Quick answer
What you need to know
- Will I need ID?
- Not necessarily. Checks can use a bank or mobile provider, a digital identity or an age estimate, among other methods.
- What the site needs
- Often it may need only a yes-or-no answer about an age limit—not your name.
- Before you use it
- Check what data is used, who sees it, when it is deleted and how to challenge a mistake.
Checked against official sources on 8 August 2026 sourcesource
Want the detail?Check the law, evidence and open questionsIncludes what the law requires, what Ofcom says, safeguards, technical diagrams and every source.
See the technical process diagram
What does the law actually require?
In the lawServices that allow pornography, and services with content harmful to children, can be required to use highly effective age assurance so children do not encounter restricted content. The precise duty depends on the service and its risk. source
Is this happening now?
What Ofcom saysThe protection-of-children duties came into force in 2025. Ofcom’s July 2026 statutory report describes age checks operating across pornography, social-media and online-dating services, and calls for remaining services to improve or introduce effective checks. source
What do we know so far?
What we foundThere is no single age-assurance method. Options include open-banking checks, mobile-network checks, credit-card checks, digital identity services and facial age estimation. Some methods verify an identity document; others return only an over-or-under-threshold result. Ofcom says no method eliminates circumvention, while the ICO says seeing an official document may often be excessive. source source
What could go wrong?
Our viewAge assurance can protect children without creating a reusable identity trail. We want services and vendors to minimise data, offer genuinely different methods, delete inputs promptly, make errors easy to challenge and disclose how performance varies across groups.
What is this trying to fix?
What we foundOfcom’s stated purpose is to keep children away from pornography and other harmful content. Its early report says correctly implemented highly effective checks work, while also finding that the job is not complete. source
What protections are built in?
What Ofcom saysData-protection rules require purpose limitation, data minimisation, security and limited retention. The ICO says a service may need to keep only a yes/no threshold result, must not reuse age-check information incompatibly, and should offer accessible alternatives and challenge routes. source
What has not been decided?
- Can users choose a method that does not disclose identity to the service?
- What inputs and outputs are retained, by whom, and for how long?
- How will providers publish meaningful accuracy and bias evidence?
- Are alternatives accessible to people without identity documents, credit histories or compatible devices?
Sources for this page
- Data protection guidance
Information Commissioner's Office. Expectations for age assurance and data protection compliance.
ICO guidance on lawful, fair, transparent, proportionate and privacy-conscious age assurance. Published 14 October 2021; last checked 8 August 2026.
- Regulator evidence
Ofcom. Use of Age Assurance Report 2026.
Ofcom's statutory assessment of how regulated services have used age assurance and early evidence of effectiveness. Published 15 July 2026; last checked 8 August 2026.
- Regulator statement
Ofcom. Ofcom's approach to implementing the Online Safety Act.
Ofcom's implementation roadmap, milestones, active duties and planned regulatory work, updated in July 2026. Published 26 October 2023; last checked 8 August 2026.
- Primary legislation
UK Parliament. Online Safety Act 2023.
The current consolidated text of the Act, including regulated services, duties, enforcement powers, safeguards and exemptions. Published 26 October 2023; last checked 8 August 2026.