Online Safety Act: Ofcom fines two adult sites for age verification failures
The question
How is Ofcom enforcing the age assurance requirements of the Online Safety Act 2023 (OSA) in respect of online providers of pornographic services, and how does the regulator determine the penalties for failure to comply?
The key takeaway
Ofcom, the UK communications regulator, is signalling that “age gates” based on self-declaration will not meet the OSA standard for pornographic content, and that penalty levels will be highly fact specific. Relevant factors include reach and risk, duration of non-compliance, cooperation and remediation, and the provider’s size and ability to pay.
The background
Age assurance - processes that estimate, infer, or verify a user’s age to prevent children from accessing age-inappropriate content - is a fundamental tenet of the OSA which came into force in October 2023. Ofcom’s statutory codes of practice require in-scope services to use “highly effective” age-assurance measures when restricting access to the highest-risk categories of content, including pornography. See our Winter 2025 edition of Snapshots for more information on Ofcom’s approach to age assurance measures.
The development
Ofcom has published two penalty decisions against providers of online pornographic services, First Time Videos LLC (who were fined £80,000) and fapello.com (who were fined £630,000), for failing to implement effective age assurance to prevent children accessing adult content. Fapello.com has now been “geo-blocked” from UK IP addresses, meaning it cannot be accessed directly from the UK.
These investigations form part of Ofcom’s initial wave of enforcement decisions under the OSA, where it is building expectations around what “effective” age assurance under Section 81 of the OSA looks like in practice. Ofcom’s core message from both investigations is that services publishing pornographic content must implement measures that are effective at preventing access by children, and that simplistic prompts (for example, “click if you are 18 or over”) are unlikely to be sufficient. Similarly, the presence of a paywall was found not to amount to effective age assurance given debit cards do not have 18+ requirements.
The decisions further highlight that enforcement is not limited to UK-headquartered businesses: services accessible in the UK can be in scope even where the provider is established overseas.
Why were the fines so different?
While both companies were investigated for failures in relation to implementing age assurance checks, the significant difference in financial penalty indicates that fines can diverge sharply depending on the regulator’s assessment of seriousness and proportionality. All penalties are assessed according to Ofcom’s Penalty Guidelines.
- Ofcom typically calibrates penalties by reference to the provider’s financial position (often by reference to turnover) to ensure the sanction is proportionate yet remains a deterrent, meaning a larger enterprise can face materially higher figures for comparable failings
- the duration of non-compliance and the scale of potential exposure (including likely UK reach/traffic and the ease with which users can access content) can increase seriousness, and therefore the level of penalty
- Ofcom’s narrative in these cases commonly distinguishes between providers that move quickly to implement robust controls and engage constructively, and those that remediate late or incompletely - prompt, evidenced remediation and cooperation can materially reduce penalty outcomes. In this case, fapello.com received a £30,000 uplift to the original £600,000 penalty for its failure to respond to a formal request for information from Ofcom.
Why is this important?
These decisions demonstrate that Ofcom is moving from supervision to active enforcement where child access risks are clear, and that financial exposure is not predictable from the type of breach alone.
The emerging lesson is that governance and transparency - being able to demonstrate what controls are in place, why they are effective, and how they are monitored - are key factors when Ofcom assesses mitigation when determining the level of penalty.
For organisations providing adult content services or any environment where age restricted material may appear, these decisions are a warning that age assurance is no longer a “nice to have”, it is a core compliance obligation which will be subject to rigorous enforcement by Ofcom.
Any practical tips?
To avoid enforcement action, online providers of pornographic services should consider:
- auditing current age assurance methods against Ofcom’s “highly effective” standard and identify gaps early
- prioritising high‑risk content as adult content requires the strongest assurance and the most robust measures
- evidencing decision‑making by keeping clear records showing why particular controls were selected, how they work, and how their effectiveness is monitored
- validating user journeys, in particular how easily a UK user could reach restricted content in practice
- reviewing payment‑based checks, as paywalls alone will likely not meet the required standard.
Autumn 2026
Stay connected and subscribe to our latest insights and views
Subscribe Here