P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Ofcom opens its intimate-image enforcement programme. The new measures start in 21 days.

Hash matching is one part of the protection system. Scope, reference quality, review and effective alternatives still need evidence.

By Parminder Kumar Sharma · · 4 min read

AI-generated editorial illustration for Ofcom opens its intimate-image enforcement programme. The new measures start in 21 days. Conceptual artwork, not a photograph or product screenshot.

Ofcom opened an enforcement programme on 9 September to assess protections against non-consensual intimate imagery, or NCII. The new hash-matching measures in its Illegal Content Codes take effect on 30 September. Those dates are 21 calendar days apart.

The implementation question is more precise than “buy an AI detector”. Providers need to establish which measures apply to their service, how their controls work and what evidence shows that they reduce the relevant harm.

The programme focuses on higher-risk services

The enforcement notice particularly identifies adult and instant messaging services. It will examine implementation of the recommended hash-matching measures or alternative measures used to meet the duties. This is a programme opening, not a finding that every service in those sectors has breached the law.

The notice expects in-scope services to be compliant by 30 September or taking steps towards compliance shortly afterwards. That language should not be turned into a general grace period. A project plan with no implemented control and no evidence of progress is not the same thing as a service actively bringing itself into compliance.

Keep the dates and processes separate

DateDevelopmentWhat it does not establish
9 September 2026Enforcement programme opensNo blanket finding against all services
30 September 2026New Code measures take effectNot a universal instruction to every website
By the end of 2026Separate consultation planned on a 48-hour removal requirementDo not merge that future process into this programme

The separate consultation is described in Ofcom's announcement. It concerns changes reflecting the law on removal within 48 hours of a report. It should not be used as a reason to delay work on the September measures.

A hash match answers a limited question

StopNCII's own description says a person generates a digital fingerprint on their device. The hash is shared; the original image or video stays on the device. Participating companies check for matching material and apply their policies. The service also describes continued checking for matches and limitations to its reach across participating platforms.

A match is a comparison against a reference set. It does not mean a system understands all the circumstances surrounding an image. A non-match does not establish consent, legality or harmlessness. Material that has never been represented in the reference database still needs a route through reporting and assessment.

A locally created hash is compared with a reference database, then assessed for action; unmatched material still needs reporting and review
Conceptual control workflow. Hashing is not biometric identification; the fingerprint metaphor refers to a file-derived representation. Reporting remains a separate route.

That is why a procurement answer should explain the whole workflow. Ask what happens after a match, who can review the decision, and what happens when a victim reports material that the matcher does not recognise. A coverage claim about one technical component cannot answer those service questions.

Database quality is part of the control

Ofcom's Detecting Intimate Image Abuse statement discusses database suitability, match review and the balance between precision and recall. It recommends perceptual matching for static images and, for video, perceptual matching where the database supports it, otherwise cryptographic matching.

Those terms carry a practical difference. An exact-file comparison and a similarity-based comparison do not have the same behaviour when a file changes. Their results should therefore not be reported as a single undifferentiated “AI detection rate”. The database available to the service and the settings used by the matcher are part of the evidence.

The statement also discusses correcting inappropriate hashes. That is an operational responsibility to assign: who receives an error report, who can escalate it to the database provider, and how does the service stop repeating an incorrect decision while the issue is resolved?

An illustrative service review

Consider a messaging service adding image sharing. Its team buys a matching integration and confirms that a test reference produces a match. That proves one narrow path works. It has not yet established whether every supported upload route reaches the check, what happens during an integration outage or whether a report reaches a person empowered to act.

A more useful acceptance exercise follows a small set of harmless, approved test assets through the workflow. It records the upload route, reference-set version, decision, handling of a non-match and escalation outcome. It also tests an unavailable-dependency case without exposing users to harmful content. This is a proposed engineering exercise, not an Ofcom-prescribed test script.

The compliance record should connect those results to the service's risk assessment and the measures it selected. If the provider takes an alternative route, the explanation needs to show why that route is effective for its actual features and risks. Naming a different supplier is not evidence of equivalent protection.

The position

Treat the September date as a delivery milestone with evidence attached. Establish scope, assign control owners and demonstrate the path from detection or reporting to a defensible decision. Keep the matcher, the reference database and the response process visible as separate parts of the service.

The most useful question at the review meeting is what still happens when the matcher returns no result. That is where an impressive demonstration can conceal an incomplete protection system.

Sources

  1. PrimaryEnforcement programme opened 9 September 2026Ofcomaccessed 2026-09-09
  2. PrimarySeptember announcement and separate planned consultationOfcomaccessed 2026-09-09
  3. PrimaryDetecting Intimate Image Abuse statement: database and review considerationsOfcomaccessed 2026-09-09
  4. PrimaryOn-device hashing and participating-platform workflowStopNCII.orgaccessed 2026-09-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.