Age verification laws are now being enforced, not just drafted. Here is what the UK, EU, US, Australia and APAC require in 2026, and what regulators have actually done.
In the week Australia’s social media minimum age took effect on 10 December 2025, platforms removed or restricted around 4.7 million accounts held by users under 16, and by early March 2026 the regulator had counted more than 310,000 further accounts prevented from signing in. Those figures are not projections from a bill’s impact assessment. They are counted outcomes, published by Australia’s eSafety Commissioner, and they mark the point at which age verification laws stopped being a drafting exercise.
Most compliance guidance still quotes statutory maximums, because maximums are easy to find. What matters more in 2026 is what regulators have done with those powers, and which methods they have accepted or rejected in writing. This guide covers the age verification regulations in force across the major markets, what each asks of a business, and where the failures are actually happening.
What has changed in age verification law since 2025?
The substance of the change is active enforcement. Between December 2025 and July 2026, the UK’s communications regulator issued confirmation decisions penalising six providers of adult services for failing to run effective age checks, with fines from £80,000 to £1.35 million, while regulators in Australia, France and Brazil moved in the same window. A compliance team reading only the statute now sees a fraction of the picture, because the operative detail sits in enforcement decisions and regulator guidance.
The second change is the diversified and maximum scope of it all. Age verification legislation used to mean pornography, and it now reaches social media, app stores, operating systems, gaming and marketplaces.
Ian Corby, executive director of the Age Verification Providers Association, described the pace on a Shufti roundtable as “a tsunami of legislation around the world,” pointing to the UK Online Safety Act, the EU Digital Services Act, roughly two dozen US states, Australia’s minimum age, and new requirements in Brazil and India. The practical consequence is that a single global age gate no longer satisfies everyone, because the jurisdictions now disagree on method, threshold and data handling.
The third change is evidentiary, because regulators have started publishing measured outcomes rather than intentions. Ofcom’s report on the use of age assurance, published in July 2026, found that among UK children aged 8 to 17 who recalled being asked to prove their age, the proportion encountering a highly effective check rose from 25% to 43% between July 2025 and January 2026. The number is moving the right way and remains short of the duty, which is why Ofcom framed the job as unfinished.
France’s regulator reported a comparable effect on 29 July 2026, saying that since February 2025, 35 of the pornographic sites most visited by French minors had deployed an age check, stopped offering pornographic content in France, or been blocked at ARCOM’s request. Time spent by minors on pornographic sites has fallen by nearly a third against the pre-intervention level, according to Médiamétrie Netratings audience data cited by the regulator.
Which age verification laws are in force by country?
The global age verification laws below create a live obligation as of August 2026. The status column matters more than the penalty column, because several widely cited laws have either not commenced or are caught in litigation.
| Jurisdiction | Instrument | Who it binds | Threshold | Status as of Aug 2026 | Maximum penalty |
|
UK |
Online Safety Act 2023, including child safety and pornography age assurance duties |
Regulated user-to-user services, search services and pornography services within scope of the Act |
18 for pornography access |
In force; pornography age assurance duties began applying in July 2025 |
Greater of £18m or 10% of qualifying worldwide revenue |
|
EU |
Digital Services Act, Arts 28 and 35 |
Online platforms accessible to minors, with additional systemic-risk obligations for very large online platforms |
Not fixed by the DSA |
In force; Commission age assurance initiatives and guidance continue developing |
Up to 6% of worldwide annual turnover |
|
Ireland |
Online Safety Code, Coimisiún na Meán |
Relevant online services, including Video-sharing platform services within scope of online safety regulation |
Age assurance requirements apply for regulated harmful content categories |
In force, under Ireland’s online safety framework |
Enforcement measures and penalties apply under the applicable Irish regulatory framework |
|
France |
Loi SREN, Art 10 LCEN, ARCOM référentiel |
Pornographic services accessible in France |
18 for pornography access |
Age verification requirements in force under French online safety rules |
Administrative and criminal penalties may apply depending on the breach |
|
Germany |
JMStV, assessed by KJM |
Telemedia services providing adult or youth-impacting content |
Depends on content classification and youth protection requirements |
In force under Germany’s youth media protection framework |
Administrative fines applicable under German youth protection rules |
|
Italy |
AGCOM Delibera 96/25/CONS |
Providers of Pornographic content services accessible in Italy |
18 for pornography access |
Age verification requirements introduced under AGCOM rules |
Sanctions under AGCOM enforcement fraemwork |
|
US, states |
State age-verification laws, including laws modelled on Texas HB 1181 |
Websites with substantial adult content, depending on state definitions |
18 |
Multiple states have enacted laws; several remain affected by litigation or enforcement challenges |
Varies, by state law |
|
US, federal |
PACT Act, 15 U.S.C. §376a |
Delivery sellers of cigarettes, smokeless tobacco and covered nicotine products |
Minimum legal purchasing age under applicable law |
In force |
Federal enforcement penalties apply |
|
Australia |
Online Safety Amendment (Social Media Minimum Age) Act 2024 |
Designated age-restricted social media platforms |
16 for holding an account |
In force since 10 Dec 2025 |
Civil penalties under the Online Safety Act framework, including up to AU$49.5 million for serious breaches |
|
Brazil |
Lei 15.211/2025 |
Online services accessible to children, depending on service type and obligations |
18 for adult content |
Framework developing; verify specific implementing measures before relying on dates or penalties |
Up to 10% of Brazil group revenue, capped at R$50m per infraction |
|
Indonesia |
PP 17/2025 and Permenkomdigi 9/2026 |
Electronic systems accessible to children |
Tiered from 3 to 18 |
Requirements developing through Indonesian digital regulation framework |
Warnings, administrative sanctions and service restrictions may apply depending on breach |
|
Malaysia |
Online Safety Act 2025, Child Protection Code |
Licensed application service providers |
16 for registration |
In force since 1 June 2026 |
Set under the Act |
|
India |
DPDP Act 2023 and DPDP Rules 2025 |
Data fiduciaries processing children’s data |
18 |
Rule 10 does not commence until 2027 |
Up to ₹200 crore for children’s data breaches |
What does the UK Online Safety Act require, and who does it reach?
The UK Online Safety Act 2023 requires services that allow pornographic content to use highly effective age assurance so that children are not normally able to encounter it, and it requires services likely to be accessed by children to protect them from other categories of harmful content. The duties arrived in stages. Providers of their own pornographic content came under Part 5 from 17 January 2025, children’s access assessments were due by 16 April 2025, and the children’s safety duties that carry the age assurance requirement took effect on 25 July 2025.
What counts as highly effective age assurance?
Ofcom does not set a numerical accuracy threshold, and it said in January 2025 that it decided against introducing one at that stage. Instead, it applies four criteria that a process must meet in full. The check must be technically accurate, meaning correct under test conditions. It must be robust, which translates to it being correct in real deployment. It must be reliable, meaning reproducible from evidence that can be trusted. And it must be fair, meaning free of bias against particular groups of users.
Ofcom then goes further than most regulators by naming methods. Open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation are all capable of being highly effective when implemented properly. Self-declaration is not, and neither are payment methods that do not themselves require the holder to be over 18. Because Ofcom publishes that list, the age verification rules in the UK are unusually testable, and a business can be told in advance that its current control will fail.
Does the Online Safety Act apply to companies based outside the UK?
Yes. Section 4 of the Act applies duties to any service with “links with the United Kingdom,” which is met if the service has a significant number of UK users, if the UK is a target market, or if the service is capable of being used in the UK and there are reasonable grounds to believe it presents a material risk of significant harm to UK users.
Ofcom has confirmed the duties apply wherever in the world a service is based. Geoblocking the UK is a lawful alternative, and several providers have chosen it, but a service that blocks UK traffic must not then point users toward circumvention.
What has Ofcom actually fined?
The maximum penalty under Schedule 13 is the greater of £18 million or 10% of qualifying worldwide revenue. The imposed penalties are considerably smaller and considerably more instructive, because they show the regulator acting against small operators rather than only against household names.
| Provider | Date of decision | Penalty for the age assurance breach |
|
8579 LLC |
20 February 2026 |
£1,350,000, plus £50,000 for failing to respond to an information notice |
|
AVS Group Ltd |
3 December 2025 |
£1,000,000 |
|
Kick Online Entertainment S.A. |
11 February 2026 |
£800,000, plus £30,000 for failing to respond to an information notice |
|
Fapello |
8 July 2026 |
£600,000, plus £30,000 for failing to respond to an information notice |
|
Youngtek Solutions Ltd |
26 May 2026 |
£500,000, plus £100,000 for failing to respond to an information notice |
|
First Time Videos LLC |
18 June 2026 |
£80,000 |
A pattern sits in the right-hand column. In almost every case, Ofcom added a separate penalty for failing to answer an information notice, so the cost of ignoring the regulator is priced independently of the underlying breach.
What the EU Digital Services Act does and does not require on age verification
The Digital Services Act does not impose a general age verification mandate, and reading it as though it does leads teams to build the wrong control. Article 28 requires providers of online platforms accessible to minors to put in place the appropriate and proportionate measures for their privacy, safety and security. Article 28(3) then states that compliance shall not oblige providers to process additional personal data in order to assess whether a user is a minor. Age verification appears once in the entire regulation, at Article 35(1)(j), which lists it as one measure that very large platforms may apply to mitigate systemic risk.
The Commission published guidelines on the protection of minors under Article 28(4) in July 2025, recommending age assurance that is accurate, reliable, robust, non-intrusive and non-discriminatory, and recommending age verification specifically for adult content, gambling and services where the law sets a minimum age. The Commission has also backed a privacy-preserving age verification app built on European digital identity wallet specifications, and adopted Commission Recommendation (EU) 2026/1035 on 29 April 2026 encouraging deployment of proof-of-age technology across the EU by the end of 2026.
Enforcement has begun but has not concluded. The Commission issued preliminary findings against four adult content platforms on 26 March 2026 over the absence of effective age verification.
Which US states have age verification laws, and what do they require?
Twenty-five states require age verification for sites carrying material harmful to minors. Treat that figure as a count of laws enacted rather than laws currently enforceable, because several are subject to injunctions.
The constitutional question however, is settled. In Free Speech Coalition, Inc. v. Paxton, decided 27 June 2025 by a 6 to 3 majority, the Supreme Court applied intermediate scrutiny and upheld the Texas statute, holding that “no person, adult or child, has a First Amendment right to access such speech without first submitting proof of age.” The practical effect is that age verification laws by state are no longer vulnerable to the broad First Amendment challenge that stalled earlier attempts.
What does the Texas age verification law require?
Texas HB 1181, effective 1 September 2023, applies to a commercial entity that publishes material on a website where more than one-third of the content is sexual material harmful to minors. Such an entity must use reasonable age verification, which the statute defines as digital identification or a commercial system relying on government-issued identification or on public or private transactional data. The entity, or the third party performing the check, may not retain any identifying information of the user. The Attorney General enforces it, and the penalties run to $10,000 per day of operation in violation, $10,000 per instance of unlawful data retention, and up to a further $250,000 if a minor accesses the material as a result.
What does the California Digital Age Assurance Act require?
California AB 1043, signed on 13 October 2025, takes a different route by pushing the obligation down to the operating system. An operating system provider must ask for a birth date or age at account setup and then supply developers, through a real-time API, with a signal placing the user in one of four brackets, which come as the following under 13, 13 to 15, 16 to 17, and 18 or over. That signal is defined as non-personally identifiable data, so the developer learns a bracket rather than a birth date.
A developer that receives a signal is treated as having actual knowledge of the user’s age range across every platform and access point of the application, even if it wilfully disregards the signal. The California age verification law becomes operative on 1 January 2027, with retro-fit deadlines of 1 July 2027 for existing devices and applications, and the Attorney General can recover $2,500 per affected child for a negligent violation or $7,500 for an intentional one.
What is the App Store Accountability Act?
The App Store Accountability Act is a model law requiring app stores to verify a user’s age category at account creation, tie a minor’s account to a verified parent account, obtain parental consent for each individual download or purchase, and share the age category and consent status with developers. Three versions exist, at very different stages.
- Utah SB 142 (2025) was the original. A 2026 amendment, HB 498, pushed every substantive app store and developer obligation to 6 May 2027 and removed the deceptive-trade-practice enforcement route, leaving a private right of action for a harmed minor or parent.
- Texas SB 2420 (2025) took effect on 1 January 2026 and is enforced as a deceptive trade practice. It was preliminarily enjoined on 23 December 2025, the Fifth Circuit stayed that injunction on 4 June 2026, and the Supreme Court declined to vacate the stay on 6 July 2026. The law is therefore enforceable while the merits remain undecided. The Supreme Court did not uphold it, and conflating that procedural order with the Paxton ruling on HB 1181 is the most common error in this area.
- Federal S. 1586 was introduced on 1 May 2025 and referred to the Senate Commerce Committee. No further action is confirmed on the public record, so it should be treated as a proposal rather than a deadline.
Is age verification required for online alcohol and tobacco sales?
For tobacco, vape, and nicotine, yes, and the federal requirement is stricter than most people expect. Under the PACT Act at 15 U.S.C. §376a(b)(4), a delivery seller must verify the buyer’s full name, birth date and residential address against a commercially available database drawn primarily from government sources, and that database must not be in the seller’s possession or under its control. An adult must also sign for delivery and present a valid government-issued photographic identification.
Alcohol works differently, because direct-to-consumer shipping is governed state by state. California requires the carrier to obtain the signature of someone aged 21 or over and the carton to be labelled accordingly, with no statutory electronic age check at the point of order. A business selling both categories therefore cannot use one workflow for both.
What is the penalty for failing to verify age?
Penalties fall into three families, and the difference between them changes how a compliance case should be argued internally.a
| Regime | Maximum |
|
UK Online Safety Act |
Greater of £18m or 10% of qualifying worldwide revenue |
|
EU Digital Services Act |
Up to 6% of worldwide annual turnover |
|
Texas HB 1181 |
Civil penalties under Texas law, including daily penalties for violations |
|
California AB 1043 |
$2,500 negligent or $7,500 intentional, per affected child |
|
Australia |
Up to AU$49.5 million for serious breaches |
|
Brazil |
Up to 10% of Brazil group revenue, capped at R$50m per infraction |
Turnover-based ceilings dominate the headlines, but imposed penalties tell a different story. Regulators have so far calibrated fines to operator size, so a mid-sized business should plan against a proportionate figure rather than dismiss the risk because it will never face 10% of revenue.
Why most age verification failures are not technology failures
The assumption behind most remediation budgets is that a stronger check would have prevented the breach. The evidence from people who run these systems points somewhere less comfortable.
Corby put it directly on the same Shufti roundtable.
“The age-verification providers generally had very good technology, but they were allowing their clients to turn some controls off.”
He described a reported bypass in which a PlayStation avatar was told to look left, look right and open its mouth, and it worked because the platform allowed unlimited retries. Fake identity documents got through, in his account, because the client had asked for authentication to be switched off. That is a configuration failure sitting inside a compliant-on-paper deployment, and no vendor selection process will catch it.
Unlimited retries deserve separate attention, because they turn a probabilistic check into a solvable puzzle. If a user can attempt the same method until it returns an acceptable result, the effective accuracy is not the measured accuracy, and a regulator applying Ofcom’s robustness criterion looks at deployed behaviour rather than the lab score.
The second failure mode is treating estimation as verification. Tom Gadsden, VP of Product at Shufti, described penetration testing against peer systems and found age-estimation-only solutions were “trivially bypassed” because the liveness and injection-attack defences were absent.
Present a video or a clip and the system returns an accurate estimate of somebody who is not the person seeking access. Facial age estimation is a legitimate, regulator-accepted method, but only when a liveness layer confirms a live human is in front of the camera.
The third is self-declaration, which persists because it costs nothing. Michael Murray, head of regulatory strategy at the UK Information Commissioner’s Office, was blunt about it on the same roundtable. “A lot of companies still use self-declaration as their primary form of what they call age assurance. But we know it’s not age assurance, it’s just asking a kid to make up a date.” Ofcom excludes it in guidance, and Brazil prohibits it by statute in Article 9 of Lei 15.211/2025, so the method is now unlawful in some markets rather than merely weak.
What age verification compliance requires in practice
Age verification requirements now vary enough between jurisdictions that a single global control will fail somewhere. Six steps close most of the gap.
- Establish whether children can reach your service, and document it: Both the UK and Brazil apply duties on the basis of likely access rather than intended audience, so an assessment on file is the first thing a regulator asks for.
- Map the threshold per market, not per product: Australia sets 16 for social media, Malaysia sets 16 for registration, most adult content regimes set 18, and Indonesia tiers obligations from age 3 upward.
- Check whether the law permits the method you have chosen: Australia’s section 63DB prohibits a platform from collecting government-issued identification to satisfy the minimum age duty unless it also offers an alternative, while Malaysia’s Child Protection Code requires verification against government-issued records. A stack that satisfies one breaks the other, so the routing has to be jurisdictional.
- Remove the retry loophole before anything else: Cap attempts per user and per device, and log the cap. This is the cheapest control on the list and it closes the failure Corby described.
- Decide retention deliberately: Texas prohibits retaining identifying information, Brazil restricts age data to the verification purpose, and Australia requires destruction after use. Default retention settings will breach at least one of these.
- Layer liveness under any biometric estimation: Without an injection and replay defence, an age estimate describes whatever the camera was shown rather than the person seeking access.
How Shufti handles age checks across jurisdictions
If you operate in more than one market, the problem is rarely finding an age check. It is running different thresholds, accepted methods and retention rules through one integration without building a separate flow for every regulator.
Shufti’s age verification runs as a configurable waterfall rather than a single gate. A user starts with facial age estimation from a liveness-checked selfie, and the flow escalates to an authoritative database lookup or document verification with face match only when the confidence score falls below the threshold you set for that product, region, or risk level. Biometric templates are processed on the user’s device, which keeps the data-minimisation position defensible under GDPR Article 9. The liveness layer beneath the estimation holds iBeta Level 3 conformance under ISO/IEC 30107-3, the point at which an age estimate stops describing the image and starts describing the person.
See how the escalation thresholds behave against your own traffic and jurisdictions, then book a 20-minute demo.
Frequently Asked Questions
Q1: Which US states have age verification laws?
Twenty-five states have enacted age verification laws for sites carrying material harmful to minors, per the Free Speech Coalition tracker as of August 2026. That count reflects laws passed rather than laws currently enforceable, since several face injunctions. No official government list exists.
Q2: Which countries require age verification by law?
The UK, France, Germany, Italy, Ireland, Australia, Brazil, Indonesia and Malaysia all impose live obligations as of August 2026, alongside 25 US states. The EU requires proportionate measures for minors under the Digital Services Act without mandating verification in general terms.
Q3: What is the penalty for failing to verify age?
Ceilings range from £18 million or 10% of revenue in the UK, to 6% of global turnover in the EU, to AU$49.5 million in Australia. Imposed UK penalties have so far run between £80,000 and £1.35 million, calibrated to operator size.
Q4: Does the UK Online Safety Act apply to companies based outside the UK?
Yes. Section 4 applies duties to any service with links to the UK, meaning a significant number of UK users, the UK as a target market, or usability in the UK combined with a material risk of significant harm. Ofcom enforces regardless of where a service is based.
Q5: What counts as highly effective age assurance?
Ofcom requires a process to be technically accurate, robust, reliable and fair, with no numerical threshold set. Open banking, photo-ID matching, facial age estimation, mobile network checks, credit card checks and digital identity services can qualify. Self-declaration cannot.
Q6: Do age verification laws apply to social media platforms?
Yes, increasingly. Australia bars under-16 accounts on age-restricted social media platforms, Malaysia requires verified registration for under-16s, and the European Commission has opened DSA proceedings against several social platforms over age assurance. Duties differ sharply by market.
Q7: Is age verification required for online alcohol and tobacco sales?
For tobacco and nicotine in the US, yes. The PACT Act requires verification against a government-sourced database outside the seller's control, plus photo ID at delivery. Alcohol direct-to-consumer shipping is state-governed and often relies on adult signature at delivery instead.















