Ofcom has opened an investigation into Pornhub over concerns about whether the adult website did enough testing before using Apple’s device-level age checks for people accessing it in Britain.

The regulator announced the action on Wednesday 23 September under the Online Safety Act. Reuters reported that Ofcom is examining whether Pornhub owner Aylo properly assessed the method’s accuracy and suitability before deployment. Aylo said it would cooperate fully and remained committed to strong protection for minors.

This is an investigation, not a finding that Pornhub broke the law or that Apple’s system failed. Ofcom must gather evidence and decide whether the company met its duties. The distinction matters because online safety has already attracted more confident commentary than confirmed facts.

Adult services accessible in the UK must use “highly effective” age assurance to prevent children from encountering pornography. The legal obligation sits with the service, even when it relies on technology supplied by another company. Outsourcing the gate does not outsource responsibility for checking whether the gate works.

What device-level age assurance changes

Traditional age checks can ask a user to upload identification, use a payment card or undergo facial age estimation. Each creates privacy, accuracy and security concerns. Device-level assurance offers a different model: the operating system or account provider can confirm that a user meets an age threshold without necessarily telling the adult site a name, birth date or passport number.

That could reduce the amount of sensitive information collected by thousands of individual websites. In principle, a service receives a simple answer — old enough or not — while the identity data remains with a major platform that already manages the account.

Editorial illustration of a digital-safety regulator reviewing anonymous age-assurance test results

The difficult words are “in principle”. Devices are shared. Account ages may be wrong. Parents hand phones to children and teenagers sometimes use adult accounts. A technical interface can be privacy-preserving and still be unreliable if the information behind it is weak or the service implements it badly.

Ofcom’s apparent focus on due diligence and testing therefore reaches beyond one website. Companies cannot simply attach a well-known technology brand to a compliance process and assume the logo performed the risk assessment. They need evidence showing how the check behaves with shared devices, incorrect account data, attempts to bypass it and users near the legal threshold.

Privacy and protection are not opposites

The debate is often presented as a choice between protecting children and protecting adult privacy. A competent age-assurance system must do both. Collecting copies of identity documents across numerous adult sites could create databases with enormous blackmail and cybersecurity value. Weak checks, meanwhile, leave children exposed to material the law specifically targets.

Data minimisation is essential. A site normally needs to know whether a threshold has been met, not the user’s identity, exact age, address or browsing history. Verification providers should retain as little as possible, publish retention periods and undergo independent security and accuracy testing.

False results matter in both directions. A false adult result may expose a child; a false child result blocks lawful adult access. Systems should offer alternative verification methods and an appeal route without turning a private browsing decision into a customer-service dossier.

People also need to watch for scams. Criminals can imitate age-verification pages to steal identity documents or card details. Users should check the domain, avoid links in unsolicited messages and be suspicious of any check demanding unnecessary information. Regulation that creates a familiar new prompt will inevitably inspire fraudsters to create a familiar fake prompt by lunchtime.

What Ofcom can do

The Online Safety Act gives Ofcom substantial enforcement powers. Serious breaches can lead to fines of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater. In extreme cases, the regulator can seek business-disruption measures that may include blocking access in the UK.

Those are maximum tools, not predictions for this case. The investigation could conclude there was no breach, produce required improvements or escalate to formal enforcement. Aylo will have an opportunity to provide evidence and respond.

Ofcom has already fined adult services more than £1 million in its early enforcement of age-assurance rules, according to Reuters. Consistency now matters. Requirements should apply to large recognisable platforms and smaller sites, while avoiding a system in which compliant businesses lose users to overseas services that ignore the rules.

Regulators should publish enough technical reasoning for the wider industry to learn from decisions without revealing a bypass manual. Apple should also explain the limits of its age signal, and services using it should make clear what additional checks or risk controls they apply.

For more coverage of platforms, privacy and online regulation, visit OutOut’s Technology section.

The OutOut verdict

The best age check is not the one with the most impressive company name. It is the one independently shown to keep children out, reveal little about adults and withstand ordinary family life in which devices and accounts are shared.

Ofcom is right to ask for evidence before accepting convenience as compliance. Pornhub deserves the investigation’s presumption rather than an instant verdict, but it also carries the duty to demonstrate that its chosen gate does more than display a reassuring screen. “Apple says this user is an adult” may be a useful signal. It cannot become the entire safety case wearing a black turtleneck.

Sources