This website uses cookies

Read our Privacy policy and Terms of use for more information.

Borrowed age checks don't borrow the liability

Ten developments across four jurisdictions, and four obligations that switched on while you were reading about something else. One is in Vienna, one is in Beijing, and the most consequential is a question about whether you can outsource a legal duty to Apple.

At a Glance

  • Borrowed age checks, borrowed liability — Ofcom is investigating Pornhub for leaning on Apple's age signal, and says the duty never left the site.

  • Austria's NIS2 law binds today — NISG 2026 is in force; registration runs to 1 January 2027 and incident reporting starts now.

  • China's cyber inspections widen — MPS Order 176 takes effect today and authorises remote penetration testing of non-CII systems.

  • Fed opens stablecoin rulebook — Two GENIUS Act proposals hit the Federal Register; comments close 30 November.

  • FedRAMP goes machine-readable — New Rev5 packages must be OSCAL from 30 September, with a one-year grace period.

  • Three deaths, one Class I recall — FDA elevates Abiomed's Impella controller removal to its most serious category.

Critical Actions

  1. Ofcom investigates Pornhub for outsourcing its age checks to Apple — Ofcom opened a formal investigation into Aylo under the Online Safety Act over whether its age assurance is "highly effective" and whether it completed a sufficient children's access assessment. In May 2026 Pornhub began relying on signals from Apple indicating a UK user may have completed Apple's own checks. Ofcom's position: the Act "is clear that it is the service provider's responsibility to ensure that any age assurance process is highly effective — no matter at what stage an age check occurs," and it will not determine how Apple operates its checks. Exposure is up to £18 million or 10% of qualifying worldwide revenue, whichever is greater. Action: Produce pre-deployment effectiveness test evidence for every third-party age or identity signal you consume, and re-run your children's access assessment if you changed the mechanism in 2026. Ofcom, 23 September 2026

  2. Austria's NIS2 law is in force today — and nothing will notify you — The Netz- und Informationssystemsicherheitsgesetz 2026 enters into force today, establishing a new Bundesamt für Cybersicherheit. The applicability self-assessment is itself the duty: core security and incident-reporting obligations bind from today whether or not you have registered. Registration runs through the new "NIS2 Services" application in the Unternehmensserviceportal and must initially be completed by 1 January 2027. Poland's registration deadline is 3 October; Italy requires ACN baseline measures from listed entities by 31 October. Essential entities face up to €10 million or 2% of worldwide annual turnover. Action: Run the in-scope self-assessment this week if you have any Austrian establishment, and gather the § 29(2) registration data including the § 25 company-size determination. USP (Austria), official notice · NISG 2026, BGBl. I Nr. 94/2025

  3. The Fed's GENIUS Act stablecoin proposals start a 30 November clock — Two proposals issued 24 September for Board-supervised payment stablecoin issuers were published in the Federal Register on 29 September. The first requires backing outstanding stablecoins with high-quality liquid reserves subject to eligible-asset and diversification standards, sets minimum capital for credit and operational risk, imposes risk-management, custody and AML standards, prohibits tying stablecoin purchases to other services, and adds examination, audit and disclosure duties. The second establishes a tailored approval pathway. Action: Model the reserve-eligibility and diversification tests against your current book before drafting comments — the capital charge follows the asset mix. Federal Register, 29 September 2026

❝

We corrected ourselves on this one. Commercial trackers — and our own earlier draft — put the Austrian registration deadline at 31 December 2026. The Unternehmensserviceportal's official text says 1 January 2027. Austria's own portal also warns readers against the commercial "NISG Betroffenheitsanalyse" offerings now circulating. Check the gv.at source, not the vendor's.

Enforcement Watch

  • China / MPS Order No. 176 — in force today — The Ministry of Public Security's Measures for Cyberspace Security Supervision and Inspection by Public Security Organs take effect today, repealing the 2018 Order No. 151. Scope expands from "internet security" to "cyberspace security" — network, data and information security together — reaching network operators, data processors, personal-information processors and product and service providers. The operative change is the toolkit: online patrols, on-site checks, scenario-specific inspections, and remote vulnerability-probing and penetration testing of non-CII systems. Confirm asset inventory, log retention, incident-response contacts and a designated PSB point of contact. Ministry of Public Security

  • FDA / Abiomed — Class I recall, three deaths — FDA classified Abiomed's removal and correction of Automated Impella Controllers as a Class I recall on 24 September, its most serious category. Affected: 0042-0000-US, 0042-0010-US and 0042-0040-US. Root cause is failure of the purge-flag component within the purge pressure sensor assembly, which can stop the controller recognising an inserted purge disc. FDA reports three deaths and 37 serious injuries as of 17 August 2026; because the Impella provides active haemodynamic support, hospital inventory may continue in use during the transition. FDA separately elevated Boston Scientific's Imager II angiographic catheter removal to Class I on 25 September over reduced stabilising agents in catheter tips — two serious injuries, no deaths. FDA — Impella · FDA — Imager II

  • CAC — two-month campaign against fabricated personas — On 30 September the Cyberspace Administration of China launched a nationwide campaign targeting five categories of fake-persona short-video content: false vulnerable identities, fabricated professional credentials, AI synthetic-media impersonation of public figures, luxury and superstition fraud personas, and staged conflict scripts. Governance reaches accounts, platforms and MCN agencies, with account bans, mandatory labelling, recommendation demotion and stronger credential verification. An enforcement campaign, not a rulemaking — no comment window. Cyberspace Administration of China

Deadline Watch

  • 2 Oct — TC260 Agent-System Development Security Guide, draft comments close (China, 1 day).

  • 3 Oct — NIS2 registration for essential and important entities (Poland, 2 days).

  • 9 Oct — FedRAMP RFC-0033 (20x Class D) and RFC-0034 (TAG) comments close (US, 8 days).

  • 17 Oct — Draft Regulation on Minors' Healthy and Safe Internet Use, comments close (China, 16 days).

  • 26 Oct — Colorado ADMT / Chatbot Safety Act written comments close and hearing (US, 25 days).

  • 31 Oct — ACN baseline security measures for listed NIS entities (Italy, 30 days).

  • end Oct — Ofcom rapid assessment to Parliament on "highly effective" age checks for over-16s (UK).

  • 13 Nov — EDPB Guidelines 04/2026 consultation closes (EU, 43 days).

  • 13 Nov — DPDP consent-manager registration opens under Rule 4 (India, 43 days).

  • 16 Nov — GovOps/CalOES "kill switch" recommendations due under EO N-9-26 (California, 46 days).

  • 23 Nov — CMS RFI on Medicare Part D pharmacy contracting standards closes (US, 53 days).

  • 24 Nov — FDA draft guidance on robotically-assisted surgical devices, comments close (US, 54 days).

  • 30 Nov — Federal Reserve GENIUS Act stablecoin proposals, comments close (US, 60 days).

  • 2 Dec — EU AI Act Art. 50(2) transitional deadline and AI Omnibus CSAM/NCII technical safeguards (EU, 62 days).

  • 7 Dec — FedRAMP CR26 VDR/VER obtain-or-maintain, grace to 7 Mar 2027 (US, 67 days).

  • 11 Dec — Cybersecurity Information Sharing Act of 2015, new sunset (US, 71 days).

  • 1 Jan 2027 — Initial NISG 2026 registration (Austria, 92 days).

Around the World

  • United States — FedRAMP's format deadline landed. Under RFC-0024, folded into the Consolidated Rules for 2026 via Notice NTC-0009, new Rev5 authorisation packages must be submitted in an approved machine-readable format from 30 September, with OSCAL as the primary Rev5 standard. FedRAMP says missing the applicable timelines results in public notification; a grace period runs to 30 September 2027, after which non-compliant services may lose certification. The comprehensive machine-readable package is a phased Class D (High) requirement due by November 2027 — not a universal 30 September obligation. CR26 becomes mandatory for all stakeholders on 1 January 2027. FedRAMP Notice NTC-0009

  • United Kingdom — the crypto gateway is open. The FCA's authorisation gateway for the UK cryptoasset regime opened at 7am on 30 September. Firms already authorised under FSMA must vary their permissions; MLR-registered firms cannot convert automatically and need new FSMA authorisation. The prioritised application window closes 28 February 2027 — apply after that but before the regime commences and a transitional provision restricts you, by operation of law, to performing pre-existing contracts with no new customer business. Firms that do not apply must wind down UK cryptoasset operations. FCA

  • United States — threat-sharing gets a 71-day reprieve. The Cybersecurity Information Sharing Act of 2015 was due to sunset on 30 September. H.R. 6500, the Continuing Appropriations and Extensions Act, 2027, signed 2 September 2026, amends 6 U.S.C. 1510(a) to strike "September 30, 2026" and insert "December 11, 2026." That preserves the liability, antitrust and FOIA protections underpinning voluntary threat-indicator sharing — but it is a stopgap, not the permanent reauthorisation industry has sought. Treat December as a checkpoint, not a resolution. H.R. 6500 text

  • European Union — how DPAs will decide to fine you. At its 21 September plenary the EDPB adopted Guidelines 04/2026 on the power to impose administrative fines in relation to other corrective powers, setting a five-step methodology and replacing the old WP29 fining guidelines. The commercially significant step: if an infringement is minor there will generally be no fine and a reprimand may issue instead; if it is not minor, there is a strong presumption that a fine should be imposed. Fourteen worked examples are included. Consultation closes 13 November. EDPB

  • California — one chatbot law signed, eight bills in limbo. The Governor signed AB 1609 (Zbur) on 28 September: large businesses must make a good-faith effort to connect a customer to a human within 15 minutes of a request, must disclose when a representative is a chatbot, and certain large businesses must publish customer-service contact details. AB 2025 (disclosure of digitally altered tenancy-listing images) appears on the 27 September signed list. Note what we are not telling you: neither release states an effective date or defines "large business," and the outcome of eight other tracked AI bills — AB 2575, AB 2392, SB 947, SB 903, SB 951, SB 574, SB 1000, SB 1246 — could not be confirmed as the constitutional window closed on 30 September. Do not treat them as signed or vetoed. Governor's office, 28 September

  • India — a statutory under-18 account ban is being drafted. On 28 September the Supreme Court directed the Union Government to consider framing rules so platforms conform their software to Indian law, Justice Bagchi stressing that "Guidelines are mere guidelines. It should be in some statutory format." The premise is that a minor's agreement with a platform is void under Section 11 of the Indian Contract Act, 1872. On 29 September the Centre told the bench, through the Solicitor General, that it would amend the IT Intermediary Guidelines to make it a statutory obligation for intermediaries not to let minors open social-media accounts. No draft text, effective date or approved age-assurance method has been specified. Sourcing caveat: this item rests on Indian legal and trade press only — we could not obtain the Court's order or a MeitY document, so treat the quotations and the Centre's commitment as reported rather than verified. Bar & Bench

Deep Dive

United Kingdom · Age Verification

Borrowed age checks don't borrow the liability

Through 2026 a comfortable theory took hold among platforms with age-gated content: age assurance is a solved problem, and someone else has solved it. The operating system knows roughly how old the account holder is. The app store has payment history, a birth date, sometimes a verified document. Why would a downstream site repeat work that Apple or Google has already done more accurately, more privately, and at vastly greater scale? Delegating the check is cheaper, less intrusive, and — the part nobody writes into the business case — it appears to move the liability somewhere better capitalised.

Ofcom's 23 September investigation into Aylo is the first regulatory test of that theory, and the framing of the notice matters far more than the identity of the respondent. Ofcom did not say Apple's signal is weak. It said something structurally different, and far more inconvenient: the Online Safety Act "is clear that it is the service provider's responsibility to ensure that any age assurance process is highly effective — no matter at what stage an age check occurs." Then it closed the obvious escape route in the same breath, stating that the investigation "will not make a determination on how Apple operates its age checks." The regulator has declined to be drawn into assessing the upstream provider at all. The only question on the table is narrower and much harder for Aylo to answer: did you conduct sufficient due diligence and testing before you started relying on someone else's check?

That reframing opens a compliance gap that almost nobody currently documents, because the gap sits between two activities that feel like they overlap and do not. Delegating an age check is a procurement decision, and procurement decisions generate artefacts: contracts, security questionnaires, data processing agreements, a vendor's own assurance that its method is robust. What Ofcom is asking to see is a different artefact entirely — evidence of effectiveness testing against a regulatory standard, generated before deployment, plus a refreshed children's access assessment, because the Act requires one before any significant change to the design or operation of a service and again in response to evidence of reduced effectiveness. A signed contract is not that. A vendor attestation is not that. And the penalty does not scale down because the failure originated in a partner's system: £18 million or 10% of qualifying worldwide revenue, whichever is greater, plus Ofcom's remedial and business-disruption powers.

The second-order problem is that none of this reasoning is specific to pornography, to Apple, or to age. Strip the facts out and what remains is a general proposition: where a statute places a duty on you, outsourcing the mechanism by which you discharge it does not outsource the duty, and your defence is the quality of your own pre-deployment verification. That reaches every service consuming an external trust signal — device-level age attestation, an identity wallet, a bank's KYC result, a platform's "verified adult" flag, a cloud provider's compliance certification standing in for your own control testing. The architecture of modern compliance is built on exactly these borrowed assurances, and this is the first time a regulator has said plainly that borrowing one creates a testing obligation rather than discharging it.

There is a reason to think this is the beginning rather than an outlier. Ofcom has a rapid assessment on "highly effective" age checks for over-16s due to Parliament by the end of October, and it has been running age-assurance enforcement programmes since March 2025 with fines already issued. Here's what organisations need to do before the first provisional decision lands and the standard hardens into precedent…

The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk