TL;DR: A year after the Online Safety Act, age assurance is being deployed across more platforms, with evidence that privacy-preserving checks can limit unnecessary data collection, reduce casual bypass, and support safer age-appropriate access, according to Yoti. The governance test has shifted from whether age checks work to how reliably they can be enforced without weakening privacy or accessibility.
NHIMG editorial — based on content published by Yoti: Age assurance after one year, with evidence on privacy, bypass, and accuracy
By the numbers:
- Ofcom found that 87% of children's recorded visits to pornography services lasted less than 30 seconds.
Questions worth separating out
Q: How should security teams implement age assurance without collecting too much personal data?
A: Start with the minimum proof the service needs, then design the workflow so the platform receives only an age result or threshold assertion.
Q: Why do age checks fail when platforms rely on weak inputs?
A: They fail because the control becomes easy to satisfy with spoofed images, replayed video, borrowed credentials, or other low-quality signals.
Q: What do security and identity teams get wrong about age verification?
A: They often treat it as a one-time onboarding check instead of an ongoing governance process with evidence, testing, and jurisdiction-specific rules.
Practitioner guidance
- Define the age assurance boundary Separate age confirmation from identity verification in policy, data flows, and logging so the platform only collects the minimum assertion needed for the service.
- Test controls against circumvention Assess whether liveness checks, digital ID assertions, and age-estimation methods can resist spoofing, replay, and VPN-assisted bypass attempts.
- Require independent benchmarking Use external testing to validate accuracy, fairness, accessibility, and security before rolling age assurance into regulated journeys.
What's in the full article
Yoti's full article covers the operational detail this post intentionally leaves for the source:
- How Ofcom and the ICO guidance shapes practical age-assurance implementation choices
- Which privacy-preserving methods are being used to prove age without full identity disclosure
- What the evidence says about bypass resistance, fairness, and independent benchmarking
- How platforms are adapting age checks across different service types and risk profiles
👉 Read Yoti's analysis of age assurance one year after the Online Safety Act →
Age assurance after one year: are privacy-first controls working?
Explore further
Age assurance is becoming an identity governance problem, not just a compliance feature. The article shows that platforms are no longer debating whether to ask for age, but how to do so without over-collecting identity data. That is a familiar governance issue for IAM and identity verification teams: the control must prove eligibility, not expand disclosure. The practical conclusion is that age assurance policies now need data minimisation, binding, and assurance-level decisions, not just product selection.
A question worth separating out:
Q: Who is accountable when age checks are inaccurate or easily bypassed?
A: The platform operator remains accountable for how the age control is designed, tested, and enforced, even when a third-party provider supplies the technology. Relevant accountability also extends to privacy, safety, and accessibility outcomes. That means governance teams should own the assurance threshold, evidence, and review process, not outsource responsibility with the tool.
👉 Read our full editorial: Age assurance after one year: privacy, accuracy and enforcement