Last reviewed: September 2, 2026. The June 29, 2026 finding still holds: no new Ofcom fines, settlements, or VPN-related enforcement actions have surfaced beyond the documented 4chan (August 2025 / March 2026) and AVS Group (December 2025) actions. The August-September 2026 review window surfaced three additions to the international age-assurance landscape this article tracks: EFF's warning that Meta's $17 billion teen-safety settlement (announced August 2026) will normalize age assurance as the default enforcement mechanism; EFF's August 31, 2026 call for California Governor Newsom to veto AB 1709, an under-16 social-media restriction with age-verification elements now sitting on his desk; and EFF's August 26, 2026 reporting on France's Constitutional Council decision n° 2026-911 DC dated August 14, 2026, which struck down that country's under-15 social-media ban as incompatible with French constitutional protections for free expression and the right to privacy. The UK OSA's defenders can no longer point to France as a parallel model. The July 2026 procedural items (Ofcom "Use of Age Assurance Report 2026" and the joint ICO / Ofcom age-assurance guidance) remain as documented. The £18M / 10%-of-turnover penalty cap and the July 25, 2025 deadline remain as documented.
TL;DR: On July 25, 2025, the UK's Online Safety Act age-assurance rules took full effect. The mechanism (third-party age verification across large parts of the web) has created a national identity-checking infrastructure that activists warn normalizes mass data collection, algorithmic censorship, and the erosion of online anonymity. Ofcom now has £18M / 10%-of-turnover enforcement power. Three concrete fines have already been issued: 4chan (£20,000, Aug 2025), AVS Group (£1M, Dec 2025), 4chan further (£520,000, Mar 2026).
Introduction: The Day the Open Internet Closed
On July 25, 2025, the internet in the United Kingdom fundamentally changed. For millions of users, what had long been an open platform for information, community, and expression became a permission-based system, partitioned by digital checkpoints demanding proof of identity. This date, dubbed "Age Verification Day" by some, marked the full enforcement of the age assurance mandates within the UK's Online Safety Act 2023.
While the government's stated goal was to protect children from harmful online content, the mechanism chosen (strong, technical age verification across large parts of the web) has in practice created a trojan horse for mass data collection, algorithmic censorship, and the erosion of online anonymity. Platforms were deputized to outsource identity checks to third-party providers, and in doing so they helped build a national identity surveillance architecture.
Section 1: The Architecture of Control
The Online Safety Act 2023 imposes a sweeping "duty of care" on a wide range of online services, forcing them to prevent children from encountering illegal and "harmful and age-inappropriate content." To satisfy Ofcom's requirement for "highly effective" age assurance, platforms have adopted invasive verification methods: photo-ID matching, facial age estimation, credit checks, and mobile operator attestations. The combination of vague definitions of "harm" and extremely punitive enforcement powers (fines up to £18 million or 10% of global turnover) coerces platforms into choosing the most legally defensible, and therefore most privacy-invasive, options.
Section 2: The Verification Machine: Technology, Data, and the Corporate Ecosystem
In practice, users now pass through digital checkpoints that demand sensitive data: passports, driver's licenses, biometric selfies, or financial credentials. An entire "age assurance" industry has sprung up to service this market, from boutique certificate providers to large data brokers and credit bureaus. The involvement of firms with deep financial and identity records transforms a one-off age check into a permanent identity event, enriching corporate profiles and creating powerful incentives for data retention and mission creep.
Section 3: The Privacy Paradox: Engineering the Ultimate Data Honeypot
Despite marketing claims of "privacy-preserving" checks, the system creates centralized databases of passports, biometric templates, and financial attestations: high-value honeypots for criminals and hostile states. Biometric data is classified under GDPR as special category data; its mass collection for routine age checks normalizes permanent biometric surveillance. Even where providers claim to delete source documents, persistent tokens and cross-site attestations allow tracking and profiling of verified users.
Section 4: The Chilling Effect: Algorithmic Censorship and Free Expression
The law's implementation led to massive over-blocking as platforms opted for extreme caution. Communities providing support for marginalized users, public health discussions, and other legitimate forums were often age-gated or restricted. Automated moderation systems, unable to reliably interpret context, further amplified the problem. The result is a pervasive chilling effect: users self-censor, vulnerable groups lose access to resources, and public discourse suffers.
Section 5: A Global Panopticon? The UK's Mandate in International Context
The UK's identity-control model contrasts with the US and EU approaches: the US focuses on platform design and parental tools, while the EU pursues privacy-by-design solutions such as cryptographic attestations from an interoperable Digital Identity Wallet. The divergence is fracturing the global internet and creates pressure for platforms to adopt the UK's most restrictive model worldwide or to block access by jurisdiction.
Section 6: The Road to Digital ID: Connecting the Dots to a Surveillance State
The Online Safety Act is part of a broader strategy that includes GOV.UK One Login, reforms to Companies House, and the emergence of State-certified Digital Verification Services. By normalizing identity checks for routine online activities, the law paves the way for a unified digital identity architecture that could link online access, employment checks, and government services to a single revocable key, creating a powerful single point of control.
Conclusion: A Blueprint for Repression
The Online Safety Act, while promoted as child protection, has created a deeply flawed infrastructure for mass surveillance and censorship. It normalizes identity-based access to the internet, creates honeypots of sensitive data, and structurally incentivizes over-blocking and algorithmic censorship. The urgent alternative is to pursue privacy-enhancing, user-empowering designs rather than identity-based control.
Enforcement Update (August 2025 – March 2026)
Ofcom has begun issuing fines under the Act. The known actions to date:
- August 2025, 4chan: £20,000 fine for alleged non-compliance with the OSA's risk-assessment duties, with additional daily penalties accruing at £100/day if uncorrected.[5]
- December 2025, AVS Group (Belize): £1 million fine for allegedly inadequate age-verification on adult sites, plus £50,000 for failing to respond to Ofcom information requests.[6]
- March 2026, 4chan: A further £520,000 fine for continued non-compliance, bringing 4chan's total exposure to roughly £540,000 plus the accruing daily penalties.[7]
None of these fines approach the £18M / 10%-of-turnover statutory cap. They are nevertheless useful as evidence that the OSA's enforcement machinery is now active and that platforms which refuse to engage with Ofcom are paying a real, escalating price. The two 4chan actions also show that the regime is willing to chase non-UK-domiciled defendants when they serve UK users.
Update (July 24, 2026)
Two procedural events of the past two weeks matter more than the absence of fresh fines. First, Ofcom published the statutorily required "Use of Age Assurance Report 2026" on July 15, 2026, the formal assessment of how regulated services have implemented age assurance under the Online Safety Act and how effective the measures have been at protecting children. The Online Safety Act required Ofcom to publish this report by the end of July 2026, so the publication is the first formal regulatory acknowledgement of whether the identity-checking infrastructure this article describes is delivering its stated child-protection goal.
Second, the Ofcom/ICO joint statement on age assurance, issued in March 2026, provides guidance that runs alongside the July 15 report. The joint guidance outlines how the two regulators will collaborate on enforcing the age-assurance provisions of the Online Safety Act. Ofcom's framing in the joint statement is that the new guidance is intended to help online platforms better protect children's personal data while ensuring adults can use services with confidence. That dual mandate (protect children, preserve adult access) is the precise tension this article raised in the privacy-paradox and verification-machine sections: every new safeguard layered on top of the age check is another data point that flows into the verification pipeline, and the privacy regulator's involvement is the only reason the children's data stays inside the same honeypot the article warned about.
The Ofcom investigation stack did not produce a new platform-specific fine in the July 2026 review window. The same due process that limited the existing three fines (4chan £20,000 / £520,000, AVS Group £1 million) held. The substantive news is that the regulatory framework is now functioning as written: the statutory report is out, the joint guidance is out, and the next compliance event on the calendar is the Spring 2027 broader categorised-services register. The article's central claim, that the OSA's age-assurance mechanism is building a permanent national identity-checking infrastructure that activists warned would normalize mass data collection, is the precise structure the joint guidance now formalises. The regulatory framework is not in stasis; it is in the first phase of expected enforcement, and the next year of ICO and Ofcom joint action will be the test of whether the children's-privacy safeguard the ICO brought to the table actually traces the data, or whether it sits alongside the data flow as a procedural checkbox.
Sources for this update: Ofcom. "Use of Age Assurance Report 2026." July 15, 2026; Ofcom and ICO. "Joint Statement on Age Assurance." March 2026.
Update (September 2, 2026)
The international age-assurance landscape this article tracks has moved sharply in the seven weeks since the Ofcom "Use of Age Assurance Report 2026" and the joint ICO / Ofcom guidance. Three developments are worth surfacing because each one shifts the same privacy-paradox and verification-machine structure this article raised: identity-based child protection is the policy-of-the-moment in three jurisdictions at once, the civil-liberties objections have moved from advocacy into court rulings and major-platform settlements, and the UK framework is now the longest-running test case rather than the leading edge.
First, EFF published on September 1, 2026 a formal warning that Meta's $17 billion teen-safety settlement (announced August 2026, between Meta and 52 state attorneys general) will normalize age-assurance technology as the default enforcement mechanism for any platform minors can reach. EFF's argument is structural: the deal constrains teen autonomy more than it protects it, expands the monitoring footprint that age checks leave behind, and enshrines identity verification at the platform layer in a way that travels with the user across products, devices, and jurisdictions. The settlement is the producer-side version of the same problem this article raised in the privacy-paradox section: once age assurance is built into a platform's compliance posture, the identity layer does not stay confined to a single age check. The EFF's separate statement on the Meta settlement (August 26, 2026) calls it a "harmful surveillance" template.
Second, EFF asked California Governor Gavin Newsom on August 31, 2026 to veto AB 1709, the under-16 social-media restriction then sitting on his desk. The bill relies on age verification to enforce its age floor, and EFF's argument is the same one this article made about the UK framework: identity-based child protection is, at the platform layer, a permanent identity-checking infrastructure, and the children's-privacy safeguard the bill's proponents point to sits on top of the same honeypot this article described. California's age-verification law landscape is documented in our prior coverage of AB 1709 and AB 1856, and the September 1 Meta-settlement warning landed inside the same week Newsom's veto decision was due.
Third, EFF reported on August 26, 2026 that France's Constitutional Council struck down that country's under-15 social-media ban in Decision n° 2026-911 DC dated August 14, 2026, ruling it incompatible with French constitutional protections for free expression and the right to privacy. The UK OSA's defenders had previously pointed to the French age floor as a parallel model; that parallel is now gone. The ruling does not bind UK regulators, but it removes the cross-jurisdiction argument that identity-based child protection is on a settled European trajectory. Combined with the September 1 Meta warning and the August 31 California veto ask, the August 14 French ruling is the third data point in a one-week sequence: age-assurance mandates are now simultaneously being normalized in court settlements, contested at the state level in the US, and struck down at the constitutional level in Europe.
The UK-specific news in this window is a CDT poll reported by The Register on September 2, 2026: 89 percent of British adults want a court order before any access to their encrypted messages. The polling lands as the UK Online Safety Act and Ofcom guidance continue to push for client-side scanning under the OSA's "accredited technology" provisions, and it puts a public-opinion floor under the argument this article has been making: the verification-machine section's identity layer is now sitting next to a public mandate that would require a judicial warrant before the same identity layer can be turned against encrypted communications. The next compliance event on the Ofcom calendar is the Spring 2027 broader categorised-services register, and the substantive question for that register is whether the children's-privacy safeguard the ICO brought to the joint age-assurance guidance actually traces the data, or whether it sits alongside the data flow as a procedural checkbox. See the September 2, 2026 daily briefing for the full set of references.
Sources for this update: EFF. "Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users." September 1, 2026; EFF. "EFF to Governor Newsom: Veto California's AB 1709." August 31, 2026; EFF. "French Top Court Gets It Right, Strikes Down Social Media Ban For Youths." August 26, 2026; EFF. "EFF Statement on Meta Settlement." August 26, 2026.
Update (September 23, 2026)
What changed: Ofcom has issued a fourth fine under the Online Safety Act, and it has opened the second major enforcement programme of the post-implementation period. On September 4, 2026, Ofcom fined Xgroovy.com a total of £730,000, split as £700,000 for failing to implement age assurance between July and November 2025 and £30,000 for failing to respond to Ofcom information requests. A daily penalty of £200 per day began accruing on September 3, 2026 if Xgroovy fails to bring itself into compliance. The fine is the second-largest under the Act to date (the largest remains the £1 million penalty against AVS Group in December 2025) and is the first under the Act's "Enforcement Programme to Protect Children from Encountering Pornographic Content Through the Use of Age Assurance." Xgroovy did eventually deploy age checks before the fine was issued, a pattern that matches the enforcement-to-compliance loop the article described: Ofcom announces an investigation, the platform rolls out identity verification, and the fine monetizes the months-long gap during which neither the children-protection safeguard nor the data-protection safeguard was in place.
On September 9, 2026, Ofcom opened a second enforcement programme targeting non-consensual intimate image abuse (NCII) and AI-generated deepfakes. The deadline for platforms to have measures in place is September 30, 2026. Ofcom has tied the programme to the StopNCII.org hash-matching platform and to the Illegal Content Codes Ofcom strengthened to include the new intimate-image-abuse obligations. The Register reported September 17, 2026 that Ofcom is finding it easier to issue OSA fines than to collect them, an enforcement-to-revenue problem that has surfaced in the prior 4chan actions (where the daily-penalty clock runs against a non-UK-domiciled defendant with no obvious UK assets) and now also constrains the Xgroovy collection. The substantive change is not the fine totals but the regulatory cadence: three months into the post-implementation window, Ofcom has now moved from "investigation" mode to "enforcement programme" mode in two separate domains (age-assurance and intimate-image-abuse), and the Spring 2027 broader categorised-services register will be the next inflection point.
The UK OSA's central claim from this article, that the age-assurance mechanism is building a permanent national identity-checking infrastructure, is now operationally being layered with a second enforcement programme that uses the same identity infrastructure as the routing layer for hash-matching NCII reports. The privacy-paradox structure the article raised in Section 3 is the same structure: every new obligation layered on top of the age check is another data point that flows through the verification pipeline, and the children's-protection and women's-protection mandates are now both being routed through the same identity infrastructure the OSA built to enforce child safety in the first place. The verification-machine layer (Section 2) now has two statutory missions feeding into the same data flow. The next compliance event on the calendar is the Spring 2027 broader categorised-services register, and the substantive question for that register is whether the children's-privacy safeguard the ICO brought to the joint age-assurance guidance actually traces the data, or whether it sits alongside the data flow as a procedural checkbox.
Sources for this update: Ofcom. "Porn Site Deploys Age Checks as Ofcom Fines It £730,000." September 4, 2026; Ofcom. "Enforcement Programme to Protect Children from Encountering Pornographic Content Through the Use of Age Assurance." 2026; Ofcom. "Ofcom to Crack Down on Spread of Illegal Intimate Images and Deepfakes, Boosting Protections for Women and Girls Online." September 9, 2026; The Register. "Ofcom Discovers Issuing Online Safety Act Fines Is Easier Than Collecting Them." September 17, 2026.
References
- Electronic Frontier Foundation
- Open Rights Group
- UK Government / Ofcom guidance
- Information Commissioner's Office (ICO)
- Online Safety Act 2023: Wikipedia (Enforcement section, August 2025 Ofcom action against 4chan)
- Online Safety Act 2023: Wikipedia (December 2025 £1M fine of AVS Group)
- Online Safety Act 2023: Wikipedia (March 2026 further £520,000 fine of 4chan)