Age verification is the load-bearing wall of every children's online-safety regime drafted in the last five years, and it is the part of those regimes that legislators understand least. The premise is intuitive: if a service is unsuitable for minors, gate it; if a service is permitted but its features differ by age, sort users into buckets. The implementation is a quiet revolution in how the internet is accessed. The pseudonymous web — the one most adults under fifty grew up with — is being replaced by an internet where access requires identity proof, age estimation, or device-level attestation. This is happening regardless of whether any particular statute survives court challenge, because platforms are pre-complying with the most stringent jurisdiction and exporting that compliance globally.
Three architectures compete. The first is document verification: upload a passport or driver's licence to a third-party provider (Yoti, Veriff, Persona, Au10tix), which returns a yes/no age token. The second is biometric age estimation: a selfie analyzed by computer vision returns an estimated age band. The third is device or operating-system attestation: Apple's and Google's age-signal APIs let the OS, which already knows the user's age from their account, pass an attestation to apps without revealing identity. Each architecture distributes trust and harm differently. Document verification creates honeypots of identity data. Biometric estimation is statistically unreliable at the critical 13/16/18 thresholds, especially for non-white faces. OS attestation concentrates power in two American companies that already mediate most mobile access.
The legislation rarely chooses among these. The UK Online Safety Act, the EU DSA, Texas's HB 1181 (upheld by the Supreme Court in Free Speech Coalition v. Paxton, 2025), Louisiana's Act 440, and dozens of other statutes specify outcomes — "highly effective age assurance" — and leave architecture to industry. Industry chooses what is cheapest and most defensible, which is usually a hybrid of document verification (for high-risk services) and OS attestation (for everything else). The political economy this produces is one where Apple and Google become the de facto age regulators of the internet. Parents who worry about platform power should worry harder about the entities that gate the platforms.
Privacy advocates have lost most of the recent fights. Free Speech Coalition v. Paxton, decided in June 2025, applied intermediate rather than strict scrutiny to Texas's age-verification requirement for pornographic sites and upheld the law. The decision narrowed Ashcroft v. ACLU (2004) and signalled that the Court is now willing to tolerate access friction for adults in exchange for child-protection rationales. The doctrinal shift is significant. It opens a wider lane for age verification across non-pornographic content, including social media, AI chat, and gaming. State legislatures noticed. Within six months of Paxton, more than a dozen states expanded their age-verification regimes to cover social media and AI companions.
The technical reality is that no age-verification system is hard to bypass. VPNs route around jurisdictional gates. Borrowed identity documents defeat document checks. Borrowed devices defeat OS attestation. Older siblings and peers willingly help. The bypass rate among motivated teenagers is roughly 100%. This is not an argument against age verification — friction reduces casual access even when it does not prevent determined access — but it is an argument against the moral relief that legislators sometimes feel after passing such laws. The teenager who wants to find pornography, addictive feeds, or AI companions will find them. The teenager who would otherwise have stumbled across them will be slightly less likely to. Both effects are real. Only the second can be claimed as a policy win.
The harder collective question is what kind of internet we are building. An internet where every interaction begins with an age check is an internet where pseudonymity is no longer the default. Whistleblowers, abuse survivors, LGBTQ youth in hostile environments, political dissidents, and the merely shy lose something. The thing they lose has been the connective tissue of online civic life for thirty years. It can be partly preserved by good architecture — zero-knowledge proofs, unlinkable tokens, federated wallets — but only if legislators specify these mechanisms rather than leaving them to platforms whose incentives favour identification.
Parenthood at the collective scale therefore has a choice to make. It can demand age verification and accept whatever architecture industry provides, in which case the trade is child protection for adult pseudonymity. Or it can demand age verification with privacy-preserving architecture specified in statute, in which case the trade is somewhat slower deployment for a sustainable settlement. The first path is faster and politically easier. The second is the one the next generation will thank their parents for if they choose it.