Copy article

Ofcom is turning age checks into infrastructure. Platforms will hate the trade-offs

ended 19. March 2026

Ofcom telling tech firms to keep underage children off their platforms sounds like a parenting headline. It is really a systems headline. Age checks are becoming infrastructure.

The internet is being pushed into an awkward fork. Either age gates stay flimsy and children keep slipping into adult spaces, or platforms build serious assurance that collects more sensitive data and creates a bigger breach target. The ‘solution’ can quietly become a new identity layer for everyday life.

That trade-off will not be solved by slogans about safety or privacy. It will be solved by evidence. If a platform claims it can enforce minimum age rules, it should be able to show how it tests circumvention, what its false positives look like, how it handles edge cases, and how little data it keeps. If it outsources the checks, responsibility should not vanish into the supply chain.

There is also a gaming-shaped wrinkle. Services like Roblox sit at the intersection of play, social media, and payments. An age check that is ‘good enough’ for video can be dangerously weak for chat, user-generated content, and in-game commerce.

Questions for comment:

  • What counts as ‘highly effective’ age assurance without turning the web into an ID checkpoint?
  • Should age estimation be treated as biometric processing by default, with stricter limits?
  • Who should carry liability when age assurance fails: the platform, the vendor, or both?
  • What should be banned outright: self-declared age, credit card checks, or face-based estimation?
  • How should Ofcom measure success: reduced harm, reduced exposure, or documented compliance?

2 responses from the Newspage community

Copy all

Star Quote
Copy

Age assurance that is truly effective should do two things: it should be hard to bypass, and it should not create a new honeypot of identity data.

The trap is looking for one universal mechanism. This needs to be risk-based. For low-risk content, light friction may be enough. For adult content, open chat with minors, payments, and high-volume user generated content, platforms should use stronger controls and be able to show evidence that they work.

The safest direction is privacy-preserving proof of age, not centralised identity. Tokenised attestations or zero-knowledge checks can let a service learn only “over 18” (or “13+”), nothing else. If you use face or voice estimation, treat it as biometric processing by default, with strict limits on retention and vendor reuse.

Liability should follow control. If a platform picks the vendor, it stays accountable, and vendors should share responsibility for failure modes and security.
Copy

Who carries liability when age assurance fails: the platform, the vendor, or both? For small businesses running any kind of online service, this is a nightmare waiting to happen. You're told to implement age checks, but nobody tells you what actually works or who's responsible when it doesn't. If you outsource verification and a child slips through, are you liable? Most small platforms can't afford legal teams to figure that out. Big tech will pass the risk to vendors, vendors will pass it to small businesses, and guess who ends up holding the bag? The smallest player with the least power. We've seen this with GDPR, cookies, accessibility. Compliance gets mandated, responsibility lands on the people who can least afford it, and there's no clear answer on how to do it right. Age assurance is about to become another expensive liability trap for small businesses who just want to operate online.