OneID® | News and Events

How accurate is age verification, and what happens at the 16-to-18 boundary

Written by The OneID Team® | 29/07/2026, 08:54

Your check says a 19-year-old might be 16. Here is why, and what to do about it

A teenager scans their face or uploads a document to confirm their age, and a system decides in seconds whether they are old enough. Age verification feels binary to the user. Behind it sits a spread of methods with very different accuracy, and one line, the gap between 16 and 18, that is harder to judge than almost any other.

That line is getting more traffic. Ofcom’s 2026 report on the use of age assurance found facial age estimation was the method most commonly recalled by 8 to 17-year-olds, with exposure rising from 25% in July 2025 to 43% in January 2026. More young people are meeting these checks, and the accuracy of the check decides whether the right ones get through.

How accurate is age verification

Age verification accuracy depends entirely on the method. A check that reads a verified date of birth returns an exact age and does not degrade with appearance. A check that estimates age from a face returns a best guess with a margin of error, and that margin is at its widest at the 16-to-18 boundary.

The 16-to-18 boundary is where accuracy gets tested

Confirming someone is over 18 against a general adult population is a comparatively easy task. The distance in appearance between a typical 15-year-old and a typical 30-year-old is large, so a system can be wrong by a year or two and still land the decision correctly.

The 16-to-18 boundary removes that room. GOV.UK and Home Office guidance on facial age estimation states that precise estimations are “less accurate at the important 16 to 18-year-old boundary” and that “even the top systems have an error margin of around 2.5 years here”. An error margin of 2.5 years across a two-year gap tells you the problem plainly. Appearance alone cannot reliably separate a 16-year-old from an 18-year-old.

That is the commercial line to watch. Where a platform has to tell 16 from 18, the accuracy of the method decides whether it blocks eligible users or admits under-age ones. A method that is accurate enough for a simple over-18 gate can be the wrong tool for a 16-versus-18 decision.

What a margin of error means for a real check

Facial age estimation accuracy is usually reported as mean absolute error, the average gap in years between a system’s estimate and a person’s true age. GOV.UK describes it as “the most common measurement of accuracy for FAE, providing an algorithm’s margin of error in years”. Lower is better.

The direction of travel has been positive. NIST testing found mean absolute error on visa photographs fell from 4.3 years in 2014 to 3.1 years in 2024. Those figures come from an adult passport-style photo population, so they are not the error at the teenage boundary, and the 3.1-year figure should not be read as the 16-to-18 number. They make a narrower point. Even the best-measured systems, on clean images, are out by a few years on average.

For the person being checked, that margin is not abstract. A genuine 19-year-old whose estimate lands low is asked to prove their age another way. A 17-year-old whose estimate lands high may be let through. The same tool produces both outcomes, and where you set the check decides which one you see more of.

Every setting trades one error for another

Two error types matter, and they pull in opposite directions. GOV.UK defines a false positive as “the proportion of people incorrectly judged to be over a threshold”, an under-age user wrongly passed, and a false negative as “the proportion incorrectly judged to be under a threshold”, an eligible user wrongly blocked.

Providers manage this with a challenge age. Rather than test at the legal line, a system checking for over-18 will often set the bar higher. GOV.UK notes it is “quite common for a system checking someone is over 18 to set this ‘challenge age’ at 25, with anyone estimated to be younger challenged to provide alternative proof”. Estimate above 25 and you pass on the spot. Estimate below it and the system routes you to a stronger check for a second attempt.

Raise that challenge age and you catch more under-age users, at the cost of sending more genuine 18 to 24-year-olds through a second step. Lower it and you reduce friction for young adults while letting more under-age users slip through. No single setting removes both errors, so the sensible answer is to match the method and the buffer to the threshold and the risk.

Exact-age methods and estimated-age methods

Ofcom lists seven age assurance methods it considers highly effective: open banking, photo ID matching, facial age estimation, mobile network operator age checks, credit card checks, digital identity services, and email-based age estimation. Self-declaration and payment-only checks are excluded. The seven split cleanly by what they return.

Returns an exact age (verified date of birth)

Returns an estimated age (carries a buffer)

Photo ID and document authentication

Facial age estimation

Open banking, bank-verified

Email-based age estimation

Digital identity service or reusable credential

 

Credit card check, an inference of 18-plus eligibility rather than a date of birth

 

Exact-age methods carry a verified date of birth, so they return the same answer whatever the person looks like, and they hold their accuracy at fine distinctions like 16 versus 18. Estimated-age methods trade that precision for lower friction and lighter data collection. They fit checks well clear of the line, or a first step that escalates a borderline result to something stronger. A credit card check sits slightly apart, signalling that someone holds an adult financial product rather than returning their actual age, so it is best read as a proof-of-18 signal.

For why different thresholds need different tools, see our guide to why 18, 16 and 13 need different age checks. For how estimation itself works, see our facial age estimation explainer.

The four things a check has to get right

Ofcom sets four criteria for whether an age assurance method is highly effective. A method should be “technically accurate, robust, reliable and fair”. Each maps to a part of the accuracy picture.

Technically accurate means the method can, in Ofcom’s words, “correctly determine the age of a user under test lab conditions”. This is where a mean absolute error or a lab error rate belongs.

Real-world performance is what Ofcom calls a method being “robust”, the check still standing up outside the lab. Camera quality and lighting move an estimation result once a method leaves controlled conditions.

Reliable means the age output is, again in Ofcom’s words, “reproducible and derived from trustworthy evidence”. Methods reading a verified date of birth meet this naturally, because the answer traces back to a document or record rather than a judgement about appearance.

Fair means a method “avoids or minimises bias and discriminatory outcomes”. NIST found error rates “were almost always higher for female faces than for males”, so a system’s accuracy is not evenly distributed across the people it checks. A method that is accurate on average can still be less accurate for particular groups, which is why fairness is tested separately.

Ofcom describes its approach as “flexible, tech-neutral and future-proof”. No method is mandated. What is required is that whatever you use clears all four bars for the threshold you are checking.

Matching the method to the threshold

The accuracy question rarely has a single answer, because the right method changes with the line you are checking. A high-certainty method suits a hard 16-versus-18 decision. A lighter estimation check suits an over-18 gate where the population sits well clear of the boundary. The design that holds up matches the method to the threshold and escalates a borderline result rather than forcing one tool to cover every case.

This is the problem OneID is built to handle. OneID is a DVS-certified provider offering identity, attribute, orchestration and holder services through a single API, which routes a check across multiple methods and falls back to a stronger one when needed. A user well above the challenge age clears an estimation check in seconds. A user inside the buffer band is routed to an exact-age method that returns a verified date of birth, so a borderline estimate becomes a definitive answer instead of a wrongly blocked customer or a wrongly admitted minor. Facial age estimation runs on-device through Regula, and the accuracy figures cited here come from Ofcom, NIST and GOV.UK rather than from OneID.

The commercial point is straightforward. Accuracy is a fit between method, threshold and risk, and getting that fit right is what keeps eligible customers moving through and under-age users out.

For the wider picture on the social media age-limit debate, see our cornerstone guide to how age checks would work. For the difference between the terms, see age assurance vs age verification vs age estimation.

Frequently asked questions

How accurate is facial age estimation? Accuracy is measured as mean absolute error, the average gap in years between the estimate and a person’s true age. NIST testing found this fell from 4.3 years in 2014 to 3.1 years in 2024 on adult visa photographs. Accuracy drops at the 16-to-18 boundary, where GOV.UK guidance puts the error margin of even top systems at around 2.5 years.

Why is the 16-to-18 boundary harder than checking someone is over 18? Confirming someone is over 18 against a general adult population allows room for error, because appearances differ widely across ages. The two-year gap between 16 and 18 removes that room. With an error margin of around 2.5 years at that line, appearance alone cannot reliably tell a 16-year-old from an 18-year-old.

What is a challenge age or buffer? A challenge age is a threshold set above the legal age to absorb the margin of error. A system checking for over-18 might set it at 25. Anyone estimated to be younger is routed to a stronger check rather than refused, so genuine adults have a second path and the buffer catches borderline cases.

What is the difference between a false accept and a false reject? A false accept, or false positive, is an under-age user wrongly passed as old enough. A false reject, or false negative, is an eligible user wrongly blocked. Tightening a check to reduce one tends to increase the other, so the settings are chosen to fit the threshold and the risk.

Which age check is the most accurate? Methods that read a verified date of birth, such as document authentication, open banking or a digital identity credential, return an exact age and hold their accuracy at fine distinctions like 16 versus 18. Estimation methods carry a margin of error and suit checks well clear of the boundary or a first step before escalation.

Does age estimation get the age wrong more often for some people? Yes. NIST found error rates were almost always higher for female faces than for males, so accuracy is not evenly distributed. This is why Ofcom lists fairness as a separate effectiveness criterion, and why average accuracy figures do not tell the whole story.