In April 2025 Ofcom finalised its Protection of Children codes under the UK Online Safety Act, starting the clock on one of the most consequential compliance deadlines of the year: by late July 2025, services likely to be accessed by children must deploy "highly effective" age assurance or engineer their content accordingly. Self-declared birth dates, the internet's forty-year-old fig leaf, are explicitly finished.
What "highly effective" excludes
Ofcom's guidance names the acceptable techniques: facial age estimation, photo-ID matching, credit-card checks, digital identity services. It equally names the failures: tick-boxes, general disclaimers, payment methods that do not prove age. The bar is technical, measurable, and enforceable with fines of up to 10% of global turnover.
Age assurance without surveillance
The privacy objection is answerable. WeVerify's Age Verification runs two modes: browser-based biometric age estimation with a liveness check, no account, no document, no data retained, at €0.20 per check; and NFC-verified age from the passport chip when certainty must be absolute. Both return an over/under answer rather than an identity, which is exactly the data-minimising architecture regulators keep asking for.
July will arrive faster than most roadmaps assume.
