The device becomes
the papers.

Three jurisdictions built age verification three different ways. Britain uploads your passport to each website. Texas moved the check into the app store. The European Union built the version that leaks nothing at all. All three end in the same place.

What was settled, and what was not

On 27 June 2025 the Supreme Court decided Free Speech Coalition, Inc. v. Paxton, upholding a Texas law requiring age verification on sites publishing material obscene to minors. The vote was 6 to 3, Justice Thomas writing. The law "triggers, and survives, review under intermediate scrutiny because it only incidentally burdens the protected speech of adults."

One sentence in that opinion is doing more work than the rest of the case combined:

"Adults have the right to access speech obscene only to minors, and submitting to age verification burdens the exercise of that right. But adults have no First Amendment right to avoid age verification."
What that resolves, and what it leaves open

The Court answered one question: can adults be required to prove their age before seeing lawful material? Yes, at least for this category of content.

It did not answer, and was not asked, any of the questions that decide what this costs you. Who holds the proof. For how long. Attached to which account. Queried by whom, and how often. Those are engineering and procurement decisions, and they are being made now, mostly by two companies.

Read the holding narrowly, because it is narrow. This was a case about material obscene to minors, and the Court reasoned by analogy to buying alcohol or a firearm. It is not a ruling that the internet may be identity-checked in general, and anyone telling you it is has skipped the opinion. What makes it matter here is the architecture built on top of it, not the holding itself.

Four different techniques, four different costs

This is where most writing on the subject falls apart, so slow down. "Age verification" covers at least four techniques with completely different consequences.

  • Age estimation. A model looks at your face through the camera and guesses a range. No document, no name. It is also the least accurate, and it fails unevenly across ages and skin tones.
  • Document verification. You photograph a passport or driving licence and upload it, usually with a selfie. This is the one people picture, and the one that creates a database of identity documents.
  • Third-party attestation. A bank, mobile carrier or credit card confirms you are an adult without the site seeing why.
  • Cryptographic proof. Your device answers a yes or no question about you and reveals nothing else. This is the best available design, and the European Union has built it.

A page that treats these as one thing gets the story wrong. The interesting finding is not about which one is worst, but that the best design and the worst end up converging.

Texas and Utah moved the check into the operating system

Verifying age site by site is expensive, unpopular and easy to route around. The obvious fix is to do it once, somewhere upstream, and let everything else ask. In 2025 Utah and Texas wrote that idea into law.

Texas SB 2420, the App Store Accountability Act, was signed on 27 May 2025. It requires app store operators to verify a user's age at account creation and sort every account into one of four brackets: under 13, 13 to 15, 16 to 17, and 18 or older. Accounts belonging to minors must be linked to a verified parent, and that parent must consent before an app is downloaded or a purchase is made. The age and consent signals are passed through to developers.

Utah's version was signed first, taking effect 7 May 2025, with the obligations on app stores and developers arriving 6 May 2026 and enforcement from 31 December 2026. Louisiana follows on 1 July 2026.

Note what changed. The law's subject shifted from the website that publishes something to the store that installs everything.

"A court blocked it, so it is not really happening."
It is happening

A federal district court did block SB 2420. On 23 December 2025 it granted a preliminary injunction, holding that the law triggers strict scrutiny and fails it. On the merits, so far, the challengers have won.

Texas moved for a stay. The Fifth Circuit granted it on 4 June 2026, finding Texas likely to succeed on appeal, which put the law into force. The industry went to the Supreme Court on an emergency application. On 6 July 2026 the Court declined to intervene.

So the position today is that a law a federal judge found unconstitutional is being complied with by Apple and Google while the appeal is heard. Compliance is not reversible in any practical sense. The verification infrastructure is being built now, and it will still exist whatever the Fifth Circuit decides.

What Apple and Google actually built

Apple's answer is the Declared Age Range API, introduced in iOS 26. An app asks, and the system returns a bracket: under 13, 13 to 15, or 16 and older. The birth date itself never leaves Apple. For children in Family Sharing a guardian sets the range; adults set their own. Every user picks Always Share, Ask First, or Don't Share.

That is good design, full stop. Ranges instead of dates, resolved on the device, disclosure under the user's control, no document anywhere in the flow. It is close to what someone who cared about privacy would draw on a whiteboard. Google's equivalent, the Play Age Signals API, passes developers an age range and supervision status rather than an identity.

Now hold that against what Texas requires, because the two do not meet.

Declared is not verified.
The gap is where the ID enters

Apple is explicit that the Declared Age Range API cannot stop someone entering a false age in their Apple Account, and that it exists to tailor content rather than to gate adult material. It is a declaration. It carries no proof.

SB 2420 does not ask for a declaration. It requires the store to verify the age, and to verify that a consenting parent is who they say they are.

A declaration cannot satisfy a verification requirement. Something has to close that gap, and there are only so many things it can be: a document, a face scan, a credit card, or a carrier check. That gap is where the identity document enters the operating system.

Neither company's public documentation states which method it uses, or how long anything collected is kept. Google's developer page says only that Play "will require age verification in accordance with that specific state's effective legal date." Apple's most recent public notice on Texas says it paused work during the injunction, which the Fifth Circuit stay has since overtaken.

Better to state that silence as a fact than fill it with a guess. Two companies are about to hold a verified age attribute, and in some cases a verified parent-child relationship, for a large share of the population of several countries. Neither has published what they collect to establish it or how long they retain it. The question is answerable only by them.

Britain already ran the experiment

The United Kingdom did not wait. Age checks under the Online Safety Act went live on 25 July 2025, with Ofcom accepting facial age estimation, photo ID matching, credit card checks and mobile network operator checks. Verification happens at each service, which means the document goes to each service.

The public response was immediate and very large. Proton reported UK VPN signups up 1,400% within minutes of the deadline, sustained between 1,400 and 1,800% daily, a level the company described as one "usually associated with civil unrest." NordVPN reported roughly 1,000%.

The government's response to that is the part to pay attention to. The Technology Secretary told Parliament that ministers "will therefore not age-gate or ban" VPNs, and that platforms are expected to detect and prevent circumvention themselves. Read that as an engineering instruction rather than a political one: the burden of defeating evasion moves to the platforms, and the way a platform defeats evasion is by identifying users more confidently. The pressure runs one direction.

Then, on 3 October 2025, the predictable thing happened.

"If you have nothing to hide, uploading an ID costs you nothing."
It cost about 70,000 people their passports

Attackers reached a third-party vendor used by Discord and took government identity photographs. Discord confirmed roughly 70,000 users were affected. The attackers claimed far more, around 2.1 million ID images across 8.4 million support tickets, and that larger figure is their assertion rather than a confirmed one.

The detail that matters is what the breached system was for. It was the queue that handled age-verification appeals. It existed because of age verification, held identity documents because of age verification, and was worth attacking for exactly that reason.

You cannot lose a document you were never asked to hand over. Every verification scheme that collects one creates a target that did not previously exist, at a company that is not in the identity business and did not want to be.

Europe built the good version

If the whole argument were that age verification means uploading your ID, Europe would refute it. Their design really is better, so grant it in full first.

The Commission published the second version of its Age Verification Blueprint on 10 October 2025. It lets you prove you are over 18, 15 or 13 without handing any personal data to the platform asking. The check is a cryptographic yes or no, computed on your device, and no identifying information leaves the phone. It runs as a "mini-wallet" on the same standards as the eIDAS 2.0 European Digital Identity Wallet, and the specification is public. Italy, France, Denmark and Spain are piloting it against their national identity systems.

The site the user visits learns one bit. Not a name, not a birth date, not a document number, not even a persistent identifier it could use to recognise the same person twice. This is close to the best that can be done.

Now the question that matters most. Where does the wallet get its confidence?

Onboarding uses passports and national identity cards.
The document did not disappear. It moved.

To hold a credential that can vouch for your age, the wallet has to be told your age by something authoritative. In the blueprint, that is your passport or national ID card, read once at setup.

After that the ID upload never happens again, which is a real improvement over Britain. But you did not prove your identity to nobody. You proved it once, permanently, to your device, which now carries a credential that answers questions about you indefinitely. Member States must offer every resident a wallet by the end of 2026.

Europe removed the leak and kept the identity layer. That is the best case, honestly engineered, by people trying to protect users. It still ends with your phone holding your papers.

This stopped being about one kind of website

It would be reasonable to read everything above as a fight about adult content that got out of hand. The dates say otherwise. Apple's own developer documentation lists when the same age machinery switches on by jurisdiction:

Jurisdictions where Apple applies age assurance requirements, with dates, from Apple developer documentation.
Jurisdiction Applies from What it does
Brazil24 February 2026Age category shared through the Declared Age Range API, plus a signal describing which assurance method was used.
Australia24 February 2026The App Store confirms adulthood automatically and blocks downloads of 18+ apps otherwise.
Singapore24 February 2026Same as Australia.
Utah6 May 2026Applies to new Apple Accounts. Enforcement provisions from 31 December 2026.
Louisiana1 July 2026Applies to new Apple Accounts.
TexasIn force since 4 June 2026Verified age at account creation, four brackets, verified parent and consent for minors, signals passed to developers.

Three countries on three continents, none of them party to the American litigation, switching on the same operating-system machinery in the same month. Whatever this started as, it is now a default property of the platform rather than a rule about a category of website.

Which puts it exactly where our page on your phone says the unfixable problems live. A content blocker cannot reach it. A VPN cannot reach it. It is not in the browser, it is not in an app, and there is no setting because it is a property of the account the device is signed into. The one identity claim the operating system holds about you is now, in an increasing number of countries, a legally mandated one.

What actually changes things

The honest reading is that the argument about whether adults can be made to verify is over, and was lost. What remains open is the part nobody litigated, which is the part that determines the damage.

  • Method is everything, and it is a policy choice. The gap between a face scan that returns a range and a passport photograph sitting in a vendor's ticket queue is the entire difference between these systems. No court has ruled on it. It is decided in procurement and in implementing regulations, which is where it can still be argued.
  • Ask what is retained, because nobody has said. Apple and Google are about to hold verified age, and in some cases verified family relationships, across whole populations. Neither has published a retention period. That is a question a legislator or a regulator can compel an answer to, and an ordinary person cannot.
  • Europe already wrote the good specification and published it. Any argument that privacy-preserving age assurance is impractical is now answerable with a working implementation and a public technical standard. Deployment is the argument, not feasibility.
  • Watch the account, not the website. The meaningful line is whether a verified identity attribute may be reused for anything beyond the check that justified it. Once the operating system holds a proven fact about you, every other product in that company's catalogue is one policy change away from being able to read it.

The thing to hold on to is that none of this required anybody to act in bad faith. Britain chose the worst mechanism and got a breach. Texas chose the most centralised one and is running it under a stay of an injunction it lost on the merits. Europe chose the best one available and built it carefully. All three arrive at a device that carries a permanent, verified claim about who you are, because that is what the requirement produces once you take it seriously. The question was never whether they would collect your ID, but what your phone becomes after you prove it once.