Ofcom has opened an investigation into Aylo, the service provider of Pornhub, over its Pornhub age checks, examining whether the platform has met its legal obligations to prevent children from accessing pornographic content under the UK Online Safety Act.
The investigation focuses on a new age assurance process introduced by Pornhub in May 2026 for some users. The process relies on signals from Apple indicating that UK users attempting to access Pornhub may have completed Apple’s own age checks.
Under the Online Safety Act, responsibility for ensuring that age assurance is highly effective rests with the service provider, regardless of where in the process an age check takes place.
Ofcom Questions Pornhub’s Age Assurance Process
Ofcom said it is concerned that Aylo may not have carried out sufficient due diligence and testing before introducing the new process. The regulator is examining whether the system is sufficiently effective in preventing children from encountering pornography.
The investigation will assess whether Aylo complied with two key requirements under the Online Safety Act: using highly effective age assurance to prevent children from seeing pornography and completing a suitable and sufficient assessment of children’s access to the service.
Ofcom will also examine how Aylo implemented the process and whether the necessary due diligence was completed before deployment. The investigation will not determine how Apple operates its own age checks.
George Lusty, Ofcom’s Director of Enforcement, said online age checks are an important protection against children encountering inappropriate or harmful material and that technology companies are expected to ensure such systems are highly effective before deployment.
Ofcom Sets Out Investigation Process for Pornhub Age Checks
Ofcom said its investigation will begin with gathering and analysing evidence to determine whether a breach has occurred. If the regulator finds evidence of a compliance failure, it can issue a provisional decision to the company.

Aylo would then have an opportunity to respond to Ofcom’s findings before a final decision is made.
If Ofcom determines that a company has broken the law, it can require the platform to take specific steps to comply with its obligations or address harm caused by the breach. The regulator can also impose fines of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.
Ofcom Expands Enforcement Against Intimate Image Abuse
The investigation comes alongside a separate Ofcom enforcement programme targeting the spread of illegal intimate images, including explicit AI-generated deepfakes.
Ofcom has said platforms should have automated hash matching technology in place by September 30 to detect and prevent the sharing of illegal intimate images. Platforms without hash matching must demonstrate that other systems and processes are equally effective at curbing the spread of non-consensual intimate images, or NCII.
Companies that fail to meet their legal duties could face fines of up to 10% of their global annual revenue.
Ofcom has partnered with SWGfL, which operates the StopNCII.org database and Revenge Porn Helpline, to share information and expertise on tackling intimate image abuse online.
The regulator is also seeking evidence from academics, survivor and victim support groups, and other stakeholders about how women’s and girls’ experiences online have changed.
Ofcom said the evidence will contribute to a report on industry progress in reducing online harms to women and girls. The regulator will also consider whether formal recommendations to the UK government are needed if industry action falls short.
The two enforcement efforts highlight Ofcom’s broader focus on requiring online services to put effective safeguards in place before harmful content or access risks materialise.






































