The Typology Files

Regulatory Update

I Did Age Verification by Hand. The Internet Is About to Learn What That's Actually Like

Every argument about online age checks treats identity verification as a technical problem waiting for a technical answer. It isn't. Behind a betting shop counter the check was never the hard part, and the part that was hard is the part nobody is building for.

By Thomas Geater· 12 August 2026 · 7 min read

Before I wrote about financial crime I worked behind the counter in a betting shop, and part of that job was deciding who to ask for ID.

The rule was Think 25. If someone looks under 25, you check. The legal age is 18, so the policy I worked to sat seven years above the line the law actually draws, which tells you something on its own about who carries the risk. The Licence Conditions and Codes of Practice make the operator responsible, and the consequence of getting it wrong badly enough is the shop’s licence rather than a telling-off.

What nobody explains before your first shift is that the rule does not tell you what to do. You cannot ID everyone. The shop is busy, a good share of the people in it are regulars who have been coming for years, and a shop that stops every customer to inspect a driving licence is a shop with no customers. The rule gives you a threshold and then hands you the actual work, which is deciding, continuously and on your own, who crosses it.

The deciding is the job. The check is the easy bit, and it always was.

What you are actually reading

You develop a set of signals fairly quickly, and none of them are the ones you would list if somebody asked you.

Age is part of it, obviously, but it is the weakest signal, because people are bad at estimating age and you are no exception. The useful ones are behavioural. Does this person know the products? Someone who has been putting the same accumulator on every Saturday for years does it differently from someone doing it for the first time. Are they being pushed forward by somebody waiting outside? Does the bet match the person? Is anyone watching to see whether it works?

None of that is written down anywhere and there is no training module on it.

Here is the part that matters for everything below: those signals were available to me because I was in the room. I could see the door. I could see who came in with whom, and I could see the person outside pretending not to wait.

Online, the check gets easier and the judgement gets impossible

The Online Safety Act placed age assurance duties on services in the UK, and almost all of the argument since has been about the check itself. Facial estimation or document upload. Third party provider or build your own. Whether the data is retained, and whether the whole thing falls over when a teenager holds up a photograph of their older brother.

That is all real, and it is the easy half.

The hard half is the one the counter taught me: when do you run the check at all? A service that verifies every user at the door is the shop that IDs every customer on a Saturday. It is compliant, and it destroys the thing it is attached to. So everybody builds a threshold instead. Something triggers the check, and most people pass through untouched.

That threshold is now the entire control. And it is being set by people who cannot see the door.

The behavioural signals I was reading are either absent online or trivially faked. There is no queue to watch and nobody standing outside. What is left is device data, account age, stated details and patterns across sessions, which is a genuinely useful set of inputs and a much thinner one than standing at a counter with your eyes open.

An old problem with a new surface

Anyone who has worked in anti money laundering recognised the shape of this several paragraphs ago.

The risk-based approach says exactly what the LCCP says. You cannot apply the same depth of scrutiny to everybody, so put the effort where the risk is. Simplified due diligence here, enhanced due diligence there, and a threshold in the middle that somebody has to be able to defend.

Every argument about calibrating transaction monitoring is the Think 25 argument wearing different clothes. Tighten the tolerance and you generate more alerts than anyone can work, which means nothing gets looked at properly. Loosen it and the thing you exist to catch walks past the counter. There is no setting that is correct. There is only a setting you can explain afterwards.

Which is why the age verification debate should be borrowing from financial services rather than starting fresh, and why the borrowing should come with a warning. Thresholds drift. They drift towards whatever produces a workload the team can survive, and that is a different thing from whatever produces the right outcome. The pressure is constant and it only points one way.

What I would want to know

If I were assessing one of these systems I would not start with the accuracy of the check. I would start with three questions, and they are the questions I should have been asked about my own shop.

What proportion of users are actually being checked, and is that number moving? A control that quietly went from checking one in ten to one in fifty has changed completely while every document describing it stayed the same.

Who can change the threshold, and does the change leave a record? In a shop the threshold lived in my head, which was a genuine weakness. In software it lives in a configuration value, which is only better if somebody is watching the configuration value.

And the one people get wrong: when a check is skipped, is that a decision or an absence? There is an enormous difference between a system that assessed somebody and concluded no check was needed, and a system where nothing happened to them at all. In the data those look identical unless you deliberately built them to look different, and hardly anyone does.

The bit I keep coming back to

What surprised me most about doing this by hand was how often the answer was uncomfortable rather than unclear.

Refusing somebody who is plainly over eighteen but has no ID on them makes you the problem for the next ten minutes. They are annoyed, sometimes in front of a queue, and they are right that you have misjudged it. You do it anyway, because the asymmetry is not close. An annoyed adult is ten minutes. A licence breach is the whole shop.

Automated systems do not feel any of that, which sounds like an advantage. It is, right up until you notice the pressure was doing something useful. It was the thing that made a person stop and think about the specific human standing in front of them.

Whatever replaces it had better be doing the same work. Most of the current discussion is not even asking.

Age VerificationOnline Safety ActLCCPKYCRisk-Based ApproachIdentity

Written by

Thomas Geater

I write The Typology Files, on financial-crime compliance and what generative and agentic AI are doing to it. BSc Business Management with Finance, University of Brighton. I work independently and take on advisory and writing engagements.

New pieces by email

One email when something new goes up

No schedule, no digest, no marketing. A piece goes up roughly every couple of weeks and you get one line and a link. Your address is stored by the form handler and used for nothing else. Unsubscribe by replying once.