Ofcom's own July report warned that services leaning on a third party's age check might not be doing enough due diligence. In September it opened a formal investigation into Pornhub for doing exactly that.
Estimated reading time: 6 minutes
In short. In May 2026 Pornhub replaced part of its age check with a signal borrowed from Apple rather than a check of its own. Ofcom's own July statutory report on age assurance had already written down, in general terms, that services relying on third-party vendors "may not be doing their due diligence sufficiently" (page 67), naming no service and setting no deadline. On 23 September, two months after that report published, Ofcom opened a formal investigation into Aylo, Pornhub's operator, over whether its process is "highly effective" and whether the assessment Ofcom's own rules require before such a change was ever carried out. Three documented mistakes: four stars.
Ofcom's account of what happened is plain enough in its own words. "In May 2026, Pornhub deployed a new age assurance process for some users. This process relies on signals from a third party, in this case Apple, that suggest UK users trying to access Pornhub may have completed Apple's age checks" [1]. Aylo did not build its own check for this route into the site. It borrowed a signal from somewhere else and trusted it.
Ofcom's rule for that arrangement is unambiguous: "The Online Safety Act is clear that it is the service provider's responsibility to ensure that any age assurance process is highly effective, no matter at what stage an age check occurs" [1]. A second duty sits alongside it: providers "must also carry out a suitable and sufficient assessment of whether their service is likely to be accessed by children" before making any significant change of this kind [1]. On 23 September, Ofcom said it is "concerned that Aylo may not have conducted sufficient due diligence and testing before implementing its new age assurance process," and opened a formal investigation into both duties [1]. George Lusty, Ofcom's Director of Enforcement, put it directly: "We expect tech firms to ensure age checks are highly effective before introducing them. Anything less could leave children at risk" [1].
One boundary is drawn carefully. "Our investigation will not make a determination on how Apple operates its age checks" [1]. The signal the whole arrangement depends on sits outside this proceeding entirely. If a breach is eventually found, the process itself runs through a provisional decision and a right of reply before any final determination, backed by fines of up to 18 million pounds or 10 per cent of qualifying worldwide revenue [1]. Nothing has been found yet. This is an opened inquiry, not a verdict.
The report that came in between
Two months before this investigation opened, Ofcom published its first statutory report on how age assurance is actually working across the industry. This site tore that report down on 22 September, and the gap it is built around matters here too: "Ofcom's enforcement record in the same period runs against pornography and file-sharing services with no checks at all, not against any of the social media shortfalls this report itself documents" [3]. The Pornhub investigation is the first sign of that gap closing, against a different kind of shortfall: not an absent check, but an unverified one.
The report's own verdict on the pornography sector reads as a clean pass. "The top 10 most popular pornography services in the UK have all implemented age assurance... All analysed pornography services implemented age assurance using methods included in our HEAA guidance. Services generally offered multiple methods, used a challenge age approach, and deployed liveness detection" (page 22) [2]. Whether Pornhub itself sat inside that anonymised "top 10" is not disclosed; the report does not name individual services. What is certain is the timing: Pornhub's Apple-signal process had already been live for roughly two months when this assessment of the sector was published.
The report did not miss the risk category entirely. Its cross-industry improvement table records: "Services who rely on third party vendors may not be doing their due diligence sufficiently to check the solution is highly effective," with the advice that such services "should conduct regular and thorough due diligence on their age assurance vendors" and that "it is the service's responsibility to ensure that their age assurance process is implemented in such a way that it is highly effective" (page 67) [2]. Ofcom's own Part 5 guidance for pornography providers makes the same point more specifically, on testing: "Where testing has been carried out by third parties, providers should understand what tests have been conducted and what metrics have been used to measure the results" (page 22) [4]. The standard Aylo is now accused of falling short of was not a new one invented for this case. Ofcom had already written it down.
The claims, tested
| Ofcom's own words | What the record shows | Verdict |
|---|---|---|
| "The top 10 most popular pornography services in the UK have all implemented age assurance... All analysed pornography services implemented age assurance using methods included in our HEAA guidance" (page 22) [2] | Two months later Ofcom opened a formal investigation into Aylo, one of the sector's best known names, over whether its process is highly effective at all [1] | A clean sector verdict published without disclosing, or without yet knowing, the case its own enforcement arm was about to open |
| "Services who rely on third party vendors may not be doing their due diligence sufficiently to check the solution is highly effective" (page 67) [2] | Written as a general, advisory "should," with no service named and no date attached, while Pornhub's own third-party-reliant process had already been running for two months [1] | The exact risk pattern was on the page; nothing in the report connects it to a live case |
| Providers "must" carry out a suitable and sufficient assessment "before making any significant change" of this kind [1] | The change went live in May 2026; formal scrutiny of whether that assessment happened at all began four months later, in September [1] | A duty written to operate before the fact was checked well after it |
The mistakes, counted
A clean sector-wide verdict landed two months before a formal investigation into one of the sector's own names (1). Page 22's "all implemented age assurance" finding for the UK's top pornography services carried no caveat and named no case, despite publishing after Pornhub's Apple-signal process had already been live for two months [2].
The report named the exact risk pattern this investigation turns on, and attached no urgency to it (2). Page 67's "services who rely on third party vendors may not be doing their due diligence sufficiently" is advisory language only, no service, no deadline, sitting in the same document that cleared the sector two sections earlier [2].
A duty timed to happen before a change was examined four months after it (3). Ofcom's own description of the assessment duty is prospective, "before making any significant change"; the change itself dates to May, the investigation to September [1].
Credit where due
Ofcom draws its own jurisdiction carefully rather than reaching past it: it states plainly that the investigation "will not make a determination on how Apple operates its age checks," leaving a company outside its direct remit alone rather than quietly ruling on it anyway [1]. It names the responsible party without euphemism, Aylo, not "a service," and discloses the real financial exposure, up to 18 million pounds or 10 per cent of worldwide revenue, and the staged provisional-decision process up front rather than leaving either vague [1]. And the risk category this case turns on is one Ofcom had already put into writing in its own guidance and its own report before this case became public, not a standard invented after the fact to fit it [2] [4].
Verdict
Four stars, from three documented mistakes. Nothing here finds Aylo at fault; Ofcom itself has made no such finding yet. What Ofcom's own paper trail shows is a regulator that wrote down the exact risk of unverified third-party age checks in July, gave it no name and no deadline, and only turned that general warning into a named investigation two months later, four months after the change itself went live. The gap between describing a risk and chasing it down is the story here, not the eventual outcome of the case Ofcom has only just opened.
The star score counts three documented mistakes against Ofcom's own published record: the clean sector-wide compliance verdict in the July report that did not flag or disclose this case; the same report's own due-diligence warning about third-party vendors, written in general advisory terms with no case attached; and the four-month gap between Pornhub's change going live in May and formal scrutiny of whether the required before-the-fact assessment happened at all beginning in September. Three falls in the 1 to 3 band: four stars; the bands are on the ratings page. Ofcom's investigation into Aylo is open and ongoing; this piece makes no finding on whether Aylo complied with its duties, only on Ofcom's own published timeline and language. Analysis is of Ofcom's press release of 23 September 2026 and its Report on the use of age assurance, published 15 July 2026.
Sources
- Ofcom launches investigation into Pornhub's age checks, Ofcom, 23 September 2026
- Report on the use of age assurance (PDF), Ofcom, 15 July 2026
- "Ofcom's own report calls Britain's rollout of child age checks 'unprecedented.' The one number that measures whether it actually worked barely moved.", Tracked Changes, 22 September 2026
- Guidance on highly effective age assurance and other Part 5 duties (PDF), Ofcom, updated 24 April 2025