Skip to content

Power

An 18+ Check Can Demand Your Face, ID and Device Data

Age-verification laws ask platforms to keep minors out. The identity vendors hired to do that can also scan documents, analyze devices and assign fraud risk.

Simone AchebePower — Surveillance

August 12, 2026 · 8 min read

A phone displaying an over-18 verification prompt beside a closed wallet and government ID card.

The prompt that appeared between Louisiana users and Pornhub in 2023 did not begin with a camera. It handed the user to LA Wallet, the state-backed digital driver’s-license app, to confirm that the license holder was over 18.

That distinction matters. LA Wallet already held the credential, and the age-checking system was designed to return an age status rather than a copy of every field printed on the license. The website needed an answer. It did not need a home address, exact birthday or new photograph.

The prompt still asked users to connect sexual browsing with a government-issued credential. Pornhub’s operator said it did not receive identifying data through the check, but many users had no independent way to inspect the exchange or confirm which logs existed around it. Trust had been moved from an adult site to an identity app and the contractors behind the transaction. It had not been removed.

That LA Wallet handoff is a useful baseline because it shows the narrow version of an age gate: a credential holder presents a limited claim, the service receives an over-or-under answer, and access follows. Across the growing age-assurance market, the same legal demand can produce a much larger collection event.

The law asks for an outcome

Louisiana’s law required covered adult sites to use reasonable age verification. It allowed digitized identification, government-issued identification and commercially reasonable systems drawing on public or private transactional data. It also prohibited the commercial entity or its verifying third party from retaining identifying information after access had been granted.

Texas adopted a similar structure. Its law named digital identification, government ID and systems using transactional data as possible routes, while restricting retention of identifying information. After years of litigation over adult-content restrictions, the US Supreme Court upheld the Texas requirement in 2025 in Free Speech Coalition v. Paxton.

Neither state law orders every user to submit a fresh face scan. Neither requires a vendor to build a device fingerprint, a bundle of browser and hardware signals used to recognize a device across attempts. The statutes create an obligation to verify age, describe acceptable methods and place some limits around identifying data. Platforms choose the implementation.

The United Kingdom makes the separation even clearer. Under the Online Safety Act, Ofcom requires services hosting pornography to use age assurance that is highly effective. Its guidance discusses methods including photo-ID matching, facial age estimation, mobile-network checks, credit-card checks, open banking and digital identity services. Ofcom sets a performance standard.

It does not prescribe one universal packet of personal data.

The platform therefore faces a procurement decision disguised as compliance. It can accept an age signal from a trusted issuer, ask a vendor to estimate age from a selfie, match a face to an identity document, or query records associated with a name and address. Each route answers the legal demand. They do not create the same surveillance system.

The age gate arrives inside an identity stack

Many age-verification companies did not start with a single over-18 button. They sell identity infrastructure to banks, marketplaces, delivery services, dating apps and cryptocurrency companies, where customers also want to catch forged documents, repeated accounts, payment abuse and sanctioned users.

Public documentation from vendors such as Persona and Entrust describes modular workflows that can combine document inspection, selfie matching, database checks, device intelligence and risk signals. A customer can turn modules on or off, set thresholds and route uncertain cases into manual review. The same dashboard that verifies a birthday can help decide whether a device, document or person looks suspicious.

This does not mean every vendor runs every check on every visitor. It means the capability sits nearby, often inside the same contract and software development kit. Once a platform has integrated an identity stack, adding another signal may require a configuration change rather than a new public debate.

The incentive is plain. A platform pays verification vendors through commercial contracts commonly priced around checks, volume or service tiers, while carrying the legal risk when minors get through and the operational cost when adults are wrongly blocked. Vendors compete on successful decisions, fraud detection and low abandonment. More signals can improve those measures, or at least give the buyer more reasons to believe they will.

That is how an age question becomes a risk file. A document image helps establish a birth date, but its security features can also be scored for signs of alteration. A selfie can support facial age estimation, which predicts an age range from an image, yet it can also be compared with the document portrait or checked against previous submissions. IP addresses, browser attributes and device data can reveal repeated attempts.

None of those secondary functions changes the legal age threshold. They change how confidently the vendor thinks it knows the person approaching it.

Fraud scoring is especially elastic. A score may combine signals such as document quality, network characteristics, device history and inconsistencies across a session, then reduce them to a label or number that determines whether the user passes, retries or reaches a human reviewer. The score is not proof of wrongdoing. It is a prediction produced under rules the user generally cannot see.

The LA Wallet prompt avoided much of this by beginning with a credential already issued by the state and returning a limited claim. A user without that credential, or in a jurisdiction without comparable infrastructure, is more likely to meet the vendor’s larger toolkit.

A deleted selfie is not the whole record

Facial age estimation is often marketed as the lighter alternative to uploading ID. Yoti, which supplies the technology to several services, says its system estimates age without identifying the person and deletes the facial image after producing the estimate. That is materially different from building a reusable face template for identification.

It is still a face measurement. The system must process the image, test whether it contains a live person rather than a replay or printed picture, and return an estimate with enough confidence for the platform’s threshold. Estimates can be wrong, with accuracy varying by age and demographic group, so borderline users may be pushed toward another method. The supposedly document-free route can end at a passport upload.

Deletion language also has boundaries. A promise to delete an image does not necessarily describe what happens to the transaction ID, pass-or-fail result, estimated age, IP address, device signals, risk flags, audit logs or records held by the platform rather than the vendor. Some of that information may be needed to secure the system, contest abuse or demonstrate compliance. Some may be retained because the customer selected a broader fraud product.

The legal roles vary by contract. A data controller, the organization deciding why and how personal data is used, may be the platform, while a verification company processes data on its instructions. A vendor can also have separate obligations or purposes. The privacy notice visible at the gate rarely lets a user reconstruct that allocation before deciding whether to continue.

State prohibitions on retaining identifying information sound decisive, but they leave hard classification work underneath. A deleted license image is easy to describe. A device fingerprint, confidence score or record that the same credential appeared before may not look like a name, though it can still distinguish one attempt from another and influence future access.

Minimal disclosure remains a choice

An age gate can disclose less. A digital credential can use selective disclosure, which reveals one attribute such as “over 18” without releasing the underlying birth date. Device operating systems, app stores and mobile carriers can also pass age-related signals, though centralizing age status with those companies creates its own tracking and exclusion risks.

No method removes trust. The useful test is whether each participant learns only what it needs for this transaction, whether the proof can be linked across services, and whether a person without conventional ID has another route. Those are design decisions. Calling the entire bundle “age assurance” does not make every field necessary.

The narrow LA Wallet response shows both the possibility and the unresolved problem. Pornhub could receive an age result without receiving a license copy, yet the user still had to place a state credential next to a private act, inside a chain of software that was easier to accept than to audit.

The law opened the gate. The market decided how much machinery to install around it.

Questions people ask

Do age-verification laws require a selfie or government ID?

Usually not as a universal rule. Laws may list government ID as one acceptable method while allowing digital credentials, database checks or other commercially reasonable systems. Facial age estimation is generally an implementation selected by a platform or vendor, not an inevitable legal command.

Can an age-verification company keep my document?

Retention depends on the jurisdiction, contract and stated purpose. Louisiana and Texas restrict retention of identifying information after access, while other regimes rely on broader privacy rules. A document may be deleted while transaction logs, risk signals or verification results remain under separate retention policies.

Is facial age estimation the same as facial recognition?

Not necessarily. Age estimation predicts an age range from a face, while facial recognition tries to identify someone or match them to another image. Both require processing a face, and an age-check workflow may add identity matching, liveness tests or device analysis even when the first step is described only as estimation.

Why do age gates collect device and fraud data?

Platforms buy age checks from identity vendors whose systems were built to detect forged documents, repeat accounts and suspicious sessions. Device signals and fraud scores help vendors manage those risks, but they go beyond establishing a birth threshold and can decide who receives access, another attempt or manual review.

Was this worth your time?
ShareFacebook
surveillanceinternet policyonline age verificationdigital identitybiometricsprivacy

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next