Copy article

Age checks are becoming critical infrastructure. Ofcom’s guidance makes the trade-off unavoidable

ended 05. March 2026

Ofcom’s guidance on highly effective age assurance is a signal that the Online Safety era is moving from principles to plumbing.

Age checks used to be a checkbox and a pop-up. Now they are becoming an end-to-end system that decides who can see what, when, and at what cost to privacy. That matters because the internet is drifting towards two extremes: services that do nothing beyond self-declared age, and services that demand a level of identity proof that feels like surveillance.

The uncomfortable truth is that both approaches can fail. Self-declaration fails by letting children through. Heavy-handed verification fails by normalising sensitive data collection and creating new breach targets. It also pushes people towards workarounds and grey markets, which is exactly where child protection breaks down.

A better standard is evidence, not promises. If a platform claims it can keep children out of high-risk spaces, it should be able to show accuracy rates, circumvention testing, failure handling, and strict data minimisation. If a vendor provides the check, liability should not vanish into the supply chain.

We'd like your views:

  • What does "highly effective" look like without turning the web into an ID checkpoint?
  • Should age estimation be treated as biometric processing by default?
  • Who should be liable when an age assurance vendor fails: the platform, the vendor, or both?
  • What should be banned outright: self-declaration, credit card checks, or facial estimation?
  • How should regulators measure success: reduced harm, reduced exposure, or documented compliance?

Guidance on highly effective age assurance part 3 guidance

2 responses from the Newspage community

Copy all

Star Quote
Copy

Ofcom is effectively saying age assurance is no longer a pop up. It is critical infrastructure, and the trade off is unavoidable: protect children without turning the web into an ID checkpoint.

The two lazy extremes both fail. Self declared age is theatre. Heavy handed verification normalises sensitive data collection, creates breach targets, and pushes people into workarounds. The standard should be evidence, not promises. Platforms should show accuracy rates, circumvention testing, failure handling, and strict data minimisation. If age estimation is used, treat it like biometric processing, with governance and a route to challenge decisions.

In our AI audits, the biggest risk is supply chain shrugging. Vendors sell the check, platforms outsource responsibility, and nobody owns the harm. If you profit from the traffic, you own the control.

Source: https://app.newspage.media/news-alerts/age-checks-are-becoming-critical-infrastructure-ofcoms-guidance-makes-the-trade-off-unavoidable
Copy

Self-declare age checks are like putting a ‘no kids allowed’ sign on a sweet shop and hoping for the best.
Kids are often more tech savvy than the adults setting the rules. If all you’ve got is “tick this box to say you’re 18”, you haven’t built protection, you’ve built theatre. It doesn’t stop determined teens for even a minute, and it lets platforms pretend they’ve done their bit.
This is why process matters. Clear rules on what “highly effective” means. Evidence it works. Testing for workarounds. Proper failure handling. And strict data minimisation so we’re not swapping child safety for a privacy nightmare.
And accountability has to be visible. Named owners. Audits. Real consequences when checks are weak or bypassed. If the platform makes the money, the platform owns the risk. No hiding behind “the vendor did it”.