Skip to content

Power

Age-Verification Laws Let Vendors Decide Who Counts as 18

US laws increasingly demand proof that a visitor is an adult without prescribing the proof. The real rules are being written inside face scans, ID checks and age tokens.

Lena VasquezPower — Courts & Policy

August 15, 2026 · 8 min read

A phone displaying an age-check oval beside a closed passport and laptop on an ordinary desk.

The concrete object in this policy fight is an oval on a phone screen.

In Yoti’s facial age-estimation flow, a user gives the camera access and positions their face inside a guide. Software analyzes the image and returns an estimated age. Yoti says its system estimates age rather than identifying the person, and that the captured image is deleted after the check. For a website trying to comply with an age law, the attraction is obvious: no driver’s license, no typed birthday, no account that openly follows the visitor into the site.

The oval looks like the least invasive option. It is also where a political command becomes a private statistical judgment.

A legislature can write “18 or older.” A facial model cannot see a legal birthday. It produces an estimate, usually with a confidence range and a known possibility of error, after which someone must decide how much uncertainty the website will tolerate. If the estimated age lands close to 18, the vendor or site can reject the visitor, request another method or apply a buffer that effectively makes the gate older than the law does.

That decision is policy. It arrives disguised as product configuration.

The law demands a result, not a measuring instrument

The current US push is led largely by state laws covering pornography and other material deemed harmful to minors. Texas’s law, known as HB 1181, requires covered commercial sites to use a reasonable method to verify that visitors are adults. In June 2025, the US Supreme Court upheld the age-verification requirement against a facial challenge in Free Speech Coalition v. Paxton, concluding that the burden on adults could be reviewed under intermediate scrutiny rather than the more demanding standard sought by the challengers.

That holding matters. It gives states more room to impose age checks around sexual content, and lower courts must follow the Supreme Court’s legal framework. It does not approve every age-checking design, settle every privacy claim or compel a particular website to hire Yoti, Persona, Veriff or another provider. Other state laws differ, litigation continues, and enforcement details remain jurisdiction-specific.

The gap is the point. Lawmakers can demand “reasonable age verification” while leaving the operational meaning of reasonable to websites and the companies selling compliance. Legislatures avoid selecting a technical system that may age badly or produce an obvious privacy scandal. Sites get flexibility.

Vendors get a market created by legal obligation.

The visitor gets the oval.

A covered site generally wants four things from that oval: a quick answer, low abandonment, enough documentation to satisfy an enforcement inquiry and as little liability as possible if the answer is wrong. The safest commercial setting may therefore be stricter than the legal boundary. A false adult, meaning a minor incorrectly allowed through, threatens regulatory exposure. A false minor usually costs the site one frustrated adult.

Those errors do not carry equal weight in the buyer’s spreadsheet. The model can be tuned accordingly.

A face scan estimates, then somebody chooses the margin

Facial age estimation uses patterns in an image to predict an age or age range. It differs from facial recognition, which tries to match a face to a known identity, although both depend on biometric analysis and both ask the user to trust claims about collection, deletion and downstream access.

No model estimates every face with equal precision. Lighting and camera quality matter. So do the examples used to build and test the model. Vendors publish accuracy material, often broken out by age bands and demographic categories, while the National Institute of Standards and Technology evaluates age-estimation systems under controlled conditions.

Those reports can describe average error. They cannot decide what a particular website should do with a 19-year-old whom the model reads as 17, or a 16-year-old it reads as 19.

Near the threshold, uncertainty becomes expensive. A vendor can recommend an age buffer, route borderline users to a second method or let the customer set a risk level. The website may formally own the final setting, but the vendor has designed the menu, measured the model and framed which tradeoff counts as prudent. “18” enters the system as law.

It exits as an estimated age plus a commercial tolerance for mistakes.

This is why the oval should not be mistaken for a neutral camera tool. It contains a hidden appeals process. People who look older may pass without disclosing a name. People whom the model places too close to the line may have to produce identification, even though both visitors are legally the same age.

The privacy-friendly route becomes conditional on how machine-readable your adulthood appears.

Document checks exchange uncertainty for identity

A document check appears more definite because a driver’s license or passport contains a date of birth. Depending on the provider and customer settings, the user photographs the document, software checks security features or database consistency, and a selfie may be compared with the portrait on the ID. A liveness check, meaning a test intended to show that the camera is seeing a present person rather than a static image, may be added.

This method answers a different question. Facial estimation asks whether this person appears old enough. A document check asks whether the submitted credential looks valid and, if identity matching is enabled, whether the person holding it resembles the credential holder.

The added certainty carries more data. The image may expose a legal name, home address, document number, photograph and exact birthday even when the website only needs a yes-or-no answer about adulthood. Vendors can minimize what they return to the site, and some promise short retention or deletion, but the user must still rely on the vendor’s architecture, contracts and security practices. A privacy notice is not a force field.

Document checks also make access depend on possession. Adults without current government identification, people whose documents are damaged, visitors using unsupported credentials and users whose current appearance differs from an old photo can be pushed into manual review or locked out. The website has complied by moving the difficult cases somewhere less visible.

The incentive again favors rejection. A vendor paid to help a client survive regulatory scrutiny has little reason to wave through a doubtful document. False negatives create customer-service costs. False positives can become evidence.

Third-party attestations move the checkpoint upstream

A third-party attestation lets another organization vouch for an age fact without handing the destination site a full ID. The attestor might be a digital identity service, a mobile carrier, a financial institution, an app store or another platform that already has age-related information. It can return an age band or a statement that the user is over 18.

This can reduce repeated uploads. It can also make the underlying surveillance harder to see.

The destination website learns less, but the attestor may learn that its customer requested an age credential, when the request occurred and which service received it. Technical designs can limit that disclosure. A zero-knowledge proof, a cryptographic method that proves a fact without revealing the underlying data, could confirm adulthood without disclosing a birthday. Yet even a strong proof inherits the issuer’s original judgment.

If the account age came from self-declaration, family settings, payment history or an earlier ID check, that evidence determines who receives the adult token.

Age signals also go stale. Accounts are shared. Parents configure devices for children, and adults use family plans or managed hardware. A person can cross the legal threshold while an old age band remains attached to the account.

The apparent simplicity of “verified by another service” conceals another classification system with its own correction procedure, retention rules and commercial relationships.

For large platforms, this upstream model has strategic value. Apple, Google and other operating-system gatekeepers already sit between users and apps, so age-range tools can turn their existing account infrastructure into compliance infrastructure. Smaller websites may disclose less sensitive data themselves, but they become dependent on a handful of companies to issue adulthood in a format regulators and vendors accept.

The checkpoint has not disappeared. It has moved into the device.

The compliance market rewards friction that looks defensible

Age-assurance companies sell risk management. Websites pay through contracts or per-check arrangements, while the legal mandate supplies demand that ordinary consumers did not create. More laws mean more checks. More ambiguity means more consulting, fallback routes and audit records.

The vendor therefore occupies an unusual role. It is not the legislature, which sets the age. It is not the website, which chooses whether to operate in a state and selects a provider. It is not the court, which decides whether a legal burden is constitutional.

Yet its model thresholds, accepted documents, retention design and failure handling determine whether an adult reaches the page.

Pornhub and some other adult sites have responded to state requirements by blocking access from affected jurisdictions rather than implementing the mandated checks. That is also an age-assurance outcome: when compliance costs, privacy concerns or legal exposure exceed the value of serving a market, everyone in that location can be treated as unauthorized. The bluntest classifier is a state boundary inferred from an internet connection.

Better rules would specify data minimization, deletion, independent testing, accessible alternatives and a meaningful route for adults who fail an automated check. They would also separate proof of age from proof of identity wherever possible. Without those constraints, “verify age” remains an instruction to buy a private gate and trust whichever errors its seller has priced as acceptable.

Return to the oval. It does not show the confidence interval, the client’s risk setting or the fallback that appears after a rejection. It shows your face and a boundary. The law supplied the number 18.

The vendor built everything that decides whether you look like it.

Questions people ask

Do age-verification laws require people to upload an ID?

Not always. Many laws permit several reasonable methods, which may include facial age estimation, government-document checks or confirmation from another service. The available choice depends on the website and its vendor, so a law that is technically method-neutral can still leave an individual with ID upload as the only fallback after another check fails.

Is facial age estimation the same as facial recognition?

No. Age estimation predicts an age or range from facial features, while recognition tries to identify or match a person. Both analyze biometric information, however, and users still depend on the provider’s claims about image deletion, retention, security and whether the image is used for any purpose beyond the immediate check.

Who decides the margin for error around age 18?

The law establishes the legal threshold, but vendors and websites implement it. A provider’s model generates an estimate, then product settings determine whether borderline results pass, fail or trigger another method. Regulators and courts can later judge whether the arrangement complies, but they do not make the initial decision at the screen.

Can a website verify adulthood without learning someone’s identity?

Yes. An age estimate or cryptographic age credential can return an over-18 result without sending the destination a name or exact birthday. That reduces disclosure to the website, but it does not remove trust: the user still relies on whoever estimated, issued or transmitted the age result.

Was this worth your time?
ShareFacebook
internet policysurveillanceage verificationbiometricsdigital identityprivacy

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next