195 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
11 new this week Library last updated 12 September 2026
← The incident library
HD-INC-186
Adult content services · United Kingdom · 2025 · A generative service published content the regulator treated as pornographic with no age assurance beyond a self declaration, and no record that any check had been run

Ofcom fined a nudification service for having no age check beyond a line saying users must be 18, and the operator blocked the United Kingdom rather than add one

By Ellie Harris · Filed Contravention period 17 January 2025 to 11 May 2025; Ofcom opened the investigation on 9 May 2025

Alleged: Itai Tech Ltd (Undress.cc) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Ofcom fined a nudification service for having no age check beyond a line saying users must be 18, and the operator blocked the United Kingdom rather than add one

What happened

On 20 November 2025 Ofcom, the United Kingdom online safety regulator, issued a confirmation decision against Itai Tech Ltd over a service called Undress.cc, following an investigation it opened on 9 May 2025 under its enforcement programme on age assurance for pornographic content.

Ofcom described the service in its decision as a web based platform that leverages artificial intelligence to generate sexually explicit images, and which produces explicit sexual images in response to user prompts using text. In its announcement Ofcom called it a nudification site.

Ofcom found that between 17 January and 11 May 2025 the service used no age assurance capable of being highly effective, contrary to sections 81(2) and 81(3) of the Online Safety Act 2023. The only measure in place was a statement on the site that users must be 18 or over. Ofcom found that any user, including a child, could view the content without highly effective age assurance in place. It also found that the operator had kept no written record of the age assurance it used, had published no summary of it, contrary to sections 81(4) and 81(5), and had not answered a statutory information notice by the deadline, contrary to section 102(8)(a).

Ofcom imposed penalties of 50,000 pounds for the age assurance contraventions and 5,000 pounds for the information notice contravention, payable by 31 January 2026. Ofcom’s case page records that Itai Tech Ltd implemented a block to restrict users with United Kingdom IP addresses from accessing the service, and that the investigation was closed on 15 January 2026. The Register reported that the block was put in place once the investigation had begun, after Ofcom had opened its case.

What an auditable version would have shown

Two of the contraventions Ofcom found were about records rather than about access. Section 81(4) requires a provider to keep a written record of the age assurance measures it uses, and section 81(5) requires it to publish a summary of how they are applied. Ofcom found neither existed. The law had already asked for the evidence, and there was none to produce.

A record kept for each attempt to reach the content would show the date, the assurance method offered, whether it ran, what it returned and whether the content was served after that result. Aggregated, the same records would show how many attempts were served without any check completing. That is the figure Ofcom’s finding turns on, and it was established from the absence of a mechanism rather than from the operator’s own records, which sections 81(4) and 81(5) required and which Ofcom found did not exist.

Such a record would show what the service did. It would not by itself decide whether the measure used was highly effective, which is Ofcom’s judgement to make.

Where the gap was

The gap was between what the site asked the user to say about themselves and what the operator could show it had checked. Ofcom found that a statement that users must be 18 was not capable of being highly effective, and that the operator kept no written record of the age assurance it used and published no summary of it.

A ConstraintGate is designed to test an action against a standing rule before it takes effect, here that content of this kind is not served unless an age assurance check has completed and returned a pass. A ConductRecord is designed to keep the check that ran, the method used, the result returned and the decision that followed, so a provider can show what happened rather than describe what it intended.

Ofcom did not require either design. They are Headlights designs.

What governance should have looked like

Ofcom’s position on the duty is published. In its announcement it said that the use of highly effective age assurance to protect children from harmful pornographic content is non negotiable and that it will accept no excuses for failure. Ofcom issued provisional decisions against two further providers on the same day, opened investigations into 20 more pornography sites across five companies, and widened two existing investigations.

Where a service generates content that falls under a duty to keep children out, best practice would be to treat the check as the thing that must be evidenced, not the notice. That means an age assurance result recorded for every session that reaches the content, a written record of the method in use and the dates it changed, and a published summary that matches what the records show. Section 81(4) and 81(5) already require the first two of those in law, which is why their absence was itself a contravention rather than a gap in good practice.

In this case the operator did not introduce age assurance. Ofcom’s case page records a block on United Kingdom IP addresses and the closure of the investigation.

Failure Pattern: it was reported that a service generating sexually explicit content stood behind a statement that users must be 18, that the regulator found this was not capable of being highly effective, and that the operator kept no written record of the age assurance it used and published no summary of it.

Governance Principle: where a rule turns on who is on the other side of a request, an organisation should be able to show what it checked, when it checked and what the check returned, rather than what it asked the user to declare about themselves.

The reference implementation of ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Itai Tech Ltd (Undress.cc) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed September 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →