Shufti-Sphere-Website-Banner
burger-menu cross-icon-2

Resources

us

216.73.216.208

UK Age Verification Law: Online Safety Act Compliance Guide

TL;DR

The UK Online Safety Act 2023 requires pornography providers and qualifying user-to-user services to run highly effective age assurance (HEAA). Part 5 duties started 17 January 2025; Part 3 duties from 25 July 2025. Ofcom has fined multiple adult platforms since November 2025, with penalties running from £20,000 to £1.35 million, and can fine up to £18 million or 10% of global turnover, plus block UK access. Accepted methods include facial age estimation, photo ID matching, open banking checks and digital identity wallets. Self-declaration and basic age gates no longer meet the standard.

 

What the Online Safety Act requires

The Online Safety Act 2023 received Royal Assent on 26 October 2023 and gives Ofcom the power to require online services to protect children from pornography and other harmful content. The duty that matters for age verification is straightforward in principle and demanding in practice: any in-scope service must prevent children from encountering pornographic content, and it must be able to show that its method of doing so is highly effective, not just present.

Two categories carry the duty on different timelines. Part 5 covers services that publish their own pornographic content, and that duty has applied since 17 January 2025. Part 3 covers user-to-user platforms and search services, which had to complete a children’s access assessment by 16 April 2025 and then put proportionate measures, including age assurance, in place from 25 July 2025.

Service type Duty In force since
Part 5: providers publishing their own pornography Highly effective age assurance at the point of access 17 Jan 2025
Part 3: user-to-user platforms and search services likely to be accessed by children Children’s access assessment, then proportionate measures including age assurance where pornography or other primary priority content is present Assessment 16 Apr 2025 · measures 25 Jul 2025
Generative AI services that can produce sexual or other primary priority content Same duties as any Part 3 or Part 5 service; Ofcom has opened investigations under this reading Live enforcement from Jan 2026

 

Key dates and enforcement timeline

Ofcom moved from guidance to active enforcement quickly. The pattern below is drawn from Ofcom’s own published enforcement decisions and industry bulletins [VERIFY current figures against Ofcom’s live enforcement register before publishing, as amounts and case counts continue to update weekly].

Date Milestone
26 Oct 2023 Online Safety Act 2023 receives Royal Assent
17 Jan 2025 Part 5 duty begins: services publishing their own pornography must run highly effective age assurance
16 Apr 2025 Deadline for Part 3 services to complete children’s access assessments
25 Jul 2025 Part 3 duty begins: user-to-user and search services allowing pornography or other primary priority content must run proportionate age assurance
18 Nov 2025 First confirmation decision: £20,000 fine against 4chan for failing to provide an illegal content risk assessment
4 Dec 2025 AVS Group Ltd fined £1 million for failing to implement highly effective age assurance across 18 adult sites, plus £50,000 for non-cooperation
12 Feb 2026 Kick Online Entertainment SA fined £800,000 (plus £30,000 for non-cooperation) after five months without compliant age checks across 34 sites
23 Feb 2026 8579 LLC fined £1.35 million, the largest OSA age-assurance fine to date, plus £50,000 for non-cooperation
19 Mar 2026 4chan fined a further £520,000 across three separate breaches, with daily penalties for continued non-compliance
Ongoing 2026 Ofcom investigating 90+ services; enforcement extending into generative AI platforms distributing sexual content

 

Two things stand out in the pattern. First, Ofcom treats a failure to respond to its information requests as a separate offence from the underlying age-assurance failure, and fines both. Second, penalties scale with persistence and portfolio size: a single-service operator that corrected its systems after a provisional decision paid less than a multi-site operator with an ongoing breach. Cooperation measurably reduces the bill.

What counts as “highly effective” age assurance

Ofcom’s guidance rules out self-declaration, simple tick-box birth-year entry and unverified payment card checks as standalone methods. Accepted approaches generally fall into a few groups:

  • Facial age estimation, which returns a confidence-based age result from a live selfie without storing a biometric template
  • Photo ID verification, matching a government-issued document to the user attempting access
  • Open banking or card-based checks that confirm the account holder is over 18 through a regulated financial provider
  • Reusable digital identity and age tokens that let a verified user prove their age across multiple services without repeating the full check each time
  • A waterfall approach that starts with a low-friction method such as age estimation and escalates to document or biometric checks only for borderline results

The waterfall pattern is now the industry default because it balances the accuracy regulators demand with the drop-off businesses want to avoid. Shufti’s own implementation follows this model: age estimation first, stronger verification only when the estimate is inconclusive, and no retention of biometric templates once a result is returned.

Penalties and enforcement powers

Ofcom can fine a non-compliant service up to £18 million or 10% of qualifying global revenue, whichever is greater. Beyond fines, Ofcom can apply to the courts for business disruption measures: orders requiring payment providers, advertisers or UK internet service providers to withdraw support from a non-compliant platform, effectively blocking it from the UK market. Enforcement so far has clustered around adult content and file-sharing services, and Ofcom has confirmed it is also assessing major social platforms and generative AI tools capable of producing sexual content, so the enforcement pool is widening rather than narrowing.

Built for the OSA, not retrofitted to it

Shufti runs an adaptive waterfall that opens with low-friction age estimation and escalates to document or biometric checks only when needed, so genuine adult users keep moving while Ofcom’s highly effective standard is met. No biometric templates are stored, and every check is logged for the risk assessment and effectiveness evidence Ofcom expects providers to keep on file.

Talk to us about deploying HEAA before your next Ofcom risk assessment window.

 

How to implement compliance

  1. Run or refresh your children’s access assessment and keep a written record; this is the document Ofcom asks for first.
  2. Choose an age assurance method proportionate to your risk level; a waterfall of estimation plus document fallback suits most consumer platforms.
  3. Remove any standalone self-declaration or birth-year gate; these no longer meet the highly effective standard on their own.
  4. Log pass rates, false positive and false negative rates, and verification time; Ofcom’s investigations have repeatedly asked for this evidence.
  5. Respond to any Ofcom information request within the stated deadline; every enforcement case to date has included a separate, and often costly, penalty for late or missing responses.
  6. Review your privacy documentation so users understand what data is collected, why, and how long it is retained.

Related Posts

Shufti Blog

What is Biometric Verification: Meaning, Types, Technology & Tools

What is Biometric Verification: Meaning, Types, Technology & Tools

Explore More

Shufti Blog

What Is Transaction Screening? Definition, Process, and How It Works

What Is Transaction Screening? Definition, Process, and How It Works

Explore More

Shufti Blog

Sanctions Screening: What It Is and How It Works in AML

Sanctions Screening: What It Is and How It Works in AML

Explore More

Shufti Blog

Qualified Electronic Signature (QES): Meaning, Requirements, and When You Need One

Qualified Electronic Signature (QES): Meaning, Requirements, and When You Need One

Explore More

Shufti Blog

AMLO Compliance in Hong Kong: AML Obligations for Licensed Corporations & VASPs

AMLO Compliance in Hong Kong: AML Obligations for Licensed Corporations & VASPs

Explore More

Shufti Blog

Corporate Transparency Act & FinCEN’s BOI Rule: What AML Requires in 2026

Corporate Transparency Act & FinCEN’s BOI Rule: What AML Requires in 2026

Explore More

Shufti Blog

What happens during a Shufti identity check?

What happens during a Shufti identity check?

Explore More

Shufti Blog

What is Biometric Verification: Meaning, Types, Technology & Tools

What is Biometric Verification: Meaning, Types, Technology & Tools

Explore More

Shufti Blog

What Is Transaction Screening? Definition, Process, and How It Works

What Is Transaction Screening? Definition, Process, and How It Works

Explore More

Shufti Blog

Sanctions Screening: What It Is and How It Works in AML

Sanctions Screening: What It Is and How It Works in AML

Explore More

Shufti Blog

Qualified Electronic Signature (QES): Meaning, Requirements, and When You Need One

Qualified Electronic Signature (QES): Meaning, Requirements, and When You Need One

Explore More

Shufti Blog

AMLO Compliance in Hong Kong: AML Obligations for Licensed Corporations & VASPs

AMLO Compliance in Hong Kong: AML Obligations for Licensed Corporations & VASPs

Explore More

Shufti Blog

Corporate Transparency Act & FinCEN’s BOI Rule: What AML Requires in 2026

Corporate Transparency Act & FinCEN’s BOI Rule: What AML Requires in 2026

Explore More

Shufti Blog

What happens during a Shufti identity check?

What happens during a Shufti identity check?

Explore More

Take the next steps to better security.

Contact us

Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

Contact us

Request demo

Get free access to our platform and try our products today.

Get started