The date is now fixed. From 25 July 2025, under the Online Safety Act, any service allowing pornographic or other primary-priority harmful content must prevent children from accessing it using highly effective age assurance, and Ofcom has signalled it will enforce from day one. A month out, this is the practical checklist.
The final-month checklist
First, classify honestly: if UK users can reach adult content on your service, you are in scope regardless of where you are established. Second, pick a compliant method: facial age estimation, photo-ID matching or equivalent, and measure its effectiveness; Ofcom expects evidence, not vendor brochures. Third, mind GDPR: collect the minimum, retain nothing you do not need, and document the DPIA. Fourth, test the journey: an age wall that breaks conversion entirely is a business decision, not a compliance one.
Effective and anonymous can coexist
WeVerify's Age Verification was built for exactly this bar: browser-based biometric age estimation with certified liveness, five seconds, no account, no document, no data retained, €0.20 per check; NFC passport-chip age for the cases that need certainty. The result is an over/under answer, not an identity file. Highly effective, provably minimal.
