Back to Blog Listing

A judge just found TikTok liable for lying about safety standards and iGaming operators need an age-gate evidence refresh

A judge just found TikTok liable for lying about safety standards and iGaming operators need an age-gate evidence refresh
Kacper Osiewalski Oct 10, 2026 4 min read

Written by: Kacper Osiewalski, Lead Backend Engineer, Digital Colliers

A Texas judge found TikTok liable in 2025 for lying about child safety protections. The company could not prove its age gates and content filters worked as advertised. For iGaming operators, the ruling is a preview. Your regulator will not ask if you have an age verification system. They will ask you to prove it works.

The regulatory landscape already demands proof

UK operators already work under RCI guidance that came into force in August 2022 and expanded in 2024. The Gambling Commission wants evidence-based intervention, not checkbox compliance. If you trigger affordability checks at £150 net deposits per rolling 30 days, you need to show the controls fired when they should have fired. Around one in four UK-licensed operators fails to hit a satisfactory AML rating on first assessment. The common thread is a gap between policy and proof.

The EU AI Act raises the stakes further. Transparency obligations apply from August 2026. High-risk system obligations kick in December 2027. If your age verification layer uses any automated decision-making, you are likely in scope. The fines reach €15M or 3% of global turnover for high-risk violations. GDPR penalties sit at €20M or 4% of turnover. The penalty for serious AML breaches in the UK goes up to 15% of gross gaming yield. The cost of not being able to prove your controls work is no longer theoretical.

The evidence gap most operators carry

Most teams can produce a flowchart showing how age verification is supposed to work. Fewer can produce a chain of custody showing it actually worked for the last 10,000 signups. The gap shows up in three places.

First, signal quality. Your age gate calls a third-party API. You log a pass or fail. But can you show the decision inputs, the confidence score, the fallback path when the primary check times out? If the regulator asks why a 16-year-old got through, your answer cannot be that the vendor said it would not happen.

Second, documentation chain. You need audit logs that survive deletion requests, system migrations, and vendor changes. The pattern I keep seeing is operators who can produce logs from the last 90 days but lose continuity beyond that. If the compliance review covers the trailing 12 months, 90 days of logs is a fail.

Third, regulator-ready proof. Kindred Group publicly reported £14M in compliance-team costs in 2023. That spend buys you people who can translate raw logs into a narrative a regulator will accept. If your team runs SQL by hand every time someone asks for evidence, you are carrying technical debt that will cost you in the next audit cycle.

The three-part audit framework

Operators shipping durable age verification systems in 2026 tend to structure the work in three layers.

Signal quality means you can reconstruct the decision path for any individual check. Store the request payload, the vendor response, the system decision, and the timestamp. If your vendor rejects a signup, log the rejection reason and the alternative path your system took. If you route failed checks to manual review, log who reviewed it and what evidence they used.

Documentation chain means you define retention windows that cover your longest compliance cycle, then build storage and access controls that survive GDPR deletion requests. Pseudonymize where you can. Separate personally identifiable information from technical decision logs. Make sure your backup and restore processes include compliance data, not just transactional data.

Regulator-ready proof means you can generate a summary report without custom engineering work. The report should answer three questions in under 10 minutes of work. How many age checks did you run this period? What was the pass rate by verification method? Which checks triggered a manual review, and what was the outcome? If that report requires a data engineer to write SQL, you do not have regulator-ready proof yet.

What winning operators do differently

The operators who pass compliance reviews on first attempt treat age verification as a sub-ledger, not a feature. Every decision gets a permanent, auditable record. The compliance team can pull reports without opening a ticket to engineering. The legal team can respond to a regulator inquiry in hours, not weeks.

The TikTok ruling makes the stakes clear. You cannot claim your safeguards work and then fail to prove it when someone asks. iGaming operators face the same obligation with higher penalties. The time to build that proof layer is before the audit notice lands, not after.

Related Posts