Online Age-Assurance Systems
SyllabusAwareness in IT: AI safety
An age-assurance system uses information or technical checks to decide whether an online user is above or below a legally or service-defined age threshold, without necessarily establishing the user's complete identity. It may use age verification or age estimation, with the required confidence depending on the risk posed by the service.
Methods used
Systems generally combine one or more methods because each provides a different level of confidence.
- Self-declaration asks the user to enter a date of birth, but it is easily circumvented and therefore provides low assurance.
- Document-based verification checks a government identity document, sometimes matching it with a selfie or a liveness check.
- Account-based verification uses trusted information held by a bank, mobile operator or digital identity provider to confirm an age threshold.
- AI-based facial age estimation analyses an image or video to estimate an age or age range rather than verify identity.
- Age inference uses signals such as account history, language or patterns of activity to assess whether an account is likely to belong to a child.
How a decision is produced
The service first selects an age threshold and a level of assurance proportionate to the risk. A checker may return an exact age, an age band or merely a yes-or-no token indicating whether the threshold is met; uncertain results may trigger another check or restricted access.
- A specialist third party can perform the check so that the online service receives only the threshold result, not the underlying identity document.
- Higher-risk services require stronger evidence and resistance to impersonation, document fraud and presentation of another person's image.
Limitations and safeguards
No method is perfectly accurate. Estimation systems can produce false classifications, and their performance may vary with image quality and the data used to train them.
- Systems should follow data minimisation, retaining no more identity or biometric information than necessary.
- They should provide security, transparent explanations and a means to challenge an incorrect classification.
- In India, the Digital Personal Data Protection Act, 2023, defines a child as a person below eighteen years in Section 2(f) and requires verifiable parental consent before processing a child's personal data under Section 9.
Keep reading
The news behind topics like this, explained every morning
Every morning Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 15 days are free.