Age assurance should not become an identity check at every digital doorway
Ofcom’s guidance explains how services regulated by the Online Safety Act should implement highly effective age assurance when they need to distinguish children from adults. It establishes common expectations for accuracy, robustness, reliability and fairness, while recognising accessibility, interoperability, privacy and data protection.
What it could improve
Ofcom makes clear that self-declared ages and contractual age restrictions are not sufficiently reliable where highly effective age assurance is required. The guidance establishes a common effectiveness standard, permits different technical methods, requires ongoing monitoring and recognises that assurance can take place elsewhere in the ecosystem, including through app stores and operating systems.
What remains unresolved
Ofcom defines what effective age assurance should achieve, but the guidance does not itself establish one interoperable assurance mechanism for the wider Internet.
- A user may still have to complete a different check for every platform, creating friction, inconsistent age decisions and repeated processing of personal data.
- A service may need only confirmation that a user is above or below a threshold. It should not receive a name, identity document or complete date of birth when a limited signal is sufficient.
- Accuracy may vary around age thresholds and between demographic groups. Children and adults need accessible alternatives and an effective appeals process.
- An assurance result associated with an account or device may not identify the person using a shared device or borrowed account during a particular session.
- Recognising a child provides little protection unless the service changes its recommendations, privacy settings, contact permissions, commercial practices and wellbeing features.
- A safeguard applied by one service does not automatically follow the child to another platform, game, AI service, website or signed-out experience.
- A reusable assurance mechanism must not become a common identifier that enables cross-service tracking.
The Child-Friendly Internet perspective
Ofcom’s recognition of interoperability and system-level assurance creates an important foundation for a Child-Friendly Internet. A trusted provider could establish the relevant age or developmental context and issue a short-lived, purpose-limited signal confirming only what a participating service needs to know. The service could provide an appropriate experience without receiving the child’s name, identity document or complete date of birth.
- Prevent the assurance signal from being used for cross-service tracking.
- Bind the signal appropriately to the user or session, particularly on shared devices.
- Reveal only the minimum information required for an age-appropriate response.
- Support progressive autonomy as children mature, with accessible alternatives and correction mechanisms.
- Require services to demonstrate that recognition results in meaningful protection.
The central question
How can age checks be effective without asking children to prove who they are at every digital doorway?
