What a global debate over child safety, privacy, digital identity, standards, and online access reveals about the future of the internet
Legal and regulatory status checked through July 17, 2026.
Asking a person’s age sounds like a minor change to a website.
For most of the open internet’s history, people could read, search, watch, learn, argue, play, and join communities without first proving that they belonged to an approved age category. Age mattered at particular boundaries—buying alcohol, entering a casino, opening certain financial accounts—but it was not a routine prerequisite for participation in digital public life.
That assumption is changing.
On July 16, the Software Freedom Law Center, India convened a global panel titled What Age Assurance Means for the Future of Digital Rights, Online Safety, and the Internet at Large. The discussion brought together civil-liberties advocates, child-rights researchers, trust-and-safety specialists, technologists, and organizations from Australia, South Korea, Europe, Africa, India, the United Kingdom, and the United States.[1]
Moderator Mishi Choudhary began with the tension that shaped the event. Children face real harms online: exploitative contact, harmful recommendation systems, compulsive design, sexualized and violent material, and products that can manipulate a young user’s attention or emotions.
But once a service must know whether a user is sixteen, seventeen, or eighteen, it must decide how it will know.
Will the user upload an identity document? Will a company estimate age from a face? Will a platform infer age from years of behavior? Will the phone, operating system, app store, bank, or government supply an age signal?
A small interface question can become a new relationship among users, platforms, vendors, and the state.
The question beneath the age gate
Age assurance is not simply a way to classify children. It can determine whether every user must submit to an identity, biometric, behavioral, financial, or device-based process before accessing lawful information and services.
The panel did not divide neatly between people who care about children and people who care about privacy. Nearly every participant accepted that harmful online systems require action. The disagreement concerned the intervention.
Is the state addressing the product features and economic incentives that produce harm—or creating a new identity checkpoint for every user? Can age assurance provide children with safer, developmentally appropriate experiences without blocking lawful access to information and community? Can a proof disclose only an age threshold while resisting tracking, coercion, and expansion into a general digital-identity layer?
And what happens to people who lack accepted documents, private devices, stable connectivity, or the ability to challenge an automated decision?
Child safety and digital rights are not opposites
The most useful lesson from the panel was that children’s rights include more than protection from harmful content.
Children also possess rights to privacy, expression, association, participation, and access to information. Those interests can conflict in a particular case, but they do not disappear because a policy is described as protective.
Protection can remove support as well as risk
John Pane of Electronic Frontiers Australia described his country’s under-sixteen social-media regime as a blunt prohibition aimed at the visible part of the problem: children’s access. The deeper causes, in his account, include harmful design, surveillance-based data extraction, and recommendation systems engineered to maximize engagement.
Australia’s law is no longer hypothetical. Since December 10, 2025, designated platforms have been required to take reasonable steps to prevent Australians under sixteen from creating or keeping accounts.[13] The eSafety Commissioner reported that platforms restricted access to approximately 4.7 million accounts during the first implementation period.[14] Three months later, however, the regulator identified significant compliance concerns involving Facebook, Instagram, Snapchat, TikTok, and YouTube and moved toward possible enforcement.[15]
The account figure demonstrates large-scale implementation. It does not establish improved wellbeing. Australia has begun a two-year evaluation following more than 4,000 children and families to examine intended and unintended effects.[16]
The distinction matters because online services can provide LGBTQ+ youth, children in unsafe homes, disabled users, and people in geographically remote communities with information and relationships unavailable nearby. A restriction may remove risk, but it can also remove agency, education, and support. Children may respond through borrowed accounts, circumvention, alternative services, or platforms with weaker protections.
Adults encounter the gate too
Paige Collings of the Electronic Frontier Foundation connected age assurance to both privacy and freedom of expression.
Age restrictions do not operate only on children. Adults must also demonstrate eligibility. For young people, the effects can be particularly serious when lawful information about health, identity, abuse, politics, or community is unavailable offline. Platforms also gain another reason to place difficult or controversial material behind a gate.
The United Kingdom’s existing Online Safety Act duties already require highly effective age assurance in several circumstances involving pornography and content harmful to children. The government then announced in June 2026 that it intends to prohibit covered social-media services from offering accounts to under-sixteens. Regulations are expected before the end of 2026, with implementation planned for spring 2027; the final service definitions and operational rules were still being developed when this article was written.[17]
The gate must be implemented somehow. Depending on the method, users may be asked for identity records, financial information, account history, a facial image, or an operating-system signal.
One of the recurring errors in public debate is to treat the final response—“over eighteen” or “under sixteen”—as though it were the complete data flow.
Identity requirements can chill ordinary users more than determined wrongdoers
Professor K.S. Park of Open Net Korea supplied a historical warning.
South Korea’s Information and Communications Network Act once imposed a general identity-verification requirement on users of covered message boards. The official English legislative record states that the provision applying that requirement to private service providers was removed after the Constitutional Court found it unconstitutional on August 23, 2012; the statutory deletion followed in 2014.[20]
Park argued that privacy-conscious ordinary users withdrew while people intentionally committing illegal acts found other identifiers or methods. That assessment is his interpretation of the policy’s effects, but the legal history confirms the broader lesson: identity-linked participation can deter lawful speakers without eliminating determined misconduct.
A person seeking ordinary speech, political participation, or sensitive information may be discouraged by a record connecting identity to activity. A motivated bad actor may treat the checkpoint as another obstacle to evade.
Digital life is part of children’s real life
Moritz Katzner of Stop Killing Games and James Baker of Open Rights Group focused on gaming, preservation, learning, and relationships.
A child interested in a complex game may rely on videos, forums, guides, and interaction with other players. Blocking YouTube, Reddit, or another social platform may not simply remove idle entertainment; it can remove the instructional and community structure surrounding an important hobby.
The same applies to creative work, disability access, identity exploration, education, and friendships. Calls to move children into the “real world” often assume that online life is somehow unreal. For many children—and adults—the internet is already where meaningful parts of life occur.
Children possess rights before adulthood
Nicholas Williams of Index on Censorship argued that child protection is too often placed in one conceptual box while freedom of expression is placed in another.
The UN Convention on the Rights of the Child does not treat children solely as objects of adult protection. Children have rights to expression, participation, privacy, association, and access to information. Those rights may be limited for legitimate protective purposes, but they do not suddenly appear on a person’s eighteenth birthday.
Dr. Kim R. Sylwander of the Digital Futures for Children centre developed that point through children’s evolving capacities. Numerical age is relevant, but children of the same age do not have identical needs, maturity, or circumstances. A single hard boundary can create a cliff that is poorly suited to developmental differences.
The stronger question is not simply whether age assurance admits or excludes a child. Where it is used, does it enable a safer and age-appropriate experience while preserving agency and access?
That is a much more demanding standard than placing a gate in front of an unchanged and potentially harmful product.
One label, many systems
“Age assurance” is an umbrella category. It includes verification, estimation, inference, self-declaration, parental confirmation, financial checks, device signals, and privacy-enhancing credentials.
Each method answers a different question with different evidence. Each creates a different balance among confidence, privacy, accessibility, cost, and resistance to circumvention.
| Method | Typical evidence | Main advantage | Principal risk |
|---|---|---|---|
| Self-declaration | Birthday or checkbox | Minimal collection | Easy to evade |
| Document verification | Government or authoritative record | High confidence | Identity-rich collection and exclusion |
| Facial estimation | Selfie or short video | Lower friction than ID | Threshold errors, demographic performance, image processing |
| Behavioral inference | Account activity and observed behavior | No new document | Continuous monitoring and opaque decisions |
| Parental confirmation | Verified adult approval | Supports family features | Does not prove relationship; unsafe for some children |
| Financial/database check | Card, bank, carrier, or brokered record | Uses existing records | Hidden data chain and economic exclusion |
| Device/OS signal | Age band from device, account, or app store | Reduces repeated disclosure | Centralized gatekeeping and shared-device problems |
| Anonymous credential | Cryptographic threshold proof | Minimizes disclosure to the website | Enrollment, recovery, revocation, and institutional control |
Self-declaration: private but weak
A birthday field or “I am over eighteen” box collects relatively little information. It is also easy to evade.
That makes self-declaration a plausible way to tailor low-risk experiences, but a poor mechanism for enforcing a hard prohibition. ISO/IEC 27566-1 treats self-assertion alone as ineffective for deciding access to age-restricted goods, content, services, venues, or spaces. Steve Wood’s 2026 review found that eleven of the seventy examined platforms still relied on self-declaration alone even as stronger age assurance became common across the wider sample.[2]
The weakness of self-declaration is often used to justify stronger methods. That is the point at which privacy and access costs begin to increase.
Documents and authoritative records: confidence bundled with identity
A passport, driver’s license, national identity card, or birth record can supply a reliable date of birth when the document is genuine and belongs to the person presenting it.
But a document contains far more than most websites need. A service asking only whether a user is over eighteen does not inherently need the person’s name, address, document number, nationality, photograph, signature, or exact birth date.
A verifier can separate those attributes from the final result. The relying website may receive only “over eighteen.” That is a real improvement over handing a complete document to every website.
It does not make the evidence disappear. The verifier, document-checking provider, identity authority, fraud service, or human reviewer may still process it.
The important privacy question is therefore not merely what the website receives. It is what the whole system collects, transmits, retains, and can later connect.
Facial estimation and behavioral inference: less conventional identity, new forms of surveillance
Facial age estimation predicts an age or age range from a selfie or short video. Wood found it was the most commonly identified method among the twelve forms of age assurance used across the seventy services he examined.[2]
Its appeal is obvious. It may be faster than finding a document, and the platform may never learn the user’s name. But the method still asks a person to place their face into a technical and commercial process. Liveness detection, anti-spoofing controls, device information, and a fallback document check may be added around the estimate.
The hardest cases occur near the legal boundary. Distinguishing a young child from a middle-aged adult is different from distinguishing a seventeen-year-old from an eighteen- or nineteen-year-old. An error can either admit someone the rule intends to exclude or deny lawful access to someone entitled to enter.
Behavioral inference creates a different problem. A platform can estimate age from account history, searches, videos watched, language, social relationships, school references, or other signals. This can be presented as less intrusive because no new document or selfie is requested.
But the apparent advantage depends on repurposing information collected for other reasons. A checkpoint becomes continuous monitoring.
An adult researching schools for a child, watching youth-oriented entertainment, or sharing an account with family members may resemble a minor. A child can also produce carefully selected adult-looking signals. The user may never learn which behavior triggered the decision.
Parents, payments, and databases: convenient assumptions that fail many users
Parental confirmation can support family accounts and age-appropriate settings. It cannot automatically prove a child’s age or establish that the adult is a safe and legitimate guardian.
Some children do not have an available adult who can help. Others seek information precisely because the adults around them are hostile, controlling, abusive, or unsafe.
Financial and commercial-record checks make different assumptions. A credit-card authorization may show access to an adult-controlled payment instrument, but not that the person at the keyboard is the cardholder. Cards can be borrowed, and many lawful adults do not have them.
Commercial databases, phone-account checks, and open banking can rely on information assembled across data brokers, financial institutions, carriers, or identity services whose role is invisible to the user.
These methods can make age assurance dependent on the same commercial surveillance economy that child-safety policy is often supposed to constrain.
Device and operating-system signals: fewer checks, greater central power
A phone, app store, console, or operating system can provide an age range to an application. This may reduce repeated disclosure: a user does not upload an ID to every service, and the application receives only a limited signal.
The privacy of an individual interaction may improve while power becomes more concentrated.
A small number of operating-system and app-store companies could become issuers of age-related permission for ordinary digital activity. Alternative operating systems, older devices, shared tablets, public computers, and platforms outside the approved ecosystem may be unable to produce the expected signal.
Once the device can answer one age-related question, governments and companies may ask it to enforce additional rules for games, purchases, political information, health content, AI companions, or services unrelated to the original mandate.
Anonymous credentials: the strongest technical answer, not a complete social answer
Cryptography can prove a limited fact without revealing the underlying identity.
Steven Bellovin describes a system in which a trusted issuer verifies a person’s age and supplies a private credential. The holder can derive unlinkable proofs such as “over eighteen.” A website verifies the proof without learning the person’s name, exact birth date, or source document.[8]
That is substantially more private than sending an ID or selfie to each website.
But someone must still enter the system. An issuer must decide which records are acceptable, verify them, fund the process, secure the credential, help users recover it, and determine whether it can be revoked. People without documents, private devices, transportation, stable housing, or technical assistance may remain excluded.
Bellovin also identifies a paradox. If a credential is useful only for age-gated content, adults may lend it to minors. Making it valuable for banking, employment, public services, or other essential functions discourages sharing—but turns it into a far more consequential identity system.
A private proof can exist inside a coercive institution.
Privacy-preserving is not the same as anonymity-preserving
A website may receive only an age threshold while the issuer, device operator, verifier, or surrounding metadata still allows transactions to be linked to one another or to a person.
From one age check to internet infrastructure
These methods are usually evaluated one transaction at a time: what does this website learn from this check? But the larger policy question emerges when the same signals, credentials, vendors, and device systems begin operating across many services.
Moving assurance to the device is often described as the privacy solution.
Instead of requiring every website to perform a separate check, the operating system or app store establishes or receives an age range and sends a limited signal to applications. The relying service learns less. Users repeat the process less often.
Those advantages are real.
So are the structural consequences.
One device is not one person
Families share phones, tablets, consoles, televisions, and computers. Libraries and community centers provide public devices. Schools issue devices that may be used by more than one student.
A device-level signal must either assume one user, require reliable multi-user profiles, or repeatedly identify the person currently present.
The first produces wrong results. The second depends on families configuring accounts correctly. The third reintroduces friction and surveillance.
People with the least money, time, and technical expertise are often the most likely to share devices and the least able to maintain a complex multi-user assurance system.
Alternative systems can become second-class
A mandate tied to approved operating systems can disadvantage:
- de-Googled Android builds;
- Linux distributions;
- older devices;
- independent app stores;
- accessibility-specific hardware;
- public terminals;
- devices made for markets outside the dominant ecosystem.
The open internet historically allowed a standards-compliant browser to reach a service regardless of who manufactured the computer. Device-level eligibility can replace that principle with a chain of approved hardware, software, accounts, and issuers.
The gatekeeper gains policy power
Apple, Google, Microsoft, console companies, and major app stores could become intermediaries for age-related access across thousands of services.
They would need to decide which evidence is accepted, which age bands exist, how shared devices work, how appeals operate, whether developers receive exact or coarse results, how often signals expire, and what happens after account suspension.
A law aimed at platform safety can therefore increase the power of the largest platform companies.
The European model shows both the promise and the risk
The European Commission’s age-verification blueprint became technically ready for national customization in April 2026.[21] It can operate as a standalone application or be integrated into a future European Digital Identity Wallet. The Commission says the design can prove that a user satisfies a threshold without revealing identity or exact age, and it has urged Member States to make compatible tools available by the end of 2026.[22]
That architecture is materially different from uploading a passport to every website. It separates issuance from presentation and is intended to reduce disclosure and cross-service tracking.
Simeon de Brouwer of European Digital Rights warned that privacy-preserving intent does not end the governance analysis. Enrollment can still require a passport, identity card, national eID, banking application, or in-person authority. Identity providers and relying services may face legal demands, implementation errors, metadata correlation, or later architectural changes.
Perfect enforcement creates pressure for more identity
Every method can be evaded somehow:
- users can lie;
- documents can be borrowed or forged;
- adults can complete checks for minors;
- facial systems can be spoofed;
- accounts and credentials can be transferred;
- behavior can be manipulated;
- users can move to another site or jurisdiction;
- a VPN can change apparent location.
A government dissatisfied with those results can escalate:
- require a stronger method;
- bind the result to a device;
- add liveness or biometrics;
- repeat the check;
- monitor behavior for inconsistency;
- restrict anonymous access or VPNs;
- retain logs for enforcement;
- connect the credential to a persistent identity;
- penalize platforms for any successful evasion.
The Global Network Initiative’s multistakeholder review identifies the central limit: policymakers should not demand complete resistance to circumvention when achieving it requires unacceptable privacy and rights costs.[9]
The endpoint may not be a perfectly safe internet. It may be an internet in which every user is continuously classifiable and access can be revoked.
AI companions are the next expansion point
The panel’s closing discussion anticipated the rapid movement of age-assurance policy from social media to chatbots and AI companions.
These systems create distinct risks:
- emotionally dependent relationships;
- simulated grooming or sexual conversation;
- encouragement of self-harm;
- manipulation;
- hallucinated personal or medical advice;
- collection of intimate disclosures;
- profiling from continuous conversation.
An age signal may help apply different safeguards. But a chatbot is not simply another social-media feed. It responds privately, adapts to the user, and may become a confidant.
Wood found regulatory gaps around AI chatbots and warned that companies may define their own child-safety standards without clear public rules.[2] The report recommends explicit coverage, risk tiers, and obligations addressing simulated grooming and emotional dependency.
The UK moved further while this article was in production. Its July 2026 package proposes blocking under-eighteens from AI services primarily offering sexualized content, restricting sexual role-play features on other chatbots, and considering protections such as mandatory breaks and limits on systems offering mental-health advice. These were announced proposals, not yet final operating rules.[18]
A device-level age signal may be deployed before governments have decided what an age-appropriate AI relationship should be.
What real deployments reveal
That infrastructure concern is not merely hypothetical. Existing deployments show how quickly a binary age result can create concentrated intermediaries, multi-company data flows, and incentives for broader enforcement.
The 2026 study Papers, Please: A First Look at Age Verification on the Web built technical signatures for age-assurance providers and crawled a large set of popular websites from Texas, Georgia, and New York. The researchers found more detected age-verification deployments in the two states with mandates than in the control state, showing that state law can change what users encounter online.[3]
They also found a concentrated market. Yoti appeared on more than sixty percent of detected deployments in the mandate-state crawls. A rule applied across many websites can therefore create a small number of central intermediaries through which sensitive transactions pass.
Apparent compliance remained low
The researchers used the voluntary “Restricted to Adults” label as a rough proxy for sites likely to contain covered material. Only about fourteen percent of those labeled sites in Texas and Georgia had detectable age verification.
That is not a definitive legal compliance rate. The label is voluntary, the laws differ, and the detection system can miss implementations.
It nevertheless illustrates a basic enforcement problem: a user who refuses a check can often move to a site that does not impose one. A compliant service adds friction and loses traffic; a noncompliant competitor can absorb it.
The result may be a two-tier internet in which well-known services implement intrusive gates or withdraw while less accountable sites gain users.
A binary result can require a large data supply chain
The website is often only the relying party. The user is redirected to a verifier, which may contact other services for network location, payment processing, document validation, fraud detection, database matching, or manual review.
The researchers observed browser and device information that could contribute to fingerprinting. They also identified method-specific connections to outside services. In a card-based flow, Stripe could receive contextual information about the originating service; a bank could learn that a Yoti transaction occurred. Government-ID workflows could involve additional identity and document-validation partners.[3]
Not every method sends every data type to every party. Precision matters. But the central lesson survives: a binary result can be produced by a much richer data chain.
The correction matters
Yoti challenged an allegation that facial images used for facial age estimation were shared with third parties. Georgia Tech and the University of California, Irvine removed that allegation after review, according to Yoti’s June 2026 update.[4]
A responsible account must not repeat the withdrawn claim.
The correction does not automatically resolve the study’s separate findings about device metadata, market concentration, particular outside services, retention statements, or the security test in which researchers substituted a prepared image during the browser capture process. Each claim must be evaluated on its own evidence.
The episode is also a reminder that privacy reporting must identify the exact method, recipient, and data flow. “The vendor shares user data” is too broad to be useful. Which data? In which workflow? With whom? For what purpose? For how long?
What responsible deployment is supposed to require
The Digital Trust & Safety Partnership’s best-practices framework is more candid than many political descriptions of age assurance. It says no approach is one-size-fits-all and that accuracy, privacy, inclusion, circumvention resistance, and affordability can conflict.[5]
Its principles call for:
- assessing the actual risk to young people;
- selecting a proportionate method;
- treating privacy and data protection as part of design and ongoing evaluation;
- ensuring inclusion and accessibility;
- using layered enforcement rather than assuming one check solves every problem;
- explaining practices publicly and reporting on effectiveness.
The framework’s value is that it rejects the idea that the most invasive method is automatically the most responsible.
Its limitation is equally important. It is a best-practices document, not evidence that companies follow those practices or that a deployment reduces harm. “Layered enforcement” can mean careful escalation from a low-intrusion method, but it can also become continuous monitoring followed by facial or document verification.
ISO/IEC 27566-1 contains serious safeguards
ISO/IEC 27566-1:2025 is the most formal effort in this source set to describe what an age-assurance system should look like. It covers functional performance, privacy, security, accessibility, complaints, and public practice statements.[6]
The standard is more privacy-conscious than a superficial description might suggest.
It calls for minimum necessary collection, discourages disclosure of exact age or underlying evidence when a limited result will suffice, and establishes a presumption that personal data used to create a result should be deleted afterward. Audit logs must not contain biometric images or copies and extracted data from identity documents.
It also asks whether providers or relying parties can correlate the same person across services, whether collaborating sites can recognize a user, whether a verifier can learn where a result is used, and whether a token can be linked to an identity.
The standard requires systems to be testable and calls for reporting of classification accuracy, false approvals, false denials, demographic error parity, completion rates, performance, and scalability.
Complaint processes and practice statements are expected to explain how users can challenge inaccurate or incomplete information, automated decisions, and security incidents.
These are meaningful protections.
The standard leaves central policy questions unresolved
The framework also permits reusable credentials, provider accounts, stored attestations, and memorized results. It does not impose complete unlinkability, one universal accuracy threshold, a mandatory independent appellate body, or an unambiguous requirement that every deployment undergo recurring third-party audit.
Most importantly, it does not decide whether age assurance is necessary in a particular context, whether the threshold is justified, or whether the intervention will reduce the targeted harm.
What ISO/IEC 27566-1 does
- Defines system actors and age-related results
- Addresses minimization, deletion, security, testability, inclusion, complaints, and transparency
- Recognizes tracking and cross-service correlation as privacy risks
- Supports audits, certification, and practice statements
What it does not do
- Prove that a gate is necessary or proportionate
- Establish that children will be safer
- Require complete anonymity or unlinkability
- Guarantee an independent appeal or recurring independent audit
- Prevent a compliant system from becoming part of broader identity infrastructure
A technically competent gate can still be attached to an unjustified wall.
Standards are also governance
Technical standards increasingly function as implementing rules for public policy. Legislatures can reference them, regulators can treat them as evidence of due diligence, and companies can use conformity claims to win contracts or defend practices.
That makes participation a question of power.
Emma Day and Sabine Witting warn that labels such as “privacy-preserving,” “fair,” and “rights-respecting” can become rights-washing when they are defined without meaningful human-rights expertise. Standards processes demand fees, sustained staff time, technical submissions, and repeated meetings. Large companies can participate continuously; civil-society and children’s-rights organizations often cannot.[7]
The issue is not that engineers should be excluded. It is that technical decisions embed assumptions about acceptable error, identity, anonymity, access, and enforcement. Those are legal, social, and political decisions too.
The governance questions should include:
- Who drafted the rule?
- Which sectors and regions were represented?
- Were children or organizations representing their rights included?
- Who certifies compliance?
- Who selects and pays the auditor?
- Are the major results public?
- Can regulators inspect the evidence?
- Can users challenge a conformity claim?
A standard can improve safety and privacy. It can also make contested infrastructure easier to procure, certify, and scale.
What regulation has changed—and what remains unproven
Steve Wood’s Phase II study provides the best available bridge between policy and outcome. It examined seventy social-media, video, gaming, and AI platforms and documented 108 child-safety and privacy changes between 2024 and 2026.[2]
The findings show that regulation is having effects. They also show why counting changes is not enough.
Regulation is producing visible activity
Wood found new measures across Meta, Google, TikTok, Snapchat, and thirty-one other platforms. Across the wider set of services, protections enabled by default were the largest category of change, with age assurance the largest subcategory.
Examples included:
- private or more restricted accounts;
- reduced geolocation;
- limits on targeted advertising;
- content filters;
- restrictions on adult-to-child contact;
- age checks for chat or adult features;
- protective upload warnings;
- parental time controls;
- reporting and support tools.
Some changes were directly linked to the UK Online Safety Act or interventions by the UK Information Commissioner’s Office.
Major platforms shifted responsibility toward families
Among Meta, Google, TikTok, and Snapchat, the pattern changed. Earlier regulatory pressure had produced more protections enabled by default. During 2024–2026, the greatest volume of changes shifted toward user-operated tools, especially parental controls.
A default protection works without a child or parent finding, understanding, and activating it. A tool transfers responsibility to the user.
That matters because families vary in time, digital literacy, language, safety, technical skill, and household relationships. A platform can announce a control that few people use and still count it as a safety measure.
Wood found that platforms did not publish comprehensive, independently audited data on the use or performance of parental controls. Some outside research suggested limited effectiveness as a standalone response to compulsive use.[2]
Age assurance was widespread, but transparency was weak
Most of the seventy platforms had some form of age assurance, although the researchers could not identify it on thirteen. They found twelve types of mechanism, and most services with age assurance offered more than one option.
Offering alternatives can reduce exclusion. A person without photo ID may use a facial estimate; someone who cannot or will not provide a face may use another method.
But multiple choices do not guarantee rights-respecting implementation. Wood found that platform explanations often failed to identify the standards the system followed, and the study did not test whether the mechanisms were accurate or effective.
A majority of platforms with age assurance in place relied on in-house solutions (31) rather than third-party providers (23). Some platforms used both: in-house for one method, such as behavioral inference, and a third-party vendor for another, such as facial age estimation. Yoti was the most-used third-party provider.[2]
Ofcom’s first statutory report shows scale and displacement
On July 15, 2026, Ofcom published its first statutory assessment of age assurance under the Online Safety Act. Thirty-two sampled services reported more than 69 million completed age checks between July and December 2025—twenty-three times the number reported in the preceding six months. Ofcom described the findings as early and warned that the sample was not representative of an entire sector.[19]
The regulator found signs that checks were deterring some children from pornography and that the largest sites had broadly implemented gates. It also found that almost half of the pornography services visited by children had no age checks, while some noncompliant sites gained traffic as gated competitors lost it.
Several social platforms continued to depend on proprietary behavioral inference that Ofcom did not accept as inherently capable of being highly effective.[19]
This is the evidence ladder in action:
Law enacted → regulator acts → system deployed → behavior changes → exposure changes → harm declines
Most public evidence currently establishes the first three stages. Evidence becomes much thinner at exposure and actual harm.
Ofcom itself stated that no method eliminates circumvention and called for vendor due diligence, privacy compliance, and system-wide involvement by search engines, app stores, operating systems, and device providers.[19]
Those recommendations may improve enforcement while also accelerating the infrastructure expansion examined in this article.
Design rules have produced some of the clearest privacy gains
The most concrete improvements in Wood’s research came from specific design and data rules:
- reducing precise geolocation;
- making profiles private by default;
- limiting personalized advertising to minors;
- restricting contact;
- adding protective prompts;
- filtering certain content;
- changing recommendation behavior.
These interventions target the environment rather than requiring every user to prove eligibility before entering it.
That does not make age assurance irrelevant. A service may need an age signal to apply the correct protections. But the signal should enable safer design, not substitute for it.
The global inequality problem
The Digital Rights Alliance Africa report covers Algeria, Botswana, Egypt, Ghana, Kenya, Nigeria, Rwanda, South Africa, Tanzania, and Uganda. It treats privacy as both a protective and enabling right: children need it not only to avoid exploitation but to learn, communicate, explore identity, and exercise expression.[10]
The report identifies laws and policies across the region, but repeatedly returns to implementation:
- many legal frameworks are general rather than child specific;
- regulators and enforcement bodies lack resources;
- digital literacy is uneven;
- rural users may lack secure connectivity;
- international standards are adopted slowly or incompletely;
- parents and caregivers may lack the knowledge assumed by consent-based systems;
- companies operate across borders that local complainants and regulators struggle to cross.
Only a minority of African Union states had ratified the Malabo Convention at the time of the report, and the convention itself lacks detailed child-specific privacy rules. The African Union’s 2024 Child Online Safety and Empowerment Policy recognizes safety, privacy, participation, best interests, and non-discrimination, but national implementation remains uneven.[10]
A technically neutral rule can deepen inequality
Consider a law that permits government ID, smartphone-based facial estimation, or a mobile-network check.
For a well-documented urban adult with a current phone, stable connectivity, and technical confidence, the process may be inconvenient.
For a person without a recognized birth record, national ID, private device, data plan, accessible interface, nearby government office, or ability to pay, the same rule can become exclusion.
A country with lower internet penetration may lose more from blocking lawful users because the network already reaches fewer people. A government with a history of surveillance or political repression creates additional risks when identity infrastructure becomes attached to speech and association.
Bridgette Ndlovu’s panel remarks emphasized that identity coverage and connectivity cannot be assumed. Patricia Ainembabazi stressed that technologies adopted in African countries are often designed elsewhere, with little input from the people governed by them. Annette Opiyo centered proportionality, evidence, accountability, inclusion, and child participation.
These are not regional side issues. They expose weaknesses in the universal model.
Children must participate in the design
CIPESA argues that children are not only vulnerable users but active participants in learning, play, creativity, and social life. Its work on AI governance calls for children’s experiences to shape systems from the beginning, including limits on profiling and manipulation, data minimization, independent audits, and AI literacy.[11]
Its 2026 policy-to-practice article similarly calls for child-specific laws, funded institutions, accountable platforms, transparency, independent audits, and meaningful participation by young people.[12]
Children should be asked:
- Which services matter to them and why?
- What harms do they experience?
- Which controls help?
- Which restrictions drive them elsewhere?
- What happens when a parent is not safe?
- What appeal process would they understand?
- How do age rules affect disabled, rural, queer, migrant, low-income, or undocumented young people?
- Which protections should apply to everyone rather than only minors?
Participation does not mean children decide every legal question. It means policy is not designed around an imagined average child who has no voice, no agency, and a safe adult standing nearby.
A rights-respecting test for any proposal
Before procurement, certification, or deployment, policymakers should answer the following questions.
What specific harm is being addressed? “Protect children” is an objective, not a defined problem. Pornography, grooming, compulsive use, targeted advertising, gambling, and AI companionship require different interventions.
What evidence connects an age gate to that harm? Explain the causal theory and how displacement, circumvention, and unintended effects will be measured.
Have less intrusive design measures been tried? Consider safer defaults, contact restrictions, advertising limits, recommendation changes, moderation, reporting, product liability, and consumer-protection enforcement.
What does the service actually need to know? Identity, exact age, age range, or one temporary threshold result are not equivalent.
What data are collected from the person and device? Include documents, images, biometrics, financial details, IP address, device characteristics, behavior, location, and fraud telemetry.
Who receives the data? Identify the platform, verifier, operating system, app store, document validator, bank, processor, data broker, cloud provider, reviewer, and subprocessor.
What is retained, and for how long? Separate original evidence, images, document data, device information, age results, credentials, transaction logs, and complaint records.
Can transactions be linked? Determine whether the provider, issuer, collaborating websites, or surrounding metadata can recognize the same person across services or over time.
What are the errors? Publish threshold-specific false approvals, false denials, demographic disparities, completion rates, abandonment, and accessibility failures.
What alternatives exist? A lawful user should not lose access because they lack an ID, credit card, smartphone, camera, private device, safe parent, stable internet, or conventional records.
What happens when the system is wrong? Require clear notice, understandable reasons, human review where appropriate, correction, restoration of access, deadlines, and independent escalation.
Who tests and audits the system? Testing should occur before launch and regularly afterward. Auditors need expertise in security, privacy, accessibility, discrimination, and children’s rights.
What prevents secondary use? Age-assurance evidence should not become material for advertising, general profiling, AI training, unrelated fraud models, political surveillance, or data-broker sale.
What is the expansion boundary? State which services are covered, who may add categories, when legislative approval is required, how necessity is reviewed, and when the authority expires.
Were children and affected communities involved? Include users of different ages, abilities, locations, incomes, identities, family circumstances, and patterns of internet access.
The better question
Age assurance is often presented as a contest between safety and privacy.
That framing is too narrow.
The policy choice affects safety, privacy, anonymity, expression, association, equality, competition, device freedom, platform power, government identity, technical standards, children’s participation, and the architecture of the internet.
Some age-related protections will require some knowledge of age. Some systems can disclose much less than others. Standards can meaningfully reduce collection, retention, tracking, error, and exclusion.
None of those facts establishes that a gate should exist everywhere a child might encounter risk.
The clearest evidence in the source set is not that age assurance has solved online harm. It is that regulation is rapidly producing infrastructure: vendor markets, facial-estimation systems, reusable credentials, app-store signals, audit schemes, practice statements, and enforcement expectations.
Infrastructure persists. It becomes interoperable. It attracts investment. It gains new uses.
That is why the most important question must come before the technical one.
Not: How do we verify everyone’s age?
But: What specific protection do children need here, and can we provide it without turning identity or eligibility into the price of ordinary participation online?
The answer will not be identical for pornography, gambling, a public encyclopedia, a multiplayer game, a support forum, an encrypted messenger, a school tool, or an AI companion.
That is not a failure of policy.
It is the complexity that rights-respecting policy must be willing to face.
Related reading
For a set of concrete, Oregon-specific illustrations of how a poorly built age-verification system could go wrong — including immigration-enforcement exposure, data breaches, and custody-dispute subpoenas — see When “Protecting Kids” Goes Wrong.
Source notes
- [1] Event recording and working transcript. Software Freedom Law Center, India, What Age Assurance Means for the Future of Digital Rights, Online Safety, and the Internet at Large, July 16, 2026. Recording: https://www.youtube.com/watch?v=euSkCvhzweQ. The event discussion is based on a locally generated Whisper transcript; any exact quotation should be checked against the recording. ↩
- [2] Steve Wood, Digital Futures for Children / London School of Economics and 5Rights Foundation. Impact of Regulation of Children’s Digital Lives: Phase II and Appendices A and B, May 2026. https://www.digital-futures-for-children.net/our-work/regulation-impact ↩ 1 2 3 4 5 6
- [3] Shreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, and Michael A. Specter. Papers, Please: A First Look at Age Verification on the Web, 2026. https://mikespecter.com/assets/pdf/AgeVerification.pdf ↩ 1 2
- [4] Yoti. An open letter to Georgia Institute of Technology and University of California, Irvine requesting retraction and correction of false statements, updated June 19, 2026. https://www.yoti.com/blog/open-letter-to-georgia-institute-of-technology-university-of-california-irvine-requesting-retraction-correction-false-statements/ ↩
- [5] Digital Trust & Safety Partnership. Age Assurance: Guiding Principles and Best Practices, September 2023. https://dtspartnership.org/age-assurance-guiding-principles-best-practices/ ↩
- [6] ISO/IEC 27566-1:2025. Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: Framework. Public record: https://www.iso.org/standard/88143.html. The analysis is paraphrased from a lawfully obtained single-user copy. ↩
- [7] Emma Day and Sabine Witting. Human Rights Experts Should Engage in Age Assurance Standards, Tech Policy Press, June 29, 2026. https://www.techpolicy.press/human-rights-experts-should-engage-in-age-assurance-standards/ ↩
- [8] Steven M. Bellovin. Privacy-Preserving Age Verification—and Its Limitations, October 2025. https://www.cs.columbia.edu/~smb/papers/age-verify.pdf ↩
- [9] Hilary Ross, Global Network Initiative. Examining the Rights Implications of Age Assurance Requirements, July 6, 2026. https://globalnetworkinitiative.org/examining-the-rights-implications-of-age-assurance-requirements/ ↩
- [10] Digital Rights Alliance Africa. Child Protection and Safety Online in Africa: The Law, Privacy, Challenges and Solutions, June 2025. https://digitalrightsalliance.africa/download/child-protection-and-safety-online-in-africa/ ↩ 1 2
- [11] Patricia Ainembabazi, CIPESA. Elevating Children’s Voices and Rights in AI Design and Online Spaces in Africa, July 18, 2025. https://cipesa.org/2025/07/elevating-childrens-voices-and-rights-in-ai-design-and-online-spaces-in-africa/ ↩
- [12] Patricia Ainembabazi, CIPESA. Protecting Children Online in Africa Must Move from Policy to Practice, June 11, 2026. https://cipesa.org/2026/06/protecting-children-online-in-africa-must-move-from-policy-to-practice/ ↩
- [13] Australian Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts. Minimum age for social media access, December 11, 2025. https://www.infrastructure.gov.au/department/media/news/minimum-age-social-media-access ↩
- [14] eSafety Commissioner. Platforms restrict access to 4.7 million under-16 accounts across Australia, January 16, 2026. https://www.esafety.gov.au/newsroom/media-releases/platforms-restrict-access-to-47-million-under-16-accounts-across-australia ↩
- [15] eSafety Commissioner. Five social media platforms flagged for compliance issues, March 31, 2026. https://www.esafety.gov.au/newsroom/media-releases/five-social-media-platforms-flagged-for-compliance-issues ↩
- [16] eSafety Commissioner. eSafety begins evaluation of Australia’s world-first social media minimum age, February 26, 2026. https://www.esafety.gov.au/newsroom/media-releases/esafety-begins-evaluation-of-australias-world-first-social-media-minimum-age ↩
- [17] UK Department for Science, Innovation and Technology. Fact sheet: New rules to protect children online, updated July 17, 2026. https://www.gov.uk/government/publications/fact-sheet-new-rules-to-protect-children-online/fact-sheet-new-rules-to-protect-children-online ↩
- [18] UK Department for Science, Innovation and Technology. New social media curfews and crackdown on addictive features to better protect 16- and 17-year-olds online, July 15, 2026. https://www.gov.uk/government/news/new-social-media-curfews-and-crackdown-on-addictive-features-to-better-protect-16-and-17-year-olds-online ↩
- [19] Ofcom. Use of Age Assurance Report 2026, July 15, 2026. https://www.ofcom.org.uk/online-safety/protecting-children/use-of-age-assurance-report-2026 ↩ 1 2 3
- [20] Korea Legislation Research Institute. English statutory record for Article 44-5 of the former Act on Promotion of Information and Communications Network Utilization and Information Protection. The record states that paragraph (1) 2 was deleted in 2014 pursuant to the Constitutional Court’s August 23, 2012 unconstitutionality decision. https://elaw.klri.re.kr/eng_service/lawViewContent.do?hseq=46968 ↩
- [21] European Commission. The EU approach to age verification, updated May 13, 2026. https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification ↩
- [22] European Commission. Commission urges Member States to rollout EU age verification app, April 29, 2026. https://digital-strategy.ec.europa.eu/en/news/commission-urges-member-states-rollout-eu-age-verification-app ↩

