Age assurance is the umbrella term for any method that establishes how old an online user is, or at least whether that user sits above or below a given threshold. It covers document checks, facial analysis, behavioural signals and plain self-declaration, and it exists because a growing body of law now conditions access to content, product features and advertising on the age of the person at the other end of the connection. The second word carries the weight. Assurance describes a spectrum of confidence rather than a binary proof, and the gap between those two ideas is what regulators, platforms and vendors have spent the past three years arguing over.

Four methods and a confidence scale

ISO/IEC 27566-1:2025, published in December 2025 by ISO/IEC JTC 1/SC 27 as the first international framework standard for the field, runs to 29 pages and sorts the practice into four concepts. Age verification confirms age against an authoritative record: a passport, a national identity card, a bank's file on an account holder. Age estimation produces a likely age from biological or behavioural characteristics, most often by analysing a face. Age inference derives age from information already held, such as an email domain, an account creation date or a purchase history. Successive validationrepeats checks through a session rather than testing once at the door.

IEEE 2089.1-2024, published in May 2024 as the second standard in the 5Rights family, approaches the same problem from the assurance side. According to the 5Rights Foundation, it sets requirements for four levels of confidence, described as asserted, standard, enhanced and strict, which a service matches to the risk its content poses. Vendor implementation guides describe a five-level scale that inserts a basic tier below standard, a discrepancy worth checking against the published text.

What a check returns matters as much as how it runs. A well-built system answers an eligibility question and discards the evidence. The European Data Protection Board's Statement 1/2025, adopted on 11 February 2025, describes an architecture in which a third-party provider performs the check and issues the user an age token, which the user then presents to the service without proving anything again. The relying party learns that a threshold was met. It does not learn a birthdate.

What a regulator counts as good enough

Ofcom set the most detailed public benchmark. Its guidance on highly effective age assurance, published on 16 January 2025 under the Online Safety Act 2023, names the methods it considers capable of meeting the standard: open banking, photo-ID matching, facial age estimation, mobile network operator checks, credit card checks, digital identity services and email-based age estimation. Self-declaration is excluded outright, as are payment methods available to under-18s. Each deployment is then measured against four criteria: technical accuracy, robustness, reliability and fairness, the last defined in terms of avoiding lower accuracy for particular ethnicities.

The mechanics are unglamorous. Photo-ID matching pairs a document capture with a live image, and Ofcom expects liveness detection so that a child cannot present a still photograph of an adult. Estimation methods are expected to use a challenge age, set above the legal threshold, to absorb the model's error margin. Australia's Age Assurance Technology Trial tested more than 60 solutions from 48 providers between November 2024 and its final report on 31 August 2025, using over 1,000 schoolchildren and adult mystery shoppers. Its conclusion was blunt: no single technology suits every use case. Layered designs, sometimes called waterfall approaches, that fall back from inference to estimation to documents perform better than any one step alone.

Where the check meets the ad request

For buyers and sellers the practical consequence is not the check itself but what it switches off. Article 28(2) of the Digital Services Act prohibits presenting advertisements based on profiling when a provider is aware with reasonable certainty that the recipient is a minor. Article 28(1) requires proportionate measures for the privacy, safety and security of minors, and the European Commission's guidelines of 14 July 2025 recommend age assurance that is accurate, reliable, robust, non-intrusive and non-discriminatory.

Signalling infrastructure has followed. Google replaced the tagForChildDirectedTreatment and tagForUnderAgeOfConsent settings with a single tag for age treatment, or TFAT, on 18 May 2026, carrying the values CHILD, TEEN and UNSPECIFIED across the Google Publisher Tag, the Google Mobile Ads SDK and the Interactive Media Ads SDK. On the device side, Apple's Declared Age Range API returns an age band rather than a birthdate, using the categories written into Texas Senate Bill 2420: under 13, 13 to 15, 16 to 17, and over 18.

The revenue effect is visible where checks have landed. Reddit switched every teenage account in the European Union to restricted chat and disabled advertising personalisation when its age checks began on 24 June 2026, across the 27 member states plus the European Economic Area and Switzerland. Verification runs through Apple, Google or Persona. Meta reported removing 756,000 under-16 accounts in Australia in seven months, split between 462,000 on Instagram and 294,000 on Facebook through 30 June 2026, under a ban covering nine named platforms since 10 December 2025.

Origin and evolution

Self-declared age gates date to the commercial web of the 1990s and remain the default on most services. The Children's Online Privacy Protection Act of 1998 made the under-13 threshold commercially meaningful in the United States without specifying how operators should find it. Pressure to replace the birthdate form field arrived with the UK Online Safety Act, which received Royal Assent on 26 October 2023 and whose adult content duties became enforceable on 25 July 2025.

Measurement matured alongside. The National Institute of Standards and Technology first evaluated automated age estimation in 2014 and reopened the work as the Face Analysis Technology Evaluation Age Estimation and Verification track, published as NIST Interagency Report 8525 on 28 May 2024. It tests algorithms against roughly 11 million photographs drawn from visa applications, border crossings and arrest records. On the visa dataset used in both rounds, mean absolute error fell from 4.3 years in 2014 to 3.1 years, a gain of roughly 28 percent over a decade. Results were last refreshed on 26 February 2026.

Limitations and disputes

Accuracy degrades exactly where regulation needs it most. Ofcom's March 2026 consultation on children's online lives conceded that while current techniques separate adults from under-18s reasonably well, far fewer solutions can tell a 14-year-old from a 16-year-old, and facial estimation performs worse at younger ages. The Meta settlement with US states makes that tolerance explicit: commercially available methods must hold false positive rates of 10 percent for 16 and 17 year olds and 3 percent for 13 to 15 year olds, with proprietary methods starting at 14 and 7 percent. A negotiated error rate for classifying children as adults is now written into a federal judgment.

Data protection law pulls the other way. The EDPB's Guidelines 3/2025 record the position that providers should not estimate, verify or permanently store a user's age, and should instead record qualification status. Knowing with reasonable certainty that a user is a minor, as Article 28(2) requires, means processing the very data the guidelines discourage retaining.

Classification of the underlying biometrics is unsettled between national regulators. The UK Information Commissioner's Office has accepted that facial age estimation used purely for categorisation is not Article 9 processing. Spain's data protection authority took the opposite view of retained facial templates, and Yoti announced on 3 September 2026 that it will pull its Digital ID app from Spanish app stores on 10 September rather than remove the biometric step, following a 950,000 euro penalty.

Circumvention is measurable. According to Ofcom's consultation, UK VPN use more than doubled after the July 2025 rollout, from around 650,000 daily users to a peak above 1.4 million in mid-August, following a signup surge Proton VPN put at over 1,400 percent within hours. And courts have begun testing the architecture itself. France's Constitutional Council struck down the country's under-15 social media ban on 14 August 2026, holding in decision 2026-911 DC that any threshold on a general-purpose service obliges every user, adults included, to prove age, and that the legislature had written no framework for how.

Adjacent terms

Age verification is one method inside age assurance, not a synonym: it checks against an authoritative record, while assurance also covers estimation and inference. An age gate is the interface element that presents the challenge, whatever sits behind it. Identity verification, the process banks and marketplaces run to establish who a person is, resolves an individual; age assurance need only answer whether a threshold is met, and good design keeps the two apart. Age ratingclassifies content rather than users, and made for kids designations and the TFAT parameter describe content or an ad request, not a determination about the individual viewing it.

Recent developments

The European Commission published its age verification blueprint on 14 July 2025, declared the software feature-ready on 15 April 2026, and adopted a recommendation on 29 April 2026 urging member states to deploy national apps by 31 December 2026. The instrument carries no penalty for missing the date. Documents released in July 2026 showed the Commission held no privacy impact assessment written for the app. In the United States, the Federal Trade Commission granted age-verification technology a conditional COPPA enforcement shield on 25 February 2026 for operators collecting children's data solely to determine age. The Court of Justice of the European Union ruled on 16 June 2026, in Joined Cases C-188/24 and C-190/24, that member states may compel age checks from platforms established elsewhere in the bloc.

Timeline

  • 1998: The Children's Online Privacy Protection Act establishes the under-13 threshold in United States law
  • 2014: NIST publishes its first evaluation of automated age estimation, NISTIR 7995
  • 26 October 2023: The UK Online Safety Act receives Royal Assent
  • 28 May 2024: NIST publishes the first FATE Age Estimation and Verification report, NISTIR 8525
  • May 2024: IEEE 2089.1-2024, the standard for online age verification, is published
  • 16 January 2025: Ofcom publishes guidance on highly effective age assurance
  • 11 February 2025: The EDPB adopts Statement 1/2025, setting ten principles for age assurance
  • 14 July 2025: The European Commission publishes Article 28(1) guidelines and the EU age verification blueprint
  • 25 July 2025: Adult content duties under the Online Safety Act become enforceable
  • 31 August 2025: Australia's Age Assurance Technology Trial publishes its final report
  • 11 September 2025: The EDPB adopts Guidelines 3/2025 on the DSA and the GDPR
  • 10 December 2025: Australia's under-16 social media ban takes effect across nine platforms
  • December 2025: ISO/IEC 27566-1:2025 is published as the first international age assurance standard
  • 25 February 2026: The FTC issues its COPPA policy statement on age verification technology
  • 15 April 2026: The Commission declares its age verification app feature-ready
  • 29 April 2026: The Commission recommends member state deployment by 31 December 2026
  • 18 May 2026: Google introduces the TFAT signal, retiring TFCD and TFUA
  • 16 June 2026: The CJEU rules on cross-border age verification in Joined Cases C-188/24 and C-190/24
  • 24 June 2026: Reddit begins EU age checks and disables teen ad personalisation
  • 14 August 2026: France's Constitutional Council strikes down the under-15 ban in decision 2026-911 DC
  • 10 September 2026: Yoti's Digital ID app leaves Spanish app stores

Summary

Who: Platforms and publishers that must determine user age, the specialist vendors supplying the checks, and the regulators setting the standard, principally Ofcom, the European Commission, the European Data Protection Board, national data protection authorities, Australia's eSafety Commissioner and the Federal Trade Commission. Advertisers and agencies sit downstream, since the result determines which inventory can be personalised.

What: A set of methods for establishing a user's age or age band, grouped by ISO/IEC 27566-1:2025 into verification against authoritative records, estimation from biological or behavioural characteristics, inference from held data, and successive validation across a session. Confidence levels and evaluation criteria are set by IEEE 2089.1-2024, Ofcom's four tests, and NIST's ongoing accuracy benchmark.

When: Self-declared gates date to the 1990s. The current regime formed between January 2025, when Ofcom published its guidance, and December 2025, when the first international standard appeared. Enforcement dates cluster through 2025 and 2026, with the Commission's recommended national deployment target falling on 31 December 2026.

Where: The United Kingdom under the Online Safety Act, the European Union under Article 28 of the Digital Services Act, Australia under its minimum age regime, and a widening group of US states through app store and social media statutes. Deployments are frequently global, because platforms apply a single configuration rather than a per-market one.

Why: Legislatures decided that self-declaration failed as a control and that platforms should carry the burden of knowing who is a child. The unresolved problem is that establishing age reliably requires processing more personal data, at a moment when data protection law is pushing in the opposite direction, and that the accuracy needed to separate a 14-year-old from a 16-year-old does not yet exist at population scale.