Three separate developments landed within days of each other, and together they sketch out where online age verification is headed in the United States and beyond. The Kids Online Safety Act (KOSA) has advanced to the Senate again, a New Mexico court has ordered Meta to pay another $567 million over harms to young users, and Illinois has moved to push age verification down to the device level rather than leaving it to individual apps and websites. Overseas, UK regulator Ofcom is scrutinizing TikTok's reliance on data-driven "age inference" rather than direct verification, a preview of the scrutiny US platforms may soon face too.

Taken individually, each story is a policy update. Taken together, they show a pattern: lawmakers, regulators, and courts are converging on the idea that platforms must know how old their users are, and increasingly, that this knowledge should live somewhere closer to the hardware itself. That shift has real consequences for anyone who values privacy, not just for minors the laws are meant to protect.

Three Fronts in the Same Fight

KOSA's return to the Senate is not its first trip through the legislative process. The bill has been advanced by a Senate panel before amid persistent warnings from civil liberties groups about free speech and privacy implications, and it has also cleared the Senate Commerce Committee alongside three other bills with bipartisan backing. Its reappearance signals that lawmakers remain determined to pass some version of child safety legislation, even as the underlying age verification questions remain unresolved.

Meanwhile, a New Mexico court has ordered Meta to pay $567 million, the latest in a string of penalties tied to the company's handling of young users on Instagram and Facebook. Fines of this size send a clear signal to every major platform: regulators and courts are willing to impose significant financial consequences when companies are found to have failed young users, and that pressure is pushing platforms toward more aggressive age-checking measures of their own.

Then there's Illinois, which is taking a structurally different approach. Rather than requiring each app or website to verify a user's age independently, the state is moving verification to the device level. In theory, this means a phone, tablet, or computer itself would carry some form of age credential that apps could check, rather than every platform collecting its own proof of age.

The Privacy Trade-Off Nobody's Talking About

Device-level verification sounds efficient on paper. Instead of uploading your ID to a dozen different apps, the device handles it once. But efficiency here comes with a catch: it centralizes sensitive data (your age, and potentially identity documents used to confirm it) in a way that could make devices themselves attractive targets for data collection, tracking, or breaches. It also raises the question of who controls that credential, how long it's retained, and whether it can be repurposed for tracking behavior beyond simple age confirmation.

This is the tension at the heart of the age verification push. Child safety advocates argue platforms need real proof of age to keep minors away from harmful content. Privacy advocates counter that verification systems, however well-intentioned, tend to normalize the collection of identity data and behavioral tracking well beyond their original purpose. Once a verification infrastructure exists, whether at the app level or the device level, the temptation to use it for advertising, profiling, or other secondary purposes doesn't disappear on its own.

TikTok and the UK: A Preview of What's Coming

Ofcom's investigation into TikTok offers a glimpse of how these debates play out once verification systems are already in place. Under the UK's Online Safety Act, Ofcom has criticized TikTok's "age inference" approach, which tries to estimate whether a user is a child based on behavioral data and account signals rather than requiring direct proof of age. The regulator's concern is straightforward: inference isn't verification, and if the system doesn't reliably catch underage users, it fails at its core purpose of protecting children from harmful content.

But age inference itself depends on collecting and analyzing user behavior at scale, which is its own form of data collection. Whether platforms rely on inference or on hard verification, the underlying trend is the same: more data about users is being gathered in the name of safety, and that data has to live somewhere, be retained for some period, and be protected against misuse.

What This Means For You

If you're a parent, these developments suggest more platforms will soon ask for stronger proof of age, whether through document uploads, biometric estimation, or device-level credentials. If you're simply a privacy-conscious internet user, it's worth paying attention to how these systems handle your data once collected, how long it's retained, and whether it's shared beyond the immediate purpose of confirming your age.

Tools like VPNs and encrypted browsers won't exempt anyone from age verification requirements built into apps or operating systems, but they remain relevant for limiting unnecessary data exposure elsewhere, particularly around browsing habits, location tracking, and third-party data brokers that operate independently of these new age-gating systems.

Actionable Takeaways

Stay informed about which apps and services you use are adopting age verification, and read the privacy policies that accompany these changes, since retention and data-sharing terms often shift alongside new verification requirements. If device-level verification arrives on your phone or computer, check what settings control that credential and whether it can be limited to specific apps rather than shared broadly. And keep watching how KOSA develops in the Senate. Its final language will likely shape age verification standards nationwide, making it one of the more consequential privacy debates of the year for anyone who uses social media, whether as a parent, a teenager, or simply a private citizen.