Your Kid's Face Scan Doesn't Vanish — And the Math Behind It Locks Out Real Adults Too
Your Kid's Face Scan Doesn't Vanish — And the Math Behind It Locks Out Real Adults Too
This episode is based on our article:
Read the full article →Your Kid's Face Scan Doesn't Vanish — And the Math Behind It Locks Out Real Adults Too
Full Episode Transcript
When a website checks if you're old enough to be there — it faces a choice that has nothing to do with catching liars. It's a silent tradeoff buried inside the math. To keep every last kid out, the system has to start rejecting real, legitimate adults too. And there's no way around it.
If you're nineteen, and a site refuses to believe
If you're nineteen, and a site refuses to believe you're an adult — that's not a glitch. That's the design working exactly as intended. Right now, twenty-five U.S. states, plus the U.K., Australia, and Spain, have laws pushing this kind of age check onto the internet. So this touches almost anyone who goes online. And a lot of people are nervous about it — worried their face gets scanned, stored, and passed around to companies they've never heard of. That fear is fair. But once you understand the machinery underneath, you'll see where the real risk lives — and where it doesn't. So why can't a computer just tell if you're over eighteen?
Start with a bartender. When someone checks your I.D., they glance at your birthdate, confirm you're old enough, and hand the card right back. They don't photograph you. They don't keep a copy. They don't mail your face to four other businesses. Some digital age checks claim to work just like that bartender — quick and private. But many of them do the opposite. They capture your whole face, store it, and share it with a chain of outside vendors. For you, that means one age check can quietly hand your most personal data to companies you'll never see.
Now, the hidden math. According to testing at N.I.S.T. — the U.S. government's measurement lab — even the best age-guessing algorithms are off by roughly two years, sometimes closer to three, for people between thirteen and twenty-four. Two years of wiggle room. So how do you make sure no fifteen-year-old slips through? You raise the bar. One provider set their cutoff at twenty-five — seven years above the legal age of eighteen. At that setting, almost no minors got through. But think about who that traps. Every legitimate nineteen and twenty-year-old now gets challenged, doubted, or blocked. N.I.S.T. even has a name for it — they call it "inconvenience," the rate at which real adults get wrongly stopped.
Push the threshold up to protect kids, and you lock out young adults. Push it down to let adults through, and some minors slip past. There's no perfect middle. A senior analyst at the Electronic Frontier Foundation put it plainly — there's basically no perfect system. Not because companies are greedy. Because the math itself has limits.
The Bottom Line
Now, the part that should actually make you feel better. People assume that if a system knows you're over eighteen, it must know who you are. That feels obvious. But those are two completely different jobs, solved by two different kinds of software. Researchers tested fourteen of these age-estimation models. When they tried to use them to identify people — to match a face to a name — the models performed about as well as a coin flip. They're terrible at knowing who you are. And that's on purpose. A well-built age system asks one thing — "is this person old enough?" — spits out a single number, and throws the image away. No stored face. No permanent record. Just an estimate, then gone.
So the danger was never the age question itself. The danger is a design choice — whether the system grabs your whole identity when all it needed was a yes or a no. And here's the twist that stings — researchers found most sites covered by these laws don't even enforce them. So the data gets collected, the privacy gets spent, and the protection often never arrives.
Let me leave you with the simple version. No age check can be perfect — to keep kids out, it has to wrongly block some adults too. A good system just asks "are you old enough?" and deletes your face right after. A bad one keeps your face and shares it around — and that's a choice, not a requirement. So the next time a site doubts your age, you'll know it's not broken — it's balancing an impossible tradeoff, and the only question that matters is what it does with your face afterward. The full breakdown's in the show notes if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
"Certified Safe" Doesn't Mean What You Think — And Your Face Is In the Database
That little word "certified" on a facial recognition product? It doesn't mean your data can't be stolen. It means a company proved certain safety systems exist — not that those systems can't fail. And
PodcastYour Family Could Be Stuck 8 Hours in 95° Heat at Europe's New Border Lines
Picture a line of cars stretched seven kilometers long. It's ninety-five degrees. And families are sitting in it for eight hours — just to cross a border. That happened on August first at the crossing between Croatia and
PodcastYour Boss Wants to Scan Your Face to Log You In. Ask These 3 Questions First.
Your new office monitor might scan your face before you've had your morning coffee. Not your phone — your monitor. Philips just rolled out a line of desktop displays that log you in by looking at you, and they're landing on office desks right
