Age assurance is where two regulatory currents collide head-on: one set of laws demands you know who is a child, another punishes you for collecting what it takes to find out. Paxton settled that hard verification mandates can stand, and the state legislative wave is building on it, but the engineering truth has not moved: the best systems prove age while learning almost nothing, estimation over documents, tokens over IDs, deletion over retention. A neutral screen still carries COPPA’s mixed-audience load; a token architecture carries the mandates coming after it. The services that will regret this decade are the ones warehousing ID scans next to browsing histories, and the leaks have already begun scoring that bet.
| Spectrum | Self-declaration → estimation → documents/database → tokens |
|---|---|
| COPPA floor | Neutral screen, no falsification prompts, retry blocking |
| Paxton (2025) | ID verification for adult content upheld (intermediate scrutiny) |
| Privacy stack | BIPA, sensitive-data rules, COPPA retention, breach exposure |
| Design rule | Strictest legal minimum, least-collecting method, retain nothing |
Engineering proportionate assurance
Fix the neutral screen first. Free-entry DOB, no hints, retry blocking; it carries COPPA mixed-audience compliance and costs a sprint.
Prefer tokens and estimation to ID warehouses. Third-party pass/fail attestations satisfy hard mandates while minimizing the biometric and breach surface; state-law variation determines where each is enough.
Treat the verifier as a critical vendor. Retention bans, deletion attestations, and breach terms in the contract; their leak is your notification.
Document the proportionality analysis. Method choice is the first question after any incident; safe harbor programs will audit it, and school deployments add FERPA/CIPA constraints.
Age gates sit on pages that already run trackers: see what fires before the gate with a free scan.