What I Learned Building Age Verification for a Platform With a Billion Users

A pile of ID cards and people being crowded into a pen with London landmarks

A few years ago I sat in a room where a small group of people decided how a platform with over a billion users would try to figure out who was too young to be there. I helped build that system. It is a strange thing to be in that room, watching smart, well-intentioned people try to solve a problem that has no clean solution, using tools that were never built for it. I came away understanding, in granular detail, how age verification actually works day to day. Most of the people writing laws that require it don’t. I don’t think what I saw should reassure anyone. I also don’t think the alternatives being proposed are much better, including, in some ways, my own.

Here’s what that machinery actually looks like. Some of it is flimsier than most of this debate assumes.

The wave

Age verification exists, originally, to keep minors away from pornography. That’s the narrow case most of these laws started from. But as concern shifted toward social media generally, the same requirement got extended to any platform hosting user-generated content, whether or not it has anything to do with adult material. The EU has moved to restrict social media access for younger teens. Australia’s blanket ban on social media for under-16s has been in force for close to a year. At least twenty US states have now passed laws specifically targeting minors’ social media access, on top of the roughly half the country that already requires age verification for adult content, with enforcement status varying widely as courts sort out which provisions survive. At the end of June, the House passed the Kids Internet and Digital Safety Act, the latest attempt at a federal version. Days later, a Pew Research Center survey found more than half of US respondents in favor of banning social media outright for anyone under 16. Some states are now pushing verification up a level entirely, requiring app stores themselves to verify age and pass that signal down to every app on the device, turning a single-platform gate into a device-wide one. Whatever you think of any single bill, the direction isn’t in question: verification is being written into law faster than anyone is checking whether it works.

What “keeping kids off” actually requires

Compliance with a law like this usually isn’t one verification prompt at the door. Legal trackers that follow this space describe a common shape: enforcement built around where an account is registered, not where someone happens to be sitting, plus notification flows and appeal paths for accounts flagged incorrectly. None of that requires a document upload by default.

Most accounts get cleared automatically through inference: account tenure, device signals, activity patterns, no documents involved. Only the accounts that can’t be resolved that way, or that get flagged and appealed, are routed to a heavier check. Discord’s public rollout of its own age-assurance system works this way, and it shows why that heavier track matters more than its size suggests. The menu at that point is thin: essentially a government ID, a credit card authorization, or a face scan, nothing lighter in between. That’s exactly where things went wrong last October, when a breach at a third-party support vendor exposed the government-ID photos of roughly seventy thousand Discord users who had gone through it. That’s the part regulators should worry about more than they seem to: the riskiest piece of the system is also the piece most bills mandate outright, since “verify with a government ID” is the easiest line to write into a statute.

The math nobody says out loud

These laws are written around the minors they’re meant to keep out. The burden of proving that falls almost entirely on adults, for the simple reason that there are far more adults than minors on any large platform, the same way there are far more adults than minors in the population at large. At the company with over a billion users where I worked on this exact problem, we noticed that roughly 94 percent of accounts never posted anything at all. They read, watched, and scrolled. That’s not unusual; researchers studying online participation have documented some version of the same pattern for two decades. It means the overwhelming majority of people a verification system touches were never the population these laws worry about. They’re adults who wanted to read something, and got asked to hand over a government ID or a credit card to prove they’re not a teenager, for content that was never age-restricted to begin with.

Multiply that across every platform now subject to these laws and you get a number that should be central to this debate and almost never is: hundreds of millions of adults exposing their most sensitive documents to solve a problem most of them could never have been part of.

Who actually gets caught by this

That cost isn’t evenly distributed, either. Someone with a compatible smartphone, a current ID that matches their legal name and photo, and nothing complicated about their identity clears most of these gates with some friction and moves on. That describes a lot of people. It doesn’t describe everyone.

It doesn’t describe undocumented immigrants, who might not have a government ID a verification system will accept. It doesn’t describe trans people whose ID hasn’t caught up to their transition, a mismatch that can trigger manual review or outright rejection. It doesn’t describe domestic violence survivors, who have specific, well-founded reasons to avoid tying a real identity to an account they’re using to seek help or stay hidden. It doesn’t describe older adults without a compatible device, or anyone whose ID photo is a decade old and no longer matches their face well enough for a scanner.

For all of these people, the cost of age verification isn’t friction. It’s exclusion, sometimes from services that have nothing to do with the harm the law was written to prevent.

Enforcement numbers nobody can actually vouch for

Platforms pushing back on these mandates like to cite their own enforcement numbers as proof they don’t need more regulation. TikTok reports removing tens of millions of suspected underage accounts a year, a number that’s climbed steadily since the company started disclosing it, and Meta’s own child-safety disclosures show the same basic pattern on Instagram and Facebook: enforcement totals that keep climbing each time the company reports them. On its face, that looks like progress. But a rising removal number is genuinely ambiguous. It’s equally consistent with better detection, a growing underage population, or both. Nobody outside the company can tell which. The accounts a platform catches are, by construction, the only accounts it can count. The ones that got through are invisible in its own data.

That ambiguity would matter less if there were strong outside evidence either way. There is, and it isn’t encouraging. A University of Newcastle study published in the British Medical Journal tracked Australian teenagers before and after the country’s under-16 ban took effect, and found more than 85 percent of them were still using restricted platforms three months in, most through their own accounts rather than workarounds. That’s not a leaky verification regime with obvious workarounds. That’s a blanket legal prohibition, in a country with real political will to enforce it, and it’s barely dented access. If a hard ban with a year of enforcement can’t move that number, a bolted-on verification requirement isn’t likely to do better. The platforms can’t prove their system works. The one government that tried the blunt version can’t either.

What a narrower fix looks like, and its limits

What led me to start a company was simpler than any one story: it felt obvious that the vast majority of people hitting these gates were adults, and that proving you’re probably not a child shouldn’t require the same heavy, document-based process built for proving exactly who you are. Adults were paying a real cost in their own personal information for a problem that was never theirs, which is why I named my company notmypii. The idea behind the product is narrow: instead of asking someone to prove who they are, ask for a signal that they’re probably an adult. In our case, that’s a confidence score derived from a wearable’s heart signal, which changes in measurable, age-correlated ways across adolescence, without collecting or storing identity data at all. Dr. Azfar Adib, a researcher I’ve followed closely and traded ideas with on this exact problem, believes a better path forward could be leveraging data from smartwatches to provide age assurance, and has published peer-reviewed research on the idea. That’s a real signal, not a novelty.

It’s still a gate. And it doesn’t touch the deeper argument this publication has made consistently, that verifying anyone at all, by any method, builds infrastructure that tends to outlive the problem it was built for. A friendlier gate is still a gate. If gating shouldn’t exist at all, a cheaper gate doesn’t fix that. It just makes the version we’re stuck with, if we’re stuck with one, less damaging.

A structural alternative worth naming

A better gate isn’t the only idea worth taking seriously here, and this is one I find interesting. The Verge’s Adi Robertson recently proposed something structurally different: fund a “children’s public internet” through a tax on major tech companies, directed at nonprofit, non-commercial platforms built for kids, things like moderated forums, ad-free educational sites, and open alternatives to existing products, run by libraries, schools, or community groups. None of that requires an age gate at all. A space built for kids from the start doesn’t need to verify anyone’s age to keep working the way it’s supposed to. The appeal is that it doesn’t ask anyone to prove anything. It tries to make the destination better instead of making the door harder to open. It has its own open questions: who administers it, who qualifies, how it’s evaluated. But it’s a genuinely different axis of solution than anything verification-based, mine included, and it deserves more attention than it’s gotten.

Close

Nobody has a full answer here, and I’d be skeptical of anyone, including people in my position, who claims otherwise. What I do think is demonstrable: this wave of legislation imposes its heaviest cost on people the laws were never intended to affect. The enforcement claims underpinning it can’t be verified by the platforms making them. And the one large-scale real-world test we have suggests it isn’t working the way its proponents assume. The next law like this should have to clear a lower bar than it does today: show it actually works before it gets written into statute. So far, almost nobody’s been asked to.


Kyle Huscher is the founder of notmypii, a privacy-preserving age-assurance alternative to traditional legacy methods.

Oh hi there 👋
It’s nice to meet you.

Sign up to receive notifications of our new blog posts in your inbox.

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *