SOURCE 0 - AGE QUALIFICATION WITHOUT A CERTAIN DATE
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · August 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
A system can apply a protective regime to an account based on a self-declared age, a behavioral prediction, or a subsequent verification meant to confirm a declared age or contest an initial qualification. These operations produce the same functional effect without being of the same nature, or necessarily deployed at the same stage of the process. Whether either falls within the high-risk regime of Regulation (EU) 2024/1689 remains an open legal question, distinct for each. That question is itself separate from the evidentiary question of anteriority: which qualification, produced by which system, existed at which date, before it took effect. SOURCE 0 fixes that anteriority independently of the entity controlling the system under review.
[/AI-SNIPPET]
What follows takes as a case study the public documentation of a consumer artificial intelligence operator concerning the age determination of its users. This is not an indictment of that product or its publisher. The mechanism described below is not specific to this operator: it is structurally identical at any provider that determines a user's protected status from a process it alone retains a record of.
This case study arises against a backdrop in which the governance of minors, the demonstration of compliance, and the traceability of automated decisions are drawing increasing attention. This general context illustrates the practical relevance of proof of anteriority, without prejudging the compliance of the operator examined.
I. THE DOCUMENTED FACT
The public documentation reviewed indicates that an account's protective status is activated when either the age information provided by the account holder or an age prediction indicates that the person is under eighteen. A separate verification path then allows this qualification to be confirmed or contested. These operations are not of the same nature. A declaration is a fact alleged by the person themselves. The prediction relies, according to the operator's separately published technical documentation, on a combination of behavioral and account-level signals — account age, typical hours of activity, usage patterns over time, and stated age — with no mention of biometric data processing. Verification, by contrast, is carried out through a third-party identity provider, which may request, depending on the country, a live selfie, a government-issued identity document, or both, comparing the selfie against the document photograph. The operator states that it does not receive these elements directly, only the verification outcome, and that the provider deletes the submitted data within seven days of the operation.
These two mechanisms — behavioral prediction and third-party verification — therefore do not belong to the same family of processing, even though the document presents them as two paths producing the same effect on account status.
The public documentation reviewed does not establish whether, for a given account, the qualification basis used, its effective date, and the relevant parameters are retained in a form that is accessible or verifiable after the fact. This absence is a property of the public source examined; it does not permit a conclusion that no such record exists in the operator's internal systems.
II. THE UNSETTLED REGULATORY QUALIFICATION
An age prediction produced by an automated system could fall within Annex III, point 1(b), of Regulation (EU) 2024/1689 (the AI Act), which covers biometric categorization based on sensitive or protected attributes or characteristics within the meaning of Article 9(1) of Regulation (EU) 2016/679. This qualification presupposes several cumulative conditions: that the system actually processes biometric data, that it assigns the person to a category on that basis, and that the category corresponds to an attribute falling within the scope of Article 9(1). The technical documentation published by the operator for the prediction mechanism describes exclusively behavioral and account-level signals, with no mention of biometric data — which, on the basis of this description, does not support attaching the prediction itself to this provision, without permitting it to be excluded with certainty in the absence of detail on the underlying model.
The verification mechanism, by contrast, relies on a facial comparison between a selfie and an identity document, which constitutes biometric processing. Annex III of the same Regulation nonetheless excludes from its scope biometric verification systems whose sole purpose is to confirm that a given natural person is who they claim to be. Whether this exception applies to the service used here depends on the actual functioning of the provider, its principal purpose, and the operations it actually performs — elements this document cannot verify.
Neither of these two uncertainties is without consequence. If a provider considers that a system falling within Annex III is not high-risk, Article 6(4) of the same Regulation requires it to document that assessment before the system is placed on the market or put into service, and to communicate it to competent authorities on request. This documentary obligation, where it applies, concerns an act fixed in time, prior to the deployment of the system concerned. The operator's public documentation distinguishes two milestones in this respect: the public announcement of the deployment of the age-prediction system itself, on 20 January 2026, and the announcement, on 18 August 2026, of a product experience dedicated to teenagers that draws in part on this system. The first date is a relevant public milestone; it does not, by itself, establish the exact legal date on which the system was put into service within the meaning of the AI Act, nor the precise nature of the deployment it announces. The anteriority relevant to Article 6(4) would, where applicable, be assessed against that actual entry into service — whatever its exact date — not against the 18 August announcement. No date of regulatory assessment is communicated for either system. Nothing in the document establishes, from the outside, whether such an assessment, assuming one is required, was produced before, during, or after the relevant period, or not at all — and if it exists, it is drafted and retained by the very entity whose system it evaluates, with no mechanism fixing its date independently.
This finding does not establish a breach of Article 6(4). It establishes that no element accessible to a third party allows, for this documentary obligation where it applies, a preexisting assessment to be distinguished from a document produced after the relevant deployment.
III. THE EFFECT ON THE INDIVIDUAL, ARTICLE 22 AND ARTICLE 15 GDPR
Of the bases described, age prediction directly raises the question of a decision based exclusively on automated processing. The applicability of Article 22 of Regulation (EU) 2016/679 nonetheless depends on the cumulative satisfaction of several conditions: a decision, based exclusively on that processing, producing a legal effect or significantly affecting the person — and the absence of an applicable exception within the meaning of Article 22(2). The measures described in the document — content restriction, possible linking to a parent account, modification of the usage regime — could, depending on their intensity, their mandatory character, and their concrete consequences on access to the service, constitute such effects. This qualification cannot be settled without examining how the mechanism actually functions, and in particular whether the described verification procedure triggers genuine, competent human intervention in the initial decision, or whether it constitutes only a second automated process substituting for the first without human review.
Separately, Article 15 of the same Regulation provides a right of access covering the personal data processed, the existence of automated decision-making including profiling, meaningful information about the logic involved, and the envisaged consequences of the processing. This right does not necessarily extend to the exact output of the model, to each signal used, or to the precise date of the individual determination; its scope depends on the limitations set out in the Regulation, in particular the protection of trade secrets. The public documentation reviewed does not permit verification of whether such information, within the limits of this article, is actually accessible through the described contestation mechanism — which presents itself exclusively as the production of a new, biometric verification intended to change the account's current status, without stating whether the initial determination, its date, and its parameters remain, on that occasion, communicable to the person concerned.
IV. THE TRANSITION AT EIGHTEEN
The document states that, once the system identifies an account holder as eighteen or older, the account may exit the protective regime and the parental control link may be severed. The documentation does not specify what event triggers this change of state for an account that has never been the subject of an active contestation — whether it rests on a new run of the behavioral prediction model, or on the third-party verification described in Section III. Nor does it specify whether this change of state is logged with an effective date and a consultable history, or whether the severance of the parental control link leaves an opposable trace of the period during which that link existed — which directly affects a parent's or guardian's ability to establish, after the fact, the extent and duration of the control they actually exercised over a minor's account.
V. WHAT SOURCE 0 SEALS
SOURCE 0 does not rule on the classification of a system under Annex III of Regulation (EU) 2024/1689, nor on substantive compliance with Articles 15 or 22 GDPR: these determinations are matters of law and, in the event of a dispute, for the court or supervisory authority seized. SOURCE 0 is not an independent third-party certification of the entity under review; the attestation is issued by Jean-François ELSEN, the mark's owner, and its independence lies in the technical separation between the system documented and the capture mechanism — not in the identity of the entity issuing the attestation itself.
Applied to the case treated here, the seal covers two distinct objects. The first is the regulatory assessment potentially required, where the conditions of Article 6(4) of the AI Act are met, for the system concerned: its fixation, through deterministic hashing and RFC 3161-qualified timestamping, followed by deposit or a formal record drawn up by a Belgian huissier de justice documenting the operations performed and the representation submitted, establishes the date on which that representation was submitted to the capture mechanism, together with its presumed integrity from that date — not the date on which the organization itself approved or implemented it internally, nor its exact qualification under Belgian evidence law, which is a matter for judicial assessment. The second is the individual determination itself: sealed at the moment it takes effect on a given account, it establishes a fixed representation, intended to be verifiable at a later stage by a third party who did not control the system that produced the determination — subject to the preservation of the artifact and its validation chain — which the contestation mechanism described in the document does not provide.
Evidence produced and retained by the entity itself is not without value; it is admissible and may be weighed under ordinary rules of evidence. It simply does not offer, on its own, the same level of evidentiary independence as a fixation carried out outside the control of the entity that produces and retains the system under review.
CLOSING AXIOM
When the date of a qualification is legally material, retaining the result alone is not sufficient to prove its anteriority. SOURCE 0 fixes that anteriority, without prejudging its truth or its lawfulness.
REFERENCE NOTE
SOURCE 0 is a registered Benelux trademark (BOIP/OBPI No. 1548293, classes 35, 42 and 45). Jean-François ELSEN is the creator of the SOURCE 0 doctrine.
REGULATORY NOTICE
This document is informational and doctrinal in nature. It does not constitute legal advice, does not rule on the substantive compliance of any specific system or processing operation with Regulation (EU) 2024/1689 or Regulation (EU) 2016/679, and does not constitute independent third-party certification within the meaning of those texts. The exact legal qualification of the sealed elements and their evidentiary weight are matters for the court or supervisory authority seized.
FREQUENTLY ASKED QUESTIONS
Does Article 6(4) of Regulation (EU) 2024/1689 (the AI Act) require a precise date for the assessment of a system falling within Annex III that the provider considers not to be high-risk?
The text requires that assessment to be documented before the system concerned is placed on the market or put into service, without prescribing a specific form of proof of that anteriority. SOURCE 0 fixes the date on which that document was submitted to its capture mechanism, independently of any later assertion by the entity that produced it.
Does every automated age prediction fall within the high-risk regime of Regulation (EU) 2024/1689?
No, not automatically. This qualification presupposes several cumulative conditions, in particular the actual use of biometric data and the attachment of the categorization to an attribute falling within Article 9(1) GDPR — conditions that documentation describing exclusively behavioral signals does not establish.
Does an age verification system based on facial comparison automatically fall within the high-risk regime of Regulation (EU) 2024/1689?
No, not automatically. Annex III excludes from its scope biometric verification systems whose sole purpose is to confirm that a person is who they claim to be, subject to conditions specific to each system's actual functioning, which must be verified case by case.
Does Article 22 of Regulation (EU) 2016/679 (GDPR) apply to every automated determination of a user's age?
No, not automatically. It presupposes a decision based exclusively on automated processing, producing a legal effect or significantly affecting the person, in the absence of an applicable exception — conditions that must be verified case by case.
Can an entity prove that a regulatory assessment existed before a given date by relying solely on its internal logs?
Such evidence remains admissible, but it does not offer, on its own, the same level of evidentiary independence as a fixation carried out outside the control of the entity that produces and retains the system under review. This difference in degree — not the absence of value of internal logs — is what SOURCE 0 is designed to address.

