Ofcom Raises Doubts Over Pornhub's Age Assurance Approach
The UK's communications regulator, Ofcom, has opened a formal inquiry into whether Aylo, the parent company of Pornhub, is meeting its legal obligations under the Online Safety Act. At the center of the investigation is a specific question: does Aylo's device-level age assurance system actually qualify as "highly effective" under the law, or has the company rolled out a method that looks compliant on paper without the testing to back it up?
This is not the first time Ofcom has turned its attention to Pornhub. As covered in our earlier report on Ofcom's investigation into Pornhub age verification in the UK, the regulator has already been examining whether the platform is doing enough to keep minors away from adult content. This latest development sharpens that scrutiny by focusing specifically on the technical method Aylo chose to use: checking a user's device rather than verifying the individual person accessing it.
Why Device-Level Age Assurance Raises Privacy Questions
Device-level age checks work by flagging a device as belonging to an adult, often through settings, app store controls, or other signals tied to the hardware itself, rather than confirming the identity or age of the specific person using it at any given moment. On the surface, this approach can seem less invasive than facial scans, ID uploads, or credit card checks, since it does not necessarily require handing over sensitive personal documents every time someone visits a site.
But that same convenience is exactly what has drawn regulatory concern. The UK Online Safety Act sets a "highly effective" bar for age assurance, meaning platforms must demonstrate their methods reliably distinguish adults from minors, not just in theory but through rigorous testing and evidence. If a device can be shared, borrowed, or set up in a way that bypasses the intended safeguard, the entire system's reliability comes into question. Ofcom's concern, in short, is whether Aylo tested this method thoroughly enough before deploying it, or whether it prioritized a lighter-touch solution that might not hold up to scrutiny.
There is also a broader privacy tension baked into all age assurance debates, regardless of the specific method. Stronger verification methods, like ID checks or biometric scans, tend to collect more sensitive data, which creates its own risks if that data is mishandled or breached. Weaker methods, like device-level flags, may protect privacy better but fail to actually stop minors from accessing restricted content. Regulators and platforms are still working out where the acceptable middle ground sits, and this case is a clear example of that ongoing tension playing out in real time.
The Wider Pattern: Age Laws and User Behavior
Aylo's situation does not exist in isolation. Age verification requirements have been rolling out across multiple countries, and the compliance methods platforms choose have real consequences for how people use the internet. As we detailed in our coverage of how age verification laws are driving mass VPN adoption, when platforms tighten access controls, a meaningful share of users simply route around them using VPNs rather than complete the verification process. That shift creates its own set of downstream effects, from traffic patterns shifting to less-regulated corners of the internet to questions about whether the original safety goals are even being achieved.
This dynamic puts platforms like Aylo in a difficult position. Choose an age assurance method that is too permissive, and regulators come knocking, as is happening now. Choose one that is too aggressive or invasive, and users may abandon the platform altogether in favor of workarounds. Ofcom's investigation is, in many ways, a test case for how strictly "highly effective" will be defined and enforced going forward.
What This Means For You
If you use Pornhub or similar platforms in the UK, this investigation is a reminder that the age assurance systems you encounter online are still very much in flux. What counts as compliant today may be found insufficient tomorrow, and companies are actively adjusting their methods in response to regulatory pressure. It is also worth remembering that no age assurance method, whether device-based, ID-based, or biometric, is free of tradeoffs between effectiveness and privacy. Understanding what data a verification method collects, and how it is stored, is a reasonable question to ask before completing any age check online.
Key Takeaways
Ofcom's inquiry into Aylo's device-level age assurance underscores how unsettled the compliance landscape remains under the UK Online Safety Act. For everyday users, the practical steps are straightforward: stay informed about what age verification methods are actually being used on the platforms you visit, be cautious about what personal data any age check requests, and recognize that regulatory scrutiny like this is part of a longer process of figuring out how to balance child safety with reasonable privacy protections. This story is likely far from over, and how Ofcom rules on Aylo's methods could set a precedent for age assurance standards well beyond a single platform.




