Ofcom opened an Online Safety Act investigation into Aylo, the operator of Pornhub, on 22 September 2026 and announced it the next day. The question is narrow but consequential: if a site uses another company's age-check signal, who answers when that signal turns out to be unreliable?
What Ofcom is actually examining
According to Ofcom's case page, Aylo rolled out a new age-assurance process in May 2026. It relies on signals from Apple suggesting that UK iOS and iPadOS users have already passed Apple's age checks. Ofcom's concern is not that Apple's checks are bad. It is that Aylo may not have done enough due diligence and testing before adopting the process, so that the process may not be "highly effective" at identifying children.
Ofcom says the investigation will examine how Aylo integrated the signals and whether it tested them properly. It also says the probe will not assess how Apple runs its age checks. The regulator states that the responsibility sits with the service provider, wherever the age check takes place. The page cites sections 12 and 36 of the Online Safety Act 2023, and notes that the duty for pornography providers has applied since 25 July 2025.
The strongest case for Ofcom
The case for strict provider liability is serious. Pornography sites are the actors with the commercial incentive, the knowledge of their audience and the ability to gate content. If a site could discharge its duty simply by pointing to an upstream vendor, the duty would become a paper exercise. Liability would diffuse to whoever is hardest to reach. Children would be the ones who pay for any gap between a signal that says "probably verified" and a user who is actually 14.
The word "suggesting" in Ofcom's description matters. A signal that a user "may have" completed an age check is probabilistic. A regulator that demands "highly effective" assurance is entitled to ask whether anyone measured how often that probability fails.
Why the approach still looks proportionate
The notable feature of this case is what Ofcom did not allege. It has not said the Apple-based method is unlawful, and it has not said children got through. Its stated concern is process: did Aylo test, and did it document its children's access assessment? That is the right place for a regulator to stand. It lets a service choose among methods while holding it to a demonstrable standard of care.
This matters for innovation. Device-level age assurance is one of the more privacy-protective designs available. The user proves age once to a platform they already trust, and the site receives a signal rather than a passport scan or face image. Many UK adults dislike handing identity documents to adult sites, and large databases of such documents are attractive breach targets. A regime that punished every reliance on a device-level signal would push providers back toward document upload and facial analysis, the very methods that raise the sharpest privacy and free-expression objections. Open Rights Group and others have long argued that mandatory age checks chill lawful adult speech. The least-bad outcome is an enforcement posture that rewards privacy-preserving designs that are verified to work.
What is at stake for Aylo
As Ofcom's announcement notes, the Act allows fines of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater, along with requirements to take specific compliance steps. George Lusty, Ofcom's Director of Enforcement, said online age checks are "a vital protection to prevent children from encountering inappropriate or harmful material, including pornography."
The Record reports that an Aylo vice president said the company is committed to working constructively with Ofcom and Apple, and pointed out that Ofcom had previously praised Apple's age verification methods. That is a fair point to raise, but it is not a defence on the law as Ofcom frames it. Praise for a tool in general does not establish that a particular integration of it, by a particular site, was tested.
Ofcom's process, per The Record, is to gather evidence, give Aylo a chance to respond, and then decide whether to impose a fine or remediation. No finding of breach has been made. The investigation is a statement of concern, not a verdict, and commentary that treats it as one is premature.
What a good outcome looks like
Three things would make this case useful beyond Aylo.
- Published test expectations. If Ofcom concludes that testing was inadequate, it should say what adequate testing looks like: error-rate measurement, bypass testing, and documentation. Other services relying on platform signals need a target they can meet.
- Clear allocation of duties. Ofcom has said it will not assess Apple. That is sensible for this case, but a chain of reliance that no regulator examines end to end is a gap. Platforms that issue age signals should be transparent about what those signals do and do not certify.
- Remediation before penalty. If the gap is one of testing rather than a demonstrated failure, compliance steps are a better tool than a maximum fine. The regime's credibility depends on distinguishing negligent from merely imperfect.
The principle Ofcom has articulated is correct: a site cannot outsource its legal duty. The test of the regulator's proportionality will be whether it equally encourages the privacy-preserving designs it should want providers to adopt.