Age assurance has moved from a compliance footnote to a platform requirement. Apple and Google now expose declared-age-range signals to developers, and app store policy in the UK, Australia and a growing list of US states assumes a real-time check rather than a self-attested birthdate at signup. Gambling apps, already the most heavily licensed category in either store, are absorbing the change first.
The practical shift is where verification happens. Operators historically ran know-your-customer checks after registration — sometimes days later, at first withdrawal — and treated the app layer as an open funnel. Regulators now want the check at or before the point of access, which pushes identity documents and biometric templates into commercial pipelines where, as the federal data-broker gap makes clear, no law requires registration, disclosure, or honouring a deletion request.
What operators are changing
Three patterns are emerging: device-attested age ranges as a first-pass filter, document-plus-liveness capture as the fallback, and re-verification triggers tied to deposit thresholds or dormancy. None of it is technically novel. The friction is retention — every added step costs conversions — and operators in unlicensed markets have little incentive to adopt checks their licensed competitors are obliged to run.
Safe online casinos in Canada are a useful test case, because the regulatory picture is split rather than national. Ontario runs a competitive market through AGCO-registered operators with enforceable verification standards, while other provinces route play through crown-corporation platforms, and offshore sites reach Canadian users with no age-check obligation at all. Consumer-facing guides such as the Star’s safe casino list already treat licensing status as the primary signal, which is effectively a proxy for whether meaningful age verification happens at all.
The open question is enforcement. Ofcom’s age assurance guidance sets a “highly effective” standard that self-declaration does not meet, and similar language is appearing in draft US state rules. Stateside the picture is murkier, since jurisdiction over privacy enforcement is split between the FTC and FCC depending on which entity holds the data. Whether platforms delist non-compliant apps or simply log the signal and pass liability downstream is what the next cycle will settle.