A date of birth box is the cheapest age gate a product team can ship. Ofcom has excluded self-declaration by name from the methods capable of meeting its highly effective standard, and three other regulators have arrived at the same place on different legal bases. That leaves a sign-up field carrying no evidential weight and a user base of ages nobody checked.
A user types 1 January 1990 into a form. The form accepts it. Nothing in the system has any evidence that the date is true. The platform has a claim on file and nothing else.
No. A date of birth field records what a user typed and nothing about how old they are. Ofcom excludes self-declaration from the methods capable of being highly effective age assurance, Australia’s eSafety Commissioner says it will not discharge the minimum age obligation, and the European Commission has opened proceedings over reliance on it.
An age gate collects an assertion. It creates a terms-of-service position and a record that a user claimed to be over a threshold.
It also teaches the users it turns away how to get through, because the only thing between them and an account is a different date.
A gate does not produce evidence, and the duties now in force are measured by outcomes. A service that must prevent children encountering certain content is judged on whether children can encounter it, not on whether a form was presented.
Ofcom’s guidance on highly effective age assurance names seven methods capable of meeting the standard, and as at August 2026 the list reads: open banking, photo ID matching, facial age estimation, mobile network operator age checks, credit card checks, digital identity services and email-based age estimation. Self-declaration is not among them. Ofcom lists it specifically under methods not capable of being highly effective, alongside online payments that do not require the payer to be 18 or over. Ofcom reports to Parliament by the end of October 2026 on what a highly effective check looks like at 16, so the list can move.
The Part 5 duties on services publishing their own pornography and the Part 3 protection of children duties are already in force.
Ofcom’s report on the use of age assurance, published 15 July 2026, went further than the guidance. It found that “to date, social media companies have failed to enforce their minimum age requirements properly”. Those requirements are mostly a stated minimum of 13 with a date of birth field behind it.
The enforcement record is narrower than that finding. Ofcom’s age assurance enforcement programme opened on 16 January 2025 and has focused on Part 5 duties, meaning pornography services. In March 2026 Ofcom wrote to six named platforms with four demands and a 30 April deadline, and said it would act if the responses did not satisfy it. No open Ofcom investigation names a social media service over minimum age enforcement or self-declared age, as at 17 August 2026. One does reach age assurance on a social platform: on 16 July 2026 Ofcom opened a case into TikTok’s children’s safety duties, focused on its use of age inference. Ofcom’s July 2026 report found current age inference methods “insufficient in preventing children from accessing a service at the point of entry”.
Australia’s Social Media Minimum Age obligation took effect on 10 December 2025 and is the only under-16 account restriction in force anywhere as at 17 August 2026. The duty falls on platforms to take reasonable steps, and no penalty attaches to a child or a parent.
The eSafety Commissioner’s Regulatory Guidance of 16 September 2025 sets out what will not count as reasonable steps for a platform. The Commissioner’s compliance update of 31 March 2026, as reported by Clayton Utz in May 2026, is direct about the form on the sign-up page: relying on self-declared age at sign-up alone will not discharge the minimum age obligation. The September 2025 guidance applies the same test to accounts a platform already holds.
The guidance sets out a successive validation approach, escalating to a stronger method where signals of under-16 status remain. Where the only check is a form, a user who fails it has unlimited further attempts and a new answer available each time.
No EU-wide social media minimum age exists. Under the Digital Services Act provisions on the protection of minors and on systemic risk, providers of platforms accessible to minors must put appropriate and proportionate measures in place for the privacy, safety and security of minors, and the Commission has opened cases where a stated age limit rests on self-declaration.
On 26 March 2026 the Commission opened formal proceedings into a large messaging platform, suspecting that its reliance on self-declaration as an age assurance measure is insufficient to prevent under-13s accessing the platform. On 29 April 2026 it reached preliminary findings against the operator of two of the largest social networks, stating that “minors below 13 can enter a false birth date that makes them at least 13 years old, with no effective controls in place to check the correctness of the self-declared date of birth”.
Both proceedings were open as at 17 August 2026. Preliminary findings are a step in the proceedings, and the operator can answer them in writing. No breach has been established. The theory of these cases matters to a platform: the Commission acted where a published minimum age had nothing behind it.
| Regulator | Legal basis | Position on self-declared age | Date |
|---|---|---|---|
| Ofcom | Online Safety Act 2023, Parts 3 and 5 | Self-declaration named as not capable of being highly effective; seven other methods listed | Guidance 24 Apr 2025; report 15 Jul 2026 |
| eSafety Commissioner (Australia) | Online Safety Act 2021, social media minimum age | Self-declared age at sign-up alone will not discharge the obligation | Obligation in force 10 Dec 2025; compliance update 31 Mar 2026 |
| European Commission | Digital Services Act, protection of minors and systemic risk provisions | Reliance on self-declaration under investigation in two open cases | One case opened Mar 2026; preliminary findings in the other Apr 2026 |
| Information Commissioner (UK) | UK GDPR and the Children’s code | Self-declaration can be easily circumvented, so what it collects is likely to be insufficient for high-risk scenarios | Opinion 18 Jan 2024, under review; joint statement with Ofcom 25 Mar 2026 |
The four instruments have nothing in common with each other, and the ages in question run from 13 to 18. The position on a typed date of birth is the same in all four.
The Information Commissioner reaches the same conclusion from data protection law. Its Opinion on age assurance, published 18 January 2024, states that “in the context of age assurance, self-declaration can be easily circumvented, which means the information you collect is likely to be insufficient for high-risk scenarios”. Ofcom and the ICO said it jointly on 25 March 2026: “self-declaration alone is not an effective means to determine the age or age range of users and prevent access by underage users”. A date of birth field is self-declaration by another name.
Section 27(3) of the Data (Use and Access) Act 2025 defines a verification service as one that ascertains or verifies a fact about a person “from information provided otherwise than by the individual”, and then confirms that fact to someone else.
Read that against a sign-up form. A date of birth typed by the user is information provided by the individual, which puts it outside the statutory description of verification before any regulator has said a word about effectiveness. The Act governs the reliability of verification providers and imposes no age-check duty. Parliament built the source of the information into the definition itself.
Ofcom sets four criteria and mandates none of the seven methods. A method must be, in Ofcom’s own words, “technically accurate, robust, reliable and fair”. The criteria describe what the check has to achieve. Our guide to the Online Safety Act age verification duties covers the duties themselves in detail.
A separate UK proposal to set a statutory minimum age of 16 was announced on 15 June 2026, with regulations intended by the end of 2026 and protections expected in spring 2027. It is not law as at 17 August 2026, and no regulations have been laid. The duties already in force are what make a date of birth field a problem today.
The liability sits behind the field, in a user base of self-declared ages that no longer counts as evidence for anything. The cheapest fix is already closed off in Australia, where prompting users who had declared themselves under 16 to correct their age upward was treated as a compliance concern. As at 17 August 2026 no regulator has set a timescale for clearing an existing base, which leaves each platform to size the job itself. For what that exercise contains, see verifying the users you already have.
For new sign-ups the change is smaller than it looks. Where an identity is already established, the user approves the share from their banking app and lands back in the flow within a few seconds. Where it is not, the same check becomes a document upload and a selfie. The delivery decides whether replacing the field costs sign-ups or saves them.
A check that reads evidence replaces the date of birth field. OneID is a UK digital verification services provider, certified against the DVS trust framework and listed on the DVS register for identity, attribute, orchestration and holder services, covering five of the seven methods Ofcom names as capable of being highly effective, as at August 2026: open banking, photo ID matching, facial age estimation on-device through Regula, mobile network operator age checks and digital identity services.
The check returns an age result taken from evidence. A user confirms through a method they already have to hand, and the platform receives confirmation that they are over the threshold. No document is passed to the platform to store. A check that cannot resolve on the first method routes to a stronger one instead of refusing an eligible customer. The platform keeps a written record of which methods it uses and how it uses them. That is what Ofcom’s guidance asks for. A log of individual checks is not required by any regulator, as at 17 August 2026.
Replacing an age gate with an age check is a change to a few screens in a sign-up flow. See how age verification works or read our global age assurance briefing for how the rules differ across markets.
Is a date of birth field enough for age verification in the UK? No. Ofcom names self-declaration as a method that is not capable of being highly effective age assurance, so a service subject to the highly effective standard cannot rely on a date of birth field alone. Seven other methods are listed as capable of meeting it, and Ofcom does not specify which one a service must use.
What is the difference between an age gate and an age check? An age gate asks for a date of birth and accepts whatever the user types. An age check establishes age from evidence such as a bank record, a document, a mobile network account or a held credential. The platform does not have to take the result on trust.
Which age checks does Ofcom count as highly effective? As at August 2026 Ofcom names seven methods capable of being highly effective: open banking, photo ID matching, facial age estimation, mobile network operator age checks, credit card checks, digital identity services and email-based age estimation. It mandates none of them. Self-declaration and payments that do not require the payer to be 18 or over are excluded.
Has any regulator fined a platform for relying on self-declared age? Not for the reliance itself, as at 17 August 2026. Ofcom has fined Fenix International, the operator of OnlyFans, £1.05 million for failing to provide accurate information about its age assurance measures, which is a penalty about what a company told the regulator, not about the check itself. The European Commission’s two proceedings remain open.
Do I need to re-check users who already gave a date of birth? Australia’s regulator has treated prompting users who declared themselves under 16 to correct their age upward as a compliance concern, which rules out the cheapest fix. UK duties turn on whether children can access a service at all, whenever they joined. Regulators have published no target completion rate and no deadline for an existing base, and that was still the position as at 17 August 2026.
Does replacing an age gate add friction to sign-up? It can remove some. A check run against a bank record, a mobile network account or a credential the user already holds asks them to confirm one fact and nothing more. If the first method cannot confirm an age, a well-built check offers another route in the same session.