Current Region:
Global

Why “Device-Only” age checks are a False Choice for lawmakers

July 30, 2026

A prominent adult platform network recently published an open letter to US lawmakers arguing that site-level age verification laws have failed. In its place, the letter proposes that lawmakers mandate Apple, Google and Microsoft to build device-level age checks into operating systems, treating such “upstream” controls as a complete substitute for the existing adult websites’ role in preventing underage access.

Age assurance can happen at several points: when a device or account is set up, when an app is downloaded or when someone accesses a particular service or restricted content. These layers perform different functions and, critically, are not interchangeable.

Device-level signals, including those required under California’s Digital Age Assurance Act, or app-store mechanisms such as those defined by the App Store Accountability Act (ASAA), represent vital progress in building a safer digital environment. However, presenting these or device filtering (as recently offered in several jurisdictions by Apple through iOS 26.4) as a total replacement for publisher-level age assurance is a false choice. Effective online safety requires a layered approach where every part of the ecosystem plays its part, rather than transferring all responsibility and liability away from the adult platforms, which, incidentally, are where the economic gains and risks ultimately lie.

A False Choice Between Layers

You would not rely on an age check at the entrance to a shopping centre to control access to every age-restricted venue within it. The relevant check normally happens when someone enters a casino or, even more narrowly, at the point they buy alcohol, because that is where the particular risk and responsibility arise.

The same principle applies online. An operating-system check can provide a useful first layer, but it cannot fully replace the responsibility of the service providing the age-restricted content.

The open letter frames the policy choice as an either-or decision: either mandate operating system providers to block adult content or require websites to verify their users. In reality, these mechanisms are complementary layers of a comprehensive safety architecture, and deliver different contributions towards achieving the policy goal.

Put simply,

  • the operating system knows about the device or account,
  • the app store knows about an app download, and
  • the service knows what content the person is trying to access.

Where lawmakers have designed well-scoped statutory signals for digital ecosystems, such as in the App Store Accountability Act, they have established dual obligations. The ASAA places duties on both the app store signal provider and the developer relying on that signal. The proposal put forward to Congress asks lawmakers to go much further by entirely eliminating publisher duties for their web content.

Given their very titles, it is self-evident that app-store protections apply to downloaded apps and may not protect someone visiting a website through a browser. An adult website accessed via a general-purpose web browser is not an app downloaded from an app store.  The Open Letter does not call for this method to replace age assurance by adult websites.

What the letter does advocate for is treating an operating system filter as a full exemption for web publishers of high risk content.  Fundamentally, this removes any accountability from the very platforms generating and monetising high-risk content.

App-store models like the ASAA attach duties to individual account transactions and provide apps with an age-category signal tied to a specific user. Relying solely on a generic device filter for web-based adult content leaves critical gaps that only publisher-level checks can close.

Operating System Filters Are Not a Substitute for Publisher Verification

A device setting may show who usually uses the device, but not who is using it at that moment, especially if it is shared, borrowed or left unlocked.

Apple’s UK system is age verification check for adults which unless completed imposes an operating-system level content filter. Basing a regulatory regime on the application proposed by adult platform lobbyists does not provide web publishers with a reliable, authenticated age signal, with a clear auditable trail to the method and rigor of the age check, and a contractual guarantee of its accuracy between the entity doing the check and the site relying on it to do so.  The letter argues there should be no legal duty on adult platforms to verify their visitors are adults, either directly, or through any formal outsourcing arrangement, be that to a third-party age assurance provider or an operating system owner such as Apple.

Device-level settings operate on the device or account level rather than verifying the person holding the screen at any given moment. An unlocked or shared family device bypasses a simple operating system toggle. In contrast, publisher-level age assurance can be configured to check that the person accessing age-restricted material at that moment has been verified as an adult, and to repeat such checks periodically.

This is the ‘proximity principle’: checking someone’s age when they try to access an age-restricted product, service or content. If you think of this in terms of physical safety on a construction site where a deep hole has been dug, it puts the fence around the hazard itself, not just a warning sign about holes at the entrance to the site.   A check right before you access adult content makes it obvious why it is needed and helps confirm the right person is being checked.  It is only done when definitely required, not just in case.

Mischaracterising Modern Age Assurance

Arguments against site-level verification often imply that users must hand over government identity documents or facial scans directly to every website they visit. This is incorrect.

An independent age assurance provider can conduct the check and return only a simple ‘over-18’ result to the destination site, without collecting, disclosing or retaining identity documents or personal data on the website itself. Through reusable and interoperable proofs and tokens, users can verify their age across multiple sites without having to repeat the verification process or expose personal details to adult content publishers.

If our members used physical ID as proof, then their systems allow users to confirm their age with far greater privacy protections than displaying a physical ID card in a brick-and-mortar venue because they apply “selective disclosure” of only the age-range, not showing all other details found on a passport or driving license. Zero-knowledge proofs are an approach gaining ground across the industry, and these can not only prevent the website learning the identity of a user through the age assurance process, but also prevent the provider that does the age check from tracking which sites the user visits.

In short, site-level responsibility does not mean handing identity documents to every website or completing a new age check on every visit. A trusted provider can check someone’s age once and provide a reusable proof, anonymously, showing only that the required age threshold has been met.

What the UK and Australian Evidence Actually Shows

Opponents of site-level checks rely on selective readings of reports to claim that age verification technology does not work. A closer look at the published data reveals a far more nuanced picture:

  • The UK Experience: Ofcom’s implementation data confirms that site-level age assurance is working on compliant services. By June 2026, 64 of the top 100 pornography services in the UK had implemented age assurance, up from 41 in August 2025, with ten more blocking UK access entirely. All ten of the most popular services had age assurance in place. Among a tracked cohort of five children in an Ofcom observational sample, visits to major non-compliant adult sites fell dramatically from 122 to 8 after age checks were introduced across top platforms. Across 88 adult services investigated by Ofcom, 73% had introduced age assurance or blocked UK users, and Ofcom had fined 7 non-compliant providers operating 24 sites. Industry letters have quoted a passage noting that non-compliant sites had gained traffic, wrongly attributing this line directly to Ofcom as its own finding. In fact, Ofcom was quoting an external submission from the British and Irish Law, Education and Technology Association, itself then only citing older US research.

  • The Australian Data: Industry arguments frequently cite a study showing 85% of surveyed teenagers continued using social media despite age restrictions. That study, more importantly, found that simple age self-declaration was still the most common barrier encountered before opening an account rather than any form of actual age assurance technology. It is widely recognised that most social media platforms are doing the minimum possible to claim compliance. Initial implementation steps made some progress, with 4.7m accounts closed based on previously declared ages below 16, but it is now widely acknowledged that clearer standards and stronger enforcement are required to achieve the impact intended by the Australian Parliament.  The problem in Australia is not too much age assurance, it is too little of it.

  • The “Less Than 5%” Claim: Recent lobbying cites a statistic claiming that under 5% of users complete site-level age verification, attributing this to an industry trade body, the Free Speech Coalition. No independent methodology or sample data is offered for this figure, which it appears relies on the claims of a single French website. It comes from an adult-industry advocacy body that challenged age verification legislation in court. Our own members do not recognise this figure from their direct experience with clients in the adult sector because it does not reconcile with the volumes of checks they are processing for compliant sites.

Market Substitution and Legal Precedents

Platform operators point to user migration toward non-compliant sites in jurisdictions like Texas as proof that site-level laws fail. However, major operators chose to geo-block their platforms in Texas, Utah and Louisiana rather than offer users a compliant verification route. That commercial choice directly contributed to the user redirection now cited as evidence.

This dynamic underscores the need for stronger cross-border enforcement, search engine accountability and more effective enforcement mechanisms, such as payment processing restrictions, not the abandonment of age checks.

From a legal standpoint, the US Supreme Court addressed this exact argument in Free Speech Coalition v. Paxton. Petitioners argued that Texas should rely on device-level filters as a less restrictive alternative rather than requiring publisher checks. The Court rejected that argument, establishing that the availability of device-level tools does not prohibit states from enforcing publisher-level age verification to protect minors, noting that a state need not address every aspect of a problem in one fell swoop.

The Path Forward: Layered Accountability

A layered approach could combine a device or account age check with occasional checks that the same person is still using it, and an additional check before they access higher-risk content. Each check provides a different safeguard.

Device-level settings and app-store frameworks like the ASAA offer essential tools for parents. They represent a key emerging layer in a modern online safety framework, particularly if they continue to survive constitutional challenges in the USA.

However, upstream tools cannot simply replace publisher accountability for high-risk web content and functionality. Protecting children online requires a multi-layered approach:

  1. Upstream Protections: Enforcing clear app-store standards and parental consent frameworks for downloaded apps.
  2. Publisher Responsibility: Mandating highly effective, privacy-preserving age assurance on platforms hosting adult content.
  3. Regulatory Enforcement: Holding non-compliant overseas sites accountable through fines and business disruption orders to restrict access to vital services such as payments.

Transferring responsibility exclusively to three operating system providers creates a single point of failure, concentrated market power and, some may also fear, even more data harvesting opportunities, while excusing adult platforms completely from their duty of care.

Real child protection means device, app store and publisher each carrying a proportionate share of the effort, applied where appropriate for each use-case, not the commercial adult industry shifting its own responsibilities to unconnected global corporations.