Age checks are becoming critical infrastructure. Ofcom’s guidance makes the trade-off unavoidable
Ofcom’s guidance on highly effective age assurance is a signal that the Online Safety era is moving from principles to plumbing.
Age checks used to be a checkbox and a pop-up. Now they are becoming an end-to-end system that decides who can see what, when, and at what cost to privacy. That matters because the internet is drifting towards two extremes: services that do nothing beyond self-declared age, and services that demand a level of identity proof that feels like surveillance.
The uncomfortable truth is that both approaches can fail. Self-declaration fails by letting children through. Heavy-handed verification fails by normalising sensitive data collection and creating new breach targets. It also pushes people towards workarounds and grey markets, which is exactly where child protection breaks down.
A better standard is evidence, not promises. If a platform claims it can keep children out of high-risk spaces, it should be able to show accuracy rates, circumvention testing, failure handling, and strict data minimisation. If a vendor provides the check, liability should not vanish into the supply chain.
We'd like your views:
- What does "highly effective" look like without turning the web into an ID checkpoint?
- Should age estimation be treated as biometric processing by default?
- Who should be liable when an age assurance vendor fails: the platform, the vendor, or both?
- What should be banned outright: self-declaration, credit card checks, or facial estimation?
- How should regulators measure success: reduced harm, reduced exposure, or documented compliance?


