Compliance
Highly effective age assurance (HEAA)
Highly effective age assurance is the standard the UK Online Safety Act sets for services that must keep children away from adult content. Ofcom judges it against four criteria: technically accurate, robust, reliable and fair. It is a higher bar than "we asked", and Ofcom has named methods that do not clear it.
Also called: HEAA, highly effective age assurance, Ofcom age assurance standard
At a glance
- Law
- Online Safety Act 2023
- Regulator
- Ofcom
- Criteria
- Technically accurate, robust, reliable and fair
- Own pornographic content (Part 5)
- Duty in force 17 January 2025
- Children's codes (Part 3)
- Enforced from 25 July 2025
- Penalties
- Up to 18 million pounds or 10% of qualifying worldwide revenue
The four criteria
Technically accurate is whether the method correctly determines age in the first place. Robust is whether it holds up against ordinary circumvention, not just against a cooperative user. Reliable is whether it works consistently across your actual user population, and not only in a demonstration. Fair is whether it works equally well across demographics, which is where facial estimation has historically struggled and where a credential based check has less to prove.
The criteria are cumulative. A method that is accurate but trivially bypassed is not highly effective, and neither is one that is accurate for most people and much worse for some.
What does not meet it
Ofcom has been direct that self-declaration of age does not meet the standard, and neither does a general-purpose payment method that is available to under-18s. Contractual restrictions in your terms of service are not age assurance at all.
The enforcement is real rather than theoretical: the Act carries penalties up to 18 million pounds or 10% of qualifying worldwide revenue, whichever is greater, and Ofcom has issued seven-figure fines over weak age checks.
Where a wallet based check sits
A credential issued by a government backed source and cryptographically verified is strong on the first three criteria by construction: the answer comes from an authority instead of an inference, the signature is checkable, and it does not degrade with lighting or accent or age band.
The honest caveat is coverage, not strength. A method nobody can use is not reliable in Ofcom's sense, so during the rollout a wallet check is one route among several, not the whole answer. Anyone telling you the EU wallet covers your whole user base today is describing 2027.
Why it matters
The four criteria are the assessment. If you're documenting your choice of method, write it against them one by one, because that's the shape of the question you will be asked.
Fairness is the criterion most often skipped in vendor material and the one most likely to be tested. Ask any estimation provider for their accuracy broken down by demographic, not just their headline figure.
Frequently asked
Is HEAA the same as the EU standard?
No. HEAA is a UK term from the Online Safety Act. The EU Digital Services Act takes a risk based approach and doesn't use it, so a service covering both markets is answering two differently shaped questions.
Does a credit card check count?
Ofcom has been clear that a payment method available to under-18s doesn't meet the standard. Whether a particular card product is restricted to adults is a question about that product.
Can one method cover every user?
Rarely, today. Most compliant deployments offer more than one route and record which was used. Be wary of a vendor whose answer to coverage is that the question doesn't arise.
Primary sources
This is a plain language explanation, not legal advice. Specifications and dates in this area move, so check anything you are going to rely on against the primary sources.
Keep reading
Age verification API
Or skip the theory and build against it
Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.