California Is Building an Internet of Age Checks and Identity Gates

California Governor Gavin Newsom has signed two controversial age verification bills into law: AB 1709 and SB 1119.

Newsom was quoted as saying that Thursday was “a good day for our children,” but both laws will also impact adults by forcing online services to distinguish between users based on age.

AB 1709 deals with features on social media that are considered addictive, such as personalized feeds and autoplay, and prohibits these for California users under 16.

Before being allowed to use these features, users must be verified under the California Digital Age Assurance Act, or another statutory age-determination method. The Act in turn relies on age-bracket signals from operating systems and app stores, which are based on age or birthdate information provided by users. The law includes data-minimization and sharing restrictions, and does not require passports or face scans from all users.

AB 1709 will in effect mean that children will be able to use social media accounts, but without access to personalized feeds, which is how many people discover new content and information, and is a key component of how these platforms work.

But the law doesn’t only affect children; adults who want to use the covered features must also verify their age. In reality, this means that companies behind the platforms will have to act as arbiters of who can and cannot use what features.

Keep reading

Microsoft Brings “Age Verification” System To Windows

Just in time for the global digital ID agenda playing out, Microsoft has published instructions for developers on how to use an API that is not yet active.

The API, or programming interface, is designed to let apps on the Windows 11 operating system find out a user’s age bracket, and whether that age has been verified by an “identity provider.”

The age bracket is very broad: under 10, 10-12, 13-15, 16-17, and 18 and over. The verification status, on the other hand, can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable, or NotApplicable.

Microsoft does not go into what these identity providers will be, or what evidence they will use to verify a person’s age. The company only says that the second value returned by the API will show “whether the user’s age has been independently verified by the identity provider.”

Microsoft frames this as a way to improve privacy, by giving app developers a way to determine a user’s age without actually knowing their date of birth, or any other personally identifiable information. According to Microsoft, this is a “privacy-preserving mechanism” that will allow apps to comply with regulations concerning child safety. But, as we’ve seen from bills that call for this type of technology to be installed in operating system, this is all about normalizing age checks (and therefore ID checks) at all stages of digital life.

In this case, an age signal does not directly expose the user’s age or date of birth. Instead, it provides a way to adapt content, features, or access controls in an app based on the user’s age range and age verification status. For example, an app can use the age signal for user-generated content, social or communication tools, in-app purchases, virtual currencies, or maturity-rated media.

Microsoft goes into some detail about how developers can use the API, but notes that it is not yet available and will not return any useful data until it is turned on later in the year. For now, the company is providing the documentation ahead of the release to give developers a head start.

In January 2024, Microsoft was more cautious about the possibility of creating a system to determine a user’s age online. At the time, the company said it was exploring various methods and seeking expert input, but was not sure that the technical solution was there yet.

“There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user’s age without risking trade-offs such as potential security, privacy, and human rights risks,” a Microsoft blog post said at the time.

California has since created its own framework for age verification.

Keep reading

Meta Settlement Ignites Global “Child Safety” Digital ID Push

The ink on the multi-billion dollar settlement agreement that Meta struck with 47 US states, the District of Columbia and a number of US territories has barely had time to dry – and already, officials and campaigners in the US, the EU, the UK, and at the UN are using it to press for similar rules to be imposed elsewhere.

In the UK, Work and Pensions Secretary Pat McFadden said that Meta should apply the new rules in that country as well, while the government there has its own plans to ban social media for under-16s and impose nighttime curfews.

“We don’t want a situation where young people in America have got a higher rate of protection than young people in the UK,” he said.

The British plan is to ban social media for those under 16 by spring 2027, and impose nighttime curfews on older teenagers, the Independent is reporting. To enforce this, platforms will have to know whether a user is a child or an adult, stepping up the pressure on companies to introduce age checks.

In the EU, the Commission is also piling on the pressure on Meta to “export” the US deal.

“We expect adequate management of screen time, appropriate parental controls on these platforms,” said digital spokesperson Thomas Regnier. “It is now up to the company to propose these commitments within the European Union in order to also protect our children here.”

The official revealed that the Commission has already been in talks with Meta since the US agreement was announced, and that the goal is to give children in the EU “at least” the same protections as those in the US.

Meanwhile, UN High Commissioner for Human Rights Volker Türk is using the settlement to call for global protections for children from what he says is the harm caused by excessive social media use.

In the US, District of Columbia Attorney General Brian Schwalb, one of those behind the lawsuit that led to the settlement, said that Meta “will not be the last” company to be forced to agree to such terms.

His California counterpart, Rob Bonta, said that Meta is “not the only player in the industry” to have “visited enormous mental health harms on kids through their products and their designs,” and added, “others rightfully must be held accountable.”

The settlement contains financial incentives for states to bring similar cases against other companies. Snap, TikTok, and YouTube are mentioned by name in this context.

Not everyone is happy with the deal, however. Arturo Béjar, a former Meta employee who was a witness in the trial, said the protections are insufficient and that the product remains harmful.

“The limitations that are in the agreement are the equivalent of saying: ‘Well, you can smoke as many cigarettes as you can in two hours a day,'” he said. “It doesn’t make the cigarettes any safer.”

Meta responded by saying that Béjar is ignoring some of the other provisions of the settlement, such as non-algorithmic feed defaults and stronger parental controls.

“We have a huge raft of built-in protections,” a spokesperson said, and argued that teenagers also derive “substantial” benefits from using social media.

Keep reading

ID Verification Breach Exposes Millions of Sensitive Identity Documents

If you ever needed more proof that governments pressuring companies to collect ID data from customers or users is a bad idea, you only have to look at what happened this week. A dark-web service advertised on August 31 has been offering over 153 million scans of driver’s licenses, more than 10 million other identity cards, over 3 million travel documents and/or international IDs, and at least 579,000 medical cards.

The data apparently stems from a company hired to verify people’s identities. The service, called Nexus, was advertised on the Russian-language cybercrime forum Exploit.

Security researcher Brian Krebs found that a blank search on Nexus returned about 11.5 million result pages with roughly 15 results per page. This would support the claim that there were over 153 million license scans in the database, and the number increased by nearly 400,000 in 24 hours.

Nexus itself claimed to have “continuously exfiltrated new data for over a year into our private database” – but this is not verified and could be an advertising claim.

What Krebs was able to verify is that his own Virginia license was among those available on the site. He searched with permission for the licenses of more than a dozen friends and relatives; nine people whose records appeared said that the attached timestamps matched or closely tracked their travels.

In the case of Krebs and his mother, the timestamps corresponded to a June 2025 car rental from Hertz. Their records were created seconds apart, matching their account that they handed both licenses to the rental representative at the same time.

Krebs’s record contained three pairs of images showing the front and back of the license in visible light, infrared, and ultraviolet.

Privacy researcher Zach Edwards also found his license on Nexus. Its timestamp matched a trip to Las Vegas, where he had presented the document to TSA, the Aria hotel and the Planet13 dispensary. Edwards said the dispensary was the only one of the three places where he knew the license had been scanned.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading

Read Between the Lies: A Pattern Recognition Guide

When Avril Haines, Director of National Intelligence, announced during Event 201’s pandemic drill in 2019 that they would “flood the zone with trusted sources,” few understood this preview of coordinated narrative control. Within months, we watched it unfold in real time—unified messaging across all platforms, suppression of dissent, and coordinated narrative control that fooled much of the world.

But not everyone stayed fooled forever. Some saw through it immediately, questioning every aspect from day one. Others thought it was just incompetent government trying to protect us. Many initially accepted the precautionary principle—better safe than sorry. But as each policy failure pointed in the same direction—toward more control and less human agency—the pattern became impossible to ignore. Anyone not completely subsumed by the system eventually had to confront its true purpose: not protecting health or safety, but expanding control.

Once you recognize this pattern of deception, two questions should immediately arise whenever major stories dominate headlines: “What are they lying about?” and “What are they distracting us from?” The pattern of coordinated deception becomes unmistakable. Consider how media outlets spent three years pushing Russiagate conspiracies, driving unprecedented social division while laying the groundwork for what would become the greatest psychological operation in history. Today, while the media floods us with Ukraine coverage, BlackRock positions itself to profit from both the destruction and reconstruction. The pattern becomes unmistakable once you see it—manufactured crises driving pre-planned “solutions” that always expand institutional control.

Mainstream media operates on twin deceptions: misdirection and manipulation. The same anchors who sold us WMDs in Iraq, promoted “Russia collusion,” and insisted Hunter Biden’s laptop was “Russian disinformation” still occupy prime time slots. Just as we see with RFK, Jr.’s HHS nomination, the pattern is consistent: coordinated attacks replace substantive debate, identical talking points appear across networks, and legitimate questions are dismissed through character assassination rather than evidence. Being consistently wrong isn’t a bug—it’s a feature. Their role isn’t to inform but to manufacture consent.

The template is consistent: Saturate media with emotional spectacles while advancing institutional agendas with minimal scrutiny. Like learning to spot a fake smile or hearing a false note in music, you develop an instinct for the timing:

Money and Power:

Medical Control:

Digital Control:

As these deceptions become more obvious, different forms of resistance emerge. The truth-seeking takes different forms. Some become deep experts in specific deceptions—documenting early treatment successes with repurposed drugsuncovering hospital protocol failures, or exploring the impact of vaccine injuries. Others develop a broader lens for seeing how narratives themselves are engineered.

Keep reading

Mark Zuckerberg’s Meta Calls on YouTube and TikTok to Match Its Teen Safeguards

Mark Zuckerberg’s Meta will pay $18 billion to settle a federal lawsuit accusing it of fueling a teen mental health crisis, but nearly a third of that sum depends on whether TikTok and YouTube agree to adopt the same safeguards. The social media giant is now directly calling on its largest competitors to follow Zuckerberg’s lead.

The settlement announced just days into a trial brought by a coalition of state attorneys general, resolves claims that Meta hooked children on its platforms and ignored the resulting harms, including anxiety, depression and suicide, to protect its profits. Meta will pay 70 percent of the total, about $12.7 billion, upfront. The remaining $5.3 billion only gets released if TikTok and Google’s YouTube together pay a matching $5.3 billion and adopt the same restrictions Meta is imposing on itself.

Those required changes include a one-hour daily usage limit for teens, a “night mode” that blocks access during bedtime hours, and age verification measures. Meta agreed to a two-hour daily limit for teens on Facebook and Instagram, which would drop to one hour if TikTok and YouTube fall in line. The night mode default would block teen access from midnight to 6:00 a.m. Most provisions in the settlement are set to last 10 years.

Meta is also banning filters for “cosmetic surgery and extreme makeup,” removing “Likes” and other reactions from teen posts by default, and strengthening parental oversight tools. The settlement leaves Meta’s recommendation algorithm, the system that decides what content teens see, untouched.

Meta published an open letter calling out its rivals directly, writing that “these protections will only be truly effective if we work with our peers — TikTok and YouTube — to put the same measures in place.” As of Wednesday afternoon, neither company had responded, despite multiple requests for comment. TikTok recently settled a separate, unrelated case with the DOJ for $400 million over children’s privacy.

Keep reading

Google To Expand Play Age Signals API to All Users Worldwide

Just in time for the global digital ID push, Google will roll out its Play Age Signals API to all Google Play users worldwide by the end of 2026. This gives Android apps an easy way to ask Google how old its users are.

Google Play’s vice president of product management, Paul Feng, announced the expansion on July 29. Australia and Canada come first by mid-August, followed by “a full global rollout to all users later this year.” Apple launched its own versionthe Declared Age Range API, worldwide in February.

An app calls the API while it’s running and Play answers with the band the user falls into, 0-12, 13-15, 16-17, or 18+ by default. Developers can redraw those bands in the Play Console. A developer who sets minimum ages of 13 and 17 gets users sorted into 0-12, 13-16, and 17 and over.

The feedback arrives as a lower and an upper bound, and the top band carries no upper bound, so an adult in that setup comes back as ageLower = 17, an age floor with no ceiling. A user who declined to share gets no band at all, only a NOT_SHARED status. Google’s rules bar any other use of the answer, “including, but not limited to, advertising, marketing, user profiling or analytics.”

To parents, Google says the API as “a privacy-preserving tool that puts parents in the driver’s seat.” A parent enters a child’s range once in the Family Link app, 16-17 rather than an exact birth date and every app that has built in the API can read it. Google says sharing is off until a parent opts in and that the setting can be changed or switched off at any time.

That default lasts until a law overrides it and Texas already has and you only have to look at the latest senate bill that we just covered to know exactly how this “privacy” preserving plan can end up being anything but. Adults can share their own range when an app asks. “Providing a safe online experience and protecting users from harm is a top priority at Google Play,” Feng wrote in his announcement.

Apps receive more than a band. Google’s developer pages say an app can receive “users’ age verification or supervision status, age ranges, and other applicable signals,” and the status field can also come back VERIFICATION_REQUIRED. A developer knows when a user declined to share and when an age was verified rather than declared, and Google leaves it to each app to decide what to accept. TechRadar, citing reports, says users who fail to complete verification can be blocked from downloading a wide range of apps, not just those with adult ratings.

The API went live in Brazil on March 17, the day the Digital ECA took effect. That law bans the “I am over 18” checkbox and threatens fines of up to 50 million reais, about US$9.44 million, or 10 percent of a company’s Brazilian revenue. Texas followed.

Play began returning ages and running an age verification flow for Texans who created accounts after May 28, once a federal appeals court stayed the December 2025 injunction that had blocked the state’s App Store Accountability Act.

Keep reading

A Law That the People It Targets Can Defeat With a Felt-Tip Pen

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced on 24 August 2026 – the very day I arrived back in New Zealand after nearly a month away.

Readers of “A Halflings View” will be well aware of my views about bans or restrictions on access to social media platform by the young. Although the news media have trumpeted the present proposals as a “ban” it is not. It actually constitutes a form of limited restriction.

This article is very much a “first impression” view of the Bill. Much of the material and commentary is gathered from earlier writings I have produced on the subject as well as from other sources among them Ani O’Brien, “Thought Crimes” (Substack) — “Hear me out: Ban the hardware not the software”; the New Zealand Initiative; Privacy Commissioner Michael Webster; UNICEF Aotearoa (Susan Glasgow); Australia’s eSafety Commissioner three-month evaluation (July 2026); UK Ofcom/House of Lords material and reporting on the Online Safety Act; and US litigation (NetChoice; the Louisiana and Arkansas decisions).

Furthermore, this article (and indeed the Bill itself) will not be the final word.

The Bill has not yet had its First Reading and that is unlikely before Parliament rises. But Prime Minister Luxon and Erica Stanford were determined to push this ill-advised proposal ahead at pace, even although what it really amounts to is an announcement until the Bill has its First Reading. And it may even fall at that fence. If it makes it, Select Committee submissions and further commentary will accumulate quickly.

Hence the critique reflects the position as at the time of publication of this article.

What the Bill actually does

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, introduced to Parliament on 24 August 2026 by Education Minister Erica Stanford, is a stand-alone statute built on two load-bearing duties.

The first (clause 11) requires operators of “age-restricted platforms” to take reasonable steps to stop New Zealanders under 16 from holding an account. The second (clause 14) requires those operators to produce an annual, written child safety risk assessment covering all under-18s who use the platform.

Behind these sit an enforcement apparatus of warnings, enforceable undertakings, corrective notices, tiered pecuniary penalties (up to the greater of NZ$40 million or 10% of global turnover), and, as a last resort, service restriction orders and access restriction orders that would conscript ISPs, app stores and ancillary providers into preventing access to the platform from New Zealand.

The regulator is the Secretary of Internal Affairs — the chief executive of the Department of Internal Affairs (DIA). More on this disturbing aspect later.

Much of the drafting is careful.

It regulates the account, not the child, so no penalty falls on minors or parents.

It explicitly forbids treating manual date-of-birth entry as a “reasonable step”.

It goes beyond the Privacy Act by requiring destruction of age-assurance data.

The Bill is also more sophisticated than the “ban” it is marketed as. As I have argued on earlier occasions about similar proposals, this is a set of managed restrictions on account-holding, not a prohibition on children seeing content. Publicly available material remains reachable.

But the care in the drafting cannot rescue the concept.

The Bill imports a policy model that has already been trialled next door in Australia and in Britain, and the trials are in.

What follows is the case against it — a case now supported by a striking amount of hard evidence rather than speculation — followed by the specific problem of handing the whole scheme to the DIA.

The central flaw: a “targeted” measure that touches everyone

The Bill’s rhetorical appeal rests on the idea that it targets under-16s. Its mechanism does not.

To reliably prevent a 15-year-old from holding an account, a platform must satisfy itself about the age of every account-holder — which in practice means age-assuring the entire adult population as well.

Privacy Commissioner Michael Webster made the point bluntly when the policy was first floated. Keeping under-16s out means everyone over 16 has to prove they are over 16. The New Zealand Initiative put it the same way — everyone will have to demonstrate they are not under sixteen, including you.

This is the paradox the Bill never resolves, and it is not a drafting quibble but the whole problem.

Clause 11 forbids the “cheap check” (a manual date of birth entry) and forbids relying solely on formal ID or a digital identity service, which forces platforms toward either document upload, facial age-estimation, or “age inference” from behavioural and device signals.

Keep reading

AG Blanche’s Warning Points Straight at Age Verification Checks

The US Department of Justice (DOJ) has managed to extract $400 million from TikTok, and this is not a story about the company being forced to change its ways – but pay up nonetheless.

The settlement, which means no admission of wrongdoing on the part of TikTok, will see the company pay $300 million now, and another $100 million once a prior consent decree is vacated.

That earlier decree came from a 2019 case, United States v. Musical.ly, an app that was later folded into TikTok. The current case, United States v. ByteDance, was filed in 2024 and is now dismissed with prejudice.

The original complaint accused ByteDance of violating the COPPA Rule by letting children slip past TikTok’s age gate and “knowingly creating accounts for children and collecting data from those children” without “verifiable parental consent.”

The 2019 consent decree also sought to ensure that the company would get “verifiable parental consent” before collecting personal information from children.

The settlement reached now requires TikTok to change absolutely nothing.

The DOJ explains this by saying that since the 2024 filing, TikTok “has undergone significant changes to its ownership, management, compliance functions, and privacy practices” and “implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.”

Those changes “have materially advanced the public interests underlying the Department’s litigation and have strengthened protections for millions of American families,” the DOJ said.

And what is “verifiable parental consent” that’s the main aspect of the original complaint and the 2019 consent decree? That’s where things get interesting. COPPA doesn’t mandate any specific method, but lists several, which escalate quickly from a signed consent form, to a payment from a parent’s credit or debit card, to submitting a government-issued ID and matching it to a face scan, or being verified over video call.

In other words, proving that a parent has given consent tends to boil down to proving who everyone is.

Keep reading