Why Age Checks Aren't Working as Planned

New UK research has found that 39% of children aged 11 to 17 have successfully bypassed online age checks, despite the country's Online Safety Act requiring platforms to verify users' ages before granting access to certain content. The finding raises uncomfortable questions about whether the current wave of age verification technology is actually protecting minors, or simply creating a false sense of security for regulators, parents, and platforms alike.

What makes this research particularly notable isn't just the headline number. It's the method. According to the study, most children didn't need sophisticated tools or technical know-how to get around age checks. They simply lied. Entering a false date of birth, one that makes them appear to be 18 or older, was by far the most common workaround. No hacking, no elaborate spoofing, just a few taps on a keyboard.

VPNs Play a Smaller Role Than You Might Think

Given the ongoing conversation around VPNs and age verification laws, particularly since several US states and now the UK have pushed platforms to verify user age before allowing access to adult content or certain social media features, it would be easy to assume VPNs are the main tool children use to slip past these barriers. The research suggests otherwise.

VPNs did play a role for some children in the study, but it was described as limited rather than dominant. This matters because much of the public debate around age verification laws has focused heavily on VPN usage, with lawmakers and platforms treating VPN traffic as a red flag for potential circumvention. The reality on the ground appears far simpler: most kids aren't rerouting their traffic through a server in another country. They're just typing in a different birth year.

This distinction matters for policymakers. If the primary bypass method is self-reported false information rather than technical circumvention, then throwing more resources at detecting VPN usage may address only a small slice of the actual problem. The bigger challenge is that age verification systems built around self-attestation, simply asking someone to state their age, are inherently easy to defeat for anyone motivated to lie, regardless of age.

The Privacy Trade-Off Behind Age Verification

The push to strengthen age verification hasn't been limited to simple birthdate fields. In response to laws like the Online Safety Act, many platforms have begun exploring more invasive verification methods, including document uploads, facial age estimation, and third-party identity checks. These methods are harder to fool than a dropdown menu, but they also require collecting and processing sensitive personal data at scale.

That trade-off deserves more attention than it typically gets. Every time a platform asks a user, child or adult, to upload a photo ID or submit to biometric age estimation, it creates a new pool of sensitive data that has to be stored, secured, and eventually deleted. History has shown that concentrated stores of personal data are attractive targets for attackers. The recent ShinyHunters breach affecting Amazon One Medical is a reminder of how even well-resourced organizations handling sensitive personal records can become the target of large-scale data theft. Age verification systems, if not built and secured carefully, risk becoming the next category of honeypot for exactly this kind of breach.

What This Means For You

If you're a parent, this research is a useful reality check. The Online Safety Act and similar regulations were designed to add friction to how minors access age-restricted content, but friction isn't the same as a wall. A 39% bypass rate suggests that legal mandates alone won't substitute for ongoing conversations with children about what they're accessing online and why certain platforms have age limits in the first place.

If you're a platform user of any age, it's worth understanding that stronger age verification often means handing over more personal information, not less. Before uploading an ID or submitting to a facial scan for a website, consider whether the platform has a clear, published data retention and deletion policy. If it doesn't, treat that as a warning sign, not a formality.

And if you're concerned about how your own browsing data is collected during these processes, using privacy-focused tools like reputable VPNs remains a legitimate way to limit tracking and data exposure for lawful, adult use, separate entirely from questions of age verification circumvention. This research separates lying about age (a policy and enforcement problem) from technical circumvention (a much smaller slice of the picture), and that distinction is worth remembering the next time a headline conflates the two.

Key Takeaways

  • 39% of surveyed UK children aged 11-17 report bypassing online age checks, primarily by entering false birthdates rather than using technical workarounds.
  • VPNs were used by some children but played a limited role compared to simple self-reported false information.
  • Stronger age verification methods, like ID uploads or biometric checks, shift the risk from access control to data security, since they require collecting sensitive personal information.
  • Parents should treat the Online Safety Act as one layer of protection, not a substitute for direct conversations with children about online content.
  • Anyone submitting ID or biometric data for age verification should check a platform's data retention policy before doing so.