Sponsored

Ofcom has opened an enforcement programme before its new control for non-consensual intimate images takes effect. The regulator wants high-risk services to use automated hash matching from 30 September, or show that another system curbs the spread of the same illegal content just as effectively.

That sounds like a deepfake detector. It is more precisely a recirculation control.

A hash is a digital fingerprint made from an image or video that has already been identified and added to a database. A platform compares content against that set and acts on a match. The method can stop the same abusive file, and perceptual hashing can catch some altered versions. A newly generated image with no corresponding fingerprint is outside that first line of detection until somebody finds it and adds its hash.

Ofcom’s test, therefore, is not whether platforms can claim to have bought a tool. It is whether the tool covers the risky services, scans the right content, adds newly discovered abuse quickly and produces decisions accurate enough to justify removal.

The enforcement programme opened on 9 September under sections 10(2) and 10(3) of the Online Safety Act 2023. Those provisions require regulated user-to-user services to prevent people encountering priority illegal content, manage the risk of their service being used for priority offences, and remove such content swiftly once aware of it.

Ofcom’s amended codes recommend hash matching as the compliance route. The user-to-user measure, ICU C14, applies to services that enable visual user content and meet specified risk and scale tests. These include high-risk pornography, file-storage and file-sharing services, high-risk services with more than 700,000 monthly UK users, and large services assessed at medium or high risk. A parallel measure covers large general search services.

The code is a recommended route, not the only possible technical design. Ofcom says a firm without hash matching must prove that its systems and processes are equally effective. Where it finds a breach of the statutory safety duties, Ofcom can impose a penalty of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater.

The initial enforcement focus is narrower than the full code. Ofcom names adult and instant-messaging services as particularly high risk and says it has written to some relevant providers. It has not disclosed their names, how many received letters, or what share of UK users their services cover.

What the evidence shows

There is real deployment evidence behind the policy. Ofcom’s May decision statement identifies StopNCII.org as the leading public third-party database. It lists Facebook, Instagram, TikTok, Reddit, OnlyFans, Pornhub, X and Snap among its partners. The database had received more than one million image hashes over three years.

Ofcom also cites Microsoft’s report that a Bing pilot identified and acted on 268,899 images returned in image-search results. Google had announced its own partnership with the operator of StopNCII. For implementation effort, Ofcom records evidence that OnlyFans integrated the database in under 80 hours, with four to five hours of maintenance a month.

These numbers establish that the mechanism can operate at scale. They do not establish compliance across the services now in scope. A partner list does not show what proportion of uploads is scanned, whether old content has been covered, how quickly matches are handled, or whether every partner uses the same database across all relevant products.

Ofcom’s programme promises to identify risky services, assess their measures and open formal investigations where potential non-compliance appears. It does not yet name an investigation or publish a coverage denominator. The enforcement programme began on 9 September. The 30 September date is when the amended code measures take effect and the compliance milestone arrives, not evidence that the market has completed implementation.

The known-image boundary

The limits are explicit in Ofcom’s technical account. Cryptographic hashing detects exact matches, so small changes can defeat it. Perceptual hashing compares similarity and can recognise modified versions, but its threshold creates a trade-off: prioritising recall catches more possible matches and raises the risk of false positives, while prioritising precision can miss more abuse.

Most importantly, both approaches depend on a reference set. Ofcom describes hash matching as a way to detect content previously identified as illegal or otherwise prohibited. It says known AI-generated deepfakes can be detected. That does not mean the system recognises every synthetic intimate image as synthetic or non-consensual. The first unseen output still needs another route into the moderation system, such as a report, sampling, or a separate detection tool. Once confirmed and hashed, matching can stop repeated circulation.

The database itself also presents an accuracy problem. StopNCII lets a person create hashes on their own device, so the image does not leave their possession, but the submitted image is not viewed or independently verified by the database. Ofcom acknowledges that consensual or non-intimate images could be submitted, including maliciously.

That is why the code couples automation with review. A first match against an unverified hash should be reviewed, and providers should run continuing quality assurance. Ofcom’s final human-review guidance sets no universal percentage. It tells firms to base review resources on documented performance, observed errors and the harm caused by both missed abuse and incorrect removal.

The useful disclosure after 30 September will be operational: which services were assessed, what share of relevant content was scanned, how many matches were confirmed, how many were overturned, and how quickly new hashes entered the system. Without those measures, compliance risks becoming a list of tools rather than evidence of outcomes.

Hash matching can make an important promise to victims: an image already known to the system should be harder to spread again. It cannot promise that a fresh deepfake will be recognised before anybody reports or otherwise detects it. Ofcom’s enforcement programme will matter if it measures both halves of that sentence.

Sources

Imogen Fairchild

Contributing writer at Clarqo.