TL;DR: Age assurance is now a cross-jurisdiction compliance requirement, with the UK, Australia, Brazil, and half of U.S. states all tightening verification expectations, while consumer trust concerns make server-side biometric flows harder to sustain, according to Incode. Privacy-preserving age checks are moving from a user-experience preference to an identity governance issue, because the data path matters as much as the decision outcome.
NHIMG editorial — based on content published by Incode: Why Platforms Are Making On-Device Age Assurance an Option for Their Users
By the numbers:
- Half of all U.S. states now mandate age verification for adult content or social media platforms, with nine new laws taking effect in 2025.
- The UK Online Safety Act made age assurance enforceable in July 2025, requiring platforms to implement highly effective checks or face fines of up to £18 million or 10% of global revenue.
- Australia's Online Safety Amendment Act took effect in December 2025, requiring platforms to prevent users under 16 from holding accounts, with fines of up to 49.5 million AUD for non-compliance.
Questions worth separating out
Q: How should organisations choose between on-device and server-side age assurance?
A: Choose on-device processing when the goal is to minimise biometric exposure and reduce the number of places sensitive data can exist.
Q: Why do biometric age checks create governance concerns for identity teams?
A: Biometric age checks create governance concerns because they involve sensitive personal data, consent expectations, retention decisions, and user trust all at once.
Q: What do security and identity teams get wrong about age verification?
A: They often treat it as a one-time onboarding check instead of an ongoing governance process with evidence, testing, and jurisdiction-specific rules.
Practitioner guidance
- Map the biometric data path Document where age assurance data is captured, processed, stored, and deleted, including whether any face image or derived biometric signal leaves the device.
- Set a privacy threshold for the first verification step Define the minimum data needed to satisfy age assurance in each jurisdiction, then prefer the least intrusive method that still meets the rule.
- Review retention and secondary-use controls Confirm that biometric or age-assurance artefacts are not retained longer than necessary and are not reused for unrelated analytics, model training, or fraud workflows without a clear legal basis.
What's in the full article
Incode's full article covers the operational detail this post intentionally leaves for the source:
- Jurisdiction-by-jurisdiction age assurance obligations across the UK, Australia, Brazil, and U.S. state laws
- The user-experience rationale for making on-device age estimation optional rather than mandatory
- Incode's explanation of how on-device facial age estimation keeps the face on the device
- The privacy and trust argument behind choosing facial estimation as the first assurance step
👉 Read Incode's analysis of on-device age assurance and privacy-first verification →
On-device age assurance: what it means for identity teams?
Explore further
Privacy-preserving age assurance is becoming an identity governance requirement, not just a product choice. The article shows that platforms are now balancing compliance, consumer trust, and biometric handling in the same flow. For identity teams, the question is whether the verification method itself creates unnecessary exposure. That makes architecture, retention, and processing location part of governance, not just UX. Practitioners should treat age assurance as a controlled identity decision with privacy consequences.
A question worth separating out:
Q: Who is accountable when age assurance fails to protect privacy expectations?
A: Accountability usually sits across identity, privacy, legal, and product teams because the failure is architectural, not isolated to one control owner. If the chosen method over-collects data or surprises users, the issue is governance alignment, not just implementation. Teams should assign ownership for processing location, retention, and user communication together.
👉 Read our full editorial: On-device age assurance is becoming the privacy option users trust