27 min read

Four Layers, Not Eight Laws: Why Your Age Gate Does Not Port to Asia-Pacific

Australia's social media minimum age law says a platform must not rely on government ID unless it also offers a reasonable alternative. Malaysia's Child Protection Code says age must be verified against government-issued records. Both are in force right now, and no single verification flow satisfies both. That contradiction is not an accident of drafting. It happens because eight Asia-Pacific regimes each put the age check at a different layer of the stack: the app store, the mobile carrier, the national ID rail, or the platform itself. Here is what each layer actually gives you, which national rails a foreign platform cannot reach at all, and the three assumptions in a European age gate design that break the moment you cross into the region.

Editorial illustration on a deep slate-navy background: four horizontal bands stacked one above the other, each a different width, with four vertical lines rising from a baseline and each one stopping at a different band instead of passing through them all. Abstract geometric shapes, no faces, no people, no readable text.

Australia’s Online Safety Act carries a provision called section 63DB. An age-restricted platform must not collect government-issued identification material, and must not use an accredited digital ID service, unless it also offers users a reasonable alternative.

Malaysia’s Child Protection Code, in force since 1 June 2026, says age must be verified against government-issued records. MyKad. Passport. Birth certificate.

Both obligations are live today. A platform serving Australian and Malaysian users cannot run one verification flow and satisfy both. In Australia, government ID cannot be the only door. In Malaysia, it is the door.

That is not a drafting accident that will get tidied up. It is what happens when eight countries independently decide where in the stack an age check belongs, and reach four different answers.

Most of the writing on Asia-Pacific age assurance is a country list: here is Australia’s date, here is Malaysia’s date, here is the penalty. That list is easy to produce and it tells you almost nothing about what you have to build. The useful question is not which law applies. It is which layer of the stack each law reaches into. The layer decides three things: who performs the check, what signal arrives at your service, and whether you are permitted to be the one asking at all.

The map is four layers, not eight laws

Jurisdiction Layer the law targets Who actually performs the check What your service receives
Singapore App store Apple, Google, Microsoft, Huawei, Samsung Nothing. The gate is on the download, not on your account
Australia Platform (you) You, with app store and search layers added in 2026 Whatever you collect, with government ID constrained
Malaysia National ID You, against government records A verified identity, by mandate
Indonesia Platform (you), scaled to risk You, method proportionate to risk Whatever you collect, deleted after use
Vietnam Mobile carrier, then national ID The carrier, via phone number An identity, and usually the parent’s, not the child’s
South Korea Licensed identity agencies (mostly carriers) SKT, KT, LG U+, card issuers A pass or fail on identity, plus a birth year
Japan Mobile carrier at point of device sale The carrier and its resellers Nothing, unless you are in a named sector
India National ID, from 2027 You, once the rules commence Not yet anything. The duty is not in force

Read down the third column. In four of these eight countries, the party performing the age check is not you and cannot be you. In two more it is you, but the method is dictated. Only Indonesia and Australia leave the method genuinely open, and Australia then removes one of the obvious options.

Layer one: the app store decides, and does not tell you

Singapore moved the check to the distribution layer. The Code of Practice for Online Safety for App Distribution Services was issued on 15 January 2025 under section 45L of the Broadcasting Act 1994, and came into effect that March. The age assurance duty had its own clock: implemented by 31 March 2026, operative from 1 April 2026 (IMDA).

Five app stores are designated. Apple, Google Play, Microsoft Store, Huawei AppGallery and Samsung Galaxy Store. They must stop users estimated to be under 18 from downloading age-inappropriate apps, judged against the store’s own rating system.

The store’s own rating system. Not IMDA’s. The regulator moved the obligation to a layer whose taxonomy it does not control.

What the five stores actually shipped is worth knowing. It is the clearest evidence available of what “technology-neutral” produces when five companies answer the same question independently:

Store Method
Microsoft Singpass, facial age estimation, or government ID
Apple Credit card or government ID
Google Machine learning inference from search and YouTube signals
Samsung Credit card only
Huawei Credit card only

Two of the five accept nothing but a credit card. In Singapore, the minimum age to hold a principal credit card is 21. So two designated stores, satisfying an 18-plus obligation, are structurally unable to pass an 18, 19 or 20 year old. That is not a bug in their implementation. It is what happens when a payment instrument is used as an age proxy and the instrument’s own issuance age sits above the legal threshold.

Ofcom made the same point from the other direction in its Use of Age Assurance Report on 15 July 2026:

some techniques such as credit card checks will not work for 16 and 17 year olds

A card check is a binary 18-plus proxy. It cannot express 13, or 15, or 16.

Australia has now added the same layer on top of its platform duty. Its Phase 2 industry codes brought search engines into age assurance from 27 June 2026, and app distribution services from 9 September 2026, eight days before this was written.

The practical consequence for a platform is uncomfortable. If your app is rated 18-plus in Singapore, part of your Singaporean signup funnel is now filtered by a credit card check you did not choose. It happens before any user reaches your screen. You get no signal saying so. Your conversion rate moves and the cause sits one layer above your logs.

Layer two: the mobile carrier owns the identity

South Korea has the oldest and deepest version of this. It is worth understanding properly, because it is the model several other countries are drifting toward.

Korea has no single horizontal statute saying “you must verify age.” It built the infrastructure first, then attached sectoral triggers to it. The Network Act designates 본인확인기관, identity verification agencies. SK Telecom, KT and LG U+ were designated in December 2012; seven credit card companies joined in 2017. As of the regulator’s 2026 review there are 23 designated agencies. The three carriers hold about 98% of the volume.

The age-gating duty itself sits elsewhere, in Article 16(1) of the Youth Protection Act, which requires providers of gazetted youth-harmful media to confirm both age and identity. Self-declaration cannot satisfy the second limb.

What a Korean identity check actually does is not examine a person. It joins three databases and requires them to agree: the carrier’s subscriber record, the ID card, and in certificate flows the bank account. The fee is about 40 Korean won per transaction, roughly two European cents, which is the same order as a commercial age check vendor’s unit economics.

The failure modes follow directly from the join. A name spelled differently on the carrier record and the residence card fails. A phone registered to an employer, a school or a landlord fails. A prepaid SIM fails, because the system works only on postpaid lines. A newly issued residence card that has not propagated fails. Where a foreigner’s residence card carries both a Hangul and an English name, only the English name works.

None of those are edge cases at the margin. They are the normal condition of a large share of foreign residents.

Can a foreign platform simply plug into this rail? Becoming a designated agency requires regulatory approval, document review, and an on-site inspection of facilities and financial capacity. That is not available without a Korean presence. There is a narrower question underneath it: whether a foreign company with no Korean business registration can contract with one of the reseller agencies as a relying party. We could not answer that from public sources, and we are not going to guess at it.

There is a precedent for what happens when a foreign platform decides the integration is not worth it. In January 2009, Korea’s identity verification threshold dropped to services with more than 100,000 daily visitors, which pulled YouTube Korea into scope. Google did not implement it. It disabled uploading and commenting for Korean users instead. It chose to degrade the product rather than join the national rail.

Vietnam runs a thinner version of the same idea and, importantly, does not actually check age at all. Decree 147/2024/ND-CP took effect on 25 December 2024, with existing accounts due by 25 March 2025. It applies to cross-border providers with at least 100,000 visits a month averaged over six months. Every account must be verified, first against a Vietnamese mobile number, and only against a personal identification number if the user confirms they have no Vietnamese number. Only verified accounts may post, comment, livestream or share.

For under-16s, the parent registers the account in the parent’s own information. The platform never tests the child’s age. The signal reaching your service in Vietnam is an adult’s verified identity attached to an account a child is using. If your compliance story depends on knowing the age of the person at the keyboard, Vietnam’s regime gives you the opposite.

A draft amendment was discussed at a ministry workshop in July 2026. It would create Vietnam’s first real platform-side age detection duty, and require under-16 accounts to be closed within 120 days. It is still a draft. Do not build for it yet, but do not be surprised by it either.

Japan’s version is the quietest. Article 13 of the Youth Internet Environment Act puts a confirmation duty on carriers and their resellers at the point of device sale. Article 16 then requires them to actually configure the filtering. Compliance with the Article 13 duty runs at about 88%.

What Japan has not done is worth stating plainly, because it is widely misreported. There is no general statutory age verification duty for adult websites in Japan. The familiar splash screen asking whether you are over 18 has no statutory basis behind it.

Japan has also not proposed an under-16 social media ban. Two separate expert processes expressly rejected a blanket statutory age limit in July 2026. The Ministry of Internal Affairs and Communications put it as: a uniform age restriction is probably not desirable. The Children and Families Agency’s final report is due in December 2026.

Japan’s real age verification mandate is narrow and old. The Internet Dating Site Regulation Act, Act No. 83 of 2003, requires dating site operators to confirm a user is not a child before each of four specified events. Three methods are accepted: an identity document, a My Number Card, or a credit card. The National Police Agency holds expressly that prepaid electronic money does not qualify.

Layer three: the national ID, and the door you cannot open

Malaysia put the check on government records. The Online Safety Act 2025, Act 866, came into force on 1 January 2026, and the Child Protection Code followed on 1 June 2026. Verification is against MyKad, passports, birth certificates, or recognised overseas equivalents. The minimum age is 16.

The obligation reaches class licensees with at least eight million Malaysian users. Only TikTok, WeChat and Telegram actually applied. Malaysia’s answer was to legislate around the ones that did not. A deeming provision, section 46A of the Communications and Multimedia Act announced in December 2025, treats WhatsApp, Telegram, Facebook, Instagram, TikTok and YouTube as automatically registered from 1 January 2026. Existing users get roughly six months to verify before lockout, which lands near 1 December 2026. That is 75 days from today.

The penalty structure is the part that should reach your leadership, not just your engineers. A Part III breach runs to RM10 million. Directors, compliance officers, managers and secretaries are deemed guilty unless they can prove lack of knowledge and due diligence. That is personal liability with a reversed burden of proof.

India has written the most technically interesting rule in the region and has not switched it on. The DPDP Rules 2025 were gazetted in November 2025, but they commence in tranches. The tranche containing Rule 10 and section 9 of the Act does not arrive until 13 May 2027.

When it does, Rule 10 will require due diligence on the person claiming to be a parent. The check is that they are:

an adult who is identifiable if required in connection with compliance with any law for the time being in force in India

That check can rest on identity details the service already holds, or on details the parent volunteers, including a virtual token mapped to such details and issued by an authorised entity.

Read that scope carefully. Rule 10 governs only the check on the claimed parent. The age check on the user is left entirely open. Whatever India ends up requiring of platforms to work out that a user is a child, it is not in Rule 10.

Two other pieces are worth writing down now, even though the duty is two years out. The Fourth Schedule expressly permits processing so a data fiduciary can confirm that a data principal is not a child. That is the carve-out an age verification vendor needs to exist at all. And section 9(3)’s bans on tracking, behavioural monitoring and targeted advertising to children are absolute. Parental consent does not cure them. Our longer treatment of that framework is in the DPDP and verifiable parental consent post.

Now the part that matters most if you are a foreign platform. The national rails these laws point at are, in most of the region, closed to you.

Rail Scale Can a foreign platform use it today?
Singpass (Singapore) 5 million users, over 4.2 million on the app Yes, via sgID, but the age scopes are not self-serve
Aadhaar (India) 1.35 billion live, over 170 billion cumulative authentications Only through DigiLocker, which requires an India-registered entity and infrastructure held in India
My Number Card (Japan) 103.8 million cards, 83.4% of the population at 30 June 2026 Effectively no. Test cards are domestic-only and accreditation needs on-site inspection. Practical route is to incorporate locally
VNeID (Vietnam) 71.5 million activated accounts at 2 July 2026 No. Only through a licensed provider, and the result may not be reused
Australia AGDIS Over 15.2 million reusable myIDs No. Public sector only until Phases 3 and 4 open on 30 November 2026
Korea 본인확인 23 designated agencies, about 98% carrier share Not as an agency. As a relying party, unconfirmed and probably needs local registration

Australia is the sharpest illustration of the mismatch. The government has spent A$465.8 million on the Digital ID system since 2023, and has 15.2 million reusable identities in it. A platform subject to the under-16 ban cannot use any of it, for two independent reasons. Private sector participation does not open until 30 November 2026. And even after it opens, section 63DB means an accredited service still cannot be the only method offered.

Layer four: the one you actually control

Australia and Indonesia leave the method to you, and they are the two regimes where your own architecture decisions carry the whole weight.

Australia’s social media minimum age obligation commenced on 10 December 2025, covering ten named platforms. Self-declaration is not enough. The expectation is a layered flow that tries the cheapest method first and escalates, the same shape we described in the orchestration post. The maximum civil penalty for a body corporate is 150,000 penalty units. After the penalty unit rose to A$364 on 1 July 2026, that is about A$54.6 million.

Two constraints shape the design. Section 63DB, already covered. And section 63F, which requires identification material to be destroyed after use, and makes any other use an interference with privacy. Together they push you toward estimation first with a document fallback, and away from storing anything.

The published results contradict each other, and the contradiction is the interesting part. About 4.7 million accounts were deactivated in the first month, announced on 16 January 2026. But those are accounts, not people, and there are only about 2.5 million Australians aged 8 to 15. Against that number, reporting in August 2026 found something else. More than half of Australian children on age-restricted platforms had still never been asked to confirm their age, three months in. We covered that gap separately in the seven-month review.

Indonesia’s PP 17/2025, known as PP Tunas, took effect on 27 March 2025 with no delay period, and its implementing ministerial regulation followed on 6 March 2026. It is the most granular scheme in the region, and it is the only one that tells you what to do when you cannot verify.

The age bands are five, and they start at three years old: 3 to 5, 6 to 9, 10 to 12, 13 to 15, and 16 to 17. Parental consent is required across the entire range from 3 to 17. Social media is high risk by default, and being high risk on any one of seven risk aspects makes the whole product high risk.

Article 22 sets four conditions. The assurance level must be proportionate to risk. The data must be processed solely for age verification. It must be deleted once that purpose is fulfilled. And an appeal mechanism must exist.

Then Article 22(4) does something no other regime in this list does. If you cannot verify compliantly, you must apply child-level protections to all users.

That is a properly designed fallback, and it is worth copying. It removes the incentive to keep a weak check running because the alternative is worse. In Indonesia the alternative to a working age check is treating your entire user base as children. That outcome is commercially severe enough to make the check worth building.

The six-month review published on 14 September 2026 reported about 28 million child accounts restricted or removed. Roblox migrated about 23 million and TikTok about 4.1 million. Facebook removed about 184,000 against an estimated 33 million child users, and the regulator said publicly that Meta had failed. A fine formula of up to 6% of global revenue was announced the same day. It has been submitted for a separate finance regulation and is not law yet.

Three things that break when you port a European design

A European age gate built in 2025 and 2026 rests on three assumptions. All three are good design. None of them survives the trip.

The age-only assertion barely exists here

The whole direction of European work is toward disclosing a boolean rather than a birth date. Wallet credentials that return age_over_18. Double anonymity. The EU age verification app.

In Asia-Pacific, two rails offer a genuine age-only assertion, and both come with conditions.

Singapore’s sgID, which is free and run by a GovTech subsidiary, exposes exactly two:

Scope Returns
myinfo.is_age_above_18 true or false, derived from myinfo.date_of_birth
myinfo.is_age_above_21 true or false

Default access for a non-government application is name and OpenID only. The age booleans require a service request and a review. It is not self-serve.

The commercial Singpass API, Myinfo, has no age attribute at all. Its personal data catalogue contains dob and nothing else age-related. No band, no boolean. The minimum disclosure for an age check through the paid, commercial route is a full date of birth.

India’s newer Aadhaar Verifiable Credential is the better design of the two. It is issued as an SD-JWT, a signed token whose individual claims can each be revealed or withheld separately by the holder. It carries AgeAbove18, AgeAbove50, AgeAbove60 and AgeAbove75 as booleans you can disclose one at a time.

The older Aadhaar channels do not have this. Both the offline e-KYC XML file and the secure QR code carry a full date of birth and no age band. And the duty that would make a verifier reach for the new credential does not commence until May 2027.

Everywhere else in the region, an age check returns a date of birth or a full identity record. Plan the data protection impact assessment accordingly, and stop assuming a minimal-disclosure path exists.

Reuse is forbidden in Vietnam

“Verify once, prove everywhere” is the most valuable pattern in this field, and we have argued for it at length in the reusable credentials post.

Vietnam’s Decree 69/2024, effective 1 July 2024, closes it off. Non-state organisations may request electronic authentication only through a licensed provider. And an authentication result may not be passed to another organisation, or used as an authentication factor in another transaction.

That is not a privacy preference you can design around with better cryptography. It is a ban on the exact thing a reusable credential is for. Does your architecture assume a verification performed once can be presented later to a second relying party? In Vietnam that assumption is unlawful, not merely awkward.

Korea’s threshold is not a birthday

This one is small, concrete, and almost always wrong in code written outside Korea.

Korean youth protection law defines 청소년 as a person under 19, excluding anyone who has reached 1 January of the year in which they turn 19. It is a calendar-year cohort, not a rolling age. Everybody ages out at the same instant, at midnight on 1 January.

// Wrong in Korea. Right almost everywhere else.
function isYouth(dob: Date, now: Date): boolean {
  return yearsBetween(dob, now) < 19;
}

// Correct for the Korean Youth Protection Act.
// Everyone born in the same calendar year crosses together on 1 January.
function isYouthKR(dob: Date, now: Date): boolean {
  return dob.getFullYear() > now.getFullYear() - 19;
}

The gap between the two is at its widest on 1 January and closes over the year. Someone born on 3 November 2007 is 18 on 2 January 2026. The rolling check says youth. The Korean rule says adult, and has said so since midnight.

There is a second trap underneath it. Korea uses at least four different thresholds in adjacent provisions. The repealed shutdown law used 16. The game time-choice system uses 18. The Youth Protection Act default is 19. The same Act’s parental consent provisions use 16. “The Korean age limit” is not a single number, and a configuration field that holds one number is the wrong shape.

The population your document check cannot reach

Every architecture above eventually falls back on a document. It is worth being precise about who that excludes, because the numbers are larger than the industry’s marketing pages imply.

The World Bank’s ID4D Global Dataset, published in July 2022 with 2021 data, counts 843 million people with no official proof of identity. About 426 million of them are children. Over 90% live in low and lower-middle-income countries.

The number that matters more for online age verification is in the second volume, published in February 2024. In 81 countries, people can obtain at least one government-recognised digital credential allowing remote authentication. That leaves over 3.3 billion people, including 2.2 billion over the age of 15, living in countries with no way to prove their official identity online at all.

Within Asia-Pacific the spread is wide. Adult ID ownership runs at 99.7% in China, 97.0% in Vietnam, 96.9% in Singapore and 96.8% in Korea. It runs at 88.3% in Pakistan and 55.3% in Lao PDR. The gender split inside those figures is the part people skip: in Pakistan, 98.7% of men and 77.1% of women. In Afghanistan, 98.5% and 76.7%.

A document-based age check in Pakistan fails structurally for roughly one woman in four. In Lao PDR it cannot be completed by nearly half of adults, at any pass rate your vendor quotes.

Estimation is the usual answer to that, and it carries its own demographic spread. NIST’s evaluation of facial age estimation was updated on 13 September 2026 and now covers 53 algorithms. It sets each algorithm’s threshold so that 10% of males aged 14 to 17 pass as over 18, then measures what happens to girls of the same age at that same setting.

One widely deployed algorithm lets 40.4% of underage girls through. Others in the same test sit at 27.0%, 25.0% and 18.7%. On one algorithm the mean error ranges from 1.9 years for East European men to 4.8 years for East and West African women, a spread of 2.9 years. We went through that data in the NIST FATE post.

Australia’s Age Assurance Technology Trial found the same shape from the other end. The headline accuracy was 97.05% across 328 mystery-shopper participants. Buried in Part C is a case study with a very different number: false negative rates up to 50% for 18 and 19 year olds at the 18 gate, and 17% for adults aged 25 and over.

Read where that error lands. It concentrates at exactly the part of the age distribution the gate exists to police. And the trial tested Australian users presenting Australian credentials. Searching it for findings on foreign documents returns nothing.

That absence is itself the finding. No credible public dataset anywhere breaks age verification pass rates down by the country that issued the document. Vendors publish country coverage counts, from 190 to 254 depending on how they count territories, and template library sizes ranging from 2,500 to 16,500. Neither of those is a pass rate. The industry publishes coverage and withholds outcomes, and no regulator has yet compelled the second.

What this means for the architecture

The single design error to avoid is treating the age rule as a global constant with per-market overrides. It is the other way round. The layer is the primary key, and everything else hangs off it.

Four things follow.

Make the layer a real field in the policy record, not an implementation detail. A per-market policy needs to answer several questions, not one. Which layer performs the check. Whether you receive a signal from it. What threshold applies. Whether that threshold is rolling or cohort-based. Whether the result may be reused.

type MarketPolicy = {
  market: 'SG' | 'AU' | 'MY' | 'ID' | 'VN' | 'KR' | 'JP' | 'IN';
  layer: 'app_store' | 'carrier' | 'national_id' | 'platform';
  weReceiveASignal: boolean;      // SG: false. The gate is upstream of you.
  threshold: number;
  thresholdKind: 'rolling' | 'calendar_year_cohort';
  governmentIdAllowedAsSoleMethod: boolean;  // AU: false, s.63DB.
  governmentIdRequired: boolean;             // MY: true, Child Protection Code.
  resultMayBeReused: boolean;                // VN: false, Decree 69/2024.
  onVerificationImpossible: 'block' | 'treat_all_as_child';  // ID: the latter.
};

Two of those booleans, governmentIdAllowedAsSoleMethod and governmentIdRequired, are the Australia and Malaysia contradiction expressed as data. Once it is data, the flow can branch on it. While it lives in a paragraph in a compliance document, somebody eventually writes one flow for both and ships a violation.

Record the decision, not the answer. A stored ageVerified: true cannot tell you, at audit, which market’s rule it satisfied or which method produced it. It also cannot tell you whether the threshold in force that day was rolling or cohort. Store the market, the layer, the method, the predicate evaluated, the policy version and the timestamp. Indonesia requires an appeal mechanism, and you cannot run an appeal against a boolean.

Design the fallback before the happy path. By happy path we mean the normal case where the document is readable and the check passes. Indonesia’s Article 22(4) makes the fallback explicit, but it is the right default everywhere.

Decide now what your service does in three specific cases. A Lao user with no national ID. A Pakistani woman whose document does not exist. A foreign resident in Korea whose carrier record and residence card disagree on the spelling of a name. If the answer is that the check fails and they leave, write that down as the product decision it is. Do not discover it later in a churn report.

Stop assuming minimal disclosure is available. Outside sgID and India’s newer credential, an age check in this region returns a date of birth or more. That changes your retention design, your data protection impact assessment, and in several markets your data residency obligations.

How Xident is built for this

Three parts of our design matter more across a multi-layer region than they do in a single market.

Every decision is a record, not a boolean. A check comes back with the outcome, the method, the predicate that was evaluated, the confidence, the policy version and the timestamp. Suppose the same user is served under four different rules in four markets, and a regulator asks which rule produced which outcome. A record answers that. A flag does not. Indonesia’s appeal requirement and Malaysia’s personal liability for compliance officers both depend on reconstructing a specific decision months later.

The Check and Verification split is what makes a layered flow affordable. A Verification is the document and identity path, with optical character recognition and a face match. A Check covers browser-based age checks, liveness, returning-user Xident ID lookup and OAuth. On our Growth plan those are 0.20 EUR and 0.02 EUR, a factor of ten apart.

That gap is the whole reason a layered flow costs less than a single-method one. Most users resolve on the cheap path, and only the ones near the threshold reach the expensive one. If a vendor bills you one blended rate per check, the layering saves you nothing and there is no reason to build it.

Estimation routes, it does not decide. We are not going to tell you facial age estimation solves Malaysia’s government-records mandate or Korea’s identity limb, because it cannot. What it does is keep the expensive path small. That is worth building in every market on this list, including the ones where the final answer has to come from a document.

The free sandbox grants 1,000 Checks and 100 document Verifications as one-time allowances rather than a monthly quota. The 100 Verifications exist so you can run the document path end to end, including the branch where it fails, before you pay for anything. A per-market policy engine with four fallback branches is exactly the kind of code you want to have exercised against a real integration before a regulator asks.

The short version

There is no Asia-Pacific age assurance strategy, because there is no Asia-Pacific age assurance problem. There are four separate problems wearing eight names.

In Singapore the check happens above you and you never see it. In Korea, Vietnam and Japan it happens beside you, on a rail you probably cannot join without a local company. In Malaysia and India it happens through you, but against records the state specifies. Only Australia and Indonesia let you own the method. Australia then removes one of the obvious options, and Indonesia tells you what to do when every option fails.

The contradiction we opened with is the useful test. Australia says government ID must not be the only door. Malaysia says government ID is the door. Any architecture that can express both as configuration rather than as two codebases will handle the next six countries as well. Any architecture that cannot will keep discovering, one market at a time, that the age gate it shipped last year answers a question that market never asked.

Malaysia’s existing-user deadline is roughly 75 days out. Australia’s digital ID system opens to the private sector on 30 November 2026, and will still not be usable as a sole method. Indonesia’s fine formula is sitting with its finance ministry. India switches on in May 2027.

The dates are published. What is not published anywhere is a pass rate for your users’ documents in the countries they actually live in. Until that exists, assume the document path fails more often than your vendor’s coverage map suggests. The fallback you have not designed yet is the one most of your Asia-Pacific users will meet.


Xident provides age verification and age estimation infrastructure built around per-market policy records rather than a single global threshold. There is a cheap Check path for returning users and a separate document Verification path. The free sandbox includes a one-time allowance of 1,000 Checks and 100 document Verifications. Talk to us about the markets on your roadmap before the dates arrive.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo