Ofcom opens its intimate-image enforcement programme. The new measures start in 21 days.
Hash matching is one part of the protection system. Scope, reference quality, review and effective alternatives still need evidence.
By Parminder Kumar Sharma · · 4 min read

Ofcom opened an enforcement programme on 9 September to assess protections against non-consensual intimate imagery, or NCII. The new hash-matching measures in its Illegal Content Codes take effect on 30 September. Those dates are 21 calendar days apart.
The implementation question is more precise than “buy an AI detector”. Providers need to establish which measures apply to their service, how their controls work and what evidence shows that they reduce the relevant harm.
The programme focuses on higher-risk services
The enforcement notice particularly identifies adult and instant messaging services. It will examine implementation of the recommended hash-matching measures or alternative measures used to meet the duties. This is a programme opening, not a finding that every service in those sectors has breached the law.
The notice expects in-scope services to be compliant by 30 September or taking steps towards compliance shortly afterwards. That language should not be turned into a general grace period. A project plan with no implemented control and no evidence of progress is not the same thing as a service actively bringing itself into compliance.
Keep the dates and processes separate
| Date | Development | What it does not establish |
|---|---|---|
| 9 September 2026 | Enforcement programme opens | No blanket finding against all services |
| 30 September 2026 | New Code measures take effect | Not a universal instruction to every website |
| By the end of 2026 | Separate consultation planned on a 48-hour removal requirement | Do not merge that future process into this programme |
The separate consultation is described in Ofcom's announcement. It concerns changes reflecting the law on removal within 48 hours of a report. It should not be used as a reason to delay work on the September measures.
A hash match answers a limited question
StopNCII's own description says a person generates a digital fingerprint on their device. The hash is shared; the original image or video stays on the device. Participating companies check for matching material and apply their policies. The service also describes continued checking for matches and limitations to its reach across participating platforms.
A match is a comparison against a reference set. It does not mean a system understands all the circumstances surrounding an image. A non-match does not establish consent, legality or harmlessness. Material that has never been represented in the reference database still needs a route through reporting and assessment.
That is why a procurement answer should explain the whole workflow. Ask what happens after a match, who can review the decision, and what happens when a victim reports material that the matcher does not recognise. A coverage claim about one technical component cannot answer those service questions.
Database quality is part of the control
Ofcom's Detecting Intimate Image Abuse statement discusses database suitability, match review and the balance between precision and recall. It recommends perceptual matching for static images and, for video, perceptual matching where the database supports it, otherwise cryptographic matching.
Those terms carry a practical difference. An exact-file comparison and a similarity-based comparison do not have the same behaviour when a file changes. Their results should therefore not be reported as a single undifferentiated “AI detection rate”. The database available to the service and the settings used by the matcher are part of the evidence.
The statement also discusses correcting inappropriate hashes. That is an operational responsibility to assign: who receives an error report, who can escalate it to the database provider, and how does the service stop repeating an incorrect decision while the issue is resolved?
An illustrative service review
Consider a messaging service adding image sharing. Its team buys a matching integration and confirms that a test reference produces a match. That proves one narrow path works. It has not yet established whether every supported upload route reaches the check, what happens during an integration outage or whether a report reaches a person empowered to act.
A more useful acceptance exercise follows a small set of harmless, approved test assets through the workflow. It records the upload route, reference-set version, decision, handling of a non-match and escalation outcome. It also tests an unavailable-dependency case without exposing users to harmful content. This is a proposed engineering exercise, not an Ofcom-prescribed test script.
The compliance record should connect those results to the service's risk assessment and the measures it selected. If the provider takes an alternative route, the explanation needs to show why that route is effective for its actual features and risks. Naming a different supplier is not evidence of equivalent protection.
The position
Treat the September date as a delivery milestone with evidence attached. Establish scope, assign control owners and demonstrate the path from detection or reporting to a defensible decision. Keep the matcher, the reference database and the response process visible as separate parts of the service.
The most useful question at the review meeting is what still happens when the matcher returns no result. That is where an impressive demonstration can conceal an incomplete protection system.
Sources
- PrimaryEnforcement programme opened 9 September 2026Ofcomaccessed 2026-09-09
- PrimarySeptember announcement and separate planned consultationOfcomaccessed 2026-09-09
- PrimaryDetecting Intimate Image Abuse statement: database and review considerationsOfcomaccessed 2026-09-09
- PrimaryOn-device hashing and participating-platform workflowStopNCII.orgaccessed 2026-09-09


