ID Scanner for Age Verification: Why Bars Get Fooled Anyway
Regula just topped the NIST facial age estimation benchmark on its first appearance. First appearance. The Riga-based forensics firm walked into one of the most watched leaderboards in biometrics and immediately ranked first for Mean Absolute Error across Europe, East Africa, and East and South Asia. That's a legitimately impressive technical result, and the headlines have been suitably enthusiastic.
But here's the thing nobody's saying loudly enough: for the investigator sitting in front of a blurry CCTV grab from a parking lot at 11pm, that leaderboard ranking means almost nothing.
This week's NIST results confirm that facial algorithms are getting exceptionally good under controlled conditions, but real investigations don't happen under controlled conditions, and the three variables that actually determine field performance are barely discussed in the benchmark headlines.
This week delivered a small flood of facial analysis news: Regula's NIST debut, Biometric Update's coverage of the broader FATE leaderboard, new academic research on cross-race and disguised face identification from Wiley's forensic science journals, and a Frontiers paper tackling child face recognition at scale. Taken together, they paint a picture that's more complicated, and more useful, than any single press release lets on.
Facial Age Estimation Benchmarks: The Story Isn't Complete
Let's give credit where it's due. The NIST Face Analysis Technology Evaluation (FATE) program is rigorous, respected, and genuinely meaningful as a signal of algorithmic quality. When Regula posts the lowest Mean Absolute Error for age estimation across multiple geographic regions, beating out established names like a major French-based vendor (ranked 2nd and 5th), a German supplier (4th), and another specialist provider (3rd), that reflects real engineering. The feature extraction is better. The model generalizes more effectively across demographic groups than most of its competitors. That matters.
"Reaching the highest accuracy in the NIST evaluation proves the strength of our forensic-driven approach and biometric verification expertise. Just as important, the results confirm that Regula performs consistently across a wide range of real-world conditions, making our solution the most universal on the market." Ihar Kliashchou, CTO, Regula (via Biometric Update)
"The most universal on the market" is a bold claim, and it's the kind of claim that sounds completely reasonable when you're looking at a clean leaderboard. The challenge is that "wide range of real-world conditions" in a NIST context still means curated datasets. High-quality images. Standardized formats. Controlled variables. That's not a criticism of NIST, that's literally what a benchmark is supposed to do. But investigators need to understand the gap between what a benchmark measures and what their casework looks like. This article is part of a series, start with Why Youre Looking At The Wrong Part Of Every Face.
Three Variables That Age Estimation Headlines Ignore
Here's where it gets interesting. If you read the week's research collectively, the NIST benchmarks, the Wiley paper on cross-race and disguised face identification, the Frontiers study on child face recognition at scale, you keep running into the same three friction points. Demographics. Image quality. Use-case fit. Every single paper circles back to them, and none of the vendor press releases address them head-on.
1. Demographics: Algorithms Don't Fail Uniformly
The cross-race identification research published in Wiley's forensic science journals this week is a useful gut-check for anyone who thinks a strong overall benchmark score means consistent performance. It doesn't. The research on forensic examiners and reviewers specifically tested performance on cross-race and disguised face identification, and the results confirm what forensic scientists have known for years: accuracy degrades selectively, not uniformly, across demographic groups.
This is actually the more dangerous failure mode. A system that performs slightly worse on everyone is predictable. A system that performs dramatically worse on specific demographic subgroups, while posting impressive aggregate numbers, can mislead investigators who don't know to look for that variance. The NIST FATE results for age estimation show Regula performing consistently across Europe, East Africa, and East and South Asia, which is genuinely encouraging. But "consistent across regions" is not the same as "consistent across all age groups, skin tones, and lighting conditions within those regions." The distinction matters when your case subject is outside the distribution the model was optimized for.
2. Image Quality: The Lab-to-Street Translation Problem
Forensic imaging researchers have documented this consistently: a system posting a 0.3% error rate on clean benchmark data can produce significantly higher false-positive risk when image quality degrades. Compression artifacts from CCTV export. Motion blur from a handheld phone. Inconsistent lighting from a doorbell camera at 2am. These aren't edge cases in real investigations, they're the norm. They're also specifically minimized in benchmark datasets, because the point of a benchmark is to measure algorithmic quality in isolation, not to simulate the chaos of real casework.
Understanding the real limitations of face recognition software in field conditions is genuinely different from understanding where an algorithm sits on a leaderboard, and conflating the two is how investigators end up with tools that look great in procurement and disappoint in practice. Previously in this series: Mass Facial Recognition Banned Case Based Comparis.
3. Use-Case Fit: Controlled Comparison vs. In-the-Wild Recognition
The Frontiers paper on child face recognition at scale brings this into sharp relief. Facial algorithms trained predominantly on adult faces underperform significantly on child subjects, a direct consequence of developmental morphological changes, proportional facial differences, and chronic underrepresentation in training datasets. For investigators working missing persons cases, custody fraud, or child exploitation investigations, this isn't a theoretical limitation. It's a case-specific failure risk that no aggregate benchmark score will warn you about.
This is the use-case fit problem in its most consequential form. A top-ranked algorithm built for adult identity verification is not automatically a good tool for cross-age child comparison. These are different problems that require different training data, different model architectures, and different validation approaches. The benchmark leaderboard doesn't tell you which problem a system was actually optimized for.
Biometrics and Privacy-Preserving Age Checks
Biometric age verification depends on biometrics such as facial geometry, not just a scanned document, which is why privacy-preserving age approaches matter to regulators and users alike. A privacy-preserving age design estimates or verifies age without storing a permanent copy of the underlying image, often converting a face into a mathematical template that cannot be reversed into a photo. For an investigator or a compliance team evaluating vendors, the practical consequence is real: a system that keeps raw biometric data on a server is a bigger liability than one that discards it immediately after the age check completes.
Facial Recognition vs Age Verification: Different Jobs
Facial recognition asks "who is this person," while age verification asks only "is this person old enough." Biometric age verification systems that borrow facial recognition components still need to be tuned for the narrower question, because a model built to match identities across a database is not automatically good at estimating a birth year from a single image. Confusing the two use cases is exactly the kind of use-case-fit mistake described above, and it shows up in age verification systems typically collect only a face image and an estimated age range, not a full identity match.
Face Verification and Selfie-Based Age Checks
Face verification confirms that the person taking a selfie right now is the same person in a reference photo, and selfie-based age estimation layers an age guess on top of that same selfie. This combination is common in online age gates for age-restricted products and platforms, where a user's date of birth alone is easy to fake but a selfie paired with facial analysis algorithms estimate a harder-to-spoof number. The tradeoff is that facial analysis algorithms estimate age with a margin of error, so most compliant systems build in a buffer rather than treating the estimate as exact.
Liveness Detection Stops Photo and Video Spoofing
Liveness detection checks that the face in front of the camera is a real, live person and not a printed photo, a video replay, or a mask. Without liveness detection, biometric age verification can be tricked by something as simple as holding up a photo of an older person, which defeats the entire purpose of the check. Regulators reviewing compliance programs increasingly expect liveness detection as a baseline control, not an optional upgrade, precisely because facial recognition scans of static images are so easy to fake.
Biometric Verification in Practice
Biometric verification is the broader category that covers face, fingerprint, and other physical traits used to confirm a claim about a person, and biometric age verification is one specific application of it. When a platform says it uses biometric verification for age, it typically means a face scan is compared against expected patterns for an age range rather than against a specific stored identity. This distinction is worth asking vendors about directly, because "biometric verification" alone doesn't tell you whether an identity is retained anywhere after the check.
Age Estimation Uses Advanced Biometric Algorithms
Age estimation uses advanced biometric algorithms trained on large sets of labeled face images to learn how skin texture, bone structure, and other visible markers correlate with age. These systems output a predicted age or age range along with a confidence score, and the NIST benchmark measures exactly this kind of output under lab conditions. The practical takeaway for buyers is that a benchmark score describes the algorithm's ceiling, not the floor it will hit on your own users' phone cameras and lighting.
What Online Identity Verification Adds to Age Checks
Online identity verification and biometric age verification often run side by side, especially in regulated industries where both a person's identity and their age need confirming before access is granted. Identity verification typically checks a government-issued document against a database or a face match, while age verification can run as a lighter, faster step for cases where full identity isn't required. Building both into one flow adds friction, so many platforms only trigger full identity verification when the age estimate lands close to a legal threshold.
Authentication in this context means confirming that the same user is returning, not re-running the full age or identity check every time. A well-built biometric age verification flow uses authentication for repeat visits while reserving the heavier verification step for the first encounter or for flagged accounts. Users benefit from this because it cuts down on repeated selfie uploads, and compliance teams benefit because the system still keeps an audit trail proving the original check happened.
Data handling is where most of the real-world risk in age verification actually lives. Storing raw face images longer than necessary, or moving data across borders without clear rules, turns a routine compliance tool into a privacy liability regardless of how accurate the underlying algorithm is. Digital platforms that publish a clear retention policy for biometric data, and that delete images promptly after an age decision is made, give users and regulators a much easier system to trust than ones that stay vague about it.
Why This Week's Research Matters for Working Investigators
- ⚡ Demographic variance is selective, not uniformstrong aggregate scores can mask significant performance gaps on specific subject profiles relevant to your case
- 📊 Child face identification is a distinct technical problemadult-trained models don't transfer reliably, and the Frontiers research confirms the gap is measurable and meaningful
- 🔍 Cross-race and disguised face comparison requires specialist validationthe Wiley forensic examiner study shows even trained human experts show performance variance here
- 🏛️ Court admissibility is pushing methodology into the spotlightOSAC guidance increasingly distinguishes documented facial comparison from black-box algorithmic output, and investigators who can't explain their methodology are accumulating evidentiary risk
The Right Question Isn't "Who Won NIST?"
Look, nobody's saying NIST benchmarks are worthless. They're not. An algorithm that consistently leads NIST evaluations has demonstrably better feature extraction than one that doesn't. Dismissing benchmark performance entirely would be anti-scientific, it's a meaningful signal of underlying model quality, and the researchers at NIST do serious, careful work. The honest position is that benchmarks are necessary but insufficient. They tell you the ceiling of algorithmic capability. They don't tell you the floor of real-world performance in your specific operational context.
The question that actually matters for solo investigators and small forensic teams isn't "who scored first at NIST?" It's: does this tool produce a documented, reproducible, explainable result from the exact image quality I encounter on real cases? Because here's the part that's not in any of the benchmark press releases, court admissibility pressure is quietly reshaping what "good enough" means.
Forensic science guidance from bodies like OSAC (the Organization of Scientific Area Committees) is increasingly drawing a hard line between examiner-guided, documented facial comparison and black-box algorithmic output. Euclidean distance analysis with transparent scoring gives investigators something they can defend in a deposition. A leaderboard ranking, presented alone, gives them nothing a competent defense attorney can't pick apart in thirty seconds. Up next: Ai Facial Recognition Wrongful Arrest Tennessee Gr.
"The list also sees strong showings from a French-based vendor (2, 5), another specialist provider (3) and a German supplier (4), who together with Regula make up the top 5." Joel R. McConvey, Biometric Update
Five strong vendors on a single leaderboard. All of them will cite that ranking in their sales conversations. None of that tells you which one has been validated on noisy, low-resolution case photos from the type of investigations you actually run, or which one generates a report you can hand to a prosecutor without wincing.
NIST benchmark results are a reliable signal of algorithmic quality in controlled conditions, but real investigative performance depends on three variables benchmarks don't measure: demographic consistency across your specific case subjects, performance on degraded real-world imagery, and whether the system was built for the comparison task you're actually running. Evaluate on your own case photos. Document everything. The leaderboard is where the conversation starts, not where it ends.
So here's the engagement question worth sitting with: when you're evaluating new investigation technology, how much weight do you give to lab benchmarks like NIST versus your own field tests on real, messy case images? Has a "top-rated" tool ever looked flawless in a demo and then quietly fell apart the moment you ran it on actual case photos?
Because Regula's debut result is genuinely impressive, first appearance, first place, consistent across three global regions. That's a real technical achievement by a serious forensics company. But the investigator who treats that ranking as a purchasing decision has confused the map for the territory. The CCTV footage doesn't care about Mean Absolute Error scores. It just keeps being blurry.
Biometric age verification is becoming the umbrella term for all of this: age estimation, age verification, identity verification, liveness detection, and biometric verification, bundled into a single compliance workflow that platforms deploy to keep minors away from restricted content and services. As biometric age verification rules tighten across more jurisdictions, the vendors who can show a documented, auditable process, not just a leaderboard rank, will be the ones compliance teams and investigators can actually rely on.
Document Verification Still Backs Up Biometric Age Checks
Document verification checks a government-issued ID against known security features and database records, and many biometric age verification programs keep it as a fallback when a face-based age estimate lands too close to a legal cutoff. Pairing document verification with a face scan gives a compliance team two independent signals instead of one, which matters when a single biometric estimate carries a margin of error. A vendor that offers document verification alongside facial age estimation is generally better positioned to handle edge cases than one that leans on biometrics alone.
Age verification and identity verification often get treated as interchangeable in vendor marketing, but they answer different compliance questions. Age verification only needs to confirm someone clears a threshold, while identity verification confirms who the person actually is against a document or database record. A platform that only needs age verification but deploys full identity verification is collecting more personal information than the task requires, which raises unnecessary privacy exposure.
Fraud risk in biometric age verification usually shows up as someone using another person's face, a manipulated photo, or a synthetic image to pass the check. Compliance programs that pair liveness detection with document verification close off most of these fraud paths, because a static photo or deepfake struggles to pass both checks at once. Investigators evaluating a vendor's fraud claims should ask specifically how the system was tested against these attack types, not just how it performed on a clean benchmark.
Identity fraud tied to age verification often involves borrowed or stolen credentials rather than a manipulated face, which is one reason document verification and biometric checks work better together than either alone. A system that only checks a face against an age estimate has no way to catch someone using a real ID that belongs to an older sibling or parent. Layering identity verification on top closes that gap, at the cost of collecting more personal data than a pure age check would need.
Compliance teams weighing biometric age verification vendors should ask for evidence beyond a leaderboard rank: independent testing on degraded images, documented error rates by demographic group, and a clear data retention policy. Compliance obligations increasingly require platforms to show their work, not just cite a benchmark placement, especially in jurisdictions where regulators can audit the underlying process. A vendor's compliance posture is really a combination of algorithm accuracy, data handling discipline, and the ability to produce records that hold up under review.
Security in a biometric age verification system depends as much on how data moves and where it's stored as on how accurate the face match is. A technically strong algorithm paired with weak security practices, like storing images in plain form after the check, still creates real risk for users and legal exposure for the platform. Reviewing a vendor's security architecture should carry as much weight in a purchasing decision as its benchmark ranking.
Age assurance is the broader term regulators use to describe any method, biometric, document-based, or self-declared, that gives a platform reasonable confidence about a user's age. Biometric age verification is one strong form of age assurance, but it isn't the only acceptable one under every regulatory framework, and some jurisdictions accept a layered approach instead of requiring biometrics outright. Understanding where biometric age verification fits inside this wider age assurance landscape helps compliance teams avoid over-building a solution the law doesn't actually require.
Risk assessment for a biometric age verification rollout should weigh accuracy, privacy exposure, and fraud resistance together rather than treating a strong benchmark score as proof the overall risk is low. A tool that scores well on NIST but retains raw images indefinitely may carry more organizational risk than a slightly less accurate tool with strict data deletion. Framing the decision as a risk tradeoff, rather than a pure accuracy contest, better matches how regulators and courts actually evaluate these systems.
Safety considerations for biometric age verification extend beyond keeping minors off restricted platforms; they also cover what happens to a minor's face data once it's captured for the check. A safety-first design minimizes how long any image is retained and limits who inside an organization can access it, treating the biometric scan as sensitive data rather than a routine login credential. Platforms that treat child safety and data safety as the same problem tend to build more defensible age verification programs overall.
An ID Scanner for Age Verification Adds a Document Layer
An id scanner for age verification reads the barcode, magnetic stripe, or printed text on a driver's license or passport and checks it against known document formats before a bouncer or cashier ever has to make a judgment call. Bars, liquor stores, and dispensaries use an id scanner for age verification specifically because a scanner catches a fake ID pattern that a tired employee glancing at a photo at midnight might miss. Compliance teams like this approach because the id scanner produces a timestamped record showing the check actually happened, which matters if a regulator ever asks for proof.
How an ID Scanner Reads a Driver's License
Most id scanners work by reading the barcode printed on the back of a driver's license, pulling the encoded birthdate, name, and license number directly rather than relying on the human-readable text on the front. This id scanning step is fast, usually under a second, and it removes the guesswork of an employee doing mental math on an unfamiliar date format. A physical id scanner mounted at a bar entrance or checkout counter can process a long line of customers far quicker than manual review, which is why bars and clubs with heavy foot traffic tend to adopt them first.
Fake IDs and the Limits of a Visual Check
Fake ids have gotten good enough that a bouncer checking a photo and birthdate by eye will miss a meaningful share of them, especially in low light. An id scanner for age verification compares the scanned barcode data against expected formatting for that state or country, flagging mismatches that indicate a fake id even when the card looks convincing under a bar's dim lighting. Some scanners also check the physical card for security features using a UV or infrared light, adding a second layer beyond just reading the barcode.
License Scanner Hardware Used in Bars and Clubs
A license scanner built for bars and clubs typically pairs a barcode reader with a small screen that shows the customer's age and a clear yes-or-no result, so staff don't need to interpret raw data themselves. These id scanners range from handheld units a doorman carries to fixed stations built into a point-of-sale system at a register. Clubs with strict compliance requirements often log every scan automatically, which gives an owner a defensible record if an underage sale is ever alleged.
Instant Age Verification at the Point of Entry
Instant age verification means the id scanner returns a result in a second or two, fast enough that it doesn't create a bottleneck at a bar door or a retail checkout line. This speed is what makes an id scanner for age verification practical at high-volume venues, where a slow manual check would back up a line out the door on a busy night. The tradeoff is that instant age verification still depends on the id being genuine, which is why pairing a scanner with basic staff training on document security features remains good practice.
An app-based id scanner works much like a dedicated hardware unit, except the barcode reader is a smartphone camera instead of a purpose-built device. This lowers the upfront cost for a small bar or independent retailer that can't justify a fixed scanner station, since the app runs on a phone the business already owns. The scanner app still reads the same barcode and compares it the same way, so the core age verification and fake ids detection logic doesn't change just because the hardware is smaller.
Driver's license scanners act as the front line for most in-person age verification, catching mismatched birthdates and malformed barcodes before a human ever needs to step in. An id scanner reads the encoded data in roughly the same way regardless of brand, though premium units add extra checks like verifying the card against a driver's license database where that data is available. Businesses relying on physical ids as their main age check should treat the scanner as a floor, not a ceiling, since scanning ids still can't catch every fraud method a determined minor might try.
Verification age thresholds vary by product and jurisdiction, so an id scanner needs to be configured for the correct cutoff rather than using a single default across every location a business operates. An age verifiers setup that's misconfigured for the wrong legal age is arguably worse than no scanner at all, because it gives staff false confidence in a system that's quietly approving the wrong customers. Regularly auditing scanner settings against current local law is a basic maintenance step that too many bars and clubs skip after initial installation.
Why Bars Choose Dedicated ID Scanners Over Visual Checks
Bars that switch from a visual check to a dedicated id scanner for age verification usually do it after a near-miss with a fake id that almost got through. The id scanner removes the guesswork, comparing the scanned data against known formatting rather than asking a busy doorman to spot a fake id in a dark entryway. Clubs running high volume on weekend nights find that id scanners also speed up the line, since each check id step takes under a second instead of a squint-and-guess judgment call.
Compliance is the other reason bars and clubs invest in id scanners rather than relying on staff alone. An id scanner for age verification creates a timestamped log of every check id event, which gives an owner something concrete to show if a regulator questions how a compliance failure happened. Bars facing repeat citations often find that a documented id scanner history changes the conversation with local licensing boards.
Not every fake id looks the same, which is why id scanners are built to check multiple things at once instead of just reading a birthdate. A good id scanner cross-references the barcode format, the card layout, and sometimes a UV feature, so a fake id has to pass several checks instead of just fooling a human eye. Clubs that see a lot of out-of-state ids benefit most from this, since staff can't memorize every state's driver's license format the way an id scanner can.
Mobile id scanners have made this kind of compliance affordable for small bars that can't justify a fixed scanning station. A mobile id scanner for age verification turns a phone into a check id tool, reading the same barcode a fixed unit would read and returning the same fast yes-or-no result. For a small club or a pop-up bar at an event, a mobile scanner means the same fake id detection without the upfront hardware cost of a full point-of-sale integration.
Staff training still matters even with an id scanner in place, because the scanner is only as useful as the employee's response to what it reports. An id scanner for age verification that flags a fake id still needs a staff member willing to act on that flag, refusing entry or a sale rather than waving the customer through anyway. Bars and clubs that pair id scanners with clear refusal policies see fewer compliance issues than those that treat the scanner as decoration behind the register.
ID Scanners and Check ID Steps in Daily Bar Operations
Bars that run a busy door on weekend nights treat the check id moment as the single highest-risk step in the whole shift, which is exactly why so many venues now lean on an id scanner for age verification instead of a doorman's eyeball alone. An id scanner for age verification turns that check id moment into a documented event, so the bar has a record beyond a staff member's memory of what happened at 1am. Clubs that log every check id scan tend to have an easier time when a licensing board asks how a specific compliance issue occurred.
Compliance officers reviewing bars and clubs for renewal often ask to see id scanner logs before anything else, because a pattern of consistent check id scans is easier to verify than a manager's verbal assurance that staff are careful. An id scanner for age verification that ties directly into a point-of-sale system can timestamp every check id event automatically, which removes the burden of manual logging from already-busy bar staff. This kind of automated compliance record is what turns a vague policy into something a regulator can actually audit.
Passport-reading id scanners matter for bars and clubs near airports, borders, or tourist-heavy strips, where a driver's license from a home state isn't always the id presented at the door. An id scanner for age verification that can also parse a passport's printed and encoded fields gives bouncers a single check id workflow instead of two separate mental processes for domestic and international documents. Clubs that serve a lot of foreign visitors find that this single-workflow approach cuts down on the fake ids and mismatched formats that trip up staff doing a purely visual passport check.
Magnetic stripes on older driver's licenses still show up occasionally, and a well-built id scanner for age verification should be able to read magnetic stripes as well as barcodes so a bar doesn't have to turn away a legitimate customer with an older card. Bars that only invested in barcode-only id scanners sometimes discover this gap the hard way, when a valid id with a magnetic stripe but a worn or unreadable barcode gets rejected at the door. Clubs upgrading their check id hardware should confirm magnetic stripe support up front rather than assuming every id scanner handles both formats equally.
Point-of-sale integration lets an id scanner for age verification feed its check id result directly into the register system, so a cashier selling age-restricted products doesn't have to run a separate manual step before ringing up a sale. Retailers and bars using this kind of pos-linked id scanner report fewer accidental sales to underage customers, since the register itself won't finalize a restricted purchase until the check id result clears. This tight integration is one reason bars and clubs increasingly ask vendors about pos compatibility before choosing an id scanner.
Developer support behind an id scanner for age verification matters more than most buyers expect, because scanning formats change as states redesign driver's license layouts and add new security features. A vendor with an active developer team can push format updates to an id scanner quickly, keeping the check id process accurate even as license designs shift. Bars and clubs that ignore developer support sometimes end up with an id scanner that quietly starts misreading a newly redesigned license until an update finally arrives.
Veriscan and similar branded scanning platforms are common names bar owners hear when shopping for an id scanner for age verification, since several established vendors sell hardware and software bundles under their own product names. Regardless of brand, the underlying check id job stays the same: read the barcode or magnetic stripe, compare it against expected formatting, and flag a fake id before a sale or entry happens. Bars comparing Veriscan-style systems against other id scanner options should focus on scanning speed, compliance logging, and format update support rather than brand name alone.
Frequently asked questions
What is biometric age verification and how accurate is it really?
Biometric age verification uses facial analysis algorithms to estimate a person's age from an image, and top systems like Regula's have posted the lowest Mean Absolute Error on NIST's benchmark across Europe, East Africa, and East and South Asia. That accuracy is measured on curated, high-quality datasets, though, and performance can degrade on compressed, low-resolution, or poorly lit images typical of real casework.
Why do age verification algorithms perform differently across demographic groups?
Research on cross-race and disguised face identification confirms accuracy degrades selectively rather than uniformly across demographic groups. A system can post strong aggregate benchmark numbers while performing dramatically worse on specific subgroups, which is more dangerous than uniform weakness because investigators may not realize the variance exists within regions that otherwise look consistent.
Can facial age estimation tools reliably identify children?
Facial algorithms trained mostly on adult faces underperform significantly on child subjects because of developmental morphological changes, proportional facial differences, and underrepresentation in training data. For missing persons or child exploitation cases, this is a real case-specific failure risk that a top-ranked benchmark score for adult-focused biometric age verification will not reveal.
