17.2 Age verification and age assurance

Parent weighing document upload and face-scan options for an age check.
Proving age can disclose much more than a date of birth.

Status reviewed 15 July 2026. Highly effective age assurance has applied to in-scope pornography and the strongest categories of content harmful to children since 25 July 2025. Further age checks have been announced for the planned under-16 social-media restrictions, but those future regulations are not yet in force.

What changed in 2025

For most of the internet's history, accessing age-restricted content in the UK often relied on self-declaration: a button that asked whether you were over 18 and took your word for it. That changed on 25 July 2025. In-scope services publishing their own pornography must prevent children from encountering it through highly effective age assurance. User-to-user and search services likely to be accessed by children must use highly effective age assurance to prevent children encountering pornography and the strongest categories of content harmful to children where that content is present. Self-declaration alone is not highly effective. Not every service must identify every visitor in the same way; the legal duty and proportionate method depend on the service and risk.

The shift was abrupt and widely felt. Major adult sites, social platforms with adult content, and a range of other services rolled out age gates within days of each other. For many people it was the first time the abstract idea of online regulation produced a concrete, personal demand: to continue doing something they had done freely the week before, they now had to upload a passport, scan their face, or route their identity through a verification company they had never heard of. The principle of protecting children from pornography commands wide support; the method by which it has been implemented is where the privacy problems begin.

How age checks actually work

The phrase "age assurance" covers several different techniques, with very different privacy characteristics. Understanding which is which is the first step to limiting your exposure, because some methods reveal far more than others and you sometimes have a choice between them.

Document verification

The most identifying method is document verification, where you photograph an identity document such as a passport or driving licence, sometimes alongside a liveness check. The source document contains more information than the service needs merely to know that a threshold is met. A well-designed system can have a specialist provider check the document, discard unnecessary fields, and return only an age-over-threshold token so that the content service never receives the document or name. A poorly designed system may retain document images, identifiers, account links, or transaction logs. Ask what the relying site receives, what the verifier retains, for how long, and whether the two parties can link repeat checks.

Facial age estimation

A less identifying method is facial age estimation, where a camera captures your face and software estimates your age from your appearance, returning only a "likely over 18" or "likely under 18" result rather than your identity. In principle this is more privacy-preserving, because it need not retain a name or a document. In practice, much depends on whether the image is genuinely processed and discarded on the spot or sent to and stored by a third party, how accurate the estimate is near the threshold, and whether the provider quietly keeps data for "model improvement". Estimation is also imperfect, so providers tend to set the bar a few years above 18 to avoid letting children through, which means many adults are wrongly rejected and pushed towards document checks instead.

Other methods

Other approaches include credit-card checks, mobile-network age confirmation, checks against banking or credit-reference data, and "reusable" digital identity wallets that you verify once and then present repeatedly. Each carries its own trade-offs. Card and bank-based checks tie your viewing to your financial identity. Reusable wallets reduce repeated document uploads but create a single, persistent record of an identity that is presented again and again, potentially building a profile of every gated service you visit. None of these methods is free of privacy cost; the question is only which costs you prefer to bear.

The privacy problem

The central concern is not the principle of keeping children away from pornography but the data trail a chosen method may create. A badly designed check can link identity evidence to sensitive online activity. A privacy-preserving design can separate the verifier from the content service and return only a yes-or-no age attribute, but the user still has to trust the separation, deletion, security, and logging claims. A breach of a verifier or relying site could be particularly harmful because identity evidence, biometrics, and intimate browsing interests are difficult or impossible to change.

There is also the problem of aggregation, the theme that runs through 1.3 and the whole of Chapter 1. A single age check is one record. But as more services adopt age assurance, and as reusable identity wallets spread, the same identity is presented across many contexts, and the potential grows for a joined-up picture of what a named individual reads, watches, and does. The danger is not any one disclosure but the slow construction of a comprehensive, identity-linked record of private behaviour, held across a patchwork of companies with varying competence and varying willingness to resist disclosure.

Finally, there is the chilling effect. People behave differently when they believe their private reading and viewing can be tied to their name. Lawful curiosity about sensitive subjects — sexuality, health, addiction, politics, religion — is exactly the kind of activity people will avoid if accessing it requires identifying themselves. That self-censorship is a real cost, borne disproportionately by the vulnerable, and it is rarely counted when these systems are assessed.

Scope creep: from adult sites to everything

The most important thing to watch is not where age assurance started but where it is going. The infrastructure is general-purpose and can gate many services or functions. In June and July 2026 the government announced an under-16 social-media restriction, stronger checks to identify under-16s, and default restrictions for older teenagers, subject to regulations that have not yet been made. That moves age assurance beyond pornography into mainstream participation. The exact services, methods, safeguards, and exemptions remain policy and regulatory questions, as explained in 17.6.

This is the pattern to recognise across the whole chapter: a measure is introduced for a narrow, sympathetic purpose, the infrastructure is built, and the scope then expands because the hard part — building the system and normalising it — is already done. Watching for this is not cynicism; it is simply paying attention to how such systems have historically evolved. The reasonable response is to support narrow, genuinely protective measures while resisting the open-ended attachment of identity to ordinary online activity.

Reducing what you expose

Where an age check applies, minimise what you reveal. Prefer a method that returns only an age attribute and does not give the content service an identity document. Facial estimation may collect less identity data than document verification, but it still processes an image and can be inaccurate or biased near a threshold. Read the verifier's notice for retention, reuse, human review, appeals, and deletion. Do not assume a certification logo proves that no logs exist. Avoid linking the check to a main email or identified account unless the service genuinely requires that link.

Using a VPN is not generally prohibited in the UK, and a non-UK exit may mean a location-triggered UK age gate is not shown. That does not make every use lawful or contractually permitted: the underlying content and conduct still matter, a service may prohibit location circumvention in its terms, and adults must not help children defeat protections. This site does not give case-specific legal advice. The policy debate about restricting children's VPN access is covered in 17.4, and VPN capabilities and limits in 5.2.

You retain data-protection rights. An age-assurance provider must have a lawful basis, process data fairly and transparently, minimise collection, limit reuse, secure the data, and respect applicable rights. The ICO says that in many cases viewing an official document may be excessive where a less revealing method can achieve the purpose. Complaint and access routes are explained in 17.8.

Primary sources: Ofcom's implementation dates, ICO age-assurance and data-minimisation guidance, and the March 2026 ICO/Ofcom joint statement.