Insights
|
Share
The Online Safety Act Is One. It Solved the Access Problem. The Presence Problem Is Still Waiting.

One year ago, the Online Safety Act's children's safety provisions came into force in the UK. For the first time, platforms faced a legal obligation, not a voluntary commitment, to take age assurance seriously. Ofcom gained real enforcement powers. The era of self-regulation in children's digital safety effectively ended.
It was a genuine milestone. And it left the harder problem untouched.
What the Act Got Right
The Online Safety Act changed the incentive structure for online platforms. Before it, child safety obligations were diffuse, voluntary, and unenforced. The Act created a clear legal standard: platforms must take proportionate, risk-based steps to prevent children from accessing age-inappropriate content. They must have age assurance mechanisms that work. They are subject to Ofcom oversight, and Ofcom has the power to act.
Age verification at the point of account registration is now a meaningful requirement. Platforms that once treated age gates as a box-ticking exercise, a self-declared date of birth with no verification, now face scrutiny over whether those mechanisms actually work.
The impact has been visible. Platforms have invested in age assurance technology. The market for age verification services has grown sharply. Ofcom has published detailed codes and guidance, and the direction of travel is clearly towards more rigorous enforcement, not less.
None of this should be dismissed. Moving from voluntary commitments to legal obligations in a sector as resistant to regulation as social media took significant political and legislative effort. The Act achieved it.
The Problem It Didn't Solve
But age verification at registration answers only one question: who is opening this account?
It does not answer the question that matters just as much: who is operating this account right now?
A child who provides a parent's ID document at registration is verified as an adult. A minor who borrows an older sibling's phone is operating inside an authenticated session that was opened by someone else entirely. A verified 18-year-old who creates an account and shares their login with a 14-year-old friend has, from the platform's perspective, never done anything wrong.
The platform verified an identity at the door. It has no mechanism to verify that the same person, the verified account holder, is the person in the room.
This is the presence problem. And the Online Safety Act's first year did not address it.
The evidence bears this out. In Australia, where a social media ban for under-16s came into force in November 2025, research found that 70% of children subject to the ban were still accessing banned platforms six months later. Age verification requirements that operate only at account creation are permeable at scale, not because the technology fails, but because verified accounts are shared, borrowed, and operated by people who were never part of the original verification event.
Why This Matters More as AI Develops
The presence problem was already significant before generative AI became widely accessible. It is now acute.
AI enables children to bypass age verification tools designed to detect false documentation. It enables the creation of synthetic identities that pass automated checks. And it enables the operation of accounts with a degree of behavioural consistency, responding to content, engaging with other users, that makes detection of non-account-holder presence increasingly difficult using traditional signals.
The threat is not hypothetical. Researchers have demonstrated the ability to generate convincing ID document images, produce realistic facial images for liveness checks, and synthesise behavioural patterns that evade anomaly detection. The tools required are accessible, inexpensive, and improving rapidly.
A regulatory framework built around point-in-time age verification is being tested by a technology environment that makes point-in-time verification increasingly easy to defeat.
What the Second Year Needs to Ask
The question the Online Safety Act's second year needs to grapple with is not whether platforms are checking age at registration. It is whether the person operating the session, at any given moment, is the person who was verified.
That is a different technical problem. It requires continuous identity assurance, verification that runs throughout a session, not only at the point of account creation. It requires mechanisms that can confirm, passively and without friction for legitimate users, that the verified account holder is the person present.
This is not a regulatory gap that can be addressed by tightening the rules around what documents platforms must accept at onboarding. It requires a different layer of technology: one that operates at the session level, not the registration level.
The regulatory direction supports this. Ofcom's children's safety codes create a risk-based framework; platforms are required to implement measures proportionate to the harm their services present. For platforms where children are at significant risk, proportionate harm reduction now means asking harder questions about presence, not just access.
The Infrastructure the Second Year Requires
Continuous session verification is not a new concept in identity technology. It exists, and it works. The challenge for online platforms is that most current implementations are designed for high-friction environments, financial services, high-value transactions, regulated communications, where the user expects and accepts a biometric prompt.
Consumer-facing platforms serving children require a different approach: passive, on-device verification that confirms presence continuously without interrupting the experience, transmitting biometric data, or creating new data privacy risks in a sector that is already under intense scrutiny from the ICO alongside Ofcom.
The architecture that resolves this tension is on-device biometric verification, a technology stack that processes identity signals entirely on the user's device, confirms presence to the platform without transmitting biometric data externally, and operates passively enough that legitimate users experience no friction.
This is the infrastructure the Online Safety Act's second year needs to start requiring.
A Milestone Worth Marking, and Building On
One year of the Online Safety Act is a genuine achievement. The UK has moved from a self-regulatory model to a legally enforceable one, faster than most comparable jurisdictions. Ofcom has set a credible enforcement tone. The platforms that once treated child safety as a reputational matter rather than a legal one have been given clear notice that the rules have changed.
But age verification at the door is the beginning of child safety online, not the end of it. The session gap, the window between a verified login and what actually happens inside it, remains open. The presence problem is the next frontier.
The Act's second year will be defined by how seriously platforms, regulators, and technologists take that question.
About YEO Messaging
YEO Messaging's patented Continuous Facial Recognition (CFR) technology verifies that the right person remains present throughout a digital session, passively, continuously, and entirely on-device. No biometric data is transmitted or stored externally.
The YEO CFR SDK integrates directly into existing platforms. For enquiries about session-layer identity verification, book a demo.

Share
Newsletter
Get weekly updates on the latest compliance changes, product releases, and much more.



