Turning online-safety law into operating requirements and enforcement

Ofcom

Ofcom is the UK regulator implementing the Online Safety Act. It translates statutory duties into codes, guidance, information demands and enforcement, making consequential choices about age assurance, platform risk and crisis responses while considering proposals from campaigners and technology suppliers.

Ofcom is a public authority with the power to turn the UK's Online Safety Act into operational expectations for online services. Parliament supplies the statutory framework; the regulator issues guidance and codes, obtains information and enforces duties. That position makes its decisions more consequential than a campaign statement or a vendor's claim that its product solves a safety problem.

Its January 2025 age-assurance decision shows the choices involved. Ofcom set criteria for accuracy, robustness, reliability and fairness. It added email-based age estimation to the methods capable of meeting the standard, expressly crediting evidence from the Age Verification Providers Association and VerifyMy. It also added conditional references to age tokens after submissions from 5Rights and others. These decisions can expand the set of tools a regulated business considers buying or building.

The same decision rejected some requested requirements. Ofcom declined fixed numerical performance thresholds at that stage and rejected mandatory independent certification. It treated privacy as a duty already imposed by data-protection law, while strengthening design and data-minimization guidance. These are substantive choices about how much discretion remains with companies, assessors and other regulators. The agency also reported imposing a £700,000 age-assurance penalty and a separate £30,000 information penalty on the provider of Xgroovy.com in September 2026.

Ofcom's remit reaches beyond age checks. Its crisis-response work addresses preparation, records and public accountability, while its non-consensual-intimate-image work has recommended StopNCII as one suitable option. Across these cases, the institution chooses how a broad legal obligation becomes a practical process. That is why the map repeatedly returns to Ofcom when tracing who ultimately sets the rules.

Assessment updated 2026-09-12

Detailed records and research

What the records show

OfcomOfcom highly effective age assurance framework

allows certification as evidence without making it mandatory or sufficient for

Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.

Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.

OSA protest-expression safeguards letter — August2025Ofcom

requested clarification, transparency and conditional remedies

2025-08-04 – 2025-08-04

The letter seeks clarity about OSA/protest-expression effects, transparency and impacts, appeal/restoration where appropriate and independent dispute mechanisms. Proscription/detention and legal claims remain attributed; no regulator receipt, response or implemented remedy is established.

OfcomOfcom crisis protocol recommendations — June2026

declined extending formal crisis-contact obligations to NGOs/fact-checkers

2026-06-09 – 2026-06-09

The statement records requests for formal contacts and real-time access, encourages relevant collaboration, but declines extending formal contact obligations beyond police. This is a class-level disposition, not proof that every Full Fact data-access demand was individually resolved.

OfcomOfcom highly effective age assurance framework

declined proposed fixed numerical thresholds in initial guidance for

Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.

Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.

OfcomCrisis revenue accounting and refunds — CMA proposal

declined to recommend specific monetization practices

2026-06-09 – 2026-06-09

Ofcom explicitly records CMA's revenue/refund request and declines to recommend specific monetization practices for the crisis protocol. Providers retain proportionate advertising-integrity choices; this does not decide CMA's other proposals.

OfcomEmail-based age estimation as a HEAA-capable method

added to methods capable of highly effective age assurance

Decision of 16 January 2025.

Statement paragraphs 3.85 to 3.87 explicitly credit AVPA and VerifyMy evidence; final Part 5 paragraph 4.17 includes the method. Capability depends on effective implementation. No approval of a named vendor or purchased service is inferred.

From the investigation

What can be joined to Ofcom's drafting change

The accepted root operational note records Ofcom's statement 3.46–47/footnote29, PDF17, identifying Full Fact's response p17 and an Ofcom/DSIT meeting on 4 August 2025 as inputs to questions about the interaction. Ofcom's resulting amendment says providers should consider an Ofcom public statement notice alongside their other indicators.

Read the research & sources ↗
What can be joined to Ofcom's drafting change

The strongest rival to a direct ministerial-trigger lobbying account is that Ofcom resolved an interaction surfaced by differently framed stakeholder inputs. The remaining discriminating record is the 4 August2025 Ofcom/DSIT meeting note or drafting record showing what was asked, by whom, and how the final wording was chosen. Root owns that separate public search.

Read the research & sources ↗
Crisis: actual parliamentary step located, commencement still unverified

The accepted statement's cover date is 9 June; the current Ofcom roadmap and regulatory index call the crisis announcement/publication 18 June, while government records establish laying 18 June. These dates are retained as source-specific metadata and procedural events, not silently normalized into one date. This packet does not establish the reason for the publication-label difference.

Read the research & sources ↗
Authority and chronology boundaries for integration

The network is a submitter and advocate in these records. Woods and Walsh are named authors of the July response, not thereby statutory committee members or holders of regulatory approval rights. Targeted Ofcom searches did not establish a formal appointment for either; an unrelated result names Siobhan Walsh , not Maeve Walsh. This pass makes no claim that no formal role exists anywhere.

Read the research & sources ↗

Further reading

CMA's monetization proposal and Ofcom's response

UK network submissions: three published dispositions

UK KYBC: government consideration, narrower advertising proposals, and a 2026 industry pathway

Full Fact's request behind the ministerial-notice reference

The cited DSIT meeting and confirmed planning records

Oak support and Statewatch: a specific limit on the common-funder inference

Crisis authority: inputs, decisions and the record left behind

Status of remaining Additional Safety Measures

Baseline evidence custody

UK age assurance: specific advocacy contributions and decisions

UK implementation: platform choice, overlapping regulators and a cancelled national programme

UK age assurance: statutory chain and consequential choices

Read the original sources 5

What the connections say

39 relationships
2

Information Commissioner’s Officereports regular inter-regulator meetings withOfcom

FOI response24 March 2026; individual dates not obtained

Reported by the cited source

ICO describes team-dependent fortnightly/quarterly meetings when refusing a broad records request. Does not attribute every meeting to Reddit or establish particular decision instructions.

Read the original source 1
3

UK Online Safety Act 2023requires age-assurance guidance and relevant code measures fromOfcom

Royal Assent 26 October 2023; relevant commencement and duty dates recorded separately.

Section 82 requires guidance for section 81, including examples and compliance principles. Schedule 4 paragraph 12 links relevant children-code age measures to HEAA. The statute does not certify providers.

Read the original source 1
4

Ofcompublishes and appliesOfcom highly effective age assurance framework

16 January 2025; Part 3 updated 24 April 2025; current page updated 2 September 2026.

The January 2025 decision sets technical accuracy, robustness, reliability and fairness criteria, with final Part 3 and Part 5 guidance. The whole process must meet the criteria. Not all services must use age assurance.

Read the original sources 4
6

Ofcomadded to methods capable of highly effective age assuranceEmail-based age estimation as a HEAA-capable method

Decision of 16 January 2025.

Statement paragraphs 3.85 to 3.87 explicitly credit AVPA and VerifyMy evidence; final Part 5 paragraph 4.17 includes the method. Capability depends on effective implementation. No approval of a named vendor or purchased service is inferred.

Read the original sources 2
7

Ofcomdeclined proposed fixed numerical thresholds in initial guidance forOfcom highly effective age assurance framework

Decision of 16 January 2025; currentness checked against the 2 September 2026 resource.

Paragraphs 3.251 to 3.259 retain a criteria-based approach despite proposed 95% and 99% thresholds, citing inadequate comparable evidence and testing, and innovation considerations. Future thresholds remain possible; the September 2026 resource does not itself impose one.

Read the original sources 2
8

Ofcomallows certification as evidence without making it mandatory or sufficient forOfcom highly effective age assurance framework

Decision of 16 January 2025; FOI response of 26 August 2025; resource of 2 September 2026.

Paragraphs 3.350 to 3.353 decline the request from Yoti for mandatory independent certification. Providers can use their own, vendor or independent tests as evidence. Trust framework certification does not automatically establish compliance. The September 2026 vendor resource maintains this distinction.

Read the original sources 3
9

Ofcomreports imposing an age-assurance duty penalty onProvider of Xgroovy.com

Decision issued 3 September 2026.

Reported by the cited source

Ofcom reports issuing a confirmation decision on 3 September 2026 and announced it on 4 September, concerning a section 12 breach. The underlying non-confidential decision has not yet been published. The reported penalty is not evidence of payment or a court judgment.

Financial details: value: 700,000; currency: GBP; kind: reported imposed regulatory penalty; period: Confirmation decision issued 3 September 2026.

Read the original source 1
10

Ofcomreports imposing a separate information-request penalty onProvider of Xgroovy.com

Decision issued 3 September 2026.

Reported by the cited source

The reported section 102(8)(a) penalty concerns failure to respond. It is separate from the GBP 700,000 age-assurance fine. The conditional GBP 200 daily penalty is not added to this fixed amount; collection has not been observed.

Financial details: value: 30,000; currency: GBP; kind: reported imposed regulatory penalty; period: Confirmation decision issued 3 September 2026.

Read the original source 1
11

Ofcomdeclined separate criterion5Rights privacy criterion proposal · March 2024

January 2025 statement.

Ofcom named 5Rights' request then declined adding a separate privacy criterion because data-protection requirements already apply. It also clarified design/minimisation guidance and said both regimes are mandatory.

Counterpart disposition of a specific NGO submission; guidance clarification is not assigned solely to 5Rights.

Read the original sources 2
12

Ofcomadded conditional references after token submissions5Rights age-token proposal · July 2024

January 2025 statement.

Ofcom recorded token submissions from 5Rights, Yoti and ACT and added references in guidance.A token is not itself an assurance method: underlying age check and sharing must satisfy HEAA, and the regulated service retains responsibility.

A concrete clarification following submissions; not exclusive attribution to 5Rights or blanket acceptance of token systems.

Read the original sources 2

Read the wider story

The big picture

Who gets to operate the switches?

Governments, funders, campaigners and companies exchange different kinds of power. The consequential moment is when someone turns another institution’s input into a decision.

Read the story
Rules & government

How a safety proposal becomes a rule

The UK and Australia offer something stronger than a list of shared contacts: documents showing policy ideas entering official consideration—and changing along the way.

Read the story
Rules & government

Who gets paid to build the machinery?

Public procurement connects policy ambitions with consultants, prototypes and evaluation. A budget announcement is only the beginning of that story.

Read the story