Ofcom Probes Device-Level Age Checks at Pornhub's Owner
Ofcom is investigating whether Aylo's Apple device-signal age checks meet the Online Safety Act's highly effective bar, putting the family-device gap on trial.

The family-device problem just got its first regulator. Ofcom has opened a formal investigation into whether Aylo, Pornhub's parent company, meets the Online Safety Act's requirement for highly effective age assurance, after the company built its UK re-entry on Apple's operating-system-level age signals. The regulator's stated concern is procedural, that Aylo may not have conducted sufficient due diligence and testing before implementing its new age assurance process, but the substantive question underneath is the one this industry has been circling all year: does knowing the device owner's age count as knowing the user's?
The backstory makes the stakes plain. Aylo halted new UK registrations in February 2026, arguing the Act was unworkable, then re-entered in May 2026 by consuming Apple's OS-level age verification signals for iOS users. That approach confirms that a device's owner cleared an age check. It structurally cannot confirm that the person holding the device now is that owner, which is why the Age Verification Providers Association argued the arrangement does not clearly achieve compliance: a child who knows a parent's PIN inherits the parent's age.
What the investigation will and will not decide
Ofcom was careful about scope. The investigation examines Aylo's implementation, both the effectiveness of the method and whether the company completed adequate children's access assessments, and the regulator stated it will not make a determination on Apple's verification system itself. That is a meaningful boundary: the OS signal is not on trial, the decision to treat it as sufficient is. The distinction matches how the device-signal era has been legislated everywhere, from California's bracket laws to the EU's wallet plans: the signal is an input the platform consumes, and the duty to assure age stays with the platform.
The enforcement context says this is not theater. By August 2026, eight of the UK's top ten pornographic sites were compliant with the Act's age assurance duties, and Ofcom holds fines of up to £18 million or 10 percent of qualifying worldwide revenue. A regulator that has already normalized compliance across the sector's majority is now testing the ceiling of what compliance means.
The layered answer the bar implies
The investigation sketches the compliance architecture by negative space. If a device signal alone may fail the highly effective bar because it verifies the account, not the human, then the passing build treats the signal as the cheap first layer and adds proof of the present user where the risk warrants it: facial age estimation anchored by passive liveness at the session level, credentials where estimation is contested, and documented testing of the whole stack, the due diligence Ofcom faulted Aylo for skipping.
That layered posture is how the deepidv platform already treats OS signals: as policy inputs with weight, corroborated when the action demands proof the device cannot give, with per-decision evidence and measured accuracy ready for exactly this kind of regulatory examination. Platforms betting an entire compliance program on the device owner's age just watched that bet get called.
Device-Level Age Assurance FAQ
- Why is Ofcom investigating Aylo's age verification?
- Ofcom opened a formal investigation into whether Aylo's use of Apple's device-level age signals meets the Online Safety Act's highly effective age assurance bar, saying the company may not have done sufficient due diligence and testing before deploying it.
- Do Apple's device age signals satisfy the UK Online Safety Act?
- That is the open question. Ofcom explicitly will not rule on Apple's system itself, only on whether a platform relying on it meets the highly effective standard, and the Age Verification Providers Association argues device-level checks alone do not clearly achieve compliance.
- What is the family-device problem in age verification?
- A device-level age signal attests the age of whoever configured or owns the device, not the person using it now, so a child with access to an adult's device and PIN inherits the adult's age. Session-level checks of the present user close the gap.
- What penalties can Ofcom impose under the Online Safety Act?
- Fines of up to £18 million or 10 percent of qualifying worldwide revenue, whichever is greater. By August 2026, eight of the UK's top ten adult sites were compliant with age assurance duties.
- What does highly effective age assurance require in practice?
- A layered stack: consuming device or credential signals where present, verifying the present user by liveness-anchored estimation or credentials where signals are weak or contested, and documented testing plus per-decision evidence that survives regulatory examination.
Relevant Articles
Steam Locks Australians Behind Credit-Card-Only Age Checks
The single-method version of the same failure.
Sep 25, 2026
Australia Doubles Down: A$99M Penalties for Failed Age Checks
The enforcement regime testing the same bar.
Sep 14, 2026
Sportsbook Age Verification: Congress Moves on Face Checks
The US move toward session-level age proof.
Sep 4, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More