UK Age Verification Law: Online Safety Act Compliance Guide
| TL;DR
The UK Online Safety Act 2023 requires pornography providers and qualifying user-to-user services to run highly effective age assurance (HEAA). Part 5 duties started 17 January 2025; Part 3 duties from 25 July 2025. Ofcom has fined multiple adult platforms since November 2025, with penalties running from £20,000 to £1.35 million, and can fine up to £18 million or 10% of global turnover, plus block UK access. Accepted methods include facial age estimation, photo ID matching, open banking checks and digital identity wallets. Self-declaration and basic age gates no longer meet the standard. |
What the Online Safety Act requires
The Online Safety Act 2023 received Royal Assent on 26 October 2023 and gives Ofcom the power to require online services to protect children from pornography and other harmful content. The duty that matters for age verification is straightforward in principle and demanding in practice: any in-scope service must prevent children from encountering pornographic content, and it must be able to show that its method of doing so is highly effective, not just present.
Two categories carry the duty on different timelines. Part 5 covers services that publish their own pornographic content, and that duty has applied since 17 January 2025. Part 3 covers user-to-user platforms and search services, which had to complete a children’s access assessment by 16 April 2025 and then put proportionate measures, including age assurance, in place from 25 July 2025.
| Service type | Duty | In force since |
|---|---|---|
| Part 5: providers publishing their own pornography | Highly effective age assurance at the point of access | 17 Jan 2025 |
| Part 3: user-to-user platforms and search services likely to be accessed by children | Children’s access assessment, then proportionate measures including age assurance where pornography or other primary priority content is present | Assessment 16 Apr 2025 · measures 25 Jul 2025 |
| Generative AI services that can produce sexual or other primary priority content | Same duties as any Part 3 or Part 5 service; Ofcom has opened investigations under this reading | Live enforcement from Jan 2026 |
Key dates and enforcement timeline
Ofcom moved from guidance to active enforcement quickly. The pattern below is drawn from Ofcom’s own published enforcement decisions and industry bulletins [VERIFY current figures against Ofcom’s live enforcement register before publishing, as amounts and case counts continue to update weekly].
| Date | Milestone |
|---|---|
| 26 Oct 2023 | Online Safety Act 2023 receives Royal Assent |
| 17 Jan 2025 | Part 5 duty begins: services publishing their own pornography must run highly effective age assurance |
| 16 Apr 2025 | Deadline for Part 3 services to complete children’s access assessments |
| 25 Jul 2025 | Part 3 duty begins: user-to-user and search services allowing pornography or other primary priority content must run proportionate age assurance |
| 18 Nov 2025 | First confirmation decision: £20,000 fine against 4chan for failing to provide an illegal content risk assessment |
| 4 Dec 2025 | AVS Group Ltd fined £1 million for failing to implement highly effective age assurance across 18 adult sites, plus £50,000 for non-cooperation |
| 12 Feb 2026 | Kick Online Entertainment SA fined £800,000 (plus £30,000 for non-cooperation) after five months without compliant age checks across 34 sites |
| 23 Feb 2026 | 8579 LLC fined £1.35 million, the largest OSA age-assurance fine to date, plus £50,000 for non-cooperation |
| 19 Mar 2026 | 4chan fined a further £520,000 across three separate breaches, with daily penalties for continued non-compliance |
| Ongoing 2026 | Ofcom investigating 90+ services; enforcement extending into generative AI platforms distributing sexual content |
Two things stand out in the pattern. First, Ofcom treats a failure to respond to its information requests as a separate offence from the underlying age-assurance failure, and fines both. Second, penalties scale with persistence and portfolio size: a single-service operator that corrected its systems after a provisional decision paid less than a multi-site operator with an ongoing breach. Cooperation measurably reduces the bill.
What counts as “highly effective” age assurance
Ofcom’s guidance rules out self-declaration, simple tick-box birth-year entry and unverified payment card checks as standalone methods. Accepted approaches generally fall into a few groups:
- Facial age estimation, which returns a confidence-based age result from a live selfie without storing a biometric template
- Photo ID verification, matching a government-issued document to the user attempting access
- Open banking or card-based checks that confirm the account holder is over 18 through a regulated financial provider
- Reusable digital identity and age tokens that let a verified user prove their age across multiple services without repeating the full check each time
- A waterfall approach that starts with a low-friction method such as age estimation and escalates to document or biometric checks only for borderline results
The waterfall pattern is now the industry default because it balances the accuracy regulators demand with the drop-off businesses want to avoid. Shufti’s own implementation follows this model: age estimation first, stronger verification only when the estimate is inconclusive, and no retention of biometric templates once a result is returned.
Penalties and enforcement powers
Ofcom can fine a non-compliant service up to £18 million or 10% of qualifying global revenue, whichever is greater. Beyond fines, Ofcom can apply to the courts for business disruption measures: orders requiring payment providers, advertisers or UK internet service providers to withdraw support from a non-compliant platform, effectively blocking it from the UK market. Enforcement so far has clustered around adult content and file-sharing services, and Ofcom has confirmed it is also assessing major social platforms and generative AI tools capable of producing sexual content, so the enforcement pool is widening rather than narrowing.
| Built for the OSA, not retrofitted to it
Shufti runs an adaptive waterfall that opens with low-friction age estimation and escalates to document or biometric checks only when needed, so genuine adult users keep moving while Ofcom’s highly effective standard is met. No biometric templates are stored, and every check is logged for the risk assessment and effectiveness evidence Ofcom expects providers to keep on file. Talk to us about deploying HEAA before your next Ofcom risk assessment window. |
How to implement compliance
- Run or refresh your children’s access assessment and keep a written record; this is the document Ofcom asks for first.
- Choose an age assurance method proportionate to your risk level; a waterfall of estimation plus document fallback suits most consumer platforms.
- Remove any standalone self-declaration or birth-year gate; these no longer meet the highly effective standard on their own.
- Log pass rates, false positive and false negative rates, and verification time; Ofcom’s investigations have repeatedly asked for this evidence.
- Respond to any Ofcom information request within the stated deadline; every enforcement case to date has included a separate, and often costly, penalty for late or missing responses.
- Review your privacy documentation so users understand what data is collected, why, and how long it is retained.
