What Is the UK’s Online Safety Act?
The UK’s Online Safety Act formally became law after receiving Royal Assent on October 26, 2023, and came into full force from March 17, 2025 (in practice, commencement dates were set for each provision). It requires online service providers to assess and manage the risks of illegal content or content harmful to children. The UK’s communications regulator, Ofcom, has begun enforcement. A broad range of operators, including social media and search services, are covered regardless of whether they are large or small, with regulation by Ofcom and penalties for violations. While particular emphasis is placed on protecting children and strengthening age assurance, concerns have also been raised about freedom of expression and the burden on small businesses
Of these, some additional provisions came into force on July 25. These include some core provisions, such as mandatory age assurance.
The “core provisions” that came into force on July 25 refer to additional duties and rules concerning the protection of minors. The main points are as follows.
- Platform operators were placed under a duty to protect users under 18 from illegal or harmful content.
- The sharing of AI-generated “deepfake pornography” and “cyberflashing” became regulated as new criminal offenses.
- Mandatory age assurance was strengthened, requiring platforms to introduce advanced age-checking methods and prevent minors from accessing adult content and the like.
- An approach that protects minors’ rights and safety from the design stage is required, including making minors’ accounts and personal information private by default, adding features to prevent cyberbullying and inappropriate contact, implementing safety measures for AI chatbots, and eliminating addictive design elements.
These provisions require platforms to strengthen their systems and operations in stages in order to “protect minors from harmful or illegal content.” However, some special cases and exemptions for smaller business also exist. Table 1 summarizes them.
Age-Checking Methods Permitted by Ofcom
As of July 2025, the age-checking methods permitted by Ofcom include the following “robust and highly effective” methods.
- Facial age estimation (using AI to estimate age from a selfie)
- Photo ID matching (uploading and checking an image of an official document, such as a driver’s license or passport)
- Digital identity services (using information already registered in a digital identity wallet such as Yoti)
- Open banking checks using a bank account or similar service (providing age information through a bank’s secure login system)
- Mobile network subscription information (checking age using a phone number and a mobile carrier’s subscription information)
- Credit card checks (using a card available only to those aged 18 or older)
- Analysis of usage history linked to an email account (making use of the account’s age-related history on a particular service)
Ofcom generally does not permit “self-declaration (a checkbox only)” or methods that are insufficiently effective at verifying the user, such as simply entering a date of birth. Furthermore, because the methods differ in terms of privacy protection and the risk of data leaks, operators are required to select their technology on the basis of a risk assessment.
Although there is a wide range of methods, various loopholes began to be used immediately after the law came into force on July 25.
Loophole 1: VPNs
As was also the case when a similar law came into force in France, VPN registrations surged. They reportedly increased by 1400% within just minutes of the law taking effect. (For comparison, the increase in France was 1000%.)
Just a few minutes after the Online Safety Act went into effect last night, Proton VPN signups originating in the UK surged by more than 1,400%.
Unlike previous surges, this one is sustained, and is significantly higher than when France lost access to adult content. pic.twitter.com/W9R5FQBWKa

Ofcom prohibits platform and website operators from carrying content that “promotes, publicizes, or recommends the use of VPNs” to help minors bypass age-checking procedures required by the Online Safety Act. However, banning VPNs themselves is impossible, and Ofcom appears to be faced with a difficult response.
Loophole 2: Flaws in Age Estimation Using Facial Images
As noted above, Ofcom also permits AI-based facial age estimation. The specific mechanism works as follows.
- Face Detection and Facial Landmark Extraction
- AI-Based Age Estimation
- A machine-learning model (mainly deep learning, such as a CNN) is trained in advance on millions to tens of millions of “face images plus actual age data”.
- The trained model compares the features of the input facial image with the enormous number of facial patterns it has seen before. It statistically calculates, “Approximately what is the average age of people with similar feature patterns to this face?”.
- In many cases, the estimate is given as a range, such as “age ◎ to age ○,” rather than as an absolute age. At the end of the process, the facial image itself is deleted immediately, protecting privacy as well.
- Processing Flow (Example)
- Upload a facial image/acquire video from a camera
- Detect face → extract facial landmarks → input into age-estimation model
- Output the closest age group or average estimated age
- Return the result and delete the image
The following advantages have been cited.
- No Personal Information Required; Privacy-Focused
- Highly Accurate and Fast Decisions
- In many cases, AI estimates are more accurate than visual inspection or decisions by staff, and are less susceptible to mistaken judgments or subjective bias.
- A decision takes only a few seconds. The technology can be used immediately by large-scale services, unattended checkouts, and automated ticket machines.
- Inclusivity (Easy for Anyone to Use)
- Protection Against Impersonation and Security
- Operational Efficiency and Trouble Prevention
- Resistance to Attacks Using Borrowed Identification
- It becomes more difficult to bypass age checks by borrowing an older person’s identification.
In ISO/IEC 27566-1 Age assurance systems Part 1: Framework, this corresponds to the part referred to as Age Estimation.
Its use is expanding in online services such as Discord, Reddit, BlueSky, and Xbox, as well as at self-checkouts in UK retail stores and restaurant chains. However, some implementations without resistance to presentation attacks have been used and circumvented, attracting attention. Specifically, it has been reported that Discord’s system can be bypassed using the photo mode in the action game Death Stranding (also known as “Desu Suto” in Japanese), released by Sony Interactive Entertainment1.
Death Stranding’s photo mode is a multifunctional system that lets players enjoy taking pictures of scenery and characters in the game. It is launched by pressing the left side of the touchpad. With game progress paused, players can freely change the camera position and angle, finely adjust various settings, and make detailed changes to the pose, facial expression, gaze, and other aspects of Sam (the protagonist), the subject being photographed. It appears that this feature was used to make him follow instructions such as “look to the right,” thereby bypassing Discord’s age estimation. It seems either that the implementation did not meet requirements of the kind specified in ISO/IEC 30107 Biometric presentation attack detection and ISO/IEC 19989 Criteria and methodology for security evaluation of biometric systems, or that these standards contained gaps. Future developments will be closely watched.
Footnotes
- Satomi. 2025-08-03. Security Hole Allows Age Verification on 18-Prohibited Sites to Be Bypassed With a “Selfie of a Game Screen.” Gizmode. https://www.gizmodo.jp/2025/08/k-id.html (retrieved 2025-08-06)
