TL;DR: Age assurance is moving toward interoperable, privacy-preserving standards as Incode, Persona, and Veratad join the OpenAge Initiative, which aims to reduce repeated verification across platforms and align implementations with tightening regulation. The shift matters because age claims increasingly sit at the boundary of identity verification, privacy, and cross-jurisdiction compliance, where fragmented controls create friction and governance gaps.
NHIMG editorial — based on content published by Incode: Incode invests in privacy-first architecture and acquires Identiq, with discussion of OpenAge and age assurance standardisation
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
Questions worth separating out
Q: How should identity teams implement interoperable age assurance without over-collecting data?
A: Start by separating the age claim from the underlying identity proof.
Q: Why does age assurance create governance issues across multiple jurisdictions?
A: Because the same age check can trigger different privacy, consent, and evidentiary expectations depending on the market.
Q: How do you know if privacy-preserving age verification is actually working?
A: Look for evidence that the system discloses only the age outcome, retains less personal data, and avoids repeated collection across services.
Practitioner guidance
- Define the age assurance claim boundary Specify whether your service needs an age threshold, an identity proof, or both, and keep those requirements separate in policy and architecture.
- Map portability to lifecycle controls Treat reusable age assertions like governed identity artefacts with defined expiry, revocation, and re-verification conditions.
- Demand evaluation methodology for biometric age estimation Ask for test datasets, confidence thresholds, and bias handling methods before accepting age estimation in production.
What's in the full analysis
Incode's full article covers the operational detail this post intentionally leaves for the source:
- The working areas Incode is contributing to within OpenAge, including biometric age estimation, privacy architecture, and interoperability protocols.
- The regulatory context behind the initiative, including how different jurisdictions are shaping implementation pressure for age assurance.
- The practical rationale Incode gives for joining a standards body rather than building a closed implementation model.
- The article's broader explanation of why open standards matter for platforms operating across multiple markets.
👉 Read Incode's article on OpenAge and privacy-preserving age assurance →
OpenAge and age assurance: what it means for identity teams?
Explore further
OpenAge is a governance response to fragmentation, not a vendor feature race. Age assurance has become a distributed identity problem because platforms, regulators, and users all need different evidence from the same transaction. Open standards only help if they reduce repeated verification while preserving assurance boundaries. For practitioners, the key question is whether a shared model can lower friction without diluting trust.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to the Ultimate Guide to NHIs.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who is accountable when age assurance data is reused across services?
A: Accountability sits with both the service requesting the claim and the provider issuing it, because each controls different parts of the trust chain. Organisations should assign ownership for issuance rules, acceptance rules, expiry, and revocation so portable claims do not become unmanaged trust artefacts.
👉 Read our full editorial: OpenAge may reshape age assurance governance across platforms