Why AI companion apps ask for ID: age checks explained
AI companion apps ask for ID, a selfie or another age check because regulators and app stores increasingly require services to keep children away from adult content and higher-risk interactions. The check does not always mean handing the app your passport: it may be facial estimation, a bank or mobile network check, or a digital identity result. For an adult, the sensible question is not simply whether age verification is safe, but what data this particular method collects, who receives it and how long they keep it.
why age checks suddenly appeared
The UK is the clearest example of why these screens are now common. Protection of children duties under the Online Safety Act took effect on 25 July 2025. Services in scope that allow pornographic or other primary-priority content must use highly effective age assurance to prevent children from encountering it.
That obligation is wider than asking someone to type a birthday. Ofcom says self-declaration is not capable of being highly effective. Its accepted methods include facial age estimation, photo-ID matching, credit-card checks, mobile-network checks, open banking, digital identity services and email-based age estimation.
One correction matters here because it is often muddled online: Ofcom does list a credit-card check as capable of being highly effective for an 18-plus decision. A debit-card payment is not, because owning or using a debit card does not prove that somebody is 18.
Character.AI announced in October 2025 that open-ended chat for under-18 users would be removed by 25 November, alongside an in-house age-assurance model and third party checks from Persona. Apple updated its App Review Guidelines on 13 November 2025 with age-restriction requirements for certain creator and software-content apps where content exceeds the app’s age rating.
OpenAI began rolling out age prediction for ChatGPT consumer accounts on 20 January 2026. It uses account and usage signals rather than demanding ID from everyone. If an adult is incorrectly placed into the teen experience, OpenAI provides a Persona verification route using a live selfie and, depending on the country and check, potentially government ID.
Australia’s Age-Restricted Material Codes expanded to relevant electronic services and other covered services on 9 March 2026. The eSafety Commissioner explicitly says the rules reach AI chatbots and companions where children could be exposed to sexually explicit conversations or material encouraging self-harm or suicide.
Regulators are also testing whether the checks work in practice. On 9 July 2026, Italy’s data protection authority fined Character Technologies €158,000 and ordered further measures including properly functioning age verification and stronger controls preventing blocked minors from simply registering again.
what the different checks actually do
A facial age-estimation check normally asks for a live camera image. Software analyses facial features and estimates whether you are comfortably above the required threshold. It is not the same as identifying you by name. A well-designed system can return only an over-or-under result to the app.
Photo-ID matching is more intrusive. You provide a passport, driving licence or another accepted identity document and usually a live selfie. The verifier reads the date of birth, checks that the document appears genuine and compares its photograph with the person at the camera.
A credit-card check relies on the fact that UK credit cards are adult financial products. Open banking can instead ask your bank to confirm an age attribute without sending the companion service your full banking history. Mobile-network checks can use the age status attached to a mobile account.
Email-based age estimation uses signals associated with an email address to estimate whether it belongs to an adult. Digital identity services can provide an age credential or an over-18 result without requiring you to upload the underlying document again each time.
These methods are not interchangeable. Facial estimation can preserve more anonymity but may misclassify somebody near the threshold. ID matching provides stronger evidence but asks you to expose a much more sensitive document. A digital identity can minimise repeated disclosure, but it moves trust to the identity provider.
what happens to your selfie or ID
UK data protection rules do not let age verification companies collect whatever they want. The ICO says personal data used for age assurance must be adequate, relevant and limited to what is necessary. It also says age-assurance data should not be repurposed for unrelated profiling.
Retention depends on the implementation.
Persona’s current processor privacy policy says its default age-assurance setting deletes personal data as soon as processing is complete and an outcome has been reached. It also says a customer can instruct Persona to retain certain information for longer where this has been disclosed and is needed for fraud prevention.
Yoti’s current terms for organisations are more specific. Facial age-estimation images and most ID-verification data are deleted when the check completes. An optional manual fallback review can retain ID and selfie images for 28 days before deletion.
OpenAI’s current help documentation says Persona deletes an uploaded selfie or ID within seven days for ChatGPT age verification. OpenAI says it does not receive the ID or selfie itself, only the age-related result needed for the account.
Do not assume those periods apply elsewhere simply because an app also uses Persona or Yoti. The operator can configure the flow differently. Read the notice shown for the actual check you are completing.
For more on what companion apps collect after you get through the age gate, see our AI companion privacy guide and privacy-focused rankings.
how to spot a legitimate age check
Treat an age-verification screen like a payment screen. You should be able to identify both the service asking for the check and, where one is used, the third party verifier processing it.
A companion character asking you inside the conversation to send a passport photograph is not normal age assurance. Nor should you upload ID because of an unsolicited message claiming your account will be deleted unless you follow an unfamiliar link.
Open the service yourself, go to its account or verification area and check the domain before submitting anything. If the flow moves to Persona, Yoti or another provider, read that provider’s privacy and retention notice rather than relying on a sentence written by the companion app.
If the service does not name the verifier, explain what will be retained or provide a privacy notice before asking for identity documents, don’t bother. That is too much information to hand over on trust alone.
The same caution applies to fake “verification fees”. An age gate is not a reason to send cryptocurrency, gift cards or a bank transfer. Our AI companion scam guide covers the wider warning signs.
the privacy trade-off for adults
Age assurance solves a real problem and creates another one. Keeping children away from adult companion features means asking adults to prove something about themselves. That inevitably costs some anonymity.
Where you are given a genuine choice, a facial estimate or privacy-preserving digital identity may reveal less than a full document upload. Open banking or a mobile-network result can also prove an age attribute without sending a passport to another company. But there is no universally best method. The verifier’s retention policy and the sensitivity of the information matter as much as the label on the button.
Keep a record of the company that performed the check, the method you used and the date. If you submitted ID or biometric information, check the stated deletion period afterwards and use your data-protection rights if the provider keeps information longer than expected.
Ofcom’s July 2026 statutory report shows the scale this has already reached: more than 69 million age checks were completed across a sample of 32 UK services between July and December 2025, 23 times the number in the previous six months.
why we do not recommend bypassing the check
We do not publish instructions for evading age gates, including through a VPN. The point of the check is to separate adults from children before restricted content is shown, and bypass instructions make that protection less effective.
Ofcom says no single method eliminates circumvention. Its 2026 research also found a rise in UK VPN use after the Online Safety Act age-check rollout, although it could not determine how much of that increase was caused by people trying to avoid age checks.
If you dislike a verification method, choose a service offering a less intrusive option or do not use that feature. Privacy concerns are a valid reason to walk away.
what changes next in the UK
The direction of travel is towards more verification, not less.
On 15 June 2026, the UK government announced plans for AI romantic companion chatbots designed to simulate sexual relationships or roleplay to enforce a minimum age of 18. It also plans to restrict comparable intimate functions for under-18 users on broader AI chatbots. The government expects the protections to come into force in spring 2027, subject to the legislation passing.
That distinction matters. The proposal is not that every chatbot becomes adults-only. It targets sexualised romantic companion services and adult intimate functionality.
Until then, age checks will continue to vary by app, feature and jurisdiction. The best consumer test is simple: ask what the service needs to know, whether it can prove your age with less information, who receives the evidence and when that evidence disappears.
For the wider regulatory picture, see AI companion laws in 2026. For the category basics, start with what an AI companion is, then read the site’s AI companion safety guide.
sources
- Ofcom, Report on the use of age assurance: July 2026 statutory report, methods, scale and circumvention evidence.
- ICO, age assurance guidance: data minimisation, transparency and age-assurance methods.
- Character.AI, important changes for teens: under-18 chat restriction and Persona age assurance.
- OpenAI, our approach to age prediction: rollout date, account signals and adult verification route.
- eSafety Commissioner, Age-Restricted Material Codes: March 2026 commencement and application to AI chatbots and companions.
- Apple Developer, updated App Review Guidelines: November 2025 age-restriction changes.
- Italian Garante, Character.AI decision: July 2026 fine and age-verification orders.
- Persona, processor privacy policy: data collected for age assurance and default deletion settings.
- Yoti, age verification terms: retention periods by verification method.
- UK Government, social media and AI companion announcement: 15 June 2026 plan for 18-plus romantic companion restrictions.
Common questions
Is it safe to upload my ID to an AI companion app?
It can be, but check who is actually processing the document and read that verifier's retention notice first. Prefer a recognised verification provider and avoid sending identity documents through chat, email or an unexplained upload form.
Why do AI girlfriend apps ask for a selfie?
A selfie can be used to estimate whether you are over an age threshold, or matched against a photo ID to confirm the document belongs to you. The two methods collect different amounts of information, so check which one the service is asking for.
Why does ChatGPT think I am under 18?
ChatGPT uses account and behavioural signals to predict whether an account may belong to someone under 18. OpenAI says adults placed in the teen experience by mistake can verify their age through Persona.
Can I use an AI companion app without verifying my age?
Sometimes, depending on the app, your country and the features you use. Adult content and some companion services increasingly require an age check, and the UK plans an 18 plus minimum age for sexualised romantic companion chatbots.
How long do age verification companies keep my photo?
There is no single retention period. Some providers delete images immediately after the result, while others allow the app operator to set a longer period, so read the verifier's own notice before submitting anything.