As children head back to school, many will do so carrying something previous generations never had: a smartphone that provides constant access to social media, messaging apps and strangers. For many parents, one concern increasingly stands out above the rest: sextortion.
These crimes almost always begin with deception. An adult criminal poses as another young person, builds trust, persuades a child to share intimate images or videos, then threatens to publish them unless the child sends money or produces even more explicit material. Behind many of these attacks are organised criminal gangs operating internationally, including the notorious Yahoo Boys of Nigeria. Their victims are children who believe they are talking to someone their own age. The consequences can be devastating, with some children taking their own lives after becoming trapped in these scams.
Ironically, the images that begin the blackmail are themselves generally treated in law as child sexual abuse material because they depict a minor, even where they are self-generated. While prosecution of the child is highly unlikely, possession and circulation of the images gives criminals exactly the leverage they need. This highlights an important but often overlooked role for age assurance. Most discussion focuses on preventing children pretending to be adults in order to access pornography, gambling or other age-restricted services. Sextortion presents the opposite challenge. Here, the objective is to prevent adults pretending to be children.
Children are naturally more cautious around adults than around people they believe to be their own age. I remember my own goddaughter, when she was about eleven, telling me that if she and her friends spotted someone suspicious on Snapchat they simply renamed the contact "#paedo". It was both alarming and oddly reassuring. They understood the risk. The criminals understand this too. That is why they rarely present themselves as middle-aged men. They present themselves as attractive teenagers. The social engineering depends on deception about age.
For services used by children, this suggests an obvious countermeasure. If someone wants to communicate with minors, the platform should have confidence that they are genuinely within the appropriate age range. Modern age assurance technologies can establish whether someone is under or over a particular age, or within an age band, without revealing their identity. Age assurance therefore becomes a safeguarding measure rather than simply an access control.
But we can intervene even earlier than that. If the compromising images are never created or never shared, the blackmail cannot begin. That is why the UK Government recently challenged Apple and Google to implement operating system protections that would prevent children from taking, sending or receiving nude images unless the user had first demonstrated they were an adult. The AVPA has been working with officials on the technical challenges involved in delivering that ambition.
The objective is entirely achievable. The difficulty lies in the architecture. Apple and Google can readily implement protections within services they control themselves, such as iMessage and FaceTime. Indeed, when the Government reviewed progress after its three-month challenge, the examples it cited were confined to Apple's own services. Extending equivalent protections to independent messaging platforms such as Snapchat, Signal or Telegram is considerably more complex because those applications control their own software, their own user experience and, in many cases, their own encrypted communications.
In theory, the operating system could carry out highly effective age assurance once and provide a trusted "18+" assertion to every third-party application. Indeed, Google has begun moving tentatively in that direction through its new Play Age Signals API. However, this remains a closed trust model in which Google controls both the verification process and the distribution of the resulting signal, while continuing to emphasise that application developers remain responsible for complying with the law. Apple has strengthened its own age assurance before allowing certain protections to be disabled, but has similarly stopped short of providing a reusable age assurance service for the wider internet.
The reason is not difficult to understand. If an independent messaging service relies on an operating system's age signal and that signal proves wrong, who carries the responsibility if a child is harmed? Today, those responsibilities are allocated contractually between the relying service and specialist age assurance providers, with agreed service levels, liability provisions and extensive technical due diligence. Moving that trust relationship into the operating system raises significant technical, commercial and legal questions that have yet to be answered. It is therefore unsurprising that platform providers have been cautious about becoming the de facto age assurance provider for every application running on their devices.
The practical consequence is that third-party messaging services are still likely to need to undertake their own age assurance before removing protections for adult users. Fortunately, that technology already exists. AVPA members perform billions of privacy-preserving age checks every year across a wide range of sectors and age thresholds. The challenge is no longer whether age assurance is technically possible. It is ensuring that it is deployed consistently, in the right places and through an architecture that provides clear accountability.
In the physical world, if an adult repeatedly approached groups of children in a park, most people would expect intervention. Online, the equivalent behaviour can currently occur at enormous scale while the offender simply claims to be sixteen. The internet has almost no understanding of age. Making it age-aware is the mission of the Age Verification Providers Association, and one of the most important steps we can take towards protecting children from online exploitation.