Age checks on social media: what the rules ask of you, and what your users will experience
The social media age limit sits at the centre of how platforms handle new users, and the rules around it have shifted from a line in the terms of service to a legal duty. For anyone running a product that children might reach, the practical question is what a compliant age check looks like and what it asks of the person on the other side of the screen. This guide sets out the rules that apply now and the methods regulators treat as effective, then looks at the change the government has signalled.
There is no single statutory social media age limit in the UK today. Platforms have long set 13 in their own terms of use. The Online Safety Act now requires many services likely to be accessed by children to run highly effective age checks, and the government has announced it will legislate for a minimum age of 16 for some platforms.
The live regime is the Online Safety Act, and its age-assurance duties are already being enforced. Two parts of the Act matter most.
Part 5 covers services that publish their own pornographic content. Since 17 January 2025, those services have had to use highly effective age assurance so that children cannot normally encounter that content. Part 3 covers user-to-user and search services likely to be accessed by children. Its Protection of Children duties came into force on 25 July 2025, with a section 12 duty to use highly effective age assurance, and Ofcom opened an enforcement programme the day before, on 24 July 2025.
The penalties are set at the level regulators reserve for duties they intend to be taken seriously. Ofcom can fine a company up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.
Ofcom has also made clear that it sees enforcement as ongoing. In its Use of Age Assurance Report, published on 15 July 2026, the regulator said age checks are now running at “unprecedented scale” and that “highly effective age checks work”, while adding that the job is “not done”. The same report stated that social media companies “have failed to enforce their minimum age requirements properly” and that Ofcom would “not hesitate to take enforcement action”.
Alongside the duties already in force, the government has announced it will legislate for a minimum age of 16 for some social media platforms. This is a proposal on a published timetable, not current law, and the responsibility would sit with companies rather than with children or parents.
Australia brought in an under-16 restriction in December 2025, and the UK has said its own plans would go further. For a business, the signal is that age assurance is becoming a permanent feature of how online services operate, and that building for it now is more sensible than waiting for each threshold to become mandatory. Where the different thresholds create genuinely different design problems, we cover that in why 18, 16 and 13 each call for a different kind of age check.
The number most people associate with social media is 13. That figure comes from platform terms of service. No UK law grants permission to use social media at 13. Platforms have historically set 13 as their minimum age in their own rules, and Ofcom’s criticism about companies failing to “enforce their minimum age requirements properly” refers to that existing floor.
A statutory minimum age of 16 would change the nature of the obligation. The duty would require a company to establish age using methods a regulator accepts as effective. A self-declared age box that a child can click through would no longer satisfy it. That shifts the work from asking someone’s age to establishing it, which is where age assurance technology comes in. The accuracy of that estimate matters most around the boundaries, and we look at what happens near the 16-to-18 line in how accurate age verification is and what happens at the 16-to-18 boundary.
Ofcom does not mandate a single technology. It sets out methods it considers capable of being highly effective, and it judges any method against four criteria: it must be, in Ofcom’s words, “technically accurate, robust, reliable and fair”. Self-declaration, where a user simply types a date of birth, does not meet that bar.
The regulator names seven methods capable of being highly effective. The table below summarises them and what the person being checked would do in each case.
|
Method |
What the user does |
|---|---|
|
Open banking |
Confirms their age through their bank without sharing account details with the service |
|
Photo ID matching |
Uploads an identity document and a selfie that are matched to each other |
|
Facial age estimation |
Takes a quick selfie, which is analysed to estimate an age range |
|
Mobile network operator checks |
Confirms an age signal already held by their mobile provider |
|
Credit card checks |
Verifies possession of a card that requires the holder to be 18 |
|
Digital identity services |
Reuses a verified identity or wallet credential they already hold |
|
Email-based age estimation |
Has the age associated with their email address estimated from where it is used |
The terms in this area are easy to mix up, and the difference between them affects what a service is actually promising. We separate them in age assurance, age verification and age estimation, and what each term means.
For the user, a good age check is close to invisible. A returning user might confirm an age signal with a single tap and be back in the product in a few seconds. A first-time user taking a selfie for facial age estimation spends a few seconds in front of the camera and is done. The experience decides whether people finish signing up or abandon halfway, which is why the choice of method is a commercial decision as much as a compliance one.
Privacy is part of that experience. Several of the accepted methods are designed to share an age result rather than a full identity, so a user can prove they are old enough without handing over a document to every service they visit. We explore that in how you can prove your age without handing over your ID.
Meeting a duty like this without hurting sign-up rates comes down to two things: covering enough of Ofcom’s accepted methods to suit different users, and routing each user to the one that fits. A gambling operator and a retailer selling age-restricted goods will not want the same check, and neither will a first-time visitor and a returning customer.
This is where OneID works. As a UK digital verification services provider certified under the UK Digital Verification Services Trust Framework, OneID covers five of Ofcom’s seven highly effective methods: bank-verified identity through open banking, document authentication with matching, on-device facial age estimation, mobile network operator age checks, and digital identity services through a reusable wallet credential. One API handles the lot, with fallback routing so that a user who cannot complete one method is offered another rather than being turned away.
The result for a business is a single integration that can meet the age-assurance duty across different audiences, with an evidence trail from every check. For the person being verified, it means a check that takes seconds and, most of the time, one they barely notice.
Is there a legal age limit for social media in the UK? There is no single statutory age at which UK law grants permission to use social media. Platforms have historically set 13 as their minimum age in their own terms of service. The government has announced it will legislate for a minimum age of 16 for some platforms, but that measure is a proposal on a timetable and is not yet in force.
What is the Online Safety Act age requirement? The Online Safety Act requires services likely to be accessed by children, and services publishing their own pornographic content, to use highly effective age assurance. The Part 5 duty has applied since 17 January 2025 and the Part 3 Protection of Children duty since 25 July 2025. Ofcom enforces both.
Are social media companies being fined for weak age checks? Ofcom opened an enforcement programme on age assurance on 24 July 2025 and has said it will “not hesitate to take enforcement action”. Under the Online Safety Act it can impose penalties of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.
How is someone’s age checked online? Ofcom sets out seven methods it considers capable of being highly effective, including open banking, photo ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation. Simply typing a date of birth, known as self-declaration, is not accepted as a highly effective method.
What is the difference between the 13 minimum and the proposed 16 minimum? The age of 13 comes from platform terms of service rather than a UK law granting permission. The proposed minimum age of 16 would be a statutory duty on companies to check age using accepted methods, rather than relying on a self-declared date of birth. The proposed measure is not yet in force.
Does age assurance mean handing over identity documents? Not necessarily. Several accepted methods, including open banking and facial age estimation, are designed to confirm an age result without sharing a full identity with the service. A user can often prove they are old enough while sharing very little other data.