All posts
5 min readOpenKYC Team

The UK Online Safety Act: Age Assurance Requirements, Explained

age-verificationregulationuk

The UK was the first major market to make age checks for adult content a hard legal requirement with a well-funded regulator behind it. Since July 2025, any service that publishes or allows pornographic content accessible from the UK must use "highly effective age assurance," and Ofcom has both the mandate and the budget to enforce it. If you serve UK users, this is the regime you design for first, because it's the strictest one currently in force.

What the Online Safety Act actually requires

The Online Safety Act became law in October 2023, but its duties arrived in phases as Ofcom published codes of practice and guidance. The piece that matters most for age assurance landed in 2025: services that publish pornographic content, and user-to-user services that allow it, must ensure children cannot normally access that content. Self-declaration, the "click here if you're 18" checkbox, is explicitly insufficient.

The standard is "highly effective age assurance" (HEAA). Ofcom deliberately avoided mandating a single technology; instead it set criteria the chosen method must meet: technically accurate, robust, reliable, and fair. The duty has been in force for pornography providers since July 2025, and the broader children's safety duties, which require age assurance to keep minors away from other harmful content like self-harm and eating-disorder material, came into effect on a similar timeline.

Scope is broader than many operators assume. The Act applies to services with links to the UK regardless of where they're based. A platform incorporated in another country with a meaningful UK user base is in scope.

The methods Ofcom considers highly effective

Ofcom's guidance lists methods capable of meeting the HEAA bar, including:

  • Photo-ID matching: the user submits an identity document and a selfie, matched against each other.
  • Facial age estimation: an AI model estimates age from a face image without identifying the person.
  • Mobile-network operator checks: confirming the account isn't subject to child filters, signalling an adult account holder.
  • Credit card checks: UK credit cards are only issued to adults.
  • Open banking: confirming age via the user's bank.
  • Digital identity wallets and services: reusable digital ID that carries a verified age attribute.
  • Email-based age estimation: inferring adulthood from how an email address is used across services.

What does not pass: self-declared ages, general terms-of-service disclaimers, or payment methods available to minors (debit cards). Ofcom also expects the method to be applied in a way that actually blocks under-18s, not as a bypassable speed bump.

The inclusion of digital identity wallets is the detail worth pausing on. The regulator has effectively pre-approved the reusable-credential model: prove your age once to a trusted provider, then present that proof anywhere it's needed.

Enforcement: real fines, real actions

The penalty ceiling is the headline: up to £18 million or 10% of qualifying worldwide revenue, whichever is greater. For a large platform, that's an existential number. Ofcom can also seek court orders requiring payment providers, advertisers, and ISPs to withdraw services from a non-compliant site. These business disruption measures can amount to a UK blackout.

And enforcement is not theoretical. Ofcom opened investigations into adult services shortly after the July 2025 deadline and has since taken action against providers that failed to implement adequate age checks, including fines and formal enforcement programmes covering services that ignored the rules. The precise tally keeps moving, but the direction is clear: the regulator went after the most obvious non-compliers first and is working down the list. Being small or offshore has not proven to be protection. Several early targets were exactly that.

The criticism: VPNs and the privacy trade-off

The rollout was not smooth. Within days of the July 2025 deadline, VPN apps surged to the top of the UK app-store charts as users routed around age walls, a pattern critics had predicted and which mirrors what happened in US states with similar laws (see our breakdown of US age verification laws). Civil-liberties groups argued the regime drives users to less-safe corners of the internet while normalising identity checks for browsing.

The privacy concern is the substantive one for platform operators. Per-site verification means sensitive viewing behaviour gets linked to verified identities across dozens of databases, each one a breach waiting to happen. Ofcom's guidance acknowledges this and points to data-protection law, but the structural problem remains: the more sites independently collect ID, the larger the attack surface.

Both criticisms point to the same conclusion. The problem isn't age assurance as a concept; it's the per-site, repeat-verification implementation of it.

What a sane architecture looks like

A one-time-verified reusable credential addresses both failure modes at once. The user verifies their age a single time with an issuer, receives a signed credential in their own wallet, and presents only the "over 18" claim to each service: no name, no document image, no account linkage.

  • Friction collapses. A returning-user age check becomes a one-tap presentation instead of a document upload, which removes the main incentive to reach for a VPN.
  • Privacy exposure shrinks. The platform never holds identity documents; it verifies a cryptographic signature. There is no honeypot to breach and far less personal data to govern.
  • It's squarely within Ofcom's framework. Digital identity services are on the regulator's list of highly effective methods. This isn't a workaround, it's the option the guidance points toward.

The same logic is being adopted at EU level, where the Commission's age-verification blueprint is built on exactly this credential model, covered in our piece on age verification under the EU DSA. A platform that integrates standards-based credentials once is positioning for UK, EU, and US compliance simultaneously, rather than bolting on a different vendor flow per jurisdiction.

If reusable verification is new territory, our explainer on reusable KYC covers how the model extends beyond age to full identity verification.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, and earn every time it's used. Join the waitlist at openkyc.org.

This article is general information, not legal advice.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist