One of the hottest trends in privacy and internet law in 2025-2026 has been the absolute fever to pass some form of age verification law governing applications and websites. They are, in some fashion, designed by the well-meaning to protect children from the dangers unleashed by unfettered internet access (an undeniably major problem) and by the cynical to convert probabilistic data to deterministic data by requiring companies to identify their users.

I'll make no bones about it: I hate these laws. I don't think they'll solve the problem they purport to solve and I think they're drafted by people who have no idea how to build what they're trying to build and the time frames involved given the cross-platform technical complexity. If you put me in front of Congress, my hand on a Bible (I'm not religious, I would swear in on Parable of the Sower is my party game answer.), I would shout to the heavens that these laws are the death of what little internet privacy remains that data brokers and adtech have left us.

But no one is inviting me to Congress to testify on these things. Alas.

So what is coming? What does it look like? Where are the concerns? Why won't it work?

Dual Frameworks Emerge

We have two frameworks emerging in Age Verification Laws out of the various states. It should surprise no one that the split is largely upon Republican and Democratic lines. Red States and Blue States have different ways of looking at these things because, surprise, Privacy Is Political.

Republican-led states have pushed forward with what I'll call the Offensive to Minors Frameworks ("O2MFs"). These laws are built upon the First Amendment framework around pornographic content and rely upon preexisting "prurient interest" definitions. States more or less have navigated First Amendment issues around pornography via the courts for decades and have come up with definitions to navigate the production and distribution of porn that they're now leveraging for additional controls on websites that publish user generated content that might include porn.

Here's an example from South Dakota's Age Verification Law:

"Harmful to minors," includes in its meaning the quality of any material or of any performance or of any description or representation, in whatever form, of nudity, sexual conduct, sexual excitement, or sado-masochistic abuse, if it:
(a)    Predominantly appeals to the prurient, shameful, or morbid interest of minors;
(b)    Is patently offensive to prevailing standards in the adult community as a whole with respect to what is suitable material for minors; and
(c)    Is without serious literary, artistic, political, or scientific value[.]

If your platform carries a "Substantial Portion" (usually defined as 33%) of O2M content, you're required to do Age Verification based on matching back to public records (this is essentially a DMV state ID check with government approved IDs) or some form of third party verification using facial recognition and age estimation technology.

These laws have already survived one constitutional challenge to the Supreme Court when Texas' AV law, HB 1181, was challenged in Free Speech Coalition v. Paxton. The key holding here that legitimized O2MFs and has prompted a rush to pass more of these laws is,

“[N]o person—adult or child—has a First Amendment right to access speech that is obscene to minors without first submitting proof of age.”

Additional challenges will no doubt surface as more of these laws emerge, especially those that are coupled with private rights of action (Wyoming) and criminal liability (Tennessee).

The second framework to emerge largely from Democratic Party-led states is a self-verification standard that requires a user to tell the website or app what age bracket they fall into when they sign up for a service. I call these Content Neutral Frameworks ("CNFs"). They largely avoid First Amendment issues by addressing all content and simply requiring the user to provide self affirmation. California is the leading example of this, requiring operating systems and app stores to create an age verification framework around the following groups:

  • 13 and Under
  • 13-16
  • 16-18
  • 18+

Developers will be required to ingest these signals from the App Stores and Operating Systems of the world. What those signals will look like downstream is currently unknown despite the short timelines the legislators have provided before these laws become effective.

I consider these laws to be Foundation Laws in the sense that I expect future laws and regulations such as Age Appropriate Design Codes to emerge putting requirements on these categories and build atop this framework. A good example of this already is the California Consumer Privacy Act requiring Opt In Consent for Minors aged 13-16 versus the more conventional Opt Out consent most US privacy law requires.

Problem Areas Emerge

The biggest concerns with these laws break down into a number of privacy, technical, and practical concerns.

From a privacy perspective, you're now mandating a government ID or biometric scan from every single one of your users but realistically, children don't have government IDs unless (a) they're old enough for a driver's license/learner's permit or (b) their parents have obtained a passport for them. So what you're really doing is demanding adults identify themselves to you, the app store or website, not children.

The concerns with biometric data are familiar ones; facial recognition technologies simply do not work with any sufficient level of accuracy, particularly on people of color, women, and (you guessed it!) minors. We have studies and plenty of reporting to this effect. Kids are now defeating age estimation tools by the largest, most technologically advanced companies out there by using fake mustaches. And, as ever with biometrics, the risk of a single data breach is catastrophic because you simply cannot ever reset biometric identifiers once they are breached. Your fingerprints, retinal scans, DNA, and facial geometry cannot be reset, no matter how much Nic Cage and John Travolta or Tom Cruise want us to think it's possible!

What we're doing is multiplying the number of companies that have access to your sensitive data, including government IDs, and telling the bad actors of the entire world, "here, come get it!" because these laws' various retention requirements either by the app or website itself or by the third party tasked with performing the age verification increase the amount of sensitive data collected and stored in the universe. The attack surface multiplies. Breaches will multiply. At the end of the day, the foreseeable impact is more fraud and identity theft, not less.

This doesn't even account for the risk from our own government misusing data online to start spurious culture war investigations into individuals as anonymity online is strangled by these laws. We live in an era where the federal government is looking to aggressively expand the definitions of domestic terrorism to include First Amendment protected activity online (see Minnesota 15). Again, Privacy is Political.

From a content perspective, looking at these "Offensive to Minors" definitions , who determines what's offensive to minors? The same people who decided that Catcher in the Rye, The Bluest Eye, The Handmaid's Tale, and Two Boys Kissing are pornographic and need to be banned? According to NBC News, citing a report by PEN America,

The analysis found that 36% of the more than 4,000 banned titles featured characters or people of color and 25% included LGBTQ characters or people. Of the titles featuring LGBTQ people, 28% featured a transgender and/or genderqueer character. One in 10 of the banned titles featured characters or people with a physical and/or learning or developmental disability, the analysis found. 

The echoes of the same book banning movement that has overturned school boards and local governments in the last few years have rebounded onto the internet and every website, platform, or service that allows user generate content.

From a technical perspective, the task of coordinating interoperable signals downstream in six months (the California age verification law goes live January 2027) from operating systems and app stores to app and websites is a monumental task for such a short time frame. What does that signal look like? In what format is the information transmitted? No app developer knows that yet because it hasn't been built. Are Apple, Google, Microsoft, Epic, etc. coordinating on what those signals look like so they're interoperable? A company like Lenovo operates Microsoft Operating System PCs and Google Android phones through their Motorola subsidiary. How do you reconcile conflicting signals from Microsoft and Google? What about shared devices with many people? What about users aging? Gmail has been asking for my birthday for YEARS even though my accounts are old enough to vote and drink. The answers to every single one of these questions have to be answered before code can be written, let alone shipped to the entire internet.

Finally, I'll close with this: Self-Verification is doomed to failure. It is a gateway to the harsher, more dangerous ID and biometric verification systems Republicans are already putting in place. How do I know?

I've been online and lying about my a/s/l since 1994.

If you need any help navigating age verification or other privacy laws, reach out to us at Brandi@BennettTechLaw.com for help.