Scope of the obligation and cost-mitigation features
Age assurance is likely to represent the most significant incremental compliance cost for some providers. As explained in section 3.2.4 , the proposed Regulation may require age assurance measures for a range of reasons. In principle, this could lead a large number of services to require age assurance measures. It is difficult to accurately predict which online services and systems will prefer to implement age assurance measures rather than applying safe features and settings to all new, recently created and logged-out users, partly because it is difficult to predict demand for adult features and settings.
In any case, several mitigation measures are in place. First, the strict age verification methods are only required for social networking services and video-sharing services and AI companions, while the safety by design obligations and the obligation for providers of software application stores allow alternative age assurance methods. As noted in the external study, age verification systems – notwithstanding the availability of the EU Age Verification Solution – are typically more expensive to operate than alternative age estimation systems. As such, targeting of the strict age verification requirements and the obligation to rely on an EU Age Verification solution to a small subset of services for the purpose of the access delay, while enabling a broader range of assurance methods for the safety by design obligations, will ensure compliance costs are proportionate to the level of risk involved ( ).
Second, existing accounts can be exempted where the provider can determine with a high level of confidence or based on the year of account creation that the account belongs to an adult. The external study found a strong preference for ‘successive validation’ techniques within the age assurance ecosystem. ‘Successive validation’ is an age assurance deployment approach under which end-users seeking to access a restricted service are subjected to the lightest touch, lowest-friction age assurance method first, and the system falls back to higher-friction, more invasive methods (e.g. age verification) only if the user fails to pass the prior age challenge. By enabling a form of successive validation, the proposed Regulation will significantly reduce both the compliance cost for companies and the friction involved in the age assurance process ( ).
Initial deployment costs
Initial deployment costs are expected to vary depending on whether a provider builds an in-house solution or relies on a third-party provider. As the external study explains, proprietary in-house systems are likely to involve significant start-up costs, including code development, testing, training data, secure cloud storage, and legal, compliance and product policy costs. For that reason, the choice to develop a proprietary in-house solution is likely to be exercised only by the largest service providers, if at all ( ). In practice, smaller and most medium-sized services are more likely to procure external solutions, which generally involve relatively modest set-up costs compared with proprietary system development ( ).
Available evidence suggests that the costs of age assurance are generally manageable for most providers. The Australian government has estimated 80 hours of staff time per social media service to implement age assurance measures, a cost of EUR 0.39 per check per user and a total cost of about EUR 33 million to assure the age of 21 million Australians with 4 social media accounts each ( , ). The impact assessment of the UK’s Online Safety ACT assumes 12h of developer time for backend Yoti integration and estimates a ten-year total cost between EUR 21 million and EUR 107 million to assure the age of 27 million users per year accessing pornography ( , ). It also notes that these costs are small compared to the costs of content moderation. In Ofcom’s 2026 implementation findings set-up costs were in many cases reported to be modest, often in the range of tens of thousands of pounds, although some providers reported higher costs ( ). Third-party providers themselves assert short implementation times of “approximately half a day” ( ) to one week ( , ). While these exact claims are not interpedently verified, the external study notes that for most small and medium-sized services, integrating third-party solutions is reasonably expected to cost in the hundreds of euros or low thousands of euros, although the evidence base remains limited ( ). Online services applying age assurance measures also need to offer a complaint-handling mechanisms that allow users to appeal incorrect age assessment. The set-up costs for this are expected to very limited for most services since notice and action mechanisms are already required for all online platforms under Article 16 DSA, including for small and micro enterprises.
More broadly, the external study found that third-party age assurance vendors are increasingly competing on ease of deployment considerations, with some providers marketing their services as having internal integration costs that can be completed within hours and days. Many service providers will likely also benefit from lower deployment costs that stem from the fact that website builder platforms like WordPress and Shopify – platforms which many in-scope services utilise for business operations – facilitate low-friction plug-ins to third-party age assurance providers. In addition, the external study found increasing market interest in and optimism about the potential of interoperability of age assurance deployments, and how they could reduce compliance costs for services in the medium term. Projects like euCONSENT’s AgeAware have created the technical and operational infrastructure through which age checks can be recognised across services and from which the costs of age checking can be shared. Interoperability innovations of this kind offer the further benefit of reducing the need for service providers to invest in multiple different age assurance deployments to satisfy the preferences of their user base ( ).
Taken together, these factors should relieve providers of some of the initial deployment costs – as well as the opportunity cost in terms of developer resource – that arise from the age assurance requirement.
Ongoing operational and per-check costs
The external study distinguishes between ongoing operational costs and per-check costs. Operational costs include legal, compliance, information security, customer support and supplier due diligence costs. These costs are likely to be lower where providers rely on third-party age assurance solutions rather than proprietary in-house systems, because much of the ongoing maintenance, operational security and due diligence is handled by the vendor. The available evidence does not suggest that such operational costs have prevented effective deployment.
In addition to the numbers cited in the section on initial deployment costs , Ofcom’s 2026 implementation findings indicate that median per-check costs are low (around EUR 0.07) ( ). They also suggest that per-check costs tend to decrease as the number of checks undertaken increases, with some large service providers understood to have faced per-checks costs of between EUR 0 and EUR 0.08 in other jurisdictions ( ). Regarding operational costs, the Australian government has predicted that the required weekly staff time will fall from 10 hours to two hours after the first year, even for the very large providers subject to the Australian access delay. Overall, these findings suggest that age assurance is unlikely to constitute a prohibitive cost barrier for most providers, even if smaller services may face relatively greater implementation challenges. This supports the view that recurring operational costs, including per-check fees, system maintenance, compliance monitoring, and security safeguards, are likely to remain proportionate in most cases ( ).
In the EU context, those costs may be further mitigated by the availability of the EU’s open-source age verification solution, which is intended to lower implementation barriers and reduce dependence on proprietary commercial systems. This may be particularly relevant for SMEs and smaller providers, for whom up-front investment and procurement costs can be more difficult to absorb. The privacy-preserving and secure nature of the EU Age Verification Solution should further significantly reduce the ongoing maintenance and compliance costs that service providers would face were they to operate proprietary age assurance system. The study indicates that, over time, the EU Age Verification Solution is likely to be the cheapest means for providers to deploy age verification, because its development has been publicly funded and its technical architecture has been made available in open-source form, so those initial development costs need not be recovered from relying service providers on a per-check basis ( ).
Recent experience in the UK offers an insight into the potential cost reduction benefits of the EU Age Verification Solution. While take-up of digital-ID-based age assurance solutions has been low under the UK’s Online Safety Act (including in part, because there is no corresponding version of the open-source EU Age Verification Solution), the limited evaluation data from Ofcom suggests that digital ID-based solutions are among the cheapest available to service providers on a per-check basis ( ). In this respect, the EU framework may offer cost-reduction opportunities that are not fully comparable to the UK context reflected in Ofcom’s evidence. The study therefore considers it reasonable to assume that providers relying on the EU solution are likely to face minimal ongoing per-check costs ( ).
Longer-term market developments and broader compliance effects
It is important to note that the costs for age assurance should be seen against the clear expectation created by the guidelines on the protection of minors that providers take effective measures to prevent minors from accessing age-inappropriate services and experiences. Moreover, as noted in the external study, this proposed Regulation comes against a backdrop where age assurance – whether for corporate policy reasons or in response to existing regulatory requirements in the EU and third-countries – is becoming an increasing norm online for service providers ( ). Indeed, for those providers that have already moved towards more robust age assurance in response to those guidelines and in response to other commercial and regulatory imperatives, the additional cost of the present proposed Regulation is therefore expected to be more limited, and mainly related to adaptation of existing systems, and compliance documentation. The study also points to evidence from the UK that some providers incurred no additional set-up costs because they already had commercial relationships and operational integrations with age assurance vendors in place ( ). This is particularly relevant for very large platforms, many of which already operate age-related controls and are developing capabilities linked to the European Age Verification framework as well as age assurance requirements in other jurisdictions. Platforms that are subject to the minimum age and have not yet implemented the EU Age Verification Solution will face some additional costs.
The external study suggests that several broader market developments are also likely to place downward pressure on costs over time. These include growing competition among third-party vendors, developments in interoperability that may allow age checks to be recognised across services and costs to be shared, and the emergence of standards that can reduce the vendor due diligence burden on service providers. The study further suggests that, as age assurance becomes a more established global norm, providers operating across borders may increasingly benefit from economies of scale by amortising deployment and compliance costs across multiple jurisdictions. Rather than there being a settled ‘consensus’, the available evidence points to a reasonable expectation that age assurance costs are likely to decrease over time as the market matures and regulatory certainty stimulates further innovation and supply ( ).
Last but not least, harmonised age assurance requirements at Union level are expected to reduce legal uncertainty and market fragmentation, thereby lowering long-term compliance burdens, especially for providers operating across multiple Member States. While the introduction or upgrading of age assurance systems may entail initial adjustment costs, a more consistent regulatory framework would reduce the need to adapt services to divergent national approaches and should therefore generate efficiency gains over time.