You Cannot Legislate an Age Estimation Into Proof

Age estimation software looks at a face and returns a number. It estimates age; it does not prove it. On average, that distinction may seem small. For any person — especially someone near a legal cutoff — it is not. Facial age estimation is uncertain, precisely where an 18-year threshold demands certainty.

H.R. 9706 would build a federal child-safety mandate on that uncertainty. On July 15, Rep. Josh Gottheimer, D-N.J., introduced the Facial Recognition to Protect Children Act. The bill would prohibit sportsbooks and prediction markets from allowing users to access a platform, take a wager or place an order unless they have verified that the user is over 18 “using commercially available facial recognition technology.”

But age estimation and identity verification are different tasks. One infers someone’s age from a face. The other matches a face to a verified identity document or record. The statute appears to require the latter, while the sponsor’s office describes the former. That distinction is not semantic. Read literally, the bill calls for facial matching against a verified document — a method that can reliably enforce an 18-plus threshold. Read as the sponsor’s office describes it, however, the mandate is facial age estimation. That’s a different technology, with different tradeoffs and it cannot prove someone is 18.

The Bill’s Underlying Concern is Justified

The bill is right to recognize that a one-time signup check is not enough. It confirms only who held the phone on the day an account was opened and does not prevent a 16-year-old from later accessing a parent’s authenticated account. Common Sense Media, whose research the sponsor cites, recommends age assurance that extends beyond registration and continues throughout a user’s relationship with a platform.

That principle is sound — “continuous” means risk-triggered, rather than a face scan at every login. A new device, a major change in behavior or a withdrawal that breaks an established pattern may warrant renewed verification. Routine, low-risk sessions generally do not.

The research driving the proposal, however, needs more careful framing. Common Sense Media’s headline finding — that 36% of boys gambled in the prior year — includes loot boxes, March Madness brackets and bets among friends. Only about one-third of that activity was sports-related, and the report does not establish how many respondents used a licensed sportsbook or prediction market. A federal mandate built around that figure risks designing a sportsbook control for conduct that often takes place well outside regulated gambling platforms.

That does not weaken the case for stronger age assurance. It clarifies what the policy must actually solve — and why the technology named in the bill matters. Facial age estimation is not weak; it is improving rapidly. But an 18-year threshold is among the hardest settings in which to rely on it, particularly when the bill’s only quality requirement is that the product be “commercially available.”

The Higher the Gate, The Wider the Guess

When the National Institute of Standards and Technology ran dozens of submitted age-estimation algorithms against the same standardized government photographs, the average error ranged from roughly 2.5 years to more than 10 years. These were research submissions tested under ideal conditions. The bill does nothing to distinguish the best systems from the worst. The threshold itself yields the harder problem.

Australia’s government-commissioned Age Assurance Technology Trial tested more than a dozen vendors. Its examiners concluded that expecting age estimation to “implement exactly a specific age-restriction” reflects “a fundamental misunderstanding” of the technology’s capabilities unless there is both an accepted margin of error and a buffer above the legal age. Add that buffer, they found, and false negatives become inevitable.

The trial’s own results show the problem worsening as the legal threshold rises. For an 18-year-old cutoff, its systems only cleared users estimated to be 21 or 22. Ofcom, the UK’s online-safety regulator, goes further: for an 18-plus requirement, its guidance uses a challenge age of 25, requiring a second check for anyone estimated below it.

Place the legal gate at 18 and set the challenge threshold where regulators suggest, and age estimation sends nearly every user it is supposed to adjudicate somewhere else. At that point, it is no longer a gate. It is triage: useful, relatively inexpensive and less intrusive, but dependent on a stronger underlying process. H.R. 9706 mandates triage, yet requires nothing meaningful of the checks that follow.

Who Gets Turned Away

The best systems the National Institute of Standards and Technology (NIST) tested can be tuned so roughly one in 10 teenage boys is incorrectly passed as an adult. At that same setting, as many as two in five girls of the same age may be passed. Nearly every system NIST tested made more errors for girls than boys when calibrated around boys’ outcomes.

The tradeoff is substantial: the same settings can wrongly block between 6% and 19% of legitimate adults under 30. A block rate in that range is not automatically disqualifying (and no security control is perfect). Still, it becomes indefensible when the law requires no appeal, fallback route or documented review for people the software gets wrong.

NIST also finds that performance varies by region of birth and by sex. A policy that makes an automated estimate dispositive while offering no recourse to those it wrongly excludes creates a single point of failure in a system designed to protect consumers.

Congress Has Named a Machine Before

Congress routinely names a technology in statute and leaves the agency to fill in standards later. H.R. 9706 states that the Federal Trade Commission (FTC) “may” do so. May is not will.

In 1991, the Telephone Consumer Protection Act (TCPA) defined an “automatic telephone dialing system” and left the Federal Communications Commission (FCC) to interpret it. Technology moved from random-number generation to stored contact lists. The statutory definition did not and the circuits split. In 2021, the Supreme Court held in Facebook v. Duguid that the law was bound by the language Congress wrote three decades earlier. The TCPA is an instrument that has gone obsolete. H.R. 9706 names one that is not the instrument its sponsor describes as being deployed.

Make Operators Show Their Work

An operator should have to measure its own error rate against a published benchmark and publish the result. Anyone it turns away should reach a human being, through a queue staffed for the volume its own false-positive rate creates. And it should hold an auditable record of what was checked, when it happened and what came back. 

None of that is a case for collecting more data. Good governance means keeping clear records of how decisions were made, and the bill already requires operators to delete identifying biometric data they do not need. Audit records carry the evidentiary weight that stored faces are usually kept for.

One more provision belongs in the bill: Congress should cap how often verification can be compelled. The sponsor’s description includes a check that runs on every login. However, most sessions carry no meaningful risk. The ones that do announce themselves through a new device, an abrupt change in behavior or a withdrawal that breaks a pattern. 

Two things reliably gate an 18-year-old, the first is a government ID check paired with liveness detection. The other is a match against a record that has already been verified. Britain settled this in 2019, when the Gambling Commission began requiring operators to verify a customer’s name, address and date of birth before letting them bet. What we are all trying to build is confidence that the right person is on the right account at the right time. A guess can tell you who to check, but it cannot tell you who to let in.

Take the First Step Toward Transformative Fraud Prevention