Latest Trending Discover Timelines Categories
←All explainers

Technology explainer

How Do Online Platforms Estimate Whether a User Is Underage?

Age assurance ranges from a self-declared birthday to document checks and automated estimation. This explainer examines accuracy, privacy, proportionality and the evidence needed to show that an age gate works.

Online services often know what users say their age is, but that is not the same as knowing whether the answer is accurate. Age assurance is the collection of methods a platform uses to determine whether someone belongs in an age band, such as under 13, under 16 or over 18.

Age declaration, estimation and verification

A simple date-of-birth field is age declaration. It is easy to use and preserves privacy, but a child can enter a different date. Age estimation uses signals to infer a likely range. Those signals may include an automated assessment of a face, account history, language, behaviour or information already held by the service. Age verification asks for stronger evidence, such as an identity document, payment credential or confirmation from a trusted third party.

These methods provide different levels of confidence. A service does not always need a person’s exact birthday. It may only need enough evidence to decide whether the user is above or below a legal threshold.

Why platforms combine methods

No single method works well in every situation. A low-risk feature may rely on declaration and behavioural signals. Access to adult content or a regulated purchase may require stronger verification. Platforms may apply checks in stages, beginning with a low-friction method and requesting additional evidence only when the result is uncertain or when risk is higher.

Parental consent can also form part of the process, but it creates its own problem: the service must distinguish a genuine parent or guardian from another child or an unrelated adult.

The accuracy problem

Every age system can make two important mistakes. A false acceptance lets an underage user pass. A false rejection blocks an eligible adult or places a teenager in the wrong account experience. Performance can also vary across lighting conditions, devices, demographic groups and people whose appearance differs from the system’s training data.

Useful evaluations therefore report error rates near the relevant threshold, not only one overall accuracy number. A system that performs well across all ages may still struggle to distinguish a 15-year-old from a 16-year-old.

Privacy and data minimisation

Stronger evidence can increase confidence while creating new privacy risks. Identity documents reveal more information than most platforms need. Face analysis may involve biometric data. Long retention periods can turn a safety check into a valuable identity database.

Privacy-conscious designs try to prove only the required fact. A third-party service might return “over 18” without sharing a name or birth date. Images can be processed and deleted rather than stored. Platforms can also separate age-checking data from advertising profiles and publish retention rules.

What regulators and auditors should measure

A credible age-assurance programme needs more than a written policy. Independent testing should measure false acceptances and rejections, attempts to bypass the system, accessibility, demographic differences, data retention and the route for appealing mistakes. Audits should also examine what happens after a user is assigned an age band, including which content, messaging and recommendation features change.

The central trade-off is not safety versus privacy as if only one can exist. The practical task is to choose a method proportionate to the risk, collect the least information necessary and prove through testing that the system works near the age threshold that matters.

First appeared in

TikTok Agrees to Two-Hour Teen Limit in $100 Million Alabama Settlement

A new version of NewTqnia is ready.