us

216.73.217.78

Back
Blogs

What is Age Verification? The complete guide for Businesses in 2026

What is Age Verification? The complete guide for Businesses in 2026
Amir RizwanAmir Rizwan MAY 16, 2026 20 minutes read

TL;DR

 

  • Age verification proves a date of birth against evidence, not against a user’s word.
  • Age assurance is the wider category that regulators now legislate.
  • Ofcom logged over 69 million UK age checks across a 32-service sample in six months.
  • Ofcom excludes self-declaration outright, and Brazilian law prohibits it by statute.
  • Method choice is a legal question first and a friction question second.

Age verification is the process which confirms that a user meets the set minimum age threshold before granting access to a restricted product, service or category of content.

Verification tests the very claim against substantial evidence, that evidence can be a government-issued document, a biometric reading of the user’s face, or a record held in an authoritative database. It differentiates from a date-of-birth prompt in one decisive respect and differentiating from such a prompt is important because it merely records what the user typed.

That distinction stopped being academic for user-to-user and search services on 25 July 2025, when Ofcom’s protection-of-children duties under the UK Online Safety Act took effect and self-declaration ceased to satisfy the law. Between July and December 2025, Ofcom recorded more than 69 million age checks across a sample of 32 services operating in the UK, a 23-fold increase on the preceding half-year. This guide covers what the term actually means, how each method works, what the law now requires across five regions, and how to choose between the options.

What is age verification, and how does it differ from age assurance, age gating and age estimation?

Four terms circulate in this market and they are not interchangeable. Understanding this distinction is important because when it comes to writing obligations regulators tend to use one of them and businesses tend to procure using another, which is how a company ends up holding a control that does not discharge its duty.

Age assurance becomes the umbrella category. It covers any technical or procedural measure that establishes a user’s age or age band, at any level of confidence. Every other term on this list sits underneath it. Age verification, on the other hand, is the most rigorous form, it confirms a specific date of birth against documentary, biometric or authoritative-record evidence.

Age estimation gives a probable age band from a facial image or behavioural signals, without ever establishing who the user is. Age gating is the frontend mechanism that either blocks or admits, and on its own it verifies nothing at all.

Iain Corby, Executive Director of the Age Verification Providers Association, draws the line that most buyers miss. “Age verification is not identity verification,” he notes, since a properly designed check returns only a yes or no against the threshold rather than a name, an address or a document image. The industry is moving toward double-blind architectures in which the site never learns who the user is and the provider that checked the age never learns which site the user was visiting.

Method What it proves Evidence used Identity revealed Regulatory standing in 2026
Age assurance That a user is above or below a threshold, at a stated confidence Any of the below Varies by method The category regulators legislate in
Age verification A specific date of birth Document, authoritative record, or verified digital identity Usually yes, unless a privacy-preserving credential is used Accepted for the highest-risk categories
Age estimation A probable age band Facial image or behavioural signals No Accepted for some thresholds, rejected for others
Age gating A user’s stated age only Self-declaration No Generally insufficient where regulators require stronger age assurance

Michael Murray, Head of Regulatory Policy at the Information Commissioner’s Office, puts the last row plainly. On his account many companies still treat self-declaration as their primary control, and in his words “it’s just asking a kid to make up a date.” He points to ICO research finding that children, and often their parents, are complicit in giving an inaccurate age, which is why the mechanism fails even where nobody is acting maliciously.

The practical consequence is that businesses should read their obligation, identify which of the four the regulator has actually mandated, and procure to that. A useful companion read is our breakdown of age verification versus age assurance, alongside the narrower comparison of age gating versus age verification.

How does online age verification work?

Online age verification operates through a small set of established methods that are grouped into six families . Each carries a different evidentiary weight, a different friction profile, and a different volume of personal data collected. Regulators increasingly publish which of them they will accept, so the selection is constrained before commercial considerations enter.

Document-based verification

The user captures a government-issued identity document which ranges typically from a passport, national identity card, driving licence or a residence permit. Optical character recognition extracts the date of birth, forensic checks assess whether the document itself is genuine, and a liveness-checked selfie confirms that the person presenting the document is its holder.

Document verification remains one of the highest-assurance methods available and the default baseline across most industries that are regulated . It also carries the heaviest friction, because it asks the user to find a physical document and complete a multi-step capture.

Facial Age Estimation

An artificial intelligence model reads facial geometry from a selfie and returns a probable age band, with no document required and no identity established. The friction in this case remains relatively lower, which is one of the main reasons behind its adoption by social platforms at scale. However, accuracy remains a subject to multiple variations across demographics, and Ofcom now applies a further distinction between age estimation, which it accepts as capable of being highly effective, and age inference is drawn from account behaviour, about which it expressed serious doubts in July 2026.

Authoritative database and eIDV checks

Electronic identity verification matches user-supplied details against civil registries, telecoms records, credit bureau files or national identity databases. No document is uploaded and no biometric is captured, so the data footprint is small.

The method performs well in markets with mature identity infrastructure and degrades where database coverage thins out, which makes coverage in specific markets the question to ask rather than an aggregate country count.

Shufti’s overview of docless verification covers how the source layer behaves in practice.

Digital identity wallets

A wallet holds a credential issued by a trusted party and releases only the assertion the relying party needs. Under Regulation (EU) 2024/1183, member states must make EU Digital Identity Wallets available to citizens by the end of 2026. The European Commission’s age verification solution, which it nicknames the mini wallet and presents as a stepping stone to the full wallets, became feature-ready on 15 April 2026 and lets a user prove they are over 18 without the disclosure of any other information. Each proof is single-use, and the solution is designed so that the check cannot be repurposed for cross-service tracking.

Credit card checks

A credit card is issued only to adults in most jurisdictions, so possession of one carries a weak inference of age. Ofcom accepts credit card checks as capable of being highly effective, but it explicitly rejects payment methods that carry no adult requirement, which excludes ordinary debit cards. The method establishes nothing about the person holding the card, so it works best as one branch of a wider flow rather than as a sole control.

Open banking, mobile network operator and email-based checks

Open banking routes the check through a bank account held in the user’s name and returns confirmation that the account holder meets the threshold. Mobile network operators query whether a mobile contract carries an adult content filter or an age flag. Email-based age estimation infers a probable age band from how long and how widely an email address has been used across other services.

All three appear on Ofcom’s list of methods capable of being highly effective, and all three are strongest in domestic markets where the underlying infrastructure is dense.

Six families of age verification method

Tom Gadsden, VP of Product at Shufti, argues that no single method carries a real-world user base on its own. Some users have a document to hand and some do not, whereas a face is always available, which is why layered flows tend to offer a route rather than impose one. “We see the best rates come from putting choice in the hands of consumers,” he observes.

Why do businesses need age verification?

The case rests on four risk tracks that operate independently of one another, which means a single documented failure can trigger all four at once.

  • Regulatory exposure: Ofcom has opened 23 investigations into the providers of 88 adult services and has fined seven providers of 24 sites, the largest being a £1.35 million penalty against 8579 LLC. Those figures establish that enforcement in this category is active rather than theoretical. Ofcom has said it prioritises by risk of harm and by services growing their user numbers as a result of failing to put age checks in place, so size alone is no shelter.
  • Financial penalties beyond the fine itself: The Online Safety Act permits penalties of up to £18 million or 10 percent of qualifying worldwide revenue, whichever is greater.
  • Commercial consequences: Merchant account suspension, advertising partner withdrawal and app store removal follow documented underage access, and for licensed gambling operators the downstream risk extends to the licence itself. These consequences arrive faster than the regulatory process does, because commercial counterparties are not bound by procedural fairness.
  • Reputational damage: The affected users are children, so coverage of a failure in this category reaches mainstream audiences rather than staying inside the trade press. Recovery is slower than in an ordinary data incident because the harm is not abstract.

Corby’s view reframes where the risk actually sits. The underlying technology has generally held up, and the failures trace instead to providers “allowing their clients to turn some controls off.”

Which industries need age verification tools?

Regulatory pressure clusters around sectors where underage access produces direct harm, though the trend through 2025 and 2026 has been outward expansion into general-purpose platforms.

Industry Typical threshold Primary framework driving the requirement
Adult content 18 UK Online Safety Act Part 5; US state statutes; Brazilian Lei 15.211/2025 Art. 9
Online gambling and iGaming 18 to 21 by jurisdiction National gambling licences; UK Gambling Commission rules
Social media 13 to 16 Australian Social Media Minimum Age Act; EU DSA Art. 28; Brazilian Art. 24
Alcohol, tobacco and vaping e-commerce 18 to 21 National retail law; delivery-point verification duties
App stores and operating systems Varies Singapore IMDA code; Texas SB 2420; Brazilian Art. 12
Gaming and virtual goods 13 to 18 DSA Art. 28; national consumer and gambling rules where loot boxes apply
Financial services and crypto 18 KYC obligations, where age falls out of the identity check

Two segments deserve particular attention because their obligations are newer than their risk. Ivan Kurachkin, Partner at 4H Agency, points out that skin betting sites are often regulated as general digital marketplaces rather than as gambling, which leaves minors able to participate but under a lighter regime.

App stores have moved from being a distribution layer to being a regulated age-signal provider, a shift Singapore, Texas and Brazil have each legislated separately. Operators building for gaming and iGaming will encounter both.

What does the global legal landscape look like in 2026?

Age assurance law expanded across five regions between 2023 and 2026, and the frameworks differ enough that a single global configuration will not satisfy all of them.

United Kingdom

The Online Safety Act imposes duties in two waves. Services publishing their own pornographic content fell under Part 5 from 17 January 2025, whereas user-to-user and search services likely to be accessed by children came under Part 3 protection-of-children duties from 25 July 2025. Ofcom lists open banking, photo-identification matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation as capable of being highly effective. It lists self-declaration, payment methods with no adult requirement, and general contractual restrictions as incapable.

Ofcom’s Use of Age Assurance Report, published 15 July 2026, is the fullest picture of the regime in operation. The proportion of children asked to prove their age who encountered a highly effective check rose from 25 percent to 43 percent between July 2025 and January 2026, and 64 of the 100 most popular pornography services in the UK had deployed age assurance as of June 2026. Ofcom will report to Parliament by the end of October 2026 on extending highly effective methods to the over-16 threshold.

United States

The Supreme Court settled the constitutional question in Free Speech Coalition v. Paxton decided by six votes to three. The Court held that Texas House Bill 1181 is a permissible exercise of the state’s power to prevent minors accessing material obscene from their perspective, and that its burden on adults is incidental. The standard applied was intermediate scrutiny rather than strict scrutiny, this detail is worth mentioning because it to a certain extent defines how far comparable statutes can actually go.

No federal or state body has published an authoritative count of state laws, and the trackers the industry relies on do not fully agree with one another, so any single headline figure deserves caution.

Louisiana stood alone when its statute took effect on 1 January 2023, and by mid-2026 roughly half of US states had an adult-content age verification law past its effective date, West Virginia’s having taken effect on 12 June 2026. Separately, the Federal Trade Commission’s amendments to the Children’s Online Privacy Protection Rule took effect on 23 June 2025 with a full compliance deadline of 22 April 2026, and they expanded the definition of personal information to include biometric and government-issued identifiers.

European Union

Article 28 of the Digital Services Act requires appropriate and proportionate measures to protect minors. The Commission published guidelines on the protection of minors on 14 July 2025, applying to all online platforms accessible to minors other than micro and small enterprises. Those guidelines recommend age verification for adult content, pornography and gambling, and age estimation where a lower threshold applies. They are voluntary, and the Commission states expressly that observing them does not by itself guarantee compliance.

The privacy constraint sits alongside the safety duty. The European Data Protection Board adopted Statement 1/2025 on age assurance on 11 February 2025, setting out ten principles derived from Article 5 of the GDPR. Two of them carry the most operational weight. The method chosen must be the least intrusive available, and the age assurance process must not enable further profiling or targeting of the user.

Asia Pacific

Australia moved first from within the region. The Online Safety Amendment (Social Media Minimum Age) Act 2024 took effect on 10 December 2025 and requires age-restricted social media platforms to take reasonable steps to prevent Australians under 16 from creating or keeping an account. The eSafety Commissioner’s position is that self-declaration alone does not constitute reasonable steps, though the Act mandates no specific method.

Singapore legislated at the distribution layer. The Infocomm Media Development Authority’s Code of Practice for Online Safety for App Distribution Services required designated app stores to implement age assurance by 31 March 2026 and to prevent under-18 users from accessing the highest age-rated apps. India took a consent-based route instead, notifying the Digital Personal Data Protection Rules 2025 on 14 November 2025 with an 18-month phased compliance period, under which data fiduciaries must obtain verifiable parental consent before processing a child’s personal data.

Latin America

Brazil is the region’s decisive development. The Estatuto Digital da Criança e do Adolescente, was sanctioned on 17 September 2025 and came into force on 17 March 2026. Article 9 requires providers of content unsuitable for under-18s to adopt reliable age verification mechanisms at each access, and it expressly prohibits self-declaration. Article 12 obliges app stores and operating systems to ascertain a user’s age band through auditable measures and to expose an age signal to app providers through a privacy-by-default API. Article 24 requires social networks to link the accounts of users up to 16 to a guardian’s account and to suspend access where there are well-founded indications of underage operation.

The sanction regime reaches a simple fine of up to 10 percent of the economic group’s Brazilian revenue, capped at R$50 million per infringement, alongside temporary suspension and prohibition of activities. As of July 2026, no other Latin American jurisdiction has a confirmed equivalent requirement in force.

Standards worth tracking

Three technical standards are used to assess these systems, and one of them changed status recently enough that a good deal of published guidance has not caught up.

  • ISO/IEC 27566-1:2025, Age assurance systems, Part 1: Framework, was published on 12 December 2025 and establishes the framework and core characteristics for age assurance systems.
  • IEEE 2089.1-2024, IEEE Standard for Online Age Verification, was published on 24 May 2024 and covers the design, specification, evaluation and deployment of online age verification systems.
  • BSI PAS 1296:2018 was withdrawn on 4th January 2026, roughly three weeks after ISO/IEC 27566-1 appeared. Any vendor guidance still presenting it as current is out of date.

How do age verification methods compare on friction, accuracy and privacy?

No method wins on all three axes at once, which is the reason layered flows have become the norm rather than the exception.

Method Typical User friction Practical assurance Personal data collected Best suited to
Document verification Medium to High Highest Document image, biometric, full identity Regulated industries requiring documentary proof
Facial age estimation Very low to low Moderate, band-level Facial image, no identity High-volume gating well away from the threshold
Authoritative database check Low High where coverage is dense Name and identifiers, no biometric Markets with mature identity infrastructure
Digital identity wallet Very low High Only the age assertion EU markets, available now and broadening from end 2026
Credit card check Low Weak on its own Card data A supporting branch, never a sole control
Open banking Low to Moderate High Bank-held identity data Domestic markets with strong adoption
Mobile network operator check Very low Moderate Mobile number, no document Mobile-first markets with contract-level age flags
Email-based age estimation Very low Weak on its own Email address A first-pass signal ahead of a stronger check

One caveat on the assurance column. It reflects how much a method proves in practice, not how Ofcom classifies it, and the two diverge. Ofcom treats facial age estimation, credit card checks, mobile network operator checks and email-based age estimation as all capable of being highly effective, provided they are technically accurate, robust, reliable and fair in the specific implementation. A method can therefore be legally sufficient and still be weak on its own.

The pattern that follows from this table is a waterfall. Clear the large majority of users through the lowest-friction method available, then escalate only the sessions that sit near the threshold or fail a confidence test. Stephen Crystal, Founder and CEO of SCCG Management, describes the goal as reserving friction for the narrow group of users who genuinely warrant it.

How should you choose an age verification solution?

Evaluate against six criteria, weighted toward the markets you actually operate in rather than toward headline coverage figures.

  • Method coverage against your regulator’s published list: Confirm the provider supports the specific methods your regulator has named, in the jurisdictions where you operate. A method accepted in one country may be excluded in another.
  • Step-up architecture: Ask how the flow escalates, what triggers escalation, and whether thresholds are configurable by product, region and risk level. A single fixed flow cannot serve five regulatory regimes.
  • Resistance at the estimation gate: Facial age estimation is only as strong as the liveness and injection defences behind it. Ask specifically about high-resolution screen replays, deepfakes, and uploaded images pulled from the internet, because those are the attacks currently in circulation.
  • Independent evidence: Look for testing against ISO/IEC 30107-3 for presentation attacks, and treat conformance letters as dated artefacts rather than permanent claims. Ask for the letter and check its date.
  • Privacy architecture rather than privacy policy: The EDPB requires the least intrusive method available, so ask where biometric processing happens, what is retained, and for how long. On-device processing and single-use credentials answer this question structurally, whereas a policy commitment answers it contractually.
  • Dual-regulator readiness: The ICO’s Michael Murray has warned that one service can breach both the Online Safety Act and UK GDPR simultaneously. Complete a child access assessment, a risk assessment for both regulators, and a data protection impact assessment before deployment rather than after it.

One further point belongs in every vendor conversation with age verification providers. Ask which controls the provider will let you disable, and record the answer, because the bypasses reported to date have overwhelmingly involved controls that were switched off rather than controls that were defeated.

How Shufti handles age verification across jurisdictions

If you operate in more than one market, you have probably discovered that a single age check cannot satisfy every regulator at once. One jurisdiction accepts facial estimation for a given threshold, another demands documentary proof for the same content, and a third prohibits collecting identity data you do not strictly need.

Shufti’s age verification solution approach is a configurable waterfall rather than a fixed flow. Facial age estimation clears users who sit comfortably above the threshold, and the journey escalates automatically to an authoritative database lookup or full document verification when the confidence score falls below the level you set, per product, per region and per risk tier.

The estimation and liveness steps run on the user’s own device, so biometric templates are processed locally rather than server-side, which addresses the EDPB’s data-minimisation expectation at the architecture level. Shufti’s liveness detection holds iBeta Level 3 conformance under ISO/IEC 30107-3.

See how a configurable age verification waterfall behaves against your own thresholds and markets, then book a demo.

Frequently Asked Questions

What is the difference between age verification and age assurance?

Age assurance is the umbrella term for any measure that establishes a user's age or age band. Age verification is the strictest form within it, confirming a specific date of birth against documentary, biometric or authoritative-record evidence. Regulators write their duties using the broader term.

What is the difference between age verification and age gating?

An age gate is a frontend prompt asking users to state or confirm their age, and it tests nothing. Age verification checks the claim against independent evidence. Ofcom explicitly excludes self-declaration from its list of methods capable of being highly effective.

Is age verification legally required?

Yes, in a growing number of jurisdictions. The UK Online Safety Act, Australia's Social Media Minimum Age Act, Brazil's Lei 15.211/2025, Singapore's app store code and roughly half of US states now impose requirements. The specific obligation depends on your content category and your markets.

How accurate is facial age estimation?

Accuracy is band-level rather than exact, and it varies across demographic groups, which is why regulators accept it for some thresholds and not others. Ofcom treats facial age estimation as capable of being highly effective, while expressing serious doubts about behavioural age inference.

What documents are used for age verification?

Passports, national identity cards, driving licences and residence permits are the standard set, most of which carry a machine-readable date of birth and security features that can be checked forensically. Coverage varies by provider and by country, so confirm support for your specific markets.

Does age verification store personal data?

That depends entirely on the method and the architecture. A well-designed check returns only a yes or no against the threshold. On-device biometric processing and single-use cryptographic credentials allow a business to confirm eligibility without retaining a face image or a document.

How long does online age verification take?

Facial age estimation typically completes in seconds because it requires only a selfie. Database checks are comparably fast. Document verification takes longer, since the user must locate a physical document and complete a guided capture, which is why layered flows reserve it for escalated sessions.

What happens if a user fails age verification?

The service should deny access to the restricted content and offer an alternative route to prove eligibility rather than ending the session outright. Unlimited retries are dangerous, because attackers iterate until something passes. Cap attempts and log every outcome for audit.

Can age verification be bypassed with a VPN?

A VPN masks location but does not defeat the check itself, and VPN use leaves detectable signals, including a mismatch between the declared country and the country the IP resolves to, time-zone inconsistencies, and frequent IP changes. Ofcom also expects services not to signpost circumvention routes.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.