Age assurance is a term familiar to regulated businesses that have recently been hit by millions worth of fines for not sticking to new requirements for verifying minors online. It’s also a well-known term among youngsters who aren’t happy about the new requirements of mandatory age confirmation and a ban if they don’t reach a certain threshold. Regulations like the UK’s Online Safety Act now have defined, clear rules on age assurance, pointing out that weak measures like age gating aren’t considered compliant. But this isn’t only about regulations.
Popular games and platforms like Roblox indeed need to ensure that their players, who are often children, are safe online and protected from adults posing as minors or other inappropriate interactions that, unfortunately, are still common in the online world. Otherwise, not proving and verifying how old your users are can result in weak age assurance systems and, later on, in fines for non-compliance and for not ensuring that the users are safe.
In brief:
- Age assurance is a broader definition and term describing various methods to verify and prove how old a user is before allowing them to access a certain platform or service.
- Regulators and governments around the world have been enforcing stricter age assurance requirements. This includes different industries, such as social media sites or gaming platforms.
- Some businesses aren’t complying and are still using weak age assurance systems, which then leaves them with non-compliance fines due to not being able to securely block children from seeing harmful content.
I review the main age assurance methods that businesses use and look at the major fines that can result when the wrongly chosen and weak approach fails.
What is Age Assurance?
Age assurance is the process of verifying a person’s age online, often used in the context of mandatory age verification compliance for businesses and protection of minors on the internet. Over the years, age assurance methods were known to be part of adult-only sites, but this has changed. Age assurance processes are now specifically targeted to teens and minors under 18 because they are the group that’s the hardest to verify sometimes, especially if age estimation (determining a person’s age using their facial features and the way they look) is used.
Age assurance aims to help companies:
- Establish clear age assurance systems, verifying that users are old enough to access age-restricted services, items, or content online.
- Protect minors and young individuals from inappropriate content online, which can be harmful to this sort of age group.
This means social media platforms, gaming sites, and similar sites are now required to verify their users’ age via age assurance processes. However, it depends on the jurisdiction, as some countries don’t specifically explain which assurance methods to use, or the rules are still ambiguous, allowing businesses to decide which option works best for their platform.
Related: KYC in Social Media: Less Anonymity = More Security?
Automate your identity verification
See how iDenfy helps 1,000+ companies verify customers in seconds with AI-powered KYC.
Explore iDenfyWho is Responsible for Age Assurance?
If you’re a regulated entity and a platform that falls under age assurance requirements, you’re responsible for ensuring that all users are of age and can access your platform only after verification. However, the responsibility falls on regulators and technology service providers, such as iDenfy, because:
- Regulators are responsible for defining the legal age assurance and verification requirements that help companies to implement compliant and acceptable measures.
- Age assurance service providers are responsible for offering reliable and easily implemented, privacy-conscious third-party tools that are in line with the requirements of regulators in all operating markets.
For example, the EU’s Better Internet for Kids advocates for this approach, stressing that companies “must make sure their age assurance methods work well, include everyone, and keep your data safe.” Additionally:
“Companies should regularly test if these checks are working as intended and make changes if they’re not protecting children well enough.”
Related: Age Verification in Online Dating: Why You Should Take It Seriously
What are the Key Age Assurance Methods?
There’s a difference between the most popular age assurance methods; for example, if we compare the level of strictness in the end-user flow or the overall accuracy in determining the user’s age. Here are the main types:
1. Age Gating
Age gating is considered to be the least safe age assurance method because it leaves the responsibility on the user, hoping they won’t lie about their age. An age gate is a simple pop-up, for example, a window that’s displayed once you enter an age-restricted site, such as an alcohol e-commerce shop, which then asks you, “Are you over 21?”, and if you respond by clicking on “Yes”, you’re instantly welcomed to the site. Minors easily bypass this self-declaration type of “gate” because it doesn’t require extra effort.
In contrast, Know Your Customer (KYC) systems are often programmed to have real-time biometric checks that scan a person’s real face and compare it with the real photo on their ID document, which is why deepfakes are also very popular as a way for fraudsters to use generative AI to bypass verification attempts. Age gates are bypassed by minors and those who don’t have special tech skills.
2. Age Estimation
Age estimation is currently one of the most commonly used age assurance methods because it’s designed not to add friction to the end-user experience but is still considered to be a safe mechanism to verify and approve user age.
The “Estimation” aspect means that the system returns an estimated result (for example, over 18 or over 21) rather than a concrete age or date of birth that the person provided online. In practice, this is possible due to the system asking the user to capture a live selfie, similar to how a standard biometric check in KYC onboarding works. Then, based on biometrics and the user’s facial features, their age is determined using special algorithms to calculate the age.
It’s important to find a good age estimation service because accuracy matters, and some solutions aren’t properly trained and might have racial bias or determine the age wrongly due to the person looking older for having facial hair, grey hair, wrinkles at a young age, etc. The industry standard is 3 years (but some solutions like iDenfy provide a 2.5-year threshold for better accuracy) since no age estimation solution can be 100% accurate all the time, and if a sales representative says otherwise during a demo call, take it as a red flag.
3. Age Verification
Age verification is the process of triggering a document-based age check, where the user is asked to capture their passport/ID card or driver’s license. The system then extracts the user’s date of birth and clearly determines the user’s age and whether they can access the age-restricted site. Most age verification measures are paired with a biometric check and are very similar to the standard KYC onboarding flow, which is often used by fintech, crypto, or other regulated platforms as a way to verify the person’s identity.
In this case, the relevant information is the age in particular. However, age estimation, for example, doesn’t store the user’s data and doesn’t have any additional info on the user’s whole identity. Age verification does, and that’s why it’s considered to be the most secure, but a less user-friendly age assurance method due to the burden on the user and the fact that they have to provide a copy of their physical ID document.
-> Keep in mind that neither is a bad or good age assurance method; the one you choose depends on your industry’s requirements. A social media site might implement an age estimation tool that determines if the user is at least 16 years old, while an adult content platform will need to check both users’ and content creators’ IDs to ensure security and compliance.
4. Digital ID or eID Verification
A digital ID, or an electronic ID, is a national identification method that varies depending on the country. The EU has various methods, including MitID, Smart-ID, or Swedish BankID, among others, like CLEAR1 for the US or OneID for the UK. Different from standard age verification checks, this approach can be used for age assurance purposes, but it doesn’t require the user to carry their physical ID document. The system already has the credentials (including the verified DOB) and onboards the user faster.
This is the biggest benefit of this verification measure, as it’s considered to be familiar, user-friendly, and safe. Since users trust their national IDs more and use them for daily services like banking, they are more likely to convert and complete your triggered age assurance step, as opposed to seeing a third-party provider or a new window that redirects them and asks them to enter personal information. According to our research and iDenfy’s statistics, eIDs convert at least 15% more users than a doc-based age assurance method.
The Biggest Fines for Businesses Due to Weak Age Assurance
The price tag for non-compliance with recent age assurance standards is high, and some major businesses have already paid for it:
Earlier in February this year, the ICO, the UK’s data protection authority, fined Reddit £14.47 million for failing to keep up with children’s privacy regulations, including ensuring a proper age assurance system. The social media mogul’s Terms & Conditions clearly prohibited users under 13 years old. However, after investigation, it appeared that no age assurance measures were actually enforced, and Reddit’s users simply declared that they were ‘over 18’.
This led to the fine and the fact that the platform was fined for processing under-13s’ personal data non-compliantly. Currently, Reddit has implemented a third-party KYC vendor and has the right to trigger a KYC check after the initial account creation stage (that means even in cases when the user’s account is a few years old).
Epic Games
The Federal Trade Commission (FTC) issued a penalty worth $275 million (part of a $520 million settlement) due to Children’s Online Privacy Protection Act (COPPA) violations for Epic Games, best known for Fortnite. The video game giant collected personal information from kids who were under 13 and did not get verifiable parental consent. The default system was set wrongly, without proper age assurance and data security measures, exposing minors to voice/chat features and leading to contact with strangers.
Roblox
Roblox faced a non-compliance fine worth approximately $12.5 million, but a settlement was reached earlier in April, 2026. Even though Roblox announced mandatory age assurance and age checks in November 2025, regulators still opened an investigation due to the possible risks to minors, such as access to harmful content or contact with bad actors.
As a result, the platform then agreed to step up and improve its age assurance system, adding doc-based government ID submission and facial age estimation into its system, along with other measures, such as behavioral monitoring and no encrypted messages to minors below the allowed age limit.
AVS Group
Ofcom assessed AVS Group’s age assurance controls, which were not good enough, as the company manages multiple adult-only sites that need to ensure that no minors bypass their measures, which, in reality, appeared to be the opposite case. The non-compliance penalty resulted in £1 million plus more than £50,000 (£300 per day for failing to answer a statutory information request).
The main issue was that the sites had a photo upload age assurance check but did not use liveness detection and selfie biometrics, only later adding this second layer once the fine was given. Minors used this crack in the system to pose as adults and used fake photos of older individuals. No liveness meant that the age assurance measures were not enough for sites that are not suitable for minors. Also, an important note is that AVS hasn’t paid, and based on Ofcom’s recent updates (from March 2026), the case is still set as “Open”, as Ofcom is “considering next steps for recovery”.
Regulations That Require Age Assurance Methods
Age gates and other age assurance methods that are based on self-declaration aren’t enough in jurisdictions where regulatory requirements are stricter on this subject matter. Here are some examples:
- The Digital Services Act (DSA) (EU). The DSA requires “appropriate and proportionate” age assurance measures for platforms that offer age-restricted items or services. On top of that, the European Commission recommends that self-declaration alone is also an ineffective age assurance method.
- The SREN Law and Arcom’s framework (France). The country has set one of the most stringent age assurance requirements among EU member states. It requires age-restricted platforms to implement multiple age assurance methods, including at least one third-party tool that specifically ensures that user anonymity is protected.
- The Online Safety Act 2023 (UK). Age-restricted platforms and sites in the UK need to apply “effective age assurance”, describing self-declaration and age gates (tick-box age declarations) as a non-compliant measure. In this sense, the UK has one of the clearest rules regarding this matter.
- State Age Verification laws and COPPA (US). Nationwide age assurance laws in the US aren’t a thing, as each state has its own requirements. For example, the Texas Age Verification Law (HB 1181) is one of the most prominent age assurance law examples, requiring age-restricted firms to use a government-issued ID method or another “commercially reasonable” age assurance solution.
- The Online Safety Amendment (Social Media Minimum Age) Act 2024 (Australia). It requires regulated businesses to take “reasonable steps” to prevent users from creating accounts if they are under 16. The recommended approach for age assurance is a combination of methods so that bypassing would not be an option.
Some major sites have pushed back against regulators’ wishes, banning their sites in certain jurisdictions, both in the EU (for example, France and the US (some states), claiming that age assurance laws are getting “too restrictive” compared to other countries. Another side of the narrative is that businesses claim that user rights and data security are at risk if the wrong age assurance method is used and, as a result, genuine, adult users drop off, not just kids trying to bypass the age check.
How Do I Know If My Age Assurance System Works?
A good age assurance system that works is the one that prevents minors from accessing age-restricted content but is still relatively easy on the user, so that it doesn’t cause unwanted friction for adults who are really just trying to access your service legally. The key factors that you need to consider both when implementing a third-party age assurance solution or building your own system are: data protection and compliance in every operating market.
If your firm is global and you want to scale, you’ll want a RegTech partner like iDenfy, which covers multiple regions and specializes in age assurance compliance. If you’re a smaller e-commerce shop owner that offers its customers vape and CBD products, the best option is to implement a more native solution, such as a specialized Shopify plugin for age verification (or any other ready-made age assurance app that’s easy to integrate, based on your platform’s environment).
| Your situation | Our recommended workflow |
|---|---|
| You operate globally and plan to scale across multiple regulated markets | A full RegTech partner like iDenfy, where thresholds, methods, and retention rules can be configured per region. One integration covers every market instead of a separate vendor and a separate audit trail for each one. |
| You run a small e-commerce store on a hosted platform, selling vape, CBD, or alcohol | A ready-made plugin or app native to your platform, such as a Shopify/WooCommerce age verification app. Setup takes minutes, needs no developer, and matches the order volume you actually process. |
| You serve UK users and fall under the Online Safety Act | An estimation-plus-fallback flow, not estimation alone. Ofcom’s “highly effective” standard is difficult to meet with a probabilistic check on its own, so borderline results must escalate to a document or credential check. |
| You already run KYC or AML onboarding (iGaming, fintech & other regulated marketplaces) | Age checks folded into the existing IDV flow. The date of birth comes out of the document you already collect, so a separate age gate adds friction without adding assurance. |
| You have a large existing user base that now needs to be re-checked | Facial age estimation first, with document verification reserved for the buffer zone. At retroactive scale, asking every user for an ID is the fastest way to lose them. |
If users are dropping off, or you’re not ready for regulations that are getting stricter, the transition will be harder, so it’s better to identify the gaps in your current age assurance workflow and add new ones (via a reliable, compliant solution), using the sandbox environment and testing, as well as trying to set up different verification workflows based on your country’s/platform’s requirements. If the solution doesn’t offer this sort of white-label options and flexibility, determine if it will be enough for your platform, as this factor heavily impacts user conversions.
A Good vs a Weak Age Assurance Solution
I also added a short checklist that will help you differentiate a good vs a weaker age assurance system. A well-designed solution should have:
-> An accurate ratio with a maximum threshold of 3 years for the age estimation method. -> Good statistics for the most vulnerable group of individuals aged 15-30 for facial age estimation (since they are the hardest to identify due to still looking young in some cases).
-> Option to trigger different age assurance workflows, including an auto ID document verification with auto DOB extraction (in cases when the estimation comes out as inconclusive and you don’t want to risk onboarding a minor).
The good news is that iDenfy has all these features on its Age Verification hub and provides both doc-based and non-doc age assurance workflows with selfie biometrics and accurate estimation. iDenfy’s Age Estimation determines the user’s age but does not store any unnecessary information, aligning with both age check requirements and data security standards.