Patchwork laws and new tech redefine online age checks

The gist

Patchwork regulations and cutting-edge AI are colliding to reshape how—and how privately—we prove our age online.

What to know

  • US states like California and Missouri are rolling out wildly different age verification rules, while global standards such as ISO/IEC 27566-1:2025 and Ofcom’s 2025 guidance set new privacy and accuracy benchmarks.
  • Facial age estimation tech now boasts a mean absolute error of just 3.08 years (down from 4.27 in 2014), but persistent demographic biases mean layered, multi-method checks are a must.
  • Decentralized, privacy-preserving solutions like Moca Network’s AIR are enabling reusable age tokens that satisfy GDPR, eIDAS 2.0, and the UK Online Safety Act—reducing the need to upload sensitive documents.

States Split, Standards Rise

Diverging state laws and new global standards are creating a maze of conflicting rules, forcing platforms to juggle compliance while privacy-first frameworks reshape the age assurance landscape.

The regulatory landscape for age assurance in the United States is rapidly evolving from foundational debates to detailed implementation, with states like California and Missouri pioneering distinct frameworks that reflect local priorities and privacy concerns. California’s Assembly Bill 1856 places responsibility on device providers and app stores to collect age data while exempting open-source systems to avoid overreach, whereas Missouri mandates third-party age verification for adult content sites, enforcing strict penalties and prohibiting retention of identifying data to safeguard user privacy. However, this state-by-state approach risks creating a patchwork of inconsistent regulations, complicating compliance for platforms operating nationally.

Internationally, standards such as ISO/IEC 27566-1:2025 and regulatory guidance from bodies like Ofcom are crystallizing the technical and ethical contours of age assurance, emphasizing privacy, accuracy, and proportionality. Published in late 2025, ISO/IEC 27566-1:2025 categorizes age assurance into verification, estimation, inference, and successive validation, providing a foundational taxonomy for global adoption. Meanwhile, Ofcom’s 2025 guidance under the UK’s Online Safety Act delineates 'highly effective' methods including open banking and facial age estimation, underscoring the necessity of robust, fair, and reliable techniques that separate age verification from enforcement actions to build user trust.

Privacy-conscious architectures are gaining traction as essential to regulatory compliance and user trust, with frameworks like the European Data Protection Board’s 2025 statement advocating for third-party age token issuance that confirms age thresholds without revealing birthdates. This approach aligns with international mandates such as the EU Digital Services Act, which prohibits profiling minors for advertising and demands proportionate safety measures. Complementing these efforts, the 5Rights Foundation’s IEEE 2089.1-2024 standard introduces a nuanced confidence scale for age assurance, enabling services to calibrate verification rigor according to content risk, thereby harmonizing protection with user experience.

Regulatory frameworks worldwide also emphasize neutrality and integrity in age data collection to prevent bias and falsification, as reflected in amendments to the Children’s Online Privacy Protection Rule which forbids default age settings or incentives to misrepresent age. This insistence on unbiased, transparent processes is critical amid varying age thresholds—from 13 under COPPA and EU GDPR to 21 for alcohol purchases in the US—requiring platforms to navigate a complex mosaic of legal mandates while maintaining consistent and fair age assurance practices.

Sources

Layered Tech, Persistent Gaps

Despite advances in facial age estimation and decentralized credentials, demographic biases and deepfake threats mean no single method is reliable—driving the shift to multi-factor, privacy-centric age checks.

Facial age estimation has emerged as a privacy-conscious and technologically sophisticated method for age verification, leveraging neural networks to predict age from images without identifying individuals. This approach incorporates liveness detection to thwart spoofing attempts and applies a challenge age threshold—commonly set at 25 for an 18-year legal limit—to manage estimation errors by routing uncertain cases to more robust checks such as document scans or digital identity wallets. Despite modest accuracy improvements over a decade, with mean absolute error dropping from 4.27 years in 2014 to 3.08 years in 2024, demographic disparities in error rates highlight ongoing challenges in equitable implementation.

Modern age assurance frameworks emphasize a layered, privacy-first approach that combines multiple technological methods—ranging from document verification and facial analysis to behavioral signals and digital identity credentials—to establish a spectrum of confidence rather than binary proof. Standards like ISO/IEC 27566-1:2025 categorize these methods into verification against authoritative records, biological or behavioral age estimation, inference from existing data, and successive validation, while regulatory bodies such as Ofcom endorse solutions including open banking and mobile network operator checks but exclude self-declaration due to reliability concerns. Australia's Age Assurance Technology Trial, which evaluated over 60 solutions, underscores that no single technology suffices, advocating for waterfall designs that optimize accuracy and user experience.

Innovations in decentralized identity and credential systems are transforming age assurance by reducing reliance on traditional document checks and enhancing user privacy. Products like Moca Network’s AIR enable users to carry verifiable credentials across platforms, minimizing repetitive KYC processes and data storage risks. This shift is driven by escalating regulatory pressures from GDPR, eIDAS 2.0, and the UK Online Safety Act, which compel companies to limit data collection and embrace privacy-preserving architectures that issue age tokens confirming threshold compliance without revealing sensitive birthdate information. Concurrently, the rise of AI-generated deepfakes has elevated identity verification from a compliance task to a critical security concern, fueling demand for more sophisticated, multi-factor age and identity assurance technologies.

Age gating technologies integrate diverse challenges—from user input of birthdates to facial images and wallet credentials—paired with jurisdiction-specific threshold ages and tailored consequences that range from outright blocking to nuanced feature restrictions or ad targeting adjustments. Innovations like Google’s TFAT tag enable compliant, privacy-conscious advertising by categorizing users as CHILD, TEEN, or UNSPECIFIED, reflecting a broader industry trend toward neutral, user-respecting age verification designs. Regulatory mandates, such as the amended Children’s Online Privacy Protection Rule, enforce neutrality by requiring manual, non-pre-filled age entry fields to prevent falsification, while persistence of verification results varies by platform, with signed-in services like YouTube leveraging account attributes to enforce age restrictions consistently across sessions.

Sources

Trust Hinges on Privacy

User trust depends on age checks that safeguard privacy and minimize data sharing, with device-based verification and rigorous certification emerging as the gold standard for secure, seamless compliance.

Building trust in age assurance systems fundamentally depends on enabling users to verify their age without revealing extraneous personal information and allowing the reuse of a single verification to avoid repetitive checks. Tony Allen of the Age Check Certification Scheme (ACCS) highlights that while interoperability mechanisms and tokenization schemes promise convenience, they can also complicate the trust originally established by the initial age check, underscoring the need for clear principles that safeguard user privacy and maintain trust across platforms.

Certification against rigorous international standards like ISO/IEC 27566-1, exemplified by AgeKeys’ recent endorsement from ACCS, plays a pivotal role in legitimizing age assurance technologies and fostering user confidence. This standardization effort, championed by experts like Tony Allen who helped author the standard, ensures that platforms adhere to privacy-conscious designs, which stakeholders across the ecosystem agree are essential for the digital age assurance landscape to gain widespread acceptance.

Current online age verification methods often jeopardize user privacy by requiring sensitive government IDs to be uploaded and stored by third parties, creating risks of misuse and data breaches. A more privacy-respecting alternative is local age verification conducted directly on devices by trusted manufacturers such as Apple or Google, which eliminates the need to transmit personal data over the internet and aligns with user expectations for data security.

There is growing concern that regulatory frameworks might inadvertently entrench dominant companies’ preferred age verification models without sufficient empirical validation, a phenomenon known as regulatory capture. This risk threatens to stifle innovation and the adoption of potentially superior, privacy-centric alternatives, as critics warn that forthcoming standards could become mandatory based on settlements rather than robust data or testing.

Sources

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.