Close the age gap regulators are probing — without touching your funnel.

Age assurance at registration. Document KYC stays at deposit. Full audit trail for MGA, GGL, KSA and UKGC.

Book a 20-minute demo

Regulators are increasingly probing the gap between registration and deposit — the window where minors can browse, get hooked, and sometimes wager before any identity check fires. The UK Gambling Commission has required age and identity verification before deposit or play since 2019; Germany's GlüStV (GGL) and the Netherlands' Koa Act (KSA) impose equivalent up-front age checks.

The friction is commercial: every heavyweight step before the first deposit costs conversions, and running full KYC on visitors who never deposit burns money. Xident puts a fast on-device age check at registration, keeps document KYC where it belongs — at deposit — and records a regulator-ready audit trail for every event. Returning players clear instantly with a reusable credential, even across your brands.

18–21
Legal gambling age range across regulated markets

Why now

Age-verification law for igaming, by country

How the major markets regulate age assurance in this sector — and what each one requires of operators.

United Kingdom In force
Law
Gambling Act / UKGC LCCP
Min. age
18
Requirement
Verify age & identity BEFORE deposit or play; ongoing affordability checks.
Germany In force
Law
GlüStV 2021 (GGL)
Min. age
18
Requirement
Identity & age verification; central player file (LUGAS / OASIS exclusion).
Netherlands In force
Law
Koa Act (KSA)
Min. age
18
Requirement
Identity verification + CRUKS self-exclusion register check.
Malta In force
Law
Gaming Act (MGA)
Min. age
18
Requirement
Age verification at registration; player protection obligations.
United States In force
Law
State gaming commissions (post-PASPA)
Min. age
21
Requirement
Age + identity + geolocation before wagering; KYC per state.
Sweden In force
Law
Spellag (Spelinspektionen)
Min. age
18
Requirement
Licensed operators must verify age/identity; Spelpaus self-exclusion.

The cost of getting it wrong

  • UK: multi-million-pound regulatory settlements and licence suspension/revocation for age & AML failings.
  • Germany: fines and loss of licence under GGL supervision; blocking of unlicensed offers.
  • Netherlands: KSA fines and enforcement for age-verification and CRUKS failings.
  • US: state-level fines, licence action, and exclusion from regulated markets.

How on-device works

How Xident verifies age for this sector

The same privacy-first flow underpins every vertical: clear most users on-device, fall back to documents only when needed, and re-use the credential for returning visits.

01

Age is estimated on the device

An on-device model runs in the user's browser and estimates whether they clear the required age threshold. No upload, no server round-trip for the image.

02

Nothing leaves the device

No selfie, no biometric template, no raw frame is transmitted. Only a pass/fail age signal reaches your backend — so there is no biometric honeypot to breach or disclose.

03

Document fallback only for borderline cases

Ambiguous ages step up to a document check, which is processed for extraction and deleted immediately. Verified users get a reusable age credential, so returning visits resolve with a one-tap Check.

The face never becomes data you hold. That is the difference between meeting an age-assurance duty and becoming the next breach headline.

The benefits

Why operators choose Xident for igaming

Meet your age-assurance obligations without becoming a store of biometric or identity data.

Age check at registration, KYC at deposit

On-device age estimation + liveness clears legal-age players in seconds at sign-up, so the age requirement is met before play — while document OCR + face match stay reserved for the deposit step where full KYC is actually mandated. Stop paying full-KYC cost on visitors who never deposit.

Regulator-ready audit logs

Every verification records timestamp, geolocation, device, steps completed and result — a complete chain of evidence for MGA, GGL, KSA and UKGC reviews, without retaining the underlying biometrics.

Multi-brand / white-label support

Run one verification layer across every brand in your group, with tenant-scoped isolation. A reusable credential lets a verified player clear instantly when they cross from one of your brands to another.

Reusable age credential — returning users never re-verify

After a user verifies once, returning visits resolve with a token lookup (a "Check") instead of a full re-verification. Conversion stays high and your per-event cost drops up to 80% versus repeating document checks.

Frequently asked questions

Does the UKGC accept facial age estimation?
Operators must verify age before gambling; facial age estimation can form part of a compliant flow, typically alongside identity verification to the standard the licence requires. Xident provides both the fast age signal at registration and the document/KYC step at deposit.
Can Xident handle the 21+ threshold for US states?
Yes. Age brackets are configurable per market (+18, +21, etc.) and the rules engine applies the correct threshold based on the player's jurisdiction.
How does this affect deposit conversion?
Because most players clear on the fast on-device path at registration, the legally-required age gate adds seconds rather than minutes, and returning players skip it entirely with a reusable credential.

Ready to verify age the privacy-first way?

Integrate in minutes. Clear most users on-device in seconds. Re-use the credential so returning users never re-verify.

Book a 20-minute demo

This page is provided for general information only and does not constitute legal advice. Age-verification law in this sector changes frequently and varies by jurisdiction. Operators are responsible for confirming their current obligations in each market with qualified legal counsel.