Australia’s regulator has already put existing accounts inside the duty. Its guidance of 16 September 2025 says measures will not count as reasonable steps if they “rely entirely on self-declaration to determine the age of existing or prospective account holders”. Existing account holders sit in the same clause.
Age verification for existing users needs its own plan, and it is the larger job. A new sign-up check changes one flow. An existing base means working through every account on the books, at whatever rate they respond, while the new-user flow ships. Compliance plans stop at the first.
In Australia the duty reaches accounts a platform already has. eSafety’s guidance of 16 September 2025 names existing account holders and says self-declaration is not enough for them. In the UK the duty is not written around sign-up: it asks whether children can normally encounter certain content or access the service, a question about everyone who holds an account.
Section 12 of the Online Safety Act is worth reading closely, because what it does not say is the point. A provider must operate systems and processes designed to prevent children of any age from encountering primary priority content that is harmful to children, must use age verification or age estimation to achieve that, and must use a method that is highly effective at correctly determining whether a particular user is a child.
Nowhere in section 12 is there a reference to account creation. Ofcom’s own formulation is the same shape: services must introduce age checks so that children are “not normally able to encounter” the content. A provider may only conclude that children cannot access its service where highly effective age assurance sits alongside controls that keep out anyone not identified as an adult.
That is a reading of how the duty is framed rather than a regulator instructing anyone to re-verify their base. Read that way, though, the back book is inside the duty by construction. A service whose existing users were never checked cannot answer the encountering question in the affirmative for those users.
The eSafety Commissioner’s regulatory guidance of 16 September 2025 rules out two further practices, and both only make sense against an existing base. Relying on users “holding an account for an unreasonable period of time before detection” is not reasonable steps, and neither is failing to prevent age-restricted users whose accounts have been deactivated from immediately creating a new one.
Its March 2026 compliance update went further, as reported by Clayton Utz in May 2026. Platforms had prompted users who had already declared themselves under 16 to undergo age assurance in order to correct their declared age upward, sometimes using methods least reliable near the threshold, and eSafety treated that as a compliance concern. Our piece on why a date of birth age gate is not an age check covers why the original declaration was never evidence.
eSafety published the first part of its evaluation on 31 July 2026, a two-year study of more than 4,000 children, with fieldwork in March 2026. Under-16s holding an account fell from 52.4% to 42.1%, a modest but statistically significant decline.
The finding that matters for a back book is a different one. Just over half of the children said their account remained active because they were not asked to prove their age, and 37.1% said their age is incorrectly listed on their account as 16 or over.
Circumvention appeared in the same survey, spread across spoofing, parental help and new accounts opened after deactivation, but no single route came close to the share who were never asked.
France passed the clearest back-book requirement any parliament has attempted. Its law, definitively adopted on 21 July 2026 at a threshold of under 15, was to apply to new accounts from 1 September 2026, with a further four months for accounts created before that date, landing on 1 January 2027. LCP, the Assemblée nationale’s channel, characterised the delay’s purpose as letting platforms run an age verification campaign across their entire user base.
On 14 August 2026 the Conseil constitutionnel struck down Article 1 as contrary to the Constitution, on two grounds. The prohibition was a disproportionate interference with freedom of expression, applied across all services without regard to their specific risks or protections. And the legislature had failed to determine the conditions and safeguards for age verification, leaving no legal protections for privacy.
The dates went with the article. President Macron has asked for a replacement, and franceinfo and Journal du Net reported on 14 and 15 August 2026 that it is expected in spring 2027. Two things are worth keeping. A platform that built to the September date spent money on a law that never commenced. And the second ground was about verification: the ban failed partly because the law did not say how age would be checked or what would protect the people being checked.
| Item | What it is | What decides it |
|---|---|---|
| Data quality | Whether the details you already hold can be matched to anything | What you captured at registration, and whether you ever checked it |
| Completion rate | The share of the base that finishes a check when asked | Method choice, how many routes a user has, and whether the request interrupts something |
| Support cost | Contacts from users who cannot complete, or will not | Whether a failed check offers another route or a dead end |
| Churn risk | Users who leave rather than verify | Where the prompt sits and what happens if they decline |
| Duration | How long the base takes to clear | Whether checks resolve against held credentials or require every user to act |
The second stage of the Gambling Commission’s financial risk assessments pilot ran 1.7 million assessments against operators’ existing customer bases. On the headline measure it went well: 97% of assessments were frictionless, against a government estimate of 80%.
What held the rest up was the identity data operators already held. Customers could not be matched to credit reference agency records because registration details were incomplete or wrong: initials instead of full names, nicknames, commercial addresses. The Commission’s April 2026 write-up said that allowing a customer to register with an initial instead of a full name, or a commercial address, “does not deliver age or identify verification properly”.
Data quality decides how much of a back book an exercise can reach. How big yours is depends on what you captured at sign-up, which you can sample this week.
Two platforms have published numbers, measuring different things. Meta reported in August 2026 that it had removed access to more than 750,000 Australian accounts assessed as belonging to under-16s as at 30 June 2026. In February 2026, roughly a month after making the check mandatory for chat, Roblox put completion at 45% of its 144 million daily active users globally.
Removals are not verifications. Meta published no completion rate, no number of users asked to verify and no appeals data. Roblox’s 45% is the only first-party completion figure for a retrospective exercise in the published record.
Beyond that the record is empty. As at 17 August 2026 no regulator has published a completion rate, a timescale, a phased approach or a safe harbour for retrospective verification, and no UK regulator has addressed retrospective verification of an existing user base directly. The nearest thing any regulator has said is eSafety’s warning about an “unreasonable period of time before detection”, and unreasonable is left undefined. The UK government told a Freedom of Information request in April 2026, before the June announcement, that it had done no modelling of the impacts of an under-16 restriction because clear agreed evidence did not exist. No credible published figure exists for the cost of re-verifying a base, or for the churn it causes.
The numbers in your plan are yours to produce. Pilot one segment, then size the exercise from the completion rate it gives you by method.
Reuse comes first. Any user whose age can be confirmed against a credential they already hold can be cleared without acting, which turns part of the base into a background process.
Reuse only reaches users who already hold a credential, and the number of methods on offer determines how many of the rest can be cleared. A base is a whole population, not the subset holding one document type. Every method a platform cannot offer becomes a group it cannot clear, and those users arrive in support instead.
Escalation handles whoever is left, because a check that returns unclear and then stops has spent the contact and gained nothing. Our six criteria for choosing an age assurance method cover all three.
The Information Commissioner’s Opinion of 18 January 2024, now under review following the Data (Use and Access) Act, offers a different option. A service likely to be accessed by a significant number of children must either establish the age of its users or apply all of the Children’s code standards to all of them, in a risk-based and proportionate way. Treating the whole base as children is a legitimate answer, and rarely the cheaper one.
OneID is a UK digital verification services provider, certified against the DVS trust framework for identity, attribute, orchestration and holder services. It covers five of Ofcom’s seven methods capable of being highly effective as at August 2026: open banking, photo ID matching, facial age estimation on-device through Regula, mobile network operator age checks, digital identity services.
A back book puts every kind of user through the same check. With several methods behind one integration, fewer users are left without a route. Someone who already holds a credential confirms with a tap rather than a document upload, and an inconclusive result escalates instead of ending in a support queue. Each check records the method used and the result, so the exercise describes itself afterwards.
Someone who has held an account for six years is asked to prove something to keep what they already have, usually while trying to do something else. The method decides whether that is a few seconds or a task, and across millions of users that is the completion rate.
Age verification for existing users can be sized in advance. Find out how many of your users could be cleared against something they already hold, how many would need to act, and how much of the data you captured at registration would match anything at all. Talk to us about a back-book assessment, or read our global age assurance briefing for the wider picture.
Do age verification rules apply to existing users or only new sign-ups? Both, depending on the regime. eSafety’s guidance of 16 September 2025 names “existing or prospective account holders”. UK duties are written around whether children can normally encounter content or access a service, and section 12 never mentions account creation. On that reading a service with an unverified existing base cannot answer that question for those users, though as at 17 August 2026 no UK regulator has required re-verification.
Can we just ask existing users to confirm their age again? A fresh self-declaration is not a check, so it does not move an account out of the unverified group. In Australia, platforms that invited users who had already declared themselves under 16 to raise their stated age were reported to have created a compliance concern, in eSafety’s March 2026 compliance update.
What is a back-book in age verification? The back-book is the existing user base carrying unverified or self-declared ages, as distinct from new sign-ups. Verifying it is a migration exercise, with its own data quality, completion rate, support cost, churn risk and duration, and it usually runs in parallel with the new-user work.
Is there a deadline for verifying existing users? Not as at 17 August 2026. France had legislated four months from 1 September 2026 for accounts created earlier, but the Conseil constitutionnel struck down the relevant article on 14 August 2026 and the dates fell with it. No regulator has published a completion rate, a timescale or a phased approach.
What completion rate should we expect? There is no benchmark. One platform has published a first-party figure: in February 2026 Roblox reported that 45% of its 144 million daily active users had completed an age check, about a month after making it mandatory for chat. Account removal figures from other platforms measure a different exercise and should not be read as completion rates.
Does verifying existing users cause churn? It can, and no credible published figure exists. What is controllable is the design: where the prompt appears, how many alternative methods a user has, whether an unclear result escalates or dead-ends, and how many users can be cleared against a credential they already hold without acting at all.