California Is Building an Internet of Age Checks and Identity Gates

California Governor Gavin Newsom has signed two controversial age verification bills into law: AB 1709 and SB 1119.

Newsom was quoted as saying that Thursday was “a good day for our children,” but both laws will also impact adults by forcing online services to distinguish between users based on age.

AB 1709 deals with features on social media that are considered addictive, such as personalized feeds and autoplay, and prohibits these for California users under 16.

Before being allowed to use these features, users must be verified under the California Digital Age Assurance Act, or another statutory age-determination method. The Act in turn relies on age-bracket signals from operating systems and app stores, which are based on age or birthdate information provided by users. The law includes data-minimization and sharing restrictions, and does not require passports or face scans from all users.

AB 1709 will in effect mean that children will be able to use social media accounts, but without access to personalized feeds, which is how many people discover new content and information, and is a key component of how these platforms work.

But the law doesn’t only affect children; adults who want to use the covered features must also verify their age. In reality, this means that companies behind the platforms will have to act as arbiters of who can and cannot use what features.

Keep reading

Microsoft Brings “Age Verification” System To Windows

Just in time for the global digital ID agenda playing out, Microsoft has published instructions for developers on how to use an API that is not yet active.

The API, or programming interface, is designed to let apps on the Windows 11 operating system find out a user’s age bracket, and whether that age has been verified by an “identity provider.”

The age bracket is very broad: under 10, 10-12, 13-15, 16-17, and 18 and over. The verification status, on the other hand, can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable, or NotApplicable.

Microsoft does not go into what these identity providers will be, or what evidence they will use to verify a person’s age. The company only says that the second value returned by the API will show “whether the user’s age has been independently verified by the identity provider.”

Microsoft frames this as a way to improve privacy, by giving app developers a way to determine a user’s age without actually knowing their date of birth, or any other personally identifiable information. According to Microsoft, this is a “privacy-preserving mechanism” that will allow apps to comply with regulations concerning child safety. But, as we’ve seen from bills that call for this type of technology to be installed in operating system, this is all about normalizing age checks (and therefore ID checks) at all stages of digital life.

In this case, an age signal does not directly expose the user’s age or date of birth. Instead, it provides a way to adapt content, features, or access controls in an app based on the user’s age range and age verification status. For example, an app can use the age signal for user-generated content, social or communication tools, in-app purchases, virtual currencies, or maturity-rated media.

Microsoft goes into some detail about how developers can use the API, but notes that it is not yet available and will not return any useful data until it is turned on later in the year. For now, the company is providing the documentation ahead of the release to give developers a head start.

In January 2024, Microsoft was more cautious about the possibility of creating a system to determine a user’s age online. At the time, the company said it was exploring various methods and seeking expert input, but was not sure that the technical solution was there yet.

“There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user’s age without risking trade-offs such as potential security, privacy, and human rights risks,” a Microsoft blog post said at the time.

California has since created its own framework for age verification.

Keep reading

Meta Settlement Ignites Global “Child Safety” Digital ID Push

The ink on the multi-billion dollar settlement agreement that Meta struck with 47 US states, the District of Columbia and a number of US territories has barely had time to dry – and already, officials and campaigners in the US, the EU, the UK, and at the UN are using it to press for similar rules to be imposed elsewhere.

In the UK, Work and Pensions Secretary Pat McFadden said that Meta should apply the new rules in that country as well, while the government there has its own plans to ban social media for under-16s and impose nighttime curfews.

“We don’t want a situation where young people in America have got a higher rate of protection than young people in the UK,” he said.

The British plan is to ban social media for those under 16 by spring 2027, and impose nighttime curfews on older teenagers, the Independent is reporting. To enforce this, platforms will have to know whether a user is a child or an adult, stepping up the pressure on companies to introduce age checks.

In the EU, the Commission is also piling on the pressure on Meta to “export” the US deal.

“We expect adequate management of screen time, appropriate parental controls on these platforms,” said digital spokesperson Thomas Regnier. “It is now up to the company to propose these commitments within the European Union in order to also protect our children here.”

The official revealed that the Commission has already been in talks with Meta since the US agreement was announced, and that the goal is to give children in the EU “at least” the same protections as those in the US.

Meanwhile, UN High Commissioner for Human Rights Volker Türk is using the settlement to call for global protections for children from what he says is the harm caused by excessive social media use.

In the US, District of Columbia Attorney General Brian Schwalb, one of those behind the lawsuit that led to the settlement, said that Meta “will not be the last” company to be forced to agree to such terms.

His California counterpart, Rob Bonta, said that Meta is “not the only player in the industry” to have “visited enormous mental health harms on kids through their products and their designs,” and added, “others rightfully must be held accountable.”

The settlement contains financial incentives for states to bring similar cases against other companies. Snap, TikTok, and YouTube are mentioned by name in this context.

Not everyone is happy with the deal, however. Arturo Béjar, a former Meta employee who was a witness in the trial, said the protections are insufficient and that the product remains harmful.

“The limitations that are in the agreement are the equivalent of saying: ‘Well, you can smoke as many cigarettes as you can in two hours a day,'” he said. “It doesn’t make the cigarettes any safer.”

Meta responded by saying that Béjar is ignoring some of the other provisions of the settlement, such as non-algorithmic feed defaults and stronger parental controls.

“We have a huge raft of built-in protections,” a spokesperson said, and argued that teenagers also derive “substantial” benefits from using social media.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading

Mark Zuckerberg’s Meta Calls on YouTube and TikTok to Match Its Teen Safeguards

Mark Zuckerberg’s Meta will pay $18 billion to settle a federal lawsuit accusing it of fueling a teen mental health crisis, but nearly a third of that sum depends on whether TikTok and YouTube agree to adopt the same safeguards. The social media giant is now directly calling on its largest competitors to follow Zuckerberg’s lead.

The settlement announced just days into a trial brought by a coalition of state attorneys general, resolves claims that Meta hooked children on its platforms and ignored the resulting harms, including anxiety, depression and suicide, to protect its profits. Meta will pay 70 percent of the total, about $12.7 billion, upfront. The remaining $5.3 billion only gets released if TikTok and Google’s YouTube together pay a matching $5.3 billion and adopt the same restrictions Meta is imposing on itself.

Those required changes include a one-hour daily usage limit for teens, a “night mode” that blocks access during bedtime hours, and age verification measures. Meta agreed to a two-hour daily limit for teens on Facebook and Instagram, which would drop to one hour if TikTok and YouTube fall in line. The night mode default would block teen access from midnight to 6:00 a.m. Most provisions in the settlement are set to last 10 years.

Meta is also banning filters for “cosmetic surgery and extreme makeup,” removing “Likes” and other reactions from teen posts by default, and strengthening parental oversight tools. The settlement leaves Meta’s recommendation algorithm, the system that decides what content teens see, untouched.

Meta published an open letter calling out its rivals directly, writing that “these protections will only be truly effective if we work with our peers — TikTok and YouTube — to put the same measures in place.” As of Wednesday afternoon, neither company had responded, despite multiple requests for comment. TikTok recently settled a separate, unrelated case with the DOJ for $400 million over children’s privacy.

Keep reading

Google To Expand Play Age Signals API to All Users Worldwide

Just in time for the global digital ID push, Google will roll out its Play Age Signals API to all Google Play users worldwide by the end of 2026. This gives Android apps an easy way to ask Google how old its users are.

Google Play’s vice president of product management, Paul Feng, announced the expansion on July 29. Australia and Canada come first by mid-August, followed by “a full global rollout to all users later this year.” Apple launched its own versionthe Declared Age Range API, worldwide in February.

An app calls the API while it’s running and Play answers with the band the user falls into, 0-12, 13-15, 16-17, or 18+ by default. Developers can redraw those bands in the Play Console. A developer who sets minimum ages of 13 and 17 gets users sorted into 0-12, 13-16, and 17 and over.

The feedback arrives as a lower and an upper bound, and the top band carries no upper bound, so an adult in that setup comes back as ageLower = 17, an age floor with no ceiling. A user who declined to share gets no band at all, only a NOT_SHARED status. Google’s rules bar any other use of the answer, “including, but not limited to, advertising, marketing, user profiling or analytics.”

To parents, Google says the API as “a privacy-preserving tool that puts parents in the driver’s seat.” A parent enters a child’s range once in the Family Link app, 16-17 rather than an exact birth date and every app that has built in the API can read it. Google says sharing is off until a parent opts in and that the setting can be changed or switched off at any time.

That default lasts until a law overrides it and Texas already has and you only have to look at the latest senate bill that we just covered to know exactly how this “privacy” preserving plan can end up being anything but. Adults can share their own range when an app asks. “Providing a safe online experience and protecting users from harm is a top priority at Google Play,” Feng wrote in his announcement.

Apps receive more than a band. Google’s developer pages say an app can receive “users’ age verification or supervision status, age ranges, and other applicable signals,” and the status field can also come back VERIFICATION_REQUIRED. A developer knows when a user declined to share and when an age was verified rather than declared, and Google leaves it to each app to decide what to accept. TechRadar, citing reports, says users who fail to complete verification can be blocked from downloading a wide range of apps, not just those with adult ratings.

The API went live in Brazil on March 17, the day the Digital ECA took effect. That law bans the “I am over 18” checkbox and threatens fines of up to 50 million reais, about US$9.44 million, or 10 percent of a company’s Brazilian revenue. Texas followed.

Play began returning ages and running an age verification flow for Texans who created accounts after May 28, once a federal appeals court stayed the December 2025 injunction that had blocked the state’s App Store Accountability Act.

Keep reading

Paxton “Child Safety” Plan Puts Legal Speech at Criminal Risk

Texas Attorney General Ken Paxton, who is currently running for the US Senate, and pushing online digital ID age verification checks in the name of “online safety,” has announced a data center plan that, among other things, vows to “protect children” by making data center companies criminally liable if the centers they operate “empower AI chatbots that undermine children’s safety.”

Paxton is effectively promising to author legislation that would introduce a novel form of liability, aimed at data centers – the physical and hardware part of the internet’s infrastructure – for the content that is generated by software running on their servers.

This is a clear departure from the principle, enshrined in Section 230 of the Communications Decency Act (CDA), that internet infrastructure is not liable for third-party, user-generated content.

And, while Paxton’s plan speaks of chatbots that “undermine children’s safety” – a broad and vague term that can easily be abused to censor speech – the actual target could be any chatbot, and any speech.

And the liability would be criminal.

Paxton is quoted as saying in a post on X: “My Texas First Data Center Plan will protect our grid, our communities, and our children while ensuring America beats Communist China in the AI race,” he wrote.

Keep reading

A Law That the People It Targets Can Defeat With a Felt-Tip Pen

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced on 24 August 2026 – the very day I arrived back in New Zealand after nearly a month away.

Readers of “A Halflings View” will be well aware of my views about bans or restrictions on access to social media platform by the young. Although the news media have trumpeted the present proposals as a “ban” it is not. It actually constitutes a form of limited restriction.

This article is very much a “first impression” view of the Bill. Much of the material and commentary is gathered from earlier writings I have produced on the subject as well as from other sources among them Ani O’Brien, “Thought Crimes” (Substack) — “Hear me out: Ban the hardware not the software”; the New Zealand Initiative; Privacy Commissioner Michael Webster; UNICEF Aotearoa (Susan Glasgow); Australia’s eSafety Commissioner three-month evaluation (July 2026); UK Ofcom/House of Lords material and reporting on the Online Safety Act; and US litigation (NetChoice; the Louisiana and Arkansas decisions).

Furthermore, this article (and indeed the Bill itself) will not be the final word.

The Bill has not yet had its First Reading and that is unlikely before Parliament rises. But Prime Minister Luxon and Erica Stanford were determined to push this ill-advised proposal ahead at pace, even although what it really amounts to is an announcement until the Bill has its First Reading. And it may even fall at that fence. If it makes it, Select Committee submissions and further commentary will accumulate quickly.

Hence the critique reflects the position as at the time of publication of this article.

What the Bill actually does

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, introduced to Parliament on 24 August 2026 by Education Minister Erica Stanford, is a stand-alone statute built on two load-bearing duties.

The first (clause 11) requires operators of “age-restricted platforms” to take reasonable steps to stop New Zealanders under 16 from holding an account. The second (clause 14) requires those operators to produce an annual, written child safety risk assessment covering all under-18s who use the platform.

Behind these sit an enforcement apparatus of warnings, enforceable undertakings, corrective notices, tiered pecuniary penalties (up to the greater of NZ$40 million or 10% of global turnover), and, as a last resort, service restriction orders and access restriction orders that would conscript ISPs, app stores and ancillary providers into preventing access to the platform from New Zealand.

The regulator is the Secretary of Internal Affairs — the chief executive of the Department of Internal Affairs (DIA). More on this disturbing aspect later.

Much of the drafting is careful.

It regulates the account, not the child, so no penalty falls on minors or parents.

It explicitly forbids treating manual date-of-birth entry as a “reasonable step”.

It goes beyond the Privacy Act by requiring destruction of age-assurance data.

The Bill is also more sophisticated than the “ban” it is marketed as. As I have argued on earlier occasions about similar proposals, this is a set of managed restrictions on account-holding, not a prohibition on children seeing content. Publicly available material remains reachable.

But the care in the drafting cannot rescue the concept.

The Bill imports a policy model that has already been trialled next door in Australia and in Britain, and the trials are in.

What follows is the case against it — a case now supported by a striking amount of hard evidence rather than speculation — followed by the specific problem of handing the whole scheme to the DIA.

The central flaw: a “targeted” measure that touches everyone

The Bill’s rhetorical appeal rests on the idea that it targets under-16s. Its mechanism does not.

To reliably prevent a 15-year-old from holding an account, a platform must satisfy itself about the age of every account-holder — which in practice means age-assuring the entire adult population as well.

Privacy Commissioner Michael Webster made the point bluntly when the policy was first floated. Keeping under-16s out means everyone over 16 has to prove they are over 16. The New Zealand Initiative put it the same way — everyone will have to demonstrate they are not under sixteen, including you.

This is the paradox the Bill never resolves, and it is not a drafting quibble but the whole problem.

Clause 11 forbids the “cheap check” (a manual date of birth entry) and forbids relying solely on formal ID or a digital identity service, which forces platforms toward either document upload, facial age-estimation, or “age inference” from behavioural and device signals.

Keep reading

AG Blanche’s Warning Points Straight at Age Verification Checks

The US Department of Justice (DOJ) has managed to extract $400 million from TikTok, and this is not a story about the company being forced to change its ways – but pay up nonetheless.

The settlement, which means no admission of wrongdoing on the part of TikTok, will see the company pay $300 million now, and another $100 million once a prior consent decree is vacated.

That earlier decree came from a 2019 case, United States v. Musical.ly, an app that was later folded into TikTok. The current case, United States v. ByteDance, was filed in 2024 and is now dismissed with prejudice.

The original complaint accused ByteDance of violating the COPPA Rule by letting children slip past TikTok’s age gate and “knowingly creating accounts for children and collecting data from those children” without “verifiable parental consent.”

The 2019 consent decree also sought to ensure that the company would get “verifiable parental consent” before collecting personal information from children.

The settlement reached now requires TikTok to change absolutely nothing.

The DOJ explains this by saying that since the 2024 filing, TikTok “has undergone significant changes to its ownership, management, compliance functions, and privacy practices” and “implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.”

Those changes “have materially advanced the public interests underlying the Department’s litigation and have strengthened protections for millions of American families,” the DOJ said.

And what is “verifiable parental consent” that’s the main aspect of the original complaint and the 2019 consent decree? That’s where things get interesting. COPPA doesn’t mandate any specific method, but lists several, which escalate quickly from a signed consent form, to a payment from a parent’s credit or debit card, to submitting a government-issued ID and matching it to a face scan, or being verified over video call.

In other words, proving that a parent has given consent tends to boil down to proving who everyone is.

Keep reading

States take Meta to trial in California in the biggest fight yet over social media harms to children

Of the thousands of lawsuits Meta faces over child safety on its platforms, none may be more consequential than one going to trial this week in California.

States are seeking extensive financial damages that could, in theory, total as much as $1.4 trillion, plus changes to how the company operates Facebook and Instagram.

The lawsuit accuses the social media giant of contributing to the youth mental health crisis by knowingly and deliberately designing features that get children addicted to its platforms. It also claims that Meta routinely collects data on children under 13 without their parents’ consent, in violation of federal law.

“Meta has harnessed powerful and unprecedented technologies to entice, engage, and ultimately ensnare youth and teens. Its motive is profit, and in seeking to maximize its financial gains,” the lawsuit says.

Dozens of states filed the lawsuit three years ago. The trial set to begin Tuesday in federal court in Oakland, California, features four of the states as plaintiffs — California, Colorado, Kentucky and New Jersey. The other 25 states are expected to have trials later.

Meta said it disputes the allegations, and the trial evidence will show its commitment to supporting young people. “We’ve listened to parents, worked with experts and law enforcement, and conducted in-depth research to understand the issues that matter most,” the company said in a statement.

States seek to land a major blow against Meta
For Meta, which already lost two pivotal cases over harms to children and teens this year, the stakes are high. The company reported a rare profit decline last month, in part due to $2.4 billion in legal expenses.

The $1.4 trillion figure, which Meta disclosed in a legal filing, is almost as high as the Menlo Park, California, company’s entire market capitalization — that is, the value of all its outstanding shares on the stock market. Paying it would inevitably put Meta Platforms in bankruptcy and perhaps put the company under state ownership.

“The state attorneys general are going for the gusto,” said Eric Goldman, a professor and co-director of the High Tech Law Institute at Santa Clara University School of Law. “They are trying to set the definitive precedent in this case and they have asked for extraordinary damages and they are going to seek extraordinary structural remedies if they succeed.”

Meta calls the possible penalty “untethered to any claimed violation” by the states.

“A sanction of that size has no analog in the history of consumer protection enforcement,” Meta said in a July 6 filing with the U.S. District Court for the Northern District of California.

If Meta loses the trial, the court would have wide discretion over the size of any financial penalty, and legal experts say anything close to $1.4 trillion would be unlikely.

“It’s not plausible in the sense that Meta doesn’t have that much money and could not get it,” said James Grimmelmann, a law professor at Cornell Law School and Cornell Tech. “An award that large would put Meta into bankruptcy, wipe out its owners, and effectively result in the states owning Meta.”

Keep reading