No statutory protection or transparency mechanism for end-to-end encryption
Section 121 of the Online Safety Act lets Ofcom mandate accredited technology to scan private messaging, Ofcom finalised its Technology Notices guidance in May 2026, and enforcement is deferred only by a ministerial assurance on technical feasibility with no legal force. Separately, technical capability notices under the Investigatory Powers Act are secret. Apple withdrew Advanced Data Protection from UK users in February 2025, the tribunal dismissed Apple's appeal after the Home Office narrowed its order to UK users only, and Privacy International's secrecy challenge was heard in 2026. No statutory transparency reporting exists, not even aggregate counts, and no dedicated litigation or defence fund backs small providers; ORG, PI and Big Brother Watch cover encryption from general budgets.
Every layer of the sovereignty stack rests on lawful, durable end-to-end encryption. The current regime works as an uncertainty tax: providers withdraw features, builders cannot promise UK users lasting security, and secrecy keeps Parliament and the market from weighing the trade-offs.
A statutory amendment protecting end-to-end encryption from scanning mandates, annual aggregate transparency reporting on IPA notices, and a philanthropic UK encryption defence fund financing interventions and representation for small providers facing notices.
// Build now: First artefact: philanthropic UK Encryption Defence Fund; the statutory E2EE amendment remains the state-led end-state.
Scanning-mandate and secret-notice regimes are being finalised and litigated this year, and durable protection needs statute with only general-budget campaigners pushing back.