This is not legal advice. Requirements in this area are changing quickly and differ by jurisdiction; the descriptions below cover how the mechanisms work, not what any country currently requires. Check an official source for your own jurisdiction before relying on anything here.
An age verification requirement is a rule that a platform must not serve certain content until it has established, to some standard, that the visitor is an adult. Nearly all the practical and political argument concerns that phrase "to some standard" — the range of methods that satisfy it differ by orders of magnitude in what they cost, what they exclude and what they reveal.
What is a requirement actually asking a platform to do?
To move from asserting age to establishing it, along a spectrum with four rough steps.
| Level | Mechanism | Certainty | Data exposure |
|---|---|---|---|
| Declaration | "I am over 18" checkbox or date entry | None | None |
| Inference | A signal correlated with adulthood, such as a payment instrument | Weak | Payment identity |
| Estimation | Statistical age prediction, typically from a face image | Probabilistic | Biometric sample, if retained |
| Verification | A credential asserting a date of birth is checked | High | Identity document or registry record |
A fifth pattern sits alongside rather than above these: attestation, where a separate party performs the check once and issues a token stating only "this person is over 18" to the site. The site learns the fact without learning the identity, and the verifier learns the identity without learning which site asked — if the system is built so that neither can be recombined.
How do the individual methods work, and how do they fail?
Each method fails differently, which is why no jurisdiction has landed on a single mandated one.
| Method | What you hand over | Who sees it | Characteristic failure |
|---|---|---|---|
| Self-declaration | Nothing | Nobody | Trivially bypassed |
| Credit or debit card check | Card details, name | Merchant and processor | Excludes adults without cards; household cards misused |
| ID document upload | Passport or licence image | The verification vendor, sometimes the site | Highest breach impact; excludes people without documents |
| Document plus liveness selfie | Document and a face video | The vendor | Adds a biometric sample to the above |
| Facial age estimation | A face image or short video | The estimation vendor | Accuracy falls near the threshold age and varies across demographic groups |
| Mobile operator check | Phone number, carrier lookup | Carrier and site | Prepaid and shared lines defeat it; ties browsing to a phone number |
| Bank or national eID | An authenticated session | The identity provider | Strong assurance, strongest identity linkage |
| Double-blind token | Verification once, token per site | Split between two parties by design | Depends entirely on the two parties not colluding or merging |
| Device or OS-level signal | An account age already known to the platform | The device vendor | Shared devices; shifts the decision to a small number of gatekeepers |
Facial age estimation is the method most often proposed as the privacy-friendly option, and its limitation is statistical rather than technical: any estimator has an error band, so a threshold has to be set conservatively above the legal age to keep false passes low, which then rejects large numbers of legitimate adults.
Why is age verification a privacy problem?
Because it creates a durable link between a verified identity and a category of browsing that previously had none.
Four distinct risks, often conflated:
- Linkage. A verification event connects a real identity to a specific site at a specific time. Whether that link is stored is a design decision the user cannot inspect.
- Retention. Audit obligations can require records be kept, which converts a momentary check into a standing database.
- Concentration. A small number of vendors performing checks for many sites become high-value targets, and the sensitivity of what they hold exceeds that of any individual platform.
- Exclusion. Adults without documents, without cards, or whose faces are estimated poorly are denied lawful access with no appeal route.
The design that addresses most of this is the double-blind pattern, where the verifier never learns the site and the site never learns the identity. Whether a given implementation is genuinely built that way is not observable from the user side, and that unverifiability is itself a structural weakness.
Where do these requirements apply?
Scope is defined by rules rather than by borders, and the rules combine three tests: where the user appears to be, what share of the service's content falls in scope, and whether the operator is deemed to be targeting that market.
Enforcement, when the operator is foreign, generally routes through the levers the jurisdiction does control — intermediaries, app stores, payment providers, and network-level access restriction. This is why a requirement can be effective against a business with no local presence.
Jurisdictions active in this area include several United States states, the United Kingdom, France, Germany, Australia and the European Union. The notes below were checked against official sources on 2026-08-03 and name the instrument and the responsible body in each case. They deliberately omit penalties, thresholds and procedural detail: those are the parts that change fastest and carry the most consequence if misread, so read them from the official source rather than from any secondary summary — including this one. Sources are listed at the end of this section.
United States. The operative rules are state law, not federal. Texas and Utah both enacted requirements in 2023 directed at commercial sites a substantial part of whose content is material harmful to minors. In June 2025 the Supreme Court upheld the Texas statute against a First Amendment challenge, holding that intermediate scrutiny applies because a state's traditional power to keep minors from such material includes the power to require proof of age, so the burden on adults is incidental. That did not settle the wider picture: litigation over newer state requirements — including laws directed at app stores rather than at adult sites — was still active in 2026, with at least one preliminary injunction on appeal.
United Kingdom. The Online Safety Act 2023 places duties on service providers rather than viewers. The Part 5 duties covering pornographic content published by a service itself were commenced on 17 January 2025 and require age verification or age estimation of a kind highly effective at determining whether a user is a child, together with record-keeping about the method chosen and a published summary statement. Ofcom is named in the Act as regulator.
France. Arcom regulates, under the 2004 law on confidence in the digital economy as amended by the 2024 law on securing and regulating the digital space. Its technical reference framework for age-verification systems was adopted in October 2024, published in the official journal that month, and remains the applicable version with no later amendment. It set a compliance window running from publication, allowed payment-card-based verification only transitionally, and anticipated privacy-preserving "double anonymity" designs — the attestation pattern described earlier on this page — becoming available on a longer horizon. Where a service does not comply after formal notice, Arcom can escalate to access providers, DNS resolver providers and search engines.
Germany. Supervision runs through a dedicated commission constituted as an organ of the state media authorities, under an interstate treaty on youth media protection alongside a federal youth protection act, with a separate federal body handling indexing and platform precautionary measures. The applicable standard is the strictest of any covered here: content that would otherwise be inadmissible may be distributed online only within a closed user group, which the commission reads as requiring one-off identification of an adult — typically involving personal contact — plus per-session authentication, rather than any form of declaration. The commission assesses whole systems and individual components against published criteria.
Australia. The Online Safety Act 2021 establishes the eSafety Commissioner as regulator, with power to register industry codes and determine industry standards. A restricted access system declaration made under that Act in 2022 and still in force specifies what an access-control system must do for the class of material covering online pornography: require an application and a declaration of adulthood, give warnings and safety information, and incorporate reasonable steps to confirm the applicant is at least 18. Keep this separate from Australia's social media minimum age obligation, which took effect on 10 December 2025 — that one concerns holding an account on a social media platform, is not a pornography measure, and in fact restricts the use of government identification for its own compliance purposes.
European Union. Two instruments of different legal types create the duties. The Digital Services Act is a Regulation, directly applicable without transposition, and its provision on protection of minors online requires platforms accessible to minors to put appropriate and proportionate measures in place — while stating that compliance must not force additional personal-data processing merely to determine whether a user is a minor. The Commission issued guidelines under that provision in July 2025 and has published an age-verification blueprint built on the same technical specifications as the European Digital Identity Wallet, designed to prove adulthood without disclosing further identity data. The Audiovisual Media Services Directive is a Directive, implemented by each member state in national law, and names age verification among the technical measures for content that may impair minors' development, with the strictest measures reserved for the most harmful content including pornography. So the EU sets the frame and the member states supply much of the operative detail, which is why national requirements still differ.
Sources for this section
All fetched and checked on 2026-08-03.
- United States — Texas HB 1181 (88R); Utah SB 287 (2023); Free Speech Coalition v. Paxton, No. 23-1122 (2025); CCIA v. Paxton, W.D. Tex., order of 6 May 2026
- United Kingdom — Online Safety Act 2023, section 81; Commencement No. 4 Regulations 2024; Part 5
- France — Arcom, protection of minors; Arcom, technical reference framework; Délibération No. 2024-20, JORF; Law No. 2024-449 (SREN)
- Germany — KJM, legal bases; KJM, inadmissible offerings and closed user groups; BzKJ, tasks
- Australia — Online Safety Act 2021; Restricted Access System Declaration 2022; Social Media Minimum Age Act 2024; day-of-effect instrument 2025
- European Union — Regulation (EU) 2022/2065; Directive 2010/13/EU, consolidated; Commission guidelines on protection of minors; EU age verification blueprint
How do these systems fail in practice?
Predictably, and in ways that matter for judging whether a given scheme is working.
| Failure mode | Consequence |
|---|---|
| Shared devices | A verified adult session is available to everyone in the household |
| Estimation error near the threshold | Adults refused, or minors admitted, depending on where the threshold sits |
| Traffic displacement | Users move toward services that ignore the requirement, which are typically the least accountable ones |
| Vendor breach | Identity documents exposed together with the fact of what was being accessed |
| Documentless adults | Lawful access denied with no alternative route |
| Inconsistent scope | Some services covered and near-identical ones not, depending on definitional thresholds |
The displacement effect is the most contested point in the policy debate and the most relevant one for a reader: a requirement applied to compliant operators changes where traffic goes, and the destinations it goes to are usually those with worse security and worse data practices — which is a risk to the user directly, whatever one concludes about the policy.