Online platforms face a 30 September deadline for new measures designed to stop illegal intimate deepfakes and other non-consensual intimate images spreading in the UK. Ofcom has formally issued amended Online Safety Act codes that bring hash-matching measures into force on that date and has opened an enforcement programme to examine how relevant services are preparing.
Intimate deepfakes are now part of a specific platform duty
The rules address intimate image abuse, which includes sharing or threatening to share intimate images without consent. Ofcom says the growth of generative AI has added to the problem because realistic synthetic sexual images can be created without a real photograph ever having existed in that form.
The new code measure recommends that certain user-to-user and search services use hash matching to detect known illegal intimate imagery and reduce its spread. Ofcom’s updated documents state that the amendments issued on 9 September come into force on 30 September. Formal enforcement action linked to the new measure would follow after the rules are in force.
In a separate enforcement announcement issued on 9 September, Ofcom said platforms should have hash matching, or an equally effective alternative, in place by 30 September. It also said firms that fail to comply with applicable legal duties can face penalties including fines of up to 10% of global annual revenue.
This is more specific than a general demand that platforms somehow remove deepfakes. The regulatory approach identifies a technical control, defines which services should consider it under the codes and provides guidance on the human review that should accompany automated matching.
Hash matching looks for a fingerprint, not an identical filename
A hash is a digital fingerprint generated from an image or other piece of content. In safety systems, specialised perceptual hashing can be designed to recognise material even after common changes such as resizing or compression. A participating service compares uploads or indexed material with hashes representing content that has already been identified through an appropriate process.
Ofcom is working with StopNCII.org, a service operated by the charity SWGfL. StopNCII allows an adult to create a digital fingerprint of an intimate image on their own device, so the underlying image does not have to be uploaded to the service simply to create the hash. Participating platforms can then use the fingerprint to help prevent matching material being uploaded or reshared.
That design matters for privacy. A system intended to protect somebody from unwanted distribution should not require them to create another unnecessary copy of the very image they are trying to contain. It also shows why the policy is narrower than generic AI detection: the main task is matching known abusive material, not asking an algorithm to decide from scratch whether every synthetic image is genuine or fake.
The rule reaches AI-generated images without treating every deepfake alike
Ofcom’s enforcement announcement explicitly includes sexually explicit AI deepfakes within the category of illegal intimate imagery it is targeting. That does not make every manipulated or AI-generated image illegal. The legal context concerns non-consensual intimate material and the duties of regulated services under the Online Safety Act.
LiveAIWire recently examined a different deepfake problem: how real-time callers can be challenged to perform an unexpected action. That research deals with detecting a live impersonation during a call. Hash matching solves another problem entirely: stopping previously identified abusive images from repeatedly circulating across services.
California has taken yet another approach. Its AI transparency law requires synthetic-media disclosures and public detection tools from covered generative AI providers. The UK measure is instead rooted in online-safety duties and the prevention of a specific category of illegal harm.
Platforms can face serious penalties, but the 10% figure needs context
Ofcom can impose substantial penalties for breaches of duties under the Online Safety Act, potentially reaching £18 million or 10% of qualifying worldwide revenue, whichever is greater. That does not mean a platform automatically receives a 10% fine if an image slips through on 30 September. Enforcement depends on the legal duty, the service, the facts and Ofcom’s process.
The regulator has opened an enforcement programme before the code takes effect so it can assess what relevant services are doing to prepare. The point is to test whether providers have appropriate systems rather than wait until a large failure becomes visible. Ofcom says services should be able to demonstrate an equally effective alternative if they are not using the recommended hash-matching approach.
Technology will not remove every form of intimate image abuse. New images may have no existing hash, offenders can move between services and automated systems can make mistakes. Human review, reporting routes, victim support and legal enforcement remain part of the surrounding system.
The difficult problem is stopping the same harm from recurring
An intimate image can be removed from one account and reappear minutes later through another. For victims, repeated redistribution creates a different burden from a one-off moderation decision. They may have to find, report and explain the same material again across multiple platforms.
Hash matching is designed to change that pattern. Once an image has been appropriately fingerprinted, participating services can recognise subsequent copies at scale. The technology is not a judgement about the person’s credibility each time the material appears. It is a way to make an earlier decision operational across repeated uploads.
Ofcom is also planning further work on removal speed. Its September material says it intends to consult by the end of the year on code changes reflecting legislation that requires providers to remove certain non-consensual intimate content within 48 hours after becoming aware of it. That is separate from the 30 September hash-matching measure.
The immediate milestone is therefore clear. From 30 September, amended codes on detecting intimate image abuse are in force. The meaningful test after that date will be whether services actually reduce re-upload and redistribution while handling matches accurately, protecting privacy and giving people a workable route when abusive material is new rather than already fingerprinted.
About the Author
Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.
