Age assurance: What makes for the maturity of a technology or an industry?

profile picture Chris Field 7 min read
An image of a person's smartphone. The person is using Yoti's facial age estimation technology. Next to this image, the text reads: "externally audited, over 600 million age checks, used by leading brands". Underneath this list are the logos of Instagram, Aldi, SuperAwesome and Only Fans.

Last week, the Australian government decided against the eSafety Commissioner’s recommendation of a pilot before requiring adult sites to verify the ages of visitors. They said this was due to concerns about the privacy of people’s data and the maturity of age assurance technology.

So what exactly would constitute a mature technology? Is it something comparable to NASA’s Technology Readiness level? This suggests the technology needs to have gone through a thorough process of research and prototyping, before testing in a live environment and then ultimately rolling it out.

If that’s the case, we can say that Yoti and other age assurance providers have met the mature technology requirements. After all, some of the largest platforms in the world, including Facebook, Instagram and OnlyFans, have been verifying the ages of their users for over a year.

Or is the concern more around the maturity of the industry? A sensible set of questions to determine the maturity of an industry might include:

  • Is there a healthy ecosystem of providers?
  • Are there standards in place?
  • Has it been adopted by global organisations?
  • Are there independent audits with consistent measurement?
  • Has there been transparent benchmarking at scale?
  • Is there an established trade body?
  • Has any sectoral research been done?
  • Have there been any regulatory reviews in other jurisdictions?

We’ve answered these questions to help others trying to determine if age assurance is a mature technology and industry.

 

Is there a healthy ecosystem of providers?

The German government regulator (KJM) has reviewed and approved over 100 methods of age assurance over the last decade.

This includes approving several facial age estimation approaches. There are numerous different providers with a range of options. They have an agreed safety buffer of five years over the threshold age for users to access adult content.

 

Are there standards in place?

There has been a publicly available specification for age assurance since 2018 with PAS 1296:2018. In the UK, Minimum Standards for Age Assurance were drawn up as a bill and presented by Baroness Kidron in 2021. These were widely welcomed by industry in the UK. Additionally, there are international IEEE and ISO standards which work through the standards development process. The first of these is due to be completed in the coming months.

 

Has it been adopted by global organisations?

Global organisations such as Instagram, Facebook, OnlyFans, Yubo, NCR (National Cash Registers), Diebold and SuperAwesome have integrated our facial age estimation technology into their platforms.

Yoti, as one company alone, has delivered over 600 million age assurance checks for more than 100 customers in over 100 countries globally. When users around the world are presented with different ways to prove their age, over 80% opt for facial age estimation.

 

Are there independent audits with consistent measurement?

Independent audits are undertaken by bodies such as the Age Check Certification Scheme (ACCS) and NCC Group, as far back as 2020 and 2019 respectively.

Age assurance technology is developing quickly. As such, it is important to create an aligned approach to age assurance. This work has been commissioned by the Digital Regulators Cooperation Forum and undertaken by ACCS. The research also discusses what ‘state-of-the-art’ age assurance looks like:

“In terms of measurement, ‘state-of-the-art’ is best described as the layer of technology that sits between those technologies that are within existing scientific knowledge and research but may not yet be commercially viable services; and those technologies that are so embedded in everyday life and usage, they have become generally accepted rules of technology.”

A diagram titled "Objective approach to state-of-the-art". It places state-of-the-art technologies on a scale, with "generally accepted rules of technology" on one end and "existing scientific knowledge and research" on the other. At the intersection of the two is a section labelled "state-of-the-art".
Source: Measurement of Age Assurance Technologies, Part 2 – Current and short-term capability of a range of Age Assurance measures. OFCOM. Figure 3.

Has there been transparent benchmarking at scale?

Accredited testing labs, such as iBeta, already test for liveness to NIST-specified levels. NIST has also started a regular global benchmarking programme for facial age estimation. Due to its scale, this benchmarking programme will include a statistically significant sample, which is likely to be over one million individuals. In comparison, the sample in Australia was based on just 14 individuals, aged 3 to 21.

We’ll soon be publishing an updated facial age estimation white paper as we continue to improve our accuracy and bias levels. We publish these levels transparently using the proposed standardised measurement approaches.

 

Is there an established trade body?

Age Verification Providers Association (AVPA) is a global trade body for independent providers of age assurance technology. They currently represent 26 industry provider members, many of which provide facial age estimation.

 

Has any sectoral research been done?

Market intelligence organisation Liminal conducts regular reviews and updates on the sector. In addition, the Future of Privacy Forum has materials describing the range of facial technologies. They make a clear distinction between 1:1 facial recognition, 1:many facial recognition, and facial analysis or characterisation.

Family Online Safety Institute (FOSI) has published a paper reviewing age assurance. In this, they state that “improving age assurance systems has the potential to significantly increase online safety for all users. It is an achievable goal that everyone can unite behind, and will take a combination of innovative technology, transparent and trustworthy practices, and thoughtful regulation that sets a floor for industry to meet and exceed. Every online ecosystem can benefit from having some type of age assurance. This includes e-commerce and online marketplaces, gaming, streaming, news, and other platforms that could offer safer and more age appropriate online experiences”.

 

Have there been any regulatory reviews in other jurisdictions?

Regulators around the world are reviewing age assurance with many referring to age verification and estimation approaches in regulation.

In the UK, the Information Commissioner’s Office’s (ICO) 2021-2022 regulatory sandbox concluded that “Yoti’s age estimation tool has demonstrated that it is, in some contexts, possible to use biometrics to make a decision about an individual or treat them differently without using that biometric data for the purpose of uniquely identifying that person”.

The ICO also concluded that our technology is distinct from facial recognition because it does not uniquely identify anyone, and “will not result in the processing of special category data”’.

The German Association for Voluntary Self-Regulation of Digital Media Service Providers (FSM) awarded Yoti’s facial age estimation with their Seal of Approval in 2020. They found that the technology meets the required level to regulate access to content for minors.

This year, the French data protection regulator, the CNIL, stated in a report that “it considers acceptable the use of age verification by validation of a payment card or a process of facial age estimation based on facial analysis without facial recognition”.

 

Facial age estimation is a privacy-preserving solution

In terms of the privacy concerns raised by the Australian government, Yoti (and many other providers) offer a range of privacy-preserving solutions. Facial age estimation simply takes an image of a user’s face, converts the pixels of the image into numbers and compares the pattern of numbers to patterns associated with known ages. As soon as the age has been estimated, the image is permanently deleted.

Our Digital ID app lets the user share only their age, or an ‘over 18’ proof of age credential, with no other personal information. Document verification checks can also be configured so that no personally identifiable information (PII) is passed on to the website needing to do the age check.

If you’d like to find out more about our age assurance solutions, please get in touch.

Keep reading

A headshot of Yoti Guardian, Gavin. The accompanying text reads "Q&A with Gavin Starks - Entrepreneur and CEO of Icebreaker One".

Catching up with Yoti Guardian: Gavin Starks

At Yoti, one of the ways we’re held accountable is by our external Guardian Council. Our Guardians are an independent board of advisors who ensure that our products, services and partnerships stay true to our core principles. As his time on the Council comes to an end, we caught up with Gavin Starks, Entrepreneur and CEO of Icebreaker One, about his experience as a Yoti Guardian.   Why did you want to be a Yoti Guardian? Yoti is working at the forefront of digital identity and tackles many of the big challenges of privacy, protection, innovation and data rights head-on.

5 min read

Yoti assessed in the NIST Face Analysis Technology Evaluation program

An increasing amount of legislation is being introduced globally demanding that organisations effectively check the age of their users. It’s important that these age checks are inclusive; people should have a choice in how they prove their age. Regulators are recognising that not everyone will feel comfortable or be able to use a method based on identity documents. Facial age estimation gives people a way to prove their age without sharing their name, date of birth and other personal information from identity documents. It can improve online safety and help companies to comply with legislation, without having to process or

3 min read

How Digital IDs can protect you from deepfake scams

Deepfakes are a hot topic right now. Taylor Swift recently became the victim of a deepfake scam; firstly an AI generated video of her promoted a fake cookware competition, and then explicit AI images of her went viral online. AI voice cloning technology pretending to be President Joe Biden tried discouraging people from voting in the polls. And celebrities including Piers Morgan, Nigella Lawson and Oprah Winfrey found deepfake adverts of them online endorsing an influencer’s controversial self-help course. But it’s not just celebrities and public figures who are at risk of deepfakes scams. Fraudsters are also using deepfake technology

3 min read