The Promise and Limits of Device-Level Age Attestation
Author: Emma Hatheway
When it comes to verifying the age of minors online, existing approaches are limited. ID uploads, facial recognition, and self-reported birthdates all come with trade-offs around privacy, accessibility, and effectiveness, as the first post in this series explored. Smaller platforms struggle to build verification infrastructure, larger ones can absorb fines without changing the course of their product roadmap, and minors can usually sidestep platform-level systems by creating a new account.
This post focuses on an alternative: device-level age attestation, which allows users to declare their age rather than verify it through a government ID or facial scan. Specifically, this declaration happens once at the device or operating system layer and gets passed to apps through an age signal. Instead of every website asking every user to prove their age, the device handles it.
That model has real limitations, similar to other forms of age verification. But it also addresses the fragmentation that exists with platform-to-platform verification, which puts the burden on users and parents to manage verification across dozens of sites.
Age verification is only one lever in online safety policy. How platforms are designed to maximize attention, and how regulators should address data practices and addictive algorithms, are equally important problems that age verification can't solve on its own. Those questions sit alongside this conversation but won't be the focus of this post.
Device-level age attestation. Source: https://www.androidauthority.com/colorado-os-level-age-restriction-3644641/
Age assurance via government ID and selfie verification. Source: https://www.yoti.com/business/age-verification/
The California Model: How Device-Level Verification Works
The wave of state-level age verification laws in the U.S. began in 2022, when Louisiana passed the first statute requiring ID checks to access pornographic websites. Texas, Arkansas, Mississippi, and others followed with similar models targeting sites where pornographic content makes up at least a third of the website’s content. The Supreme Court's 2025 decision in Free Speech Coalition v. Paxton upheld this approach, giving further momentum to platform-level mandates.
California's Digital Age Assurance Act (A.B. 1043), signed in October 2025, takes a different path. Rather than requiring individual websites to check IDs or regulate content, it shifts verification to the device and operating system layer and frames the issue around proactive child safety instead of pornography specifically.
Under A.B. 1043, users would be required to submit their age upon device activation. For users under 18 years, a parent submits the age on their behalf. This information would then be used to provide an age signal and passed via an API handshake between the device manufacturer and apps that the device user is attempting to download or access. The law requires the OSPs to only share limited data and information to apps, websites, and other covered platforms (such as the age signal of “younger than 13”) to prioritize data privacy.
While this law was supported by many of the big players in Tech, such as Google, Meta, and OpenAI, it is unclear how OSPs like Apple and Google are planning to adapt to this new legislation. Some concerns have been raised about how the timeline to enable these new protections and workflows will affect smaller OSPs operating on Linux, which don’t have the capacity to stand up the necessary infrastructure. Smaller organizations often respond to compliance pressure by over-restricting content to avoid fines.
It's worth noting that even a privacy-conscious system like age signaling still creates tiers of access. Once an app receives a signal that a user is under 16, someone has to decide what that user can and can't see. That decision often falls to the platform, not the parent. This is where concerns raised in the first post of this series resurface —content that gets categorized as 18+ could include self-harm resources, mental health support, or LGBTQ community forums. Device-level attestation moves the gatekeeping infrastructure, but it doesn't resolve the underlying question of who determines what information youth should be able to access online.
Privacy and Data Protection Gaps
Done properly, device-level age signaling provides stronger privacy protections than the alternatives. Consider what happened to Discord in the wake of the UK's Online Safety Act. As platforms scrambled to comply with age-verification requirements, Discord's third-party verification vendor was breached, leaking over 70,000 user ID photos. By passing only a minimal age signal between the device manufacturer and the app, the California model sidesteps the need to collect or store identifying documents.
Still, the U.S. continues to lag on data privacy legislation even as online safety mechanisms gain traction. Some critics of A.B. 1043, such as the Electronic Frontier Foundation, argue that a privacy law would protect users far better than age gating and signaling. EFF argues that the main underlying problem isn't that platforms don't know a user's age, but rather that platforms collect and monetize personal data regardless of who the user is. Under that logic, restricting data collection broadly would reduce the harms that age verification is trying to address, without requiring the surveillance infrastructure that comes with knowing every user's age.
Data privacy legislation should be a prerequisite to age attestation. Without federal rules governing how companies collect, store, and sell user data, age signals become another data point for platforms to exploit. A privacy law establishes a critical baseline, creating a digital environment where users consent to how their information is used. Age attestation then builds on that foundation, adding protections specific to children and bringing parents and kids into the conversation. Whether that complementary relationship holds in practice depends on the guardrails applied to device manufacturers and platforms to limit what they do with age signals once implemented.
User Autonomy vs. Corporate Control
Device-level age attestation should include greater flexibility for children and parents. Rather than leaving content restrictions entirely to technology companies, parents and children themselves should have a say in what's accessible.
This becomes especially important as we think about how flexible age assurance should function. Privo, a Safe Harbor provider specializing in age verification and children's privacy compliance, promotes the need for a “smart age gate”, in which access to content online expands as a minor gets older. At the device level, this could look like a settings panel where parents see content categories and toggle access by age bracket, rather than managing a static list that doesn't evolve as their kid ages.
This kind of flexibility matters because the alternative is treating every minor as a single category. A "younger than 18" signal collapses a nine-year-old and a seventeen-year-old into the same user, which doesn't reflect how kids actually develop or how their information needs change over time.
Parental control keeps decision-making with families, which is preferable to corporate or government classification in many cases. But the framing also has limits and concerns. Some parents will use these tools to restrict access to sex education or information about identity and sexuality. Device-level attestation can't solve for that, and solely providing parental autonomy is not a clean fix.
Expanding parental responsibility only works if parents and kids have support. Right now, most parents learn about safety features reactively, after an incident or through word of mouth. Device-level attestation creates an opportunity to change that by building education directly into the device setup process. Apple and Google need to develop onboarding flows that walk kids and parents through what the age signal does, what content categories exist, and how to adjust settings over time.
Broader education and support is needed as well. Governments, public health advocates, and technology companies all have a role in helping parents, teachers, and kids understand what youth actually encounter online, from how harms manifest to where supportive communities form. Most current resources are aimed at parents, which leaves children navigating restrictions they weren’t able to shape. Guidance that helps kids name what they're encountering online and ask for the access they need would help shift these conversations from top-down to collaborative. That matters especially for teenagers, whose information needs (around identity, mental health, relationships) are often the same categories most likely to get restricted.
What Device-Level Age Attestation Doesn't Solve
Device-level age attestation has natural limitations. Many families share devices, which forces all users under a single age declaration. School-issued devices raise similar questions depending on how a district configures them. And the digital divide means that the families least able to afford devices with these features are also the least likely to have the resources or technical literacy to work around the limitations. If device-level attestation becomes the standard, it needs to account for how families actually use devices, not how an idealized single-user household does.
Most importantly, device-level age attestation doesn't address what happens once kids get access. Gamification and opaque algorithms will continue to persist, regardless of who's been age-gated out. Even when blocking works, the platforms kids can access are still built to maximize attention and time-on-app. Those design choices will keep harming users of all ages until regulators force companies to disclose how their products are engineered and set real limits on manipulative features.
Conclusion
California's A.B. 1043 is a meaningful shift. Moving age verification to the device layer reduces the privacy exposure of ID-based systems and takes some pressure off smaller platforms that can't build verification infrastructure from scratch.
But the law's success depends on things outside its own text. Apple and Google have to build systems that families can actually navigate. Age signaling without a federal privacy framework gives platforms one more data point to work with, not fewer. And the harder questions, like who decides what content gets categorized as 18+, or how parents balance protection with a minor’s need to find LGBTQ resources or mental health information, still exist when verification moves to the device.
The path forward starts with data privacy legislation. Infrastructure changes, design transparency, and education for the parents and kids who actually use these systems all have to be built on top of that foundation. Until those pieces come together, age attestation is a partial fix to a much bigger problem.
If you want to dig further into how online safety policy is evolving, check out the following resources:
Online Safety Regulation: The Duty of Care Framework and Implementation Blind Spots
Youth Voices, Legislative Momentum, and the Future of Online Safety
Beyond Parental Controls: Rethinking Age Assurance & Digital Agency for Youth
All Tech Is Human's Responsible Tech Guide is also a strong general resource for getting involved in this space.

