11 min read

The Geoblock Came Too Late: Fapello's £630,000 Fine and the Liability You Can't Exit Your Way Out Of

Ofcom fined the operator of fapello.com £630,000 in July 2026, after the site had already geoblocked the United Kingdom. Exiting a market is a forward-looking move applied to a backward-looking problem: a fine prices the window you were live and non-compliant, and leaving on day N does nothing about days one through N. Here is what the Fapello decision actually establishes, why the extra £30,000 for ignoring an information request is the part operators keep underestimating, and why the only version of 'cheaper than the fine' was verifying before the window ever opened.

Editorial illustration on a deep slate-navy background: a closed geo-fence gate blocking a region, with a dated penalty stamp already pressed onto the ground behind it inside the gate. A light emerald audit-trail line runs backward in time past the gate; a blue clock marks the non-compliance window that closed before the exit. Abstract, no faces, no real people, no brand marks, no readable text.

On 9 July 2026, Ofcom fined the operator of fapello.com £630,000. The detail worth stopping on is what the site had already done by the time the penalty landed: it had geoblocked the United Kingdom. UK IP addresses could no longer reach it. In the language every “just leave the market” deck uses, the company had exited. Ofcom fined it anyway.

That is the whole lesson, and it runs directly against the instinct a lot of operators are acting on right now. We wrote earlier this year about the forward-looking version of this decision, the choice between building a verification flow and blocking a jurisdiction outright, and why geoblocking is not the zero-cost option it looks like. Fapello is the other half of that argument, the part the spreadsheet leaves out. A geoblock is a switch you flip going forward. A fine is a bill for what already happened. Flipping the switch does not un-happen the months in which children in the UK could reach the content, and those are the months the regulator prices.

What the Fapello decision actually says

Under Part 3 of the Online Safety Act, a service that hosts pornographic material has a duty to protect children through what the Act calls highly effective age assurance: a check good enough to determine, with real confidence, that a user is over 18. Fapello did not have one that met the bar. Ofcom imposed a £600,000 penalty for that failure, and a further £30,000 for failing to respond to a legally binding information request on time, for a total of £630,000 (Ofcom, 9 July 2026).

The line in the decision that matters most is almost a throwaway. “Since Ofcom instigated formal enforcement action against this provider, it has ‘geoblocked’ access from UK IP addresses, meaning it is no longer directly available to people in the UK. We will continue to monitor the site for compliance.” Read that again with an operator’s eye. The block came after enforcement started. It did not stop the fine, it did not close the file, and it did not end the monitoring. George Lusty, Ofcom’s Director of Enforcement, put the posture plainly: “Age checks are no longer optional for porn sites in the UK,” and providers who fail to answer the regulator accurately and on time “should expect to face enforcement action, including fines.”

This is not a one-off. Ofcom fined Youngtek Solutions £500,000 for the same age-check failure plus £100,000 for an information-request failure, and fined AVS Group £1,000,000 with a £1,000-per-day continuing penalty until it deployed a compliant check. Coverage of the Fapello decision noted the same escalation mechanic sitting behind it, a daily penalty for ongoing non-compliance rather than a single closed number (Biometric Update). The pattern across every one of these is that the penalty attaches to a period of exposure, and the daily rate exists precisely so that walking away slowly, or walking away late, does not run out the clock.

Exit is forward-looking. Liability is backward-looking.

Here is the mismatch at the centre of the “we’ll just block the country” plan. A geoblock changes what happens from the moment you deploy it. A fine measures what happened before you did. Those are two different time horizons, and the second one is the one that costs money.

Think about what a regulator is actually pricing. The harm the age-assurance duty exists to prevent is a child reaching adult content. Every day the site was live in the UK without a highly effective check was a day that harm was possible. Blocking UK traffic on, say, the first of a month does nothing about the previous eight months of open access. The liability for those eight months already exists. It sat there accruing the entire time the site was reachable, and the block does not reach back and erase it. You cannot geoblock the past.

This is why the market-exit math so many operators are running is wrong in a specific, expensive way. The block is cheap, that part is true. It is a CDN rule and an afternoon. But the people reaching for it tend to reach for it late, after a mandate has been in force for a while, often after a regulator has already opened a file. By then the cheap move buys nothing except an end to future exposure, and future exposure was never the part that was going to generate the biggest bill. Fapello’s block was real and it was too late to matter to the £630,000.

The £30,000 is the part operators keep misreading

Split the fine and look at the smaller number, because it carries a lesson the larger one hides. Six hundred thousand was for the missing age check. Thirty thousand was for not answering Ofcom’s information request on time. Those are separate duties, and the second one has nothing to do with age assurance at all. It is an evidence duty, and it runs in parallel with the gate.

We have made this point before in the context of Ofcom’s broader move toward treating compliance as an evidence problem, and Fapello is a clean illustration of why it bites even harder for a company that intends to leave. The reasoning inside a lot of operators is that once the decision to exit is made, the investigation is somebody else’s problem, so the information requests can be ignored. That is exactly the mistake the £30,000 punishes. While you are still under investigation you owe accurate, timely answers regardless of what you plan to do with the market next month. Silence is its own offense, priced separately, and it is a strikingly easy one to trigger by simply going quiet once you have decided to walk.

There is a structural point underneath this. The reason regulators can fine a company that has already left is that the whole enforcement regime is built on records, not on your current market presence. Ofcom does not need you to be live to establish that you were non-compliant during a defined window; it needs the evidence of that window. Which means the platforms most exposed are the ones that ran an age gate they could not prove was working, or ran none and kept no account of it. The self-declared birthday that fell over in the Reddit and ICO episode is the archetype: not just an inadequate check, but one that leaves nothing behind to defend.

The escape hatch is closing in more than one jurisdiction

It would be comforting to file this under UK-specific aggressiveness and move on. It is not UK-specific. The design principle, that a duty attaches to the fact you served a market rather than to whether you serve it today, shows up wherever online-safety enforcement has teeth.

In the United States the state laws increasingly carry per-day statutory penalties, which is the same instrument as Ofcom’s daily rate, aimed at the same behaviour: a company that complies slowly, or leaves slowly, still racks up a number for each day it was out of compliance. We walked through how that penalty structure changes the risk calculus and why the content-threshold games that used to keep general-audience platforms out of scope are collapsing. The EU’s regime works the same way at the level of designation. The common thread is that none of these frameworks reward you for having exited after the fact. They reward, or rather stop punishing, only the operators who were compliant during the window that is under review. A year into Ofcom’s enforcement programme, the enforcement data shows a regulator that treats leaving as a signal of guilt to be documented, not a resolution, which is exactly what the Fapello monitoring language confirms.

Rerun the build-versus-exit math with the tail in it

Put the retroactive liability back into the comparison and the build-versus-exit decision looks different from the one most teams model. The exit case is usually built on two numbers that are both wrong. The cost of a compliant check is overestimated, because people price it as a custom build with an in-house identity stack. The cost of leaving is underestimated, because people price only the lost revenue from users they were not monetising well, and leave out the fine for the period they were live.

Both errors are fixable, and fixing them tends to flip the answer. On the first, the reason verification looks expensive is that operators conflate two very different operations and price the whole thing at the rate of the expensive one. A document Verification, an ID read plus a face match, is genuinely costly and genuinely heavy on the user, and if you force it on everyone your funnel bleeds, which is the real story behind most age-check drop-off. But most of what a children’s-safety gate needs is not a document. It is a fast, cheap age signal at the point of access, an order of magnitude below a document scan, and reserving the heavy check for the narrow set of cases that actually need it is what makes the economics work. The full build-versus-buy breakdown is where those numbers live, and the short version is that the compliant path is a lot closer to the geoblock’s cost than the exit deck assumes.

On the second error, the fine is not a tail risk you can wave off as unlikely. Ofcom has opened dozens of investigations and is publishing the fines on a rhythm. If you are a pornography provider with meaningful UK traffic and no highly effective check, the base rate of a penalty is not low, and the penalty is sized to the exposure window, not to a flat statutory minimum. Once that number is in the spreadsheet at its real magnitude, the afternoon-long CDN rule stops looking free.

What Xident does here, and what it does not

We are precise about this boundary because a vendor that oversells it does real damage. Xident provides the two operations the duty actually calls for and keeps them separate. A Check is the cheap, fast path: a browser-based age signal, a liveness pass, a returning-user lookup, the thing you put at the point of access to satisfy a children’s-safety gate without wrecking conversion. A Verification is the heavy path, a document read and face match, reserved for the cases that genuinely need identity rather than an age signal. Each comes back as a structured decision with an audit trail, which is not incidental to this story. The audit trail is the exact artefact that the £30,000 half of the Fapello fine was about. It is what lets you answer an information request accurately and on time, and what lets you prove a gate was working during a window a regulator later asks about, rather than asserting it.

We are equally deliberate about retention, because the wrong way to build this is to become the next incident. A structured decision plus an audit trail is what you keep. The passport scan is not. Discard the source document once the check resolves, and for returning users lean on a reusable, cryptographically bound credential so a verified person re-proves with a lookup instead of a fresh upload. That discipline is the whole reason the breach wave that hit age-verification vendors this year was a retention failure rather than an unavoidable cost of verifying, and it is the difference between a system that answers the regulator and one that becomes the headline. If you want the standard the check itself has to clear, we wrote up how to measure and prove highly effective age assurance rather than assert it.

What Xident does not do is decide whether you are in scope, in which markets, or whether exiting one of them makes sense for your business. That is a legal and commercial judgment, and it belongs with counsel who can read your traffic and your obligations against the current law. We also cannot make a past non-compliance window disappear. Nobody can. A vendor who implies otherwise is selling the same comfort the late geoblock sold Fapello, and it is worth exactly as much.

The Fapello decision is small in pounds and large in what it settles. Leaving a market does not resolve a liability you have already earned; it only stops adding to it, and often it stops too late to matter. The block is a forward tool. The fine is a backward bill. The only move that was ever genuinely cheaper than the penalty was the one nobody reaches for once a regulator is already at the door: verifying before the window opened, and keeping the proof that you did.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo