A New Approach to Age Verification Emerges in Congress

A bipartisan group of senators, including Andy Kim, Adam Schiff, Cynthia Lummis, and John Barrasso, has introduced legislation known as the Digital Age Assurance Act. The bill proposes a fundamentally different approach to how apps and websites confirm a user's age: instead of each platform independently collecting identification documents, selfies, or other sensitive data, operating systems themselves would collect a user's age once and pass along a simple age signal to apps through an API whenever it's needed.

This marks a departure from the patchwork of state-level age verification laws that have proliferated in recent years, many of which require individual apps or websites to verify identity directly, often through document uploads or facial scans. The federal proposal instead centralizes that responsibility at the device or account level, with Apple, Google, Microsoft, and other operating system providers becoming the primary collectors of age data.

How OS-Level Age Assurance Would Actually Work

Under the framework described in the legislation, age collection would happen during operating system account setup, the same process users already go through when setting up a new phone, tablet, or computer. Once that age is established, the operating system would generate an age signal, not necessarily an exact birthdate or government ID, but a categorical marker (such as "over 18" or "under 13") that gets transmitted to apps and websites requesting it.

Proponents argue this reduces the number of times sensitive identity documents change hands. Rather than uploading a driver's license to a dozen different apps, each with its own data retention practices and security posture, users would verify their age once at the OS level. Apps would simply query that signal via an API rather than building or buying their own age verification infrastructure.

The trade-off is centralization. Instead of age data being scattered (and duplicated) across many platforms, it becomes concentrated with a small number of operating system providers who already hold enormous amounts of information about their users. Critics of similar state-level proposals, such as one pending in California according to public discussion of the bill text, have raised concerns that mandatory OS-level age checks could function as a de facto identity layer for the entire internet, since operating systems would know not just a user's age but potentially which apps are requesting that signal and when.

Comparing This to Current App-Based Verification

Today's age verification landscape is fragmented. Some states require platforms to verify age through ID uploads, credit card checks, or facial age estimation software. Each method has its own privacy risks: uploaded IDs can be breached, facial scans require biometric processing, and credit card checks exclude users without financial accounts. Because verification happens separately at each platform, the same sensitive data often gets collected and stored redundantly across many services.

The OS-based model aims to reduce that redundancy by having a single, standardized age signal that travels with the user. In theory, this limits the number of parties handling raw identity documents. In practice, it shifts significant power and responsibility to a handful of operating system makers, raising questions about how long age data would be retained, who could request it, and whether it could later be linked to other data these companies already collect, such as location, app usage, or account activity.

These questions echo broader debates about surveillance and data collection that have played out in other corners of federal policy. Concerns about how government and commercial data collection frameworks are actually implemented, and whether oversight keeps pace with stated privacy protections, have surfaced repeatedly, including in Senator Wyden's disclosures about FISA Section 702 compliance failures, which showed how good intentions in legislation don't always translate into consistent enforcement.

What This Means For You

If this bill or something like it becomes law, the way you prove your age online could change significantly. Instead of repeatedly uploading ID documents to individual apps and websites, your device or operating system account would handle that verification once and share only a limited age signal as needed. For many users, this could mean fewer instances of sensitive documents being stored on third-party servers.

But it also means operating system providers would take on a new, more centralized role in verifying identity, effectively becoming gatekeepers for age-restricted content across the entire internet. How that data is secured, minimized, and governed will matter enormously. The bill is still in early stages, and the technical and privacy safeguards that accompany any final version will determine whether this approach genuinely improves privacy or simply relocates the risk.

Key Takeaways

  • The Digital Age Assurance Act would require operating systems, not individual apps, to verify user age and transmit a privacy-preserving signal via API.
  • This could reduce redundant collection of ID documents across multiple platforms, but concentrates age data with major OS providers.
  • Watch for details on data retention, oversight, and whether age signals could be linked to other data these companies already hold.
  • As this legislation moves through Congress, compare it against state-level age verification laws to understand how your personal data might be handled differently depending on where you live.
  • Stay informed: policies like this could reshape mobile privacy well beyond age verification, affecting how much trust users place in operating system providers going forward.