Europe Industry compliance

UK age assurance pressure rises

This matters for product, legal, trust and safety, and messaging teams operating chat, direct messaging, social features, or account notifications in the UK because Ofcom is turning age assurance into an evidentiary compliance function rather than a policy aspiration. In July 2026, Ofcom published its statutory age assurance report and opened additional consultations for Category 1 services on user identity verification, privacy impact assessments, and complaints. Services relying on age inference now face a higher burden to prove effectiveness, vendor governance, and privacy compliance.

Published:08/04/2026 Updated:08/04/2026

1. Regulatory focus

In its July 2026 《Use of Age Assurance Report 2026》, Ofcom applied a common enforcement logic across social, dating, and other services that may expose children to harm: if a service uses age inference to meet child safety duties, it must prove that the method is “highly effective” or move quickly to stronger age assurance methods. The report also identifies three concrete remediation areas: full alignment with HEAA guidance, regular due diligence on age-assurance vendors, and compliance with privacy and data protection obligations. Outsourcing does not transfer accountability.

2. Business impact

For services with direct messaging, stranger contact, group invitations, content discovery, or account recovery flows, age assurance is no longer a narrow child-safety feature. It now affects onboarding friction, complaint handling, retention, and data-minimisation design. On 10 July 2026, Ofcom also launched its Category 1 additional-duties consultation covering user empowerment, user identity verification, privacy impact assessments, and complaints. If a platform combines messaging features with high-risk social interaction, its policies, vendor terms, risk logs, and audit evidence will need to line up under one defensible compliance record.

3. Operating recommendations

Operationally, teams should first map which messaging journeys expose minors to stranger contact, adult material, or other high-risk interactions, then place age-assurance controls at those specific entry points instead of relying on a one-time age declaration during sign-up. Vendor governance should become a quarterly control covering error rates, appeals and reversals, data retention periods, cross-border processing, and subprocessors. Services should also maintain an Ofcom-ready evidence pack: risk assessments, privacy impact assessments, test results, complaint samples, and documentation explaining fallback or compensating controls where age assurance is not the only safeguard.

Frequently Asked Questions

Can we keep operating in the UK if we only use age inference and do not use face or ID checks?
Possibly, but the standard is not whether a method exists. It is whether you can demonstrate that it is effective for the specific risk being controlled. Where direct messaging, matching, recommendations, or stranger contact can expose minors to higher-risk interactions, Ofcom has signaled that age inference is generally not a default-safe answer. You need supporting test evidence, compensating controls, and a documented upgrade path.
If age assurance is outsourced, who owns appeals, false positives, and data retention responsibility?
The regulated service remains responsible. Contracts should define reversal timelines, human review paths, logging, subprocessor disclosures, and deletion schedules, and those controls should be reviewed regularly. If the vendor fails, Ofcom is still likely to examine whether the platform performed ongoing due diligence and implemented remediation, rather than treating outsourcing as a liability shield.
Our SMS OTP, account recovery, and messaging features are owned by different teams. How should we unify the compliance evidence?
Build records by risk scenario rather than by internal org chart. Put sign-up, recovery, stranger contact, minor visibility settings, and appeals into one control matrix. For each scenario, retain the trigger, control logic, vendor touchpoints, human intervention steps, appeal outcome, and retention rationale. That prevents a common failure mode where the SMS recovery flow is documented but the in-app messaging flow is not.
This article is for informational purposes only and does not constitute legal advice.

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch