14 min read

Your Age Assurance Program Is Probably Uninsured

Age verification law tells you to check every user. Your cyber policy has spent three years carving out exactly the data class those checks produce. Insurers have won a run of BIPA coverage denials, express biometric exclusions are now standard form language, and almost nobody has mapped their age assurance flow against their own policy wording. Here is the coverage gap, the case law that created it, and the architecture that keeps age assurance claims inside the policy instead of on your balance sheet.

Editorial illustration: a verification gate feeds a stream of face-scan tokens toward an insurance policy shield, but a wedge-shaped exclusion has been cut out of the shield and the tokens pass straight through the gap onto the balance sheet below. Abstract, no faces, no text.

Two teams inside your company are working from maps that do not agree. Compliance has spent eighteen months building an age assurance program because Ofcom, the FTC, and a dozen state legislatures left no other option. Risk management has spent the same eighteen months renewing a cyber policy whose exclusions got quietly wider every year. Neither team has read the other’s document. When they finally do, the discovery is usually the same: the single largest liability the compliance program creates is the one liability the insurance program specifically does not cover.

This is not a hypothetical exposure. Insurers have been litigating biometric privacy coverage since 2021, they have mostly been winning, and the wording that won for them has now migrated from disputed policy language into standard exclusions printed on the form. Meanwhile age assurance obligations expanded from adult content to social media, app stores, gaming, and advertising. The regulatory surface grew, the insurable surface shrank, and the gap between them is where your age verification architecture now sits.

What the courts decided while everyone was reading Ofcom guidance

The pattern is consistent enough to plan around. When a company gets hit with a biometric privacy class action and turns to its insurer, the insurer points at an exclusion, and the courts have generally agreed.

The Seventh Circuit held that a policy’s “access or disclosure” exclusion bars coverage for Illinois BIPA claims, reasoning that a person’s biometric identifiers count as nonpublic information within the meaning of the exclusion (Wilson Elser). That is a broad holding. Access-or-disclosure language appears in a very large share of commercial general liability and cyber forms, and it was not drafted with biometrics in mind at all. It just happens to fit.

Then the exclusions got specific. In Tony’s Finer Foods, an Illinois appellate court read a Lloyd’s cyber policy exclusion covering loss based on the insured’s collection of information without the knowledge or permission of the person concerned, and found it described the underlying BIPA allegations precisely (Clausen Miller, National Law Review). Note what that exclusion does. It is not a data breach exclusion. It excludes the collection itself. A BIPA claim does not require anyone to steal your data. It requires only that you gathered a biometric identifier without the statutory notice and written consent. So the very act that the age verification statute pushes you toward is the act the policy carves out, and no security failure is needed to trigger either one.

Carriers have gone further and added express biometric data exclusions across their books rather than relying on general wording that a court might read narrowly (Hunton Andrews Kurth). On the CGL side, insurers have leaned on three separate provisions to deny: the access/disclosure exclusion, the statutory violation exclusion, and the employment-related practices exclusion (Woodruff Sawyer). A defendant fighting on all three at once is not fighting about whether the claim is covered. It is fighting about which exclusion applies first.

Policyholders do occasionally win, and it is worth being precise about how. In Thornley v. Citizens Insurance, decided in the Northern District of Illinois in March 2026, the court denied the insurer’s motion for judgment on the pleadings in a dispute over a $20 million BIPA class settlement, finding genuine factual disputes about whether the insurer had forfeited the access/disclosure exclusion under the mend-the-hold and waiver doctrines (Hunton). Read that carefully. The policyholder survived because of how the insurer behaved during the claim, not because the exclusion failed on its terms. That is a procedural lifeline, not a coverage position. You cannot design a risk program around the hope that your carrier mishandles its own denial.

I am not an insurance lawyer and this is not coverage advice for your specific policy. But the direction of travel is not ambiguous, and the practical question for anyone shipping an age gate in 2026 is simple: if a biometric privacy class action lands tomorrow, does your policy respond, and have you actually checked rather than assumed?

Why age assurance is the worst possible shape for this risk

Biometric privacy litigation grew up around employee fingerprint timeclocks. Warehouse workers, hospital staff, a food distributor’s shift crew. Those cases hurt, but they had a ceiling built into them: the class was bounded by headcount. A company with 900 employees had a 900-person class.

Age assurance has no such ceiling. If you gate at signup, the class is every user who ever signed up. If you gate at content access, it is every session. The population you are checking is the population you sell to, which is the whole point of the product and also the whole problem with the liability.

Run the arithmetic. Illinois amended BIPA in August 2024 through SB 2979, which limited recovery so that collecting the same biometric identifier from the same person by the same method is a single violation with a single damages recovery, rather than accruing per scan (Seyfarth Shaw, King & Spalding). The Seventh Circuit later confirmed the amendment applies retroactively to cases pending when it took effect (Davis Wright Tremaine, ABA). That was a real and substantial win for defendants. It killed the per-scan multiplier that made Cothron-era exposure arithmetically absurd.

It did not make the exposure small. Statutory damages remain $1,000 per person for a negligent violation and $5,000 for a reckless or intentional one. A platform that ran server-side facial age estimation on 400,000 Illinois users without BIPA-compliant written notice is looking at $400 million on the negligence tier before anyone argues about intent. Single recovery per person is a meaningful cap only if your user population is small, and if your user population were small you would not be building an age gate.

Texas runs a parallel regime under CUBI with no private right of action, which sounds like relief until you look at the enforcement record. The Attorney General brought the CUBI case that Meta settled for $1.4 billion (Vinson & Elkins). Class actions are not the only way this gets expensive, and an AG action is a category that most cyber policies handle even less generously than private suits, because regulatory fines and penalties sit under a sublimit if they are covered at all.

So you have a liability whose size scales with your user count, whose trigger is collection rather than breach, and whose most likely funding source has an exclusion with your name on it.

The renewal questionnaire became a compliance audit

Underwriters noticed before most engineering teams did. Cyber renewals in 2026 come with tighter underwriting standards and a visible expansion of exclusions, driven by claims severity rather than by any single new threat (Insurance Thought Leadership). Whether you hold biometric data has become one of the questions that determines your regulatory-fines sublimit, sitting alongside PHI and cardholder data as a category that changes the shape of the policy (GB&A). Companies coming to renewal have reported premium increases in the 40 to 100 percent range, exclusions that hollow out the coverage they thought they had, and in some cases outright declination.

Here is what makes this different from every other security questionnaire your team has filled out. The answers are not policy answers. They are architecture answers, and by renewal time the architecture is already shipped.

“Do you collect biometric identifiers?” is not a question your legal team can negotiate. It is determined by whether an engineer chose to run face geometry server-side eighteen months ago. “What is your retention period for identity documents?” is determined by a config value. “Can you delete a specific user’s biometric template on request?” is determined by whether templates exist at all. You are being underwritten on decisions you made before you knew they were underwriting decisions.

Which means the useful move is to treat insurability as a design constraint at the same time as compliance, rather than discovering the conflict at renewal.

Four age assurance patterns, ranked by insurability

Compliance analysis of these patterns is well covered. The insurance analysis almost never is, and it ranks them differently, because insurers care about what you hold rather than what you decide.

Pattern What you retain Exclusion exposure Breach magnitude
Server-side facial age estimation with retained frames or templates Face geometry, images Highest. Squarely inside express biometric exclusions and access/disclosure wording. High. A template store is a standing target.
Document upload plus liveness, documents retained Government ID images, face scan High on both counts. You hold the biometric and the identity document. Severe. This is the breach shape that produced 2026’s worst incidents.
On-device estimation, no template persisted, decision returned An age band and an audit record Materially reduced, not zero. Processing still occurs; the argument is about what was collected and kept. Low. There is no biometric corpus to lose.
Third-party attestation or reusable credential, no biometric touches you A signed assertion and its provenance Lowest for you. The collection happens elsewhere, under that party’s obligations. Lowest. You hold a claim, not a face.

Two honest caveats before anyone screenshots that table.

Age estimation is not a BIPA-free zone. Plaintiffs have argued, with some success at the pleading stage, that facial age estimation involves a scan of face geometry and therefore falls inside the statute regardless of whether a template is persisted. On-device processing with immediate frame disposal gives you a genuinely stronger argument on both the collection question and the retention question. It does not give you a dispositive one, and any vendor telling you their estimation product is categorically outside BIPA is selling you a legal opinion they are not qualified to write. The distinction that matters to your insurer is narrower and more practical: is there a biometric corpus in your systems that a plaintiff can point to, and that an attacker can take?

Second, moving collection to a third party moves the exposure, it does not delete it. You inherit whatever that party does badly, through your own privacy notices and your own controller obligations under GDPR. The Persona and Discord incident is the reference case for what happens when your vendor’s architecture becomes your headline. Which brings us to the part of the risk transfer that most teams get wrong.

The indemnity that isn’t

Almost every age verification contract contains a vendor indemnity for privacy claims arising from the vendor’s processing. Procurement reads the clause, confirms it exists, and closes the file. That is where the analysis usually stops, and it stops two questions too early.

The first question is whether the vendor has insurance that funds the obligation. A vendor can agree to indemnify you while carrying no policy that would pay for it, which turns your risk transfer into an unsecured claim against a company whose balance sheet you have never seen (Honigman). If the same class action that hits you also hits them, you are an unsecured creditor standing in line behind their own defence costs. Ask for the certificate of insurance, not the clause.

The second question is sharper and almost nobody asks it. Does the vendor’s policy contain a biometric exclusion? Your age verification vendor is a company that collects biometric identifiers as its entire business model. It is exactly the risk profile that carriers have been writing exclusions to avoid. If their policy excludes biometric privacy claims, their indemnity of you is funded by operating cash, and their operating cash was not sized for a class action covering your user base.

Then check the cap. Indemnity caps are commonly set at twelve months of fees paid. If you spend €200,000 a year on verification and your Illinois user population implies nine figures of statutory exposure, the cap is a rounding error dressed up as protection. That mismatch is not a reason to skip the vendor. It is a reason to stop treating the indemnity as the control and start treating the architecture as the control.

Retain the decision, not the artifact

The cheapest liability is the one that never enters your systems, and this is the point where insurance analysis and privacy engineering finally give the same answer.

Most platforms overbuild the check. They reach for a document scan because a passport feels like the serious, defensible instrument, and then they hold the passport image because someone said “audit trail.” Now you own a document store, a biometric corpus, a retention schedule you will not honour, and a claim your carrier has excluded. All of it to answer a question with two possible answers.

The design that survives both a regulator and an underwriter separates the question from the evidence. Most of your traffic needs a low-friction age signal, not an identity: a lightweight Check that returns an age band and nothing else. A small minority of cases, high risk or contested or regulated at a higher standard, needs a full document Verification. Sending every user down the Verification path is the expensive mistake. It costs you conversion and it costs you per-check spend, which is why we split these as distinct operation types in our pricing. The insurance cost is the one nobody had on the list, and it is not the smallest of the three.

What you keep afterwards is the decision and its provenance. The user was assessed as over 18, at this timestamp, by this method, at this confidence, under this policy version. That record satisfies an Ofcom information request or an FTC inquiry, because regulators ask whether you performed an effective check and can evidence it. They do not ask you to produce the passport. Keeping the passport does not strengthen the evidence. It converts an evidentiary asset into a breach liability and an uninsured claim, which is a bad trade in every direction. The layered orchestration approach exists precisely so that the expensive, data-heavy path is the exception rather than the default.

Before your next renewal

Six things, in rough order of how quickly they pay off.

  1. Read your own exclusions. Search the cyber and CGL policies for “biometric”, “access or disclosure”, and “collection of information”. If any of the three appear in an exclusion, your age assurance program is likely outside the policy today. Do this before the broker call, not during it.
  2. Draw the data flow honestly. Not the architecture diagram from the design doc. What is actually persisted, in which store, for how long, and can you delete one user’s record on demand. If the answer to the last part is “we would have to write a script”, that is your answer.
  3. Get the vendor’s certificate of insurance and read its exclusions. An indemnity from an uninsured counterparty is a promise, not a control.
  4. Size the cap against the exposure. Twelve months of fees versus your Illinois and Texas user counts. If the ratio is embarrassing, say so internally and in writing, because unpriced risk that nobody documented is how these become board-level surprises.
  5. Route by risk, not by reflex. Every session does not need a document. Deciding which ones do is a product decision with a direct line to your premium.
  6. Get compliance and risk in the same room once a quarter. The whole failure mode described here is two competent teams optimising separately against documents neither has read.

None of this argues against age assurance. The obligations are real, they are enforced, and the fines for ignoring them are the one liability guaranteed to be uninsured. The argument is narrower: the way you satisfy the obligation determines whether the resulting risk sits inside your policy or on your balance sheet, and that is an architecture question being decided by default at most companies right now.

If you want to walk through where your current flow sits on that table, we are happy to look at it with you.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo