OTHER

Enhancing Conversations Around Strengthening Age Verification Policies

In the current digital environment, both technology professionals and legislators confront an important dilemma: while the internet can serve as a powerful vehicle for education and worldwide communication, it also poses substantial risks for children when they have unrestricted access.

However, overseeing children’s online behavior without infringing on adult privacy rights is a delicate challenge and comes with the potential for breaches of personal information.

Some proponents see these regulations as victories for child protection, yet many security experts warn that the proposed laws often suffer from flawed implementations that could inadvertently endanger adult security as well. Last month, 23 states in the U.S. had put forth age verification laws, with two additional states anticipated to follow in September. Concurrently, the U.K.’s Online Safety Act, which became effective in July, requires various online platforms to authenticate user identities before granting access.

Here’s a concise overview of the ongoing dialogue surrounding age and identity verification.

What is age verification?

The term age verification laws encompasses more than just the basic age checks many remember from creating accounts on sites like Neopets in childhood. In the U.S., these checks are rooted in the Children’s Online Privacy Protection Act (COPPA), which was enacted in 1998. It’s crucial to understand that the age checks from the COPPA era are easily circumvented—many simply involve checking a box that claims the user is 13.

In recent regulatory contexts, age verification often necessitates users to present official identification to a third-party service or provide biometric facial scans, comparable to Apple’s Face ID feature.

What is the purpose of age verification?

Essentially, concerns about internet safety reach beyond merely preventing children from visiting sites like Neopets. Parents and policymakers seek to shield minors from harmful content, including online pornography, illegal substances, and social media platforms where they may come into contact with detrimental individuals.

Techcrunch event

San Francisco
|
October 27-29, 2025

These concerns are valid. Parents have shared heartbreaking stories of children who lost their lives after purchasing fentanyl-laced drugs on Facebook or took their own lives due to relentless bullying on Snapchat.

As technology progresses, these issues become increasingly urgent: reports indicate that Meta’s AI chatbots have participated in inappropriate exchanges with children, while Character.AI and OpenAI face lawsuits related to minors’ suicides allegedly triggered by their chatbots.

Nonetheless, the internet is not solely detrimental. It provides numerous opportunities—from learning to play an instrument to forging international friendships. Specialized telehealth services can be accessed from home, and virtually any inquiry can be resolved at any hour (for the record, Antananarivo is the capital of Madagascar).

This scenario has led legislators worldwide to believe they can strike a balance: instead of dismantling the entire internet, they aspire to place certain content behind barriers that require users to verify their age using government IDs or biometric scans.

Is it secure to verify your identity by submitting a government ID or biometric data?

The safety of digital verification methods mainly relies on their implementation.

For instance, Apple designed its Face ID system so that biometric data remains on the device and is not uploaded to the cloud, greatly lowering hacking risks.

However, identity verification becomes problematic when linked to another network. Historical evidence shows that when technology fails to be robust, such measures can lead to adverse consequences.

The Electronic Frontier Foundation states, “No age verification method is completely privacy-protective or entirely accurate. Each method carries distinct types of risks.”

Recent incidents illustrate severe repercussions stemming from security failures.

Tea, an app aimed at women sharing experiences with men from dating apps, required users to upload selfies alongside their IDs for verification. Unfortunately, this data was compromised, revealing users’ private information to malicious actors on platforms like 4chan. What was envisioned as a protective measure instead led to significant harassment and violations of privacy.

Such breaches are not uncommon, as multiple security reports indicate. This problem is not confined to new apps; even established tech firms and governments are susceptible to data breaches.

Does losing my online anonymity truly matter? I’m not engaging in any illicit activities.

Opposition to these laws arises not only from individuals reluctant to link their browsing behaviors with government IDs.

In regions where individuals risk prosecution for political expression, anonymity is vital for meaningful dialogue and criticizing authorities without fear of backlash. Whistleblowers may struggle to expose corporate misconduct, and survivors of domestic violence might find it challenging to escape danger.

In the U.S., the threat of political persecution has become increasingly evident. For example, former President Trump has suggested he might imprison political adversaries, and the government has revoked visas of international students who have criticized U.S. policies.

What age verification laws are currently in effect in the U.S.?

As of August 2025, 23 states in the U.S. have enacted age verification laws, with two more anticipated to take effect by the end of September 2025.

These statutes mainly target websites hosting “sexual material harmful to minors,” with definitions varying by state.

As a result, pornographic sites are required to verify users’ identities before granting access. Some platforms, such as Pornhub, have opted to restrict access from states implementing these laws instead.

“Given that age verification processes require users to provide highly sensitive data, they are intrinsically susceptible to data breaches,” Pornhub noted in a blog post. “Regardless of intentions, governments have historically struggled to safeguard data.”

What is classified as “sexual material harmful to minors”?

The definition varies based on the enforcing authority.

As rights of LGBTQ individuals face increasing threats in the U.S., activists express concerns that such laws could categorize innocent information relating to LGBTQ communities or even sex education as “sexual material harmful to minors.” These apprehensions appear warranted, particularly as references to civil rights movements and LGBTQ history have been removed from government materials during Trump’s administration.

Texas’s age verification law, upheld by the Supreme Court in June, heightens these concerns, as it was passed alongside other legislative measures affecting the LGBTQ community, including restrictions on public drag performances and bans on gender-affirming healthcare for youth. The drag show ban was later ruled unconstitutional for infringing First Amendment rights.

What is the status of age verification in the U.K.?

In July 2025, the United Kingdom enacted the Online Safety Act, mandating various online platforms to validate users’ identities before granting access. Individuals identified as minors are prohibited from accessing specific websites. The Act encompasses search engines, social media, video-sharing sites, instant messaging services, and cloud storage platforms—essentially any medium used for media consumption or communication.

Consequently, platforms like YouTube, Spotify, Google, X, and Reddit now require UK users to verify their identity before accessing certain content. The implications extend beyond just pornographic or violent materials, creating obstacles for UK users attempting to access critical news and educational resources, complicating information retrieval while raising privacy issues.

The U.K. lacks a standardized method for identity verification; individual websites may select their verification strategies, while Ofcom, the communications regulator in the U.K., will oversee enforcement. However, as demonstrated by the Tea incident, the security of any authentication method cannot be guaranteed.

Users subjected to identity verification must navigate the dilemma of choosing between unrestricted access to content and their privacy.

Does the U.K. age verification law affect me if I live outside the U.K.?

Even if you’re not a U.K. resident, you may be impacted by technology platforms that proactively comply with these regulations.

In the U.S., platforms like YouTube have started implementing technology that estimates users’ ages based on their online behavior, independent of the age entered during account registration.

Can a VPN bypass these restrictions?

Yes, and recent app rankings in the U.K. support this—one month after the Online Safety Act was enacted, half of the top ten free iOS apps were VPNs (Virtual Private Networks). Following Pornhub’s blockage in various U.S. states, VPN downloads surged dramatically.

When Pornhub faced a suspension in France, ProtonVPN reported a staggering 1000% increase in registrations within thirty minutes—an even steeper rise than when TikTok temporarily restricted access for users in America.

You may have previously used a VPN for secure remote access to work systems or to alter your location for streaming British shows for free from the U.S.

However, this raises another concern: free VPNs may not consistently follow optimal privacy protocols, despite their assertions to the contrary.

For more insights regarding VPNs, TechCrunch provides guides covering essential aspects of VPNs and tips to determine if you need one.