Some attacks are possible, and certified systems treat this as a robustness problem to be engineered against, not ignored. Liveness detection checks that the camera is looking at a real, present person rather than a photo, a screen replay or a mask, and is tested against international presentation attack standards. Image quality checks, limits on repeated attempts and fallback to verification for borderline results close off the casual routes. Where a document is used, a live selfie can be matched to the document photo, so a borrowed ID fails without the collusion of its owner. No control is perfect, but the tick box these systems replace was defeated by a single click.
The most common forms of circumvention reported in quantitative research is often not actually evading age assurance technology itself – it is no age check at all or self-declaration – the very approaches age assurance is intended to replace.
Stories reported by teenagers to focus groups of using make-up or false beards and moustaches are anecdotal evidence as these claims do not feature in quantitative analysis. No technology is perfect, and there may be a limited number of cases where this has worked, but our members’ solutions are designed not to be fooled so easily, and certification procedures test for resistance to such presentation attacks.