On 25 July 2025 the UK became the first major market to enforce age verification for adult content at national scale. Launch week delivered exactly the spectacle observers predicted: major platforms deploying facial age estimation and ID checks, VPN downloads surging up the app-store charts, and a noisy public debate about privacy, effectiveness and the future of the open web.
What actually worked
Early experience separates the deployment patterns. Services that chose low-friction estimation first, with document verification as fallback, kept conversion losses to single digits. Services that led with document upload saw abandonment spike. And services that built data retention into the flow found themselves answering privacy regulators as well as Ofcom, a reminder that the OSA and GDPR must be satisfied simultaneously.
The template for every market that follows
The EU is finalising its own age-verification approach, and member states are watching London's experiment closely. The compliance architecture that survives both regimes is the one WeVerify ships: five-second browser-based age estimation with certified liveness and zero data retention for the mass case, NFC chip verification for the certainty case, and an over/under answer instead of an identity file. Age assurance is becoming global infrastructure; the privacy-preserving version of it is a choice.
