Back to library

Now reading

Five countries, one EU layer: the age verification map for adult platforms in Europe

Contents

    Audio · Listen

    0:00
    0:00

    Customize

    0.5× 1.5×
    Aa Aa

      No highlights yet.

        You may also like

        Age assurance in the United StatesState-by-state rules and enforcement Deepfake fraud: the 2026 defense playbookDetecting synthetic identity attacks Digital identity wallets, explainedEUDI, mDL and the new rails

        Share

        Request a demo

        Quick tips

        Turn pages with the arrows, your keyboard, or by dragging the page corner

        Click the page number on the left to jump anywhere in the book

        Select any text to highlight it

        Search on Google →

        Download your eBook

        Would you like to include your highlights?

        eBook

        Get instant access

        Enter your work email to read the full eBook. Free, with the audio narration included.

        Please enter a valid email address.

        We’ll only use your email to share related Incode resources.

        Nice highlight

        Share it on LinkedIn

        eBook cover illustration Download the cover image for your post →

        Five countries, one EU layer: the age verification map for adult platforms in Europe

        Illustration: a person facing a screen rendering a digital face

        Completed

        Request a demo
        01 / 06

        TL;DR

        • Age verification is now the price of market entry for adult platforms in Europe. The UK, France, Italy, and Germany run live, enforced regimes; Spain is building its law and wallet infrastructure in public; the EU layer sits underneath all of them.
        • Enforcement has moved from warnings to consequences: £6,235,000 in UK fines across nine providers in one year, formal notices backed by 48-hour blocking powers in France, a 48-platform obligation list in Italy, and payment-blocking powers in Germany since December 2025.
        • The duty is the same everywhere. The plumbing isn't. France and Italy mandate double anonymity, the UK enforces a published list of "highly effective" methods, Germany accepts only regulator-assessed systems, and Spain is anchoring on a government wallet.
        • The EU sets the floor and the calendar: the Commission's preliminary findings under the Digital Services Act (March 2026) ruled self-declaration ineffective, with exposure up to 6% of global turnover, and member states are urged to have an EU-compliant age proof live by 31 December 2026.
        • Platforms that exited rather than comply are paying in revenue instead of fines. The workable answer is structural: serve each market's compliant flow from one orchestrated integration, with configuration governance and per-jurisdiction audit evidence built in from day one.
        02 / 06

        Important to know

        • Ofcom's statutory age assurance report landed on 15 July 2026: 69 million age checks ran across a sample of 32 services in the second half of 2025, a 23-fold increase on the prior six months, and the share of children who met a highly effective check when asked to prove their age rose from 25% to 43%.
        • The same report opens the quality era. 64 of the UK's top 100 adult services now run age checks and 10 more geoblock, but Ofcom has begun investigating whether implemented methods are actually effective, including its first case against an adult site that already has checks in place.
        • Aylo's flagship sites have been dark in France since June 2025 rather than adopt the double-anonymity standard; France was the group's second-largest market worldwide (CNN, 2025). All 17 sites designated by the French ministerial order now verify age or have left.
        • Italy's regime is live, not proposed: 48 listed platforms had until 12 November 2025 to deploy certified, double-anonymous, per-session checks, on penalty of fines up to €258,228 and blocking until compliant (AGCOM).
        • Germany has required verified closed user groups for online pornography since 2003, the longest-running regime in Europe. Since 1 December 2025 its regulators can also cut payment flows to seriously non-compliant sites.
        • The model is going global: Brazil's data protection authority began monitoring 18 major adult platforms in June 2026 under the country's new child-protection law, with direct enforcement scheduled from January 2027.
        69Mage checks in the UK, second half of 2025 (Ofcom)
        23×increase over the previous six months (Ofcom)
        43%of children now meet a highly effective check, up from 25% (Ofcom)
        03 / 06

        Context: what is happening

        One duty, six rulebooks

        Twelve months ago this week, the UK's duty to keep children off pornographic services with highly effective age assurance took force. In the year since, Ofcom has fined nine providers a combined £6,235,000, opened 23 investigations covering 88 adult services, and published statutory evidence that the checks are working. Its July 2026 report found that when children were asked to prove their age, the share who met a highly effective check nearly doubled in six months.

        Key stat

        69 million age checks ran across just 32 services in the UK between July and December 2025, a 23-fold increase on the previous six months (Ofcom, July 2026).

        The UK is the loudest regime, not the only one. France's SREN law and Arcom's technical standard made double-anonymous verification mandatory in April 2025. Italy's AGCOM rules went live for 48 named platforms in November 2025. Germany has been running the same basic duty since 2003 and tightened it in December 2025. Spain's parliament is processing a minors-protection law while the government ships a wallet that proves age without revealing identity.

        Every major European market now ties adult-content access to a proof of age, and no two markets accept the same proof in the same way.

        The map, regulator by regulator

        Here is where each regime stands as of 21 July 2026.

        UK

        Online Safety Act (Part 5 and children's duties); Ofcom. Highly effective age assurance (HEAA) in force since 25 Jul 2025.

        What it requires: Methods from Ofcom's published list (facial age estimation, photo-ID matching, open banking, mobile-operator and credit card checks, digital identity services); checks must be "technically accurate, robust, reliable and fair"; regular due diligence on vendors; configuration accuracy is audited.

        Enforcement to date: £6,235,000 in fines across 9 providers; 23 investigations covering 88 services; 73% of investigated services now comply or geoblock. Maximum exposure: £18M or 10% of global revenue; business disruption orders. Source: Ofcom, Jul 2026.

        France

        SREN law (May 2024) + Arcom référentiel (Oct 2024); Arcom, privacy design with CNIL. Binding since Jan 2025; double-anonymity option mandatory since 11 Apr 2025.

        What it requires: At least two verification methods, at least one double-anonymous: the site never learns the user's identity, the verifier never learns which site the proof is for.

        Enforcement to date: Formal notices in Aug and Dec 2025; all 17 sites designated by ministerial order now verify or have exited France; minors' time on adult sites down 35% in a year (Arcom). Maximum exposure: €250,000 or 4% of worldwide turnover (doubled to €500,000 or 6% on repeat); blocking and de-indexing orders within 48 hours. Source: Arcom; Sénat.

        Italy

        Caivano decree (2023) + AGCOM delibera 96/25/CONS; AGCOM. Live since 12 Nov 2025 for 48 listed platforms.

        What it requires: Certified independent third-party verification in two separated steps (identification, then per-session authentication); double anonymity; system principles include accessibility, non-discrimination, and effective handling of user complaints.

        Enforcement to date: Obligation list published 31 Oct 2025; supervision and blocking powers active. Maximum exposure: Fines from €10,329 to €258,228, then site blocking until compliant. Source: AGCOM delibera 96/25/CONS.

        Germany

        JMStV (2003, revised 1 Dec 2025); KJM and state media authorities. Longest-running regime in Europe.

        What it requires: Pornography available only inside closed user groups gated by age verification the KJM has positively assessed (80+ systems to date); OS-level child-protection duties phase in to Dec 2027.

        Enforcement to date: Two decades of proceedings and blocking orders; payment-flow blocking power in force since 1 Dec 2025. Maximum exposure: Fines up to €500,000; payment blocking against persistent violators. Source: KJM; die Medienanstalten.

        Spain

        Organic law for the protection of minors in digital environments (bill) + Cartera Digital Beta wallet; CNMC, AEPD. Bill in Congress committee, amendments incorporated June 2026; not yet law. Wallet in beta; Spain among the first five EU mini-wallet adopters.

        What it requires: As drafted: mandatory age verification for adult content, social media minimum age raised from 14 to 16, parental controls by default; the wallet issues an anonymous proof of majority.

        Enforcement to date: Five CNMC fines of €44,829 each for ineffective age checks (Dec 2024); AEPD privacy criteria already shape EU practice. Maximum exposure: Bill's penalty regime pending final text; existing audiovisual-law sanctions apply meanwhile. Source: Congreso de los Diputados; CNMC; AEPD.

        EU (DSA)

        Digital Services Act, Art. 28; European Commission. Preliminary breach findings against four major adult platforms issued 27 Mar 2026.

        What it requires: Effective protection of minors; click-through self-declaration ruled not effective; Commission guidelines (Jul 2025) recommend age verification for adult content.

        Enforcement to date: Formal proceedings open since May 2025; preliminary findings issued. Maximum exposure: Up to 6% of global annual turnover. Source: European Commission.

        EU (wallet layer)

        Commission recommendation on age verification, 29 Apr 2026. Mini-wallet app feature-ready since 15 Apr 2026; member states urged to have a solution live by 31 Dec 2026.

        What it requires: A white-label, privacy-preserving proof of age, deployable as a standalone app or inside national EUDI wallets; Denmark, France, Greece, Italy, and Spain moving first.

        Enforcement to date: Non-binding; national rollouts in progress. Maximum exposure: Not a sanctions instrument (an enabling layer). Source: European Commission.

        Brazil (global watch)

        Digital ECA, Law 15.211/2025; ANPD. Enforceable since 18 Mar 2026; monitoring phase under way.

        What it requires: Verified age via identity document, biometric age estimation, or national registry checks; self-declaration excluded.

        Enforcement to date: ANPD monitoring 18 major adult platforms since Jun 2026; public complaint channel live; direct enforcement from Jan 2027. Maximum exposure: BRL 50M per violation or 10% of Brazil revenue; service suspension. Source: ANPD, via trade and legal press.

        The layer underneath

        Two EU developments turn these national regimes into a single direction of travel. First, the Commission's preliminary DSA findings against four major adult platforms established that an "I am over 18" button protects nobody and defends nothing. Second, the age verification mini-wallet gives every member state a ready-made, privacy-preserving proof of age, and the Commission wants at least one compliant solution live in each country by 31 December 2026.

        For a platform, that means the question is no longer whether a market will demand verified age. It's which technical standard that market has chosen, and how fast you can meet it.

        04 / 06

        The challenge and impact

        One audience, five proofs

        Picture this: your compliance lead's Monday morning inbox holds an information notice from Ofcom, a formal notice from Arcom, and a certification query from an Italian assurance provider. Three regulators, three deadlines, three different definitions of a valid age check. One integration roadmap.

        That's the real difficulty of the European map: the duty itself is settled, and the plumbing is what diverges. A UK-compliant flow built on facial age estimation with a document fallback doesn't satisfy France unless one path is double-anonymous. The French flow doesn't satisfy Italy unless a certified third party re-authenticates the user every session. None of it satisfies Germany unless the gate sits in front of a closed user group using a system the KJM has assessed. Build each one separately and you're running four or five verification stacks, each with its own vendor, thresholds, logs, and failure modes.

        Configuration is the new exposure

        The UK's most instructive fine wasn't for missing checks. Ofcom fined Fenix International, the provider of OnlyFans, £1.05M because the facial age estimation "challenge age" it reported as 23 had actually been set at 20 for years, an error that sat unnoticed through two information requests. And in June 2026 Ofcom opened its first investigation into an adult service that has age checks, on the suspicion that one of its methods isn't actually highly effective.

        The regulator doesn't audit your intentions; it audits your settings. When the information notice arrives, who in your organization signs the answer, and how do they know it's true?

        The traffic trap

        Compliance costs conversion, at least at first. The most-visited adult site in the UK lost roughly 77% of its UK traffic within months of turning on checks (IBTimes, 2025), while VPN sign-ups spiked. But the traffic that leaks away lands somewhere, and Ofcom has said plainly that it prioritizes enforcement against sites growing their numbers because they didn't deploy checks. Winning displaced users puts you at the top of the queue.

        77%UK traffic lost by the most-visited adult site after checks went live (IBTimes, 2025)
        £1.05Mfine for a challenge age set at 20 while reported as 23 (Ofcom)

        What this means for you

        If you lead trust and safety: the method list is your specification. Every market on the map accepts facial age estimation with a document fallback somewhere in its stack; France and Italy add the double-anonymity constraint on how the result reaches you.

        If you own compliance: the evidence burden is now continuous, not annual. Ofcom expects vendor due diligence as a standing practice, Italy requires per-session proof, and every regime expects you to know your own configuration.

        If you run operations or the P&L: the exit options have been priced. One UK operator that geoblocked early was investigated and closed without a fine; one that geoblocked after enforcement began paid £630,000 anyway. Aylo has now foregone its second-largest market for over a year.

        The status quo has three price tags: leave a market and lose its entire revenue line, stay non-compliant and absorb fines up to £18M, 10% of revenue, or 6% of global turnover, or comply market by market with duplicated stacks and settings nobody fully owns. Every month of indecision is billed in one of those three currencies.

        05 / 06

        The modern approach

        What good looks like, and how to build it

        Compliant platforms are already showing the after-state: every European market served from a single verification integration, with each user routed automatically to their market's compliant flow. In that state, more than nine in ten users clear the check on their first attempt, a new market's requirements become a configuration change measured in weeks rather than an engineering quarter, and when a regulator's information notice arrives, the per-jurisdiction evidence exports in hours.

        The industry has a name for the design that gets you there: the waterfall. One integration, many methods, ordered by friction: age estimation first for most users, document-plus-biometric fallback for the rest, a wallet rail ready for the users and markets that prefer it. The regulators' method lists read like a waterfall specification already.

        The per-country readiness framework

        1. Map your markets to their instruments. For each country you serve, name the law, the regulator, the deadline, and the accepted methods. The map on page 4 is the starting grid; assign an owner per row.
        2. Cover each regulator's method list with layered options. No single method passes every market or every user. Estimation, document verification, and digital-ID rails each cover what the others miss.
        3. Treat double anonymity as architecture, not a feature toggle. France and Italy require that the verifier can't see the site and the site can't see the user. If your verification data model can't support that separation, retrofitting it later is a rebuild.
        4. Orchestrate per-country flows from one integration. Route by market at the top of the funnel: the UK user meets the HEAA flow, the French user the double-anonymous flow, the Italian user the per-session flow, all from the same stack.
        5. Govern configurations like regulated settings. Challenge ages, estimation thresholds, and fallback logic each need a named owner, a change log, and a periodic reconciliation against what you've told regulators. That's the £1.05M lesson.
        6. Build the evidence layer per jurisdiction. Pass rates, method mix, and configuration history, exportable per market, ready before any information notice arrives.
        7. Design for the edge users. Accessibility, alternative methods for users without documents or smartphones, and a working complaint and re-check path; Italy's principles require effective complaint handling, and the others reward it.

        Readiness checklist

        • Every market we serve is mapped to its instrument, regulator, and in-force date
        • Each market's accepted method list is covered by at least two live methods
        • At least one flow satisfies double anonymity end to end (France, Italy)
        • Per-session re-authentication is supported where required (Italy)
        • One integration routes users to the correct market flow automatically
        • Every verification configuration (challenge age, thresholds, fallbacks) has a named owner and a change log
        • Reported settings are reconciled against live settings on a fixed schedule
        • Vendor due diligence runs on a standing cadence, documented (Ofcom expects it)
        • Per-jurisdiction evidence (pass rates, method mix, config history) exports on demand
        • First-attempt completion rate is tracked per market and reviewed monthly
        • A wallet-based method is on the roadmap ahead of the 31 Dec 2026 EU milestone
        • Users who fail a check have an accessible complaint and re-verification path
        06 / 06

        How Incode helps

        One integration, every market's flow

        Incode builds identity verification and age assurance used across more than 40 jurisdictions, with the method coverage, privacy architecture, and evidence trail the European map demands. The compliance coverage on Incode's age assurance platform names the UK Online Safety Act, Ofcom's HEAA standard, and the EU DSA specifically.

        99.8%+accuracy separating minors from adults (Incode facial age estimation)
        92%+of users complete verification on their first attempt
        40+jurisdictions covered by one integration
        • Meet every method list from one stack. Incode's facial age estimation separates minors from adults with 99.8%+ accuracy and a 0.9-year mean absolute error for 13 to 17 year olds, with document and biometric verification (iBeta Level 3 tested liveness) as the fallback rung. That covers the mandated check in each mapped market, and cuts your time to comply when the next one switches on.
        • Privacy architecture built for double anonymity. On-device processing, double anonymization, and automated deletion align Incode flows with the French and Italian standards and the AEPD's criteria. Privacy is not a feature here. It is the architecture, which is what turns the strictest markets from blockers into open ones.
        • Wallet-ready before the deadline. Digital ID age verification lets you accept proofs from digital IDs and wallets as the EU mini-wallet and Spain's Cartera Digital roll out, so the December 2026 milestone lands as a feature release, not a findings letter.
        • Configuration you can defend. Challenge ages and thresholds are configurable and auditable, so the numbers you report to a regulator are the numbers running in production, and audit findings stop being a lottery.
        • Compliance that keeps your funnel. 92%+ of users complete verification on their first attempt, which is the difference between meeting the duty and meeting it while your competitors absorb your drop-off.