Hoje, 06:23 AM
We are building a platform with user generated content and wanted to actually understand the Online Safety Act age requirements before assuming this only applies to large social media companies. Here is what I have pieced together so far, would appreciate anyone correcting me or adding context.
The Online Safety Act places duties on a wide range of online services, not just the obvious large platforms, requiring companies to assess the risk their service poses to children and to put in place proportionate measures to protect them, which can include age verification or age estimation for services that carry higher risk content. The specific requirements seem to scale with risk rather than applying identically to every service.
Ofcom, as the regulator, has published codes of practice outlining what counts as highly effective age assurance, and simple self declaration of age, where a user just types in a birth date, is generally no longer considered sufficient for higher risk services, pushing companies toward more robust methods like document verification or facial age estimation instead. This creates a real cost and technical burden for smaller startups.
What I am still trying to understand is how a very early stage startup is actually expected to carry out this risk assessment properly without a dedicated legal or compliance team, and whether there are simplified expectations for smaller platforms.
Has anyone here actually had to implement age verification or assessment under the Online Safety Act? Curious what approach you took, how much it cost to implement, and whether Ofcom's guidance was actually clear enough to act on confidently. Found a fairly clear explanation of this on Entrepreneur Plus while I was reading around the topic, helped me understand the founder side of it a bit better.
The Online Safety Act places duties on a wide range of online services, not just the obvious large platforms, requiring companies to assess the risk their service poses to children and to put in place proportionate measures to protect them, which can include age verification or age estimation for services that carry higher risk content. The specific requirements seem to scale with risk rather than applying identically to every service.
Ofcom, as the regulator, has published codes of practice outlining what counts as highly effective age assurance, and simple self declaration of age, where a user just types in a birth date, is generally no longer considered sufficient for higher risk services, pushing companies toward more robust methods like document verification or facial age estimation instead. This creates a real cost and technical burden for smaller startups.
What I am still trying to understand is how a very early stage startup is actually expected to carry out this risk assessment properly without a dedicated legal or compliance team, and whether there are simplified expectations for smaller platforms.
Has anyone here actually had to implement age verification or assessment under the Online Safety Act? Curious what approach you took, how much it cost to implement, and whether Ofcom's guidance was actually clear enough to act on confidently. Found a fairly clear explanation of this on Entrepreneur Plus while I was reading around the topic, helped me understand the founder side of it a bit better.







