Harm categories
Harm Watch uses two layers of classification. The public form uses plain-English categories anyone can navigate quickly. Behind the scenes, each category maps to one or more of Ofcom’s seventeen kinds of priority illegal harm under the Online Safety Act 2023. The Ofcom layer never appears on the public form but is what approved organisations receive in the feed and API.
A submission is an allegation only — not a confirmed breach or a legal verdict.
Public reporting categories
What appears on the form. Twelve accepted categories, plus two that route away to specialist authorities.
Routed to specialist authorities
Child sexual abuse or exploitation
Routed to the Internet Watch Foundation, who can act on it anonymously.
report.iwf.org.uk
Terrorist or extremist material
Routed directly to the government reporting service.
gov.uk/report-terrorism
Accepted for logging
A scam, fake shop or fraud
Fake retailers, investment or crypto scams, phishing, anything designed to take money dishonestly.
Intimate images shared without consent
Including nudify tools, sexual deepfakes and threats to share images.
Abuse, harassment or threats
Content targeting a person with threats, stalking, pile-ons or exposure of their private details.
Hate towards a group of people
Attacks on people because of race, religion, disability, sexuality or gender identity.
Suicide or self-harm content
Content encouraging or instructing people to harm themselves.
Eating disorder content
Content promoting starvation, purging or disordered eating.
Children’s harm tier — no direct illegal-harm equivalent.
Pornography with no age check
Adult content anyone can reach without proving their age.
Harmful to children in another way
Bullying, violent content, dangerous challenges, anything aimed at children that should not be.
Children’s harm tier — no direct illegal-harm equivalent.
Drugs, weapons or stolen goods
Sites selling controlled drugs, weapons, stolen items or laundering money.
Exploitation or trafficking
Content advertising or arranging the exploitation of people.
Impersonation or fake identity
Sites pretending to be a person, a company or a public body.
Something else harmful
Tell us what is wrong with it in the description box. This option requires a description.
Resolved at triage. Requires a description.
Ofcom’s seventeen kinds of priority illegal harm
The internal taxonomy defined in Schedules 5, 6 and 7 of the Online Safety Act and in Ofcom’s Register of Risks. This is what the API returns and what organisations export. It does not appear on the public form.
| # | Category | Status |
|---|---|---|
| 1 | Terrorism | Blocked — routed away |
| 2a | CSEA: grooming | Blocked — routed away |
| 2b | CSEA: image-based CSAM | Blocked — routed away |
| 2c | CSEA: CSAM URLs | Blocked — routed away |
| 3 | Hate | Accepted |
| 4 | Harassment, stalking, threats and abuse | Accepted |
| 5 | Controlling or coercive behaviour | Accepted |
| 6 | Intimate image abuse | Accepted |
| 7 | Extreme pornography | Accepted |
| 8 | Sexual exploitation of adults | Accepted |
| 9 | Human trafficking | Accepted |
| 10 | Unlawful immigration | Accepted |
| 11 | Fraud and financial offences | Accepted |
| 12 | Proceeds of crime | Accepted |
| 13 | Drugs and psychoactive substances | Accepted |
| 14 | Firearms, knives and other weapons | Accepted |
| 15 | Encouraging or assisting suicide | Accepted |
| 16 | Foreign interference | Accepted |
| 17 | Animal cruelty | Accepted |
Two categories — animal-cruelty and foreign-interference — have no corresponding public form option. Both are available to admins at triage and can be added to the form later if demand warrants it.
Content harmful to children
A parallel structure in the Act, separate from the illegal content tiers. Stored as descriptors in the Harm Watch schema rather than as primary categories.
Primary priority content
Services must prevent children encountering this tier. Triggers highly effective age assurance requirements.
Priority content
Services must protect children in age groups at risk from encountering this tier.
Non-designated content
Anything else presenting a material risk of significant harm to an appreciable number of children. Deliberately open — this is why the “suggest a category” field on the form exists.
A note on regulatory scope
The Online Safety Act regulates user-to-user services, search services, and Part 5 publishers of pornography. A standalone scam site with no user-generated content and no search function is not a regulated service, so a good deal of what the public reports will sit outside the Act entirely — even when it is plainly harmful.
The Ofcom mapping is there to make the data legible to people who work in that framework, not to imply every record falls inside it. The osa_regulated flag in the API carries that distinction.