A Process Investigation, Not (Yet) a Failure Finding
On September 23, 2026, Ofcom opened a formal investigation into Aylo, the Canadian-based operator of Pornhub, under the UK's Online Safety Act. The question at the center of the probe is narrower than headlines suggest: not whether children accessed Pornhub in the UK, but whether Aylo did enough testing before it changed how it checks ages in the first place.
In May 2026, Pornhub began relying on a new signal-based method: it checks whether Apple's device-level age assurance indicates a UK user "may have completed Apple's age checks," and treats that as sufficient to grant access. Ofcom's enforcement director, George Lusty, said the regulator is "concerned that Aylo may not have conducted sufficient due diligence and testing before implementing its new age assurance process" and that, as a result, children may still be reaching the site. Ofcom was explicit that it is not investigating how Apple's own age-check system works — only whether Aylo, as the service provider, met its own legal duty to verify the method was "highly effective" before switching to it.
Steelmanning the Regulator
The case for this scrutiny is genuinely strong, and it would be dishonest to pretend otherwise. The Online Safety Act 2023 does not just require age checks — it requires providers to complete a "children's access assessment" and re-test effectiveness whenever they materially change how age assurance works, precisely because a device-level signal is a fundamentally different trust model than, say, credit-card or ID verification. A platform hosting pornography that quietly swaps its verification method without validating it first is exactly the failure mode Parliament built the Act to close after years of ineffective self-regulation. And Ofcom has already shown it will act: in December 2025 it fined AVS Group Ltd £1 million — plus £50,000 for stonewalling information requests — after finding its photo-upload age verification across 18 adult sites was too easy for children to circumvent. If a Pornhub-scale platform's age gate quietly weakened when it moved to a new method, that is not a hypothetical harm; it is the exact harm the statute targets.
Where the Concern Belongs
But there is a meaningful difference between AVS's failure and what Ofcom is investigating here. AVS's system was found not to work — children could get through a verification photo-upload flow that was, on inspection, weak. Ofcom has made no equivalent finding against Aylo yet; the investigation is about whether Aylo tested and documented its move to Apple's signal before switching, a procedural and evidentiary question that sits upstream of any demonstrated harm. That distinction matters for how the Act should be enforced going forward. A regime that penalizes companies as severely for inadequate pre-deployment paperwork as for a verification method that visibly failed in the field risks pushing platforms toward whichever age-assurance vendor has the thickest compliance file, rather than the one that is actually hardest to circumvent — Apple's device-level signal, notably, is the kind of cryptographically-anchored, non-transferable check that privacy advocates and security researchers have favored over ID uploads or photo estimation for years, precisely because it can't be defeated by a VPN or a borrowed ID scan the way many "proven" verification methods can.
What's at Stake for the Act's Second Year
The maximum penalty here is real: fines of £18 million or 10% of qualifying worldwide revenue, whichever is greater — a figure that, applied to Aylo's global business, would dwarf the £1 million AVS penalty. Ofcom also retains the power to direct payment processors and ISPs to cut a non-compliant site off from UK users entirely. Those are proportionate tools when a platform's age gate is genuinely broken. They are a blunt instrument if applied to a provider that adopted what independent observers regard as one of the more robust verification methods available and can show it acted reasonably, even if its pre-launch testing paperwork falls short of Ofcom's evidentiary bar.
Aylo has said it will cooperate fully, and has publicly described Apple's system as "one of the strongest and hardest to circumvent protections currently available," according to The Record. If Ofcom's investigation ultimately turns up evidence that the Apple signal was routinely bypassed or that Aylo ignored warning signs, a significant fine will be justified and other platforms should take note. But if the finding is that Aylo adopted a strong method without a fully documented assessment, proportionate regulation argues for a compliance order and a deadline to fix the paperwork — not a fine sized to punish a company for choosing a better technology than its predecessor got fined for lacking.
The Precedent That Actually Matters
What should worry innovation-minded observers is not this specific case but the incentive it sets. If "tested well enough" becomes a moving target that only gets defined after the fact, platforms will rationally default to the most bureaucratically defensible age-check method rather than the most effective one. The Act's second year of enforcement, coming after the AVS precedent, is the moment for Ofcom to draw that line clearly: process failures and outcome failures are not the same offense, and the penalty regime should say so explicitly.