BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/An AI Guesses Their Age, Give or Take Three Years
IndustryAugust 20, 2026
Read · 5 min
age verification · age assurance

An AI Guesses Their Age, Give or Take Three Years

NIST measured facial age estimation at 3.1 years mean error. What that does to an 18 threshold, and where to set the number the law leaves to you.

Key takeaways
  • Facial age estimation returns an estimate, not a fact. NIST measured the best algorithms at a mean absolute error of 3.1 years, improved from 4.3 years a decade earlier.
  • An error of roughly three years around an 18 threshold is the arithmetic reason your challenge age has to sit above 18, which is the online version of the Think 25 policy shops already run at the till.
  • For bladed products, UK law requires age verification twice, once when the sale is accepted and again when the parcel is handed over. Most merchant tooling addresses only the first.
  • Nobody has told you what good enough means. NIST declines to say whether the software fits any particular use, and the statutory guidance says courts will be the final arbiter.
  • The two errors cost different things. A wrongly approved minor is a legal breach, a wrongly refused adult is a lost sale, and where you put the threshold is a commercial decision about that asymmetry.

If you sell knives, alcohol, vapes, fireworks or anything else with an age on it, you have probably been offered a face check. The customer looks at their camera, a model estimates their age, the order goes through. It is fast, it is cheap, and the sales page will tell you it is highly accurate.

It is reasonably accurate, which is a different claim, and the gap between those two words is where your legal exposure lives. What follows is the published measurement, what the law actually asks of you, and how to set the one number that decides whether this works.

How accurate is facial age estimation?

Good enough to be useful and not good enough to be trusted alone. The National Institute of Standards and Technology ran the first round of its age estimation evaluation across six algorithms and about 11.5 million photographs drawn from four United States government sources, and reported that the mean absolute error fell from 4.3 years in 2014 to 3.1 years.

Mean absolute error is the average gap between the guess and the truth. A figure of 3.1 years means that on average the estimate is out by about three years in one direction or the other, and average is the operative word. Some estimates are close, some are much worse, and the tail is what will reach you as a problem.

NIST also found that error rates were almost always higher for female faces than for male ones, without a settled explanation, and that image quality, sex, region of birth and the subject's actual age all influence how well the algorithms perform. An accuracy figure quoted to you as a single number has flattened all of that.

The sentence in the NIST material that matters most to a buyer is the disclaimer. NIST makes no recommendation about whether the software is fit for any particular use case. It measured the technology and stopped there.

Why does three years matter so much at 18?

Because your threshold is 18 and your instrument has a spread of roughly three years around whatever it returns. Set the pass mark at 18 and you are accepting everyone the model estimates at 18, which will include a meaningful number of people who are 16 and 17.

Physical retail solved this decades ago without any mathematics. The statutory guidance for bladed products describes shops adopting Think 21 or Think 25 policies, where staff ask for identification from anyone who looks under that age, precisely because human judgement of age is unreliable near the boundary.

A face model needs the same buffer for the same reason. If the vendor lets you configure a challenge age, the number belongs several years above your legal threshold, and everyone the model places below that buffer gets routed to a document check rather than refused. That is the design: the model is a fast lane for the obvious cases, not the decision maker for the marginal ones.

Sequence diagram showing an age check running from checkout through a model estimate and a configured threshold to a document fallback and a second check at delivery
The threshold in the middle is the only part of this you control, and it decides everything downstream.

What does the law actually require?

For bladed products in the United Kingdom, considerably more than a checkout widget. The statutory guidance sets out a duty that lands in two places, and merchants routinely buy for one of them.

At the sale, the seller must have a system in place to verify that the purchaser is not under 18, and that system must be likely to prevent purchases by under 18s. The guidance is explicit that a tick box confirming age does not meet this, nor does relying on a buyer's own statement without a further check.

At delivery, verification has to happen again, when the package is handed over. Packages must be clearly marked as containing a bladed article deliverable only to someone aged 18 or over, delivery to a locker is prohibited, and there are restrictions on delivering bladed products to residential premises with a defence available where the seller took all reasonable precautions and exercised all due diligence.

What the guidance conspicuously does not do is name a technology. It leaves the choice to the seller and notes that courts will be the final arbiter of whether a system was adequate. That is an uncomfortable place for a small business to stand, and it is the honest position: you choose, and the standard is judged afterwards.

QuestionWhat is settledWhat is left to you
Is a tick box enough?No, the guidance rules it outNothing, this one is decided
Which system to use?Not specified in the legislationThe entire choice, judged later by a court
How accurate is a face check?NIST measured 3.1 years mean errorWhether that is adequate for your risk
Where to set the challenge age?Nothing in law states a numberThe number, and its commercial cost
Do you check again at delivery?Required for bladed productsContracting your carrier to actually do it
Note

If you sell bladed products, your carrier contract is part of your compliance, not an afterthought. The guidance points sellers toward contractual arrangements with the delivery company requiring age verification on handover, and toward monitoring whether it is actually happening. A carrier who leaves parcels behind a bin has undone the check you paid for at checkout.

Which error are you optimising against?

Both, and they cost completely different things, which is why this is a business decision rather than a technical setting. This is the same shape as a fraud rule, and shops that have tuned one will recognise the trade immediately.

A wrongly approved minor is a legal breach, potentially an offence, and the kind of failure that ends up in a Trading Standards test purchase. A wrongly refused adult is an abandoned basket and a customer who feels accused. The first is rare and catastrophic. The second is common and merely expensive.

Because the costs are asymmetric, the threshold should be too. Push the challenge age up until the legal risk is small, accept the friction that creates, and then work on making the fallback route fast rather than on lowering the threshold. Shops that get this backwards, tuning for conversion and discovering the legal exposure later, are making the same mistake we described in the real cost of blocking a good order, except with a worse downside on the other side.

There is a fairness dimension too, and it is not optional to think about. If the model is less accurate on female faces, then a threshold set to control legal risk pushes proportionally more women into the document fallback. Whatever you think of that, you should know it is happening rather than discover it from a complaint.

Card listing four questions to ask an age assurance vendor before buying, covering mode, threshold, processing location and retention

Estimation or verification, and why the difference matters

These are two different products often sold under one name. A research overview of the field separates systems that operate in estimation mode, predicting an age from facial features, from those in verification mode, confirming a claimed age, and notes that deployment has to weigh legal, ethical and sociological factors alongside the technology.

Estimation asks how old this person looks and hands you a number. Verification asks whether this person is over a stated threshold and hands you a decision. The second sounds simpler and is usually the same model with the threshold applied inside the vendor's system rather than yours, which means somebody else picked your buffer.

Ask which one you are buying. If it is verification, ask what threshold sits behind the yes, and whether you can move it. A vendor who cannot tell you where the line is has sold you a decision you cannot defend.

Where in the checkout should the check sit?

Later than most implementations put it, and the reasoning is about sunk effort rather than technology. A face check placed before someone has chosen anything is a stranger asking for your camera, and it is refused far more often than the same request made after a basket is full.

The three plausible positions each trade differently. Before browsing catches everyone and costs the most traffic. At checkout, after the basket and before payment, is where most shops land, because the customer has committed but no money has moved. After payment, with the order held pending verification, converts best and creates a refund queue plus an awkward email for anyone who fails.

The middle position is usually right, with one exception. If your entire catalogue is age restricted and your fallback is slow, moving the check earlier stops people building a basket they cannot complete, which reads as less insulting than a refusal at the final step.

What matters more than the position is what a failure looks like. A message that says the check did not confirm your age and offers a document route in one tap is a recoverable moment. A message that says access denied, with no route forward, converts a false positive on an adult customer into a permanent loss and quite often a public review. Design the failure state first and the placement question gets easier.

Do repeat customers have to do it every time?

No, and this is where a small amount of design saves both friction and data. Once a customer has been verified, what you keep should be the conclusion rather than the evidence.

A record that says this account was confirmed over 18 on a given date by a given method is enough to let them buy again without repeating the check. It is also dramatically less sensitive than the alternative, because it contains no image and no biometric material, so the ongoing risk of holding it is small. Once a faceprint does get stored, the rules change entirely, as they do when a camera vendor offers to match every face in your shop.

Two caveats keep that honest. The record belongs to the verified account rather than the device or the browser, or you have built something a shared family computer defeats. And a check that was valid a year ago is still valid, since ages do not go down, which makes this one of the rare compliance records that never needs refreshing.

Where it gets harder is guest checkout, which by definition has no account to attach a verification to. Shops selling restricted goods generally end up requiring an account for those products, and the honest framing to the customer is that the law requires the check and the account is what saves them repeating it.

What happens to the photograph?

This is the question that turns a compliance purchase into a data protection one, and it is the one most merchants forget to ask. A face image is not ordinary customer data, and processing it to infer a characteristic puts you in territory with its own rules.

The Information Commissioner's Office has been clear in its work on age assurance that organisations should treat an estimated age as an estimate rather than a fact, should minimise what they collect, should consider on device processing and prompt deletion of images, and should offer alternative routes for people the method does not suit. Recording the outcome as a certainty when the instrument produces a probability misrepresents your own evidence.

Practically, three settings decide most of your exposure. Whether the image is processed on the customer's device or uploaded to a vendor. Whether the image is deleted immediately after the estimate or retained. And what is written into your own records afterwards, which should be the outcome and the method, not the photograph. The retention question is the same one that runs through every AI tool you connect, and it has the same answer pattern we set out in what your AI tools keep after you press delete.

Ofcom's guidance for online services, written for a different duty, has become the de facto reference point on which methods are capable of being effective, treating facial age estimation as one of them while ruling out self declaration. It is a useful benchmark even where it does not bind you, because it is the only public list of that kind.

What to do before you buy

Work out which duty applies to you first, because the answer changes the shape of the solution. Selling age restricted physical goods, hosting adult content and operating a service with a minimum age are three different obligations that people discuss as one thing.

Then run the vendor through four questions. Estimation or verification. Is the challenge age configurable and what is it set to now. Where does the image get processed. How long is anything kept, and what exactly lands in your own database.

Track your false positive rate once it is live, meaning adults the model refused, because it is the only number that tells you whether the buffer you chose is costing more than it is worth. Test it with real faces before you switch it on, including people in their late teens and early twenties if you can, and watch what the fallback route feels like rather than only the happy path. The fallback is where most of your customers in the contested band will end up, so a fallback that takes four minutes and a passport is a fallback that loses the sale.

And keep the evidence. A dated note of which system you chose, what threshold you set, why you chose it and what your carrier agreed to is the file that answers the question a regulator or a court would ask. The choice being yours cuts both ways: nobody can tell you in advance that you got it right, and nobody can say you did not think about it if you wrote down the thinking. If your category is one where this bites, it is worth noting that the same restricted goods list tends to trigger advertising problems too, as we found in which categories collect the most automated ad rejections. Building the check into the storefront rather than bolting it on at checkout is the cleaner path, and it is how we think about restricted product flows in stores built with our ecommerce website builder.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building