- Fundamental differences between AI-based estimation and verification using official documents.
- European and Spanish regulatory frameworks that prioritize the protection of minors and user privacy.
- Digital identity systems and electronic wallets as an anonymous alternative to prove legal age.
Today, browsing the internet without encountering a wall asking you to prove your age is nearly impossible. From social media to adult content websites and games, protecting young people has become an absolute priority for governments and tech companies, leading to a surge in the implementation of access control systems.
The truth is that not all these methods are the same; some are as simple as checking a box (which are now useless), while others ask for extremely sensitive data . Understanding how these tools work and what rights we have is essential to avoid handing over our privacy on a silver platter while trying to access a service.
Difference between estimating and verifying age

To begin, it's important to clarify that having a machine try to guess your age is not the same as having you prove who you are. Age estimation is essentially an inference. The system analyzes your profile picture, your tone of voice, and your online behavior to say, "This user is probably over 18." The problem is that these systems are quite unreliable, especially with people from certain ethnic groups or if someone decides to wear a fake mustache to fool the algorithm.
On the other hand, age verification aims for absolute certainty. This is where official documents come in. The user uploads a photo of their passport or national identity card, and the system confirms the date of birth. While much more accurate, the risk is greater, as we are handling critical personal information that could be stolen or leaked if the platform lacks robust security.
Common methods for proving legal age

There are several ways websites use to ensure you're not a child entering prohibited sites:
- Official documentation: Driver's licenses, passports, or national identity cards are used. Depending on the country, some regulations allow for covering up unnecessary information, such as the photo or national identification number. minimize data exposure.
- Credit cards: It's a quick method. Google, for example, sends a bank authorization request to confirm the card is valid. It's not an actual charge, but a validity verification which usually disappears from the account within a few days.
- Advanced Biometrics: Some companies use facial scans to verify identity that estimate age using AI without needing to store the user's identity, seeking a balance between security and fluidity.
The legal framework in Spain and the European Union

In our country, things are fairly well regulated. The General Law on Audiovisual Communication requires video-sharing services to have systems in place to prevent access to harmful content , such as pornography or gratuitous violence. Furthermore, the EU Digital Services Regulation requires major platforms to consider the best interests of the child when designing their interfaces.
The Spanish Data Protection Agency (AEPD) has been very clear with its ten principles. The most important is that verification must be anonymous for the provider and that this process cannot be used to track, locate, or create browsing profiles of users. Basically, knowing that you are of legal age does not mean that the website can know exactly who you are and what you do online.
Towards a future of anonymous digital identity

To avoid the chaos of uploading ID cards to every website we visit, the European Commission is promoting a harmonized approach. This involves creating a digital identity "mini wallet ." The idea is that users would have an electronic credential issued by a trusted entity (such as a bank or the government) that simply states "YES, you are over 18," without revealing their name, address, or any other personal information.
This token-based affirmation system is the holy grail of privacy. Instead of handing over the document, you provide cryptographic proof. This way, child protection laws are met while respecting freedom of expression and the anonymity of adults, preventing platforms from building massive databases of real identities linked to sensitive consumer habits.
Operational risks and dilemmas
It's not all sunshine and roses. Many platforms, faced with very strict or ambiguous local laws, prefer to block access entirely in certain regions rather than risk hefty fines or handling sensitive data. This creates a loophole where some users lose access to legal information simply because the company can't find a way to verify age that is both secure and cost-effective.
Furthermore, there is a risk that the verification result will be permanently saved in the user's account. Even if the document is deleted, the "of legal age" attribute remains, and if this data is cross-referenced with other activity logs, a very detailed profile of the person can be built without their explicit consent.
The evolution of these technologies navigates between the imperative need to protect children from digital dangers and the fundamental right of adults to browse the internet without being monitored. Success will depend on implementing privacy-by-design standards and ensuring that digital identity tools are universal, transparent, and, above all, do not turn access to information into an intrusive bureaucratic process.