To ensure a safe and age-appropriate online environment for minors, age assurance is critical as noted by the Report of the Co-chairs of the Special Panel. Indeed, age assurance underpins both age restrictions and age-appropriate safety by design measures. However, the current framework around age assurance lacks clarity and its implementation is patchy.
2.3.1. Age assurance underpins safe online experiences for minors
Age assurance is crucial to ensure that minors only access services and systems that are safe and age appropriate. Currently, many minors below the established age limit access and use digital services and systems that are not designed for them. A range of surveys indicate that in the EU millions of minors under the age of 13 use social media and have their own accounts ( ). For example, across six countries, 34% of 9–11-year-olds report having a social media profile ( ). In April 2026, the Commission preliminary found META in breach of the DSA for failing to effectively prevent minors under 13 from accessing Instagram and Facebook ( ). The measures put in place by META to enforce the restrictions of 13 do not seem to be effective. The Commission also investigates TikTok and Snapchat for the same issue ( ). To note again that Preliminary Findings and opened proceedings are only an intermediate step in a Commission investigation and merely indicate a suspicion of a potential lack of compliance of these providers.
Age assurance is also important to ensure that minors who are old enough to have accounts receive age-appropriate experiences. The Report of the Co-Chairs of the Special Panel emphasizes that child safety online must follow a developmental approach that tackles age-specific risks. Some online services have started – to an extent – to differentiate certain experiences for different age groups. For instance, several services now offer so-called “teen accounts”, and the terms and conditions of certain platforms only allow users above 16 or above 18 to host LIVE streams or to access adult content, and vary some account settings with age ( , ). While the account settings on many online services are often not safe for minors even when the platforms identify them as such ( ), minors automatically receive adult settings when they are not recognised as minors. The guidelines on the protection of minors make clear that ineffective age assurance such as self-declaration alone measures cannot underpin age-appropriate design. As mentioned above, the Commission investigates several very large online platforms for failing to ensure that 13-17-year-olds receive age-appropriate experiences ( , ), indicating a suspicion of potential lack of compliance of these providers.
2.3.2. Ineffective implementation of age assurance
Existing age requirements on online services are typically not developed based on children’s needs and hardly enforced. Most providers of digital services set out a minimum age to access or use their service in their terms and conditions ( ). As noted by the OECD, the rationales behind the ages chosen by services derive from privacy and contract laws reasons rather than based on an assessment of safety or developmental appropriateness ( ). The OECD further highlights that “very few of [the services that set a minimum age in their Terms of Service] implement age assurance in a systematic way” and that only 2 out of the 50 online services studied systematically require assure age for account creation ( ). The only age check before account creation is typically self-declaration. It is widely recognised that self-declaration alone is not an effective age assurance measure, because many users do not reveal their true age ( , , ). Minors routinely mis-state their age online ( ). In practice, underage users can therefore easily access many age-restricted online services.
Figure 4 illustrates that both age verification and age estimation are deployed at most in haphazard way. Some services have recently started to require age checks before accessing certain high-risk features, such as live streams. Yet, many users do not use these features and users typically remain on the service if they fail to prove being old enough for an age-restricted feature. Hence, most users only need to prove their age once they have been flagged as likely underage and offered to appeal a pending account suspension. Account-based services often try to infer users’ age ex post, for instance by using age inference models that predict users age from their behaviour on the service (behavioural profiling), sometimes combined with human reviews ( ). While these systems can contribute to age assurance, they have failed to detect many minors with false stated ages. This is likely due both to inherent limitations of age inference – especially for users who reveal limited information about themselves and do not share videos and images of themselves – and to implementation choices that reduce the detection of minors ( ).
Figure 4 Circumstances in which online services use (a) age verification and (b) age estimation in 2024
(a) Use of age verification
(b) Use of age estimation
Note: Taken and adapted from OECD (2025).
The recent experience in Australia illustrates that it is difficult to ensure effective age assurance without concrete requirements for age checks before account creation. The Australian law only requires “reasonable steps to prevent Australians under 16 from creating or keeping accounts” ( ). A range of surveys and the eSafety Commissioners own data suggest that the majority of minors who previously had social media accounts still have them ( , , , ). Crucially, most minors were never asked to prove their age ( ). More recent laws on online age restriction typically require age checks before account creation ( ). While no age assurance system is completely circumvention-proof, age checks before account creation likely increase the effectiveness of age restrictions.
2.3.3. The need for clear age assurance requirements
While age assurance is an important measure to ensure the safety of children online, they should not result in the exploitation of users’ personal data. Many services currently do no offer users any privacy-preserving options to verify their age. Some services force users to upload their identity documents directly to the service ( ). This creates significant privacy and security risks because it reveals the user’s identity and often additional sensitive information on the document, such as precise birthdate, national identity number, sex, home address, and sometimes other personal characteristics ( ). Furthermore, these data are sometimes stored for extended periods of time ( ). As emphasized by Fegert and Melchior (2026), “[a]ny method employed to check age should uphold the highest privacy and data protection standards and should not lead to the processing of identity documents and biometric data for the purpose of age estimation.” Privacy-preserving age assurance solutions are rapidly developing, and the EU Age Verification Solution allows citizens to verify their age under the highest privacy standards ( ). In order to be implemented in such a way that they always remain privacy-preserving, such solutions must be mandated to respect minimum requirements, so as to ensure that age assurance measures remain in line with the fundamental rights of all users, including their right to privacy and data protection.
Overall, age assurance is an important measure for the protection of minors online, not only in terms of enforcing access restrictions to content or services that are harmful to children, but also to ensure that services are designed in an age-appropriate manner. Currently, age assurance measures are not robust nor effective and are used in a manner that may infringe upon children and adult’s rights to privacy and data protection. Clear rules are therefore necessary so that age assurance is used in a manner that serves minors in practice, is proportionate to the risk and abides by fundamental rights.