1. Regulatory focus
In its July 2026 《Use of Age Assurance Report 2026》, Ofcom applied a common enforcement logic across social, dating, and other services that may expose children to harm: if a service uses age inference to meet child safety duties, it must prove that the method is “highly effective” or move quickly to stronger age assurance methods. The report also identifies three concrete remediation areas: full alignment with HEAA guidance, regular due diligence on age-assurance vendors, and compliance with privacy and data protection obligations. Outsourcing does not transfer accountability.
2. Business impact
For services with direct messaging, stranger contact, group invitations, content discovery, or account recovery flows, age assurance is no longer a narrow child-safety feature. It now affects onboarding friction, complaint handling, retention, and data-minimisation design. On 10 July 2026, Ofcom also launched its Category 1 additional-duties consultation covering user empowerment, user identity verification, privacy impact assessments, and complaints. If a platform combines messaging features with high-risk social interaction, its policies, vendor terms, risk logs, and audit evidence will need to line up under one defensible compliance record.
3. Operating recommendations
Operationally, teams should first map which messaging journeys expose minors to stranger contact, adult material, or other high-risk interactions, then place age-assurance controls at those specific entry points instead of relying on a one-time age declaration during sign-up. Vendor governance should become a quarterly control covering error rates, appeals and reversals, data retention periods, cross-border processing, and subprocessors. Services should also maintain an Ofcom-ready evidence pack: risk assessments, privacy impact assessments, test results, complaint samples, and documentation explaining fallback or compensating controls where age assurance is not the only safeguard.