Turning online-safety law into operating requirements and enforcement
Ofcom
Ofcom is the UK regulator implementing the Online Safety Act. It translates statutory duties into codes, guidance, information demands and enforcement, making consequential choices about age assurance, platform risk and crisis responses while considering proposals from campaigners and technology suppliers.
Ofcom is a public authority with the power to turn the UK's Online Safety Act into operational expectations for online services. Parliament supplies the statutory framework; the regulator issues guidance and codes, obtains information and enforces duties. That position makes its decisions more consequential than a campaign statement or a vendor's claim that its product solves a safety problem.
Its January 2025 age-assurance decision shows the choices involved. Ofcom set criteria for accuracy, robustness, reliability and fairness. It added email-based age estimation to the methods capable of meeting the standard, expressly crediting evidence from the Age Verification Providers Association and VerifyMy. It also added conditional references to age tokens after submissions from 5Rights and others. These decisions can expand the set of tools a regulated business considers buying or building.
The same decision rejected some requested requirements. Ofcom declined fixed numerical performance thresholds at that stage and rejected mandatory independent certification. It treated privacy as a duty already imposed by data-protection law, while strengthening design and data-minimization guidance. These are substantive choices about how much discretion remains with companies, assessors and other regulators. The agency also reported imposing a £700,000 age-assurance penalty and a separate £30,000 information penalty on the provider of Xgroovy.com in September 2026.
Ofcom's remit reaches beyond age checks. Its crisis-response work addresses preparation, records and public accountability, while its non-consensual-intimate-image work has recommended StopNCII as one suitable option. Across these cases, the institution chooses how a broad legal obligation becomes a practical process. That is why the map repeatedly returns to Ofcom when tracing who ultimately sets the rules.
Ofcom → Ofcom highly effective age assurance framework
allows certification as evidence without making it mandatory or sufficient for
Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.
Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.
OSA protest-expression safeguards letter — August2025 → Ofcom
requested clarification, transparency and conditional remedies
2025-08-04 – 2025-08-04
The letter seeks clarity about OSA/protest-expression effects, transparency and impacts, appeal/restoration where appropriate and independent dispute mechanisms. Proscription/detention and legal claims remain attributed; no regulator receipt, response or implemented remedy is established.
declined extending formal crisis-contact obligations to NGOs/fact-checkers
2026-06-09 – 2026-06-09
The statement records requests for formal contacts and real-time access, encourages relevant collaboration, but declines extending formal contact obligations beyond police. This is a class-level disposition, not proof that every Full Fact data-access demand was individually resolved.
Ofcom → Ofcom highly effective age assurance framework
declined proposed fixed numerical thresholds in initial guidance for
Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.
Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.
Volume3 2.19/fn11 identifies OSAN25-26;2.20-21 retains reasonable grounds to infer all necessary offence elements and context-sensitive judgment, citing expression costs. It agrees criminal beyond-reasonable-doubt is not the test; this is no court judgment.
Ofcom → Crisis revenue accounting and refunds — CMA proposal
declined to recommend specific monetization practices
2026-06-09 – 2026-06-09
Ofcom explicitly records CMA's revenue/refund request and declines to recommend specific monetization practices for the crisis protocol. Providers retain proportionate advertising-integrity choices; this does not decide CMA's other proposals.
Ofcom → Email-based age estimation as a HEAA-capable method
added to methods capable of highly effective age assurance
Decision of 16 January 2025.
Statement paragraphs 3.85 to 3.87 explicitly credit AVPA and VerifyMy evidence; final Part 5 paragraph 4.17 includes the method. Capability depends on effective implementation. No approval of a named vendor or purchased service is inferred.
added conditional references after token submissions
January 2025 statement.
Ofcom recorded token submissions from 5Rights, Yoti and ACT and added references in guidance.A token is not itself an assurance method: underlying age check and sharing must satisfy HEAA, and the regulated service retains responsibility.
The accepted root operational note records Ofcom's statement 3.46–47/footnote29, PDF17, identifying Full Fact's response p17 and an Ofcom/DSIT meeting on 4 August 2025 as inputs to questions about the interaction. Ofcom's resulting amendment says providers should consider an Ofcom public statement notice alongside their other indicators.
The strongest rival to a direct ministerial-trigger lobbying account is that Ofcom resolved an interaction surfaced by differently framed stakeholder inputs. The remaining discriminating record is the 4 August2025 Ofcom/DSIT meeting note or drafting record showing what was asked, by whom, and how the final wording was chosen. Root owns that separate public search.
The accepted statement's cover date is 9 June; the current Ofcom roadmap and regulatory index call the crisis announcement/publication 18 June, while government records establish laying 18 June. These dates are retained as source-specific metadata and procedural events, not silently normalized into one date. This packet does not establish the reason for the publication-label difference.
The network is a submitter and advocate in these records. Woods and Walsh are named authors of the July response, not thereby statutory committee members or holders of regulatory approval rights. Targeted Ofcom searches did not establish a formal appointment for either; an unrelated result names Siobhan Walsh , not Maeve Walsh. This pass makes no claim that no formal role exists anywhere.
FOI response24 March 2026; individual dates not obtained
Reported by the cited source
ICO describes team-dependent fortnightly/quarterly meetings when refusing a broad records request. Does not attribute every meeting to Reddit or establish particular decision instructions.
Royal Assent 26 October 2023; relevant commencement and duty dates recorded separately.
Section 82 requires guidance for section 81, including examples and compliance principles. Schedule 4 paragraph 12 links relevant children-code age measures to HEAA. The statute does not certify providers.
16 January 2025; Part 3 updated 24 April 2025; current page updated 2 September 2026.
The January 2025 decision sets technical accuracy, robustness, reliability and fairness criteria, with final Part 3 and Part 5 guidance. The whole process must meet the criteria. Not all services must use age assurance.
Statement paragraphs 3.85 to 3.87 explicitly credit AVPA and VerifyMy evidence; final Part 5 paragraph 4.17 includes the method. Capability depends on effective implementation. No approval of a named vendor or purchased service is inferred.
Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.
Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.
Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.
Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.
Ofcom reports issuing a confirmation decision on 3 September 2026 and announced it on 4 September, concerning a section 12 breach. The underlying non-confidential decision has not yet been published. The reported penalty is not evidence of payment or a court judgment.
The reported section 102(8)(a) penalty concerns failure to respond. It is separate from the GBP 700,000 age-assurance fine. The conditional GBP 200 daily penalty is not added to this fixed amount; collection has not been observed.
Ofcom named 5Rights' request then declined adding a separate privacy criterion because data-protection requirements already apply. It also clarified design/minimisation guidance and said both regimes are mandatory.
Counterpart disposition of a specific NGO submission; guidance clarification is not assigned solely to 5Rights.
Ofcom recorded token submissions from 5Rights, Yoti and ACT and added references in guidance.A token is not itself an assurance method: underlying age check and sharing must satisfy HEAA, and the regulated service retains responsibility.
A concrete clarification following submissions; not exclusive attribution to 5Rights or blanket acceptance of token systems.