UK online safety act review - not working

UK Parliament Asks the Question You’ve Been Screaming for a Year: Is Age Verification Actually Working?

The House of Lords has launched a formal inquiry into the Online Safety Act — and for the first time, lawmakers are asking whether the law itself is broken, not just the enforcement.

If you’ve spent the past year scrambling to implement age verification on your sites, burning budget on third-party ID-check vendors, and watching competitors ignore the rules without consequence, you’ll want to pay close attention to what’s happening in Westminster right now. Because Parliament is finally admitting what many of you have suspected all along: the UK’s Online Safety Act (OSA) may have a fundamental design problem.

On Monday, July 27, the House of Lords Communications and Digital Committee — the UK’s upper parliamentary chamber — launched a formal inquiry into the OSA’s implementation, issuing a public call for written evidence from industry stakeholders. The committee’s chair, Baroness Barbara Keeley, didn’t mince words: “It is now clear that the Act is not working as well as it should. We want to understand why.”

That’s a remarkable statement, given the Act was sold as a watershed moment for internet regulation when it passed in 2023.


What Triggered the Inquiry

The immediate catalyst is a string of data breaches at age-verification vendors — the very companies that adult platforms have been mandated to route their users through. AU10TIX, used by X (Twitter), TikTok and Uber, exposed driver’s licence data in 2024. A Discord age-verification vendor was hacked in 2025, leaking approximately 70,000 users’ ID photographs. Verification firm Persona became embroiled in controversy following a problematic UK age-check trial, also tied to Discord.

Let that sink in: webmasters who implemented age verification in good faith — doing exactly what Ofcom required of them — were routing their users’ passport photos and driving licences through systems that were being actively compromised.

But the inquiry goes well beyond the breach issue. The Lords committee has identified two distinct failure modes it wants to examine: whether Ofcom has enforced the law vigorously enough, and whether the legislation itself contains structural flaws requiring amendment. That second strand is new territory. Previous criticism has been aimed at the regulator’s pace. This inquiry is asking whether Parliament got the law wrong in the first place.


Ofcom Has Been Busy — But Is It Working?

To be fair to Ofcom, the regulator hasn’t been sitting on its hands. In the Act’s first year, it launched five enforcement programmes, opened 21 investigations, and issued a series of escalating fines against adult platforms:

  • £20,000 against 4chan for refusing to provide an illegal-content risk assessment
  • £1 million against AVS Group, a Belize-registered operator of 18 adult sites, for failing to deploy age assurance
  • £1.35 million against 8579 LLC — its largest single penalty to date — with a £1,000-per-day running sanction for continued non-compliance
  • A formal investigation into X, after analysis of 50,000 Grok-related posts found roughly 2% appeared to feature minors in explicit contexts

The maximum penalty the regulator can impose is £18 million or 10% of global revenue, whichever is higher. Nobody has come close to that ceiling yet — but the trajectory is clearly upward.

The problem is that enforcement has been selective and slow, and some of the worst actors have been barely touched. As Alison Boden, executive director of the Free Speech Coalition (FSC), put it: “Some adult platforms have experienced overly aggressive enforcement despite making good faith efforts to comply, while some of the worst actors have exposed the limitations of one country’s ability to police the entire internet.” The FSC intends to submit evidence to the inquiry — and plans to tell Parliament, in effect, “we told you so.”


The Real Problem: You’re Collecting Passport Photos for Vendors Who Get Hacked

Here’s the compliance architecture the OSA created, as it plays out in practice: a user visits your site, gets redirected to a third-party verification vendor, uploads their passport or driving licence, and the vendor sends back a green light. You get the user. The vendor gets the data — potentially forever, since the Act sets no data retention limits.

That data then sits in the vendor’s systems. And as the breach record shows, those systems are not secure.

The Act does mandate “highly effective” age verification for content harmful to children — but it says nothing about what data the verification process can collect, how long it can be retained, or whether privacy-preserving alternatives must be offered. A cryptographic method called zero-knowledge proof (ZKP) already exists and is Ofcom-endorsed: it can confirm a user is 18+ without revealing their identity to anyone — not the platform, not the vendor. But the OSA doesn’t require platforms to use ZKP. The market has defaulted to identity-document collection because vendors have a commercial interest in retaining that data.

The Lords inquiry is now formally asking whether Parliament needs to close that gap by legislation.


The Collateral Damage Has Been Extraordinary

For those outside the adult industry, the scale of scope creep will be eye-opening. Because age verification requirements haven’t only landed on porn sites:

  • Reddit required UK users to verify their age to access discussion boards for topics including hard cider and cigars
  • Spotify gated music videos and song lyrics behind age verification for UK users
  • Online forums covering cycling and sustainable living shut down entirely rather than face compliance costs
  • Support communities for sexual assault survivors and people struggling with substance addiction have in some cases required government ID — stripping vulnerable users of anonymity at the moment they needed it most

Baroness Keeley’s inquiry will examine all of this. The committee is asking for submissions by 5pm on 7 September 2026, and questions include the pointed: “What evidence, if any, is there that UK users are less exposed to illegal content since the OSA illegal content duties came into force?”


What This Means for Your Business

For adult webmasters with UK traffic, here’s the practical read-out from this inquiry:

Don’t expect a rollback anytime soon. The inquiry is not looking to scrap the OSA — it’s looking to fix it. If anything, the direction of travel is toward tighter enforcement and potentially mandated use of more privacy-preserving (but still obligatory) verification methods. The AVPA’s Iain Corby, an OSA supporter, called for Ofcom to “create a level playing field by enforcing at scale” — meaning the committee may actually push for more aggressive action against non-compliant platforms, not less.

ZKP could become mandatory. If Parliament follows through on the most logical legislative correction, platforms may be required to offer zero-knowledge-proof verification as a default or exclusive method. That would remove the current model where vendors harvest and hold your users’ ID documents — which could actually be a better outcome for you from a liability standpoint.

The jurisdictional question remains unresolved. 4chan and Kiwi Farms have challenged Ofcom’s authority over US-incorporated companies in a US federal court, arguing the enforcement violates the First, Fourth, and Fifth Amendments. If they succeed, it could significantly undercut the Act’s reach over non-UK platforms. That case is still live.

Submit evidence if you have a stake. The committee has invited submissions from domestic and international industry participants. If you’ve been directly affected — by compliance costs, by Ofcom investigations, or by the commercial impact of verification requirements on your user base — this is a rare opportunity to put your experience on the parliamentary record. The call for evidence is open until September 7.

Adult entertainment attorney Corey Silverstein, who has been critical of age verification legislation across multiple jurisdictions, summarised the stakes well: “Child safety and adult privacy are not mutually exclusive. Effective policy must protect both. I hope this inquiry produces an evidence-based reassessment of age-verification mandates.”

Parliament is finally listening. Whether it draws the right conclusions is another question entirely — but for the first time since the OSA passed, the people who built this system are being asked to explain why it isn’t working.


Written submissions to the Lords Communications and Digital Committee inquiry are due by 5pm GMT+1 on Monday, 7 September 2026. Full details at the UK Parliament website.