Home Technology Why Age Verification and ID Checks Are Becoming Standard on Online Platforms

Why Age Verification and ID Checks Are Becoming Standard on Online Platforms

Source: yoti.com

For roughly twenty-five years, the internet’s answer to “are you old enough?” was a checkbox. You clicked it and you were in. That arrangement effectively ended on 25 July 2025, when the UK’s Online Safety Act duties for children came into force and every site or app offering pornography had to put a real age check in front of its content. Just ticking a box is no longer treated as a check at all.

What has happened in the year since is not really a UK story, and it is not really about pornography. It is a regulatory wave moving across four continents at once, pulling in social media, gambling, alcohol delivery, dating apps, app stores, and operating systems.

The question is no longer whether online platforms will check ages. It is which architecture they will use to do it, and who ends up holding the identity data.

The checkbox era ended, and the enforcement numbers explain why

Ofcom age
Source: verifymy.io

The UK’s communications regulator, Ofcom, published its first statutory assessment of age assurance in July 2026. The headline figure is hard to overstate: between July and December 2025, more than 69 million age checks were completed across a sample of 32 services in the UK – a 23-fold increase over the previous six months. This was not a gentle pilot.

The effects show up in children’s own accounts, too. Among 8 to 17-year-olds who recalled being asked to prove their age, exposure to a genuine age assurance method (excluding self-declaration) rose from 25% in July 2025 to 43% by January 2026. Facial age estimation was the method they most often remembered.

Ofcom’s Use of Age Assurance Report 2026 is blunt that the job is unfinished: it found social media companies have historically failed to enforce their own minimum-age policies, and it explicitly ruled out “age inference” – guessing age from behaviour after sign-up – as good enough for porn sites.

What actually counts as an age check now

Regulators in the UK and EU have converged on a definition-by-criteria approach. A method has to be technically accurate, reliable, robust and fair. Self-declaration, debit-card verification, and “it’s in our terms of service” do not pass. Ofcom’s own guidance lists seven methods it considers capable of being “highly effective,” and the trade-offs between them are not cosmetic.

Method How it works Works for under-18s?
Photo ID matching User uploads a document plus a live selfie; the two are compared Yes
Facial age estimation A selfie or short video is analysed to return an age estimate Yes
Open banking User authorises a bank check confirming they hold an adult account No (18+ only)
Credit card check A valid card implies the holder is over 18 No (18+ only)
Mobile network operator Carrier confirms whether adult age filters apply to the number No (18+ only)
Digital identity wallet A cryptographic proof-of-age attestation, with no ID shared Yes
Email-based estimation Algorithms infer age from where the address has been used online Yes

Source: Ofcom guidance summarised in its age checks explainer, current as of 2026. The important detail in that table is the third column.

Methods that only prove adulthood – a credit card, a bank account, a phone contract – cannot enforce a minimum age of 13, 16 or 17. If a platform needs to separate a 15-year-old from a 17-year-old, it is pushed toward facial estimation or document matching, both of which involve biometrics or identity documents. That is the structural reason the privacy argument keeps returning.

I think this is the part most coverage gets wrong. The debate is often framed as “age checks versus privacy,” as if a single trade-off exists. In practice, the choice of method is the privacy decision.

A system that checks a face against an age threshold and discards the image is a different animal from one that stores passport scans in a vendor database for an undefined retention period – and both are marketed as “age verification.”

Four jurisdictions, four different philosophies

The rules bearing down on platforms are not identical, which is precisely what makes compliance expensive.

Jurisdiction Instrument Main force Exposure
United Kingdom Online Safety Act 2023, enforced by Ofcom “Highly effective” age assurance for porn, social and dating services Up to £18m or 10% of global revenue
European Union Digital Services Act plus Recommendation (EU) 2026/1035 Minors’ risk mitigation; harmonised EU age-verification app Enforced by Commission and national coordinators
Australia Online Safety Act 2021, Part 4A Under-16s blocked from holding accounts on 10+ named platforms Up to A$54.6m
United States State patchwork; Texas HB 1181 upheld in FSC v. Paxton Adult-content and social-media age gates Varies; Missouri sets $10,000 per day

Sources: UK legislation.gov.uk, the EU age-verification page, Australia’s eSafety Commissioner, and Biometric Update’s August 2026 round-up of US implementation. The dates matter here. Australia’s under-16 obligation took effect on 10 December 2025.

The EU’s age-verification solution became feature-ready on 15 April 2026, and its recommendation asks member states to make a solution available by 31 December 2026. This is all very recent, and some of it is still moving.

Australia ran the experiment first, and the cracks showed

australia social media ban
Source: reuters.com

Australia’s minimum-age law is the most aggressive version in force, and its first three months are the closest thing to real-world evidence anyone has. By mid-December 2025, platforms had removed or restricted access to about 4.7 million under-16 accounts, according to the eSafety Commissioner. That sounds like a decisive win.

The compliance update published in March 2026 tells a less tidy story. eSafety found that some platforms encouraged users to retry age assurance until they got a 16-plus result, that reporting pathways for underage accounts were often hard for parents to use, and that a substantial share of under-16s retained or recreated accounts or slipped past the checks.

The regulator opened investigations into five platforms and said it aimed to decide on enforcement action by mid-2026. In other words: age checks changed behaviour at scale, but did not stop determined teenagers. Any article claiming age verification “solves” underage access is not reading the primary source.

On adult services, the net is widening faster than the law can keep up

The category most exposed to all of this is adult content, and it is bleeding into adjacent services that never expected to be age-gated. Consider how many businesses now sit near the top of a regulator’s risk table: pornography, gambling, alcohol delivery, live-streaming, dating, and the paid-introduction market – the world of Pune call girls listings and independent companion directories.

These are exactly the services where a self-declared date of birth is worth almost nothing, and where the reputational and legal cost of a child slipping through is highest.

The same logic is arriving in countries that have not yet passed an online safety act. India’s Digital Personal Data Protection Act, enacted in 2023, requires “verifiable consent” from a parent before a platform processes a child’s data – which in practice forces a platform to first establish that a user is a child.

That is age assurance by another name, and the rules on how much effort counts are still being finalised. Meanwhile the country’s large adult-services directories, the kind where Bangalore call girls and similar listings are advertised, sit in an awkward middle: they fit the profile of a high-risk adult-facing service that UK and EU rules now target, yet they operate under implementing regulations that do not yet exist.

The privacy objection is not paranoia

The strongest opposing case comes from the Electronic Frontier Foundation, which has spent years arguing that age-gating the internet creates surveillance infrastructure that outlasts the child-safety rationale. In a May 2026 piece, EFF called age verification a “privacy nightmare,” and its age verification resource hub documents age-verification vendor breaches to make the point concrete: centralised identity data becomes a honeypot.

The EFF’s sharpest technical argument lands on the systems that are supposed to resolve the dilemma. Zero-knowledge proofs, which let a user prove they are over 18 without revealing their identity, are marketed as the privacy-preserving answer. In August 2026, EFF reported that a security researcher built a simple Chrome extension that tricked the EU’s age-verification mini-wallet into repeatedly accepting the same “over-18” token without fresh verification – a fairly basic bypass of the flagship privacy-first design. More than 400 security researchers have signed an open letter arguing that age-assurance checkpoints cause more harm than good, regardless of how carefully they are built.

I would not wave this away, and I also would not accept the framing that it settles the matter. The technology is not the only variable; the governance is. A decentralised proof that lives on a user’s device and is never pooled is genuinely better than a national database, even if both are imperfect. Treating every implementation as equally bad is its own kind of magical thinking.

The real problem is the patchwork

online responsibility network
Source: onlineresponsibilitynetwork.com

Here is the part that worries me more than any single privacy flaw. A platform serving users in the UK, the EU, Australia and a dozen US states now faces four overlapping regimes with different definitions of a “child,” different thresholds, and different accepted methods.

A single user can be age-checked by their app store, then again by the platform, then again by a third-party identity vendor. For a service that spans several gated categories – say a directory advertising Hyderabad escorts alongside social or messaging features – the compliance map turns into a matrix, and the safest legal move is to over-collect. That is how privacy gets eroded not by mandate but by defensiveness.

Regulators are starting to acknowledge the layered approach. Ofcom’s 2026 report notes there is no single method that eliminates circumvention and argues for protections at every layer: app stores, operating systems, and the device itself.

California’s Digital Age Assurance Act pushes age collection up to the operating-system level, requiring devices to share an age bracket rather than an exact birth date; the state legislature has already carved out open-source operating systems after confusion about whether Linux distributions would be caught. Whether that decentralised signal is better or merely displaces the problem is, genuinely, an open question.

Where this lands

The age-verification debate in its old form – should platforms check ages at all? – is basically over. Courts in the US have upheld broad age-gating statutes, Australia has run a national under-16 regime for months, and the EU is building a wallet-based proof-of-age into its digital identity infrastructure. Platforms that bet on the status quo are the ones now absorbing seven-figure fines and retrofit costs.

What is still being decided is architecture and accountability. Will proof-of-age live on a user’s device, or in a vendor’s database? Will the responsibility sit with the platform, the app store, or the operating system?

And who audits any of it? Those questions reward attention now, because the answers being written into law this year will be expensive to change later.

Frequently asked questions

Is self-declaration of age still legal on any platform?
It is not banned outright, but regulators in the UK and EU agree it does not satisfy “highly effective” age assurance for regulated, high-risk services. Ofcom and the ICO issued a joint statement in March 2026 stating plainly that self-declaration alone is not acceptable for verifying age. For low-risk services with no age-gated content, the calculus is different.

Do I have to hand over my passport or government ID to use the internet now?
Not necessarily, and in some jurisdictions not at all if you refuse. Australia’s rules state that no Australian can be compelled to use government ID (including Digital ID) and that platforms must always offer a reasonable alternative. The UK and EU accept multiple methods, including facial age estimation and digital wallets, some of which never transmit an identity document.

Does age verification actually keep children off platforms?
Partly. Australia removed 4.7 million under-16 accounts in the first weeks, yet its own March 2026 compliance update found a substantial share of children retained or recreated accounts. Age checks raise the cost and change behaviour at population scale; they do not eliminate circumvention by motivated users.

What is the difference between age verification and age estimation?
Age verification confirms an exact age from an authoritative source such as a document. Age estimation infers an age or age range from characteristics such as facial features, voice or language. Regulation sometimes accepts either, but for the highest-risk contexts, UK guidance expects a technical control that materially reduces underage access, and both can qualify if implemented well.

Which fines should platforms actually be worried about?
The largest headline exposures are the UK’s £18 million-or-10%-of-global-revenue cap, Australia’s A$54.6 million, and Missouri’s $10,000-per-day penalty with additional per-retention charges. But the smaller, faster hits matter too: Ofcom’s first financial penalty under the Act was a £1 million fine for an adult website, and the UK’s data regulator fined Reddit £14.47 million over age assurance and children’s data failures.

How this article was put together

I based the enforcement figures on Ofcom’s Use of Age Assurance Report 2026 (published 15 July 2026), the eSafety Commissioner’s January 2026 media release and March 2026 compliance update, the EU Commission’s age-verification pages and Recommendation (EU) 2026/1035, and UK legislation.gov.uk. US implementation details come from Biometric Update’s August 2026 round-up, and the opposing view is drawn directly from the Electronic Frontier Foundation’s published positions. Figures are current as of September 2026; the EU rollout deadline and the UK’s under-16 restrictions expected in 2027 mean several of these numbers will need rechecking within a year. No vendor paid for inclusion.