The Internet is starting to card everyone. These startups are making millions from it


Age-verification systems are increasingly sophisticated. They're lucrative for the businesses creating them, too. — Pixabay

At a liquor store, bar, or casino, getting carded is part of the cost of entry. Now the Internet is carding people, too – and the companies doing the carding are cashing in.

New laws and platform rules are pushing games, social platforms, AI products, and adult sites to replace birthday boxes (the fields where you enter your date of birth) with identity checks. What was once a compliance tool for sellers in age-restricted industries is becoming infrastructure for the Internet, and a growth market for the companies supplying it.

Socure, a Nevada-based identity-verification company founded in 2012, says it now generates more than US$340mil (RM1.39bil) in annual recurring revenue from over 3,000 customers. New ARR (annual recurring revenue) grew 62% year over year, and age verification is among its fastest-growing product lines. The roughly 500-person company has raised approximately US$646mil (RM2.64bil) in private funding.

London-based Yoti, founded in 2014 by Robin Tombs, 57, and Noel Hayden, 55, says it has completed more than one billion age checks for roughly half a billion people. Its revenue rose 62% in 2025 and reached roughly US$43mil (RM175.91mil) in the year ended March 2026.

And San Francisco identity startup Persona, founded in 2018 by Rick Song, 35, and Charles Yeh, 33, raised US$200mil (RM818.20mil) at a US$2bil (RM8.18bil) valuation in April 2025. The roughly 700-person company has raised about US$418mil (RM1.71bil) to date, and its annual recurring revenue surpassed US$100mil (RM409.10mil) in 2025, according to a Forbes estimate.

Age assurance is one use-case within its broader identity-verification business; Persona works with businesses including Roblox, OpenAI, Coursera, and Lime.

All three are benefiting from the same shift: Businesses increasingly need to know not just who a user is, but how old they are and which parts of their platform they should be allowed to enter.

“At a casino, you have to physically walk in,” Socure founder and CEO Johnny Ayers, 41, tells Inc. “Now you can do it from your phone.”

A complex regulatory environment leads to business opportunities

Regulatory pressure is arriving from several directions. Britain now requires services hosting “harmful” content to use “highly effective” age assurance (though both terms remain undefined).

Australia requires social-media platforms to take reasonable steps to prevent children under 16 from holding accounts. The European Commission is developing an EU-wide method for anonymously proving that a user is above a required age.

In the United States, businesses face a state-by-state mix of adult-content laws, app-store requirements, children’s privacy statutes, lawsuits, and federal legislation. That turns a seemingly simple question – How old is this user? – into a series of product and legal decisions. Which users must be checked? Is a facial estimate enough? Should the company demand an identity document? What happens when a child is verified as an adult – or an adult enters a space intended for children?

Those questions can be headaches for the platforms themselves, but they create new potential customers for identity companies.

Socure began by helping banks, fintech companies, gambling platforms, and government agencies determine whether users are who they claimed to be. Age was already embedded in those decisions. “If you’re opening a PrizePicks account, you have to be 19. If you’re opening a sportsbook account, you have to be 21,” Ayers says. “Now go to an adult-content site, you have to be 18.”

Its systems can combine phone and device signals, facial age estimation, barcode scans, identity documents, behavioral information, and fraud checks. Customers can begin with a lighter check and escalate when the user, behaviour, or jurisdiction appears riskier. But a method accepted in one state may not satisfy another.

“You’re left with a half solution, which can only work in five or 20 of the states, not every state,” says Deepanker Saxena, Socure’s head of product.

Age verification is becoming less like checking ID at a door and more like designing a risk system: when to check, how hard to check, and what to do when the result is uncertain. All of this must happen without driving away legitimate customers.

From birthday box to biometrics

Yoti shows what the pure-play version of the market looks like. Its products include what chief regulatory and policy officer Julie Dawson describes as 12 forms of age assurance, including facial age estimation, mobile-number checks, and inference signals, and a free consumer digital-ID app that lets users reuse a verified age credential across businesses that accept it.

PlayStation uses Yoti for age verification in the United Kingdom and Ireland. Instagram has tested its video-selfie technology, while Epic Games uses its facial age estimation in parental-consent flows.

Dawson says Yoti moved toward facial age estimation after encountering users who did not possess identification, did not want to share it, or did not control their own documents. She distinguishes the process from facial recognition: it estimates a person’s age without matching the face to a known identity, then deletes the image. “Detect, analyse, delete,” she says.

Yoti says its model has a mean absolute error of 1.1 years for users ages 13 to 17 and 1.3 years for children ages six to 12.

The technology can keep children out of adult spaces. Companies are increasingly also using it to keep adults out of spaces intended for children. Dawson points to youth-focused platform Yubo, which has used Yoti to separate teenagers from adults. The concern, she says, includes “55s in the teens areas”.

That risk is also driving changes at much larger youth platforms. Roblox, for example, is building one of the most ambitious age-based systems using Persona. Roblox says 231 million people visit daily. As of March 31, more than half of its global daily active users – and 65% of its US users – had completed an age check. The platform now requires an age check before users can access chat, limits communication to similar age groups, and uses age-based accounts to shape content, defaults, and parental controls.

“Age checks alone are one piece,” a Roblox spokesperson says. “Youth online safety involves a multilayered system.”

Still, age checks do not end the trust-and-safety problem. For example, a 16-year-old seller tells Inc. they have sold 16 Roblox accounts since January that passed the platform’s facial age check in the 13-to-15 range, unlocking chat and voice features. Similar listings reviewed by Inc. were advertised as “verified with face”.

The sales expose a contradiction in online verification: A verified account may be safer – and more valuable to someone trying to bypass the safeguard. An industry source says verified under-18 accounts can sell for US$5 to US$150 (RM20 to RM613) depending on their history and access, and marketplaces built around such accounts can be worth tens of thousands of dollars.

Roblox prohibits buying or selling accounts. It says its system is more accurate than self-declared ages and defaults users to the youngest age supported by an estimate.

The company also uses behavioral analysis to detect age mismatches, and may prompt users to complete another age check or revoke age checks for accounts suspected of changing hands.

But once a platform attaches privileges to an age classification, that classification acquires financial value.

The arms race after verification

Age verification does not end fraud. It changes the target. A child can borrow an adult’s identification. A buyer can purchase a verified account. VPNs can send users through different regulatory systems. Reddit threads and creator videos trade instructions for bypassing the checks.

Companies must also detect deepfakes, injected camera feeds, emulators, printed photographs, masks, and prerecorded videos.

“Fraudsters are creative,” Saxena says. “Teenagers are much more creative.”

Entrust’s 2026 Identity Fraud Report found that deepfakes were involved in one in five biometric fraud attempts. Deepfake selfies increased 58% in 2025, while injection attacks – attempts to feed manipulated images or videos directly into a verification system – rose 40%. Yoti says it detected 3.2 million injection attacks across its age and identity checks last year.

Vendors therefore examine not just the face but the device and session around it. Socure even examines how a phone vibrates. Saxena says a phone resting on a table moves differently from one held in a hand, which absorbs part of the vibration. The signal helps distinguish a person from an emulator or bot.

“Our goal is, can we understand the entire physics of how the process works?” he says.

The cost of knowing

The harder companies try to verify age, the more invasive the process can become.

Yoti says it returns only the result of a check rather than the person’s underlying identity. Dawson says users often assume age assurance means handing personal information to every website they visit.

“People think we’ve got paper airplanes sending entire documents with all of your data,” she says, “when all we’re sharing is ‘over 18’ or ‘over 16’.”

Socure says it also returns a yes-or-no result without disclosing a name or exact age. “We run the transaction, return yes-no age, delete the transaction,” Ayers says. “You turn the light on and you turn the light off.”

But a minimal answer does not necessarily mean minimal processing. Socure’s privacy policy says its products may process identity documents, biometric information, device and network data, behavioral signals, verification results, and risk insights.

Rindala Alajaji, associate director of state affairs at the Electronic Frontier Foundation, a digital civil-liberties nonprofit, says no current method solves every part of the problem.

“There is no technology available that is entirely privacy-protective, fully accurate, and that guarantees complete coverage of the population,” she says.

Even when a platform receives only an over-or-under result, the vendor may still process sensitive information to produce it. ID-based checks can also exclude users who lack identification or whose appearance does not match their documents.

“Age-verification systems are surveillance systems,” Alajaji says. “No one should have to sacrifice their privacy or anonymity in order to exercise their free speech rights online.”

Buy it, build it, risk it

For founders building products that may be used by minors, allow users to interact with one another, or offer age-restricted content, the first question is whether an age gate is required at all. Then they must decide where it belongs, which users must pass through it, and how much data, friction, and error the business can endure.

Dawson, of Yoti, expects the eventual system to be hybrid: reusable credentials for some users, documents for others, facial estimates or device signals where appropriate, and checks performed only when someone enters a restricted area.

The United States may prove especially difficult. Without a national privacy or online-safety framework, businesses face competing state mandates, product-design rules, lawsuits, and technical standards.

For Yoti, age assurance is the business. For Socure and Persona, it is a fast-growing use case within broader identity systems. For their customers, it is a compliance expense, a product decision, and a new source of liability.

The internet’s bouncer is no longer guarding one door. It is deciding which room every user belongs in – and whether the person holding the phone is really the person trying to enter. – Inc./Tribune News Service

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read