Artifact GuideUKAge Assurance Options

UK Online Safety Act Age Assurance Options

Compare age verification and age estimation methods against the legal purpose, age threshold, error costs, privacy, accessibility, and bypass routes.

A method name or vendor accuracy claim does not establish suitability. Test the complete user journey and provide an equivalent fallback.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Compare age-assurance methods only after identifying the legal purpose, age threshold, protected content or feature, and required certainty. Where is required, test the complete deployed process rather than relying on a method name. This page covers the main method families, their practical trade-offs, the evidence to request, and the fallback a service needs when the primary method excludes a legitimate user.

Section 1

What are the main Age Assurance Options under the UK Online Safety Act?

Choose from method families, not marketing labels. Methods based on can compare identity or age evidence, query authoritative records, or use relevant account attributes. Facial predicts an age or range; behavioural or usage signals infer likely age; and attestation relies on another party's statement. Each family has different coverage, error, privacy, security, and circumvention risks.

Compare methods at the exact threshold and in the complete user journey. Measure false-adult and false-child results, performance near the boundary age, demographic variation, spoofing and repeat attempts, account sharing, fallback use, abandonment, accessibility, device requirements, geographic coverage, and the consequences of an error.

A document or database match may exclude users who lack the required record. Facial processes an image and returns an estimate rather than documentary proof. Payment or mobile-account data may describe the account holder rather than the person using the service. Treat each limitation as a test question and provide another route where the primary method excludes a legitimate user.

Ofcom's current codes and guidance, not a vendor's category label, determine whether a deployed method can satisfy a particular Online Safety Act duty. Check the current guidance for the duty, then retain implementation-specific evidence showing what the complete process does at the relevant threshold.

A layered design can route clear low-risk results automatically and send uncertain cases to another method or review. The combination still needs testing as one system, with data minimisation, retention, security, vendor, and deletion controls for every layer.

  • Best fit: state the legal purpose, threshold, protected content or feature, required certainty, and acceptable error direction before comparing vendors.
  • Evidence: protocol, representative test population, threshold-specific results, attack testing, demographic analysis, accessibility findings, privacy assessment, and production monitoring.
  • Fallback: provide an equivalent route for users without a particular identity document, device, payment method, biometric capability, or credit history.
  • Decision: approve, layer, pilot, reject, or restrict the method, with an owner and review trigger.
Section 2

How should teams choose between Age Assurance Options?

Start with the duty and consequence of error. A control that must prevent children from a service or regulated content needs evidence that it reaches the applicable standard at the relevant threshold. A method used only to adapt an age-appropriate experience may have a different certainty requirement, but the decision still needs evidence.

Compare candidates on the same test population and journey. Include accuracy near the threshold, false-adult and false-child results, robustness, reliability, fairness, circumvention, accessibility, coverage, fallback, data use, retention, security, supplier dependencies, and monitoring. Record why rejected options failed these criteria.

  • Define the age threshold and whether the control needs verification, estimation, or a layered result.
  • For , document the decision boundary and test how uncertain results move to another method.
  • Test uncertain results, retries, fallback, appeals, account recovery, and downstream access enforcement.
  • Choose the method that meets the duty while limiting collection, disclosure, retention, and exclusion.
  • Record approval, residual risk, monitoring thresholds, and the events that require re-selection.
Section 3

Which edge cases should teams check before relying on an Age Assurance Options decision?

Check shared and family accounts, logged-out access, embedded content, optional sign-up, alternate clients, VPN use, account recovery, users close to the threshold, and users who cannot use the primary document, device, biometric, payment, or database route.

Revisit the choice when the service adds content or features, changes the age threshold or downstream control, changes supplier or model, expands to a population not represented in testing, or monitoring shows bypass, error, exclusion, or unexpected retention.

  • Check whether the service is likely to be accessed by children, or is designed to keep children out.
  • Separate the safety aim from the data protection impact so the control does not collect unnecessary information.
  • Review any age assurance vendor to confirm who receives the data and for what purpose.
  • Treat any uncertainty as a review item, not as a reason to copy a previous decision unchanged.
Section 4

How should teams put the age-assurance decision into operation?

Create a decision record that names the service, statutory purpose, threshold, protected journey, chosen method, test evidence, fallback, downstream control, data flow, retention, supplier, privacy and security safeguards, owner, approval, and residual risk.

Monitor threshold-specific errors, bypass, repeated attempts, abandonment, fallback use, complaints, demographic disparity, and deletion failures. Set a named response when a threshold is crossed rather than waiting for a scheduled review.

  • Write the exact user journey or feature that needs age assurance.
  • State the selected method and why it is the least intrusive option that still works.
  • List the evidence used to support the decision, including policy notes, risk assessment, and implementation tickets.
  • Set a review trigger for product, vendor, or legal changes.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Supports this page's Age Assurance Options analysis under the UK Online Safety Act.
"“Age verification” means any measure designed to verify the exact age of users of a regulated service."
Related guides

Explore more topics

Does the UK Online Safety Act apply to this service?
A practical scope test for user-to-user, search, and provider-pornography services under the UK Online Safety Act, including UK links and exemptions.
How Ofcom and ICO duties overlap for online services
How the UK Online Safety Act, UK GDPR, Data Protection Act 2018, and Children's Code apply together to safety technologies and children's data.
How Ofcom enforces the UK Online Safety Act
Ofcom information notices, investigations, representations, confirmation decisions, penalties, remediation, and court-based service restrictions.
How to complete a children's access assessment
The two-stage UK Online Safety Act children's access assessment, evidence, timing, reassessment triggers, and next duties.
How to complete an illegal content risk assessment
UK Online Safety Act illegal content risk assessment scope, required elements, deadlines, review triggers, records, and resulting safety measures.
Is This a User-to-user or Search Service Under the UK Online Safety Act?
Classify user-to-user, search, and combined services under the UK Online Safety Act, apply the UK-links and exemption tests, and identify the next duties.
Ofcom Transparency Reporting FAQ
Who receives Ofcom transparency notices, what Schedule 8 can require, the 2026 notice process, first-report timing, and evidence controls.
Online Safety Act Children's Access Assessment
Decide whether children are likely to access a regulated service or part of it, document the evidence, and identify when a children's risk assessment follows.
Online Safety Act Complaints Handling Workflow
Route and decide Online Safety Act complaints, record the required response, and distinguish an internal review from an Ofcom complaint or super-complaint.
Online Safety Act Illegal Content Risk Assessment
Assess illegal-content risks by offence kind, likelihood, severity, affected users, service design, controls, evidence, and review triggers.
Online Safety Act moderation, reporting, and complaints
How UK Online Safety Act duties shape content moderation, user reporting, complaints, reinstatement, terms, records, and human oversight.
Online Safety Act: User-to-user and Search Service Scope
Decide whether an online service is a regulated user-to-user service, search service, combined service, or exempt service under the UK Online Safety Act.
UK Online Safety Act Age Assurance Requirements
When Online Safety Act services need age assurance, what highly effective age assurance means, and how safety duties interact with data protection.
UK Online Safety Act Age Assurance Selection Workflow
Choose an age-assurance method for an Online Safety Act duty by testing effectiveness, privacy, accessibility, evasion risk, and the consequence of error.
UK Online Safety Act Applicability Test Guide
Test whether a service is covered by the UK Online Safety Act by checking service functionality, UK links, exemptions, and the duties that follow.
UK Online Safety Act categories: thresholds and duties
How Category 1, 2A, and 2B thresholds work, how Ofcom categorises services, and what the July 2026 register means.
UK Online Safety Act Categorisation Guide
Apply the UK Online Safety Act Category 1, 2A, and 2B thresholds, calculate active UK users, and use Ofcom's register published in June 2026 and updated in July.
UK Online Safety Act Checklist
Verify UK Online Safety Act scope, assessments, controls, reporting, complaints, records, child safety, and category-specific work.
UK Online Safety Act Children's Safety Duties Guide
Apply the UK Online Safety Act children's access, risk-assessment, safety, age-assurance, reporting, complaints, and record-keeping duties.
UK Online Safety Act Compliance Guide
Build a UK Online Safety Act compliance program from service scope through assessments, controls, evidence, review, and Ofcom response.
UK Online Safety Act Content Moderation and Appeals Guide
Design UK Online Safety Act moderation, content-reporting, complaints, and review processes for illegal content and content harmful to children.
UK Online Safety Act Deadlines and Compliance Calendar Guide
UK Online Safety Act compliance dates for risk assessments, child safety, categorised services, fees, and event-based deadlines.
UK Online Safety Act Enforcement and Penalties Guide
How Ofcom investigates Online Safety Act breaches, issues decisions, requires remedies, imposes penalties, and seeks court orders.
UK Online Safety Act FAQ: scope, duties, and deadlines
Standalone answers and decision paths for UK Online Safety Act scope, risk assessments, child protection, age assurance, categories, reporting, and enforcement.
UK Online Safety Act ICO Overlap Guide
Apply the Online Safety Act and UK data protection law together for age assurance, moderation, profiling, recommender systems, and safety-data sharing.
UK Online Safety Act Illegal Content Duties Explained
Understand the illegal-content risk assessment, safety, reporting, complaints, record-keeping, and review duties for regulated user-to-user and search services.
UK Online Safety Act Moderation, Complaints and Appeals
Build moderation, content-reporting, and complaints procedures for regulated services, and understand where the Online Safety Act does and does not require an appeal.
UK Online Safety Act Ofcom Enforcement Guide
How Ofcom assesses Online Safety Act concerns, gathers information, investigates suspected breaches, and reaches enforcement decisions.
UK Online Safety Act Penalties and Fines Guide
The Online Safety Act penalty ceiling, qualifying worldwide revenue, daily penalties, penalty factors, and payment consequences.
UK Online Safety Act Regulated Service Scope Guide
Understand which user-to-user, search, combined, and provider-pornography services the UK Online Safety Act regulates and which exemptions narrow scope.
UK Online Safety Act Requirements Guide
See which UK Online Safety Act requirements apply to Part 3 services, child-accessible services, provider pornography, and categorised services.
UK Online Safety Act Risk Assessment Template
A field-by-field template for recording service facts, statutory risks, evidence, controls, residual risk, approval, and reassessment triggers.
UK Online Safety Act Risk Assessment Workflow
Run illegal-content and children's risk assessments in the right order, with evidence for risks, controls, governance, and reassessment triggers.
UK Online Safety Act Risk Assessments Playbook
Organise recurring Online Safety Act risk assessments across product, safety, data, engineering, legal, and governance teams.
UK Online Safety Act Senior Manager Liability Explained
Understand when a named senior manager or corporate officer can face personal liability for Online Safety Act information offences and how to control the risk.
UK Online Safety Act Service Classification Workflow
Decide whether a service is regulated, whether it is user-to-user or search, which exemptions apply, and whether Ofcom categorisation adds duties.
UK Online Safety Act Service Scope and Categorization Guide
Move from UK Online Safety Act service scope to Category 1, 2A, or 2B threshold analysis without confusing categorisation with basic coverage.
UK Online Safety Act Transparency Reporting
Understand who must publish an Online Safety Act transparency report, what an Ofcom notice controls, and how to prepare traceable reporting data.
UK Online Safety Act vs DSA: scope and duties
Compare UK Online Safety Act and EU DSA scope, service classes, child-safety and platform duties, dates, evidence, exemptions, and enforcement.
When Are Senior Managers Liable Under the UK Online Safety Act?
When section 110 can make a named senior manager liable for an Online Safety Act information offence, the available defences, and the controls to keep.
When is age assurance required under the UK Online Safety Act?
When UK Online Safety Act services need highly effective age assurance, what Ofcom expects, and how UK data protection law applies.