Summary

  • Ofcom opened a sector-wide enforcement programme on 9 September 2026 focused initially on adult and instant-messaging services and their measures against non-consensual intimate imagery. Opening the programme is not a finding that any named service has breached the Online Safety Act.
  • Amendments to the user-to-user Illegal Content Codes take effect on 30 September. ICU C14 recommends hash matching for qualifying services but distinguishes a match, suspicion, an illegal-content judgment and a moderation action; it also permits alternative measures and requires safeguards for error, expression and privacy.

The programme begins before any verdict

On 9 September, Ofcom opened an enforcement programme into how services prevent users encountering or sharing non-consensual intimate imagery, or NCII. The first focus is on adult and instant-messaging sectors and on the use of hash matching. Ofcom says it will identify services that may be at risk of non-compliance, assess their measures and, where potential non-compliance emerges, consider formal enforcement.

Those are successive states. A sector programme allocates attention. A risk selection identifies where the regulator will look. An assessment tests a provider’s systems. A formal investigation, finding and penalty require later steps. The announcement does not name a service as having failed, and it should not be rewritten as a collective verdict against every adult service or messenger.

The statutory baseline comes from section 10 of the Online Safety Act 2023. Providers of regulated user-to-user services must use proportionate design or operational measures to prevent users encountering priority illegal content and to mitigate identified risks. They must operate proportionate systems that minimise the time priority illegal content remains and swiftly take illegal content down when alerted or otherwise aware.

Ofcom translates those duties into recommended measures. The amended user-to-user Codes were issued on 9 September and come into force on 30 September. A provider implementing an applicable recommendation is treated as complying with the corresponding duty. But providers may use alternative measures. If they do, they must record what they adopted, why it meets the duty and how they considered freedom of expression and UK users’ privacy.

Ofcom’s news release compresses that into a clear public deadline: use hash matching or prove another approach is equally effective. The code supplies the precision. The deadline belongs to an operative compliance measure, not a universal command to deploy one vendor or a declaration that only one technical architecture can satisfy the Act.

ICU C14 has a defined perimeter

ICU C14 applies to services that enable photographs, videos or other visual user-generated content and satisfy specified combinations of risk, purpose, size or file-sharing function. A high-risk service is covered where its principal purpose is hosting or disseminating regulated pornographic content, it has more than 700,000 monthly active UK users, or it is a file-storage and file-sharing service. A large service at medium or high risk is also covered.

That perimeter matters. “Adult services and messaging” describes Ofcom’s enforcement focus; it is not a substitute for applying the measure’s conditions service by service. Nor does it mean every image in a qualifying service becomes a candidate for public inspection. ICU C14 defines relevant visual content and recommends technically feasible perceptual matching, with cryptographic matching for video where the available hash set cannot support perceptual matching.

A hash is a derived representation used for comparison. It can support detection without sending the public an intimate image or asking an analyst to browse randomly through users’ media. Ofcom’s statement on detecting intimate image abuse says a database equivalent to or better than the leading third-party StopNCII.org database should materially reduce the prevalence of this abuse. That is an expected control effect, not proof that every database entry, match or downstream decision will always be correct.

The code therefore distinguishes verified and unverified hashes. A verified hash was determined to represent intimate-image-abuse content when it entered a database. An unverified hash was not. That label travels with the database state; it does not remove the service’s responsibility for how a later match is used.

A match can open two different paths

ICU C14.4 gives the clearest boundary. When relevant content produces the first positive match against an unverified hash at the applicable perceptual configuration—or the first cryptographic match—the provider should treat the event as reason to suspect the content may be illegal and review it under ICU C1. Suspicion is an instruction to examine; it is not an illegal-content judgment.

For other matches, ICU C14.5 creates a branch. Depending on the provider’s assurance in the detection outcome, it may treat the content as illegal and take it down swiftly. If that assurance is not sufficient, it should again treat the match as a reason for suspicion and review the content. The Illegal Content Judgements Guidance adds the legal discipline: a provider needs a sufficient understanding of UK law and must consider all reasonably available relevant information before concluding that there are reasonable grounds to infer an offence.

That matters acutely for intimate images. Similar pixels do not answer whether disclosure was consensual, whether a relevant defence or exemption exists, or what contextual information accompanies the post. Hash matching can make discovery faster. The judgment still belongs to the service applying law and available information to the case.

This is not an argument for delay. The harm of repeated circulation can be severe and difficult to reverse. The code is designed to support action before or as soon as content can be encountered by UK users. The governing problem is to combine speed with a defensible route through uncertainty rather than pretending uncertainty disappeared at the match.

Human review is a control system, not a ritual

ICU C14 requires human moderators to review and assess an appropriate proportion of detected content. The proportion is not a fixed number. Ofcom’s four-page human-review guidance says allocation should respond to documented performance evidence, accuracy, error patterns and harm.

It identifies two jobs. Moderation review can decide an individual question, such as whether a first match to an unverified hash depicts an intimate image. Quality-assurance review samples detected content and prior decisions to test how the technology and the surrounding process perform. The second task is not simply an appeal queue; it looks for systemic error.

The guidance makes the trade-off explicit. A perceptual system configured for recall, or a system using unverified hashes, may require more review because false positives are more likely. Severe harm to depicted people can justify faster action when assurance is high. High-impact action against an uploader makes reversibility more important. Quality assurance must also look beyond detected material: reports, complaints, community moderation and sampling may uncover false negatives that the matching system missed.

The hash set itself is part of governance. It should contain a significant body of original items, be updated regularly and be protected from unauthorised access or interference. If a provider determines that a hash does not represent intimate-image-abuse content, it should take reasonable steps to have the hash removed. For perceptual matching, providers must balance precision and recall, review performance at least every six months and keep a written account of the configuration, evidence and corrective steps.

Ofcom calls these provisions safeguards for expression and privacy. Its guidance also says data-protection law still applies. That is why a provider cannot demonstrate compliance by publishing sensitive hashes, victim identities or intimate material. It must make the control legible without reproducing the harm or giving evaders the parameters needed to defeat detection.

Publish a privacy-minimised hash-to-decision receipt

What is missing is a joined record of the decision path. A useful public and regulatory hash-to-decision receipt would begin with the service and policy version in scope; the source and version of the hash set; whether a matched hash was verified or unverified; the matching method and configuration class; and the assurance tier used to choose between review and immediate action.

It would then record the contextual inputs considered, whether review was individual moderation or quality assurance, the action and its effective time, whether the action was reversible, the complaint or appeal state, and whether a correction restored content, changed a hash or changed the configuration. Aggregate fields would report false positives and false negatives with their denominators, review coverage and the date of the six-month performance assessment. A separate regulator field would say whether the service was merely within the programme, under assessment, formally investigated, found compliant or found in breach.

The public receipt must not include an intimate image, a person’s identity, a reusable hash, a complaint narrative or an exploitable threshold. A regulator may need protected evidence behind the public status. The point is to preserve meaning at the transitions, not to create another database of victims.

This receipt is my editorial proposal. It is not required by Ofcom, the Act, StopNCII or any provider commitment. It applies the authority trace in Heng Lu’s Policy Mirror: each institutional statement should show who can decide and what evidence supports the state. His running-code test moves attention from policy language to observable transitions and correction. Why BTW Media Exists supplies the editorial restraint: the public record should distinguish measured operation from institutional positioning.

Ofcom lists proactive protection against intimate-image abuse among its online-safety priorities, while noting that enforcement priorities do not alter duties applying across a much larger field of services. The success test is therefore not a high number of matches or investigations. It is whether repeated harmful circulation falls while decisions remain accurate, reversible where possible and attributable to the actor that actually made them.

Sources

  1. Ofcom — NCII enforcement programme
  2. Ofcom — announcement of the 30 September measures
  3. Ofcom — statement on detecting intimate image abuse
  4. Ofcom — Illegal Content Codes for user-to-user services
  5. Ofcom — guidance on the appropriate proportion of human review
  6. Ofcom — Illegal Content Judgements Guidance
  7. Online Safety Act 2023
  8. Ofcom — online-safety priorities for 2026–27
  9. Heng Lu — The Policy Mirror
  10. Heng Lu — Running Code Primary
  11. Heng Lu — Why BTW Media Exists