AI & Technology

Three ways online platforms can use AI to better protect against underage access

By Clive Summerfield, CEO of FARx

Under the UK’s Online Safety Act, apps, websites, and online platforms accessed by children in the UK must check users’ ages – whether that’s through processes such as entering a birthdate, via a photo ID check or with biometric identity verification. Failure to do so can now result in hefty fines, criminal prosecution and even domain blocking. 

While many security leaders have implemented “age gates” to work towards compliance with the Act, a recent report by Internet Matters suggests that increased digital literacy among young people has made these restrictions nothing more than an easy hurdle to jump. According to the findings, 46% of children believe age checks are easy to bypass, with 32% admitting doing so recently. Among the most common methods reportedly used to bypass age gates are using AI-generated faces, a video of another person’s face or a realistic character from a video game.   

Most recently, Ofcom criticised TikTok, YouTube, Meta, and other major platforms for failing to do enough to protect children, finding that 84% of those aged eight to 12 were still using at least one major service with a minimum age of 13. 

 Ultimately, the challenge for security leaders is no longer whether age checks are in place, but how robust those checks are amid growing digital literacy. Perhaps AI – the tool often used to bypass these security systems – is in fact the answer to robust identity verification and access control online.  

A common scenario 

Imagine this… an adult is creating an account online and completes an ID check to verify that they are who they say they are, and that they are old enough to have an account. 

Confident that the platform is secure, they have no reason to question the process or set up any additional content controls. Only to discover their 10-year-old has quite easily gained access to their account and has been watching inappropriate, and potentially harmful, content for months.  

The account was verified, but the person using it was not.  

The reports show that this scenario is already unfolding daily, exposing a fundamental flaw in how online age verification works today. That flaw is commonplace across a range of security systems; a heavy reliance on a single moment of trust to continuously verify and protect users. For example, with just a password, date of birth, form of ID, or a facial check, the platform accepts that a user is who they say they are from that point onwards.  

But technology has evolved past this. 

Even single-modal biometrics, such as a face scan or a voice print – hailed as the next frontier in identity verification – can now be replicated. Voice cloning, once requiring specialised equipment and expertise, can now be performed with minimal audio samples and widely available tools. Meanwhile, synthetic faces and deepfake videos are becoming increasingly realistic, accessible, and harder to detect.  

Once identity has been verified and access granted, platforms have no reliable way to know whether the same person is still using that account.  

The solution lies in three core shifts 

Moving on from one-shot solutions – Let’s face it, modern day security processes are far from modern. Passcodes, PINs, special answers and even Face-ID have been outgrown by the rapid advancement of AI and technology. These one-shot processes are now nothing more than the sand in which security leaders bury their heads. As William TunstallPedoe (the technologist behind Alexa’s early voice technology) puts it, “voice cloning has gone from expensive, studio-grade work to something that can be done with a tiny voice sample and open-source software… it won’t be long before you’re unable to tell whether the person behind the screen is even real.” 

In order to truly protect people online – be that a child from harmful content or an adult from bank fraud – security leaders must emerge from the sand and explore new innovations. Fused biometrics, for example, uses multi-signal design to recognise the difference between a synthetic identity and a real one as well as a change in identity. This enables advanced protections against AI-powered identity replication, while also closing the gap between initial verification and actual use. This immediately raises the barrier to anyone attempting to bypass controls. 

From a single moment of trust to continuous assurance – To make age verification effective, platforms need to move beyond a one-off gate toward a continuous, verified link between a digital identity and the real personbehind it; confirming not only who set up the account but also who is using it at any given moment.  

AI-powered fused biometrics provides a way to facilitate this shift, by logging and learning multiple biometric signals – such as voice, face, speech attributes, facial movement, and liveness indicators. In doing so, the system can continuously and seamlessly operate in the background of the chosen application to monitor interactions and act when those biometric signals change – such as when a child attempts to access their parent’s account or a fraudster has hacked into a bank account. Upon flagging a change, content can either be restricted or the session shut down entirely. 

Essentially, it is the confirmation that an account not only belongs to a real person, but that the same real person remains present throughout a session, and not just at login. 

Recognise that regulation alone won’t fix the problem – While Ofcom now has the power to enforce the Online Safety Act, the real challenge for CTOs is technical: building trust in digital interactions at a time when AIdrivenimpersonation is making deception easier than ever. The technology to do this already exists in the form of fused biometrics. 

Put simply, it’s a case of recognising humans the way humans recognise each other, by combining voice, speech and face recognition to verify who is really on the other end of the device, continuously and reliably. 

Author

Related Articles

Back to top button