OneID® | News and Events

Six criteria for choosing an age assurance method

Written by The OneID Team® | 24/08/2026, 10:44

Thirteen jurisdictions are now regulating children’s access to social media, at five different age thresholds, and they agree on almost nothing about method. One has a full under-16 account restriction actually in force, as at 17 August 2026. The rest are proposals, adopted laws awaiting commencement, partial measures, cases in litigation, or a different mechanism entirely. Our social media age limits by country hub sets out where each one stands.

For a platform operating in several of those markets, the practical test is whether the age assurance built for one market survives being pointed at the next. That breaks into six questions. Three of them track something a regulator has pressed on in writing. The other three are our own judgement about what a platform will need: threshold agility, reuse and evidence.

How do you choose an age assurance method?

Start from what the check has to survive rather than from a feature list. Six things decide it: whether the threshold is configurable, whether a user who fails one method has another, whether an unclear result escalates, whether a held credential can be reused, whether the platform receives a result or a document, and whether every check leaves a record.

Where these six come from

No regulator publishes a readiness framework. The furthest Ofcom goes is a list of seven methods capable of being highly effective, with the choice among them left open. A report on what highly effective means at a 16 threshold is due to Parliament by the end of October 2026. Australia’s eSafety Commissioner sets an outcome called reasonable steps and interprets it case by case. The European Commission enforces a platform duty on minors’ safety without setting a minimum age at all.

That leaves a platform to work backwards from enforcement, which is what these six criteria do. Score one to five on each, where one is no capability, two is a plan with nothing built, three is a manual process a person runs case by case, four is an automated path with one manual exception, and five is the standard described under each criterion. Nothing below three on any one criterion counts as ready. Escalation and evidence matter more than the rest at the start, and they are the two least likely to be in a compliance plan already.

Threshold agility

The live and proposed numbers run 13, 14, 15, 16 and 18. Denmark’s political agreement of 7 November 2025 set 15 with parental dispensation from 13, and as at 17 August 2026 a new government is renegotiating it towards a stricter version, with no bill introduced. France adopted an under-15 law on 21 July 2026, and its constitutional court struck down the central article on 14 August 2026. Australia sits at 16 and is the only one in force. The announced UK proposal is also 16, with no regulations laid as at 17 August 2026. Norway’s bill, which as at 17 August 2026 has not been put to the Storting and is unlikely to bind before 2027, sets the limit at 1 January of the year a child turns 16. Its EEA clearance came on the condition that the law imposes no obligations on platforms. No regulator has told a platform to handle a cohort threshold, and a date of birth comparison will not handle one unless it is built to.

The standard is met when the threshold is configuration, and a jurisdiction can be switched on or off without a release.

Method plurality

A single accepted method refuses everyone who cannot complete it. A meaningful share of any adult population has no passport or driving licence to hand, and a check that offers one route treats those people as ineligible when they are only unverified.

Australia’s rules bar a platform from collecting government-issued identification for age assurance unless a reasonable alternative method is also offered, which makes a second route a legal condition of using the first. Ofcom sets no equivalent condition, which leaves both the choice of methods and the consequences of a narrow one with the platform.

The standard is met when at least three accepted methods are live and a user can move between them in one session.

Escalation on an inconclusive result

Checks return unclear results. Facial age estimation is least reliable close to a threshold. Home Office guidance on facial age estimation, published 29 May 2026, puts the error margin of even the top systems at around 2.5 years at the 16 to 18 boundary. A 16 threshold sits inside that margin on either side. Our guide to how accurate age verification is covers what that margin does to a real check.

Australia’s regulator has addressed this directly. eSafety’s March 2026 compliance update is reported as treating repeated attempts with the same method as inconsistent with the waterfall approach its September 2025 guidance sets out, and as expecting a platform to move to a stronger method where signals of under-16 status remain. On Clayton Utz’s reading of the same update, eSafety also flagged platforms that let a self-declared under-16 raise their stated age upward. Either finding leaves a single pass-or-refuse gate short of the standard.

The standard is met when an inconclusive result triggers a stronger method automatically, and repeated identical attempts are blocked.

Reuse

Someone whose identity has already been established once should not establish it again to prove a single fact about themselves. Reuse is our addition, and no regulator’s guidance asks for it. What it buys is measured in the sign-up flow.

The difference is what the person does. An age check against an identity already established takes a tap and about three seconds, and a person who has none to draw on uploads a document instead, once for every service they sign up to.

The standard is met when a held credential is accepted and a returning user completes in a single step.

Data minimisation

A platform can receive an age result, or it can accumulate identity documents. UK GDPR Article 5(1)(c) requires personal data to be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”. The Information Commissioner’s Opinion on age assurance, published in January 2024 and under review following the Data (Use and Access) Act, goes further, setting the expectation that where a hard identifier is used to assess age, a service may only need to retain a yes or no output once the check is complete. Australia has made the point statutory, requiring personal information collected for age assurance to be ringfenced and destroyed.

An integration that stores documents accumulates a security liability in proportion to how many people it verifies. The test to apply is what remains on your own systems once the whole base has been through the check.

The standard is met when the default path returns an age result and no document is retained by the platform.

Evidence

A regulator that asks how a platform is meeting its duties has powers to compel the answer. eSafety issued 23 legally enforceable information-gathering notices to 10 platforms in the first three months of Australia’s obligation. Ofcom can require a service to provide, and even to generate, information it needs, with penalties reaching the greater of £18 million and 10% of qualifying worldwide revenue.

No regulator has imposed a per-check log, and this criterion is a readiness judgement rather than a duty. The judgement is that a platform which can say what method ran and what happened when it did not resolve answers those questions in hours instead of building the answer under a deadline. Our piece on what a regulator can actually ask for sets out where the real record duties sit.

The standard is met when that record is structured, retrievable per user and per check, and could be handed to a regulator without a reconstruction project.

The six at a glance

Criterion The question it asks The standard is met when
Threshold agility, our criterion and not a duty Can the age change per market without re-engineering the check The threshold is configuration and a market can be switched without a release
Method plurality Can a user who cannot complete one method be offered another Three or more accepted methods are live and a user can move between them in one session
Escalation Does an unclear result route to something stronger An inconclusive result escalates automatically and repeated identical attempts are blocked
Reuse, our criterion and not a duty Can a returning user or credential holder confirm age without repeating the verification A held credential is accepted and a returning user completes in one step
Data minimisation Does the platform receive a result or collect documents The default path returns an age result and no document is retained
Evidence, our criterion and not a duty Can the platform describe what a check did without a reconstruction project Method, result and escalation are recorded per check and retrievable

Enforcement sits behind method plurality, escalation and data minimisation, and not behind the remaining three. Parliaments set the differing numbers. No regulator has required a configurable threshold, a reusable credential, or a record of what a check did. The standards themselves are ours, including the floor of three methods.

Which of the six to score first

Score escalation first, then evidence. A single-pass gate is the most common way an implementation is built, and escalation is the criterion eSafety has addressed most directly in guidance. Evidence has no regulator behind it at all, which makes it the easiest thing to leave out of a plan and the slowest to retrofit.

The existing user base is a separate exercise, and a larger one than a new sign-up flow. No regulator has published a timescale or a completion rate for it. Our piece on verifying the users you already have covers what the exercise contains.

A five on threshold agility does not compensate for a one on escalation or a one on evidence.

What scoring four or five buys

A platform scoring four or five across the six absorbs a new threshold as a configuration change. One that has to open its code for each market runs a separate project per jurisdiction, each on a timetable set by a legislature or a court.

Any platform that built to the French commencement dates spent that work on a provision that never took effect, struck down eighteen days before it would have applied. Denmark carries a different exposure. As at 17 August 2026 its threshold has been reopened by a new government, with nothing yet introduced to build against.

Where OneID fits

OneID is a UK digital verification services provider, listed on the DVS register and certified against the DVS trust framework for identity, attribute, orchestration and holder services. It covers five of the seven methods Ofcom names as capable of being highly effective: open banking, photo ID matching, facial age estimation on-device through Regula, mobile network operator age checks, and digital identity services.

Orchestration is the part that matters to a multi-market build. One integration sits in front of several methods, and the service handles the market rules and the routing between them. A person who already holds a credential confirms their age without producing a document.

The six criteria in this piece are published in our global age assurance briefing, which covers thirteen jurisdictions with every position dated. OneID wrote that framework, so this section is a vendor’s account of its own product rather than a score against it.

Score your own age assurance position against the six criteria, or read the full briefing for the jurisdiction detail behind them.

Frequently asked questions

Does one age assurance method meet every regulator? No. Ofcom applies a highly effective test to the method against the threshold being checked, and approves no method in advance. In Australia the question is whether a platform took reasonable steps, judged case by case. The European Commission’s duty on minors’ safety runs through risk assessment and mitigation, and the threshold belongs to national law. Clearing one of those does not clear the others.

Does Ofcom require a particular age assurance method? No. Ofcom’s guidance names seven methods capable of being highly effective and requires none of them. The test it applies is that a method must be “technically accurate, robust, reliable and fair” for the threshold being checked. Ofcom’s rapid assessment for Parliament on the 16 threshold lands by the end of October 2026, so the list should be treated as live.

How many age assurance methods should a platform offer? No regulator sets a number. A platform in Australia that collects government-issued identification for age assurance has to offer a reasonable alternative alongside it. Our own criterion is three or more, on the commercial ground that every adult without the one credential you accept is a sign-up you decline.

What happens if an age check cannot decide? It should escalate automatically. A waterfall approach appears in eSafety’s September 2025 guidance, and an unresolved check passes to a stronger method under it. Clayton Utz’s May 2026 note on the regulator’s March 2026 compliance update reports eSafety objecting where a platform let a user take a second run at the identical check.

Do platforms have to keep records of age checks? Not of individual checks. The UK duties are written records: the risk assessment, the children’s access assessment and the measures in use, under sections 23 and 36 of the Online Safety Act 2023, plus the methods used where section 81 applies. Nothing in those sections reaches a separate entry for each check a service runs.

Can one age assurance system cover several countries? Yes, if the threshold is a setting and not a code path. The thresholds in play are 13, 14, 15, 16 and 18. The Norwegian threshold, not yet law as at 17 August 2026, falls on 1 January of the year a child turns 16 instead of on a birthday. A system treating the threshold as a per-market setting covers all of those from one integration.