Age assurance is becoming an increasingly important tool in efforts to protect children and young people online, driving demand for technical standards that are effective, privacy-preserving and interoperable across jurisdictions.
These key takeaways capture the discussion from a CIPL roundtable held in San Francisco on 23 July 2026, which brought together senior professionals from CIPL member companies, standards bodies, regulatory agencies, and civil society organizations to examine the evolving landscape of age assurance standards. The discussion focused particularly on the work of the International Organization for Standardization (ISO) and the Institute of Electrical and Electronics Engineers (IEEE), as well as the need for greater coordination across standards bodies and regulators.
The paper identifies key challenges and opportunities for developing and implementing interoperable age assurance solutions, including:
- The need for consistent terminology and a common taxonomy covering age verification, age estimation, and age inference.
- Greater coordination and clarity among standards bodies to create a coherent and interoperable standards framework.
- The importance of common measures for assessing the accuracy and effectiveness of age assurance technologies.
- The need for risk-based and proportionate regulatory approaches that can accommodate different services, use cases, age thresholds, and levels of risk.
- The use of privacy-enhancing technologies — such as zero-knowledge proofs, selective-disclosure credentials, and cryptographic attestations — to support privacy-preserving age assurance.
- The importance of developing common approaches to recognizing and accrediting trusted age signals to enable interoperability across services and jurisdictions.
- The need to consider accessibility, inclusion, parental involvement, and children’s evolving capacities when developing age assurance standards.
- Practical steps to support adoption, including greater public access to standards, clearer guidance for procurement and certification, and stronger cooperation between privacy and online safety regulators.
The paper concludes with recommendations for standards bodies, regulators, and organizations seeking to establish a more coherent, privacy-preserving, and interoperable age assurance ecosystem.