Ofcom's Protection of Children Codes explained: children's access assessments, children's risk assessments, content categories and the safety measures expected.

The children's codes are where the Online Safety Act stops being about illegal content and starts being about design. They ask a harder question than "did you remove it?" They ask whether a child using your service was likely to encounter harm in the first place.

Part of our UK Online Safety Act guides. Not legal advice.

  • What the children's codes cover
  • Children's access assessment
  • Children's risk assessment
  • Content categories
  • Measures in the codes
  • Frequently asked questions

What the codes cover

Ofcom's children's codes set out the measures a service can adopt to meet the children's safety duties. Following a code measure gives you a clear route to demonstrating compliance with the corresponding duty. You can depart from the codes, but then the burden shifts to you to show your alternative achieves at least the same protection.

Two assessments sit in front of the codes: the children's access assessment, which decides whether the duties apply, and the children's risk assessment, which decides what you do about them.

Two limbs. First, can children access the service? The answer is yes unless you operate age assurance that meets Ofcom's highly effective standard. A checkbox asking a user to confirm they are 18 does not clear that bar.

Second, if children can access it, is a significant number of children using the service, or is the service of a kind likely to attract a significant number of child users? Either limb brings you into scope.

See our age assurance guide for what clears the highly effective standard.

Structurally similar to the illegal harms assessment, but scoped to harms to children and broken down by age group. You assess the risk that children in each age band encounter each category of harmful content on your service, factoring in your functionalities, recommender systems, and how children actually use the product rather than how it was designed to be used.

The output feeds directly into which code measures you adopt. Keep the two documents linked, because Ofcom will read them together.

The three content categories

Primary priority content

Pornography, and content encouraging or providing instructions for suicide, self-harm, or eating disorders. Services must prevent children from encountering it at all, which in practice means highly effective age assurance.

Priority content

Abusive or hateful content, bullying, content depicting or encouraging serious violence, dangerous stunts and challenges, and content encouraging harmful substance use. Services must protect children from encountering it, calibrated by age group.

Non-designated content

Other content that presents a material risk of significant harm to an appreciable number of UK children, identified through your own risk assessment rather than a published list.

The distinction matters because the duty differs. Primary priority content must be prevented from being encountered by children. Priority content must be protected against, which allows more room for proportionate design measures.

Measures set out in the codes

Age assurance

Highly effective age assurance where primary priority content is allowed on the service.

Content recommender systems

Excluding or downranking identified harmful content in feeds served to children, rather than only removing it on report.

Content moderation

Systems capable of swiftly taking down harmful content, with performance targets and review capacity proportionate to the service.

Reporting and complaints

Routes that a child can actually find and use, with outcomes communicated back.

Terms and clarity

Terms of service written so a child user can understand what is and is not allowed.

Governance and accountability

A named accountable person for children's safety and a reporting line to senior management.

User support

Signposting to support material when a child encounters or reports harmful content.

A summary for orientation. Which measures apply to your service depends on its size, type and risk rating, and Ofcom's published codes are the authoritative text.

What is a children's access assessment?

It is the test that decides whether the children's safety duties apply to you at all. You assess whether children can access the service, and if so whether a significant number of children use it or whether it is likely to attract them. If the answer is yes on either limb, the children's duties bite and a children's risk assessment follows. Services that conclude children cannot access them need highly effective age assurance to back that conclusion up, otherwise the assessment does not hold.

Our service is not aimed at children. Do the codes apply?

Intent is not the test. What matters is whether children are likely to access the service in practice. A platform with no under-18 marketing, no age gate, and a visible under-18 population is likely in scope. This is the most common misreading we see.

How do the children's codes relate to the illegal harms duties?

They are separate and cumulative. The illegal content duties apply to every in-scope service and cover criminal content. The children's safety duties apply on top, to services likely to be accessed by children, and cover content that is harmful to children but not necessarily illegal. You need both assessments; one does not substitute for the other.

Does age-appropriate mean the same protections for a 9-year-old and a 16-year-old?

No. Ofcom's approach expects measures calibrated by age group, which means your systems need some notion of which age band a user falls into, not just whether they are over or under 18. Tuteliq's age assurance returns age ranges rather than a single boolean for this reason.

How does Tuteliq map to these measures?

Directly on detection and age assurance: behavioural detection of bullying, abuse, self-harm, violence and exploitation across text, voice, image and video, plus document and biometric age assurance returning age bands. It does not supply your recommender system changes, your terms of service, or your governance structure. Those are yours.

Age bands, behavioural detection, and the audit trail

Tuteliq returns age ranges rather than a single over-18 flag, and detects harm as behaviour across text, voice, image and video, so children's-code measures can be calibrated by age group.

Get Started Free · Read Documentation · View Pricing