often than anyone outside this trade would believe: everything I quote below is General Condition C9, as imposed by the Notification at Annex 1 to the 15 July statement. It is not yet in force and it is not what the General Conditions say today. GC C9.3(b) requires providers to block P2P messages sent from telephone numbers they reasonably believe have been used to scam. That is the envelope: who sent it, judged on intelligence about the sender. It is what a careful operator does, and I have no complaint. Then comes sub-paragraph (c), and I am going to quote it in full, because I want no argument about what it says. Providers must “block, via automated means and without undue delay, P2P Messages that contain URLs or Telephone Numbers which they reasonably believe were used as part of a Scam”.

Sit with the word contain for a moment. You cannot know what a message contains without inspecting its contents. All of them, every message, every time, because the offending URL could be anywhere in it. And note the channel. P2P. Person-to-person. The instrument defines it as “a message sent from one SIM to another”, which is to say the text you send your mother. The commercial channel gets the mirror-image duty at GC C9.7. Private correspondence is not the exception to this regime. It is half of it, and, as we shall see, the half that arrives first.

I can hear the answer, so let me make it for them, because it is the best one they have. This is not really reading. Ofcom itself describes what it mandates as, in effect, an exact database matching tool: a lookup against known scam URLs and numbers, with no human required to read anything and no machine interpreting your prose. That is true. It is narrower than the worst thing I could have accused them of, and I am not going to pretend otherwise. It is also beside the point. To find a URL in a message you must parse the message. The narrowness is in what the machine is looking for, not in what it opens. Every envelope is still slit. The clerk simply has a short list and no curiosity.

And Ofcom knows the clerks are already curious, because it says so in the plainest sentence in either document. The guidance states that these are minimum measures, that providers may go further, and that going further expressly includes monitoring messages nobody has reported at all, on probabilistic rules, hunting for anything that looks suspicious. Our rules, it says, neither require nor prevent this. It adds, correctly, that such monitoring is likely to be more intrusive. Then it moves on. The mandate sets the floor. The ceiling is left precisely where it was, and Ofcom has written down that it is leaving it there.

And I know exactly what comes next, because it is what always comes next: if the industry is already doing this, what precisely is your complaint? Three things. Industry practice is not a legal justification, which we put to Ofcom in January in rather blunter terms than that, and which I return to below. What was the practice of some is now the duty of all, including providers who until this moment have only ever looked at the envelope. And whatever the tooling, a regime whose transmission guarantee has been watered down and whose notification duty has been deleted outright is a different animal from one where neither was ever on the table. Narrow tooling does not make a wide mandate narrow.

Mum, it's a scam

Let me make this concrete, because the abstraction flatters it. You text your mother: Mum, whatever you do, do not ring 0330 123 4567, it is a scam. That number is on the list, as by definition it would be, or you would not be warning her about it. Your message therefore contains a telephone number reasonably believed to have been used as part of a scam. C9.3(c) is satisfied. Blocked, by automated means, without undue delay.

Your intention has nothing to do with it, and that is a drafting choice rather than an oversight. Sub-paragraphs (a) and (b) of the same condition both turn on messages intended to Scam the intended recipients; the words are right there on the page. Sub-paragraph (c) carries no such qualifier. The intent test attaches to the number's history, not to your message. And the tool Ofcom has specified, an exact database match, is by design incapable of noticing the word not.

Now, before anyone tells you this is a clever gotcha that Ofcom never considered, it is not, and I want to give them full credit, because the passage is buried in Annex 4 where almost nobody will look. Ofcom sets out the scenario in terms: an individual may copy a scam URL or telephone number to send to a friend, to warn them about a scam. It accepts the message may be blocked. It accepts, expressly, that this interferes with the right to freedom of expression. They saw it coming.

It is the answer that should stop you. Having accepted that your warning will be destroyed, Ofcom reasons that this should not much matter, because the actual scam message containing that same number would also be blocked, so your mother is protected anyway. The warning is redundant, because the danger has already been dealt with.

Hold that against what Ofcom wrote back near the front of the same document, in its own account of how these crimes actually work. The scammer makes first contact by text, and then, in Ofcom's words, may ask the victim to communicate with them using an online messaging app such as WhatsApp or Facebook Messenger. Those are number-independent services. They live under the Online Safety Act, not the Communications Act, and nothing whatsoever in this statement reaches them. So the redundancy argument holds inside one channel only, and Ofcom's own description of the crime has the criminal leaving that channel at the second step.

Follow it all the way through, with your mother rather than with a defined term. The approach comes at her on Facebook, or on WhatsApp, or by email, or as a voice call from the very number you were trying to warn her about, because it is a telephone number and telephone numbers are for ringing. In none of those places has anything been blocked. In none of them does the protection Ofcom is relying on exist at all. The one channel where the danger was neutralised is the one channel where your warning was destroyed, and it was destroyed precisely because it named the danger accurately.

That is the shape of it. The blocking works where the criminal has already gone. The silence works where your mother still is.

And the guidance goes further than the statement let on, so let me put that on the table too. Buried among the validation steps, operators are asked to consider whether and how it may be possible to identify messages where an individual copies a scam URL or telephone number to send to a friend, to warn them about a scam. They are also invited to consider quarantining messages they cannot confidently classify either way, holding them back so somebody can look before anything is destroyed. That is a real thought, properly had, and I would rather credit it than pretend it is not there.

Now read the verbs. Providers must block, via automated means, without undue delay. Providers should consider whether and how it may be possible to spot a warning. One of those is a duty and the other is an invitation to have a think, and both are pointed at the very same message. The only other protection on offer is the one I mentioned a moment ago: take appropriate steps to ensure the end-user's number is not blocked. The number, not the message. Nobody, anywhere, is told to deliver the warning.

And that is the pattern, once you have seen it. What binds is the Notification at the back, and nothing else. Every acknowledgement that this might go wrong, every mitigation, every reassurance that somebody will be thinking carefully, lives in the reasoning or in the guidance, which is to say outside the only text a tribunal would be reading. The duty to block is in the rule. The care is in the commentary.

And two paragraphs before that, the same annex says something which cannot stand beside it. Blocking messages that contain scam URLs or telephone numbers, Ofcom says, does not engage Article 10 at all. Then, two paragraphs later, the warning message, which contains a scam telephone number, is blocked and does interfere with freedom of expression. Same annex, same measure, same morning. They cannot both be right, and the reason they collide is the drafting gap I have already described: because sub-paragraph (c) never asks about intent, the category it creates holds scams and warnings alike, while the rights analysis treats it as though it held only scams.

Whether your destroyed warning even counts as a False Positive is, at best, unclear. The defined term speaks of a message incorrectly identified and blocked on the basis the provider reasonably believed it was intended to scam the recipient, which is a belief sub-paragraph (c) neither requires nor forms. Annex 4 plainly assumes warnings are caught by the false positive machinery, and I hope it is right, because a great deal rests on it. But the definition does not say so, and the definition is what a compliance team will read.

So run the sequence, on either reading. Blocked automatically. Not notified, because that duty was lobbied away. No duty to deliver it once anyone works out what happened, and no duty even to keep it, since Ofcom confirms providers need not retain blocked messages at all. And a right to challenge which you will never exercise, because you do not know there is anything to challenge.

And note that all of this is the mandated floor working exactly as designed, with an accurate list and a correct match. Now consider the ceiling, which nobody regulates. Ofcom's own footnote records that operators already review messages against a broad set of scam indicators, including phrases such as “Hi Mum”, and observes, correctly, that such probabilistic methods are by their nature less precise and produce more false positives. Ofcom neither requires this nor forbids it. It is also, and I feel faintly ridiculous having to write this down, the most ordinary way in the English language to begin a message to your mother.

So there are two layers here, and they fail in opposite directions. The mandated one blocks you warning your mother about a scam, and does so correctly. The unmandated one blocks your child saying hello, and does so incorrectly. Neither of you is told about either.

If you think I am overreading the instrument, take it from its author. Ofcom's Article 8 assessment of these measures, the P2P measures, not the business ones, accepts that they may interfere with the right to privacy, because we expect mobile operators will need to use technology to review the content of private messages. The next paragraph lists the possible harms, and one of them, in Ofcom's own words, is unwarranted surveillance. Their phrase. Their document. Their rules.

And one more detail from the scope provisions, the one that moves this piece from commentary to confession. The content-blocking duty does not fall on “the MNOs”. GC C9.1 applies it to any communications provider that transfers or terminates P2P messages. That includes us. The company whose entire pitch, in this very blog, is that we look at the envelope and have never needed to steam open the correspondence, will from 18 January 2027 be required by law to open it. I am not describing something other people will do to you. I am describing something we will be conscripted to do to you, on pain of enforcement, and I would rather tell you that plainly now than have you discover it later and wonder why I did not.

What Ofcom removed, and who asked for it

If content inspection were the whole of it, I could almost live with it, because a careful operator can do careful things. What I cannot live with is what happened between the consultation and the statement, and who asked for it.

Ofcom consulted on two safeguards, and their reach was the reach of the blocking itself: both attached to automated blocking under GCs C9.3(b), C9.3(c), and C9.7, private and commercial alike. The first was a duty on providers to take steps to stop legitimate messages being caught in their own blocking tools. The second was a duty to tell senders when a message had been blocked. Both are gone.

On the first, the objectors are a roll-call: BT, Sky, Virgin Media O2, VodafoneThree, Mobile UK, and UKCTA. The arguments were that no failure to deliver legitimate messages had been demonstrated, that operators already have every commercial incentive to deliver, and that a duty to carry sitting alongside a duty to block would leave operators walking a tightrope with a penalty waiting on either side. BT went furthest, and said Ofcom was attempting to offload its own Human Rights Act duty onto private operators. Ofcom agreed. An up-front duty to get legitimate messages through became an after-the-fact duty to identify, monitor, and address erroneous blocking.

Orwell's real subject was never the surveillance. It was the language that makes surveillance sayable. He wrote that the great enemy of clear writing is insincerity, and that when there is a gap between what you are doing and what you are prepared to say you are doing, you reach instinctively for the longer word. So read the two formulations again. Ensure the transmission of legitimate messages: six words, every one of them concrete, and you know on reading it who owes what to whom. Identify, monitor, and address instances where messages are blocked in error: longer, softer, and nobody owes you anything. The first is a promise. The second is a process. The same people wrote both, about the same problem, within nine months.

That replacement is a real obligation and I will not pretend otherwise. But look at what it does not do. Where an operator discovers that it destroyed your lawful message in error, Ofcom does not expect it to then deliver the message. The stated reason is that doing so could cause confusion. So the remedy for having your correspondence wrongly destroyed is that the operator performs a root cause analysis and tries not to do it to somebody else. Restoration is not forbidden, to be fair: a provider may unblock where appropriate, Ofcom says, for example following a challenge under GC C9.17. Which is to say the route back for your wrongly destroyed message runs through the challenge you were never told you had grounds to raise. Failing that, you are invited to use some other means of communication.

There is a word for a message that is destroyed, whose contents are nowhere preserved, and which is not restored even once the destruction is admitted to have been a mistake. He gave us that one as well. The memory hole was never a device of malice. It was a device of tidiness.

On the second, the same names. BT, Sky, Virgin Media O2, and VodafoneThree all told Ofcom that notification would be disproportionate, because most blocked messages are scams anyway. I will give the tipping-off argument its due, because it is a real one, and because it is ours as much as theirs: tell a sender their message was blocked and you have handed the scrotes a Haynes manual on bypassing the block, complete with torque settings and an exploded diagram. It is precisely why we publish what we block without publishing how we decide. Had that been the whole of it, I would not be writing this section. But BT also costed it, and told Ofcom that a notification duty would add to its termination payments, and that other providers might drive up notification volumes to harvest the revenue. Note what it costed. Its estimate was framed for P2P messages alone. So the inter-operator payments argument that helped see off the safeguard was costed against private correspondence between individuals, and the safeguard died for both channels.

And then there is the evidence. An earlier draft of this said we were not shown it. That was wrong, and the truth is worse. Ofcom went back to providers in May and asked how often they block legitimate messages by mistake. The providers reported that they hardly ever do: somewhere between never and about once a month. On that basis, Ofcom decided a duty to tell you was not worth the candle.

Now read Ofcom's own footnote to that evidence. The figures are largely built out of complaints. No provider actually measures how often it wrongly blocks. And the rates may be under-reported, because users may not have known their message was blocked, or may not have bothered to complain.

Then read what Ofcom tells operators about hunting for false positives. They must not rely on complaints and challenges as their main method, because the number of challenges they receive may not reflect how much wrongful blocking is actually going on. They should expect to miss it on P2P in particular, for two reasons Ofcom sets out itself: end-users may not know a message was blocked, and they are in any event less likely than business senders to challenge it. Which is to say the regime knows its blind spot is deepest over private correspondence, and shallowest over the commercial traffic that has a contract and a service manager.

So Ofcom knows that complaints do not measure wrongful blocking. It says so, in terms, and writes a General Condition on the strength of it. It then uses complaint-derived data to conclude that wrongful blocking is too rare to be worth telling anyone about. The evidence that nobody complains has been used to remove the mechanism by which anyone would know to complain.

Doublethink was the term for holding two contradictory beliefs at once and accepting both of them. It was not offered as a figure of speech. It was offered as a technique. One paragraph knows that complaints do not measure wrongful blocking. Another counts the complaints and concludes that there is not much wrongful blocking. The two have never met. Both were published on the same morning, over the same name, in the same document.

So here is the finished article. Your lawful message may be inspected, it may be silently binned, nobody is obliged to tell you, and if the operator later works out that it should not have binned it, nobody is obliged to deliver it. The burden falls on you, the wrongly-blocked, to notice the silence, deduce that you have been blocked, and invoke your shiny new right to challenge a decision you were never told about. That is not a safeguard. That is Kafka with a message centre. We publish Call Quality Reports so that our customers can see what we are blocking for them. We do not publish how we decide, for the reason I gave earlier, and there is all the difference in the world between telling you a thing happened and handing over the workshop notes. Ofcom has arrived at the opposite instinct on both counts: keep the method to yourself, and do not mention that it happened either.

The cohort nobody asked about

Then there are the volume limits on pay-as-you-go SIMs, which sit in the P2P rules and bite on private messaging only. Here I must declare an interest in my own back catalogue. We told Ofcom, in writing, that we saw no issue with frustrating the bulk sending of P2P messages from PAYG SIMs, and that it was a sensible ex-ante measure at the point of entry rather than an ex-post criminal matter about the possession of equipment. I have not changed my mind. A bot firing thousands of texts an hour is not a person wishing their nan a happy birthday.

So this is not an objection to volume limits. It is an objection to a question Ofcom did not ask.

The rule bites on PAYG and on nobody else. Ofcom says so expressly: pay monthly users will not be constrained, because contracts, credit checks, and billing details make it harder for a criminal to acquire those SIMs in bulk. That is sound as far as it goes. But note why the two cohorts differ in the first place, on Ofcom's own account at the front of its statement: operators do not apply the same level of credit or identity checking to PAYG as they do to a contract. The line Ofcom has drawn is, substantially, a credit line.

Now turn to Annex 3, where Ofcom discharges its duty to have regard to the needs of, among others, persons on low incomes. Its conclusion is that it has not identified any adverse impacts on specific groups of persons likely to be affected in a different way to the general population.

I am afraid it has. A rule that applies to one tariff cohort and expressly not to the other affects that cohort in a different way to the general population. That is what the word only does. Whether the effect is material is a perfectly fair question, and the answer may well be hardly at all. But Ofcom did not ask it. It looked at a measure that bites on prepay and on nothing else, and recorded that it had found no differential impact on anybody.

It matters more than it looks, because Ofcom is not setting the limit. Each operator sets its own, on its own evidence, at whatever level it judges will disrupt scammers without stopping legitimate use. I have no quarrel with that in principle; operators know their own traffic, and a regulator picking a national number would be worse. But the consequence is that how many texts a prepay customer may send before the network stops them is now a commercial judgement, made by the operator, reviewed by nobody in particular, and applied to the one group of customers who did not, or could not, pass a credit check. That deserved a paragraph in the equality assessment. It got a line saying there was nothing to see.

And here is a question the statement never asks, which I will leave hanging because it deserves a proper answer rather than a paragraph. A great many pay-as-you-go propositions are sold on unlimited texts. That word is not Ofcom's to define: the advertising rules permit an unlimited claim only where the user suffers no additional charge and no suspension of service for exceeding a threshold, where any provider-imposed limitation is moderate, and where it is clearly explained in the marketing communication itself. Last year the ASA told EE that even a fair usage policy almost nobody ever hits is still a limitation, and still has to be spelled out. Ofcom has now required every operator to impose a hard cap on how many texts a prepay customer may send, and set it themselves. Advertising appears in this statement only as something fraudsters do; how these caps sit with what the operators' own marketing promises is nowhere considered. Somebody's marketing department is going to have an interesting fourth quarter.

The one definition they would not give

My favourite touch, and I say this as a connoisseur, is the treatment of RCS. Faced with the question of whether RCS falls under the Communications Act or the Online Safety Act, Ofcom has decided that operators are best placed to assess this in the first instance. A regulator that loves a definition almost as much as I do has, on the single question where a definition would actually help, declined to supply one and handed the parcel to the very people it regulates. Marvellous.

The shrug matters more than the joke, because that boundary is the boundary of everything in this statement. Number-based services, SMS and MMS, are regulated under the Communications Act, which is where all of this lives. Number-independent services, WhatsApp, Facebook Messenger, iMessage, are not, and Ofcom says so plainly: they use functionality that does not depend on telephone numbers, so they fall outside the Act. RCS sits on the fence. Which is precisely why nobody would define it.

The half they can reach

So hold that boundary in your head, and then read Ofcom's own account of how these scams actually work. A scammer makes first contact by SMS, and then, in Ofcom's words, may ask the victim to communicate with them using an online messaging app such as WhatsApp or Facebook Messenger. That is not my speculation about what criminals might do once the pipes are watched. It is the regulator's own description of the standard journey, and the second leg of it lies outside the scope of every rule that follows.

Now look at the number doing the heavy lifting at the front of the statement. Forty per cent of UK mobile users report having received at least one suspicious message in the past three months. It is an alarming figure and I do not dispute it. But read the footnote under it. Suspicious messages there means messages arriving in the phone's default messaging app, which is to say via SMS, RCS, and iMessage. iMessage is out of scope. The harm has been measured across a wider set of channels than the remedy can reach, and nobody closes the gap between the two.

And here is the thing I went looking for. Ofcom does think about displacement, once, and the once is instructive. Utility Warehouse warned that capping pay-as-you-go would simply push the scammers onto pay monthly SIMs. Ofcom's answer is genuinely good: it will not, because acquiring pay monthly SIMs at scale is hard. The contracts, the credit checks, the billing details. Displacement, in other words, is defeated by acquisition barriers, and by nothing else. Hold on to that, because it is the only displacement analysis in the document, and it cuts the other way the moment you step over the fence.

Because the industry asked the over-the-fence question too. VodafoneThree and Utility Warehouse told Ofcom, in terms, that increased regulation of A2P messaging risks displacing fraud to other platforms. The statement records the concern, turns to the question of costs, and never comes back to it. I have looked for the answer and I cannot find one. So the one analysis we do have says scammers move unless the next channel is hard to get into, and the next channel here is WhatsApp, whose acquisition barrier is an app store and thirty seconds. On Ofcom's own reasoning, we know exactly where the traffic goes. Nobody has asked what the apparatus is worth once it has gone there.

Consider who can move and who cannot. A criminal enterprise can shift from SMS to an encrypted app for nothing, over an afternoon, and it has every incentive to. We have watched scrotitude migrate from carrier to carrier for thirty years, and it remains remarkably light on its feet. The people who cannot move are the ones for whom SMS simply is the messaging service: no smartphone, no data allowance, no app, or no inclination. They are, and this is not a coincidence, the same cohort we met earlier, the prepay customers whose volume limits nobody thought to assess for differential impact. So the apparatus is built on the one channel the least equipped cannot leave, to catch people who can leave for free, and it will still be running long after they have gone.

Let me forestall the obvious rejoinder, because I can hear it coming. I am not asking Ofcom to extend any of this to WhatsApp, and I would fight it if it tried. My point is the reverse. When a remedy can only reach half the problem, and the half it reaches is the half where the intrusion is deepest and the escape is cheapest, that is the strongest argument yet that this balance was never Ofcom's to strike. A sectoral regulator can only act inside its own statute, so it acts where its statute reaches, whether or not that is where the harm will be tomorrow. Parliament can look at the whole landscape at once, weigh the intrusion against the displacement, and decide whether the trade is worth making at all. Which is exactly what we told Ofcom in January.

Surveillance, outsourced

And here is the part that should trouble you whatever you make of the rest. Strip away the packaging and this is state-sanctioned, private-sector surveillance of private correspondence, at national scale, and I can find no politer word for it than vile.

Consider what the state itself may not do. It cannot read your post, or listen to your calls, on a whim. When it wants the content of your communications it must go through the Investigatory Powers Act: a warrant, a threshold, a Secretary of State, independent oversight, and a judge. That architecture exists precisely because reading a citizen's correspondence is understood to be one of the gravest things a state can do to its people, so it is fenced about with safeguards.

This statement reaches the same intrusion and quietly steps around every one of those fences. It does not have the state read your messages. It conscripts your telephone company to do it, continuously, on everything, with no warrant, no suspicion, no oversight of the list your words are being checked against, and no judge within a mile of it. You get the intrusion of state interception, delivered with none of the discipline of state interception, and dressed up as consumer protection. Worse, the private conscript has every commercial incentive to over-block. The duty to carry your lawful message was struck out at the industry's request, what replaced it does not oblige anyone to deliver a message they have worked out they wrongly destroyed, and no one has to tell you that any of it happened. All of the snooping, none of the due process, and a Terms of Service where a warrant used to be.

I am not the only one uneasy about this, and I am nowhere near the shrillest. Amnesty International UK responded, and I should say plainly that they are more relaxed about the scanning than I am. They told Ofcom that mandatory scanning is rightly confined to a closed list, and that they did not find the proposals excessively problematic, in part because number-based messaging like SMS already carries low expectations of privacy, given the legacy constraints and the mandatory law-enforcement access built into these systems long ago. They are quite right that this is how it is. I would only say, as we said to Ofcom in January, that the length of time a thing has been done is not an argument that it ought to be. The envelope has been opened for thirty years. Thirty years of opening it has never once been a reason.

What Amnesty was worried about is the part I am worried about, and they got there before me. That the industry-standard filter already advertises AI and pattern analysis rather than the list Ofcom mandates. That the consultation nowhere discusses how any of this sits alongside the surveillance and intelligence powers we already have. That the new mandatory datasets could open fresh vectors for surveillance under bulk powers. And, in terms, that the infrastructure once built could be turned by the security services on URLs and numbers with nothing to do with scams, a point they thought worth making out loud given where this country currently sits on protest and dissent. United Nations experts got a mention. Their central recommendation was that Ofcom should not lean on generic data protection rules, and should define the purpose limits properly, because generic compliance with GDPR is not enough in 2026.

Ofcom's answer, in substance, is that it consulted the Information Commissioner and is satisfied the measures can be implemented in accordance with data protection law. Told that generic data protection would not hold the line, it confirmed that generic data protection was satisfied.

We should be very slow indeed to build this, because machinery outlives the intentions of the people who commission it. A tool built to catch a fake bank text is, mechanically, a tool that reads everyone's texts and drops the ones on a list. Change the list, and you change the target, and the second change is a great deal quieter than the first. We asked ourselves, in Are we evil?, whether we should wield rather less power than this. It is telling that Ofcom has mandated rather more, and asked itself rather less.

Made by no one you elected

Which brings me back to where I always seem to end up. None of this arrives as an Act, debated by people you can vote out. It arrives as guidance and General Conditions, drafted by an unelected regulator, which the industry will treat as law because the alternative is enforcement. I have written before of my fondness for the quaint American notion that lawmaking belongs to those closest to the People, and for the older instinct that it should be kept out of the hands of arbitrary decision-making by unelected nobles. You do not have to be a card-carrying libertarian to feel the hair on your neck rise when the power to inspect, and to silently suppress, private correspondence is created in this way, for the best of reasons, with the safeguards filed off somewhere between the consultation and the statement.

And I did not merely feel it, we filed it. Our response to this consultation, dated 28 January, told Ofcom that the balancing of over-blocking against fraud against invasion of privacy is a matter for an elected Parliament and not a sectoral regulator, and that the mere fact of today's industry practice proves neither that privacy rights have been upheld nor that what happens today is lawful. Ofcom's published answer to the first point runs to a single paragraph, and I will summarise it fairly: Ofcom has various duties relating to telephone numbers, including specific powers to make rules about mobile messaging, and it took them into account. That is a competent answer to the question are you allowed to. It is not an answer to the question should this be you. The second point, that industry practice is not proof of lawfulness, is recorded in the statement and answered nowhere, while the argument it was aimed at survives intact and is deployed more than once in support of the finished rules.

And look at who did the asking. Of the three mobile networks left in this country, Virgin Media O2 is owned outright by a Denver-run holding company incorporated in Bermuda and by Telefónica of Spain, behind which sit the Spanish state and Saudi Telecom. BT and Vodafone are British-incorporated, British-listed, and British-run, and their largest shareholders are an Indian conglomerate and, until last week, Abu Dhabi's state telecoms company. Sky, which is not a network at all but rides on Virgin Media O2, belongs to Comcast of Philadelphia. And VodafoneThree, our largest network, is forty-nine percent owned by CK Hutchison of Hong Kong until the sale to Vodafone completes later this year.

Hold that last one, because it is the most instructive thing I can offer you. When Li Ka-shing's conglomerate proposed to take a minority stake in a British mobile network, the machinery of the British state woke up. Two years of scrutiny. A review under the National Security and Investment Act. A Secretary of State. Binding mitigations, including a national security committee inside the merged company. Debates in the Commons. That is what it looks like when this country decides that something touches its interests: an Act, a Minister, and somebody you can hold to it.

Now count what it took to decide that those same networks may read the content of your correspondence and bin it without telling you. One consultation, one regulator, and one paragraph in reply when we asked whether it should be Parliament's call at all. We will spend two years deciding whether a Hong Kong billionaire may own half a network. We will spend an afternoon deciding what the network may read.

A floor is not a safe harbour

One more thing before I sum up, briefly, because it belongs in a different piece and I intend to write that piece. The record-keeping conditions require providers to keep false positive records for at least two years, challenge correspondence for at least one, and KYC and KYT material for at least three after the relationship ends. Note the words at least. Those are floors. I already suspect some will file them as ceilings, delete on schedule, and feel diligent about it.

Because here is what sits on the other side of the ledger. Under section 104 of the Act, the obligation to comply with a General Condition is a duty owed to every person who may be affected by a contravention, and a breach of that duty which causes someone loss is actionable by them. There are gates on it, and I will not pretend otherwise: Ofcom's consent is required, and a provider that took all reasonable steps and exercised all due diligence has a defence. But the ordinary limitation period for a claim of that kind is six years, and nothing puts an equivalent long-stop on Ofcom's own enforcement, which is administrative and not an action under the Limitation Act at all.

So line the numbers up. Two years of records. Six years of civil exposure. No outer limit on the regulator. And no requirement to retain the blocked message itself, which Ofcom confirms and justifies on data minimisation grounds. Add the missing notification, and the person who was wrongly blocked may not discover it for years, if ever, so their clock starts long after everyone's evidence has been lawfully shredded.

Which leaves the operator somewhere genuinely uncomfortable, and this is the part that ought to concentrate a few minds in compliance departments. You will be told what to keep and for how long. You will be told you need not keep the message. And you may then be asked, years later, to account for a decision you no longer hold the evidence to defend. Complying with the minimum is not a defence. It is simply a tidier way of having nothing to say for yourself. That deserves a piece of its own, and it will get one.

To be clear

Let me be unambiguous, because I fully expect to take fire from both directions for this, and I would rather choose the words that get misquoted. The scrotes will wave this blog about as cover for carrying on regardless, and the virtue-signalling luvvies who cheerlead every draconian intervention going will brand me an apologist for fraud. Both will quote me selectively, and neither will be right. Fraud is real, it does grievous harm, and stopping it is both the will of Parliament and a matter of basic decency. We do not need Ofcom to tell us to fight it; we jettison revenue every month doing exactly that, and we would happily do more if the rest of the industry would stop talking and start acting. My objection is not to the mission. It is to a design that deputises private companies, ours now among them, to read the content of lawful messages, block them in silence, with the duty to carry the legitimate ones traded away on request and nobody told when they are dropped, all of it authored by a body that no one elected.

Get those five things right and I will be first in the queue to help. Get them wrong, and this statement will be remembered less for the scams it stopped than for the precedent it set.

One last thing, and it is the tell. The rules come into force in two waves. The A2P rules, the ones about commercial messaging sent by businesses that can be identified, contracted with, and held to account, are given twelve months, and bite on 15 July 2027. The P2P rules, the ones that reach into private correspondence between individuals, are given six, and bite on 18 January 2027. Whatever the operational logic, the effect is that the more intrusive half arrives first and gets half the time to prepare. There is still time to do this properly.

Source: Ofcom, Statement: Combatting mobile messaging scams, 15 July 2026. All General Conditions cited in this piece are General Condition C9 as imposed by the Notification at Annex 1 to that statement, dated 15 July 2026, and not as the General Conditions read today.

← All posts