us

216.73.217.78

Back
Blogs

Age Verification Laws in 2026 and What Regulators Now Demand From Businesses

Age Verification Laws in 2026 and What Regulators Now Demand From Businesses
Richard M. MARCH 4, 2020 19 minutes read

Age verification laws are now being enforced, not just drafted. Here is what the UK, EU, US, Australia and APAC require in 2026, and what regulators have actually done.

In the week Australia’s social media minimum age took effect on 10 December 2025, platforms removed or restricted around 4.7 million accounts held by users under 16, and by early March 2026 the regulator had counted more than 310,000 further accounts prevented from signing in. Those figures are not projections from a bill’s impact assessment. They are counted outcomes, published by Australia’s eSafety Commissioner, and they mark the point at which age verification laws stopped being a drafting exercise.

Most compliance guidance still quotes statutory maximums, because maximums are easy to find. What matters more in 2026 is what regulators have done with those powers, and which methods they have accepted or rejected in writing. This guide covers the age verification regulations in force across the major markets, what each asks of a business, and where the failures are actually happening.

What has changed in age verification law since 2025?

The substance of the change is active enforcement. Between December 2025 and July 2026, the UK’s communications regulator issued confirmation decisions penalising six providers of adult services for failing to run effective age checks, with fines from £80,000 to £1.35 million, while regulators in Australia, France and Brazil moved in the same window. A compliance team reading only the statute now sees a fraction of the picture, because the operative detail sits in enforcement decisions and regulator guidance.

The second change is the diversified and maximum scope of it all. Age verification legislation used to mean pornography, and it now reaches social media, app stores, operating systems, gaming and marketplaces.

 Ian Corby, executive director of the Age Verification Providers Association, described the pace on a Shufti roundtable as “a tsunami of legislation around the world,” pointing to the UK Online Safety Act, the EU Digital Services Act, roughly two dozen US states, Australia’s minimum age, and new requirements in Brazil and India. The practical consequence is that a single global age gate no longer satisfies everyone, because the jurisdictions now disagree on method, threshold and data handling.

The third change is evidentiary, because regulators have started publishing measured outcomes rather than intentions. Ofcom’s report on the use of age assurance, published in July 2026, found that among UK children aged 8 to 17 who recalled being asked to prove their age, the proportion encountering a highly effective check rose from 25% to 43% between July 2025 and January 2026. The number is moving the right way and remains short of the duty, which is why Ofcom framed the job as unfinished. 

France’s regulator reported a comparable effect on 29 July 2026, saying that since February 2025, 35 of the pornographic sites most visited by French minors had deployed an age check, stopped offering pornographic content in France, or been blocked at ARCOM’s request. Time spent by minors on pornographic sites has fallen by nearly a third against the pre-intervention level, according to Médiamétrie Netratings audience data cited by the regulator.

Which age verification laws are in force by country?

The global age verification laws below create a live obligation as of August 2026. The status column matters more than the penalty column, because several widely cited laws have either not commenced or are caught in litigation.

Jurisdiction Instrument Who it binds Threshold Status as of Aug 2026 Maximum penalty

UK

Online Safety Act 2023,  including child safety and pornography age assurance duties

Regulated user-to-user services, search services and pornography services within scope of the Act

18 for pornography access

In force; pornography age assurance duties began applying in July 2025

Greater of £18m or 10% of qualifying worldwide revenue 

EU

Digital Services Act, Arts 28 and 35

Online platforms accessible to minors, with additional systemic-risk obligations for very large online platforms

Not fixed by the DSA

In force; Commission age assurance initiatives and guidance continue developing

Up to 6% of worldwide annual turnover

Ireland

Online Safety Code, Coimisiún na Meán

Relevant online services, including Video-sharing platform services within scope of online safety regulation

Age assurance requirements apply for regulated harmful content categories

In force, under Ireland’s online safety framework

Enforcement measures and penalties apply under the applicable Irish regulatory framework

France

Loi SREN, Art 10 LCEN, ARCOM référentiel

Pornographic services accessible in France

18 for pornography access

Age verification requirements in force under French online safety rules

Administrative and criminal penalties may apply depending on the breach 

Germany

JMStV, assessed by KJM

Telemedia services providing adult or youth-impacting content

Depends on content classification and youth protection requirements

In force under Germany’s youth media protection framework

Administrative fines applicable under German youth protection rules

Italy

AGCOM Delibera 96/25/CONS

Providers of Pornographic content services accessible in Italy

18 for pornography access

Age verification requirements introduced under AGCOM rules

Sanctions under AGCOM enforcement fraemwork

US, states

State age-verification laws, including laws modelled on Texas HB 1181 

Websites with substantial adult content, depending on state definitions 

18

Multiple states have enacted laws; several remain affected by litigation or enforcement challenges 

Varies, by state law

US, federal

PACT Act, 15 U.S.C. §376a

Delivery sellers of cigarettes, smokeless tobacco and covered nicotine products 

Minimum legal purchasing age under applicable law

In force

Federal enforcement penalties apply

Australia

Online Safety Amendment (Social Media Minimum Age) Act 2024

Designated age-restricted social media platforms 

16 for holding an account 

In force since 10 Dec 2025

Civil penalties under the Online Safety Act framework, including up to AU$49.5 million for serious breaches 

Brazil

Lei 15.211/2025

Online services accessible to children, depending on service type and obligations 

18 for adult content

Framework developing; verify specific implementing measures before relying on dates or penalties 

Up to 10% of Brazil group revenue, capped at R$50m per infraction

Indonesia

PP 17/2025 and Permenkomdigi 9/2026

Electronic systems accessible to children

Tiered from 3 to 18

Requirements developing through Indonesian digital regulation framework 

Warnings, administrative sanctions and service restrictions may apply depending on breach 

Malaysia

Online Safety Act 2025, Child Protection Code

Licensed application service providers

16 for registration

In force since 1 June 2026

Set under the Act

India

DPDP Act 2023 and DPDP Rules 2025

Data fiduciaries processing children’s data

18

Rule 10 does not commence until 2027

Up to ₹200 crore for children’s data breaches

Global age verification law timeline, 2025–2027What does the UK Online Safety Act require, and who does it reach?

The UK Online Safety Act 2023 requires services that allow pornographic content to use highly effective age assurance so that children are not normally able to encounter it, and it requires services likely to be accessed by children to protect them from other categories of harmful content. The duties arrived in stages. Providers of their own pornographic content came under Part 5 from 17 January 2025, children’s access assessments were due by 16 April 2025, and the children’s safety duties that carry the age assurance requirement took effect on 25 July 2025.

What counts as highly effective age assurance?

Ofcom does not set a numerical accuracy threshold, and it said in January 2025 that it decided against introducing one at that stage. Instead, it applies four criteria that a process must meet in full. The check must be technically accurate, meaning correct under test conditions. It must be robust, which translates to it being  correct in real deployment. It must be reliable, meaning reproducible from evidence that can be trusted. And it must be fair, meaning free of bias against particular groups of users.

Ofcom then goes further than most regulators by naming methods. Open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation are all capable of being highly effective when implemented properly. Self-declaration is not, and neither are payment methods that do not themselves require the holder to be over 18. Because Ofcom publishes that list, the age verification rules in the UK are unusually testable, and a business can be told in advance that its current control will fail.

Does the Online Safety Act apply to companies based outside the UK?

Yes. Section 4 of the Act applies duties to any service with “links with the United Kingdom,” which is met if the service has a significant number of UK users, if the UK is a target market, or if the service is capable of being used in the UK and there are reasonable grounds to believe it presents a material risk of significant harm to UK users. 

Ofcom has confirmed the duties apply wherever in the world a service is based. Geoblocking the UK is a lawful alternative, and several providers have chosen it, but a service that blocks UK traffic must not then point users toward circumvention.

What has Ofcom actually fined?

The maximum penalty under Schedule 13 is the greater of £18 million or 10% of qualifying worldwide revenue. The imposed penalties are considerably smaller and considerably more instructive, because they show the regulator acting against small operators rather than only against household names.

Provider Date of decision Penalty for the age assurance breach

8579 LLC

20 February 2026

£1,350,000, plus £50,000 for failing to respond to an information notice

AVS Group Ltd

3 December 2025

£1,000,000

Kick Online Entertainment S.A.

11 February 2026

£800,000, plus £30,000 for failing to respond to an information notice

Fapello

8 July 2026

£600,000, plus £30,000 for failing to respond to an information notice

Youngtek Solutions Ltd

26 May 2026

£500,000, plus £100,000 for failing to respond to an information notice

First Time Videos LLC

18 June 2026

£80,000

A pattern sits in the right-hand column. In almost every case, Ofcom added a separate penalty for failing to answer an information notice, so the cost of ignoring the regulator is priced independently of the underlying breach.

What the EU Digital Services Act does and does not require on age verification

The Digital Services Act does not impose a general age verification mandate, and reading it as though it does leads teams to build the wrong control. Article 28 requires providers of online platforms accessible to minors to put in place the appropriate and proportionate measures for their privacy, safety and security. Article 28(3) then states that compliance shall not oblige providers to process additional personal data in order to assess whether a user is a minor. Age verification appears once in the entire regulation, at Article 35(1)(j), which lists it as one measure that very large platforms may apply to mitigate systemic risk.

The Commission published guidelines on the protection of minors under Article 28(4) in July 2025, recommending age assurance that is accurate, reliable, robust, non-intrusive and non-discriminatory, and recommending age verification specifically for adult content, gambling and services where the law sets a minimum age. The Commission has also backed a privacy-preserving age verification app built on European digital identity wallet specifications, and adopted Commission Recommendation (EU) 2026/1035 on 29 April 2026 encouraging deployment of proof-of-age technology across the EU by the end of 2026.

Enforcement has begun but has not concluded. The Commission issued preliminary findings against four adult content platforms on 26 March 2026 over the absence of effective age verification.

Which US states have age verification laws, and what do they require?

Twenty-five states require age verification for sites carrying material harmful to minors. Treat that figure as a count of laws enacted rather than laws currently enforceable, because several are subject to injunctions.

The constitutional question however, is settled. In Free Speech Coalition, Inc. v. Paxton, decided 27 June 2025 by a 6 to 3 majority, the Supreme Court applied intermediate scrutiny and upheld the Texas statute, holding that “no person, adult or child, has a First Amendment right to access such speech without first submitting proof of age.” The practical effect is that age verification laws by state are no longer vulnerable to the broad First Amendment challenge that stalled earlier attempts.

What does the Texas age verification law require?

Texas HB 1181, effective 1 September 2023, applies to a commercial entity that publishes material on a website where more than one-third of the content is sexual material harmful to minors. Such an entity must use reasonable age verification, which the statute defines as digital identification or a commercial system relying on government-issued identification or on public or private transactional data. The entity, or the third party performing the check, may not retain any identifying information of the user. The Attorney General enforces it, and the penalties run to $10,000 per day of operation in violation, $10,000 per instance of unlawful data retention, and up to a further $250,000 if a minor accesses the material as a result.

What does the California Digital Age Assurance Act require?

California AB 1043, signed on 13 October 2025, takes a different route by pushing the obligation down to the operating system. An operating system provider must ask for a birth date or age at account setup and then supply developers, through a real-time API, with a signal placing the user in one of four brackets, which come as the following under 13, 13 to 15, 16 to 17, and 18 or over. That signal is defined as non-personally identifiable data, so the developer learns a bracket rather than a birth date.

A developer that receives a signal is treated as having actual knowledge of the user’s age range across every platform and access point of the application, even if it wilfully disregards the signal. The California age verification law becomes operative on 1 January 2027, with retro-fit deadlines of 1 July 2027 for existing devices and applications, and the Attorney General can recover $2,500 per affected child for a negligent violation or $7,500 for an intentional one.

What is the App Store Accountability Act?

The App Store Accountability Act is a model law requiring app stores to verify a user’s age category at account creation, tie a minor’s account to a verified parent account, obtain parental consent for each individual download or purchase, and share the age category and consent status with developers. Three versions exist, at very different stages.

  1. Utah SB 142 (2025) was the original. A 2026 amendment, HB 498, pushed every substantive app store and developer obligation to 6 May 2027 and removed the deceptive-trade-practice enforcement route, leaving a private right of action for a harmed minor or parent. 
  2. Texas SB 2420 (2025) took effect on 1 January 2026 and is enforced as a deceptive trade practice. It was preliminarily enjoined on 23 December 2025, the Fifth Circuit stayed that injunction on 4 June 2026, and the Supreme Court declined to vacate the stay on 6 July 2026. The law is therefore enforceable while the merits remain undecided. The Supreme Court did not uphold it, and conflating that procedural order with the Paxton ruling on HB 1181 is the most common error in this area.
  3. Federal S. 1586 was introduced on 1 May 2025 and referred to the Senate Commerce Committee. No further action is confirmed on the public record, so it should be treated as a proposal rather than a deadline.

Is age verification required for online alcohol and tobacco sales?

For tobacco, vape, and nicotine, yes, and the federal requirement is stricter than most people expect. Under the PACT Act at 15 U.S.C. §376a(b)(4), a delivery seller must verify the buyer’s full name, birth date and residential address against a commercially available database drawn primarily from government sources, and that database must not be in the seller’s possession or under its control. An adult must also sign for delivery and present a valid government-issued photographic identification.

Alcohol works differently, because direct-to-consumer shipping is governed state by state. California requires the carrier to obtain the signature of someone aged 21 or over and the carton to be labelled accordingly, with no statutory electronic age check at the point of order. A business selling both categories therefore cannot use one workflow for both.

What is the penalty for failing to verify age?

Penalties fall into three families, and the difference between them changes how a compliance case should be argued internally.a

Regime Maximum

UK Online Safety Act

Greater of £18m or 10% of qualifying worldwide revenue

EU Digital Services Act

Up to 6% of worldwide annual turnover

Texas HB 1181

Civil penalties under Texas law, including daily penalties for violations

California AB 1043

$2,500 negligent or $7,500 intentional, per affected child

Australia

Up to AU$49.5 million for serious breaches

Brazil

Up to 10% of Brazil group revenue, capped at R$50m per infraction

Turnover-based ceilings dominate the headlines, but imposed penalties tell a different story. Regulators have so far calibrated fines to operator size, so a mid-sized business should plan against a proportionate figure rather than dismiss the risk because it will never face 10% of revenue.

Why most age verification failures are not technology failures

The assumption behind most remediation budgets is that a stronger check would have prevented the breach. The evidence from people who run these systems points somewhere less comfortable.

Corby put it directly on the same Shufti roundtable.

 “The age-verification providers generally had very good technology, but they were allowing their clients to turn some controls off.” 

He described a reported bypass in which a PlayStation avatar was told to look left, look right and open its mouth, and it worked because the platform allowed unlimited retries. Fake identity documents got through, in his account, because the client had asked for authentication to be switched off. That is a configuration failure sitting inside a compliant-on-paper deployment, and no vendor selection process will catch it.

Unlimited retries deserve separate attention, because they turn a probabilistic check into a solvable puzzle. If a user can attempt the same method until it returns an acceptable result, the effective accuracy is not the measured accuracy, and a regulator applying Ofcom’s robustness criterion looks at deployed behaviour rather than the lab score.

The second failure mode is treating estimation as verification. Tom Gadsden, VP of Product at Shufti, described penetration testing against peer systems and found age-estimation-only solutions were “trivially bypassed” because the liveness and injection-attack defences were absent. 

Present a video or a clip and the system returns an accurate estimate of somebody who is not the person seeking access. Facial age estimation is a legitimate, regulator-accepted method, but only when a liveness layer confirms a live human is in front of the camera.

The third is self-declaration, which persists because it costs nothing. Michael Murray, head of regulatory strategy at the UK Information Commissioner’s Office, was blunt about it on the same roundtable. “A lot of companies still use self-declaration as their primary form of what they call age assurance. But we know it’s not age assurance, it’s just asking a kid to make up a date.” Ofcom excludes it in guidance, and Brazil prohibits it by statute in Article 9 of Lei 15.211/2025, so the method is now unlawful in some markets rather than merely weak.

What age verification compliance requires in practice

Age verification requirements now vary enough between jurisdictions that a single global control will fail somewhere. Six steps close most of the gap.

  1. Establish whether children can reach your service, and document it: Both the UK and Brazil apply duties on the basis of likely access rather than intended audience, so an assessment on file is the first thing a regulator asks for.
  2. Map the threshold per market, not per product: Australia sets 16 for social media, Malaysia sets 16 for registration, most adult content regimes set 18, and Indonesia tiers obligations from age 3 upward.
  3. Check whether the law permits the method you have chosen: Australia’s section 63DB prohibits a platform from collecting government-issued identification to satisfy the minimum age duty unless it also offers an alternative, while Malaysia’s Child Protection Code requires verification against government-issued records. A stack that satisfies one breaks the other, so the routing has to be jurisdictional.
  4. Remove the retry loophole before anything else: Cap attempts per user and per device, and log the cap. This is the cheapest control on the list and it closes the failure Corby described.
  5. Decide retention deliberately: Texas prohibits retaining identifying information, Brazil restricts age data to the verification purpose, and Australia requires destruction after use. Default retention settings will breach at least one of these.
  6. Layer liveness under any biometric estimation: Without an injection and replay defence, an age estimate describes whatever the camera was shown rather than the person seeking access.

How Shufti handles age checks across jurisdictions

If you operate in more than one market, the problem is rarely finding an age check. It is running different thresholds, accepted methods and retention rules through one integration without building a separate flow for every regulator.

Shufti’s age verification runs as a configurable waterfall rather than a single gate. A user starts with facial age estimation from a liveness-checked selfie, and the flow escalates to an authoritative database lookup or document verification with face match only when the confidence score falls below the threshold you set for that product, region, or risk level. Biometric templates are processed on the user’s device, which keeps the data-minimisation position defensible under GDPR Article 9. The liveness layer beneath the estimation holds iBeta Level 3 conformance under ISO/IEC 30107-3, the point at which an age estimate stops describing the image and starts describing the person.

See how the escalation thresholds behave against your own traffic and jurisdictions, then book a 20-minute demo.

Frequently Asked Questions

Q1: Which US states have age verification laws?

Twenty-five states have enacted age verification laws for sites carrying material harmful to minors, per the Free Speech Coalition tracker as of August 2026. That count reflects laws passed rather than laws currently enforceable, since several face injunctions. No official government list exists.

Q2: Which countries require age verification by law?

The UK, France, Germany, Italy, Ireland, Australia, Brazil, Indonesia and Malaysia all impose live obligations as of August 2026, alongside 25 US states. The EU requires proportionate measures for minors under the Digital Services Act without mandating verification in general terms.

Q3: What is the penalty for failing to verify age?

Ceilings range from £18 million or 10% of revenue in the UK, to 6% of global turnover in the EU, to AU$49.5 million in Australia. Imposed UK penalties have so far run between £80,000 and £1.35 million, calibrated to operator size.

Q4: Does the UK Online Safety Act apply to companies based outside the UK?

Yes. Section 4 applies duties to any service with links to the UK, meaning a significant number of UK users, the UK as a target market, or usability in the UK combined with a material risk of significant harm. Ofcom enforces regardless of where a service is based.

Q5: What counts as highly effective age assurance?

Ofcom requires a process to be technically accurate, robust, reliable and fair, with no numerical threshold set. Open banking, photo-ID matching, facial age estimation, mobile network checks, credit card checks and digital identity services can qualify. Self-declaration cannot.

Q6: Do age verification laws apply to social media platforms?

Yes, increasingly. Australia bars under-16 accounts on age-restricted social media platforms, Malaysia requires verified registration for under-16s, and the European Commission has opened DSA proceedings against several social platforms over age assurance. Duties differ sharply by market.

Q7: Is age verification required for online alcohol and tobacco sales?

For tobacco and nicotine in the US, yes. The PACT Act requires verification against a government-sourced database outside the seller's control, plus photo ID at delivery. Alcohol direct-to-consumer shipping is state-governed and often relies on adult signature at delivery instead.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.