Send email Copy Email Address
© CISPA / David Rohner

©CISPA / David Rohner

2026-07-20
Felix Koltermann

“Whenever we introduce online age verification, everyone is affected”: A Conversation with Dr. Wouter Lueks

Age assurance technologies (AAT) have been gaining a lot of public attention in the recent debate around online child protection. CISPA researcher Dr. Wouter Lueks has assessed their effectiveness, side-effects and acceptance in a recent paper. Together with colleagues from the University of Hamburg and the Leibniz Institute for Media Research, he provides recommendations on which types of AAT are better or less suited to protect minors online. We asked him to explain the technology, elaborate on his concerns, and propose solutions.

What makes age assurance technologies such a prominent topic right now?

There is a belief in society that we need to protect children from online harms. This concern used to focus mostly on over-eighteen, age-restricted content such as gambling and pornography. Now it has expanded to include a broader range of things, including social media and other potentially harmful content. Different countries are now proposing measures to limit minors from accessing this content. That naturally brings up the debate about how to enforce such restrictions online.

From a technological perspective, what are age assurance technologies?

Age assurance technologies aim to solve the problem of determining the age of a user visiting a website or online platform. There are several high-level methods to do this, all with different implications. For example, one approach is age estimation through a selfie. A system analyzes a picture of the user and estimates their age. At the more reliable end of the spectrum, you can use identity documents or other official sources of information to verify a person’s age. The key point is that all of this happens in a digital context and an online environment. The technological possibilities also differ depending on whether access happens through an app on a smartphone or through a website. Unlike going to a cinema and presenting an ID card physically, everything here is mediated through a device.

How would you categorize the different approaches to age assurance?

I would distinguish four categories. The first is parental control and consent. Parents configure a child’s device to block certain apps or websites, or they must approve access. The second is age inference, where systems look at behavior patterns, possibly over time, to infer a user’s age. The third is age estimation, where systems analyze a selfie or other information to estimate someone’s age. Both inference and estimation are inherently fuzzy. It is debatable how accurately they can distinguish, for example, between a seventeen-year-old and an eighteen-year-old. The final category is age verification, where official documents or trusted sources are used to determine a user’s age. Each approach has advantages and disadvantages.

Who would be affected by the introduction of age assurance technologies?

Whenever we introduce online age verification in broader terms for all services, everyone is affected. People often think these measures ony target children, but that is impossible in practice. Websites do not know in advance whether a user is a minor, so everyone must go through the age verification process. That includes elderly people, tourists from foreign countries, and people who may not be technologically comfortable. For some people, these additional digital hurdles may become barriers that exclude them from participating online. This is especially important because many people support age verification in principle, but become much more hesitant when they realize they personally will also need to interact with these systems.

© CISPA / David Rohner

©CISPA / David Rohner

In a recent paper, you discuss unintended side effects. Could you give some examples?

I think it is important to distinguish between problems that arise from specific technological solutions and problems that arise from the very idea of age gating itself. Some problems can potentially be fixed by improving a specific technology. Others are fundamental and remain regardless of implementation.

One example of a fundamental concern is censorship. Right now, the stated goal is to protect children from harmful content, for example, on social media. But there is nothing inherent in these technologies that limits them to that use case. Tomorrow, the same systems could be used to restrict access to online games, LGBT content, political material, or books.

Whenever you build an age-gating system, you are effectively building a censorship system. You are deciding that some people may access certain content while others may not. At the moment, policymakers may have good intentions, but systems like this can easily be repurposed in the future.

You also mention privacy concerns. What are your concerns in this regard?

One common method is asking users to submit both a selfie and a picture of an identity document. From an age verification perspective, this is relatively reliable. But from a privacy perspective, it is terrible. The platform only needs to know whether someone is over eighteen, but instead it receives a full identity profile: name, date of birth, ID number, place of birth, and more. We have already seen cases where such data was stored improperly and later leaked, creating risks such as identity theft. Even asking people to upload selfies to random online platforms is already problematic.

Let’s have a look at the implementation of AATs. Do they actually work effectively?

That is another major issue. Even if age verification technologies work reasonably well, they are easy to circumvent. For example, users can simply install a VPN. Their traffic then appears to originate from a country where the regulations do not apply. As a result, websites may stop applying age gates entirely. This is why I think the debate focuses far too much on creating an ironclad front door, while the back door—labeled “VPN”—remains completely open. We end up imposing burdens and harms on everyone while still allowing a significant number of users to bypass the system.

Given these concerns, you propose a hierarchy of approaches. What does that hierarchy look like?

Since these systems affect everyone and are relatively easy to circumvent, in the paper we argue for lighter-weight solutions. For example, parental controls and consent mechanisms may not be perfect, but they have fewer negative externalities because they do not affect everyone universally.

A second possibility is on-device verification. For example, when setting up a smartphone, a user could enter their date of birth or perform a one-time verification step locally on the device. From then on, the device would simply report whether the user is above a certain age threshold. This avoids repeatedly sharing personal data with websites.

The European Union is currently developing the EU Digital Identity Framework, which would allow citizens to store official credentials. Do you see this framework as a potential solution to some of the privacy concerns surrounding age assurance technologies?

Potentially, yes. If implemented according to current privacy requirements, it could reduce much of the information leakage. Users could theoretically prove in zero knowledge that they are over eighteen. In other words, the only information revealed would be whether they are above the required age threshold. That would significantly improve privacy protections.

What would your recommendation to policymakers be?

If we do want to implement age assurance tech, then I would recommend aiming for lighter-weight, easier-to-implement solutions such as on device solutions rather than pursuing supposedly ironclad technologies that are still easy to circumvent. In other words, misguided perfectionism should not become the enemy of something that is good enough.

The problem is that rather than regulating the design of social media platforms—for example, algorithms designed to maximize engagement—policymakers instead introduce age gates. That is a very blunt solution. And these solutions are not harmless. They introduce censorship risks, exclusion risks, and privacy risks.

Scientific Publication:

Lueks, Wouter, Dreyer, Stephan, Federrath, Hannes, and Simon, Judith, “Assessing Age Assurance Technologies: Effectiveness, Side-Effects, and Acceptance”, arXiv e-prints, Art. no. arXiv:2603.25695, 2026. doi:10.48550/arXiv.2603.25695.