A bipartisan group of senators has introduced legislation that would fundamentally change how age verification works online in the United States. Senators Andy Kim (D-NJ), Adam Schiff (D-CA), Cynthia Lummis (R-WY), and John Barrasso (R-WY) unveiled the Digital Age Assurance Act, a bill that requires operating system providers, think Apple and Google, to collect users' ages and share that information with individual apps upon request.

The stated goal is straightforward: protect children from harmful content and predatory design features baked into many apps and platforms. But the mechanism the bill relies on, having device makers act as centralized age verifiers for the entire app ecosystem, raises the kind of privacy questions that have dogged similar efforts in other countries.

What the Digital Age Assurance Act Does

Under the proposal, smartphone and tablet operating systems would be responsible for determining a user's age category and passing that signal along to apps when requested. Rather than each individual app building its own age-verification system (often through invasive methods like ID uploads or facial scans), the burden shifts upstream to the handful of companies that control mobile operating systems.

The bill's sponsors have emphasized privacy safeguards as part of the package, including provisions that would prevent children's data from being sold or transferred to third parties and restrictions on targeted advertising to minors. That framing matters: the legislation is being pitched not just as a child-safety measure but as a privacy-protective alternative to the patchwork of app-by-app verification schemes currently in use. Senator Kim's earlier draft text of the bill, which shifts age checks to app stores, laid the groundwork for this approach by moving verification responsibility away from individual apps and toward the platform layer.

The Privacy Trade-Off: Centralizing Age Data at the OS Level

Here's the tension worth sitting with. Today, if one app's age-verification system is breached or misused, the damage is largely contained to that app. Under a model where Apple or Google verifies age for every app on a device, that single point becomes a far more attractive target and a far more consequential point of failure.

Even with strong statutory language barring data sales, centralizing age verification at the OS level means operating system providers would need mechanisms to determine age in the first place, whether through account history, payment information, government ID, or biometric estimation. Each of those methods carries its own privacy footprint, and the bill's success will depend heavily on how narrowly "age signal sharing" is defined and enforced in practice, not just in the text of a press release.

There's also the question of scope creep. Systems built to verify age for child-safety purposes have historically expanded well beyond their original mandate once the infrastructure exists. A framework that can tell an app "this user is under 18" is technically capable of telling that app far more, depending on what safeguards are actually written into implementing regulations rather than the bill's summary.

Lessons from the UK and EU Age-Verification Experiments

The United States is not the first to attempt this. The UK's Online Safety Act and the EU's Digital Services Act have both pushed platforms toward age-gating and age-verification requirements, and both have run into friction. Age-verification tools in those jurisdictions have been criticized for pushing users toward third-party ID-checking services with their own data-handling practices, for producing false positives that lock out legitimate adult users, and for creating new attack surfaces that weren't well scrutinized before rollout.

Those experiences don't necessarily doom the Digital Age Assurance Act, but they're a useful reference point. A federal, OS-level approach could avoid some of the fragmentation seen in Europe, since it centralizes the function in a small number of companies rather than thousands of individual sites. Whether that centralization reduces overall privacy risk or simply concentrates it in fewer, higher-value targets is the open question Congress will need to answer as the bill moves through committee.

What This Means For You

If you use a smartphone, tablet, or any app that currently asks you to self-report your birthdate, this bill could eventually change how that process works. Parents may see more consistent parental control enforcement across apps rather than relying on each platform's own settings. Teens and young adults may find themselves subject to age checks earlier in the sign-up process, even for apps that previously required no verification at all.

For privacy-conscious users, the practical takeaway is to pay attention to how "age assurance" is implemented if this bill advances, not just whether it passes. The difference between a privacy-respecting age signal and a data-collection pipeline often comes down to technical implementation details that get worked out well after a bill's introduction.

Key Takeaways

The Digital Age Assurance Act is still early in the legislative process, but it signals where federal child-safety policy is heading: toward device-level verification rather than app-by-app compliance. Readers who want to stay ahead of the curve should keep a few things in mind. Review the privacy settings and parental controls already available on your devices, since those tools may become more central to compliance under this framework. Watch for how implementing rules define what "age signal sharing" actually includes, since that detail will determine how much data actually moves between your device and the apps you use. And stay engaged as the bill moves through committee, since public comment periods and congressional testimony are typically where the technical safeguards, or the lack of them, get decided.