California Governor Gavin Newsom signed a sweeping package of child online safety laws on September 10, and the fine print affects far more than the teenagers the legislation was designed to protect. Buried inside the new rules is a requirement that Apple, Google, and other platform operators verify the age of every user, not just minors. For adults who assumed age checks were a problem for someone else, that assumption no longer holds.
What California's New Kids Safety Laws Actually Require
The laws Newsom signed target some of the most criticized features of modern social media and AI products. Algorithmic feeds and autoplay functions are now banned for social media users under 16, cutting off the engagement-maximizing recommendation engines that critics say keep young users scrolling far longer than intended. Separately, operators of AI chatbots must now build in crisis protocols that activate when a minor shows signs of suicidal ideation during a conversation, a direct response to concerns about AI companions engaging with vulnerable teens without any human safety net.
Those provisions alone would have made this a notable legislative session. But the broader, more consequential piece is the age verification mandate placed on app store operators like Apple and Google. Rather than asking individual apps to verify age at the point of sign-up, California is pushing the burden upstream to the platforms that control app distribution itself.
Why Age Verification Now Applies to All Users, Not Just Teens
Here's the part that changes the calculus for adults: to reliably identify which accounts belong to minors, app stores need a baseline understanding of every user's age, not just the ones who are underage. There is no practical way to verify that a 15-year-old is a 15-year-old without first asking, and verifying, that an adult account actually belongs to an adult.
That means the verification infrastructure being built for teen protection doesn't stay contained to teen accounts. Every user who wants to download apps, use social platforms, or interact with AI chatbots on a California-linked device may be asked to confirm their age as part of routine account setup, regardless of whether they're 17 or 47. This is the tradeoff regulators are making: broader identity checks in exchange for tighter guardrails around minors.
What Data Apple, Google, and Platforms Will Collect and Store
The practical question for every user is what age verification actually looks like on the back end. Age assurance systems generally rely on some combination of self-reported birthdates, device or account history signals, and in stricter implementations, document or biometric checks. California's law places the verification obligation on Apple and Google at the app store level, which means these companies will be maintaining age-related data tied to user accounts across potentially millions of app interactions.
Even when a system avoids demanding a photo ID or facial scan, storing and cross-referencing age data at the platform level creates a new layer of identity infrastructure that didn't exist before. Once an app store can confirm your age bracket, that signal can be requested by other apps, chatbot developers, or services trying to comply with the same law. The more platforms build around a shared age-verification layer, the more that data becomes a permanent fixture of how you access apps and services, not a one-time checkbox.
Can VPNs or Privacy Tools Offset the New Verification Requirements
A natural instinct for privacy-conscious users is to reach for a VPN to sidestep new identity checks. It's worth being clear about the limits here: a VPN changes your apparent location and encrypts your traffic, but it does nothing to prevent an app store or platform from asking you to verify your age directly through your account, device, or app credentials. Age verification enforced at checkout, sign-up, or app-store level operates independently of your IP address.
We've already seen this pattern play out elsewhere. In the UK, regulators building a teen social media curfew have pushed platforms to build in VPN detection specifically because location-masking tools were being used to dodge age-based restrictions. California's approach, verifying age at the account or app-store level rather than relying solely on location signals, is a similar acknowledgment that VPNs alone are not a durable workaround for identity-based rules.
What This Means For You
If you use Apple or Google devices and live in, or regularly interact with, California-based services, expect to encounter age verification prompts even as an adult. This isn't a hypothetical future risk, it's a direct consequence of how the new law is structured. Your best move is to understand what each platform is actually asking for before you comply. Self-reported birthdates carry different privacy implications than document uploads or biometric scans, and it's reasonable to ask which method a given app or app store is using before you hand over information.
The broader lesson from California's age verification law and privacy debate is that identity checks are increasingly happening at the infrastructure level, not the app level, which makes them harder to opt out of with technical workarounds alone.
Key Takeaways
- California's new laws, signed September 10, ban algorithmic feeds and autoplay for under-16 social media users and require AI chatbot crisis protocols for minors.
- Age verification requirements extend to Apple, Google, and other platforms, meaning adult users will also be asked to confirm their age.
- Expect age-related data to be collected and potentially shared across apps as compliance infrastructure expands.
- VPNs address location and encryption, not app-store-level identity verification, so they won't shield adults from these new checks.
- Pay attention to how each platform verifies age, self-reported data carries far less privacy risk than document or biometric verification.




