Ofcom is examining an Apple age signal 140 days after go-live: the duty stays with the site
Ofcom opened a formal investigation on 22 September 2026 into how Aylo, the provider of Pornhub, built a UK age check on signals from Apple, and it has made no finding. The case tests a rule for any UK service using a third-party check: the legal duty stays with the service.
By Parminder Kumar Sharma · · 21 min read

140 days, and no finding
On 5 May 2026 Aylo, the provider of Pornhub, began restoring access for eligible UK iPhone and iPad users who had confirmed their age with Apple. On 22 September 2026 Ofcom opened a formal investigation into that process. The gap is 140 days (derived: 5 May to 22 September), and when Ofcom published its case page on 23 September it recorded two duties under examination and no finding.
That number is checkable, and on its own it says very little. It is not a measure of regulatory delay, and it is not evidence that the process failed. Ofcom's enforcement guidance says opening an investigation "does not imply that Ofcom has taken a view" on whether any provision was contravened. The record bears that out: of the five investigations Ofcom opened on 30 July 2025 into age assurance on adult services, two were later closed without any findings about the provider's compliance, and three ended in penalties.
The case still matters beyond one company, because of one sentence in Ofcom's announcement: it is "the service provider's responsibility to ensure that any age assurance process is highly effective", however the check is run and wherever it sits. Ofcom's Director of Enforcement, George Lusty, put the timing point in his own words: "We expect tech firms to ensure age checks are highly effective before introducing them."
Any UK service that leans on a check run by someone else, whether an identity wallet, a bank, a mobile network or an operating system, inherits the same two questions. Can you show that it is highly effective, and did you show it before you switched it on?
What Ofcom has actually put on the record
Ofcom published two pages on 23 September 2026: a news release and a case page with the reference CW/01358/09/26. Both are short, and what they leave open matters as much as what they fix. Both were read in full for this briefing, alongside the guidance and statute they rely on.
What Ofcom's news release and case page fix, and what they leave open (Ofcom, 23 September 2026)
| Item | Fixed on the record | Not stated |
|---|---|---|
| The case | Opened 22 September 2026 under Ofcom's enforcement programme on age assurance for pornographic content. Subject: Aylo Freesites Ltd, in relation to its service Pornhub. | A finding, a provisional notice or a proposed penalty. A timetable: the page says only that an update will follow "in due course". |
| The law | Sections 12 and 36 of the Online Safety Act 2023: highly effective age assurance, and children's access assessments. Ofcom dates the duties to 25 July 2025 and 16 April 2025. | Any other duty. Ofcom names no other section for this case. |
| The concern | Aylo "may not have conducted sufficient due diligence and testing" before its May 2026 process, so the process "may not be highly effective". | That either is true. Ofcom says it is concerned. It says there is a risk that children could encounter content, not that any did. |
| The Apple element | The process "relies on signals from a third-party (Apple)" that suggest UK iOS and iPadOS users "may have completed Apple's age checks". | What the signal technically is, what Aylo reads, or what happens when the signal is missing or wrong. |
| Apple's role | The investigation "will not make a determination on how Apple operates its age checks". | Any view of Apple's system, good or bad. Apple is not the subject of the case. |
| The powers | If a breach is found: required steps to comply or remedy, and a fine of up to 18 million pounds or 10% of qualifying worldwide revenue, whichever is greater. | Any proposed amount. Ofcom's procedure puts a proposed penalty first in a provisional notice, and none appears on Ofcom's pages as at 29 September. |
| Aylo's response | Aylo says it will "cooperate fully" and is "prepared to provide the technical evidence, testing and supporting assessments" behind its position. | What that evidence shows. Ofcom has not commented on it. |
Two wording points for anyone writing this up. First, Aylo's statement dates Ofcom's letter 21 September, while Ofcom's case page dates the opening to 22 September. The two records differ by a day, and this briefing uses Ofcom's date. Second, Aylo's statement describes the matter as an investigation into "Aylo's failure to comply" with the Act. Ofcom's page says it is investigating whether Aylo "has failed, or is failing" to comply. Use the regulator's wording in anything a board or a customer will read.
One structural point that is easy to miss: section 12 is a duty on user-to-user services, which is why Ofcom applies its Part 3 guidance here. Part 5 of the Act, section 81, covers services that publish their own pornographic content. Ofcom's case cites sections 12 and 36 only.
What 'Apple-powered' means, and what nobody has said
Start with the words each party uses. Ofcom describes "signals" from Apple that "suggest" users "may have completed" Apple's checks. The hedging is Ofcom's, and it is the whole issue: a signal that suggests something is not proof of it. Aylo describes "eligible adult users" who "have confirmed their age through Apple's UK age-verification process", and calls Apple's update "device-level" age verification.
Apple's own support pages say what the confirmation is. An adult confirms that they are 18 or older with a credit card that belongs to them, or by scanning a passport, a driving licence or an accredited proof-of-age card. For an existing account, Apple checks "if you have a credit card on file or other eligible methods", and its guidance page adds that Apple may look at "how long you've had an Apple Account". Debit cards and gift cards are not supported. Until age is confirmed, Apple turns on a web content filter and communication safety features, and the user cannot adjust those safety settings without confirming. Apple's UK page is dated 29 April 2026.
Here is what the primary sources do not say. Neither Ofcom nor Aylo describes how the status reaches Pornhub: whether it is a cryptographically signed assertion, a state of the browser or operating system that the site infers, or something else. The two Apple pages I read describe age confirmation for the Apple Account, its safety settings and 18+ app downloads, and neither describes a signal passed to third-party websites. That silence is not proof that no signal exists, because Ofcom says the process relies on one. It means the form of the signal is an open fact, and the legal analysis depends on it.
One outside view has filled the gap. By 8 May the Age Verification Providers Association, a trade body for age-check suppliers, had argued that Pornhub "does not appear to receive any authenticated signal, signed token or cryptographically verifiable assertion" from Apple, and that a check based on browser characteristics would be easy to spoof. Treat that as an informed inference from an interested party, not as a finding. Its members sell age verification, it wrote "does not appear", and Ofcom has said nothing of the kind.
The test: highly effective, judged on the whole process
The statute sets the test. Section 12(4) requires a provider to use age verification or age estimation, or both, to prevent children of any age from encountering primary priority content, a category that includes pornography. Section 12(6) adds that the method must be "of such a kind, and used in such a way" that it is "highly effective at correctly determining whether or not a particular user is a child". Two phrases carry weight. "Used in such a way" makes the implementation part of the test. "A particular user" points, on a plain reading, at the individual rather than the device or the household. That second point is my reading, not something Ofcom has said about this case.
Ofcom's guidance turns the statute into four criteria: technical accuracy, robustness, reliability and fairness. It adds two principles to have regard to, accessibility and interoperability. It stresses that the whole is what counts. The "age assurance process as a whole" must be highly effective, and implementing one of its example methods is "not a guarantee" of compliance.
The example list names open banking, photo-ID matching, facial age estimation, mobile-network operator checks, credit card checks, email-based age estimation and digital identity services. A device- or account-level signal from an operating system is not on it. The list is expressly non-exhaustive and paragraph 3.6 does anticipate system-level methods, so absence from the list is not a mark against the method. It does mean nothing in the guidance certifies it either. The guidance is dated 24 April 2025 and predates Apple's UK check, which Aylo dates to March 2026.
How a device-based signal maps to Ofcom's criteria: questions, not findings (criteria from Ofcom's Part 3 guidance on highly effective age assurance; the questions are this briefing's)
| Criterion | What Ofcom's guidance asks for | Question for a device-based signal |
|---|---|---|
| Technical accuracy | Method evaluated against metrics such as true positive and false negative rates. Third-party test results are acceptable if you understand what was tested (paragraphs 4.5, 4.11 to 4.15). | Where are the error rates for the initial check, and can the site see or commission them? |
| Robustness | Tested in deployment. Circumvention that is easily accessible to children is mitigated. Device or account sharing is named as a risk (paragraphs 4.22 to 4.36). | What happens when a child uses an adult's confirmed device or account? What does the site do when the signal is absent, stale or spoofed? |
| Reliability | Reproducible outputs, and data that "comes from a trustworthy source" (paragraphs 4.38 to 4.50). | A card in your name, an ID scan and account history are different strengths of evidence. Which sits behind each confirmed status, and does the site know? |
| Fairness and accessibility | Avoid bias, consider offering more than one method, and work for all users (paragraphs 4.51 to 4.67). | Aylo's May statement restores access for "eligible age-confirmed UK iOS users". Does a single-platform route meet the accessibility principle, and what happens to adults who cannot or will not confirm with Apple? |
Ofcom and the Information Commissioner's Office have already said, generally, what a robust check must do. Their joint statement of 25 March 2026 asks providers to choose a method that guards against fake input and "binds the proof of age to the user presenting for the age check". That was six weeks before Aylo's change and about no particular service. It remains the cleanest statement of the question a device-level signal has to answer: how does an adult's confirmation reach the person actually holding the phone?
Four comforting names, none of them a control
A label is not a control, and this story is thick with labels.
- "Device-level age verification." It sounds like a category of assurance. In the sources it describes where in the chain the check sits. Apple's pages call it confirming that you are an adult, for the Apple Account, its safety settings and 18+ app downloads, and neither describes passing that status to websites.
- "Kid safe by default." Aylo's phrase for devices running iOS 26.4 or later. It describes a default for accounts that have not confirmed an age, which is a statement about the child's device. The legal duty is about whether the site can tell that a particular user is an adult.
- "Privacy-preserving." Aylo's word for Apple's approach. Whether it holds depends on what data crosses between Apple and the site and what each keeps. No source I read sets that out.
- "Highly effective." In Aylo's statement it is a conclusion, reached after citing government announcements: "making this a highly effective age assurance method". In the Act and in Ofcom's guidance it is a legal standard applied to the whole process and evidenced by testing. Ofcom's page says it is concerned the process may not meet it.
Ofcom's welcome of Apple's launch belongs on the same list. Press reports and Aylo's own statement quote Ofcom calling Apple's decision "a real win for children and families" and saying Ofcom's rules can be applied "in a variety of contexts". I could not find that statement on Ofcom's website, so it rests on press coverage and Aylo's quotation of it. Even taken at face value it welcomes what Apple did. It does not say that any particular site's use of the result is highly effective. Ofcom's July 2026 report is explicit that it welcomes innovation while stressing that all interventions must work reliably in practice and that "regulated services can demonstrate that they have met their duties".
Aylo also quotes that report's finding that age assurance works on individual services but "not yet at an overall system level". The same report says, in the sentence that calls for a system-wide effort, that "the compliance obligations rest on regulated services themselves". Both halves are in the report. A summary that keeps only one of them is a label.
From investigation to decision: where this case sits
The Register's headline says Ofcom is taking "a hard look". The legal position is firmer than that phrase and softer than a charge. Ofcom's guidance lists lighter tools it can use instead of an investigation: compliance remediation, warning letters and enforcement programmes. Here Ofcom chose the formal route. Its news release says it "has decided to open a formal investigation", and its guidance says that means it is satisfied the evidence merits one and that the case is a priority. A formal investigation still stops short of a contravention notice. That notice comes later, and only if Ofcom considers there are reasonable grounds for it.
Ofcom's Online Safety Enforcement Guidance sets out the path, and the Act fixes its main steps.
- Initial assessment. Ofcom can resolve a concern by other means without opening an investigation, or open an enforcement programme. It has run one on age assurance for pornographic content since 16 January 2025.
- Case opening. A case opening letter, then usually a public announcement. From here the provider "must co-operate fully" (section 105).
- Evidence gathering, including formal information notices. Failing to answer one can itself be enforced.
- Provisional notice of contravention (section 130), if Ofcom considers there are "reasonable grounds for believing" a failure. It gives Ofcom's reasons and may propose steps and a penalty. The provider may make representations, and the guidance says written ones typically get at least 20 working days.
- Confirmation decision (sections 133 and 137), which can require steps and impose penalties and must state appeal rights, or closure, which Ofcom can choose at any point.
Aylo's case is at stage two. Ofcom's pages record no provisional notice and no timetable. The announcement says only that an update will follow.
Ofcom's programme page gives a record to measure against. Six investigations under section 12 show a confirmation decision as at 29 September 2026. Counting from the day each case was opened, they took between 126 and 358 days, with a median of 218 days (all derived from the dates on the page). The section 12 penalties in those decisions ranged from 500,000 to 1,350,000 pounds. In each of the six, Ofcom also found a separate failure to answer a request for information under section 102(8), with penalties from 30,000 to 100,000 pounds.
Two caveats stop that record being read as a forecast. First, it is a record of other cases. One provider is described as having had no age checks before its investigation, Ofcom also found a failure to respond to a request for information in every one of the six, and none is described as turning on a third-party signal. Second, the only other case on the page whose opening text questions an implemented method, the investigation of Bit Hive SP. Z O.O. opened on 16 June 2026, shows no outcome after 105 days. So the record says how long a routine case can take and nothing about how long a contested one will.
The penalties sit far below the statutory ceiling of 18 million pounds or 10% of qualifying worldwide revenue, whichever is greater. They were set on other providers, having regard to Ofcom's Penalty Guidelines, and they say nothing about what a much larger operator would face. This briefing does not estimate one.
What each stage of an Ofcom investigation would and would not establish (Ofcom's Online Safety Enforcement Guidance; Online Safety Act 2023, sections 105, 130, 133 and 137)
| Stage | What it establishes | What it does not establish |
|---|---|---|
| Case opened (where this case is) | Ofcom is satisfied the evidence merits an investigation and that the case is a priority. The provider must co-operate fully. | That any duty was breached. The guidance says opening "does not mean that a breach finding will be made". |
| Provisional notice of contravention | Ofcom considers there are reasonable grounds for believing a failure, and says why. It may propose steps and a penalty. | A final decision. The provider can make representations, and Ofcom can still issue a further notice or close the case. |
| Confirmation decision | A contravention is found, with the steps required, any penalty and the appeal rights. | A view on Apple's system, or on another provider's use of the same signal. Ofcom says effectiveness depends on how a method is implemented. |
| Closure without findings | Ofcom sees no need to go on, for example because the concern is resolved or is no longer a priority. | That the method complies. Ofcom's closure notices say they were made "without making any findings" about compliance. |
Privacy and data minimisation: questions for any third-party check
Every age check processes personal data, and Ofcom's guidance says so at the outset. Its data protection section directs providers to the ICO's Children's code and Age Assurance Opinion, flags a data protection impact assessment (which data protection law requires where processing is likely to be high risk), and lists privacy information for users, records of processing and documented security measures as ways to show that privacy was considered. It notes that the Privacy and Electronic Communications Regulations apply where a service stores or gains access to information on a user's device (paragraph 5.6). The joint Ofcom and ICO statement adds that a method must be "necessary, proportionate to your risks" and compliant with data protection law. Its worked example for a user-to-user service collects "only the information strictly necessary to confirm a user's age or age range".
No source I read says what data crosses between Apple and the site, what either keeps, or whether the site can tie an adult status to a visitor's browsing history. Aylo describes the approach as "privacy-preserving". That is the company's claim about a mechanism whose data flows it has not described in public, and neither Ofcom nor the ICO has assessed it on the record I read.
Questions to put to any third-party age check, in roughly the order a regulator would:
Take this with you
Data protection questions to settle before go-live
- Who is the controller or processor at each step, and who can see both the age status and what the person then does on your service?
- What exactly do you receive: a yes or no, an age band, an identifier, a device attribute? Is it the minimum you need to establish age?
- Do you read anything from the user's device or browser to get it? If so, do the Privacy and Electronic Communications Regulations apply, and have you met them?
- What is your lawful basis, how long do you keep the status, and can it be linked to a user's history? Where the fact of a visit is itself sensitive, that linkage is the risk.
- Was a data protection impact assessment done before go-live, and is it updated when the third party changes what it checks or shares?
- Can a person challenge a wrong result, and how quickly? The joint statement's example gives users tools to do so.
- What does the third party learn from the fact that you asked?
Method, not accusation
Every voice in this story has a stake, and none of them is the evidence.
Aylo said on 27 January 2026 that it would stop taking part in what it called a "failed system", and it restricted access for new UK users from 2 February. It says it has advocated device-based verification "for years", and its May and September statements welcome an approach that reopens UK access for eligible Apple users. That is a commercial position as well as a policy one, and the company has been open about both. The Age Verification Providers Association is a trade body whose members sell age checks, and a device-level route competes with theirs. In what I read I found no statement from Apple about the case, and Apple is not the subject of it.
None of those positions is evidence about whether the check works. The evidence is testing, and Ofcom has said it will look at Aylo's. Aylo says it is ready to supply it. Until Ofcom says what it found, a careful reader holds two thoughts together: the concern is real enough to justify a formal investigation, and it is still only a concern.
What to do about it, in order
Take this with you
The order worth doing it in
- Map every age check you rely on end to end. Name who performs each step and what reaches you. If any step is run by a party you have no contract with, record that as a risk.
- Ask the third party for evidence and keep it: test method, error rates for the initial check, circumvention testing and change history. Ofcom's guidance says to understand what tests were run and which metrics were used (paragraph 4.5).
- Write down what the signal actually is: signed or unsigned, who could forge it, and what happens when it is missing, stale or contradicted. If you cannot describe it, you cannot test it.
- Test the failure cases yourself in live conditions before launch: a shared device, a child using an adult's confirmed account, a missing signal, an altered environment. Record results, not assurances.
- Where your children's access assessment rests on age assurance, complete and record a new one before any significant change to how age is checked (section 36(4)(a)), and keep the written record (section 36(7)).
- Finish the data protection impact assessment before go-live: what you receive, what you keep, for how long, and whether the signal can be tied to browsing history. Check the Privacy and Electronic Communications Regulations if anything is read from the device.
- Set a trigger for reassessment. Ofcom's children's access guidance counts user reports, media reports, independent research and vendor updates as evidence of reduced effectiveness (paragraph 5.18), so route them to a named owner.
- Write change control into the contract: notice when the third party changes what confirms an adult, and a right to the evidence behind it.
- Prepare to answer an information notice quickly and completely. Section 105 requires full co-operation, and on Ofcom's programme page every section 12 confirmation decision also carried a separate failure-to-respond finding.
- Use the regulator's wording in board and customer papers: Ofcom is investigating whether, not found, until a decision says otherwise.
The question that exposes the gap
The distance between a regulator's welcome and a regulator's finding is the distance between someone else's check and your own evidence. Ofcom said in advance what it expects, in its Director of Enforcement's words: age checks that are highly effective before they are introduced.
So the question is not whether the check you rely on has a reassuring name, or whether a regulator once said something kind about the company behind it. It is this. If your regulator asked you today for the test results behind an age check you rely on but did not build, what would you send?
Key facts
Sources
- PrimaryOfcom news release of 23 September 2026 announcing the investigation into Aylo: the concern, the scope, Ofcom's statement that it will not determine how Apple operates its checks, the process and the maximum penaltyOfcomaccessed 2026-09-29
- PrimaryOfcom case page CW/01358/09/26, read in full: case opened 22 September 2026, sections 12 and 36, the description of the Apple signals, guidance paragraph 3.6 and the duty commencement datesOfcomaccessed 2026-09-29
- PrimaryOfcom age assurance enforcement programme page, read in full and last updated 23 September 2026: the opening dates, provisional notices, confirmation decisions, closures and penalties used for the days-from-opening recordOfcomaccessed 2026-09-29
- PrimaryOfcom case page for the Bit Hive investigation opened 16 June 2026, shown as open with no outcome, used as the only other case whose opening text questions an implemented methodOfcomaccessed 2026-09-29
- PrimaryGuidance on highly effective age assurance for Part 3 services, published 24 April 2025, read in full: method list, paragraph 3.6 on system-level age assurance, the four criteria, privacy sectionOfcomaccessed 2026-09-29
- PrimaryChildren's access assessments guidance, published 24 April 2025, used for the triggers for a new assessment and the examples of evidence of reduced effectivenessOfcomaccessed 2026-09-29
- PrimaryOnline Safety Enforcement Guidance, cover dated 16 December 2024, used for the investigation process, the effect of opening a case, provisional notices, representations and closureOfcomaccessed 2026-09-29
- PrimaryJoint statement on age assurance of 25 March 2026, used for binding proof of age to the user, necessity and proportionality, and the data minimisation exampleOfcom and the Information Commissioner's Officeaccessed 2026-09-29
- PrimaryReport on the use of age assurance, published 15 July 2026, used for the system-wide effort passage and the statement that compliance obligations rest on regulated servicesOfcomaccessed 2026-09-29
- PrimaryOnline Safety Act 2023 section 12, safety duties protecting children, used for the age verification or estimation requirement and the highly effective test in subsections 4 and 6legislation.gov.ukaccessed 2026-09-29
- PrimaryOnline Safety Act 2023 section 36, duties about children's access assessments, used for the before-a-significant-change trigger and the written recordlegislation.gov.ukaccessed 2026-09-29
- PrimaryOnline Safety Act 2023 section 130, provisional notice of contravention, used for the reasonable grounds threshold and the right to make representationslegislation.gov.ukaccessed 2026-09-29
- PrimaryOnline Safety Act 2023 section 133, confirmation decisions requiring steps, used for the content of a confirmation decision including appeal rightslegislation.gov.ukaccessed 2026-09-29
- PrimaryOnline Safety Act 2023 section 105, investigations, used for the provider's duty to co-operate fullylegislation.gov.ukaccessed 2026-09-29
- PrimaryAylo newsroom statements of 23 September 2026, 5 May 2026 and 27 January 2026, read in full: the company's description of the Apple process, its position on the investigation, and its 2 February 2026 restriction of new UK usersAyloaccessed 2026-09-29
- PrimaryApple Support (UK) page on age requirements for managing an Apple Account, dated 29 April 2026, used for how adults confirm age and the default safety settingsAppleaccessed 2026-09-29
- PrimaryApple Support (UK) page on confirming that you are an adult, used for the account information Apple may examine, including account ageAppleaccessed 2026-09-29
- Reported byNews report of 23 September 2026 that pointed to the Ofcom announcement, with an Aylo comment added the same day; used only as a pointer, and for the headline quoted in the pieceThe Registeraccessed 2026-09-29
- Reported byTrade body commentary arguing the Apple route does not clearly achieve compliance, used as an interested party's inference about the form of the signal and labelled as suchAge Verification Providers Associationaccessed 2026-09-29
- Reported byTrade press report of 8 May 2026 on Aylo's return for Apple-confirmed users and the trade body's response, used to date that responseBiometric Updateaccessed 2026-09-29
- Reported byReport of 25 March 2026 quoting Ofcom's welcome of Apple's UK age verification, used because the statement was not found on Ofcom's own website9to5Macaccessed 2026-09-29


