As governments around the world increasingly adopt age assurance requirements intended to make online experiences safer for youth, policymakers and regulators are faced with their next challenge: how should those requirements be implemented in practice?
Age assurance – the process of determining whether a user is eligible to access age-restricted services, products, or features – is becoming a foundational component of policies intended to make online experiences safer for young people. While it can play a role in a comprehensive approach to youth online safety, it is not in and of itself a safety intervention and cannot address online harms on its own. Age assurance systems also introduce important tradeoffs affecting privacy, users’ ability to access online services, expression, competition, and the openness of the device ecosystem for users of all ages.
KGI’s Age Assurance Rules: An Implementation Guide provides practical recommendations for policy stakeholders tasked with developing rules in support of age assurance mandates, whether those rules arise in regulation, legislation, or as part of judicial remedies or settlements. Building on KGI’s earlier report, Age Assurance Online, which assesses existing age assurance technologies, the guide focuses on how to design age assurance rules that can support safer online experiences for young people while appropriately accounting for the significant tradeoffs that mandatory use of these systems presents.
The guide provides practical recommendations across the major components of a balanced age assurance regime:
- Rule Design: Rules should be designed to measurably reduce harms experienced by youth online rather than perfect age-gating, they should assign responsibility for complying with youth safety requirements to app and service providers, and they should pair age assurance obligations with corresponding safety requirements.
- Operational Rules: Rules should require covered providers to offer multiple age assurance methods, establish comprehensive accuracy requirements that account for both false acceptances and false rejections, provide timely and meaningful avenues for recourse for users denied access, and support parental consent without requiring parental identity verification.
- Evaluation and Reporting Rules: Rules should require transparent reporting of evaluation methods and system performance (including performance across relevant demographic groups), and covered providers’ performance claims should be subject to independent verification.
- Privacy Rules: Rules should limit the disclosure, collection, retention, and use of age-related information to what is necessary for age assurance, and they should require technical privacy protections, including zero-knowledge proofs and selective disclosure, where appropriate.
Age assurance is a tool, not a solution. Used thoughtfully and governed well, it may help reduce risks to young people online by underpinning specific safety mitigations. Used poorly, or designed without regard for the burdens it imposes, it can harm the very people it is intended to protect and the broader digital ecosystem.
By drawing on the recommendations in this guide, policymakers can better ensure that age assurance rules reflect the realities of current technologies and appropriately account for both the harms they seek to mitigate and the tradeoffs they introduce. As the technology and evidence evolve, implementation rules should continue to evolve as well, ensuring age assurance systems deliver meaningful benefits to youth online safety while preserving other important values, including privacy, service availability, competition, and openness.
Resources
Age Assurance Online
Age Assurance Online Report Overview
Age Assurance Rules
Assigning Responsibility for Age Assurance