Ofcom's own report calls Britain's rollout of child age checks 'unprecedented.' The one number that measures whether it actually worked barely moved.
Estimated reading time: 7 minutes
In short. Ofcom's first statutory report on age assurance under the Online Safety Act, published 15 July 2026, says age checks are being deployed "at an unprecedented scale": 69 million completed across 32 services in six months, a 23-fold increase. The report's own Children's Online Safety Tracker data tells a flatter story: 73% of children aged 11 to 17 recalled seeing harmful content in the four weeks before the survey, against 70% before the child safety duties took effect, which the report itself calls "little change." Four of the social media services Ofcom examined use age inference, a method its own guidance does not list as capable of being highly effective, as their first line of defence, and four out of five using facial age estimation have not added the safeguard Ofcom recommends against misclassifying children as adults. Three documented mistakes: four stars.
Ofcom is required, under section 157 of the Online Safety Act 2023, to report on how regulated services have used age assurance and whether it has worked. Its first report under that duty, "Report on the use of age assurance," was published on 15 July 2026 and sent to the Secretary of State to be laid before Parliament [1]. The regulator's own framing of the findings is confident. Age checks, it says, are "being deployed at an unprecedented scale, ensuring the UK is at the forefront of global efforts to make online experiences safer for children" [1]. The report itself puts a number on the scale: "Between July and December 2025, over 69 million age checks were completed across a sample of 32 services operating in the UK and analysed in this report, a 23-fold increase on the previous six months" (page 3) [2].
Scale is not the same as effect, and the report's own evidence on the effect is thinner than the framing suggests.
The number that was supposed to move
Buried in the social media chapter, not the overview, is the report's actual before-and-after comparison of harm. "Wave 2 of COST, published in May 2026, found that 73% of children aged 11 to 17 recalled exposure to at least one piece of harmful content in the four weeks before the survey. This is broadly consistent with Wave 1 results from March 2025 to April 2025, where the equivalent figure was 70%" (page 39) [2]. Wave 1 was fieldwork before age assurance existed. Wave 2 was fieldwork four to five months after the child safety duties came into force. The report's own conclusion from its own data: "This suggests little change in recalled exposure to harmful content following the children's safety duties coming into force" (page 39) [2].
That is the one number in the whole document that tracks the same children's-reported experience before the checks and after them. It moved three points in the wrong direction. Every other headline figure in the report, the 69 million checks, the 23-fold increase, the top-100 porn sites now gating access, measures activity, not outcome: how many age checks happened, not how much harm they stopped.
A separate survey cited in the same section softens this slightly. Among children with a social media profile, 56% noticed some change to their online experience since July 2025, but only 11% said they could no longer access content or features they previously could, and 16% said they saw less upsetting content (page 39) [2]. Most of the noticed "change" was not the kind the duties exist to produce.
Four services are using the method Ofcom says isn't on the list
The report's social media chapter distinguishes two approaches: an "active age-gated content approach," where a check only triggers when a user tries to reach restricted content, and a "passive age inference approach," where a service infers a user's age from behaviour after they have simply declared it. On the second method, the report is direct: "A passive age inference approach, whereby users declare their age upon access and age inference models are used to subsequently infer whether a user is an adult or a child... Age inference is not included in our non-exhaustive list of methods that are capable of being highly effective in our HEAA guidance" (page 36) [2]. Despite that, "Four analysed social media services used age inference as the first layer of their age-assurance approach... The age inference models on all four services were developed by the service itself and based on proprietary technology" (page 38) [2].
The report's own overview sets out what it expects to happen next: "Services that use age inference should replace or supplement it with other method(s) of age assurance that our HEAA guidance sets out as being capable of being highly effective, unless they can demonstrate using reliable evidence that the way they are deploying these models is highly effective in line with our HEAA guidance, and fulfils UK data protection obligations" (page 5) [2]. That is a "should," addressed to services that have already had a full reporting cycle to get it right, not a finding that any of the four has stopped.
The services that did adopt Ofcom's preferred, active-gating approach have their own gap. All five analysed services using that approach offered facial age estimation, but "Four out of five of the analysed social media services in question used facial age estimation without implementing a challenge age approach," the safeguard Ofcom says reduces the risk of a borderline child being wrongly classified as an adult (page 36) [2].
A catalogue of gaps, and no name attached to any of them
Section 8 of the report, "Summary of issues and suggested improvements," lists what a year of monitoring actually found across the industry: services using facial age estimation without a challenge age; services using facial estimation or photo ID matching without liveness detection, which the report says "reduces the risk of children using still images of adults or prerecorded videos to circumvent these methods" (page 65) [2]; services relying on a single one-time check with no repeat verification; and services with "not fully implemented an appeals process to restore a user's access where they have incorrectly had it restricted" (page 66) [2]. Every remedy in that section is phrased as "should," "we expect," or "we advise." The report's own framing of the exercise is that "throughout this report we have highlighted areas where we observed that analysed services' age assurance implementation has fallen short of our expectations and is not in line with our HEAA guidance," and that "services should implement the necessary changes as a matter of urgency" (page 65) [2]. No service is named against any specific shortfall, and the report records no enforcement action tied to any of them.
That silence is not because Ofcom has no enforcement record to point to. On 4 September 2026, three weeks before this piece, Ofcom fined the operator of a pornography site £700,000 for having no age checks in place between July and November 2025, plus £30,000 for ignoring a legally binding information request, and separately confirmed provisional decisions against two more providers over age-check failures [3]. The regulator plainly has both the appetite and the machinery to fine a named company. The mechanism runs against pornography providers that never implemented checks at all. It has not, on the evidence in this report, been pointed at social media services that implemented checks using a method Ofcom's own guidance says does not count.
The claims, tested
| The report's own words | What the report's own data shows | Verdict |
|---|---|---|
| Age checks are "being deployed at an unprecedented scale, ensuring the UK is at the forefront" (webpage summary) [1] | The only before-and-after measure of children's actual exposure to harm, Wave 1 to Wave 2 of the Children's Online Safety Tracker, moved from 70% to 73%, which the report itself calls "little change" (page 39) [2] | Activity scaled up; the measured outcome did not follow |
| Age inference "is not included in our non-exhaustive list of methods that are capable of being highly effective" (page 36) [2] | Four analysed social media services use it as their first layer regardless (page 38) [2], told only that they "should" switch or prove it works (page 5) [2] | A named non-compliant method, no named consequence |
| "We will not hesitate to take enforcement action against services based on the risk of harm they pose" (webpage summary) [1] | Ofcom's enforcement record in the same period runs against pornography and file-sharing services with no checks at all, not against any of the social media shortfalls this report itself documents [3] | The enforcement machinery exists; it has not yet reached this report's own findings |
The mistakes, counted
The headline framing of scale is not matched by the report's own outcome data (1). "Unprecedented scale" and a "23-fold increase" in checks (page 3) [2] describe activity. The one measure of actual harm to children the report tracks before and after, recalled exposure at 70% and then 73%, moved in the wrong direction, and the report says so itself in the paragraph that reports it, not in the overview (page 39) [2].
A method the report says is not highly effective is in active use by four social media services, with no named consequence (2). Age inference is explicitly excluded from Ofcom's own list of methods capable of being highly effective (page 36) [2], yet four services use it as their first layer (page 38) [2], and the report's response is advisory, not enforcement (page 5) [2].
A full section catalogues industry-wide gaps, without naming a single service against any of them (3). Missing challenge ages, missing liveness detection, missing appeals processes (pages 65 to 66) [2] are set out as generic observations for "services" in general, while Ofcom's real, named, fined enforcement actions in the same period are all against a different category of provider entirely, adult sites with no checks in place [3].
Credit where due
The report does not read as a whitewash. It states its own contrary finding in plain language rather than burying it: "little change in recalled exposure to harmful content" is Ofcom's phrase, not this site's (page 39) [2], and it names the age-inference gap and the missing challenge-age safeguard itself rather than waiting to be asked. On pornography specifically, the same report records that "all of the UK's top 10 and the majority of the top 100 porn sites now have age checks in place" [1], and the September enforcement action against a provider that had none shows the regulator following through on that part of the duty with a real, published, named fine [3]. The regulator has also committed to a further, harder test: a rapid assessment of age checks for under-16s, due to Parliament "by the end of October" to inform the government's planned social media age restriction (page 4) [2], a deadline that gives this report's own gaps a near-term chance to be closed rather than restated next year.
Verdict
Four stars, from three documented mistakes. This is not a case of a report hiding its own bad news; Ofcom states the flat harm-exposure figure and the age-inference gap in its own words, on the page, with citations. The mistake is what happens between the finding and the response: a method the regulator's own guidance excludes remains in active use by named categories of service with no named consequence, a page of catalogued shortfalls addresses "services" in the abstract, and the one enforcement record that exists this year points entirely at a different, simpler failure, no checks at all, rather than at the harder problem of checks that exist but do not meet the standard. Scale is real. Whether it has protected children is, on the regulator's own numbers, still an open question.
Sources
- Use of Age Assurance Report 2026, Ofcom, published 15 July 2026, last updated 27 July 2026
- Report on the use of age assurance (PDF), Ofcom, prepared under section 157 of the Online Safety Act 2023, published 15 July 2026
- Porn site deploys age checks as Ofcom fines it £730,000, Ofcom, published 4 September 2026