As observed 9 September 2026, the Online Safety Act duties and Ofcom's implementation require highly effective age assurance (HEAA) for defined services and harmful-content risks. They do not create a universal identification requirement for everyone using the internet. The consequential influence record is unusually explicit: Ofcom credited AVPA and VerifyMy evidence when adding email-based age estimation to its examples of methods capable of HEAA. That is acceptance of a method-level contribution, not approval of the company, procurement, demonstrated deployment performance or evidence of a payment.
The [Online Safety Act 2023](http[local research file] assented to on 26 October 2023, defines a child as under 18 (section 236, PDF 218/printed 204). Section 230 (PDF 212/printed 198) distinguishes verifying exact age from estimating age or age-range; a bare self-declaration is neither. Identity-document matching is one possible method. Facial age estimation is another. The final Part 5 guidance explains that open banking can pass an over-18 result without passing date of birth or other information to the relying service (paragraph 4.12, PDF 17). A token can communicate a completed age check; it is not itself the underlying age-assurance method.
| Decision or duty | Precise scope and timing |
|---|---|
| OSA section 81, [current official text](http[local research file] | Part 5 provider-published pornography: use verification/estimation so children are not normally able to encounter it; method and deployment must be highly effective. Also record methods/privacy consideration and publish a summary. Official commencement annotation: 17 January 2025, SI 2024/1333 regulation 2(1)(a). |
| OSA section 12, [current official text](http[local research file] | User-to-user services likely to be accessed by children: proportionate protection duties. Sections 12(4)–(6) require HEAA for identified primary-priority content unless that kind is prohibited for all users by the terms. A prohibition does not remove the broader protection duties. This covers more than pornography: section 61 includes suicide, self-injury and eating-disorder encouragement/instructions. |
| OSA sections 35–36 | All Part 3 user-to-user and search services assess children's access. The statutory test examines actual use/likely attraction, not just the intended audience. Claiming children cannot access requires verification/estimation that actually excludes them. Initial access-assessment deadline: 16 April 2025. |
| OSA section 82 and Schedule 4 paragraph 12 | Ofcom must give Part 5 guidance with examples and compliance principles; the children's codes must recommend HEAA for the section 12(3)(a) duty and have regard to that guidance. Statutory guidance obligation is distinct from certification of vendors. |
| Final Protection of Children Code | Statement/guidance 24 April 2025; issued code cover dated 4 July 2025 and in force 25 July 2025. Initial children's risk-assessment deadline 24 July 2025. See [issued user-to-user code](http[local research file] |
The section 12 commencement annotation says 10 January 2024. That should not be confused with the operational compliance deadline after the statutory assessment/code process: Ofcom's dated implementation table and enforcement case expressly identify 25 July 2025 for these children's safety duties. The [current implementation dates table](http[local research file] preserves the sequence.
The code's recommendations are a statutory route to compliance, not every word a freestanding legislative prohibition. OSA section 49(1) treats relevant recommended measures as compliance;49(5)–(6) accommodates alternative measures subject to scrutiny and privacy/expression safeguards. Section 50(1) says failure to follow a code provision does not itself create court/tribunal liability. The underlying duties remain mandatory.
The issued code, PDF 20–27 (printed 21–28), distinguishes service-wide adult access controls for services principally hosting primary-priority/priority harmful content (PCU B2/B3) from content/feed protections (B4–B7). For B4–B7 it allows appropriate restrictions to remain on users who do not elect to prove adulthood, rather than demanding a document from every user. Each measure has its own content/risk/functionality conditions; B7 excludes bullying from its priority-content trigger. Search services have children's-access and protection duties, but not the same HEAA duty as user-to-user services to prevent access to pornography. Ofcom's July 2026 report paragraph 4.34, PDF 31, makes that distinction expressly.
The [16 January 2025 statement](http[local research file] provides the decision record. Its currently linked attachment carries a 16 May 2025 listing date, while the PDF cover says16 January 2025; no new decision date is inferred from the media listing or URL query.
Paragraphs 3.85–3.87, PDF 27: AVPA/VerifyMy evidence supported adding email-based estimation, conditional on effective implementation. Paragraphs 3.103–3.105, PDF 30–31: token references were added, retaining responsibility for the underlying check and sharing process. The preceding response summary, paragraphs 3.66–3.68 and footnote 94 on PDF 24, attributes the token recommendation to 5Rights, Yoti and the ACT App Association. Paragraph 3.108, PDF 31, and 3.350–3.353, PDF 76–77: certification can evidence compliance but is neither compulsory nor automatic; Ofcom did not adopt Yoti's request to mandate independent testing/certification. Paragraphs 3.243–3.259, PDF 54–57: requested numerical thresholds were declined at that stage, citing inadequate comparable evidence/testing and market-development concerns. Paragraphs 3.277–3.290, PDF 62–65: 5Rights' separate privacy-criterion proposal was declined because existing data-protection law applied; design/minimisation guidance was strengthened. None of these outcomes proves a private bargain or sole authorship.
The [April 2025 children's statement Volume 4](http[local research file] paragraphs 13.343–13.357, PDF 204–207, separately handles behavioural age inference. It rejected adding inference to the HEAA examples: evidence of efficacy was insufficient and inference needs a period of on-service activity. That is incompatible with keeping children out of a harmful-content service from entry. For services children may use, Ofcom left an evidential route for a wider process, requiring proof of accuracy, timing, protection during the inference interval, reliability and fairness. Email-based estimation from other established service uses is not interchangeable with this behavioural on-platform inference.
A short official [FOI response2053425](http[local research file] dated 26 August 2025 despite its October folder, is particularly useful. PDF 2 Q3 says Ofcom does not certify/approve specific vendors and had no vendor contracts or MOUs. Q4 says Ofcom has no access to data users submit to those vendors; it expressly does not answer for other authorities. These are dated institutional statements, not a current independent audit of data flows or proof that platforms and vendors cannot access data. Q5 rejects a general internet-wide age-check requirement.
The [July 2026 statutory report](http[local research file] cover 15 July 2026, describes early findings predominantly from the first six months after July 2025 duties, not final causal proof. Paragraphs 5.30–5.35, PDF 42–43, retain the inference concerns; its sampled service evidence does not justify claiming every listed method works in every deployment. The 2 September resource follows these identified implementation shortcomings.
The [Xgroovy case update](http[local research file] case CW/01318/09/25, distinguishes a 16 June 2026 provisional notice from a 3 September confirmation decision, announced 4 September. Ofcom reports a £700,000 section 12 penalty and a separate £30,000 section 102(8)(a) information-request penalty, plus a conditional daily information penalty. The underlying non-confidential confirmation decision is still promised for later publication. Record these as reported imposed penalties, not money collected or a court judgment. The case identifies the provider by service, not a resolved legal-company name.
The strongest rival to a vendor-capture reading is disclosed technical consultation within a technology-neutral regime: one commercial method was accepted, while commercial certification and threshold requests were not adopted wholesale. The missing discriminating records are the complete technical evidence submitted for email-based estimation and independent test/evaluation records showing why it met each criterion; any actual procurement/payment or contractual link needs its own evidence. The market lane owns the vendor counterpart route; the advocacy lane owns original 5Rights submissions and should reuse this statement source for disposition.
Further public acquisition stops at this coherent packet. Reopen the enforcement branch when the non-confidential Xgroovy confirmation decision is published, and the prospective 16+ branch when the actual assessment, legislative instrument and commencement arrangements appear. Nothing here assesses the separate national digital-ID project's status; that belongs to root's currentness check. Do not turn its cancellation or continuation into a conclusion about OSA age assurance or the separate DVS framework.
Original bytes retained: enacted Act and current section 12/81 HTML, with hashes. Ordinary Ofcom GETs returned 403; the public web reader was the successful substitute. Ofcom captures are scoped derivative reader outputs with extract hashes only—no original PDF/HTML hash is claimed. Source-level locators and actual read extents are in policy-candidate.json; manifests distinguish error-response hashes from originals. The old /illegal-and-harmful-content/age-assurance path returned 404, while the actual current linked /protecting-children/age-assurance route was read. No paid access, outreach, restricted-route workaround or canonical edits.