The UK’s online age-checking policy is intended to reduce children’s access to pornography and other harmful content. The key question is not whether an age-check screen exists, but whether it reduces actual exposure without requiring users to disclose excessive amounts of identity information.
In its initial assessment published on July 15, 2026, Ofcom said that age checks are helping to make UK children’s online experiences safer, while also noting that the protection system is not yet complete. In particular, it believes that age-estimation methods used by some social media services require further performance testing.
What Is the UK’s Online Age-Checking System?
The Online Safety Act 2023, the UK’s online safety law, imposes child-protection duties on online businesses according to the type of service and level of risk. Ofcom enforces the rules and oversees whether the protective measures adopted by businesses meet legal standards.
Terms that are often used interchangeably under this system can be distinguished as follows.
| Term | Meaning | Representative examples |
|---|---|---|
| Age assurance | An umbrella term covering all processes used to determine a user’s age or age range | ID checks, facial age estimation, device signals |
| Age verification | Checking a date of birth or whether someone is over a threshold age against reliable information | Passport or driver’s license checks, digital identity checks |
| Age estimation | Probabilistically estimating an age range from characteristics or behavioral data without directly checking a date of birth | Facial age estimation, account activity-based analysis |
| Self-declaration of age | Users directly enter their date of birth or whether they are adults | Entering a date of birth, an “18 or over” button |
Because children can easily enter a different date, simple self-declaration alone is difficult to regard as highly effective age assurance.
Which Services Does It Apply To?
Age assurance is not relevant only to pornography sites. Social media services that host user posts, gaming communities, dating services, and search services may also need to assess whether children are likely to access them and the risk of harmful content. However, the following distinctions are important.
- Services that directly provide pornography or allow it to be posted may be required to use strong age assurance to prevent access to adult content.
- Social media, gaming, and dating services likely to be used by children must establish measures such as age-based access restrictions, controls on content recommendations, and safety settings, depending on their risk assessments.
- The same checking process does not apply to every business solely on the basis of its industry category. Service features, content, and connections to UK users affect the determination.
- A site is not automatically exempt merely because it is small or based overseas, although detection and enforcement may become more difficult.
It is therefore inaccurate to say that “every internet user in the UK must provide ID.” The law imposes outcome-based duties and does not mandate a single technology for every service.
Ofcom’s “Highly Effective” Standard
Rather than approving specific providers or products across the board, Ofcom focuses on the performance that age assurance must achieve. The four key factors for determining whether age assurance is highly effective are as follows.
- Technical accuracy: Error rates in which actual minors are incorrectly classified as adults or adults are incorrectly classified as minors must be sufficiently low.
- Robustness: The system must not be easily defeated by circumvention attempts such as using someone else’s documents, recapturing a screen, using synthetic images, or sharing accounts.
- Reliability: It must produce consistent results repeatedly, rather than functioning only at certain times or on certain devices.
- Fairness: Error rates must not become excessively high for particular groups based on skin color, gender, disability, age range, or other characteristics.
Whether these four conditions are met cannot be determined from the name of the technology alone. For example, even when the same facial age-estimation method is used, results vary according to the model, capture conditions, decision thresholds, and retesting procedures.
Problems at the Age Threshold
Age estimates generally come with probabilities and margins of error. This is why it is difficult to distinguish perfectly between an actual 17-year-old and a 19-year-old when applying an age threshold of 18.
Businesses may consider the following safeguards for borderline ranges.
- Apply a conservative buffer to the estimated age.
- Provide another means of proof if one method fails.
- Allow adults to appeal if they are incorrectly blocked.
- Separately disclose the rate at which children are incorrectly allowed through and the rate at which adults are incorrectly blocked.
- Independently test error rates by group and performance in real-world usage environments.
Widening the buffer can reduce the number of children incorrectly allowed through, but it may increase the blocking of adults who look young. Effectiveness must be assessed with these trade-offs in mind.
Comparison of Major Age-Checking Methods
| Method | Advantages | Main limitations | Privacy risks |
|---|---|---|---|
| Government-issued ID check | Can be highly reliable because it directly checks a date of birth | Accessibility for people without documents, forgery and identity theft, mismatch between the account user and document owner | Leakage or excessive retention of names, dates of birth, photographs, and document numbers |
| Facial age estimation | Can be designed to estimate only an age range without necessarily revealing identity | Errors occur around the age threshold and under different capture conditions, and performance must be tested across groups | Collection of facial images, potential reuse, and lack of transparency about retention and model training |
| Financial, credit card, or open banking check | Can confirm a threshold age using a financial relationship held in an adult’s name | Exclusion of adults without financial instruments, mismatch between the cardholder and actual user | Unnecessary exposure of financial institution or transaction-related information |
| Mobile network operator check | Can reduce the need to submit separate documents by using existing subscriber information | Family plans, prepaid lines, and differences between the account holder and actual user | Possibility of linking a phone number to the service being used |
| Digital identity service | Can provide multiple sites with only an “over the threshold age” signal instead of original documents | Dependence on identity providers and the possibility of extensive tracking | Risk of linking usage records across different services |
| App store, operating system, or device-based check | Can reduce repeated checks by transmitting a previously configured age signal to multiple apps | Shared devices, accounts in a parent’s name, incorrect initial settings, and dependence on ecosystem providers | Possibility that usage history will be concentrated in a central account |
No method is the most accurate and privacy-friendly in every situation. High-risk content may require strong proof, but requiring users to repeatedly submit original identity documents to each service increases the risk of large-scale data leaks.
Design Principles That Are Less Intrusive to Privacy
Age checks do not necessarily conflict with privacy protection. A service can be structured so that it does not directly receive a date of birth or a copy of an identity document, but instead receives only a result such as “18 or over” from an independent provider.
A privacy-preserving system should follow these principles.
- Data minimization: If an exact date of birth is not needed, process only whether the user is over the threshold age.
- Purpose limitation: Do not repurpose age-check data for advertising, user profiling, or model training.
- Short retention periods: Do not unnecessarily retain identity document images or facial videos after the check is complete.
- Separation and unlinkability: Design the system so that age-check providers cannot easily track the sites users visit or combine records from multiple services.
- Security: Apply encryption during transmission and storage, access controls, and breach-response procedures.
- Transparency: Explain to users what data is collected, who processes it, how long it is retained, how automated decisions are made, and how to appeal.
- Alternative methods: Provide another verification route for people who cannot use a particular document or facial capture.
Facial images do not always constitute special-category biometric data under UK data protection law. The specific manner of use matters, including whether the images are technically processed for the purpose of uniquely identifying an individual. However, facial data is sensitive information that is difficult to change after a leak, so it requires a high level of protection.
Sign-in required
Sign in with your Google account to like and comment.