Age verification online, explained: how it works and where it falls short
As the UK, Australia and a growing list of US states require platforms to check users’ ages, here’s a plain-language look at the main methods and the trade-offs they carry.
Why you’re suddenly being asked your age
A wave of laws now requires online services to confirm how old their users are before granting access to certain content or features. The UK’s Online Safety Act brought in age checks for high-risk services in 2025; Australia introduced an under-16 social media ban; the EU’s Digital Services Act imposes age-assurance duties; and several US states have passed their own rules. The umbrella term for this is “age assurance” — a legal requirement that a service confirm a user meets a minimum age, without dictating exactly how.

Thanks — you're subscribed.
Check your inbox to confirm.
The main methods
- Self-declaration. The oldest and weakest approach: you tick a box or enter a birth date. It’s frictionless but trivially easy to bypass, which is why regulators increasingly consider it insufficient on its own for higher-risk services.
- Document (ID) verification. You upload a government ID, and software checks its authenticity, often extracting the date of birth and comparing a selfie against the ID photo. It’s robust but requires handing over sensitive identity documents.
- Facial age estimation. You take a quick selfie and an algorithm estimates your age range from facial features, usually paired with a “liveness” check to confirm you’re a real person and not a photo. It doesn’t identify who you are and needs no ID upload, which is why many parents prefer it — but it estimates rather than proves age.
- Third-party and inference methods. Some systems confirm age via a linked account, a payment credential, or by analyzing account history and behavior, returning only a pass/fail signal to the platform.
How facial age estimation actually works
Because facial age estimation is spreading fastest, it’s worth understanding. The system captures a selfie, analyzes facial characteristics that correlate with age, and returns an estimated age band — enough to decide whether you clear a threshold such as 16 or 18. Importantly, it is not the same as facial recognition: it’s designed to estimate age, not to identify a specific individual. If the estimate isn’t confident enough, well-designed systems fall back to a stronger method such as an ID check.
Where it falls short
- Privacy and surveillance. Digital rights groups warn that mandatory checks nudge every user toward some form of identity or biometric verification. In fuller ID-verification setups, a third-party vendor may retain certain records for a period to document compliance, which expands how much sensitive data is collected and stored.
- Accuracy and fairness. Age-estimation algorithms don’t perform equally for everyone. Research has found they can be less accurate for people from some racial and ethnic backgrounds, sometimes misclassifying adults as minors — echoing documented bias in facial-recognition systems.
- Workarounds. Determined users can turn to VPNs, borrowed credentials or alternative access routes. After the UK’s checks took effect, VPN interest spiked, and critics argue this both undermines the goal and pushes some users toward less-regulated corners of the internet.
- Exclusion. Every method risks shutting out legitimate users — people without government ID, or whose faces the algorithm reads poorly — raising questions of equitable access.
The bottom line
There is currently no age-check method that is simultaneously accurate, private, inclusive and hard to evade; each involves trade-offs between safety and privacy. Understanding which method a service uses — and what it does with your data — helps you make an informed choice about what you’re handing over. Many privacy advocates argue the more durable fix is strong, comprehensive data-protection law rather than age gates alone.
General information, not legal advice. Laws and platform requirements in this area are changing rapidly and vary by country and state. Compiled from reporting as of June 30, 2026.
Sources
- CNBC — Online age-verification tools spread across U.S. for child safety, but adults are being surveilled — https://www.cnbc.com/2026/03/08/social-media-child-safety-internet-ai-surveillance.html
- Electronic Frontier Foundation — 10 (Not So) Hidden Dangers of Age Verification — https://www.eff.org/deeplinks/2025/12/10-not-so-hidden-dangers-age-verification
- New America — Age assurance and age verification — https://www.newamerica.org/insights/age-verification-the-complicated-effort-to-protect-youth-online/age-assurance-and-age-verification/
- IAPP — How facial age-estimation tech can help protect children’s privacy — https://iapp.org/news/a/how-facial-age-estimation-technology-can-help-protect-childrens-privacy-for-coppa-and-beyond


