What Ofcom Actually Did
On September 4, 2026, Ofcom fined the operator of Xgroovy.com £700,000 for failing to deploy "highly effective age assurance" between July and November 2025, as required by Section 12 of the Online Safety Act 2023. A further £30,000 was levied for ignoring a statutory information request, plus a running £200-a-day penalty until the provider hands over the requested data or November 3, 2026 — whichever comes first. The provider has since introduced age checks and geoblocked UK users entirely.
The same day, Ofcom issued provisional notices of contravention against two more adult-site operators, Cyberitic, LLC (running shesfreaky.com) and ZD Media, alleging breaches of the same Section 12 duty plus failure to answer information notices under Section 102(8). Cyberitic's investigation began on September 10, 2025; it now has 20 working days to respond before Ofcom finalises a decision. These are not isolated actions — they are the latest entries in an enforcement programme that has already fined 8579 LLC £1.35 million and AVS Group Ltd £1 million for the same category of failure.
The Case For the Crackdown
Ofcom's underlying mandate is not manufactured. Section 12 requires any service likely to be accessed by children and hosting pornography to use age assurance that actually works — not a tick-box birthday field. Before the Act, age-gating on adult sites was essentially theatre: enter any date of birth, or click "I am 18," and you were in. Millions of UK minors could and did access hardcore content this way. A regulator that discovers a provider simply ignoring a binding legal duty for four months, then stonewalling a follow-up information request, has a legitimate case for a fine that stings enough to change behaviour elsewhere in the market — and the deterrent clearly registered: Xgroovy fixed its age gate as soon as enforcement bit, exactly the response the law is designed to produce.
Where the Model Breaks Down
But look at what "fixed" meant in practice. Xgroovy didn't settle into ongoing UK compliance — it geoblocked the country. That is the tell. For a mid-sized adult site, the cheapest response to a six-figure enforcement risk is not to build and maintain a robust age-verification pipeline; it's to exit the jurisdiction. Ofcom counts that as a win because British children can no longer reach that specific domain. It is not obviously a win for the Act's stated purpose, because nothing stops those users — adult or minor — from reaching one of the thousands of adult sites with no UK presence, no UK revenue, and therefore nothing for Ofcom to fine.
That asymmetry is structural, not incidental. Cyberitic and ZD Media, like Xgroovy, are the kind of small-to-mid offshore operators for whom a UK fine is a rounding error next to the cost of running an actual age-verification stack — deploying face-estimation or document-checking vendors, storing evidence of compliance, responding to Ofcom's information notices. Exiting the UK market is frequently the rational, profit-maximising choice. Ofcom's enforcement programme is very good at making individually named sites disappear from the UK; it has much less power over the long tail of unnamed sites that quietly absorb the traffic. Open Rights Group's briefing on VPNs and the Act makes the adjacent point directly: peer Baroness Kidron's own observation, cited in the briefing, is that most VPN downloads driven by this regime are adults distrustful of handing biometric data to unfamiliar verification vendors — not children routing around a block.
The Privacy Trade-off Regulators Rarely Price In
There's a second cost the fine notices don't capture. Open Rights Group has documented that "highly effective age assurance" in practice usually means facial-estimation or ID-scanning tools from third-party vendors — and that at least one major provider, Persona, has been shown reusing face-scan data for purposes well beyond the age check itself, including screening against watchlists. Ofcom's enforcement, by design, only checks whether a provider has age assurance running — not whether the assurance vendor is trustworthy with the data it collects. A regime that fines sites into adopting biometric verification, without an equivalent regulator scrutinising what those verification vendors then do with millions of Britons' faces and IDs, is solving one privacy-adjacent harm by creating another.
A Better-Targeted Enforcement Posture
None of this argues for scrapping age-assurance duties. It argues for proportionality in where enforcement effort goes. Fining named, UK-traffic-heavy providers that ignore the law outright — as Ofcom did here — is defensible and probably necessary. But a regime that measures success in named-site compliance, while treating vendor-side data handling and the whack-a-mole migration to unregulated alternatives as someone else's problem, will keep racking up fines without proportionately reducing the harm the Act was written to prevent. Ofcom's next annual report should track how much UK traffic to non-compliant sites actually falls after each fine — not just how many notices it issued.