Ofcom's Compliance Ultimatum: Dating Platforms Can't Wait for 2027
Key Points
- •Ofcom issued an open letter warning dating platforms that current Online Safety Act duties, including Children's Access Assessments, apply immediately rather than in 2027.
- •Ofcom will publish technical standards for highly effective age assurance at age 16 in October 2026 ahead of planned 2027 government legislative changes.
- •Proposed 2027 UK legislation will ban under-18s from accessing AI chatbot services that primarily offer sexualised content on digital platforms.
- •Match Group and Bumble have highlighted safety compliance in investor presentations, while smaller operators face cost burdens from potential double compliance across 2026 and 2027.
Ofcom has just told dating platforms something they'd rather not hear: the compliance work they were hoping to defer until the government's 2027 child protection overhaul arrives needs to happen now. The regulator issued an open letter this week making clear that existing Online Safety Act obligations remain in full force, regardless of forthcoming legislative changes, and that enforcement action awaits those who miscalculate. The timing is pointed, with some platforms appearing to bank on a wait-and-see approach whilst the government signals additional protections expected from spring 2027.
This is regulatory brinkmanship, and dating platforms are particularly exposed. Most rely on self-declared age gates rather than robust verification, making them precisely the kind of service Ofcom can point to when demonstrating enforcement credibility. The threat isn't theoretical—it's a shot across the bow for anyone treating current Children's Access Assessments as optional homework whilst waiting for clearer rules in 2027. Compliance teams should be treating this as the deadline, not the warm-up act.
What's required right now
According to Ofcom's letter, platforms likely to be accessed by children must already have completed Children's Access Assessments. They must identify and assess risks using Ofcom's Children's Register of Risks and Risk Profiles, implement measures from the regulator's Codes of Practice—or demonstrate alternative approaches that meet the same duties—and maintain appropriate documentation of all of it.
Create a free account
Unlock unlimited access and get the weekly briefing delivered to your inbox.
Dating platforms present a peculiar case. Most enforce 18+ age restrictions in their terms of service, but enforcement has historically been tick-box at best: enter your birth date, you're in. That places them in regulatory limbo. If a platform is theoretically adults-only but practically accessible to under-18s without meaningful friction, does it qualify as a service "likely to be accessed by children"? Ofcom's supervisory approach suggests the answer is yes, and the burden of proving otherwise falls on operators.
If a platform is theoretically adults-only but practically accessible to under-18s without meaningful friction, does it qualify as a service "likely to be accessed by children"? Ofcom's supervisory approach suggests the answer is yes.
The current requirements also extend to assessing risks from illegal activity that could affect children and taking steps to mitigate those risks. For dating platforms, that means evaluating exposure to grooming, child sexual abuse material, and other harms—even if the service is nominally age-gated. It's a compliance burden that requires both technical implementation and ongoing monitoring, neither of which comes cheap.
The 2027 shadow hanging over compliance budgets
The government's proposed measures, expected from spring 2027, add a layer of complexity that makes the current compliance push particularly awkward for operators. Plans include a ban on social media services for under-16s, restrictions on harmful features, default protections for 16- and 17-year-olds, and—most relevant for dating platforms experimenting with AI—a ban on under-18s accessing AI chatbot services primarily offering sexualised content.
That last provision could significantly constrain product development. Several dating platforms have been testing AI-driven matching, conversation prompts, and even companion features. If those tools edge anywhere near "sexualised content," the 2027 rules will require either hard age verification at 18 or abandoning the feature for younger users. Ofcom has committed to publishing a rapid assessment of "highly effective age assurance at age 16" in October 2026, which will almost certainly set technical standards that platforms with 18+ gates will need to meet or exceed.
The regulatory calculus is uncomfortable: invest now in compliance infrastructure that may be superseded by stricter requirements in 18 months, or risk enforcement action whilst waiting for clarity on what those stricter requirements will actually be.
For smaller operators and white-label providers, the cost of double compliance—once now, once in 2027—could be material.
What enforcement actually looks like
Ofcom has been explicit that it will monitor whether services are implementing safety measures effectively and will take enforcement action where they fall short. The regulator's blog on supervision and compliance, published alongside the open letter, outlines a framework that includes information requests, formal investigations, and financial penalties for non-compliance.
For dating platforms, the risk isn't just fines. Enforcement action brings reputational damage in a sector already grappling with trust deficits around safety. Match Group (MTCH) and Bumble (BMBL) have both made safety central to recent investor presentations, positioning their scale as an advantage in navigating regulatory complexity. Smaller operators without dedicated compliance teams are more exposed, particularly those running on third-party infrastructure where responsibility for child safety measures may be contractually murky.
The regulator's stated priorities—improving protections for children, tackling illegal content, and protecting women and girls—map directly onto dating platform vulnerabilities. These aren't tangential concerns. They're the core risks that regulators and, increasingly, investors are using to evaluate whether operators have their houses in order.
What operators should be doing
Compliance teams should be treating Ofcom's letter as a compliance audit trigger. If your platform hasn't completed a Children's Access Assessment, that's the starting point. If you've completed one but haven't implemented measures from Ofcom's Codes of Practice—or documented why alternative measures meet the same duties—you're exposed.
For platforms experimenting with AI features, the October 2026 age assurance assessment will be critical. Ofcom's definition of "highly effective" will set the bar for what's expected, not just in 2027 but as a benchmark for current best practice. Waiting until then to begin technical implementation is a gamble.
The broader issue is that child safety compliance under the Online Safety Act is no longer a one-off project. It's ongoing infrastructure. The platforms that treat it as such—building in verification, monitoring, and risk assessment as core product functions—will be better positioned both for current enforcement and for whatever 2027 brings. Those still relying on self-declared birth dates and hoping regulators look the other way are running out of road.
Key Takeaways
- •Dating operators relying on self-declared birth dates must immediately implement robust age verification infrastructure to avoid Ofcom investigations, reputational damage, and financial penalties.
- •Compliance teams should prepare for material cost burdens as initial Online Safety Act requirements precede stricter technical age assurance standards coming in October 2026 and Spring 2027.
Frequently Asked Questions
Policy & Regulation Desk
The DII Regulatory Monitor tracks legislation, enforcement action, safety rules and compliance across dating industry markets.
Comments
Join the discussion
Industry professionals share insights, challenge assumptions, and connect with peers. Sign in to add your voice.
Your comment is reviewed before publishing. No spam, no self-promotion.
