The federal government has introduced digital safety legislation that would ban social media access for children under 16, and two of the world's largest tech companies are already moving to comply. Google and Meta have begun rolling out 'age assurance' technology in Canada, using artificial intelligence to estimate how old their users actually are, rather than simply trusting the birthdate someone typed in when they signed up years ago.

The timing is not a coincidence. As lawmakers push forward with rules aimed at protecting minors online, platforms are under growing pressure to prove they can identify underage accounts before regulators force their hand with fines or outright bans.

What's Happening With Canada's Digital Safety Bill

The proposed legislation would prohibit children under 16 from holding social media accounts, joining a growing list of countries experimenting with hard age limits for platforms like Instagram, TikTok, and YouTube. Rather than waiting for the bill to become law, Google and Meta have started deploying age assurance systems in Canada now, following similar rollouts the companies previously tested in the United States.

Meta has already begun using AI models to flag accounts it believes belong to minors and automatically shift them into more restrictive 'teen account' settings, limiting who can message them, what content they see, and how they can be found by strangers. Google is expanding a comparable system that uses behavioral signals, rather than just a self-reported age, to guess whether an account belongs to a child or teenager.

Both companies frame this as a proactive step toward child safety. But the approach also raises a less-discussed question: what data is being collected to make these age guesses, and where does it go afterward?

How Age Assurance Technology Actually Works

Unlike traditional age verification, which typically asks users to upload a government ID or scan their face, 'age assurance' as described by Google and Meta relies more heavily on inference. The systems analyze patterns such as how an account interacts with content, who it follows, what kind of language it uses, and other behavioral markers, then estimate an age range without necessarily requiring a document upload.

That sounds less invasive on the surface, but it still means platforms are building and storing detailed behavioral profiles to make these determinations. It's a similar underlying logic to the cookies that track your browsing habits across sites, except here the tracking is being used to make consequential decisions about a user's account access and privacy settings, not just to serve ads.

Companies operating in Canada, the U.S., and elsewhere have generally avoided detailing exactly what signals feed into these AI models or how long that data is retained, which leaves users and parents with limited visibility into the process.

The Privacy Trade-Offs Behind Age Verification

Age assurance systems sit at an uncomfortable intersection: they're designed to protect children, but they require collecting and analyzing more personal data to work. This is not a new tension in tech policy, but it's one that deserves scrutiny as more governments mandate these systems.

Recent history offers reasons for caution. Investigations into platforms like TikTok have shown how invisible tracking mechanisms can quietly collect sensitive personal information far beyond what users expect, even from people who never installed the app. Elsewhere, companies building AI-driven products have faced legal challenges over how they handle user data without clear disclosure. And regulators have shown they're willing to act decisively when companies mishandle personal information, as seen in South Korea's record-setting fine against Coupang over a major data protection failure.

The lesson across these cases is consistent: whenever a platform collects more data, even for a well-intentioned purpose like protecting minors, that data becomes a target and a liability if it isn't secured and governed properly.

What This Means For You

If you or your children use Google or Meta products in Canada, you may start noticing age-related prompts, restricted settings, or account changes as this age assurance rollout continues. Parents should expect platforms to ask more questions, request more verification steps, or automatically adjust privacy settings based on estimated age.

It's worth paying attention to what permissions and data access these systems request, and reviewing your account's privacy settings periodically rather than assuming defaults are sufficient. If a platform shifts your account or your child's account into a more restrictive mode, take the time to understand why and what data triggered that change, if that information is made available.

Key Takeaways

Canada's push to ban social media for under-16s is accelerating how quickly Google, Meta, and likely other platforms adopt AI-based age assurance tools. This shift brings real child safety benefits, but it also expands the amount of behavioral data companies collect to make those determinations.

As this legislation moves forward, keep an eye on how these companies disclose their data practices, review your family's privacy settings on major platforms, and stay informed as more details emerge about how age assurance data is stored, shared, or used beyond its original purpose.