Podcast
Online safety has no borders: age verification around the world
Dmytro Sashchuk, Associate Legal Researcher and Analyst at Veriff, joins us to discuss age verification laws and their impact on businesses.
How do age verification regulations differ globally?
The goal’s the same everywhere, keep kids away from age-restricted content. The approach isn’t. The UK is regulator-led: the Online Safety Act sets requirements, and Ofcom (with the ICO) fills in the details. The US is fragmented, driven mostly by state law and shaped by ongoing litigation. The EU mixes both, the Digital Services Act provides a blueprint, but member states like Italy, France, and Germany still add their own rules. A business operating internationally can’t assume one implementation covers every market.

Why does the UK’s Online Safety Act matter beyond the UK?
It set the precedent that simple self-declaration isn’t enough. That standard is spreading; Australia has adopted similar legislation, Ireland a similar approach. Any business with an English-speaking audience should treat it as part of their compliance framework, not just a UK issue.
What should businesses do to stay compliant?
Drop the idea that one process fits every market. Instead:
- Map your services against each region’s requirements and document where a law doesn’t apply.
- Offer more than one verification method (age estimation, documents, digital ID) for flexibility.
- Collect only what’s necessary; privacy exposure is its own risk.
- Document your rationale for chosen methods, including privacy impact assessments.
- Monitor regulatory change continuously, new countries keep joining the wave.
What are the biggest challenges right now?
For businesses: fragmentation, and a landscape that shifts fast enough that today’s compliance won’t guarantee tomorrow’s. For users: the friction of proving identity online. For regulators: circumvention via VPNs and offshore operators.
Age verification laws and regulations
Talk to one of Veriff’s fraud experts to see how IDV can help you stay compliant.
What trends are shaping the industry?
A shift from self-declaration toward facial age estimation; low-friction, no ID required for routine cases. Reusable age credentials are emerging too, letting users verify once and reuse it elsewhere. And regulation itself is standardizing, with tiered assurance levels and clearer fairness/privacy requirements.

Which industries face the most scrutiny?
Adult content, then social media, with app stores now a growing focus; especially under US state laws. Enforcement is real: Texas has sued Discord, Roblox, and TikTok, and Ofcom continues active investigations.
How does a provider like Veriff help?
By turning a moving regulatory target into something configurable. Veriff’s own AI models for document and biometric verification support accuracy, fairness, and explainability to regulators, across a range of methods so businesses can match assurance level to risk.
What’s next?
More technical standards will define which methods are appropriate for different use cases, with age assurance becoming standard digital infrastructure rather than an afterthought. Globally, expect more regulation, not less: the EU’s framework, expanding US state laws, and newer entrants like Brazil show this is now a worldwide trend. The UK’s evolving approach, including proposals to extend protections for under-16s across social media, also demonstrates that regulators are broadening the scope of age assurance beyond adult content. The UK’s most exportable ideas, real proof over self-declaration, extraterritorial reach, and meaningful penalties, will continue influencing other jurisdictions, even where the letter of the law differs. The safest bet for businesses is building flexible, configurable age assurance today rather than waiting for a single global standard.