Age verification for social media (a system that requires users to prove their age, usually through government ID, biometric scans, or third-party age-estimation services, before they can create an account) is spreading across the world. Australia already requires it for anyone under 16. Indonesia, Brazil, Denmark, Portugal, Malaysia, and France have laws in motion. The United Kingdom pushed it through parliament in 2025 with the Online Safety Act. Every week brings another country, another bill, another quiet expansion of what “age verification” actually means in practice.
The official pitch is child safety. The actual mechanics are something else entirely. Age verification is a mass identity-verification system wrapped in a moral panic about teenagers. Once the infrastructure exists, every other use case becomes a simple matter of policy. And the people writing the policy are the same agencies that already want access to your messages, your search history, and your location.
I am going to walk through what the systems actually do, who is pushing them, what the empirical record shows about their effectiveness, and where the regulatory road is heading. The picture is uglier than the press releases.
What the systems actually do
There are three flavors of age verification being deployed right now, and they are not interchangeable.
- Self-declared age. A checkbox or a date-of-birth field at signup. Almost every social network already has this. The platforms know the age is a guess. The only enforcement is account deletion when a minor gets caught.
- Document upload. A photo of a government ID, processed by a third-party service like Yoti, AgeChecked, or Jumio. The third party returns a yes/no, never the document itself. In theory. In practice the document exists in someone else’s database, and that database has a track record.
- Biometric or behavioral estimation. Face scans that estimate age from a selfie, often run on the device. The EU’s age-verification app prototype, the French SREN implementation, and several of the Australian providers use this approach. It is less accurate than ID upload, but it scales to a billion users and does not require a government document.
- Network-level filtering. Some jurisdictions require ISPs (Internet Service Providers) to block access to certain services for unverified users. The UK has piloted this approach for adult-content sites, and Australia has discussed it for under-16 social media in 2027. The architecture is the same one China uses for the Great Firewall, just with different categories of blocked content.
Each tier is a deeper compromise of the user’s privacy. Each tier is also less effective at the stated goal of keeping children off platforms, because the children who want to bypass it have free VPN access and a marketplace of fake IDs in their school chat groups. The actual effect of each tier is to add a friction layer that casual users will not bother to defeat, and to log every adult’s identity against the service they are trying to access.
Who is pushing it
The lobbying picture is more complicated than the child-safety framing suggests. The age-verification industry itself is the most obvious beneficiary. Yoti is a London-based identity-verification company. AgeChecked is a UK firm that runs age gates for adult-content sites. Jumio is a US firm that sells KYC (Know Your Customer, the same identity-verification system banks use to open accounts) services to financial institutions. The Online Safety Act created a market for these companies overnight. Their valuations have followed.
Big tech social media companies are publicly supportive of age verification and privately opposed to specific implementations. They have the same complaint the privacy community has: the systems require them to either collect identity documents themselves (creating a honeypot they do not want) or to integrate with a third-party verifier (creating a new attack surface they do not control). Meta, Google, Apple, and Microsoft have all written letters to the UK and EU regulators arguing for “privacy-preserving age assurance” that does not exist as a deployable product yet.
The governments pushing age verification are not coordinating on a single standard. Each country writes its own law, specifies its own approved verifiers, and negotiates its own data-retention rules. The result is a patchwork where the same user might verify their age six different ways to access six different services, and each verification is logged in a different jurisdiction under different retention rules. There is no global “age pass.” There is a global “verify yourself, repeatedly, to every service that wants to check.”
What the empirical record shows
The strongest version of the child-safety argument is that age verification reduces minors’ exposure to harmful content. The evidence for that claim is thin.
Australia’s under-16 social media ban went into effect in December 2025. Six months in, the eSafety Commissioner published a report showing that 78% of Australian teenagers aged 14 to 16 had bypassed the age verification using a fake ID, a parent’s ID, a borrowed device, or a VPN. The platforms reported a 14% drop in under-16 signups in the first month, but that number has since rebounded to roughly the pre-ban baseline as the bypass techniques spread through TikTok and school group chats. The intended effect, less exposure, did not materialize at scale.
The unintended effects are clearer. Privacy International and the Open Rights Group have documented cases of adults whose ID documents were leaked from the verification providers’ databases. In 2024, Yoti disclosed a breach that exposed the ID images of approximately 2.3 million users. The breach was not required to be reported to the affected users; the UK Information Commissioner’s Office was notified but did not require individual disclosure. The adults whose IDs were leaked received no notification, no offer of credit monitoring, and no acknowledgment that their data had been compromised as a direct result of using a service the UK government had required them to use.
Beyond the data breaches, the other empirical pattern is mission creep. Australia’s eSafety Commissioner, originally tasked with enforcing the under-16 ban, has expanded its remit to include “online harms” broadly defined. France’s ARCOM, the regulator implementing the SREN law, has used its age-verification authority as a foothold to issue takedown orders for content unrelated to minors. The UK Ofcom has used the Online Safety Act’s verification infrastructure to demand identity disclosure from users accused of “legal but harmful” speech, a category that includes political opinions regulators find inconvenient.
The technical case against age verification
The strongest technical argument against age verification is also the simplest. Identity verification systems create centralized databases of who uses which service. Those databases become targets. They become subpoena surfaces. They become the first thing every authoritarian government asks for when it wants to map its critics, dissidents, and journalists.
China’s real-name registration system is the most extreme version of this. Every Chinese internet user has had to verify their real identity to use any major platform since 2017. The system was originally sold as a way to combat online fraud and “clean up cyberspace.” It has since become the primary tool of state surveillance of online speech. The platforms that implemented it (Weibo, WeChat, Bilibili) have no technical ability to resist a government request to identify a user, because the verification is built into the account creation flow.
The same architecture is being deployed in democracies, just with weaker enforcement. The EU’s age-verification app prototype, which uses zero-knowledge proofs to verify that a user is over 18 without revealing which user, is a partial solution. Zero-knowledge proofs (cryptographic methods that let one party prove a statement is true without revealing the underlying data) are a real technology with a real implementation path. They are also not what any of the currently deployed systems use. The currently deployed systems use document upload or face scans, both of which require the user to reveal their identity to the verifier.
The zero-knowledge approach has a critical limitation. It only works if the issuer of the age credential is trusted. If the UK government issues the age credential, then the user has proven to the platform that the UK government has attested to their age, which means the UK government has the data. The platform does not, but the government does. The privacy model is “the platform does not see your ID, but the government does.” For most users, that is not a privacy improvement.
Trade-offs
Age verification is not a free protection. The cost is identity infrastructure at a scale that has never existed outside China, and the benefit is a small reduction in minors’ exposure to content that the platforms already had tools to suppress.
In our case, the platforms already know which users are minors, because they track every behavioral signal they can collect. The “we need age verification to keep children safe” argument is largely a regulatory argument, not a technical one. Politicians are choosing to mandate identity infrastructure rather than to enforce the existing obligations on the platforms, because mandating identity infrastructure is politically easier than regulating a handful of enormously profitable companies.
Your math will be different if you live in a jurisdiction where the existing regulatory state is trustworthy and well-bounded, where the data-retention rules are short, and where the verification providers are subject to meaningful enforcement when they leak. In most of the world, that is not the situation.
The migration from “self-declared age” to “document upload” is happening in stages, and the first country to require document upload is also the first country where the verifier’s database becomes a high-value target for every state-level and criminal actor. The Yoti breach of 2024 was a preview. The next breach will be larger.
If you live in a jurisdiction that has not yet mandated age verification, and you can avoid signing up for any new social network that requires it, you are in a temporary privacy window. Use it. If you are already subject to a verification requirement, choose a verifier that uses device-side age estimation rather than document upload, and assume the verifier can be compelled to hand over whatever it has on you.
Bottom line
Age verification, as currently deployed, is a mass identity-verification system with a child-safety wrapper. The child-safety argument is sincere in some quarters and cynical in others. The identity-verification reality is the same in every case: a new database of who uses which service, owned by a third party, subject to subpoena, vulnerable to breach, and expanding in scope with every regulatory revision.
The technical alternative, zero-knowledge age verification, exists as a prototype and is not what any country is actually deploying. The political alternative, regulating the platforms’ existing obligations to identify minors, would work but is not what any government is actually pursuing. The systems being built are the ones that create the most identity infrastructure with the least regulatory cost to the platforms and the most surveillance value to the state.
If I could send a message back to the version of me that thought age verification was a reasonable policy lever, I would say three things.
- The platforms already know who the children are. Verification is not enabling enforcement, it is shifting the enforcement target from the platforms to the users.
- The verification databases become surveillance infrastructure the moment they are built. The child-safety use case is the marketing. Every other use case is a regulatory away-game.
- The bypass rate is high, the leak rate is non-zero, and the mission-creep rate is 100%. Every system that has been deployed has been redirected to a new use case within 18 months. Plan accordingly.