Quick tips
Turn pages with the arrows, your keyboard, or by dragging the page corner
Click the page number on the left to jump anywhere in the book
Select any text to highlight it
Would you like to include your highlights?
eBook
Enter your work email to read the full eBook. Free, with the audio narration included.
Please enter a valid email address.
We’ll only use your email to share related Incode resources.
Twelve months ago this week, the UK's duty to keep children off pornographic services with highly effective age assurance took force. In the year since, Ofcom has fined nine providers a combined £6,235,000, opened 23 investigations covering 88 adult services, and published statutory evidence that the checks are working. Its July 2026 report found that when children were asked to prove their age, the share who met a highly effective check nearly doubled in six months.
69 million age checks ran across just 32 services in the UK between July and December 2025, a 23-fold increase on the previous six months (Ofcom, July 2026).
The UK is the loudest regime, not the only one. France's SREN law and Arcom's technical standard made double-anonymous verification mandatory in April 2025. Italy's AGCOM rules went live for 48 named platforms in November 2025. Germany has been running the same basic duty since 2003 and tightened it in December 2025. Spain's parliament is processing a minors-protection law while the government ships a wallet that proves age without revealing identity.
Every major European market now ties adult-content access to a proof of age, and no two markets accept the same proof in the same way.
Here is where each regime stands as of 21 July 2026.
Online Safety Act (Part 5 and children's duties); Ofcom. Highly effective age assurance (HEAA) in force since 25 Jul 2025.
What it requires: Methods from Ofcom's published list (facial age estimation, photo-ID matching, open banking, mobile-operator and credit card checks, digital identity services); checks must be "technically accurate, robust, reliable and fair"; regular due diligence on vendors; configuration accuracy is audited.
Enforcement to date: £6,235,000 in fines across 9 providers; 23 investigations covering 88 services; 73% of investigated services now comply or geoblock. Maximum exposure: £18M or 10% of global revenue; business disruption orders. Source: Ofcom, Jul 2026.
SREN law (May 2024) + Arcom référentiel (Oct 2024); Arcom, privacy design with CNIL. Binding since Jan 2025; double-anonymity option mandatory since 11 Apr 2025.
What it requires: At least two verification methods, at least one double-anonymous: the site never learns the user's identity, the verifier never learns which site the proof is for.
Enforcement to date: Formal notices in Aug and Dec 2025; all 17 sites designated by ministerial order now verify or have exited France; minors' time on adult sites down 35% in a year (Arcom). Maximum exposure: €250,000 or 4% of worldwide turnover (doubled to €500,000 or 6% on repeat); blocking and de-indexing orders within 48 hours. Source: Arcom; Sénat.
Caivano decree (2023) + AGCOM delibera 96/25/CONS; AGCOM. Live since 12 Nov 2025 for 48 listed platforms.
What it requires: Certified independent third-party verification in two separated steps (identification, then per-session authentication); double anonymity; system principles include accessibility, non-discrimination, and effective handling of user complaints.
Enforcement to date: Obligation list published 31 Oct 2025; supervision and blocking powers active. Maximum exposure: Fines from €10,329 to €258,228, then site blocking until compliant. Source: AGCOM delibera 96/25/CONS.
JMStV (2003, revised 1 Dec 2025); KJM and state media authorities. Longest-running regime in Europe.
What it requires: Pornography available only inside closed user groups gated by age verification the KJM has positively assessed (80+ systems to date); OS-level child-protection duties phase in to Dec 2027.
Enforcement to date: Two decades of proceedings and blocking orders; payment-flow blocking power in force since 1 Dec 2025. Maximum exposure: Fines up to €500,000; payment blocking against persistent violators. Source: KJM; die Medienanstalten.
Organic law for the protection of minors in digital environments (bill) + Cartera Digital Beta wallet; CNMC, AEPD. Bill in Congress committee, amendments incorporated June 2026; not yet law. Wallet in beta; Spain among the first five EU mini-wallet adopters.
What it requires: As drafted: mandatory age verification for adult content, social media minimum age raised from 14 to 16, parental controls by default; the wallet issues an anonymous proof of majority.
Enforcement to date: Five CNMC fines of €44,829 each for ineffective age checks (Dec 2024); AEPD privacy criteria already shape EU practice. Maximum exposure: Bill's penalty regime pending final text; existing audiovisual-law sanctions apply meanwhile. Source: Congreso de los Diputados; CNMC; AEPD.
Digital Services Act, Art. 28; European Commission. Preliminary breach findings against four major adult platforms issued 27 Mar 2026.
What it requires: Effective protection of minors; click-through self-declaration ruled not effective; Commission guidelines (Jul 2025) recommend age verification for adult content.
Enforcement to date: Formal proceedings open since May 2025; preliminary findings issued. Maximum exposure: Up to 6% of global annual turnover. Source: European Commission.
Commission recommendation on age verification, 29 Apr 2026. Mini-wallet app feature-ready since 15 Apr 2026; member states urged to have a solution live by 31 Dec 2026.
What it requires: A white-label, privacy-preserving proof of age, deployable as a standalone app or inside national EUDI wallets; Denmark, France, Greece, Italy, and Spain moving first.
Enforcement to date: Non-binding; national rollouts in progress. Maximum exposure: Not a sanctions instrument (an enabling layer). Source: European Commission.
Digital ECA, Law 15.211/2025; ANPD. Enforceable since 18 Mar 2026; monitoring phase under way.
What it requires: Verified age via identity document, biometric age estimation, or national registry checks; self-declaration excluded.
Enforcement to date: ANPD monitoring 18 major adult platforms since Jun 2026; public complaint channel live; direct enforcement from Jan 2027. Maximum exposure: BRL 50M per violation or 10% of Brazil revenue; service suspension. Source: ANPD, via trade and legal press.
Two EU developments turn these national regimes into a single direction of travel. First, the Commission's preliminary DSA findings against four major adult platforms established that an "I am over 18" button protects nobody and defends nothing. Second, the age verification mini-wallet gives every member state a ready-made, privacy-preserving proof of age, and the Commission wants at least one compliant solution live in each country by 31 December 2026.
For a platform, that means the question is no longer whether a market will demand verified age. It's which technical standard that market has chosen, and how fast you can meet it.
Picture this: your compliance lead's Monday morning inbox holds an information notice from Ofcom, a formal notice from Arcom, and a certification query from an Italian assurance provider. Three regulators, three deadlines, three different definitions of a valid age check. One integration roadmap.
That's the real difficulty of the European map: the duty itself is settled, and the plumbing is what diverges. A UK-compliant flow built on facial age estimation with a document fallback doesn't satisfy France unless one path is double-anonymous. The French flow doesn't satisfy Italy unless a certified third party re-authenticates the user every session. None of it satisfies Germany unless the gate sits in front of a closed user group using a system the KJM has assessed. Build each one separately and you're running four or five verification stacks, each with its own vendor, thresholds, logs, and failure modes.
The UK's most instructive fine wasn't for missing checks. Ofcom fined Fenix International, the provider of OnlyFans, £1.05M because the facial age estimation "challenge age" it reported as 23 had actually been set at 20 for years, an error that sat unnoticed through two information requests. And in June 2026 Ofcom opened its first investigation into an adult service that has age checks, on the suspicion that one of its methods isn't actually highly effective.
The regulator doesn't audit your intentions; it audits your settings. When the information notice arrives, who in your organization signs the answer, and how do they know it's true?
Compliance costs conversion, at least at first. The most-visited adult site in the UK lost roughly 77% of its UK traffic within months of turning on checks (IBTimes, 2025), while VPN sign-ups spiked. But the traffic that leaks away lands somewhere, and Ofcom has said plainly that it prioritizes enforcement against sites growing their numbers because they didn't deploy checks. Winning displaced users puts you at the top of the queue.
If you lead trust and safety: the method list is your specification. Every market on the map accepts facial age estimation with a document fallback somewhere in its stack; France and Italy add the double-anonymity constraint on how the result reaches you.
If you own compliance: the evidence burden is now continuous, not annual. Ofcom expects vendor due diligence as a standing practice, Italy requires per-session proof, and every regime expects you to know your own configuration.
If you run operations or the P&L: the exit options have been priced. One UK operator that geoblocked early was investigated and closed without a fine; one that geoblocked after enforcement began paid £630,000 anyway. Aylo has now foregone its second-largest market for over a year.
The status quo has three price tags: leave a market and lose its entire revenue line, stay non-compliant and absorb fines up to £18M, 10% of revenue, or 6% of global turnover, or comply market by market with duplicated stacks and settings nobody fully owns. Every month of indecision is billed in one of those three currencies.
Compliant platforms are already showing the after-state: every European market served from a single verification integration, with each user routed automatically to their market's compliant flow. In that state, more than nine in ten users clear the check on their first attempt, a new market's requirements become a configuration change measured in weeks rather than an engineering quarter, and when a regulator's information notice arrives, the per-jurisdiction evidence exports in hours.
The industry has a name for the design that gets you there: the waterfall. One integration, many methods, ordered by friction: age estimation first for most users, document-plus-biometric fallback for the rest, a wallet rail ready for the users and markets that prefer it. The regulators' method lists read like a waterfall specification already.
Incode builds identity verification and age assurance used across more than 40 jurisdictions, with the method coverage, privacy architecture, and evidence trail the European map demands. The compliance coverage on Incode's age assurance platform names the UK Online Safety Act, Ofcom's HEAA standard, and the EU DSA specifically.