Governments and regulated businesses are replacing self-declared birthdays with systems that estimate, verify and continually assess whether a person belongs on the other side of an age limit.
A fourteen-year-old opens a social media app. The account already lists the user as fourteen. The platform still offers a facial age check and the camera returns an estimate of sixteen. The account remains active. The technology did exactly what it was asked to do. It returned a number. What failed was the process around it, which let a single new result override stronger evidence the platform already held.
Australia’s eSafety Commissioner has flagged cases like this as evidence of a deeper problem. Platforms have held stronger evidence that a user is under sixteen, yet let a new result override it, or let children retry the same check until it returns a passing score.
That distinction now matters across social media, adult content, gambling, alcohol sales and gaming. Age assurance is becoming part of the infrastructure that determines who can open an account, access a service, or buy a product.
The most common online age check still asks users to enter a date of birth. The person being restricted supplies that evidence themselves. A child only needs to change the year.
The case for something sturdier has grown harder to ignore. Research from the Children’s Commissioner for England found that 70 percent of surveyed 16- to 21-year-olds had seen online pornography before turning eighteen, at an average first exposure age of thirteen. Fifty-nine percent said their first encounter was accidental, mostly via social media.
Age assurance is the umbrella term for methods that establish or estimate whether someone meets an age requirement. It generally splits into three approaches. Estimation predicts a likely age from physical or behavioral traits. Facial analysis is the most established form, returning a number, a range, or a ‘Yes or No’ against a threshold. Verification starts from known evidence, such as an identity document or a digital identity wallet, and can return just ‘over eighteen’ rather than a full birth date. Inference works from context, drawing on school enrollment, payment history or account activity that supports a conclusion without either of the above.
Regulators increasingly expect these to be chained rather than used alone. The UK’s Information Commissioner’s Office calls this a “waterfall” approach, where each method filters out the clear cases and passes only the uncertain ones down to the next, more demanding check. With a seven-year buffer against an eighteen-plus threshold, for example, anyone estimated at twenty-five or older passes without further checks, while anyone estimated younger is routed to a secondary check, such as an identity document.

Australia moved first and went furthest. Its social media minimum-age law took effect on 10 December 2025, requiring platforms to keep Australians under sixteen off their services. Platforms reported removing or restricting roughly 4.7 million accounts in the weeks after, with more than 300,000 further accounts blocked by early March 2026. But eSafety’s own compliance review found platforms letting children retry age checks until they passed, and many under-16s still holding accounts.
The EU and Brazil are moving on similar lines. The European Commission built its own age verification app and is urging member states to roll it out by the end of 2026 under the Digital Services Act, while already investigating Meta and Snapchat over how they screen younger users. Brazil’s Digital ECA, in force since March 2026, bans simple self-declaration outright and requires reliable verification for both social media and adult content, backed by fines of up to R$50 million a violation.
Asia is enforcing at scale too. Indonesia’s under-16 rules pushed TikTok to shut down 4.1 million local accounts and YouTube 600,000, and Malaysia followed in June 2026 with its own verification mandate backed by fines of up to RM10 million. Gabon has done the same in Africa, setting a digital age of majority of 16 with a year to reach compliance, while Kenya, Nigeria and South Africa are still at the consultation stage
In the UK, Ofcom recorded more than 69 million age checks across 32 services between July and December 2025, 23 times the volume of the prior six months. That surge followed the Online Safety Act making ‘highly effective’ checks mandatory for pornography sites. All ten of the UK’s most-visited adult sites now have checks in place. Even so, of the small share of children who went looking for pornography, about half still reached a site with no checks at all.
Gambling adds a further wrinkle. UK operators must verify a customer’s name, address and date of birth before they can bet, because the risk isn’t just a minor signing up. It’s a minor gambling on a parent’s already-verified account. The Gambling Commission’s 2025 research found young people doing just that, with and without permission.
Alcohol sales bring the question to the counter. England and Wales laid legislation in June 2026 to let registered digital verification services stand in for a physical ID at the till, with the change expected to take effect this autumn. Proving you’re old enough will soon no longer mean handing over a passport.
Gaming is catching up too. In April 2026, eSafety issued legally enforceable notices to Roblox, Minecraft, Fortnite and Steam, requiring the platforms to explain their child safety systems or face fines of up to A$825,000 a day.
Facial estimation appeals to services because it avoids collecting a name or document. It fits the moment an anonymous visitor “walks” into a website to buy something, someone with no account and no history to check against, so a fresh estimate from a selfie is the only signal available. A loyal customer is a different case. Once that person’s age has already been verified once, the service can match their face against that verified record instead of estimating it all over again.
Companies such as Innovatrics build this waterfall logic directly into their age estimation solution. A selfie-based estimate comes first, with identity documents required only when the result falls near the legal threshold. The routing decision is what counts here, not whether the estimated age gets treated as fact.
Average accuracy doesn’t tell an operator how many minors will slip through or how many adults will be wrongly challenged at a given threshold. That’s a policy choice, not just an engineering one. NIST’s Face Analysis Technology Evaluation for Age Estimation and Verification tests exactly this. In Innovatrics’ May 2026 submission, the company ranked second in the Demographics aggregate, a consistency measure across twelve groups spanning six geographic regions of birth and two sexes, and second in Challenge 25, which tests routing accuracy near an age boundary. Averaging its position across those two tables put it first among 23 vendors and 42 submissions in that combined view.
A service that only needs to know someone is over eighteen rarely needs to keep a passport copy or a facial image indefinitely. The ICO says organizations should collect only what a decision requires, avoid reusing it for anything else, and tell users how to challenge a wrong result.
A privacy-conscious flow can process a selfie, return a pass or fail, and delete the image. Liveness detection matters here. Ofcom found some services had rolled out facial estimation without it, leaving them open to a photo or a screen replay standing in for a real person. Minimal data doesn’t have to mean weaker security. It means collecting less and protecting what’s collected more carefully.
Most age checks are framed as a single access event. They can take the form of a new visitor, a new account, one estimate, or one document. A child enrolled in an identity or public-service program at six may look nothing like themselves at fifteen, and a system has to tell the difference between growing up and a genuine identity mismatch
That’s a face-matching problem, not an estimation problem, and it has to hold up over years, not just sessions. India’s UIDAI tested this directly, matching biometric samples from children enrolled between ages five and ten against samples taken more than five years later. In essence, it is a harder version of the same task a retailer or platform faces with a loyal customer. Innovatrics placed first specifically on face-match accuracy in that test, recording the lowest false-match rate of any submission.
The distinction matters for how a system is built. A new, anonymous visitor gets estimation or verification. A known, returning one gets matched against their existing record. Getting this right means fewer repeat checks for genuine users, and no gap for someone trying to reuse an account that isn’t theirs.

No single technology will carry age assurance on its own. Estimation offers a low-friction first look, verification supplies stronger evidence, inference catches conflicts that build up over time, and long-term biometric matching keeps an identity tied to the right person as they age.
What matters isn’t whether a system can produce an age. It’s whether the service understands what that number means, knows when to question it, and can act on it without collecting more than the decision requires.
For a business, that becomes a design choice, not a compliance checkbox. A gambling operator confirming a bet, an alcohol retailer at the till and a social platform screening new sign-ups are all answering the same underlying question, but the transaction, the jurisdiction and the user in front of them call for different amounts of proof. The right approach picks the level of evidence each case actually needs, no more, while collecting as little personal data as the decision allows. Add too much friction and users leave or look for a workaround. Add too little evidence and the check becomes theatre rather than protection
The birthday box asked users to make a claim. Age assurance asks services to earn confidence in the answer.
Explore Our Age Estimation Solution