Age Assurance Expectations and Highly Effective Verification


Age assurance is a core component of online safety compliance, particularly for platforms that host or generate content. The Online Safety Act and associated EU AI regulations place clear expectations on platforms to verify the age of users, especially when content or services may be inappropriate for minors. These expectations are not merely procedural but must be embedded into platform design, processes, and governance structures. The duty to verify age is not optional; it is a legal obligation tied to the protection of children and vulnerable users.
Understanding Age Verification Requirements
Platforms must implement effective age verification mechanisms that align with regulatory expectations. The EU AI Act, particularly Article 5, prohibits certain AI practices including those that exploit children or manipulate vulnerable users. This means that platforms must ensure that AI systems used for content recommendation, user interaction, or data processing do not disproportionately affect minors. Verification must be accurate, proportionate, and aligned with the level of risk posed by the platform’s activities. For example, a social media platform that allows minors to access AI-generated content must have systems in place to confirm user identity and age before such access is granted.
Age verification must also be consistent with data protection laws such as the UK GDPR. Platforms must not collect or process personal data unnecessarily, and must ensure that any data used for age verification is stored securely and retained only as long as required. The approach must be proportionate to the risk posed by the platform. For instance, a platform that provides educational resources to adults may not require the same level of verification as one that allows minors to access AI-generated pornography or gambling-related content.
Effective Verification Practices
Effective verification involves a combination of technical, procedural, and organisational measures. Technical solutions such as identity documents, biometric data, or third-party verification services must be selected based on their ability to reduce risk while maintaining usability. For example, a platform might use a trusted identity provider that verifies user data through government-issued documents or mobile phone number validation. The chosen method must be resilient against fraud or circumvention, and must be reviewed regularly to ensure effectiveness.
- Ensure that verification systems are accessible to users with disabilities, including those who may have difficulty providing traditional forms of identification.
- Train staff on how to identify and respond to potential attempts to bypass verification systems or submit false information.
- Document verification processes and maintain records of decisions made, including any exceptions or special considerations.
Organisational measures must also be in place. This includes assigning responsibility for age verification to designated roles within the organisation, conducting regular audits of verification processes, and ensuring that these processes are reviewed in light of evolving threats or regulatory developments. For example, a platform might appoint a dedicated compliance officer to oversee age verification, or integrate verification into existing risk management frameworks.
Platforms must also consider the broader context of AI governance. The AI management system standard ISO/IEC 42001:2023 provides a framework for embedding AI governance into organisational processes. Clause 7.2 of this standard highlights the importance of identifying and addressing AI-related risks, including those related to age verification. The standard requires that AI systems are designed and operated in a way that respects human rights, including the right to privacy and protection from harm. Age verification must be aligned with these principles, ensuring that systems do not inadvertently exclude or misidentify users.
Lastly, platforms must stay informed of regulatory developments. The Digital Omnibus on AI, which came into force on 27 July 2026, introduces further obligations for AI systems. While some obligations such as those in Annex III are deferred to 2 December 2027, platforms must begin preparing now. The obligation to apply machine-readable marking to generative AI systems placed on the market before 2 August 2026 highlights the importance of proactive compliance. Age verification must be part of this broader compliance framework, ensuring that AI systems are not only compliant but also transparent and accountable.
