# Age assurance is coming for the internet

> Australia banned under-16s from social media. The EU wants age checks on "every" account. The UK already fines platforms that guess. If you run a Moodle site, a training portal or any platform a child might touch, this is aimed at you too, and the smart move is not to build an identity gate you don't need.

## The number that isn't the story

When Australia's under-16 social media ban took effect on 10 December 2025, it became the first nationwide restriction of its kind, with penalties for platforms that fail to keep minors off their services reaching AUD 49.5 million. Five more countries have since adopted similar measures and roughly two dozen, including the UK, France and Canada, are considering them.

The number everyone repeated was 16. The number that actually reshapes the web is a different word: **every**. When the European Commission published its KIDS Act proposal on 17 September 2026, the obligation was not to check the age of children. It was to verify age whenever a new account is opened, which means every user, adult included, has to prove something about themselves just to sign up.

That is a much bigger deal than a ban on teenagers, and it explains why the fight over age assurance has become a fight about the open web.

## What the laws actually require

The rules differ by country, and a growing share of them are stuck in court. But the shape is consistent enough to plan around.

In the **EU**, the proposed KIDS Act targets what it calls "Social Media+": social networks, video-sharing platforms, online games, AI chatbots and companions, and even app stores. Age is meant to be verified through **certified solutions**, independent of the platforms themselves, including a free EU age verification app and, in time, the European Digital Identity Wallet. Self-declaration is explicitly ruled out as a method, and the largest platforms have to submit compliance plans checked by independent auditors.

In the **UK**, the Online Safety Act has been enforcing "**highly effective age assurance**" since July 2025. The bar is specific: a method must be technically accurate, robust, reliable and fair, and it must also be easy to use and work for all users. Self-declaration is not enough, and the UK regulator has said that profiling-based guesses are not enough either. Fines can reach 10% of qualifying worldwide revenue. The effect is measurable: across a sample of 32 services, more than 69 million age checks were completed in the second half of 2025, a 23-fold increase over the previous six months.

In the **United States**, 27 states now require age verification for adult sites, several have passed Age-Appropriate Design Codes that force "safe for minors" defaults, and a newer wave targets the operating system itself: from January 2027, laws in California and elsewhere will require age signals to be provided at the OS level, so platforms increasingly receive an age band without asking for it.

None of this is settled law everywhere, and much of it is being challenged on free-speech grounds. That uncertainty is exactly why it is worth understanding the mechanism now, rather than after it lands in your inbox as a compliance request.

## Why a learning platform is not off the hook

You are probably not the target. Much of this legislation is aimed at social media and adult content, and some bills explicitly carve out educational institutions and non-profits. But three ripples reach any platform a minor might plausibly use.

**First, self-declaration is dead as an idea.** The "are you over 13?" dropdown was always security theatre, and regulators have now said so in writing. Whatever you build next should assume that a date of birth typed by the user is worth nothing on its own.

**Second, age is becoming a signal you receive whether you asked or not.** Once operating systems start broadcasting age bands, your platform will get age data it never collected. You will have to decide what to do with it: ignore it, use it for safety defaults, or use it to gate content. Doing nothing is a decision too.

**Third, age-appropriate design duties do not care about your category.** The US state design codes apply to services "reasonably likely to be accessed by minors", not just social networks. That covers high-privacy defaults, no dark patterns, limits on overnight notifications, and, importantly, **graduated** treatment: not a binary adult/minor flag, but bands such as under-13, 13 to 15, 16 to 17 and adult. A learning platform with school-age users is squarely in that conversation.

And if you gate anything by age on purpose, whether it is regulated training, a certification, or content that simply is not for everyone, you are now measured against a real standard rather than a checkbox.

## Verification, estimation, inference

Most of the public argument collapses three different things into one word. They are not the same.

- **Verification** confirms a claimed age against authoritative evidence: a passport, a bank record, a wallet credential.
- **Estimation** infers an age range from a face, with no document and no identity.
- **Inference** deduces age from behavioural signals, with no image at all.

Regulators keep a short list of methods that can clear a high bar: ID document checks, facial age estimation, credit-card or Open Banking checks, mobile network operator lookups, and digital identity credentials. Self-declaration never does.

The sensible architecture is a **waterfall**: start with the least intrusive check, and step up only when the risk justifies it. Estimate first; if the person lands near the boundary, ask for something stronger. Crucially, a well-designed flow can confirm someone is over a threshold **without collecting or storing their identity**. That is the whole point of the newer wallet-based approaches: prove "over 18" cryptographically and reveal nothing else.

## The trap: do not build an identity gate you do not need

Every identity document you collect is a liability. It is a honeypot, a data-protection obligation, and a breach waiting to happen. Privacy advocates have hammered this for years, and they are right about the failure mode: the quickest way to "protect children online" is also the quickest way to build a surveillance database that leaks.

So the practical question is not "how do I verify everyone". It is **"what do I actually need to know, and what is the lightest way to know it?"** For most learning platforms, the honest answer is that you need to know whether minors are plausibly among your users, and to behave accordingly, not to identify every learner.

If, and only if, a specific piece of content genuinely needs a hard age gate, then gate **that content**, not the whole site, and prefer methods that never store an identity. When the check really does call for a document, reading the machine-readable zone is a solved problem: it is standard OCR on a fixed strip of text, and there are open libraries for it, including [one we maintain ourselves](/software/ocrideu/). Even then, the rule is to read the age signal and discard the document, immediately.

## A short checklist

- Decide honestly whether minors are likely to use your platform. If the answer is yes, design for it now.
- Assume self-declaration is worthless. It is, and regulators have said so.
- If minors are present, use graduated age bands and safe defaults rather than one blunt switch.
- Gate specific content, not entire platforms, and use a waterfall of checks.
- Prefer methods that produce an age signal and never store an identity.
- Keep records of the decisions you made and the methods you use. Enforcement asks for evidence, not intentions.
- Watch the operating-system age signals arriving in 2027. They will change what your platform knows by default.

## The direction of travel

The specifics will keep moving, and a good chunk of today's rules will be rewritten in court. But the direction is stable and worth building against: platforms are expected to know roughly how old their users are, to protect minors by default, and to do it **without hoarding identity**. That expectation started with social media. It is already spreading to anything a child might open, and a learning platform is exactly the kind of thing a child opens.

Getting ahead of it is not about buying an age-verification vendor today. It is about making sure that when the request arrives, you have a clear answer to three questions: who is plausibly on your platform, what you actually need to know about them, and how little you can collect while still doing the right thing.
