The Future of Age Verification: Your Face Never Leaves Your Device

Age Verification on Devices Just Got a Lot Smarter – And More Secure

The world is rapidly moving towards stricter online age verification laws, with over 30 countries now enforcing some form of age check. The UK’s Online Safety Act and Australia’s under-16 rules are just two examples of the trend. But as governments crack down on underage access to social media, a pressing question arises: what happens to the faces collected during these checks? A growing number of platforms are turning to facial age estimation, but this raises concerns about data security and user consent.

Facial age estimation is often touted as a convenient solution, allowing users to verify their age without needing government-issued IDs or database lookups. In regulated markets, one company – Incode Technologies – claims that its facial age estimation method is chosen by users eight times out of ten over other age assurance methods. However, this convenience comes at a cost: users are asked to share one of the most sensitive pieces of information about themselves – their face.

The problem with server-based age estimation lies in its very design. When a user’s face is sent to a server for analysis, it becomes vulnerable to data breaches and interception. The Identity Theft Resource Center’s 2025 Annual Data Breach Report reveals that the U.S. saw a record high of 3,322 data compromises last year – an increase of 79% over five years. Furthermore, 63% of consumers have expressed serious concern about biometric data collection.

As the threat landscape continues to evolve, so too do the tactics used by attackers. Incode has tracked the rise of agentic fraud – a type of cybercrime carried out with the help of AI agents. In 2024, this accounted for just 3% of fraud attempts, but by the first quarter of 2026 it had reached 40%. Incode estimates that agentic fraud will exceed 90% within the next 18 months.

In response to these growing concerns, Incode has developed a new approach to age verification. Its facial age estimation and passive liveness models now run entirely on the user’s device – the face is never transmitted or stored remotely. This innovative solution meets age assurance requirements worldwide without compromising user privacy.

The industry’s standard answer to data security has been to rely on a privacy policy, promising that biometric data will be handled with care and deleted after the check. However, this approach is fundamentally flawed: it cannot stop a breach or an insider attack; it can only assign responsibility afterward. Incode is instead taking a different route – building systems where sensitive data never becomes accessible in the first place.

Last month, Incode announced a $100 million commitment to advancing privacy-preserving identity infrastructure, alongside its acquisition of Identiq – a company specializing in cryptographic solutions for peer-to-peer anti-fraud collaboration. The funds will be directed at on-device processing capabilities and continued R&D in privacy-enhancing technologies.

For users concerned about age verification and data security, there is one key takeaway: look out for platforms that prioritize architecture over policy. By choosing companies like Incode that are committed to building secure systems from the ground up, you can rest assured that your face – and your personal data – will remain safe.


Source: Bleeping Computer — 2026-07-18