CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Facial Age Verification: Face Verification Fixes Congress Missed

Every Bet, Every Login: Congress Wants Your Face Scanned to Gamble Online
A smartphone camera prompt illustrates facial age verification, the scan-based check proposed for online sports betting apps.

Picture this: You open your sports betting app on a Sunday morning, coffee in hand, ready to place your usual wager on the game. But instead of your balance and the odds, you see a camera prompt. Show us your face to continue. That's not a dystopian hypothetical anymore. It's the direction a bipartisan group of U.S. lawmakers is actively pushing, right now.

TL;DR

A new federal bill, introduced by Rep. Josh Gottheimer with eight co-sponsors, would require online betting apps to scan your face every time you log in or place a bet, but the bill includes no accuracy rules, no anti-spoofing requirements, and no enforcement penalties.

Rep. Josh Gottheimer introduced the bill with eight co-sponsors in what CryptoNews describes as the first time legislators have sought real-time biometric checks (meaning face scans tied to your physical body, not just a password) for every single financial transaction on sports betting and prediction platforms, not just when you first sign up. Every login. Every wager. Your face, every time.

The stated goal is protecting kids. And honestly? The problem it's trying to solve is real. According to Common Sense Media data cited in Gottheimer's official congressional release, 36% of boys between ages 11 and 17 have gambled. That's more than one in three. These aren't kids sneaking into casinos, they're on the same phones they use for homework.


Facial Age Verification Mandates: The Real Problem

Age Estimation, Biometric Verification, and Why the Gap Matters

Age estimation and biometric verification sound like the same thing, but they solve different problems. Age estimation just guesses a number from your face. Biometric verification tries to confirm you are a specific, previously known person. A bill that mixes the two up, as this one arguably does, ends up demanding facial recognition-grade data collection while only delivering age-estimation-grade accuracy.

Minors are getting into betting apps. The numbers are hard to argue with. Iowa's Division of Criminal Investigation has received more than 80 reports of underage betting. Tennessee's sportsbooks flagged over 400 underage accounts in 2024, up from about 100 the year before, according to Gaming America. How are they getting in? Mostly through shared accounts (a teenager using a parent's login), fake IDs that pass basic checks, or simply accessing someone else's unlocked phone.

Online sports betting exploded after 2018, when a Supreme Court ruling let states set their own rules. American bettors now wager roughly $160 billion on sports each year, generating about $16 billion in revenue for the industry. That's an enormous market, and apparently, a meaningful slice of it involves people who are legally too young to participate. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.

400+
Underage accounts flagged by Tennessee sportsbooks in 2024 alone, quadruple the number from the prior year
Source: Gaming America / USA Today investigation

So lawmakers want to use face scans to stop it. The instinct is understandable. The execution? That's where things get complicated fast.


Age Verification Solutions vs. Facial Scans

Facial Recognition, Face Verification, and the Selfie Problem

Facial recognition and face verification both start with a selfie, but a selfie alone can't prove age or identity on its own. A live selfie check paired with liveness detection can help confirm a real person is present, not a printed photo. Still, a selfie only works as well as the estimate behind it, and no estimate is perfect.

Here's a distinction that matters, and that most coverage is glossing over: the bill isn't asking apps to recognize who you are. It's asking them to estimate how old you look. Those are two very different things.

Facial recognition tries to match your face to a known identity, like a database, a passport photo, or an account profile. Age estimation is different. It analyzes your face and essentially guesses: this person looks like they're probably 34. It doesn't confirm you're the account holder. It just tries to decide whether you're old enough to bet.

The National Institute of Standards and Technology (NIST), the federal agency that evaluates this kind of software, studied age-estimation algorithms and found that no single system clearly outperformed the others. The average error? 3.1 years. On a visa photograph. That's a best-case scenario with a high-quality, controlled image. On a dimly lit phone camera at 10pm? The margin for error only grows.

"The bill sets no accuracy standard, no anti-spoofing safeguard, and no enforcement mechanism or penalty, and leaves no rule for users whose estimated age lands near the legal line, and no defense against photos, recorded video, or synthetic faces." Technical analysis of the proposed legislation, Legal Sports Betting

Read that again. No accuracy rules. No protections against someone holding up a photo of an adult in front of their camera. No rules for what happens if the software guesses you're 20 when you're actually 24, and the app locks you out of your own account. The bill is less a technical standard and more a political statement dressed up as a solution. Previously in this series: That Attack Ad About Your Local Candidate A Laptop Made It A.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

What This Actually Means for Online Betting

Face, Age, and User Trust in Everyday Verification

Every user handing over a face scan is trusting that the age threshold built into the software actually reflects a fair, tested standard. Right now, that trust isn't backed by any published rule. A user check that fails silently, or locks someone out with no appeal, is a user experience problem as much as a privacy one.

If you're a regular adult who bets on games, here's the practical reality. Platforms would be required to build face-scan checkpoints into everyday account use. You'd hand over biometric data (your face, the thing that makes you you, that you can't change if it gets stolen) to a private company operating in an industry not exactly known for its data-security track record.

And here's the thing: the company receiving that face scan doesn't have to be the betting platform itself. They'd outsource it to a third-party verification vendor. Which means your face travels through at least two companies' systems every time you log in. That's before considering that determined underage users will likely just use a parent's phone, face and all, or find workarounds through other means, according to RG.org's investigation into how minors bypass existing sportsbook safeguards.

Why This Matters, Even If You Never Bet

  • This won't stop at betting appsFace-scan age checks in gambling are a test run. If it works politically, expect them in online poker, day-trading platforms, and high-limit payment apps next.
  • 📊 A 3.1-year error rate has real victimsA 22-year-old who looks young could get locked out of their own account. Skin tone and lighting conditions make those errors worse, not better, for some users.
  • 🔮 The winning companies won't be gamblersThe real beneficiaries of this bill are the biometric vendors building the face-scan software. Whoever gets into these platforms first will have contracts and data pipelines that are very hard to displace.
  • 🔐 Your face is not a password you can resetIf a betting platform's vendor gets breached and your facial data leaks, there's no "change face" option. This data is permanent in a way that email addresses and phone numbers simply aren't.

Tribal gaming operations face their own wrinkle here. As SCCG Management notes, tribal sovereignty means federally mandated tech requirements create legal friction between federal authority and tribal gaming rights that the bill doesn't begin to address. This thing isn't just half-baked, it's essentially raw dough.


The Gap Between "Policy" and "Protection"

Look, nobody is arguing that underage gambling is fine. It isn't. The jump in flagged accounts in states like Tennessee is genuinely alarming, and the industry has done a mediocre job policing itself through conventional means like knowledge-based questions (your mother's maiden name, your first car) and ID document uploads.

But there's a difference between a policy that solves a problem and a policy that appears to solve a problem while creating new ones. This bill currently looks a lot like the second type. No accuracy benchmarks. No demographic bias testing (meaning no one has to prove the software works equally well across skin tones and ages). No penalties for platforms that implement it badly. And no acknowledgment that a face-scan can only tell you what someone looks like, not whether they're the person whose account you're trying to access. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

As Gaming Intelligence notes in its legislative analysis, platforms facing compliance pressure (requirements to follow the rules, or risk fines and losing their licenses) will rush to integrate whatever verification vendor promises the fastest, smoothest rollout, not necessarily the most accurate or secure one. Speed will beat safety. It almost always does when a deadline is involved and the details are vague.

Key Takeaway

The bill's child-safety goal is real and worth taking seriously. But as written, it mandates the collection of permanent biometric data from millions of law-abiding adults without setting any standard for accuracy, fairness, or security, which means it may create a false sense of protection while normalizing face scans for financial apps across the board.

If you've ever wondered whether an app asking for your face is really protecting you or just protecting itself from liability (meaning the ability to get sued), that's the exact tension this kind of legislation forces into the open. The smart move for anyone using a regulated financial app right now, betting or otherwise, is to read the privacy policy before any face-scan prompt appears, specifically looking for how long your biometric data is stored and whether it's shared with third parties. That single habit won't protect you from everything, but it puts you miles ahead of most users who just tap "allow" and move on.


Here's the question nobody in this debate is asking loudly enough: if a 15-year-old can beat today's age verification by borrowing a parent's phone, and the proposed solution is a face scan that also runs on that same parent's phone, exactly what problem are we solving? The technology isn't the barrier. The shared device is. And no bill has proposed scanning the phone.

Age verification and age estimation get used interchangeably in coverage of this bill, but the legal text leans on age estimation specifically, a technical choice with real consequences for accuracy expectations. Age assurance is the broader industry term covering both approaches, plus document checks and parental confirmation, and it's worth knowing that vocabulary before evaluating any age verification proposal in Congress.

Yoti's age verification service is one of the most cited examples in this space, and it's worth understanding why. Yoti uses facial estimation models trained on millions of images to guess an age range rather than confirm an exact identity, which is precisely the kind of age assurance approach lawmakers seem to be assuming, without writing that assumption into the bill's text.

Age verification face scans create new threats that a simple ID check never did. Once a platform stores biometric templates instead of scanned documents, a breach exposes something a person cannot change or replace. That single fact should shape how any age verification mandate handles storage and retention, and this bill currently says nothing about it.

Privacy-protective facial scanning is technically possible, some vendors process an image, produce an age estimate, and discard the photo immediately without retaining biometric verification data long-term. But "possible" is not the same as "required," and nothing in the current bill forces platforms toward that privacy-protective facial design instead of the cheaper, more invasive alternative of permanent storage.

Face verification and identity verification often get folded into the same conversation as age checks, but they answer different questions. Face verification confirms this face matches that face; identity verification confirms this person is who they claim to be on paper. Age assurance, by contrast, only needs to answer one narrower question: does this person meet an age threshold.

Liveness detection matters here because a static photo or video replay can otherwise fool an estimate-only system. Without liveness detection built into the verification flow, someone meets the age threshold on paper simply by holding up a photo of an adult relative. The bill's silence on liveness detection is one of its most glaring omissions.

Information security practices around stored face data deserve more attention than they're getting in this debate. Our privacy expectations around biometric verification should not be lower just because the sector involved is sports betting rather than banking. A breach at a verification vendor exposes the same permanent facial data regardless of which industry hired them.

Identity verification vendors serving the betting industry will likely see this bill as a business opportunity rather than a compliance headache. Whichever company offers the fastest identity verification integration is likely to win contracts across multiple sportsbooks, concentrating a huge amount of sensitive age verification and biometric verification data in very few hands.

Age assurance done well involves layered checks, an estimate as a first pass, document verification as a backup, and clear appeal paths when the age estimation software gets it wrong. Age assurance done poorly is just a single selfie scan with no fallback, which is closer to what this bill currently allows. The difference between those two versions of age assurance is exactly what lawmakers should be debating before passage.

Frequently asked questions

What is facial age verification and how would it work for betting apps?

Facial age verification uses a face scan to estimate how old someone looks, rather than confirming their identity. Under the proposed bill, betting apps would require a face scan at every login and every wager, analyzing the face to guess an age and decide whether the user is old enough to bet, without matching that face to a known identity database.

How accurate is facial age verification technology?

According to NIST testing, no age-estimation algorithm clearly outperformed the others, and the average error was 3.1 years on a visa photograph, a controlled, high-quality image. On a dimly lit phone camera at night, that margin of error would likely grow, meaning someone in their twenties could be misjudged and locked out.

What are the risks of using facial age verification for online betting?

The bill requiring facial age verification includes no accuracy standards, no anti-spoofing safeguards, and no enforcement penalties. It offers no defense against photos or recorded video, no rule for users near the age threshold, and requires handing biometric data to a betting platform and a third-party vendor, meaning a face travels through at least two companies' systems.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search