Shufti-Sphere-Website-Banner
burgermenu kruis-icoon-2

Informatiebronnen

fr

5.196.175.156

UK Age Verification Law: Online Safety Act Compliance Guide

TL; DR

The UK Online Safety Act 2023 requires pornography providers and qualifying user-to-user services to run highly effective age assurance (HEAA). Part 5 duties started 17 January 2025; Part 3 duties from 25 July 2025. Ofcom has fined multiple adult platforms since November 2025, with penalties running from £20,000 to £1.35 million, and can fine up to £18 million or 10% of global turnover, plus block UK access. Accepted methods include facial age estimation, photo ID matching, open banking checks and digital identity wallets. Self-declaration and basic age gates no longer meet the standard.

 

What the Online Safety Act requires

The Online Safety Act 2023 received Royal Assent on 26 October 2023 and gives Ofcom the power to require online services to protect children from pornography and other harmful content. The duty that matters for age verification is straightforward in principle and demanding in practice: any in-scope service must prevent children from encountering pornographic content, and it must be able to show that its method of doing so is highly effective, not just present.

Two categories carry the duty on different timelines. Part 5 covers services that publish their own pornographic content, and that duty has applied since 17 January 2025. Part 3 covers user-to-user platforms and search services, which had to complete a children’s access assessment by 16 April 2025 and then put proportionate measures, including age assurance, in place from 25 July 2025.

Service type Plicht In force since
Part 5: providers publishing their own pornography Highly effective age assurance at the point of access Januari 17 2025
Part 3: user-to-user platforms and search services likely to be accessed by children Children’s access assessment, then proportionate measures including age assurance where pornography or other primary priority content is present Assessment 16 Apr 2025 · measures 25 Jul 2025
Generative AI services that can produce sexual or other primary priority content Same duties as any Part 3 or Part 5 service; Ofcom has opened investigations under this reading Live enforcement from Jan 2026

 

Key dates and enforcement timeline

Ofcom moved from guidance to active enforcement quickly. The pattern below is drawn from Ofcom’s own published enforcement decisions and industry bulletins [VERIFY current figures against Ofcom’s live enforcement register before publishing, as amounts and case counts continue to update weekly].

Datum Milestone
Oktober 26 2023 Online Safety Act 2023 receives Royal Assent
Januari 17 2025 Part 5 duty begins: services publishing their own pornography must run highly effective age assurance
April 16 2025 Deadline for Part 3 services to complete children’s access assessments
Juli 25 2025 Part 3 duty begins: user-to-user and search services allowing pornography or other primary priority content must run proportionate age assurance
18 november 2025 First confirmation decision: £20,000 fine against 4chan for failing to provide an illegal content risk assessment
4 Dec 2025 AVS Group Ltd fined £1 million for failing to implement highly effective age assurance across 18 adult sites, plus £50,000 for non-cooperation
Februari 12 2026 Kick Online Entertainment SA fined £800,000 (plus £30,000 for non-cooperation) after five months without compliant age checks across 34 sites
Februari 23 2026 8579 LLC fined £1.35 million, the largest OSA age-assurance fine to date, plus £50,000 for non-cooperation
Maart 19 2026 4chan fined a further £520,000 across three separate breaches, with daily penalties for continued non-compliance
Doorlopend 2026 Ofcom investigating 90+ services; enforcement extending into generative AI platforms distributing sexual content

 

Two things stand out in the pattern. First, Ofcom treats a failure to respond to its information requests as a separate offence from the underlying age-assurance failure, and fines both. Second, penalties scale with persistence and portfolio size: a single-service operator that corrected its systems after a provisional decision paid less than a multi-site operator with an ongoing breach. Cooperation measurably reduces the bill.

What counts as “highly effective” age assurance

Ofcom’s guidance rules out self-declaration, simple tick-box birth-year entry and unverified payment card checks as standalone methods. Accepted approaches generally fall into a few groups:

  • Facial age estimation, which returns a confidence-based age result from a live selfie without storing a biometric template
  • Photo ID verification, matching a government-issued document to the user attempting access
  • Open banking or card-based checks that confirm the account holder is over 18 through a regulated financial provider
  • Reusable digital identity and age tokens that let a verified user prove their age across multiple services without repeating the full check each time
  • A waterfall approach that starts with a low-friction method such as age estimation and escalates to document or biometric checks only for borderline results

The waterfall pattern is now the industry default because it balances the accuracy regulators demand with the drop-off businesses want to avoid. Shufti’s own implementation follows this model: age estimation first, stronger verification only when the estimate is inconclusive, and no retention of biometric templates once a result is returned.

Penalties and enforcement powers

Ofcom can fine a non-compliant service up to £18 million or 10% of qualifying global revenue, whichever is greater. Beyond fines, Ofcom can apply to the courts for business disruption measures: orders requiring payment providers, advertisers or UK internet service providers to withdraw support from a non-compliant platform, effectively blocking it from the UK market. Enforcement so far has clustered around adult content and file-sharing services, and Ofcom has confirmed it is also assessing major social platforms and generative AI tools capable of producing sexual content, so the enforcement pool is widening rather than narrowing.

Built for the OSA, not retrofitted to it

Shufti runs an adaptive waterfall that opens with low-friction age estimation and escalates to document or biometric checks only when needed, so genuine adult users keep moving while Ofcom’s highly effective standard is met. No biometric templates are stored, and every check is logged for the risk assessment and effectiveness evidence Ofcom expects providers to keep on file.

Talk to us about deploying HEAA before your next Ofcom risk assessment window.

 

How to implement compliance

  1. Run or refresh your children’s access assessment and keep a written record; this is the document Ofcom asks for first.
  2. Choose an age assurance method proportionate to your risk level; a waterfall of estimation plus document fallback suits most consumer platforms.
  3. Remove any standalone self-declaration or birth-year gate; these no longer meet the highly effective standard on their own.
  4. Log pass rates, false positive and false negative rates, and verification time; Ofcom’s investigations have repeatedly asked for this evidence.
  5. Respond to any Ofcom information request within the stated deadline; every enforcement case to date has included a separate, and often costly, penalty for late or missing responses.
  6. Review your privacy documentation so users understand what data is collected, why, and how long it is retained.

gerelateerde berichten

Shufti Blog

Wat is biometrische verificatie: betekenis, soorten, technologie en hulpmiddelen?

Wat is biometrische verificatie: betekenis, soorten, technologie en hulpmiddelen?

Meer ontdekken

Shufti Blog

Wat is transactiescreening? Definitie, proces en hoe het werkt.

Wat is transactiescreening? Definitie, proces en hoe het werkt.

Meer ontdekken

Shufti Blog

Sanctiescreening: wat het is en hoe het werkt in de strijd tegen witwassen.

Sanctiescreening: wat het is en hoe het werkt in de strijd tegen witwassen.

Meer ontdekken

Shufti Blog

Florida SB1161 en verantwoordingsplicht van deepfake-platformen: wat de wet vereist (bijgewerkt oktober 2025)

Florida SB1161 en verantwoordingsplicht van deepfake-platformen: wat de wet vereist (bijgewerkt oktober 2025)

Meer ontdekken

Shufti Blog

VideoIdent voor Duitse cryptobeurzen: handleiding voor naleving van MiCA, GwG en BaFin voor CASPs

VideoIdent voor Duitse cryptobeurzen: handleiding voor naleving van MiCA, GwG en BaFin voor CASPs

Meer ontdekken

Shufti Blog

Video-identificatie in Zwitserland: FINMA-richtlijn voor naleving door banken, verzekeraars en vermogensbeheerders

Video-identificatie in Zwitserland: FINMA-richtlijn voor naleving door banken, verzekeraars en vermogensbeheerders

Meer ontdekken

Shufti Blog

FMA-video-identificatie in Oostenrijk: FM-GwG-nalevingsrichtlijn voor financiële instellingen

FMA-video-identificatie in Oostenrijk: FM-GwG-nalevingsrichtlijn voor financiële instellingen

Meer ontdekken

Shufti Blog

Wat is biometrische verificatie: betekenis, soorten, technologie en hulpmiddelen?

Wat is biometrische verificatie: betekenis, soorten, technologie en hulpmiddelen?

Meer ontdekken

Shufti Blog

Wat is transactiescreening? Definitie, proces en hoe het werkt.

Wat is transactiescreening? Definitie, proces en hoe het werkt.

Meer ontdekken

Shufti Blog

Sanctiescreening: wat het is en hoe het werkt in de strijd tegen witwassen.

Sanctiescreening: wat het is en hoe het werkt in de strijd tegen witwassen.

Meer ontdekken

Shufti Blog

Florida SB1161 en verantwoordingsplicht van deepfake-platformen: wat de wet vereist (bijgewerkt oktober 2025)

Florida SB1161 en verantwoordingsplicht van deepfake-platformen: wat de wet vereist (bijgewerkt oktober 2025)

Meer ontdekken

Shufti Blog

VideoIdent voor Duitse cryptobeurzen: handleiding voor naleving van MiCA, GwG en BaFin voor CASPs

VideoIdent voor Duitse cryptobeurzen: handleiding voor naleving van MiCA, GwG en BaFin voor CASPs

Meer ontdekken

Shufti Blog

Video-identificatie in Zwitserland: FINMA-richtlijn voor naleving door banken, verzekeraars en vermogensbeheerders

Video-identificatie in Zwitserland: FINMA-richtlijn voor naleving door banken, verzekeraars en vermogensbeheerders

Meer ontdekken

Shufti Blog

FMA-video-identificatie in Oostenrijk: FM-GwG-nalevingsrichtlijn voor financiële instellingen

FMA-video-identificatie in Oostenrijk: FM-GwG-nalevingsrichtlijn voor financiële instellingen

Meer ontdekken

Neem de volgende stappen naar een betere beveiliging.

Contact

Neem contact op met onze experts. Wij helpen u de perfecte oplossing te vinden voor uw compliance- en beveiligingsbehoeften.

Contact

Demo aanvragen

Krijg gratis toegang tot ons platform en probeer onze producten vandaag nog uit.

Start