Frequently Asked Questions
The Basics
Blank - do not use
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
What is age assurance and why is it needed?
Age assurance is the umbrella term for the technologies used to check whether someone is old enough, or young enough, to buy a product, use a service or see certain content. There are three main approaches:
- Age verification confirms your date of birth against an authoritative source, such as an identity document, your bank or the electoral roll.
- Age estimation calculates your approximate age from characteristics such as your facial features or voice, without learning who you are.
- Age inference draws a conclusion from facts already established about you, for example that you hold a mortgage, so you cannot be a child.
Each solution delivers a different level of confidence, and regulators decide the level required for each situation. Society has traditionally required those who sell certain products, services and content to restrict by age. In the early days of the internet, these laws were not imposed online. Age assurance is closing the gap between the real and virtual world.
Do I always have to upload my ID or scan my face?
No. Neither is the default, and no well-designed regulation mandates a single method. Users should always be offered a choice, which typically includes facial age estimation, identity documents, open banking, a mobile operator check, a credit reference check, a reusable digital identity app or inference from the transactions for which email addresses or mobile numbers have been used. Facial age estimation is optional and momentary, and document routes are one option among several. If one route does not work for you or you are not comfortable with it, another should be available. The claim that age assurance always means uploading a passport to the platform you wish to access does not describe the privacy preserving systems offered by third-party age verification providers.
Is age assurance the same as digital ID?
No. Digital identity proves who you are. Age assurance proves one fact about you, that you are over (or under) an age threshold, and the systems offered by our members prove that fact without identifying to the services you are accessing at all. Some people may choose a digital identity wallet as a convenient way selectively to share an age proof, but that is one option, not generally a requirement. Laws requiring age checks are not laws requiring digital ID, and conflating the two is one of the most common category errors in this debate.
Why are some privacy and civil liberties groups worried about age assurance?
Opponents of online age assurance raise five main risks:
- Adults being forced to identify themselves to browse lawful content;
- children being excluded from legitimate services;
- sensitive data being retained and then breached;
- age checks expanding beyond their original purpose; and
- weak or biased systems making unfair decisions.
These are only risks if age assurance is badly designed and poorly regulated. They are also precisely why the AVPA supports privacy-preserving, independently certified, data minimising systems with a choice of methods, no unnecessary retention of personal data, accessible appeal routes and stronger regulatory oversight. See below for responses to each of these objections and explanations of what good design, certification and regulation do about it. Where a poor deployment falls short, we warn about the risk that creates.
Technology
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
What is interoperability, and why is it such a priority for the AV industry?
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
What methods of age verification are available?
Age verification checks can be completed using passports, driving licences, online banking, through credit reference agencies or with a digital ID app on your mobile phone account; innovative new technology can estimate your age from a selfie using artificial intelligence, with the image immediately deleted after the check.
Credit card
Generally, only adults in the UK possess credit cards; an individual can use their card to confirm they are over 18 using standard a payment process. This doesn’t reveal their identity to the verification provider – just the fact that they have been issued a card. All the card schemes’ privacy and security measures apply.
Mobile phone
UK mobile operators issue SIM cards with access to adult content blocked by default, and only remove that block once the user proves their age. Online age checks can therefore be made by reference to a user’s mobile number. Mobile network operators also follow Know Your Customer (KYC) processes for those who pay monthly and/or get a handset on credit. So for the primary account holder, the records from that check can be used to confirm age.
Email inference
Based on when and where a user has provided their email address, their age-range can be inferred e.g. not many childen lease a car or take out a mortgage
Facial estimation
By using machine learning techniques, a user’s image is compared to a database of photos of people who’ve volunteered to prove their age, and an estimate within 1-2 years of the real age is generated – typically the test is set a few years above 18, so that the margin for error is so small regulators accept it e.g. under ½% (Other similar biometric techniques are also under development e.g. using voiceprint analysis).
Hand movement estimation
By analysing the way a user moves their fingers on their webcam, age-range can be estimated.
EKG/ECG analysis
Drawing on historic heartbeat data held by smartphone health apps connected to watches and other monitoring devices, age can be estimated.
ID documents
Passports, Driving Licences or PASS cards can be used – again the level of check can range from showing the document via a video call, to reading the near-field communication chip embedded in modern forms of ID, and comparing the photo encrypted within that to a live selfie.
Database checks
Electoral roll or credit reference agency records can be checked against data supplied by the user. Confirming the user is the owner of that record is more complex – but can be done the way credit score services do this, for example, by asking about several recent transactions or other information likely to be known only to the user.
Digital ID apps
If you have set up a digital ID on an app on your smartphone, you will be able to give consent to the app confirming you meet a particular age-restriction. When acting as an age verification method, only the answer as to whether you qualify based on your age will be shared with the website, as a simple "yes" or "no" - other aspects of your identity such as your name or address, will not be shared unless you give further consent.
Online banking
The creation of a system of "open banking" allows AV providers to get you to log into your bank, just as you do for online banking, and then they can ask the bank to confirm your date of birth.
Privacy, anonymity and your data
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
Can I stay anonymous online after an age check?
Yes, in a well-designed system and this is the essence of age assurance. Age is not identity, and the check is built on separation: the website that needs the check does not perform it, and the independent provider that performs it returns only a yes or no answer, such as "over 18: yes". The website never sees your name, document or date of birth. Where a “double-blind” approach is offered, then the provider does not learn what you go on to do.
Adults can continue to browse, read and speak anonymously after an age check, just as showing ID at a nightclub door does not mean the bartender records every drink you order against your name. Methods such as facial estimation and verification methods processed entirely on a user’s device (e.g. their smartphone or computer) neither capture nor share a user’s name at any stage.
What data is collected, and what is retained?
Collection should be the minimum needed to answer one question. For facial estimation that is an image processed for a few seconds. For a bank or mobile network operator check it is a yes or no answer from an institution that already knows your age.
A properly designed system does not retain the data used to perform the check once it is completed, unless, exceptionally, a clearly specified legal purpose requires limited retention. Where retention is genuinely necessary, it should be minimised, time limited, documented and independently audited. Certification checks that stated retention practices are real, and a certificate can be withdrawn if they are not. The principle behind all of this is simple: the safest data is data that is never stored, and the systems are designed so that nothing needs to be systematically retained. For age assurance providers this reduces costs of compliance and data storage, as well as the potentially fatal reputational risk from a data breach.
What about breaches reported recently?
Generally, such stories relate either to digital identity products rather than age assurance, or to legacy systems never designed to meet the standards required in the age verification sector.
In one widely quoted example, users may have had government ID photos exposed through a breach at a third-party customer service database. Images had been uploaded in connection with age related appeals and were sitting indefinitely in the general helpdesk system. The reported breach concerned the appeal workflow the website had instituted, not the core privacy preserving age assurance transaction (nor the appeals process offered by the age assurance provider itself, which would not have retained thousands of ID documents, so they could not have been stolen). The incident shows why data retention, support workflows and vendor oversight matter. It does not show that age assurance is inherently unsafe. It shows why the safest systems minimise what is collected, separate the age check from the platform, avoid unnecessary retention and are independently audited, and why appeal evidence needs the same discipline as the check itself: reviewed quickly, then deleted, not left in a general-purpose helpdesk ticketing tool. Certified age assurance is the answer to incidents like this, not their cause, and the incident is a strong argument for regulators to require the high international standards we endorse.
Nothing is unhackable. Why should I trust any of this?
That instinct is correct, and it is the assumption the age assurance industry applies in its privacy-by design approach. No system can promise perfect security forever, so well-designed age checks do not depend on defending large stores of data. They depend on not creating them in the first place. A hacker cannot steal a database that was never built.
Data in transit is protected using strong encryption, and providers’ security management is audited against standards such as ISO 27001. Where any data must be retained temporarily to process the check, it should be encrypted at rest, access controlled, time limited and audited. No one should claim invulnerability. The claim that can be made, and independently verified, is that the exposure is kept as close to zero as engineering allows, and that this is a categorically better position than the alternative, in which websites collect and keep dates of birth and ID copies themselves, while delivering the age-restrictions online which society has determined should be applied.
Will an age check create a record of the websites I visit?
Under the ‘double-blind’ model, originally demanded by the French data protection authority, CNIL, but now becoming an industry standard, the provider confirms your age without recording a user linked history of which sites requested checks, and the website learns nothing about you except that you passed the age test.
Certified providers are prohibited from building browsing profiles of users, and auditors verify this. Any operational logs kept for security or billing are de-identified aggregates.
Could criminals set up fake age check services to harvest personal data?
Phishing is a risk for every online service, including banking, and the defences here are layered. You do not have to find or judge an age assurance provider alone: the digital service you are accessing chooses which providers to integrate, and platforms carry out due diligence because their reputation depends on it. Certification bodies publish public registers of audited providers that anyone can check. Regulators can act against imposters, and emerging interoperability schemes (see below) vet every provider in their network. A fraudster can imitate a brand. They cannot get onto an official register or join a well-managed network of providers.
Facial age estimation
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
What is facial age estimation and how does it work?
Software analyses patterns in an image of your face for the few seconds needed to estimate your age, then the image is discarded. The system needs no name, no document and no date of birth, which is why, for many people, it is the most private option on the menu. It is also the option that works for people who have no ID documents at all.
Is facial age estimation the same as facial recognition?
No, and the difference matters. Facial recognition tries to identify who someone is, by matching a face against a stored template or watchlist. Facial age estimation estimates an age or age range and never asks who you are. A compliant deployment will not create or retain any identity template that would allow the system to recognise you later. It is not built to identify individuals and is not a surveillance tool. Calling it "facial recognition by another name" is inaccurate: the two technologies answer different questions and are built differently.
Is facial age estimation biometric data processing?
The legal answer can depend on how a system is implemented, and we do not claim it is never biometric processing. What matters are the safeguards:
- whether the image is processed transiently,
- whether any biometric template is created,
- whether the system is capable of subsequently identifying the person and
- whether any image or template is retained.
In implementations designed by our members, the answers are transient, no, no and no.
The UK Information Commissioner’s Office accepted that personal data is not used for the estimation process because any image is first transformed into a mathematical map of the face that is no longer sufficiently detailed to re-identify the user. Lawful deployment still requires a data protection impact assessment, transparency with users, strict minimisation and often, regulators insist there are alternative methods for anyone who prefers not to use biometrics.
How accurate is facial estimation?
A margin of error is inherent in facial age estimation – it is a feature not a fatal flaw. It is designed into how the technology is used, exactly as it is offline. Shops apply policies such as “Challenge 25” because staff cannot judge 18 precisely, anyone who looks under 25 (or sometimes an older limit) is asked for ID. Online systems use the same logic, setting a buffer above the legal age, so a user must be estimated well above the threshold to pass on estimation alone.
Independent testing by NIST, the US government’s measurement laboratory, shows the best systems estimating age with an average error of around two years, and under two years for teenagers. This technology is improving year on year. With a sensible buffer, the realistic failure case is that an adult who is estimated to be too young is asked to complete a second check, not that a child is waved through.
What about bias? Does it work equally well for everyone?
Bias risk is real and must be managed, not denied. Facial recognition systems – not estimation systems - have historically been studied and did not perform as well for some groups, including people with darker skin tones and people whose appearance is affected by a medical condition or disability. This is the result of physics – darker skin reflects less light – which is becoming less of a problem as the quality of cameras improve – and training data used to create the estimation algorithms not being sufficiently diverse.
The UK ICO expects providers to test and review accuracy across demographic groups, consider equality impacts, offer reasonable adjustments and provide accessible ways to challenge a result. NIST’s public evaluations measure differential performance openly, which is driving rapid improvement. Just as important is the system around the algorithm: buffers and thresholds are set to be cautious, and anyone the software is uncertain about is offered another method rather than being turned away. No one should be excluded simply because an estimation system is less sure about them than someone with lighter skin (or any other protected characteristic).
Can teenagers fool it with make-up, filters or AI images?
Some attacks are possible, and certified systems treat this as a robustness problem to be engineered against, not ignored. Liveness detection checks that the camera is looking at a real, present person rather than a photo, a screen replay or a mask, and is tested against international presentation attack standards. Image quality checks, limits on repeated attempts and fallback to verification for borderline results close off the casual routes. Where a document is used, a live selfie can be matched to the document photo, so a borrowed ID fails without the collusion of its owner. No control is perfect, but the tick box these systems replace was defeated by a single click.
The most common forms of circumvention reported in quantitative research is often not actually evading age assurance technology itself – it is no age check at all or self-declaration – the very approaches age assurance is intended to replace. Stories reported by teenagers to focus groups of using make-up or false beards and moustaches are anecdotal evidence as these claims do not feature in quantitative analysis. No technology is perfect, and there may be a limited number of cases where this has worked, but our members’ solutions are designed not to be fooled so easily, and certification procedures test for resistance to such presentation attacks.
When the system gets it wrong
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
What happens if I am wrongly assessed as underage?
You should be offered another method immediately. A good age assurance journey never makes facial estimation, a credit check or any single method the only route. It provides alternatives on the spot and offers alternative methods or a route to appeal the decision. This is not a courtesy: fairness of exactly this kind is one of the criteria regulators such as Ofcom use to judge whether age assurance is highly effective, and regulators such as the ICO, require to be compliant with legal requirements for fairness. Certification examines the whole journey, not just the algorithm. Being wrongly assessed should cost you a minute to use a different method, not your access.
What about people without passports, driving licences, bank accounts or stable homes?
This is one of the strongest arguments for the current generation of technology. If age checks meant ID documents only, millions of adults would be excluded. They do not. Facial age estimation requires no documents, no bank account and no credit history, and inference methods work from things people already have, such as a long-standing phone number or email address. A choice of methods is an inclusion measure, and regulators increasingly require it. Where an individual still cannot pass any automated route, platforms should offer a solution such as professional attestation where a doctor, teacher etc. gives a reference confirming the user’s age.
Does it actually work?
Do age checks actually work?
The evidence says yes, at scale. Australia’s Age Assurance Technology Trial, the largest independent evaluation yet conducted, tested solutions from 48 providers and concluded that age assurance can be done privately, robustly and effectively, that there were no substantial technological limitations preventing implementation and that no single solution fits every context, which is why choice of method matters.
- In the UK, since it was first required in August 2025, the vast majority of the most visited adult sites now operate age assurance for UK users (80% of the top 100 sites).
- In Australia, almost five million under 16 social media accounts were deactivated or restricted within months of the minimum age law taking effect – but there is more to do as the platforms have resisted challenging users whose ages may have been inflated when they opened their account (and 9 in 10 platforms in scope for the law were still not checking age for new accounts when this was tested in May 2026).
The measure of success is a substantial reduction in children’s exposure, and that is what the data shows even where digital services have been reluctant to implement regulations.
Didn’t age assurance fail in Australia?
No, and the claim deserves a precise answer because it is now common in litigation and lobbying. The trial findings above still stand and has not been retracted. Since the law took effect in December 2025, millions of underage accounts have been removed. Where children kept or regained access, the regulator’s compliance reviews traced this mainly to implementation choices by platforms, such as allowing unlimited retries of age checks or letting users simply correct their declared age, rather than to the underlying technology. The response has been tightening enforcement, including a proposal to double maximum fines and giving the regulator powers to inspect the systems put in place to determine if they constitute reasonable steps to deliver the legal objective.
No safety measure eliminates a harm completely, and that has never been the test. Seat belts do not prevent every road death, yet no one calls them a failure. Bars sometimes serve underage drinkers but minimum ages for buying alcohol are not abandoned. Some deployments were poor, and the regulator is dealing with them. That is regulation working, not technology failing.
Won’t children just use VPNs, borrowed IDs or fake accounts?
Some older teenagers will try, just as some use fake IDs in shops, and no one concludes from fake IDs that shops should stop checking. Determined circumvention takes deliberate effort, and that effort is the point. Age checks are most protective against the vast majority of exposure, which is casual and unlooked for: content served into a feed or reached in one click which children then stumble across. That path closes. A teenager who configures a VPN to evade a check knows they are breaking a rule, which is a very different situation from a ten-year-old inadvertently being exposed to pornography, and one parents are far better placed to supervise.
Borrowed IDs and photo spoofing are countered by liveness detection and selfie matching, as described above, and regulators can require platforms not to facilitate or profit from circumvention by, for example, promoting VPNs.
Is asking for a date of birth, plus the platform’s own signals, enough?
Most regulations require a degree of age assurance proportionate to the risk. A tick box or date of birth field is not age assurance: Ofcom’s guidance says expressly that self-declaration alone does not count, and that a highly effective process must be technically accurate, robust, reliable and fair. Layering weak internal signals on top of self-declaration does not automatically make it highly effective either.
A lawful process should be able to demonstrate, with evidence from real deployment, that it meets those four criteria. This matters because some platforms present self-declaration with ‘heuristics’ (age inference from user-generated content and behaviour) as equivalent to certified age assurance. It is not, and regulators generally do not accept it as such.
Is age inference just behavioural profiling by another name?
It should not be, and the distinction is worth drawing sharply. Age inference is strongest and least intrusive when it rests on verifiable facts already established for another legitimate purpose: an account that holds a mortgage, a payment instrument that requires adulthood, a trusted attribute, such as a commercial pilot’s licence from a digital wallet. It is weaker and more intrusive when it relies on opaque behavioural profiling of what users watch, type or click. The AVPA supports clear limits: inference should be explainable, proportionate, tested and privacy preserving, and should not be used to justify tracking that would not otherwise happen.
Rights and society
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
Does age assurance censor the internet?
No content is removed or banned by an age check. Adults retain access to everything they could lawfully see before, after a check that takes seconds, exactly as an adult can buy any legal product after showing ID at a till. In 2025, the US Supreme Court upheld age verification requirements for pornography, and arguably content harmful to minors more broadly, on the basis that they impose only an incidental burden on adults. Age assurance is also narrower than the alternatives usually proposed when it is absent, such as banning services outright or filtering content for everyone. It applies the offline settlement society reached long ago to the online world, while leaving adults’ choices untouched.
Could age assurance expand into a general permission system for the internet?
It should not, and the AVPA does not support that outcome. Age assurance should be limited to defined age restricted risks, with clear legal authority, proportionality, data minimisation and independent oversight. We do not support general purpose identity checks for ordinary internet use. The point of age assurance is to prove a narrow attribute, not to create a general licence to browse, speak or read online, and the technologies described in this FAQ are deliberately built so they cannot serve as identity infrastructure: they carry no identity data. Mission creep is a policy choice, not a property of the technology, and it is one legislators can and should rule out in the laws they write. Liberal democracies will not find it any easier to introduce ID checks because age assurance is already in place (unless those who oppose ID checks continue to conflate them with age checks and persuade the public that ID checks are already in place) and totalitarian regimes tend not to be restrained in any case.
Could it harm LGBTQI+ users, vulnerable users or young people seeking help?
These concerns deserve direct answers, because for someone not yet out in a hostile household, school, workplace, town, region or country, the fear of being identified is real. The best protection lies in double-blind architecture: the website never learns who you are and a certified provider keeps no user linked record of which sites requested checks, so an age check cannot out anyone. Methods that need no ID serve people who cannot safely use official documents.
On young people seeking help: age assurance laws target specific age restricted content and services. They generally do not apply to helplines, sexual health information, counselling or education, and nothing in the technology requires that they should. Where platforms carry both restricted content and support content, well-written regulation rightly pushes them to gate the former, not the latter.
Don’t children have rights to information and participation online?
Yes, and age assurance done properly serves those rights rather than undermining them. Age assurance should be used to restrict access to content and services that are genuinely age restricted or harmful to children, not to block children from information, advice, support, education or participation. Where a service contains both restricted and beneficial content, the correct answer is proportionate design, not crude exclusion.
Knowing that a user is a child also enables age-appropriate experiences, stronger default protections and freedom from adult targeting, which is what frameworks such the UK’s Children’s Code, requires. If a deployment ever locks children out of help or education, that is an implementation failure to be corrected, and regulators should treat it as such. Every country in the world with the one exception of the United States, has signed the UN Convention on the Rights of the Child. Even in the USA, their own constitution sets out rights that apply to all citizens, not only adults. So, there are legal protections against the abuse or over-interpretation of regulation in ways that is itself harmful to the interests of children.
Isn’t keeping children safe online their parents’ responsibility?
Parents and legal guardians have an important role, and age assurance is a tool that finally makes it feasible to exercise that role effectively.
Society has never applied "it’s the parents’ job" to age restricted goods anywhere else. We do not let off licences sell vodka to twelve-year-olds and blame the parents. Offline, the seller checks. Online, until recently, nobody checked, and parents were left to supervise a global internet single-handed, perhaps across dozens or hundreds of platforms, games and websites. Age assurance does not replace parents. It gives them the same backup online that the law has always given them on the high street.
Many websites are based abroad. How can these laws be enforced?
The same way other internet laws are enforced: against the service, not the office address. Regulators can fine companies that serve their residents wherever the company sits, and where lawmakers have anticipated this challenge, escalate by requiring payment providers and advertisers to withdraw services, or ultimately having access blocked. In practice, most major regulated services are likely to comply rather than lose a market. Enforcement is also getting easier as jurisdictions converge: with the UK, the EU, Australia and a growing list of US states all requiring age assurance, compliance is becoming the global default, and there is already extensive cooperation between regulators.
Trust, standards and what good regulation looks like
Blank - do not use
euCONSENT was a European Commission funded project to create an interoperable network of AV providers. It began a pilot of its technology in February 2022 with over 1,600 participants across 5 countries which successfully proved the concept of interoperability, modelled on the EUs eIDAS 1.0 architecture. It has now been updated to reflect the eIDAS 2.0 Wallet approach by a non-profit organisation established by the original project team, and has built AgeAware, a tokenized, double-blind solution. This will allow you to prove your age once with an AV provider and then re-use that same check many times over with other websites, even if they use a different AV provider.
So, if today you buy a bottle of wine as part of your supermarket order and are asked to prove your age, tomorrow, you will not need to repeat that process to access a pornographic website.
How are providers tested, audited and certified?
Independent, government accredited certification bodies test providers’ claims rather than taking them on trust. Auditors examine accuracy, security, privacy and retention practices against published standards, including whether data really is deleted when the provider says it is. Certification must be renewed periodically, complaints are investigated and certificates can be withdrawn. Certified providers appear on public registers, so websites, regulators, journalists and consumers can all check who has passed. When we describe what a well-designed system does, certification is what turns that description from a promise into a verifiable property.
What standards apply to age assurance?
The ISO/IEC 27566 series establish a global framework for age assurance systems, building on the pioneering BSI PAS 1296:2018. IEEE 2089.1, approved in 2024, defines standardised levels of age assurance to support consistent regulation and interoperability worldwide. Liveness and spoofing defences are tested against the ISO 30107 presentation attack standards, information security is managed under ISO 27001 and data protection law, such as the GDPR, applies on top of all of it.
Why not make app stores or devices do all age checks instead?
Device level and app-store approaches can help in some contexts, especially where a user wants a reusable age proof set up once, and several US states are legislating in this direction. But they are not a complete substitute for service level accountability. Many risks arise inside websites, apps and accounts after installation, on shared or second-hand devices, and on the open web that app stores never touch. A good system allows privacy preserving reuse of age proofs, whether from a device, a wallet or a provider for lower risk use-cases, while keeping clear duties on the service that create or distribute higher risks. The two models are complements, not rivals, serving different use-cases.
What should platforms, regulators and legislators require?
The AVPA’s position is that good age assurance regulation should require:
- A choice of methods, so no one is forced to use ID or any single technique
- Data minimisation, collecting only what the check requires
- No unnecessary retention, with any legally required retention still minimised, time limited, documented and audited
- Independent testing and certification against published standards
- Fairness testing across demographic groups, with results published where possible
- Accessibility so everyone can prove their age-range one way or another and therefore inclusive so no protected characteristic leads to exclusion
- Clear alternative methods or appeal routes when a check is wrong
- Anti-circumvention controls, including limits on retries and spoofing defences
- Interoperability and reusable proofs, so users check once and reuse the result
- Clear accountability for both the relying platform and the age assurance provider
Regulation built on this checklist answers criticisms of age assurance by design, and gives authorities a concrete benchmark against which any deployment can be judged.
Jurisdiction guides
United Kingdom: What does the law require?
Under the Online Safety Act, services that allow pornography have had to use highly effective age assurance since July 2025, and platforms likely to be accessed by children must protect them from other harmful content. Ofcom is the regulator. Its guidance names approved approaches including facial age estimation, open banking, ID matching and mobile operator checks, sets the four criteria of technical accuracy, robustness, reliability and fairness, and states that self-declaration alone is not age assurance.
United Kingdom: Is it being enforced?
Yes, actively. Ofcom has opened dozens of investigations and issued its first fines against non compliant sites, and the large majority of the most visited adult services now operate age assurance for UK users. Ofcom and the Information Commissioner’s Office have jointly confirmed that age assurance can and must be delivered in a privacy preserving way, and are reporting publicly on its effectiveness. They have also extended the requirement for highly effective age assurance to the enforcement of 13 as the minimum age often specified in a site’s terms and conditions, and under Article 8 of GDPR which requires parental consent before a young child can give permission for their personal data to be processed.
United Kingdom: What about age restricted goods, such as alcohol and knives?
Online retail has its own rules. Deliveries of bladed articles must be verified as being handed to an adult under the Offensive Weapons Act, and alcohol retailers must operate age verification under licensing law.
European Union: What does the law require?
The Digital Services Act requires platforms to protect minors, and the European Commission’s guidelines identify age assurance as a key measure for services carrying adult content and other age restricted risks. Before the DSA, GDPR and the AVMSD also created age-restrictions but enforcement was limited. Several member states, including France, have additionally legislated for mandatory age verification for pornography at national level and recently the Court of Justice of the EU enabled such states to enforce their own laws against services established elsewhere in the EU.
European Union: What is the EU age verification app or “mini wallet”?
The Commission has published a white label age verification solution, feature complete since April 2026, that member states can adopt directly or integrate into national apps. It lets users prove they are over 18 without revealing anything else, and is built on almost the same specifications as the European Digital Identity Wallet being rolled out across all member states, with front runner countries including France, Denmark, Greece, Italy and Spain deploying it first. It is a working model of the approach this FAQ describes: the proof sits on the user’s device, and no central database is involved. It is not a legal requirement to use this app, and some users may prefer not to use a government-controlled solution in all situations.
United States: Is age verification constitutional?
The Supreme Court answered this in June 2025 in the Free Speech Coalition v Paxton case, upholding Texas’s age verification law for pornographic websites. The Court held that requiring proof of age to access material that is obscene to minors is consistent with the First Amendment. The ruling is specific to content harmful to minors rather than a blank cheque for all age gating, but claims that age verification laws are inherently unconstitutional no longer reflect the law of the land.
United States: How widespread are these laws?
More than 20 states now require age verification for sites with significant adult content, and the legislative trend is expanding to app stores, with states including Utah and Texas requiring app stores to verify ages and obtain parental consent for minors’ downloads. Federal proposals build on the same principles.
Australia: What does the law require?
The Online Safety Amendment (Social Media Minimum Age) Act requires major social media platforms to take reasonable steps to prevent under 16s from holding accounts, effective December 2025. Separate industry codes require age assurance for pornography and other high risk services. The eSafety Commissioner enforces the regime, with penalties for platforms, not for children or parents.
Australia: What has happened since it took effect?
Nearly five million under 16 accounts have been deactivated or restricted. The government’s independent Age Assurance Technology Trial, which evaluated 48 providers before commencement, found age assurance can be done privately, robustly and effectively. Compliance reviews have focused on platforms whose implementations were too easy to retry or bypass, and the government has moved to double maximum penalties.
About the AVPA
Who are the AVPA and what do we stand for?
The Age Verification Providers Association is the global trade body for the age assurance industry. Our members provide age checks to platforms, retailers and regulators around the world and commit to a code of conduct built on privacy by design, data minimisation and independent certification. We stand for the position set out across these FAQs: that children deserve the same protection online as offline, that adults’ privacy and anonymity must survive the process intact, that claims made by providers should be independently audited rather than taken on trust and that the alternative to regulated age assurance is not a freer internet but self-declaration, platform profiling and unmanaged ID retention, which serve no one.