The government's ban on under-16s creating livestreams depends on platforms knowing who is under 16. Ofcom's own audit of Instagram, TikTok, Twitch and YouTube found none of them checked.
Estimated reading time: 6 minutes
In short. Ofcom's Behavioural Insight Hub audited how Instagram, TikTok, Twitch and YouTube handle livestreaming, using researcher accounts across four age groups between November 2025 and March 2026. The report ties the exercise directly to the government's incoming restriction on under-16s creating livestreams. Its own results show why that link matters: "On all services included in the audit, age was self-declared at sign-up, and there were no requirements for users to prove their age using highly effective age assurance" (page 5). On one service, under-18s could complete a gift purchase with no friction despite being prohibited under that service's own terms (page 8), and creator moderation tools defaulted to the least restrictive setting on two of the four (page 10). Three documented mistakes: four stars.
Livestreaming is, in Ofcom's own words, "a risky functionality according to Ofcom Risk Profiles, with substantial evidence of child sexual exploitation and abuse (CSEA) risks" (page 4) [1]. It is also, per Ofcom's own research cited in the same document, extremely widely used by children: "71% of children aged 8-17 said they had watched a livestream while 28% said they had livestreamed their own video" (page 4) [1]. To find out how the biggest platforms actually handle that risk, Ofcom's Behavioural Insight Hub ran a structured audit: researcher accounts, screen-recorded, walking through sign-up, discovery, going live, interacting, gifting, safety tools and ending a stream on Instagram, TikTok, Twitch and YouTube, selected "based on their popularity as a livestreaming platform and accessibility for researchers" (page 4) [1]. Fieldwork ran November 2025 to March 2026; the findings report was published 9 September 2026 [2].
The report states plainly why this matters right now, not in the abstract: "It is also relevant to recent announcements by the UK Government that will prevent under-16s from creating livestreams. Livestreaming features will remain available to 16 and 17-year-olds but will be restricted by default" (page 4) [1]. A rule that stops under-16s creating livestreams only works if a platform knows, with some reliability, who is under 16.
The one thing the policy needs, and the one thing none of the four platforms had
The audit's overview is direct about what researchers found when they signed up: "Sign-up flows were designed for speed and may encourage rapid completion, and researchers were not required to complete an age check using methods set out in our highly effective age assurance guidance at sign up" (page 3) [2]. The results section is more specific still: "On all services included in the audit, age was self-declared at sign-up, and there were no requirements for users to prove their age using highly effective age assurance" (page 5) [2]. Two of the four services did tell users how an under-18 account would differ from an adult one, "but this information was provided only after users had signed up and self-declared that they were under-16" (page 5) [2] - a safeguard that only engages after a child has already told the service, honestly, that they are one.
To its credit, the report does not pretend this breaks a legal duty that does not exist. A footnote on the same page is explicit: "There is no requirement in the Act to set a minimum age limit or use highly effective age assurance to enforce any minimum age limit services choose to set" (page 5) [2]. But the report's own reason for existing, cited in its own introduction, is a policy that will need exactly that reliability: an under-16 livestreaming restriction "relevant" enough to name on page 4. And its own footnote on the same finding cites Ofcom's separate qualitative research showing children are already working around self-declaration: "children below the minimum age to livestream on services were still able to livestream regularly by joining friends' livestreams as guest, using parents accounts, or entering a false date of birth" (page 5) [2].
A rule the platform wrote for itself, that its own design did not enforce
Livestreaming gifting is a live money flow: viewers buy virtual currency and send it to creators. Some services restrict who can do that by age. Ofcom's researchers tested whether the restriction held. It mostly did not: "Some services had age-based restrictions for gifting, but these were not enforced on our accounts or were easy to bypass. On one service, under-18s appear able to complete a purchase without any friction, even though they were prohibited under the terms of service" (page 8) [2]. On a second service, the purchase itself was blocked, but "quick-access gift buttons appeared beside comment and reaction buttons, making spending features visible to younger users and potentially more salient, potentially encouraging children to bypass restrictions" (page 8) [2]. This is not Ofcom finding a gap in what a service promises; it is Ofcom finding that a service's product did not match the rule the service itself wrote into its own terms.
Ofcom's own methodology paper explains why no reader of the findings report can know which of the four services that was: "We do not identify any platform in any of the published findings. All findings are anonymous, and where necessary platform names are redacted" (page 9) [1]. Ofcom names all four platforms it tested. It does not name which platform failed its own gifting rule.
"Safety tools exist," but existing was not the same as switched on
The overview's account of safety tools starts with a fair-sounding claim: "Safety tools exist on all the services, but had low visibility, effortful reporting routes and defaults that normalised low safety" (page 3) [2]. The results section shows what "defaults that normalised low safety" meant in practice: "On two services, creators' moderation tools were defaulted to the least restrictive option (researchers were unable to verify this for the other two services)" and "the default visibility setting when creating a livestream was the most public option" across every service where researchers checked it (page 10) [2]. Reporting tools fared no better: on all services, "the journey to submit a report had multiple steps and, in some cases, took users away from the live display" (page 8) [2], while only one of the four had an emergency moderation tool immediately visible to a creator (page 9) [2]. A tool that exists behind a kebab menu, switched to its weakest setting by default, is a different thing from protection a user actually gets.
The claims, tested
| The report's own words | What the report's own evidence shows | Verdict |
|---|---|---|
| The audit is "relevant to recent announcements by the UK Government that will prevent under-16s from creating livestreams" (page 4) [1] | "On all services included in the audit, age was self-declared at sign-up, and there were no requirements for users to prove their age using highly effective age assurance" (page 5) [2] | The restriction needs reliable age data; none of the four tested services collect it |
| Gifting is subject to "age-based restrictions" on some services (page 8) [2] | "On one service, under-18s appear able to complete a purchase without any friction, even though they were prohibited under the terms of service" (page 8) [2] | A service's own written rule, not enforced by its own design |
| "Safety tools exist on all the services" (page 3) [2] | Moderation tools "defaulted to the least restrictive option" on two of four services, and livestream visibility defaulted to "the most public option" throughout (page 10) [2] | Existing and defaulting on are not the same thing |
The mistakes, counted
The policy the audit says it supports needs age data none of the four platforms collect (1). The report ties itself directly to the government's under-16 livestreaming restriction on page 4, then reports on page 5 that every one of the four services tested relies on self-declaration alone, with no highly effective check, at the exact point where that age would first need to be known.
A service's own terms of service against under-18 gifting was not enforced by that service's own product (2). Ofcom's researchers, not a complainant or a whistleblower, tested the restriction directly and found "under-18s appear able to complete a purchase without any friction" on one of the four services (page 8), while the methodology paper's own transparency rule means no reader can be told which one.
The claim that "safety tools exist on all the services" (page 3) is true and also beside the point (3). The report's own results show those tools defaulted to their weakest setting on at least two of the four services and were, across the board, buried behind menus rather than offered at the point a user might need them (pages 8 to 10).
Credit where due
This is not a report burying its own findings. Ofcom states the self-declaration gap in its own results section, not just a caveat; it discloses the legal position honestly, noting in a footnote that the Online Safety Act does not itself require a minimum age or highly effective age assurance for this function (page 5); and it names, openly and in the same document, exactly which four platforms it tested, publishing a transparency notice about the research in advance [1]. The audit's own limitations section is equally candid: it is "a snapshot" using researcher accounts, covering selected journeys rather than every possible one, and it does not claim to measure the prevalence of harm, only design features that could plausibly shape it [1]. This is evidence gathered to inform the codes of practice still being written, not a compliance verdict dressed up as one.
Verdict
Four stars, from three documented mistakes. Ofcom went and looked, with real researcher accounts across four age groups, rather than taking the platforms' word for it, and it wrote down what it found in plain language, including the parts that undercut its own framing. What the evidence shows is a policy problem hiding in plain sight: the government's under-16 livestreaming restriction, which this audit says it exists to support, depends on platforms knowing a user's real age, and not one of the four largest livestreaming platforms in this sample asks for anything more than a typed-in date of birth to establish it.
Sources
- Behavioural Audit of Livestreaming Services: Methodology Paper (PDF), Ofcom, published 9 September 2026
- Behavioural Audit of Livestreaming Services: Key Findings Report (PDF), Ofcom, published 9 September 2026