Part of the AI Regulation News hub.
Ofcom has opened an enforcement programme under sections 10(2) and 10(3) of the Online Safety Act to assess the measures high-risk services take against non-consensual intimate imagery, which Ofcom's news release of the same day describes as including explicit AI-generated deepfakes
The version that travels is that platforms must hash match by 30 September. The bulletin says the codes recommend hash matching, and that a provider may comply by other measures.
Bottom line: The enforcement programme is open as of 9 September 2026. The duties it enforces, at sections 10(2) and 10(3) of the Online Safety Act 2023, already bind regulated user-to-user services. The hash matching measures in the Illegal Content Codes of Practice are recommendations and, on Ofcom's statement, come into force on 30 September 2026.
Who this affects: Online safety compliance leads and general counsel at regulated user-to-user services with UK users, most immediately in the adult and instant messaging sectors, and the regulatory lawyers advising them on Online Safety Act code compliance.
Issue date: Case opened 9 September 2026. The code measures take effect 30 September 2026. The separate call for evidence closes 6 November 2026.
What changed: Ofcom moved from publishing measures to opening an enforcement programme against them, three weeks before those measures take effect, and named the sectors it will look at first.
Analysis: Following the code is a route to compliance, not the only one. The bulletin expressly contemplates alternative measures, which means the operative question for a service is evidence of effectiveness rather than adoption of a particular tool.
Primary sources: Ofcom enforcement programme bulletin, NCII measures · Ofcom news release, 9 September 2026
- Instrument (EN)
- Enforcement programme into measures being taken by services to prevent users from encountering or sharing non-consensual intimate imagery (NCII)
- Authority
- Ofcom, Office of Communications
- Jurisdiction
- United Kingdom. Regulated user-to-user services with UK users, wherever established
- Status
- Open. Case opened 9 September 2026, with the opening text published the same day
- Bindingness
- The section 10 duties are binding and already in force. The enforcement programme is a monitoring and assessment workstream, not a determination against any service. The hash matching measures are recommendations in the Codes of Practice and take effect 30 September 2026
- Issue date / next deadline
- Opened 9 September 2026. Code measures in force 30 September 2026. Call for evidence responses due 6 November 2026
- Legal basis
- Sections 10(2) and 10(3) of the Online Safety Act 2023, as stated in the bulletin's relevant legal provisions field
- Primary source
- https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/Enforcement-programme-into-measures-being-taken-by-services-to-prevent-users-from-encountering-or-sharing-non-consensual-intimate-imagery-NCII
What Ofcom actually opened
The enforcement bulletin records a case opened on 9 September 2026, with the status Open, into duties under the Online Safety Act 2023 to protect users from encountering and sharing non-consensual intimate imagery. The relevant legal provisions field names sections 10(2) and 10(3).
Ofcom describes it as a programme of work to assess the measures being taken by providers of services that present particular risks of harm to UK users from NCII, and states that the programme will focus on hash matching measures. Four activities are listed under the heading of what Ofcom will do as part of the programme: identifying services that present particular risks, assessing the measures those providers are taking, determining where potential non-compliance is identified whether formal enforcement action may be appropriate, and driving compliance across the sector through supervision engagement, industry communications and formal investigations.
An enforcement programme is not a finding. No service is named in the bulletin, no contravention is alleged against anyone, and no penalty is imposed. What has happened is that a regulator has opened an enforcement programme and said what it will look at.
Recommended is not required, and the bulletin says so
The bulletin's background section describes the position in the regulator's own words: "These measures recommend that those service providers that fall within scope use hash matching technology to detect NCII, for the purpose of then making an illegal content judgement. They come into force on 30 September 2026." The verb is recommend, and the date is three weeks after the case was opened.
The structure behind that is the ordinary one for Online Safety Act codes. Part 3 of the Act imposes the duties, which the bulletin summarises as proportionate measures to prevent users encountering priority illegal content including NCII, measures to mitigate and manage the risks identified in the service's most recent illegal content risk assessment, and systems and processes designed to minimise the time priority illegal content is present and to take it down swiftly on becoming aware. The codes recommend how to meet them.
Ofcom then makes the alternative route explicit. The programme, it says, will focus on services' implementation of the new hash matching measures recommended in the codes, "or any alternative measures implemented to comply with their duties". The news release published the same day puts the same point in operational terms: a service without hash matching would need to show that its systems and processes curb the spread of NCII by other equally effective means.
So the question a provider should be preparing to answer is not which tool it bought. It is what evidence it holds that its chosen approach works, and that evidence problem is harder for a service that has taken the alternative route.
Ofcom has already named where it will start
The bulletin identifies the sectors by name: services in the adult and instant messaging sectors are at a particularly high risk of being used for the upload and dissemination of NCII, and so they will be the focus of this enforcement programme.
It also records a step already taken. Ofcom says it has already written to some of these relevant services to outline the measures and remind them of their duties to comply when the duties come in. A service in either sector that has not received such a letter should not read anything reassuring into that, and the bulletin says nothing about how many were written to.
On timing, Ofcom states that it expects services in scope of the measures to have brought themselves into compliance by 30 September 2026, or to be taking steps to come into compliance shortly thereafter, and that services who are not compliant, or are not taking steps to come into compliance, may be subject to formal enforcement action. The word is may, and the bulletin does not describe any automatic consequence of missing the date.
Where the 10 per cent figure comes from, and where it does not
The penalty figure being quoted in coverage of this announcement, fines of up to 10 per cent of global annual revenue, appears in Ofcom's news release of 9 September 2026. It does not appear in the enforcement programme bulletin, which sets out no penalty at all. We state that absence as a fact about the two documents rather than as a point about the underlying statutory maximum, which we did not open.
That distinction matters when the figure is repeated. The news release attributes it to failure to comply with legal duties, not to failure to deploy hash matching, which is consistent with the bulletin's position that the codes recommend and the Act binds.
The same split applies to the deepfake framing, which sits in the news release and not in the bulletin. The release says online platforms should have hash matching in place to detect and prevent the sharing of illegal intimate images, "including explicit AI-generated deepfakes". The enforcement bulletin does not use the word deepfake anywhere, and it does not use the words artificial intelligence or synthetic either. It says NCII throughout. Anyone citing this programme as an artificial intelligence measure is citing the release.
The news release also carries a statistic we can report only as sourced. David Wright, Chief Executive of SWGfL, is quoted saying that the organisation's research suggests over 369,000 women in the UK experience this abuse annually. That is SWGfL's figure, published in Ofcom's release, and neither document states the methodology or the population it is drawn from. We do not characterise it as large or small.
The two things published alongside it that bind nobody
The first is a call for evidence. Ofcom is asking academics, survivor and victim support groups and others how women's and girls' experiences online may have changed since its guidance for a safer life online for women and girls was published in November 2025. A call for evidence creates no obligation on anyone. Responses are due by 6 November 2026, and Ofcom says the evidence will inform a report on industry progress to be published next summer.
The second is an intention to consult. Ofcom says that by the end of this year it will consult on strengthening its Illegal Harms Codes of Practice to reflect changes to the law requiring platforms to remove non-consensual intimate image content within 48 hours of it being reported. That is three removes from an obligation on a service: a stated intention, to run a consultation, on amendments to a code that has not been amended. Nothing about a 48 hour code requirement is in force through this announcement, and we did not open the legislation the release links to.
One more conditional is worth recording accurately. Ofcom says that if industry action falls short it will consider making formal recommendations to Government on where the Online Safety Act may need to be strengthened. That is a possible recommendation about possible future legislation, and it changes nothing today.
What we did not verify
What we opened: the Ofcom enforcement programme bulletin for the NCII programme, read in full including the programme-into field, the case opened date, the summary, the relevant legal provisions field naming sections 10(2) and 10(3), and the opening text of 9 September 2026. We also opened and read in full Ofcom's news release of the same date, which carries the article:published_time metadata value 2026-09-09T09:01:47.000Z against the bulletin's 2026-09-09T09:00:48.000Z. The two pages returned materially different bodies, so this is not a shell serving one document at two addresses.
What we did not open: the Online Safety Act 2023 itself, including sections 10(2) and 10(3) and the penalty provisions; the Illegal Content Codes of Practice and the new hash matching measures in them; Ofcom's May 2026 statement announcing those measures; the November 2025 guidance for a safer life online for women and girls; Ofcom's online safety priorities document; the existing investigation into forums hosting image-based sexual abuse; the SWGfL research underlying the 369,000 figure; and the legislation behind the 48 hour takedown requirement. Every description of those documents here is as the bulletin or the release describes them.
What we refuse to claim: we do not say that hash matching is legally required, because the bulletin says the codes recommend it and expressly contemplates alternative measures. We do not say any service is non-compliant or under investigation, because an enforcement programme is an assessment workstream and the bulletin names no service. We do not say a 48 hour takedown duty applies through this announcement, because what Ofcom described is an intention to consult on code amendments. We do not state the statutory maximum penalty as a legal proposition, because we read the 10 per cent figure in a news release and not in the Act. We do not quantify how many services are in scope, because neither document gives a number.
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Two dates and one distinction. The code measures take effect on 30 September 2026 and they recommend hash matching; the duties Ofcom is enforcing sit in section 10 and already bind. If your service is in the adult or instant messaging sector, Ofcom has said in writing that you are the first place it will look. If you are relying on something other than hash matching, the file you need by the end of September is not a procurement record. It is evidence that your approach is equally effective, in a form somebody else can assess.
Source File
Open the enforcement bulletin and check three fields: the relevant legal provisions entry naming sections 10(2) and 10(3), the background sentence stating that the measures recommend hash matching and come into force on 30 September 2026, and the enforcement programme paragraph naming the adult and instant messaging sectors as the focus.
These measures recommend that those service providers that fall within scope use hash matching technology to detect NCII, for the purpose of then making an illegal content judgement. They come into force on 30 September 2026. ยท Ofcom enforcement programme bulletin, opening text, 9 September 2026
FAQ
Is hash matching legally mandatory for platforms from 30 September 2026?
Not as the bulletin frames it. The binding duties are in the Online Safety Act, at the sections 10(2) and 10(3) provisions Ofcom names. The hash matching measures sit in the Illegal Content Codes of Practice, which the bulletin says recommend that in-scope providers use the technology, and which take effect on 30 September 2026. The bulletin expressly refers to any alternative measures implemented to comply with the duties.
Does the enforcement programme mean any service is under investigation?
No. An enforcement programme is an assessment and monitoring workstream. The bulletin names no service, alleges no contravention and imposes no penalty. It says that where potential non-compliance is identified, Ofcom will determine whether formal enforcement action may be appropriate.
Which services is Ofcom looking at first?
The bulletin states that services in the adult and instant messaging sectors are at particularly high risk of being used for the upload and dissemination of NCII and so will be the focus of the programme. Ofcom also says it has already written to some of those services, without saying how many.
Is there now a 48 hour takedown requirement for intimate image content?
Not through this announcement. Ofcom said it will consult by the end of 2026 on strengthening its Illegal Harms Codes of Practice to reflect a change in the law on removal within 48 hours of a report. That is an intention to consult on a code amendment that has not been made, and this piece does not describe the underlying legislation, which we did not open.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.