Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Facial age estimation and digital ID wallets: are controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Independent testing published by NIST shows facial age estimation models vary sharply in accuracy, robustness and fairness, while Yoti says its top model recorded a 2.14-year mean absolute error and held up across changing conditions. The bigger issue is that age assurance only works when performance, privacy and verification steps are independently measurable, not assumed.

NHIMG editorial — based on content published by Yoti: Independent testing, in-store age checks and the UK government's digital ID wallet

Questions worth separating out

Q: How should organisations set assurance standards for digital age checks?

A: Organisations should set explicit assurance thresholds before deployment, covering accuracy, robustness, reliability and fairness.

Q: Why do digital identity wallets complicate authentication governance?

A: They complicate governance because the trust chain becomes more variable.

Q: What breaks when age estimation is treated as the only control?

A: When age estimation is treated as the only control, errors in model output can directly become access decisions.

Practitioner guidance

  • Set minimum assurance criteria for age checks Define acceptable thresholds for accuracy, robustness, reliability and fairness before any age-estimation or wallet workflow is approved for production use.
  • Separate proof of age from unnecessary face matching Use anonymous age credentials where possible and avoid transferring facial images to tills, checker apps or point-of-sale systems unless a clearly documented risk requires it.
  • Test wallet and checker workflows under real operating conditions Validate how the process behaves when people wear glasses, change expression, use different devices or move through busy retail environments.

What's in the full article

Yoti's full blog post covers the operational detail this post intentionally leaves for the source:

  • Side-by-side interpretation of the NIST facial age estimation test images for each vendor model
  • Step-by-step in-store proof-of-age flow using the Yoti app, checker app and point-of-sale scanner
  • Practical explanation of how the UK government digital ID wallet compares with certified private-sector wallets
  • Operational discussion of where device authentication, face matching and anonymous age credentials diverge in practice

👉 Read Yoti's analysis of facial age estimation testing and digital ID age checks →

Facial age estimation and digital ID wallets: are controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Independent testing is now the governance baseline for age assurance. Age-checking systems cannot be evaluated on vendor claims alone when the decision affects minors, regulated sales or public trust. The key issue is not whether a model can work in a controlled demo, but whether it remains accurate, robust, reliable and fair across real-world conditions. Practitioners should treat third-party testing as a control requirement, not a marketing extra.

A question worth separating out:

Q: Who should own failures in digital age verification workflows?

A: Accountability should be shared across the organisation that sets the policy, the provider that supplies the technology and the retailer or service that accepts the decision. The most important step is to define ownership before deployment, including false approvals, privacy complaints and manual override decisions. Without that, failures become ambiguous and hard to remediate.

👉 Read our full editorial: Independent age assurance testing raises the bar for digital ID



   
ReplyQuote
Share: