New ‘hash matching’ tool will stop certain images being shared in the UK
Key Points
- Ofcom has given platforms until 30 September to run hash matching against intimate image abuse
- Hash matching turns an image into a digital fingerprint and blocks uploads that match a known illegal file
- StopNCII.org lets victims create a hash from their own device without the image leaving their possession
- Firms without hash matching must prove their systems are equally effective or face fines of up to 10% of global revenue
- SWGfL research suggests more than 369,000 UK women experience intimate image abuse each year
Online platforms have until 30 September to start running hash matching technology that blocks non-consensual intimate images and explicit AI-generated deepfakes before they spread, Ofcom confirmed on Wednesday (9 September).
The regulator set the deadline as it opened an enforcement programme to check whether tech firms are meeting their legal duties to curb intimate image abuse, with fines of up to 10% of global annual revenue for those that fail.
Hash matching works by converting an image into a unique string of characters known as a hash, which acts as a digital fingerprint for that file.
Platforms compare the hash of every image uploaded against a database of hashes from known illegal images, and block any upload that matches.
The image itself is never stored or shared as part of the process, because the database holds only the fingerprints and not the pictures.
Ofcom said it continues to recommend the hash matching tool run by StopNCII.org, a database operated by online safety charity SWGfL, which also runs the Revenge Porn Helpline.
The StopNCII tool lets a person generate a hash of an intimate image, including an AI-generated deepfake, from their own phone or computer. The hash then goes to participating platforms, which can detect and block the image if anyone tries to upload it.
“Tools like StopNCII.org allow a person to create a digital fingerprint of an intimate image, including AI-generated deepfakes, from their own device, so it can be blocked before it is ever shared, without the image itself leaving their possession,” said David Wright, Chief Executive of SWGfL.
“Requiring platforms to adopt hash matching is a vital shift toward stopping this abuse before it spreads, rather than only responding once the damage is already done,” he added.
Ofcom has partnered with SWGfL to share information, expertise and evidence on effective approaches to tackling intimate image abuse online.
Platforms that do not use hash matching must prove to the regulator that their own systems curb the spread of such images by other equally effective means.
SWGfL research suggests more than 369,000 women in the UK experience intimate image abuse every year, and the charity said demand on the Revenge Porn Helpline continues to grow sharply.
“Technology companies now have a legal responsibility to put the right tools in place to stop this kind of deeply harmful content spreading on their services,” said Almudena Lara, online safety policy development director at Ofcom.
“The deadline is fast approaching and firms that ultimately fail to comply with their duties can expect us to take robust action under our enforcement programme, launched today,” she added.
Ofcom will also consult by the end of the year on strengthening its Illegal Harms Codes of Practice to reflect a change in the law requiring platforms to remove non-consensual intimate images within 48 hours of a report.