Ofcom is turning age checks into infrastructure. Platforms will hate the trade-offs
Ofcom telling tech firms to keep underage children off their platforms sounds like a parenting headline. It is really a systems headline. Age checks are becoming infrastructure.
The internet is being pushed into an awkward fork. Either age gates stay flimsy and children keep slipping into adult spaces, or platforms build serious assurance that collects more sensitive data and creates a bigger breach target. The ‘solution’ can quietly become a new identity layer for everyday life.
That trade-off will not be solved by slogans about safety or privacy. It will be solved by evidence. If a platform claims it can enforce minimum age rules, it should be able to show how it tests circumvention, what its false positives look like, how it handles edge cases, and how little data it keeps. If it outsources the checks, responsibility should not vanish into the supply chain.
There is also a gaming-shaped wrinkle. Services like Roblox sit at the intersection of play, social media, and payments. An age check that is ‘good enough’ for video can be dangerously weak for chat, user-generated content, and in-game commerce.
Questions for comment:
- What counts as ‘highly effective’ age assurance without turning the web into an ID checkpoint?
- Should age estimation be treated as biometric processing by default, with stricter limits?
- Who should carry liability when age assurance fails: the platform, the vendor, or both?
- What should be banned outright: self-declared age, credit card checks, or face-based estimation?
- How should Ofcom measure success: reduced harm, reduced exposure, or documented compliance?


