Ofcom’s Intimate Image Abuse Hash-Matching Codes: What Changed for Certain UK Online Services on 30 September 2026
Ofcom's amended Illegal Content Codes recommending hash matching for intimate image abuse take effect from 30 September 2026. This measure creates new standards for large general search services (more than 7 million UK monthly users) and for user-to-user services that meet specific size, risk and type criteria - which can include smaller porn or file-sharing services at high risk.
Under the Online Safety Act 2023, services must comply with illegal content safety duties and keep risk assessments up to date. While the Codes are recommended measures rather than absolute mandates, they set the benchmark for detecting and managing intimate image abuse. Providers may use alternative measures, but must keep a written record (OSA ss.23(4), 34(4)), and must have particular regard to users' freedom of expression and privacy (OSA s.49(5)).
Here is a breakdown of what the hash-matching measure involves, how it handles deepfakes, and what is expected of human review pathways.
Perceptual vs. Cryptographic Hash Matching
The Codes recommend connecting to a database of known intimate image abuse (NCII) hashes to scan content. Ofcom recommends perceptual hash matching. Cryptographic hash matching is a fallback only for video, where the provider's hash set does not support perceptual matching.
A verified hash is one that was determined to be of intimate image abuse content when it was added to the database; any other hash is unverified. Some databases, including Ofcom's benchmark StopNCII.org how it works, do not review the underlying images (the hash is generated on the victim's device), so their hashes are unverified.
Upload-time matching is expected for user-to-user services. For search services the measure applies to content that users can encounter through search results.
Human-Review Expectations
Ofcom's measure recommends that providers "should ensure human moderators review and assess an appropriate proportion of detected content" (ICU C14.6 / ICS C8.6). This is a recommended measure, not a legal requirement: providers that follow it are treated as complying with the relevant duty, and providers may use alternative measures.
Ofcom has not set a fixed proportion. It expects providers to decide based on their confidence in the hash-matching results and on the harm of both missed and wrongly actioned content. Human review is also recommended for quality assurance of the technology, and where a provider uses verified hashes further review of each match may not be needed.
First match to an unverified hash (at that configuration of the technology): the provider should treat this as reason to suspect the content may be illegal and review it under Ofcom's content-moderation measure (ICU C1 / ICS C1). Ofcom says the review can be done by human moderators, by automated technology such as nudity detection, or both (Ofcom Statement: Detecting intimate image abuse).
Deepfakes and Novel AI Generation
Synthetic images that appear to show a real person in an intimate state can be intimate image abuse, and known instances can be detected by hash matching once hashed; new or unhashed deepfakes are not detected by this measure.
Crucially, hash matching relies on reference databases and does not independently discover novel, never-before-hashed generative content.
Consequences of a Match
User-to-user services may take matching content down; search services may remove it or lower its ranking. However, a hash match does not itself establish illegality. The sexual offence of intimate image abuse requires a lack of consent and lack of reasonable belief in consent, which a hash cannot show. A match could simply be consensual sharing, non-intimate images wrongly added to a database, or advertisements.
Implementation and Risk Assessments
Providers must keep risk assessments up to date and carry out a further assessment before making a significant change to service design. The Codes’ entry into force does not, by itself, create a freestanding statutory requirement to rewrite risk assessments on that calendar day. Separate duties under the Crime and Policing Act 2026 are not covered here; check commencement. Ofcom issued the amended Codes on 9 September 2026 after the draft had been laid before Parliament for the statutory 40-day period; under section 43(4) of the Online Safety Act they come into force at the end of the period of 21 days beginning with the day of issue - i.e. from 30 September 2026.
Frequently Asked Questions (FAQ)
Does every platform have to use hash matching?
Not every platform. The recommendation applies to large general search services (over 7 million UK monthly users) and to user-to-user services that allow images, videos or visual content to be shared and that are (a) high risk for intimate image abuse and either pornography-focused, file-storage/sharing, or above 700,000 UK monthly users, or (b) large (over 7 million) and medium or high risk.
Does a hash match prove an image is illegal?
No. A hash match, particularly to an unverified hash, is a reason for the platform to suspect the content may be illegal. Ofcom recommends that such a first match be reviewed, by human moderators or by suitable automated technology, to decide whether it is intimate image abuse, and that human moderators review an appropriate proportion of detected content and are used for quality assurance. These are recommended measures, not a blanket legal requirement. A hash shows an image resembles a database entry; it cannot show whether the person consented.
Do private encrypted chats have to be scanned?
The Online Safety Act measures for hash matching discussed here focus on user-generated content that is communicated publicly. The Codes do not establish a mandate to break end-to-end encryption to scan private messages.
CurrentBeam is an independent digital publication using AI-assisted research and drafting. Articles link to their sources; automated checks do not establish that a human has reviewed an article. See our Editorial Guidelines for our process and how to request corrections.
Was this article helpful?

