9 min read

One Year of 'Highly Effective' Age Checks: What the Online Safety Act's Enforcement Data Shows Before Ofcom's July Report

July 2026 marks a year of the Online Safety Act's age-assurance duties, and Ofcom's statutory effectiveness report is due. Here's what the enforcement data already reveals — and what operators should fix now.

A one-year compliance scoreboard for UK age assurance: a row of platform icons, most stamped 'age-checked', a few marked 'geoblocked', and a rising VPN-download curve behind them, with an Ofcom effectiveness report landing on the table

On 25 July 2025, the Online Safety Act’s duty to run “highly effective age assurance” on the riskiest content came into force. A year later, that date has a sequel: Ofcom committed to report on the effectiveness of age assurance by the end of July 2026. One report closes the first chapter and sets the terms of the next.

For platform operators, the anniversary is not a moment for reflection so much as a deadline. The grace period — the year in which “we’ve deployed something” was a defensible answer — is ending, and the regulator is about to grade the difference between deploying an age check and running one that works. This post reads the year’s enforcement record to predict what that grade will emphasise, and what to fix before it lands.

The scoreboard after twelve months

Ofcom did not wait for the anniversary to start enforcing. In its first year it opened investigations into roughly ninety services and issued a run of escalating penalties, most of them against adult-content operators that had left the age gate off.

Provider Date Penalty For
AVS Group (Belize) Dec 2025 £1M + £50K No highly effective age assurance; ignoring an information request
Kick Online Entertainment Feb 2026 £800K + £30K Section 12 breach; late information-request response
8579 LLC Feb 2026 £1.35M Failure to implement age assurance (largest in this strand)
4chan Mar 2026 £520K No age assurance; no illegal-content risk assessment; deficient terms

Sources: Ofcom; Inforrm.

On the adoption side, the picture is more encouraging. Of the top 100 dedicated pornography services, Ofcom reported that 77 had age assurance in place by the end of January 2026 and a further 7 had simply geoblocked UK users — the market-exit calculation some operators run when verification looks harder than walking away. Age checks across the ecosystem were reportedly triggering on the order of five million verifications a day.

Read quickly, that looks like a win: most of the highest-risk sites now gate, and the ones that don’t are being fined into line. Read carefully, it is the setup for the harder question the July report has to answer.

What the fines actually punished

The instinct is to read this list as “operators got fined for not having an age check.” That is only half of what happened, and the half you learn less from.

Look at the structure of the penalties. AVS was fined £1M for the missing age assurance and a separate £50K for ignoring an information request. Kick drew £800K for the section 12 breach and another £30K for a late response, plus a running daily penalty until it produced a full list of the sites it operates. 4chan’s £520K was three findings stacked — no age assurance, no risk assessment, no compliant terms of service. Ofcom is running a layered model: a substantive penalty for the gate, distinct penalties for the paperwork, and daily-rate penalties to force cooperation.

The lesson for anyone who does run an age check is in that structure. A working gate is necessary but not sufficient. The regulator is also grading whether you can answer an information request quickly and accurately, whether you completed the risk assessment that justifies your chosen method, and whether your terms describe what you actually do. Several of these fines punished the second category as much as the first. If your compliance posture is “the check works, the evidence is somewhere,” you are exposed on exactly the axis these penalties targeted. The evidence trail is the deliverable, not a by-product.

The number that will define the July report

Here is the figure that adoption statistics do not capture, and the one the effectiveness report cannot avoid: research through the year still found that around 72% of children aged 8–12 were accessing sites and apps with a stated minimum age of 13. Seventy-seven of the top hundred porn sites gate, and pre-teens are still getting into services that were never supposed to admit them at all.

That gap between adoption and outcome is the whole story of year two. Two forces drive it.

The first is circumvention. When the duties took effect, UK VPN downloads spiked — Proton reported hourly signups up more than 1,400% from the 25 July switch-on, and downloads climbed into the millions within days (Biometric Update). A determined teenager with a free VPN, a borrowed face, or a retry button routes around a gate that a compliance dashboard records as “passed.” We have written about the retry loophole that quietly defeats age estimation and the binding problem — the difference between verifying a moment and verifying the person actually using the account. Ofcom now has a year of field data showing those gaps are not theoretical.

The second is weak methods dressed as compliance. A self-declaration checkbox and a soft age-estimation pass both produce a green tick without producing assurance. The ICO’s £14.5M fine against Reddit — for over-relying on self-declaration while collecting children’s data anyway — was the clearest signal that asking an age is not assuring it. The July report is Ofcom’s opportunity to say the same thing on the content side: that “highly effective” is a measured property, not a deployment status.

Expect the report to pivot the enforcement question from did you deploy age assurance? to can you show it keeps the right users out? Adoption was year one’s metric. Effectiveness is year two’s.

What the report is likely to sharpen

Two developments during the year telegraph where Ofcom is heading.

In March 2026, Ofcom and the ICO issued a joint statement on age assurance and wrote to major platforms about highly effective checks. That coordination matters because it closes a favourite escape hatch: the argument that satisfying the online-safety regulator and satisfying the data-protection regulator pull in opposite directions. They do not, and the two bodies saying so together means an operator can no longer justify a surveillance-heavy design as an Ofcom necessity, or a lax one as an ICO courtesy. You now have to satisfy both at once — effective and data-minimising.

Expect the report to lean on proportionality rather than a single mandated method: match the strength of the check to the risk of the surface, prove the method resists the circumvention routes seen in the wild, and hold the evidence without hoarding the identity. That is a higher bar than “we bought a vendor,” and it rewards the operators who instrumented their funnels to measure pass rates, retry patterns, and drop-off rather than just logging a boolean.

Four things to verify before the report lands

The report will not change the law; it will clarify how the existing duties get graded. Four checks tell you whether you are ready for that clarification.

First, confirm your method matches the risk of each surface. A low-risk sign-up can lean on estimation or inference; a surface that bars under-18s from adult content needs a method a motivated user cannot type past — document plus NFC chip verification for the cases that demand certainty, benchmarked against the known error bands near the threshold. One method for every surface is either too weak where it counts or too invasive where it doesn’t.

Second, confirm you are keeping the evidence, not the identity. The artifact Ofcom asked for in fine after fine was proof a check happened — which method ran, what assurance level it returned — not a vault of ID images. A birthday or a passport scan you retain is a breach waiting to be found and a data-minimisation finding waiting to be written; the privacy-first posture is also the lower-liability one.

Third, confirm your gate resists circumvention, not just first attempts. Cap and budget retries so a probabilistic check cannot be rolled until it passes, bind the verified result to the session and account so a borrowed adult face doesn’t unlock a child’s login, and treat the VPN-and-proxy reality as an input to your design rather than a regulator’s problem. Watch how the parallel state-level anti-circumvention laws evolve; the direction of travel is unmistakable.

Fourth, confirm your paperwork is current. The completed risk assessment, terms of service that describe your real controls, and a process to answer an information request within Ofcom’s window were each a separate line item in this year’s penalties. The enforcement risk is now a standing cost, and the cheapest of the four fixes is the one operators most often defer.

How Xident handles it

Xident is built for the exact standard the July report will sharpen: assurance you can prove, without the surveillance database the ICO keeps fining people for building. The first gate is client-side facial age estimation under liveness, returning a threshold classification — over or under 12, 15, 16, 18, 21, or 25 — rather than a self-asserted birthday. Where the result sits near the line or the surface is high-risk, the flow escalates automatically to document OCR, face match, and NFC chip verification, so the boundary that Ofcom cares about is enforced by a method a determined user cannot game their way past.

The circumvention failure modes that defined year one are handled at the architecture layer, not left to chance: attempts are budgeted so a probabilistic check cannot be retried into a pass, and the verified result binds to the session and account rather than to a single fleeting moment. Crucially, the system produces a decision and a record — a threshold result logged with its method and assurance level — not a hoard of dates of birth and ID scans. That is the data-minimising posture the ICO expects, the evidence trail Ofcom asks for, and — via a reusable, user-held credential — a returning-user experience that doesn’t re-collect identity every time. It is, in one stack, the answer to the only question the effectiveness report really asks: do you know the age of your users, and can you show that your method keeps the wrong ones out?


A year in, the Online Safety Act has proven that regulators will fine the operators who never built a gate. Year two is about the operators who built one that a child can still walk through. When Ofcom’s report lands at the end of July, the platforms that measured effectiveness — pass rates, retry abuse, binding, drop-off — will have a data-backed answer. The ones that only measured adoption will be reading their own grade for the first time.

This post is general information about public enforcement actions and regulatory guidance, not legal advice. Age-assurance duties are still being interpreted; consult qualified counsel for your specific obligations.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo