The escalating global legislative landscape demanding robust age verification for online services is fundamentally reshaping how digital identities are managed and protected. As more than 30 countries and a majority of U.S. states enact stringent age assurance laws, the focus is shifting from merely whether platforms verify age to the critical question of how this is achieved and, crucially, what happens to the sensitive biometric data collected in the process. This paradigm shift is pushing the industry towards privacy-preserving architectural solutions, exemplified by Incode Technologies’ recent $100 million commitment and the launch of its groundbreaking On-Device Age Estimation product.
The urgency behind these legislative movements is palpable. The United Kingdom’s Online Safety Act, for instance, is set to implement "highly effective" age checks, with significant restrictions on under-16 access to social media platforms anticipated by spring 2027. Australia has already seen its under-16 online access rules take effect in December, with the government signaling an intent to double maximum fines for non-compliance to $99 million, reflecting a firm stance against early waves of non-adherence. Brazil’s Digital ECA legislation became enforceable in March 2026, further underscoring a global trend. In the United States, the patchwork of state-level mandates means that nearly half of all states now require some form of age verification for specific online activities, creating a complex compliance environment for businesses operating nationwide.
Historically, facial age estimation has emerged as a seemingly straightforward solution, offering a path to compliance without the need for cumbersome government identification or extensive database lookups. This method offers a degree of accessibility, particularly for individuals who may lack formal documentation. In markets with established age assurance regulations, Incode reports that users opt for facial age estimation eight out of ten times compared to other verification methods. However, this widespread adoption comes with a significant user concern: sharing one’s face, a highly personal and sensitive piece of biometric data. Until recently, the standard industry practice involved capturing a user’s facial image, transmitting it to a remote server for analysis, and then processing the age estimation there.
The Perilous Landscape of Server-Based Biometric Processing
The conventional server-based approach to facial age estimation, while functional, presents escalating risks, particularly for vendors relying on third-party technology stacks. The ramifications of data breaches are starkly illustrated by the Identity Theft Resource Center’s 2025 Annual Data Breach Report. This report documented a record high of 3,322 data compromises in the U.S. alone last year, representing a staggering 79% increase over a five-year period. Compounding this crisis, supply-chain breaches – where vulnerabilities in a vendor’s or partner’s systems lead to a compromise – have doubled over the same timeframe.
This data vulnerability has directly impacted consumer trust. The same report found that a significant 63% of consumers have expressed serious concerns regarding the collection of their biometric data. This sentiment is not without justification, as the sophistication of cyber threats continues to outpace defensive measures. Incode, through its analysis of over 7 billion identity verifications processed on its platform, has meticulously tracked the alarming rise of "agentic fraud." This form of fraud leverages artificial intelligence agents to execute attacks with unprecedented speed and scale.
The trend is stark: in 2024, agentic fraud constituted a mere 3% of all fraud attempts. By the first quarter of 2026, this figure had surged to an alarming 40%. Incode’s projections indicate that agentic fraud is poised to exceed 90% of all fraud attempts within the next 18 months, highlighting an escalating arms race in the digital security landscape. This rapid evolution necessitates a fundamental re-evaluation of how sensitive data, particularly biometric information, is handled.
Shifting from Privacy by Policy to Privacy by Architecture
The industry’s traditional response to data privacy concerns has largely revolved around "privacy by policy." This approach relies on a written promise – a privacy policy – stipulating that biometric data will be handled with care and securely deleted after the verification process is complete. While legally binding, a privacy policy is not a security control in itself. It cannot physically prevent a data breach, thwart an insider threat, or safeguard against a compromised vendor. Its function is primarily to assign responsibility after an incident occurs.
A more robust and proactive approach is "privacy by architecture." This paradigm involves designing systems from the ground up to ensure that sensitive data is never accessible in the first place. If a user’s face is never transmitted from their device, it cannot be intercepted during transit. If it is never stored on a server, it cannot be compromised in a database breach. This architectural approach liberates users from having to trust third-party assurances; privacy becomes an inherent feature of the system’s design, a verifiable fact rather than a conditional promise.
A Significant Investment in Privacy-First Identity Infrastructure
In response to these pressing challenges, Incode Technologies, a recognized leader in AI-powered identity verification and fraud prevention, has made a substantial $100 million commitment to advancing privacy-preserving identity infrastructure. This significant investment was coupled with the strategic acquisition of Identiq, a company specializing in privacy-enhancing cryptographic solutions designed for collaborative anti-fraud efforts.
This substantial financial allocation is earmarked for several key areas: enhancing on-device processing capabilities, driving continuous research and development in privacy-enhancing technologies, and expanding engineering resources and the company’s global operational footprint.
The first tangible outcome of this initiative was unveiled in July with the public launch of Incode’s On-Device Age Estimation. This product represents a pivotal moment, marking the first instance where Incode’s proprietary AI models for age estimation and liveness detection operate entirely on the user’s own device. These advancements are not novel departures but rather logical extensions of architectural decisions made at Incode’s inception: a core belief in AI-driven verification, a commitment to processing data at the edge, and a design philosophy for fraud collaboration that inherently protects sensitive information.
Part One: Age Verification Without the Face Leaving the Device
Incode’s On-Device Age Estimation technology integrates two sophisticated AI models directly within the user’s smartphone, tablet, or laptop. These models perform two critical functions: facial age estimation and passive liveness detection. The liveness detection component is vital for ensuring that the individual presenting themselves to the camera is a real, live person, effectively thwarting attempts using static photos, sophisticated deepfakes, or replayed video segments.
Crucially, the entire facial analysis process is executed locally on the user’s device. The facial data is not transmitted to Incode’s servers, nor is it stored by the platform. What is ultimately communicated is the outcome of the verification: whether the user meets the platform’s predetermined age threshold. In instances where the age check cannot be definitively completed due to any technical impediment, the platform automatically presents the user with an alternative verification method, pre-selected by the service provider.
Achieving this level of on-device processing required significant technological innovation. Incode successfully compressed its complex AI models to approximately one-tenth of their original size. This was accomplished through a technique known as knowledge distillation, where a more compact, "student" model is trained to accurately replicate the judgments of a larger, more sophisticated "teacher" model. The resulting lightweight models are optimized to run seamlessly within standard web browsers or mobile applications across a wide spectrum of devices, without the need for specialized hardware.
The architectural decision to process facial data locally means that neither Incode nor the client platform has any technical capability to access a user’s biometric data or images of their face. In essence, the user independently proves their age, and their facial data remains exclusively on their personal device.
The Role of Server-Side Analysis in Session Integrity
While the facial analysis occurs on the user’s device, a residual server-side component remains essential for maintaining the integrity of the entire verification session. An age check that is easily circumvented through session tampering would render the entire exercise futile. Incode’s server-side layer is designed to analyze session metadata – including the timing, methodology, and characteristics of the device and network connection – to detect and prevent sophisticated attacks such as injected camera feeds or manipulated device environments.
This server-side analysis is strictly confined to metadata and contains absolutely no facial or biometric information. Its sole purpose is to fortify fraud detection and ensure the overall security and reliability of the verification session. Without these defenses, the system would be vulnerable to manipulation, allowing minors to falsely present as adults or vice-versa, thereby undermining the core objectives of age assurance and online safety.
Incode’s security infrastructure has been honed over more than a decade of operation within some of the most challenging digital environments. Its models have been rigorously tested and deployed in high-stakes sectors such as banking, fintech, and healthcare, where fraudsters frequently employ advanced techniques like deepfakes, injection attacks, and video replay. The company’s security layer boasts a remarkable 99% spoof detection rate across a comprehensive array of threats, including deepfakes, injection attacks, replay attacks, and physical spoofing. This level of security is comparable to the anti-impersonation standards trusted by eight of the top ten U.S. financial institutions, and Incode’s platform has flagged over one million face-based attack attempts in 2026 alone.
The On-Device Age Estimation product represents the first enterprise-grade solution to successfully integrate on-device age estimation with these advanced server-side session integrity defenses. Incode believes this combination is poised to establish a new benchmark for age verification practices globally.
Part Two: Collaborative Fraud Fighting Without Data Pooling
The second critical component of Incode’s $100 million commitment addresses a distinct, yet equally significant, security exposure: the traditional methods by which institutions share fraud intelligence. Fraudsters operate collaboratively across organizational boundaries, often exploiting systemic weaknesses. Conversely, the entities tasked with defending against these threats have historically operated in relative isolation, each possessing only a partial view of the overall threat landscape.
The conventional solution proposed to bridge this intelligence gap has been the pooling of customer data across multiple institutions into centralized data lakes. However, this approach exacerbates the very problem it aims to solve. These centralized data repositories become prime targets for data breaches, precisely the kind of vulnerability highlighted by recent breach statistics.
Identiq, prior to its acquisition, dedicated nearly a decade and invested over $50 million in developing patented privacy-enhancing technologies. These innovations enable organizations to share critical fraud signals and intelligence without exposing any customer data to third parties or central repositories. This "privacy-by-design" approach eliminates the need for data brokerage and the inherent risks associated with large, centralized data lakes.
When integrated into Incode’s platform, Identiq’s technology is projected to facilitate billions of verifications annually, augmenting Incode’s existing capabilities with invaluable network-level fraud intelligence.
Itay Levy, Co-Founder and CEO of Identiq, articulated the core problem that drove their innovation: "Every institution shared the same concern with us: how do we fight fraud together without giving up control of our customers’ data." He continued, "Identiq built the answer to that very question. As part of Incode, that answer is now available to every organization that deals with massive amounts of user data."
Setting the Standard for a Privacy-Conscious Digital Future
The current landscape is defined by a dual pressure: expanding regulatory mandates on one side, and a growing user demand for privacy-preserving solutions on the other. Regulators are actively deliberating and defining which age assurance methodologies are considered truly effective, making this a pivotal period for establishing new industry standards.
Incode’s current position is not a speculative roadmap but a testament to a proven track record. The company adheres to a comprehensive compliance program, encompassing certifications such as SOC 2 Type 2, ISO/IEC 27001, HIPAA Attestation of Compliance, and FedRAMP Ready status. It also holds the Age Check Certification Scheme (ACCS) and the Kantara IAL2 Component Services Trust Mark. With over 7 billion trust checks processed and now a shipping product where user facial data never leaves their device, coupled with fraud collaboration capabilities that eschew data pooling, Incode is demonstrably leading the charge.
Ricardo Amper, Founder and CEO of Incode, summarized the company’s philosophy: "We have always believed that privacy and fraud prevention are not a tradeoff, but part of the same problem – solved together or not at all." He concluded, "Age checks are becoming law around the world. Our job is to do what we can so that proving your age asks as little of the user as possible."
As global regulations continue to mandate stricter age verification, the industry faces a critical juncture. The innovations pioneered by companies like Incode, focusing on privacy-by-architecture and on-device processing, are not merely technological advancements but essential components of building a more secure and trustworthy digital future for all users. The ability to comply with legal requirements without compromising individual privacy is no longer an aspirational goal, but an achievable reality, setting a new standard for how the digital world verifies identity.








