Age verification laws are rapidly evolving worldwide. The focus is shifting from whether platforms will verify age to the ethical implications of collecting and storing biometric data.
— Ricardo Amper, Founder and CEO of Incode Technologies
Over 30 age verification laws are currently in effect globally. In the UK, the Online Safety Act mandates “highly effective” age-checking measures, with plans to limit social media access for users under 16 starting in spring 2027.
Australia introduced regulations for users under 16 in December, and following breaches, the government signaled it would double penalties to $99 million. Brazil’s digital ECA will enforce age verification beginning March 2026, while half of U.S. states require some form of age verification.
Facial age estimation has emerged as a leading solution for compliance. This method requires no government ID or database checks, making it accessible for users of all ages, including those without documents.
In a regulated environment, Incode data indicates users prefer this method 80% of the time. However, this approach necessitates users to share their faces, raising concerns about privacy. Traditionally, this process involved capturing facial images and sending them to a server for analysis.
The Issues with Server-Based Age Estimation
This responsibility is growing, particularly for vendors relying on third-party technology. According to the Identity Theft Resource Center’s 2025 Annual Data Breach Report, the U.S. saw a record 3,322 data breaches last year, a 79% increase over five years, while supply chain breaches doubled over this timeframe.
Moreover, 63% of consumers express serious concerns regarding biometric data collection.
While fraud is advancing faster than defenses, Incode has processed over 7 billion verifications on its platform, highlighting the rise of agency fraud facilitated by AI agents. This type of fraud constituted 3% in 2024, projected to soar to 40% by early 2026 and potentially exceed 90% within 18 months.
Incode’s facial age estimation and passive liveness detection now operate entirely on personal devices—your face is neither transmitted nor stored.
Discover how our platform meets global age verification requirements without your biometric data ever leaving your device.
Privacy by Policy vs. Privacy by Design
Industry-standard responses often revolve around a privacy policy—a legal promise that biometric data will be handled carefully and deleted post-analysis.
Policies alone are not safeguards. They cannot prevent breaches, whether from insiders or third parties. Responsibility can only be assigned after a breach occurs.
Privacy by design fundamentally alters this scenario. By engineering systems that ensure sensitive data is never accessible, we eliminate the risk of interception. If facial data isn’t transmitted, it can’t be captured. If it isn’t stored, it can’t be compromised. Users are not left at the mercy of promises; instead, privacy is built into the architecture.
$100 Million Commitment to Privacy
Last month, Incode Technologies, a frontrunner in AI-driven identity verification and fraud prevention, pledged $100 million. This commitment coincides with our acquisition of Identiq, a firm specializing in privacy-enhancing cryptographic solutions aimed at peer-to-peer fraud prevention.
This funding will enhance on-device processing capabilities, spearhead research into privacy-enhancing technologies, and expand our engineering resources globally.
In just two weeks, we launched our first product—on-device age estimation, which empowers users’ devices to perform age assessment without transferring facial data.
This innovation stems from foundational architectural choices made at Incode’s inception, prioritizing AI-driven verification over human access to biometrics, localized processing, and fraud collaboration without data exposure.
Part 1: Age Verification Without Transmitting Data
On-device age estimation utilizes two models from Incode directly on users’ own devices—facial age estimation and passive liveness detection—to verify that a genuine, live person is in front of the camera, as opposed to a static image or manipulated video. Analyzed locally, facial data is never transmitted or stored.
The process assesses whether the user meets the required age for the platform. If verification fails for any reason, users are provided with alternative verification methods chosen by the platform.
This capability required scaling down model sizes. Incode innovatively employed knowledge distillation to compress both models to about one-tenth of their original size, allowing seamless operation on standard devices.
As the analysis occurs directly on users’ devices, neither Incode nor client platforms can access biometric data or facial images. Users confirm their age—all biometric data remains securely on their device.
Why Send Data to the Server at All?
No single method can guarantee foolproof age verification. However, on-device solutions can’t entirely guard against session tampering (like intercepted camera feeds). Incode’s server-side component scrutinizes session metadata (details about when and how sessions occur, along with device characteristics) to identify injection attempts and tampering.
Importantly, this metadata does not include any facial or biometric information; it exists solely for fraud detection and session validation.
Without robust systems, minors might be misidentified as adults, undermining safety and compliance objectives. Our systems are built to withstand some of the internet’s most significant risks, including banking and healthcare sectors where daily threats such as deepfakes and injection attempts are prevalent.
With Incode’s security measures, we ensure a 99% spoof detection rate against deepfakes, injection attempts, replay attacks, and physical impersonation—criteria upheld by top U.S. banks. Incode reported over one million facial attacks across its platforms in 2026.
On-device age estimation is pioneering as the first comprehensive enterprise-ready solution that merges age estimation with advanced fraud defenses. We believe this approach will redefine age verification standards globally.
Part 2: Collaborating to Combat Fraud Without Exposing Data
The second pillar of our initiative addresses how financial entities exchange fraud intelligence. Fraudsters frequently unite across institutional lines, whereas defensive agencies remain isolated, each observing a fraction of the threat landscape.
The conventional approach of consolidating customer data across entities inadvertently heightens risks—the central data lake model has proven an appealing target, as reflected in breach statistics.
Identiq has dedicated nearly a decade and over $50 million to develop patented privacy-enhancing technology that allows organizations to exchange fraud alerts without compromising customer data.
This new paradigm eliminates central data lakes and third-party data intermediaries.
This integration with Incode’s platform provides significant network fraud intelligence and is anticipated to facilitate billions of verifications annually.
Itay Levy, co-founder and CEO of Identiq, expressed: “Every institution shares the same concern: how to collaborate in fighting fraud while retaining control over customer data.”
“Identiq offers a solution to that challenge, now available to any organization with substantial user data within Incode.”
The Current Landscape of Standards
Regulatory pressure is intensifying from multiple angles. Regulations are expanding, while users increasingly demand privacy-conscious verification methods. Regulatory bodies are actively defining valid age verification techniques; we are currently in a crucial standard-setting phase.
Incode’s ongoing compliance initiatives encompass SOC 2 Type 2, ISO/IEC 27001, HIPAA Attestation of Compliance, FedRAMP Ready, Age Check Certification Scheme (ACCS), and the Kantara IAL2 Component Services Trust Mark. With over 7 billion reliable checks conducted, we now boast a product that keeps facial data securely on the device and a collaborative anti-fraud approach that minimizes data exposure.
“We have always maintained that privacy and fraud prevention are interconnected challenges that must be addressed together,” stated Ricardo Ampere, Founder and CEO of Incode.
“As age verification becomes a global mandate, our mission is to streamline the process for users, reducing the burden of proving their age.
Experience Incode’s On-Device Age Estimation
Discover how on-device age estimation enables your platform to fulfill age verification obligations without transmitting users’ facial data. Schedule a walkthrough for your team by visiting incode.com/Privacy.
Sponsored and authored by Incode Technologies.
Source: www.bleepingcomputer.com


