Ofcom Investigates Pornhub Device-Level Age Checks Under UK Online Safety Rules

Security researchers analyzing AI-assisted vulnerability discovery and exploit trends

UK communications regulator Ofcom has opened a formal investigation into whether the age-assurance process used by Pornhub operator Aylo satisfies duties under the Online Safety Act. The inquiry focuses on a device-level approach that uses operating-system age signals rather than requiring a fresh identity or age check inside the service.

Investigation focuses on effectiveness and due diligence

Ofcom said it will examine whether the service uses highly effective age assurance and whether Aylo completed an adequate children’s access assessment. The regulator also raised the question of whether sufficient due diligence and testing took place before the process was introduced. Opening an investigation is not a finding of non-compliance, and Ofcom said it is not making a determination about Apple’s age-verification system itself.

The technical distinction matters because a device-level signal may describe an account holder without proving who is using the device at a particular moment. Shared devices, known passcodes and household account practices can therefore affect the assurance provided by the overall workflow.

Age assurance is a system-level control

Organizations assessing age controls should document the signal source, binding between the signal and the current user, fallback methods, privacy boundaries and testing evidence. They should also record how exceptions and account recovery are handled, because those paths can weaken an otherwise strong primary check.

The case is relevant to broader Access Control & Identity design: assurance depends on the full chain between enrollment, device, account and transaction. A vendor feature alone does not establish that the deployed service meets a regulatory or operational threshold.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *