Age assurance duties under the Online Safety Act

Published: 23 February 2024
Last updated: 2 September 2026

The Online Safety Act introduces rules that service providers must follow on robust age checks to protect children.

This page helps services understand what they need to consider when implementing or reviewing highly effective age assurance (HEAA) processes. For full details, services should consult the Part 3 Guidance on highly effective age assurance (PDF, 394.54 KB) or the Guidance on highly effective age assurance and other Part 5 duties (PDF, 775.13 KB) as relevant to assist them in implementing HEAA.

If you do not currently have HEAA in place and need to determine if you should be implementing this, start by reading our section below on highly effective age assurance and why it is important.

If you already have age assurance in place, start by reading step 4 of the section on how to implement highly effective age assurance.

What is highly effective age assurance and why is it important?

Age assurance is a cornerstone of the Online Safety Act and the basis for children’s online safety. To effectively protect children, services that allow harmful content must understand which of their users are children. This will allow them to ensure children are protected from harmful content and contact without unduly infringing the rights of adult users.

Under the Act, age assurance must be highly effective at correctly determining whether a user is an adult or a child. In our guidance, we establish a principles-based approach to HEAA that is designed to be flexible, tech-neutral and future-proof. While there are a range of duties and measures that require HEAA, we have set out a consistent standard of highly effective age assurance across all in-scope services.

Failure to comply with the law could result in enforcement actions and – in the most serious cases – fines of up to 10% of your qualifying worldwide revenue, or £18 million, whichever is greater.

Future expansions to age restrictions

In June 2026, the Government announced that the use of highly effective age assurance will be critical to the successful implementation of age restrictions for social media services. We recognise that this would introduce a new age limit of 16 alongside 18. We are working to deliver a rapid assessment of highly effective age assurance for determining whether someone is over 16 that can be used to inform parliamentary debate by the end of October.

In the meantime, the existing duties continue to apply.

How to determine if your service is required to implement highly effective age assurance

Services that are in scope of the Online Safety Act must check if they need to implement HEAA.  If you are unsure if you are in scope of the Online Safety Act, you can use our online tool to check.

The requirement to implement HEAA depends on whether your service allows content that is harmful to children, as defined by the Online Safety Act.  

There are two types of services that must implement HEAA: user-to-user services and all publishers of pornography.

    User-to-user services (Part 3 services)

    Part 3 services are defined in the Act as providers of user-to-user and search services. The age assurance duties for Part 3 services apply to user-to-user services.

    User-to-user services are online services that enable users to generate, share or upload content (such as messages, images, videos, comments, audio) on the service that may be encountered by other users of the service. This includes services that enable user interactions.

    Not all user-to-user services must implement HEAA. To determine if your service needs to do so, follow these steps:

    1. Complete a Children’s Access Assessment

    All Part 3 services must complete a children’s access assessment to determine if they are “likely to be accessed by children”. To complete a children’s access assessment, you can use our children's access assessment digital toolkit.

    As explained in our Children's Access Assessments Guidance (PDF, 968.02 KB), we anticipate that most Part 3 services that do not use highly effective age assurance are likely to be accessed by children within the meaning of the Act.

    2. Carry out a Children’s Risk Assessment

    If you determine that the service, or part of your service, is likely to be accessed by children then you need to complete a children’s risk assessment. Our digital toolkit is designed to help you do this.

    You should follow the four-step risk assessment process outlined on the Protection of children duties under the Online Safety Act page. This will enable you to identify which Protection of Children measures are recommended for your service, including the measures relating to HEAA.

    Publishers of pornography (Part 5 services)

    A Part 5 service is an internet service on which pornographic content is published or displayed by the provider of the service. This is defined in the Act as ‘regulated provider pornographic content’. This is distinct from Part 3 services which host user generated content that may include pornography.

    Specific duties are imposed on part 5 services to use a form of age assurance that is highly effective at correctly determining whether a particular user is a child, to ensure that children are not normally able to encounter such content on their services along with record keeping duties (section 81 of the Act).

    In January 2025, these duties came into force, and we published the Guidance on highly effective age assurance and other Part 5 duties (PDF, 775.13 KB).

    All Part 5 service providers must implement HEAA. Age assurance must be applied before a user is able to view any pornographic content or access the service, unless the user has been determined to be an adult.

    Part 5 service providers must also keep a record of age assurance, including:

    • the kinds of age assurance you have used and how you have used them on your service.
    • how you have had regard to privacy and data protection laws when deciding which age assurance process to use and how.

    How to implement highly effective age assurance

    Show all steps

    1

    Our approach to age assurance gives services a degree of flexibility in how to comply.

    Our guidance sets out a non-exhaustive list of kinds of age assurance that we consider are capable of being highly effective at correctly determining whether or not a user is a child.  It also sets out methods we do not consider capable of being highly effective.

    Methods capable of being highly effective at 18 include:

    • Credit card checks
    • Digital identity services
    • Email-based age estimation
    • Facial age estimation
    • Mobile-network operator (MNO) age checks
    • Open banking
    • Photo-identification (photo-ID) matching

    Methods not capable of being highly effective at 18 include:

    • Self-declaration of age
    • Age verification through online payment methods which do not require a user to be over 18 (debit cards)
    • General contractual restrictions on the use of the service by children

    2

    We have developed guidance for publishers of pornography (Part 5 services) and Part 3 services to assist you in implementing HEAA to comply with your duties.

    To ensure that an age assurance process is, in practice, highly effective at correctly determining whether or not a user is a child, you should ensure that the process fulfils each of the following four criteria.

    Meet the four criteria

    Technical accuracy

    Technical accuracy is the degree to which an age assurance method can correctly determine the age of a user under test lab conditions.

    Robustness

    Robustness is the degree to which an age assurance method can correctly determine the age of a user in actual deployment contexts. Implement age assurance processes that have undergone tests in multiple environments during development.

    Reliability

    Reliability is the degree to which the age output from an age assurance method is reproducible and derived from trustworthy evidence.

    Fairness

    Fairness is the extent to which an age assurance method avoids or minimises bias and discriminatory outcomes.

    Consider the two principles

    As well as meeting the four criteria, your age assurance process should be easy to use and work for all users. This will also help you make sure that adult users can still access legal content. You should consider the following two principles when implementing age assurance methods or processes.

    Accessibility

    This is the principle that age assurance should be easy to use and work for all users, regardless of their characteristics or whether they are members of a certain group.

    Interoperability

    This means the ability for technological systems to communicate with each other using common and standardised formats.

    Consider third-party or in-house age assurance solutions, and wider system level measures

    You have the flexibility to purchase method(s) from a third-party vendor or choose to implement your own in-house age assurance method(s).

    Using a third-party vendor

    If you are using a third-party vendor, you can use Vet your vendor: A resource to help services conduct due diligence on their age assurance providers for a non-exhaustive list of key questions to ask as part of your due diligence when selecting and reviewing any vendor(s) you employ.

    Implementing your own methods

    If you are implementing your own method(s), you still need to do the appropriate due diligence. Use our vendor resource, as well as the relevant HEAA guidance, as a guide for the types of questions you should be considering when developing in-house solutions.

    Additionally, there are wider system-level age assurance measures that could be used by service providers to distinguish between children and adults on the service, including providers of app stores and operating systems.

    Ultimately, regardless of where the age assurance occurs in the ecosystem or whether it is implemented by the service provider or by a third-party, it is the service providers responsibility to ensure that the assurance process is highly effective.

    Determine where to place your age gate to comply with your duties under the Act

    Where you need to place your highly effective age check depends on the type of service, the content that is allowed on the service, and the risk level. If the principal purpose of a service is to host or disseminate a kind of primary priority content that is harmful to children, such as pornography, or priority content that is harmful to children, such as violent content, then HEAA should be used to prevent children from accessing the entire service. 'Principal purpose’ in this context refers to the main activity or objective of the service.

    For pornography services, we outlined in a blog post that we consider that the safest approach to do this is by using a ‘front gate’, whereby the user sees only a blank landing page, with no content visible until they have completed the age check.

    Other user-to-user services may need to use HEAA to target safety measures towards children to protect them from being exposed to harmful content they have identified through content moderation or in children’s recommender feeds.

    User-to-user services should consult Ofcom’s Protection of Children Code for user-to-user services (PDF, 953 KB) for more information on the age assurance measures required for different user-to-user services, and to determine where to place your age gate to comply with your duties.

    3

    All age assurance methods involve the processing of personal data. As outlined in our Joint Statement with the ICO on age assurance (PDF, 708 KB), services can process personal data for age assurance, as long as the method used is necessary, proportionate for your risks, and complies with data protection legislation.

    We’ve worked closely with the Information Commissioner’s Office (ICO) to adopt a cohesive approach supporting compliance with our respective regulatory regimes. Our HEAA guidance sets out where services should consult ICO guidance for further information on data protection requirements.

    Compliance by service providers with both the online safety and the data protection regime is mandatory and should not be considered a trade-off.

    Our Report on the use of age assurance (PDF, 1.51 MB) identifies privacy and data protection compliance as an area for improvement. Services must give users clear, accessible information about how their data is processed, used and deleted, especially where information is aimed at children. This may include plain English or child-friendly formats.

    4

    Once you have implemented your HEAA process, you should make sure that you are monitoring the effectiveness of your age assurance process. You should make changes to your age assurance process where appropriate to improve effectiveness.

    In the Report on the use of age assurance (PDF, 1.51 MB), we identified three main areas where we observed shortcomings in services’ implementation of age assurance. Services should review their age assurance process against these areas and make improvements without delay:

    1. Follow our HEAA guidance in full, including implementing a challenge age and liveness detection where relevant, repeating age checks and applying anti-circumvention measures where appropriate, consider offering a variety of age assurance methods, and implement an age assessment appeals process
    2. Do your due diligence, including using Vet your vendor: A resource to help services conduct due diligence on their age assurance providers and measuring and monitoring performance using appropriate metrics
    3. Comply with UK privacy and data protection obligations, consulting relevant ICO guidance

    Section 8 of the Report on the use of age assurance (PDF, 1.51 MB) gives more detail on these areas and the suggested improvements.

    Further guidance and resources

    To understand our recommendations, including further technical detail to help services implement HEAA, user-to-user services should consult:

    To understand the scope of Part 5 and how they can meet all the requirements of the Part 5 of the Act, Part 5 services should consult:

    For service providers which allow pornography, our Adults Only page has further information about what steps you need to take to protect people from harm.

    Rate this page

    Was this page helpful?