What counts as 'age verification'? The methods vary wildly in strength.
Age verification is an umbrella term for many different methods, ranging from a simple click to biometric scans. A 2024 report from Leiden University [5] identifies ten distinct methods, including self-declaration (just stating your age), hard identifiers (uploading a passport), credit card checks, facial age estimation, and behavioral profiling. Each has a different level of assurance—and different trade-offs. Self-declaration is privacy-friendly but provides very low assurance because it is trust-based and easily circumvented. Facial age estimation is easy to use but raises serious privacy concerns because it processes biometric data. The key point is that when a policy says 'age verification,' it rarely specifies which method, and the evidence shows that the weakest methods are the most common.
A 2023 study of online CBD and Delta-8 purchases in the US [1] found that 37.5% of CBD websites and 70% of Delta-8 websites only required a self-reported age confirmation—a simple checkbox or pop-up. None required ID or a signature at delivery. This means a minor can easily bypass the system. The study's authors conclude that these methods are 'self-reported and easily circumvented,' directly undermining the goal of preventing youth access.
Does age verification actually reduce youth access? The evidence is mixed and often negative.
The strongest evidence on effectiveness comes from early implementation signals of the UK's Online Safety Act 2023, analyzed in a 2026 policy study [4]. The study reports that after age assurance was introduced, some adult sites saw traffic reductions, but there was also a clear increase in circumvention behavior—particularly the use of VPNs (virtual private networks) to bypass geographic restrictions. Public response was mixed: broad support for child protection alongside concerns about effectiveness and privacy. The authors are careful to call these 'preliminary governance and implementation signals rather than evidence of policy effectiveness.' In other words, we don't yet know if the policy actually reduces the number of children seeing harmful content, or if it just pushes them to less regulated corners of the internet.
A 2024 commentary on Canada's proposed PYPEPA (Protecting Young Persons from Exposure to Pornography) Act [2] goes further, arguing that such legislation is rooted in 'moralistic policies' and 'fundamental misunderstandings' of the online landscape. The author contends that these laws are 'harmful and ineffective' and have far-reaching negative consequences, particularly for sex workers. This study does not provide quantitative data on effectiveness, but it adds a critical voice: even the intent behind these laws may be flawed.
Public trust is low, and privacy concerns are high—undermining the whole system.
A 2024 study from the University of Strathclyde [3] directly investigated how the UK public feels about online age verification laws. The findings are stark: there is 'general disengagement and a lack of trust in the government' regarding these measures. The study argues that governments are using a 'responsibilization strategy'—shifting the burden onto online service providers—which has led to the widespread deployment of either privacy-invasive methods (like facial recognition) or ineffective ones (like self-declaration). The former violates the privacy of underage users, and the latter fails to protect them. The public seems to recognize this, and their distrust may lead them to disengage or actively circumvent the systems.
This distrust is compounded by the fact that even well-designed systems have inherent tensions. The Leiden report [5] explicitly notes that increasing the accuracy of age verification often requires collecting more personal data, which conflicts with privacy rights. For example, a highly accurate system might require uploading a government ID, which exposes sensitive information and creates a database that could be hacked or misused. The report emphasizes that 'age assurance is a complex matter' and should not be seen as a 'silver bullet.'
About These Sources
This answer is built on 5 studies (3 peer-reviewed, 2 preprints) — published from 2023 to 2026, 4 from 2024 or later, 1 in Q1 journals — selected as the most relevant from 6 studies that passed quality screening, drawn from 54 papers retrieved from a database of over 500 million.
Sources used in this answer
Absence of Age Verification for Online Purchases of Cannabidiol and Delta-8: Implications for Youth Access
In a 2023 study of 20 US online retailers, 37.5% of CBD and 70% of Delta-8 websites used only self-reported age confirmation, with no verification at delivery, concluding these methods are easily circumvented.
Porn Vilification and Age Verification: Regulating Online Pornography and Sex Work
A 2024 commentary argues that Canada's PYPEPA and similar laws are moralistic, rooted in misunderstandings of sex work, and produce harmful, ineffective legislation despite evidence of growing harm.
Online age verification : government legislation; supplier responsibilization; public perceptions
A 2024 analysis found that governments use a 'responsibilization strategy' leading to privacy-invasive or ineffective age verification, and that the UK public shows general disengagement and lack of trust in these laws.
Age assurance for online sexual content: applying the health policy triangle to UK early signals and transferable safeguards for sub-Saharan Africa
A 2026 policy analysis of the UK Online Safety Act 2023 reports early signals of platform compliance, traffic reductions to some adult sites, increased VPN use for circumvention, and mixed public responses, but cautions these are not evidence of policy effectiveness.
Mapping age assurance typologies and requirements
A 2024 report from Leiden University maps ten age assurance methods (e.g., self-declaration, facial estimation, credit cards), noting that higher accuracy often conflicts with privacy, and that age assurance is not a silver bullet.
