An intimate image shared without consent can be copied long after the original upload has been removed. The same problem arises with a realistic sexual deepfake depicting someone who never posed for the image. Platforms’ responsibilities therefore extend beyond responding to the first complaint.
On 9 September 2026, Ofcom announced an enforcement programme ahead of new code measures taking effect on 30 September. Here is what that means, as at 13 September 2026.
Preventing repeat sharing
The new measures focus on hash matching. This compares a digital fingerprint of an image or video against a database, helping services identify copies of material already flagged as intimate image abuse. It can also help detect the circulation of sexual deepfakes.
The user-to-user code amendment has a defined scope. It covers qualifying services allowing visual content: large services at medium or high risk, and certain high-risk services, including pornography-focused services, file-storage and sharing services, and services with more than 700,000 monthly active UK users. Its hash-matching recommendation concerns publicly communicated content. It is not a blanket instruction to scan every private conversation. A separate amendment covers large general search services, so the measures also address how abusive images are found through search results.
Ofcom expects services within scope to use hash matching or demonstrate equally effective alternatives. The underlying legal duties are mandatory; the codes provide a route to compliance. Appropriate human review and safeguards against mistaken removals remain part of that approach.
Removal duties and the 48-hour rule
Section 10 of the Online Safety Act 2023 requires regulated user-to-user services to use proportionate measures against illegal content and systems designed to remove it swiftly once alerted or otherwise aware of it.
The Act now also contains a separate requirement for systems designed to remove reported intimate-image content, and identified copies or substantially similar content, as soon as reasonably practicable and within 48 hours. This concerns reports by the person depicted or someone acting for them, and the provision contains exceptions, including where the provider considers the material is not intimate-image content.
That statutory provision should be distinguished from the 30 September hash-matching measures. Ofcom says it will consult before the end of 2026 on further code changes reflecting the 48-hour requirement. Forty-eight hours is not an invitation to leave known illegal content online until the deadline.
The person sharing the image can still commit an offence
Platform regulation does not replace criminal liability. In England and Wales, section 66B of the Sexual Offences Act 2003 includes an offence of intentionally sharing an intimate photograph or film without the depicted person’s consent and without a reasonable belief in consent, subject to statutory exceptions and a reasonable-excuse defence. The image can appear to show the person, which is relevant to deepfakes. More serious forms address particular intentions or purposes.
Agreement to take or privately send an image is not agreement to its wider circulation, nor does a platform’s decision either to remove or keep an image online indicate whether the sharing of it will be viewed as criminal by the courts.
Practical next steps
Someone affected can report the content to the service, retain the web addresses and reporting references, and consider StopNCII. Its tool creates the image fingerprint on the user’s device and shares the hash with participating companies. It does not remove material from the whole internet.
If you are being investigated over sharing intimate images or a deepfake, preserve the relevant messages and obtain advice before responding to the allegation. Contact Chetwode Criminal Defence Solicitors for a clear assessment of the evidence, consent issues and your next steps.

