technology

Ofcom’s Intimate Image Abuse Hash-Matching Codes: What Changed for Certain UK Online Services on 30 September 2026

✍️
CurrentBeam Editorial Team
AI-assisted · Human reviewed · September 30, 2026
⏱️ 5 min read
Abstract technical illustration of a digital file passing through a scanning grid and producing an alphanumeric hash fingerprint for database matching, in clinical blue and charcoal tones.

Ofcom's amended Illegal Content Codes recommending hash matching for intimate image abuse take effect from 30 September 2026. This measure creates new standards for large general search services (more than 7 million UK monthly users) and for user-to-user services that meet specific size, risk and type criteria - which can include smaller porn or file-sharing services at high risk.

Under the Online Safety Act 2023, services must comply with illegal content safety duties and keep risk assessments up to date. While the Codes are recommended measures rather than absolute mandates, they set the benchmark for detecting and managing intimate image abuse. Providers may use alternative measures, but must keep a written record (OSA ss.23(4), 34(4)), and must have particular regard to users' freedom of expression and privacy (OSA s.49(5)).

Here is a breakdown of what the hash-matching measure involves, how it handles deepfakes, and what is expected of human review pathways.

Read Next
Windows 10 ESU Now Runs Through October 2027: Cost, Eligibility and How to Enroll

Perceptual vs. Cryptographic Hash Matching

The Codes recommend connecting to a database of known intimate image abuse (NCII) hashes to scan content. Ofcom recommends perceptual hash matching. Cryptographic hash matching is a fallback only for video, where the provider's hash set does not support perceptual matching.

A verified hash is one that was determined to be of intimate image abuse content when it was added to the database; any other hash is unverified. Some databases, including Ofcom's benchmark StopNCII.org how it works, do not review the underlying images (the hash is generated on the victim's device), so their hashes are unverified.

Upload-time matching is expected for user-to-user services. For search services the measure applies to content that users can encounter through search results.

Human-Review Expectations

Ofcom's measure recommends that providers "should ensure human moderators review and assess an appropriate proportion of detected content" (ICU C14.6 / ICS C8.6). This is a recommended measure, not a legal requirement: providers that follow it are treated as complying with the relevant duty, and providers may use alternative measures.

Ofcom has not set a fixed proportion. It expects providers to decide based on their confidence in the hash-matching results and on the harm of both missed and wrongly actioned content. Human review is also recommended for quality assurance of the technology, and where a provider uses verified hashes further review of each match may not be needed.

First match to an unverified hash (at that configuration of the technology): the provider should treat this as reason to suspect the content may be illegal and review it under Ofcom's content-moderation measure (ICU C1 / ICS C1). Ofcom says the review can be done by human moderators, by automated technology such as nudity detection, or both (Ofcom Statement: Detecting intimate image abuse).

Deepfakes and Novel AI Generation

Synthetic images that appear to show a real person in an intimate state can be intimate image abuse, and known instances can be detected by hash matching once hashed; new or unhashed deepfakes are not detected by this measure.

Crucially, hash matching relies on reference databases and does not independently discover novel, never-before-hashed generative content.

Consequences of a Match

User-to-user services may take matching content down; search services may remove it or lower its ranking. However, a hash match does not itself establish illegality. The sexual offence of intimate image abuse requires a lack of consent and lack of reasonable belief in consent, which a hash cannot show. A match could simply be consensual sharing, non-intimate images wrongly added to a database, or advertisements.

Implementation and Risk Assessments

Providers must keep risk assessments up to date and carry out a further assessment before making a significant change to service design. The Codes’ entry into force does not, by itself, create a freestanding statutory requirement to rewrite risk assessments on that calendar day. Separate duties under the Crime and Policing Act 2026 are not covered here; check commencement. Ofcom issued the amended Codes on 9 September 2026 after the draft had been laid before Parliament for the statutory 40-day period; under section 43(4) of the Online Safety Act they come into force at the end of the period of 21 days beginning with the day of issue - i.e. from 30 September 2026.

Frequently Asked Questions (FAQ)

Does every platform have to use hash matching?
Not every platform. The recommendation applies to large general search services (over 7 million UK monthly users) and to user-to-user services that allow images, videos or visual content to be shared and that are (a) high risk for intimate image abuse and either pornography-focused, file-storage/sharing, or above 700,000 UK monthly users, or (b) large (over 7 million) and medium or high risk.

Does a hash match prove an image is illegal?
No. A hash match, particularly to an unverified hash, is a reason for the platform to suspect the content may be illegal. Ofcom recommends that such a first match be reviewed, by human moderators or by suitable automated technology, to decide whether it is intimate image abuse, and that human moderators review an appropriate proportion of detected content and are used for quality assurance. These are recommended measures, not a blanket legal requirement. A hash shows an image resembles a database entry; it cannot show whether the person consented.

Do private encrypted chats have to be scanned?
The Online Safety Act measures for hash matching discussed here focus on user-generated content that is communicated publicly. The Codes do not establish a mandate to break end-to-end encryption to scan private messages.

Tags:#Online Safety Act#Ofcom#Content Moderation#Hash Matching#Deepfakes#UK Tech Law
Share:𝕏 TwitterFacebookWhatsApp
← Back to All Articles
✍️
CurrentBeam Editorial Team
Editorial Team

CurrentBeam is an independent digital publication using AI-assisted research and drafting. Articles link to their sources; automated checks do not establish that a human has reviewed an article. See our Editorial Guidelines for our process and how to request corrections.

Was this article helpful?

Share this article:𝕏 Twitter🔗 LinkedIn📘 Facebook

Related Articles

Windows 10 ESU Now Runs Through October 2027: Cost, Eligibility and How to Enroll
technology

Windows 10 ESU Now Runs Through October 2027: Cost, Eligibility and How to Enroll

📖 7 min📅 September 29, 2026