Artifact GuideUKAge Assurance

UK Online Safety Act Age Assurance

Age assurance means age verification, age estimation, or both. The required certainty depends on the Online Safety Act duty and age threshold.

Test the complete system for effectiveness, fairness, circumvention, privacy, security, accessibility, fallback, and downstream enforcement.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

means , , or both. Under the Online Safety Act, the required method and certainty depend on the duty: preventing children from accessing a service or content, or applying child-safety measures by age. Start with that legal trigger, then test effectiveness, privacy, accessibility, and circumvention.

Section 1

Age assurance basics under the UK Online Safety Act

Ofcom uses as the collective term for and . Under section 230, age verification verifies a user's exact age, while age estimation estimates a user's age or age range. The Act does not require one universal technique, and the method must be assessed against the duty it supports.

The main triggers differ. A children's access assessment may rely on when a provider seeks to conclude that children cannot normally access the service. Services likely to be accessed by children may need to apply child-safety measures by age. Services within the pornography duties must use highly effective age assurance to prevent children from encountering regulated pornographic content.

The current Ofcom code and guidance for the duty determine what requires. The complete process, including fallback and the downstream restriction, needs implementation-specific evidence; a supplier's product name or general accuracy claim does not establish compliance.

and can use different evidence and expose users to different privacy or exclusion risks. Compare candidate methods against the named duty, the relevant threshold, the actual population, the data collected, and the route offered when the primary method cannot produce a usable result.

Place the check before a user can encounter the protected content. If is used, document the decision boundary and route uncertain results to another method. Test previews, embeds, logged-out access, alternate clients, account sharing, recovery, and VPN or other foreseeable bypass routes.

Online-safety and data-protection duties apply together. Define the purpose, minimise the personal data used, assess lawful processing and children's interests, secure transfers and templates, limit retention, control vendors, provide usable information, and offer an accessible alternative where the primary method excludes a user.

  • Scope record: service, content or feature, statutory trigger, age threshold, user group, and required outcome.
  • Method record: verification or estimation inputs, decision rule, fallback, retries, manual review, downstream control, and deletion event.
  • Test record: threshold-specific errors, demographic performance, spoofing, account sharing, bypass routes, accessibility, abandonment, and production monitoring.
  • Governance record: safety owner, privacy assessment, security review, supplier controls, complaints route, approval, residual risk, and reassessment trigger.
Section 2

Who should own age assurance, and what evidence should prove the decision?

Product owns the user journey and downstream access control; safety and legal identify the duty and threshold; privacy maps processing and retention; security tests circumvention; accessibility and equality owners test exclusion; an accountable decision-maker accepts residual risk.

Evidence should show the service scope, statutory trigger, method and supplier, threshold-specific testing, attack testing, demographic performance, fallback, data flow, deletion, user information, complaints route, approval, and production monitoring.

  • Name one accountable owner and one reviewer for the workflow.
  • Keep source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for notices, risk assessments, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, or material changes in the source text.
Section 3

Age assurance edge cases to check before you rely on a decision

Boundary issues arise where logged-out or embedded access bypasses the check, one account is shared, a user is near the threshold, a supplier cannot cover a population, an uncertain result has no fallback, or the same age signal is reused for another purpose.

Test every access path and state what happens after failure, retry, challenge, account recovery, supplier outage, or a change in the age result. A successful age check is ineffective if the downstream content or feature gate can be bypassed.

  • Check whether the rule changes for different service types, audiences, or access paths.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams implement age assurance with proportionate controls?

Use a workflow that starts with the statutory purpose and ends with a tested downstream restriction. Capture service scope, user groups, children's-access and risk-assessment links, method choice, data flow, fallback, test results, owner, approval, monitoring, and escalation.

The output should include a decision record, method test pack, privacy and security assessment, implementation evidence, monitoring plan, complaint route, and change trigger.

  • Create a short intake question that identifies the scenario.
  • Map the answer to a required action, evidence field, owner, reviewer, and review date.
  • Link related artifact pages with descriptive anchors so users can move from scope to deadlines, controls, penalties, and templates.
  • Update the workflow when official source material changes or when non-public evidence shows recurring exceptions.
Primary sources

References and citations

Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Options
Compare age verification and age estimation methods by assurance, privacy, accessibility, bias, evasion risk, and operational evidence.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.