TL;DR: Its MyFace passive liveness model achieved 0% APCER and 0% BPCER at both ISO 30107-3 Level 1 and Level 2 in iBeta testing, according to Yoti, while its facial age estimation received a smaller German buffer and showed 0.6% false positives for 13 to 17 year olds. The governance question is no longer whether these controls work in isolation, but how identity programmes balance assurance, user friction and policy choice across verification routes.
At a glance
What this is: The post argues that digital identity verification is shifting toward lower-friction liveness and age assurance, with performance, buffer settings and user choice now shaping governance decisions.
Why it matters: It matters because IAM and identity verification teams need controls that are accurate enough for compliance yet usable enough to scale across age checks, right-to-work flows and consumer identity journeys.
By the numbers:
- Yoti says its MyFace passive liveness model correctly detected every Level 1 attack in 450 tests and every Level 2 attack in 375 tests without incorrectly rejecting genuine users.
- 13 to 17 year olds is 0.6%
- Yoti says 60% of 18 year olds and 80% of 19 year olds pass an over-17.5 check, showing how threshold design changes user flow.
👉 Read Yoti’s analysis of liveness testing, age assurance and digital ID choice
Context
Digital identity verification depends on whether a system can reliably tell a live person from a spoofed presentation, and whether it can infer age or identity with enough confidence to support policy decisions. In this article, the primary issue is not the model itself but the governance trade-off between assurance, user friction and acceptable error rates in identity verification.
For IAM programmes, this sits at the intersection of human identity proofing, age assurance and regulatory enforcement. The practical question is how to design identity checks that are strong enough for right-to-work, age-restricted content and consumer onboarding without creating unnecessary failure rates or pushing users toward weaker workarounds.
The article also points to a broader policy shift: private-sector digital ID, government digital ID and physical documents are increasingly being treated as interchangeable routes to the same trust outcome. That is a typical direction of travel for modern identity ecosystems, but it raises new questions about consistency, evidence quality and auditability.
Key questions
Q: How should organisations balance age assurance accuracy with user friction?
A: Use a risk-based threshold model. For low-risk journeys, minimise friction with passive checks and narrow step-up triggers. For higher-risk or regulated flows, accept more user friction if it materially reduces misclassification. The right balance depends on the policy objective, the harm of false positives and the evidence source available for escalation.
Q: Why do biometric verification systems need policy buffers?
A: Because model outputs are probabilistic, not absolute. A buffer gives the organisation room to tolerate uncertainty when deciding whether to allow access or request stronger evidence. Without a buffer, small model errors can either block legitimate users or let underage or unverified users through.
Q: How do security teams evaluate whether liveness detection is strong enough?
A: Look for measurable resistance to presentation attacks, defined false accept and false reject rates, and testing that reflects the real environment where the control will run. A good evaluation also includes exception handling, logging, and whether staff can bypass the control when operations become urgent.
Q: Who should be accountable when multiple digital ID routes are accepted?
A: The organisation that sets the acceptance policy remains accountable for how those routes are validated and documented. If government ID, private-sector ID and physical documents are all acceptable, teams must define equivalence, audit trails and escalation rules so the decision can be defended later.
Technical breakdown
Passive liveness detection and ISO 30107-3 PAD
Passive liveness asks a user to present a face to a camera without active prompts, then applies presentation attack detection to decide whether the input is genuine or spoofed. ISO 30107-3 defines PAD performance testing, including Attack Presentation Classification Error Rate and Bona Fide Presentation Classification Error Rate. The significance here is that passive systems improve usability, but they must still prove they can resist replay, mask and other presentation attacks at defined assurance levels.
Practical implication: identity teams should treat liveness as a measured control with assurance thresholds, not a generic front-end feature.
Facial age estimation, thresholds and buffer policy
Facial age estimation infers an approximate age range from biometric input, then applies a threshold or buffer to decide whether further verification is needed. A narrower buffer increases user convenience, but it also raises the risk of false positives, where minors are estimated as older than they are. The governance challenge is not just model accuracy, but how policy sets the boundary between acceptable friction and unacceptable misclassification for a given use case.
Practical implication: teams should map age thresholds to regulatory tolerance, not just vendor accuracy claims.
Digital ID choice and trust routing
The article describes multiple identity proofing routes, including government digital ID, certified private-sector digital ID and physical documents. The technical issue is trust routing: which evidence source is accepted, how it is checked against a government or authoritative database, and whether the resulting assurance is equivalent across paths. This matters because the control is no longer a single credential format, but a policy model that must recognise several proofing mechanisms while preserving auditability.
Practical implication: architects should document which proofing routes are equivalent, which are conditional, and which require step-up verification.
NHI Mgmt Group analysis
Age assurance is becoming a policy engine, not just a model test. The article shows that the real decision is how much confidence is required to gate access, not whether a biometric model can produce a score. That shifts age verification into the same governance territory as authentication assurance, where threshold selection, exception handling and evidence quality matter as much as model performance. Practitioners should treat age estimation as an identity control with explicit policy boundaries.
Digital identity programmes are moving toward evidence portability. The discussion of government IDs, certified private-sector IDs and physical documents points to a world where multiple credentials can satisfy the same trust requirement if the checking rule is consistent. That creates a governance burden: organisations must define which routes are acceptable for which transactions and how those routes are validated against authoritative sources. Practitioners should expect more interoperability pressure, not less.
Low-friction verification only works when the false-positive cost is managed. The article’s buffer discussion shows that reducing user friction is valuable only if the resulting misclassification rate remains acceptable for the policy goal. That is especially relevant in age-restricted access, where too many false negatives frustrate legitimate users and too many false positives weaken enforcement. Practitioners should measure verification by downstream policy success, not just completion rate.
Personal identity controls increasingly resemble IAM governance problems. Whether the subject is a selfie, an identity document or a wallet credential, the same discipline applies: prove the subject, set the threshold, and verify the result against a trusted source. The named concept here is evidence routing: the selection and validation of acceptable identity proofing paths for a specific policy objective. Practitioners should design for route governance, not one-off verification events.
From our research:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which helps explain why identity proofing and verification governance so often outruns operational visibility.
- For lifecycle context, see NHI Lifecycle Management Guide, which covers provisioning, rotation and offboarding patterns that govern non-human access.
What this signals
evidence routing: identity teams are moving toward policy-driven acceptance of multiple proofing routes, which means the governance burden shifts from a single credential check to route-level assurance, logging and exception handling. That is where standards such as NIST SP 800-63 Digital Identity Guidelines become more operational than theoretical.
With 79% of organisations having experienced secrets leaks according to the Ultimate Guide to NHIs, the broader lesson is that trust systems fail when evidence and lifecycle controls are not managed as one programme. Identity verification, credential governance and auditability now need to be planned together.
If your programme is expanding into age assurance, right-to-work checks or wallet-based identity, align policy, thresholds and escalation paths before scale creates inconsistency. That is the difference between a controllable identity workflow and a fragmented set of local exceptions.
For practitioners
- Define assurance thresholds by use case Set separate thresholds for age-restricted content, right-to-work checks and account recovery so that the same biometric or document control is not forced into one policy model. Use documented acceptance criteria for false positives, false negatives and step-up triggers.
- Map approved proofing routes to policy outcomes List the identity proofing routes your organisation accepts, then tie each route to a specific outcome such as over-18 access, employment eligibility or account verification. Where multiple routes are allowed, define which authority is used to confirm the result.
- Test liveness and age controls against real user populations Validate model performance using the ages and scenarios you actually serve, not only lab benchmarks. Include edge cases such as older teens, poor lighting, device variability and spoof attempts so that operational performance matches the policy you intend to enforce.
- Separate evidence quality from user experience Track completion rates, manual review rates and misclassification rates as distinct metrics. A smooth flow is not sufficient if it creates weak assurance, and strong assurance is not acceptable if it produces avoidable user failure in high-volume journeys.
Key takeaways
- Digital identity verification is shifting from a single proofing event to a governed set of evidence routes.
- Model accuracy matters, but policy thresholds and buffer settings determine whether identity controls succeed in practice.
- IAM teams should treat age assurance, liveness and digital ID choice as part of the same trust architecture, not separate concerns.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63A | Identity proofing and evidence routing are central to age assurance and digital ID choice. |
| NIST CSF 2.0 | PR.AC-1 | Access decisions depend on verified identity and policy-controlled acceptance routes. |
| NIST SP 800-53 Rev 5 | IA-2 | Identity verification and authentication controls underpin regulated digital ID journeys. |
| GDPR | Art.32 | Biometric and identity data processing requires strong security and risk controls. |
Align proofing routes and assurance thresholds to SP 800-63A evidence and identity proofing guidance.
Key terms
- Liveness Detection: Liveness detection is the mechanism that checks whether a biometric sample comes from a real, present person rather than a spoof such as a photo, screen, or mask. In identity programmes, it is a core defence against presentation attacks and should be tested under realistic operating conditions.
- Presentation Attack: A presentation attack is an attempt to fool a biometric system with a fake face, replayed video, mask, or other synthetic artefact. In practice, the control fails when it measures resemblance alone, because the attacker’s objective is to pass as the real user without actually being that person.
- Age Estimation Threshold: The policy boundary used to decide whether a person’s estimated age is sufficient for access or whether stronger verification is required. It converts probabilistic model output into an operational rule, so governance depends on how narrowly or broadly the threshold is set.
- Evidence Routing: The selection and validation of which identity proofing path is acceptable for a specific policy outcome. It matters when multiple credentials, documents or digital wallets can satisfy the same requirement, because the organisation must still define equivalence, authority and auditability.
What's in the full article
Yoti's full blog post covers the operational detail this post intentionally leaves for the source:
- iBeta testing results for MyFace passive liveness at Level 1 and Level 2, including APCER and BPCER performance
- Detailed discussion of the German buffer change and the regulatory context behind the 3 year threshold
- Expanded explanation of Australia’s age assurance discussions and the practical consequences for social media checks
- The policy comparison between government digital ID, private-sector digital ID and physical documents in right-to-work flows
👉 Yoti’s full blog post covers the test results, buffer changes and policy discussion in more detail.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org