TL;DR: Age assurance is shifting from trust claims to measurable, certifiable controls, as Australia’s Age Assurance Technology Trial found Yoti’s September 2024 facial age estimation model reached a 1.80-year mean absolute error for ages 12 to 23, while New York’s draft SAFE for Kids Act sets minimum accuracy, circumvention and independent testing expectations, according to Yoti. The direction of travel is clear: age assurance is moving toward measurable, certifiable controls.
NHIMG editorial — based on content published by Yoti: Age assurance performance, New York SAFE for Kids Act and public perceptions of online safety
By the numbers:
- Yoti’s September 2024 model achieved a mean absolute error of 1.80 years for 12-23 year olds.
- The true positive rates were consistently above 94% from age 13 upwards.
Questions worth separating out
Q: How should security teams implement age assurance without collecting too much personal data?
A: Start with the minimum proof the service needs, then design the workflow so the platform receives only an age result or threshold assertion.
Q: Why do age checks need independent testing before they are deployed?
A: Because age assurance fails in practice when vendors rely on internal accuracy claims alone.
Q: What breaks when age assurance settings are left configurable in production?
A: The control can drift away from the version that was tested and certified.
Practitioner guidance
- Define measurable age-check thresholds Set minimum acceptable accuracy, false positive and circumvention detection thresholds before approving any age assurance method for production use.
- Prefer privacy-preserving proof patterns Use zero-knowledge proof or double-blind age assurance where the use case allows it, so the operator proves age status without retaining identity documents or unnecessary personal data.
- Lock production to certified settings Require only certified configurations in live environments and block unapproved tuning options that could weaken performance or change the tested security posture.
What's in the full article
Yoti’s full post covers the operational detail this post intentionally leaves for the source:
- The full breakdown of the Australia Age Assurance Technology Trial results, including how each tested method performed against the trial’s evaluation criteria.
- The New York SAFE for Kids Act consultation details, including the draft minimum accuracy and circumvention expectations.
- The article’s discussion of zero-knowledge proof and double-blind age assurance as privacy-preserving implementation patterns.
- The author’s commentary on public attitudes, uptake and the practical rollout implications for UK age-check deployments.
👉 Read Yoti’s analysis of age assurance testing, regulation and public acceptance →
Age assurance standards are tightening. What should teams change now?
Explore further
Age assurance is becoming a measurable control, not a policy preference. The article reflects a broader shift from trust-based age gating to evidence-based assurance. That matters because regulators are increasingly specifying minimum performance, circumvention detection and independent validation. For identity programmes, this moves age assurance closer to the discipline used for authentication assurance and away from informal product claims.
A question worth separating out:
Q: Who is accountable when age assurance lets minors bypass restrictions?
A: Accountability sits with the operator that chose the method, configured it and relied on its output. If the service accepted uncertified settings, skipped independent validation or failed to minimise data, the governance failure is on the programme owner, not just the technology provider. Regulators will look for evidence of control design and oversight.
👉 Read our full editorial: Age assurance regulation is tightening around privacy and accuracy