Age Verification Under the Online Safety Act: What 'Highly Effective' Actually Means in Practice
The "I confirm I am over 18" checkbox is dead in UK law, at least for any service that has actually read section 81 of the Online Safety Act 2023. The statutory text is short and, for once, refreshingly specific: a provider of regulated pornographic content must use age verification or age estimation "of such a kind, and used in such a way, that it is highly effective at correctly determining whether or not a particular user is a child." No definition of "highly effective" follows in the Act itself. That was left to Ofcom, and the guidance it produced is more interesting than the average regulatory document, mostly because it has now been tested against real services, real fines, and a report full of numbers that undercut some of the industry's own marketing.
Four criteria, not a list of approved tools
Ofcom deliberately avoided writing a list of acceptable technologies into the guidance. Instead it set out four properties that any method, whatever it is, has to demonstrate:
- Technical accuracy: does the method actually measure what it claims to measure, under real conditions rather than lab conditions.
- Robustness: does it resist straightforward circumvention, a photo of a photo, a borrowed ID, a VPN that just changes the billing country.
- Reliability: does it perform consistently across the population it is checking, not just on the demographic the model was trained on.
- Fairness: does it work without materially worse outcomes for particular groups, and does it treat a wrongly-rejected adult reasonably.
The guidance adds that a method also has to be easy to use and interoperable enough not to lock users into one provider. That is a genuinely sensible way to regulate, because it is tech-neutral: it does not freeze the standard around whatever happens to work in 2026, and it does not hand a state-mandated monopoly to whichever vendor got their lobbying in first. It also means "highly effective" is not a certificate you get once. It is a standard a provider has to keep meeting as the population, and the attackers, change.
What it rules out is easier to state than what it allows: self-declaration, a birthdate field with no verification behind it, a checkbox, and anything relying purely on contractual terms ("by using this service you confirm you are 18"). None of those measure anything. Ofcom's list of methods it considers capable of being highly effective, when implemented properly, includes photo-ID matching, facial age estimation, open banking checks, mobile network operator age checks, and reusable digital identity services. Email-based age estimation sits on the list too, on the basis of account signals rather than the email address itself, though it is generally treated as weaker evidence than the others.
Part 5 versus Part 3: not the same duty
It is worth being precise about which duty applies where, because the Act does not impose one uniform age-check obligation. Part 5 (section 81) covers services that publish their own pornographic content: the duty is absolute, children must not normally be able to encounter it, and "highly effective" age assurance is the mechanism for achieving that. Part 3 covers user-to-user and search services likely to be accessed by children more generally, TikTok, Reddit, whatever comes next. There, age assurance sits inside a broader risk-based duty under Ofcom's Protection of Children Codes: a platform has to assess the risk its service poses to children and apply proportionate measures, which may or may not mean full "highly effective" age checks depending on what the risk assessment finds. A children's social network and a general-purpose forum with an 18+ subforum are not held to identical technical bars, even though both might end up using similar tools.
What the accuracy numbers actually look like
Facial age estimation is the method getting the most real-world use, so its published accuracy figures are a useful sanity check on what "highly effective" costs in practice. Yoti, one of the larger providers, reports a mean error of around 1.1 years when estimating the age of 13 to 17 year olds, and says it correctly identifies 99.3% of that age group as under 21. That sounds precise, and for a binary "under 18 or not" gate it mostly is, because the useful signal is not the exact age guess, it is how confidently the model can place someone on the correct side of a threshold several years wide. Where it gets harder is right at the boundary: distinguishing a 17 year old from an 18 year old on facial features alone is a genuinely different, much noisier problem than distinguishing a 13 year old from a 25 year old. Ofcom's own 2026 report on the use of age assurance says as much, noting "serious doubts" about the effectiveness of some age inference models at exactly that margin, and warning that a meaningful number of children could still be getting through methods that look statistically strong in aggregate.
The same report has the one number that matters most for judging whether any of this is working: the proportion of children who, when tested, actually encountered a highly effective age check rose from 25% in July 2025 to 43% by January 2026. Progress, clearly, but also a plain admission that well over half of the children Ofcom sampled still were not being properly gated six months after the Part 5 deadline had passed.
Enforcement has started, and it is not symbolic
The clearest illustration of what "highly effective" means in practice is not the guidance document, it is Ofcom's enforcement record. In 2026 it fined the pornography site Fapello.com £630,000, £600,000 for the underlying section 81 failure between July and November 2025, and £30,000 on top for not responding properly to a statutory information request. Fapello had geoblocked the UK by the time the fine landed, having tried and then abandoned age checks. That did not help: the fine covered the period the site was live and non-compliant, and leaving the market afterwards does nothing to un-happen the months it spent without any real age gate. Ofcom has said explicitly that it is prioritising enforcement against porn sites that are gaining UK traffic precisely because they have not put checks in place, which is the obvious adverse-selection problem with partial enforcement: sites that comply lose the users who specifically wanted a service without age checks, and those users go to whichever site is still non-compliant.
The data protection side nobody can skip
Highly effective age assurance nearly always means processing something sensitive, a face, an ID document, an open banking record, and that pulls UK GDPR into the picture alongside the Online Safety Act. The ICO and Ofcom published a joint statement in March 2026 specifically to head off the argument that a Part 5 duty somehow excuses a provider from ordinary data protection principles. It does not. Data minimisation, purpose limitation and storage limitation all still apply: a facial age estimation check should use the image to produce an age estimate and then discard it, not retain it as a biometric identifier for some other purpose, and a document check should not become a de facto identity database. None of the technologies Ofcom lists as capable of being highly effective are mandated outright; the joint statement is careful to frame facial age estimation, digital ID and one-time photo matching as current viable examples rather than an approved shortlist, leaving providers to justify their own choice against both regulators' tests at once. In practice this is the part that trips services up: it is one thing to stand up an age check that is technically accurate, it is another to run it in a way that would survive an ICO audit of what happens to the data afterwards.
The VPN problem, and why banning them was never the answer
Every discussion of UK age verification eventually arrives at VPNs, because changing your apparent country is the obvious way around a geographic compliance boundary, and search interest in VPN apps spiked visibly around each enforcement deadline. The government considered and dropped the idea of restricting VPNs, correctly, since a VPN is dual-use infrastructure with entirely legitimate privacy and security purposes for the overwhelming majority of its users, and banning a category of software to catch a subset of its use is exactly the kind of blunt instrument that causes more collateral damage than it prevents. Instead, the current approach puts the onus back on platforms: providers are expected to take reasonable, robust steps to detect and prevent attempts by underage users to circumvent their age assurance, which in practice means treating a sudden shift in a user's apparent location or network characteristics as a signal worth acting on, rather than treating VPN use itself as something to police.
That framing is the more defensible one. It keeps the compliance burden on the service that chose to publish age-restricted content and profit from UK access, rather than pushing it onto a general-purpose privacy tool used for reasons that have nothing to do with the Act. Whether it actually closes the gap is a separate question, and one Ofcom's own numbers suggest is still very much open.