Age verification is the requirement that a service establish whether a user is a minor by a method that does not rely on the user's own unverified assertion. It has become the principal regulatory mechanism attached to AI companion and chatbot products, because most other restrictions on those products are conditioned on the user being a minor.
The definitional problem it solves
Self-attestation — a checkbox or a birth-date field — has been the default compliance mechanism online for two decades and is trivially defeated. Legislative drafting has therefore moved toward defining verification negatively, by what does not count.
S. 3062, the GUARD Act contains the sharpest US formulation. A "reasonable age verification measure" means government-issued identification or another "commercially reasonable method" that can "reliably and accurately" determine adulthood. The process must expressly provide "that requiring a user to confirm that the user is not a minor, or to insert the user's birth date, is not sufficient," must subject every user to every measure the entity uses, and may not infer age "on factors such as whether the user shares an Internet Protocol address, hardware identifier, or other technical indicator with another user determined to not be a minor" — closing the household-inference route by which a service might treat a device as adult because another user on it is.
The retroactivity question
Verification regimes must decide what happens to accounts that already exist. The GUARD Act's answer is the most aggressive in current US drafting: on the effective date a covered entity must "freeze any such account," restoring functionality only against verified age data. That converts verification from a signup gate into a whole-userbase re-credentialing event.
The privacy trade-off
Reliable verification requires collecting identity documents or biometric signals from every user, which creates a data-protection exposure that did not previously exist — the more reliable the method, the more sensitive the data it generates. Legislative drafting has responded with handling restrictions rather than by relaxing the standard: the GUARD Act limits collection to what is "minimally necessary," requires encryption in transit and retention limits, and bars covered entities from sharing, transferring, or selling verification data to any other entity — an absolute prohibition rather than a consent-based restriction. It permits third-party verification vendors while providing that using one "shall not relieve the covered entity of its obligations under this Act or from liability."
Deployers have also begun building inference-based alternatives. OpenAI reports being "in the early stages of rolling out our age prediction model" to apply teen protections automatically to accounts it believes belong to under-18 users (Update to GPT-5 System Card: GPT-5.2 (OpenAI, December 2025)) — which avoids collecting identity documents but substitutes a classifier whose errors fall on users in both directions.
Estimation as an alternative to verification
A second drafting approach requires an operator to estimate age rather than verify it. Colorado's Chatbot Safety Act requires operators of conversational artificial intelligence services to use "commercially reasonable methods or generally accepted methods to estimate the age of account holders or users" and not to willfully disregard clear and convincing information that a user is a minor, providing that an estimated age or age range is itself considered knowledge of the minor's age (Colorado HB 26-1263 (Chatbot Safety Act, Enrolled Act)).
The Colorado Department of Law's proposed 4 CCR 904-6 rules give that standard the most detailed regulatory content of any US instrument to date, and reach the opposite conclusion from the GUARD Act on identity documents: an operator "must not use as a sole method of age assurance a method that requires a user to provide government-issued identification", on the stated ground that methods must maximize user choice. Rule 9 sets nine cumulative conditions, including collecting only data necessary for age assurance of that user and deleting it after the minimum compliance period; being reasonably effective at identifying users under 18, performing with measurable consistency, and being tested with quantifiable accuracy rates in line with industry standard rates; using operating-system, app-store, and device signals without willfully disregarding contradicting evidence; re-assessing estimates on new signals; maintaining a process for reports that a user is a minor or falsified their age; not relying solely on self-declaration, general terms of use, or payment methods available to minors; and detecting fraudulent or misused information. An inconclusive outcome cannot support a determination that a user is not a minor (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)).
The rules name four generally accepted methods: an age-assurance method satisfying ISO/IEC 27566 on age assurance systems, which Rule 14 incorporates by reference; a cryptographic technique such as a zero-knowledge proof demonstrating minority from verified data without revealing other information; matching a scan of a government-issued identity document against a live photo or video using facial recognition; and assessment of a user's digital footprint originating from a verified email address. For willful disregard the Department will weigh, alongside the factors in 4 CCR 904-3 Rule 6.13, whether an operator ignored behavioral signals processed by the language model — direct statements of minor status, recurring discussion of grade-level and high-school situations, age-specific activities, or a user consistently occupying a child role in described parent–child interactions — and whether design choices nudged users toward inaccurate estimation, such as age-reporting tools that pre-fill a birth date over 18 (Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026)).
Age as a proxy for maturity
Verification establishes a user's age; the developmental premise of age-gating is that age tracks the capacities the protections are meant to compensate for. The American Psychological Association's June 2025 health advisory states that premise is unreliable: adolescence is "a long developmental period, and age is not a foolproof marker for maturity or psychological competence," so "two adolescents of the same age are unlikely to be at the same level of maturity or development" (Artificial Intelligence and Adolescent Well-being: An APA Health Advisory (June 2025)). The advisory adds that individual differences — temperament, neurodiversity, exposure to stress or violence, social isolation, traumatic experience, mental health, and socioeconomic or structural disadvantage — mediate how adolescents respond to the same content.
The advisory does not conclude against age-differentiated design. It treats adolescence as ages 10 to 25, a band wider than the under-18 and under-16 thresholds used in the GUARD Act and most state statutes, and asks that systems "designed for, or foreseeably accessed by" adolescents carry age-appropriate defaults, reduced persuasive design, and protective settings on by default. The effect is to recommend age-differentiated treatment while denying that any single age threshold identifies the population needing it.
Public support
A Reuters/Ipsos poll of 4,505 US adults conducted over the six days ending August 3, 2026 and published August 9, 2026 found 66% supporting laws that would require social media companies to use age-verification tools to keep children under 16 off their platforms. Support was highest among Republicans at 74%, against 69% of Democrats; the margin of error was 2 percentage points in either direction. The same poll recorded 85% saying social media can be addictive for children (Source: reuters.com). The finding stands against the First Amendment challenges brought by the trade group NetChoice, which has sued to stop laws requiring apps to verify users' ages (NetChoice v. Bonta (CAADCA litigation)).
Relationships
- depends-on: AI and Children — verification is the gating mechanism for most minor-specific AI restrictions
- contradicts: Artificial Intelligence and Adolescent Well-being: An APA Health Advisory (June 2025) — holds that age is not a reliable marker of the maturity that age-gating proxies for, while still recommending age-differentiated design
- instance-of: Colorado 4 CCR 904-6 — ADMT and Conversational AI Service Proposed Rules (2026) — the most detailed US regulatory specification of an age-assurance standard, barring reliance on government-issued identification as a sole method
- related: Colorado HB 26-1263 (Chatbot Safety Act) — requires age estimation rather than verification, with the estimate itself constituting knowledge of minority
- related: GUARD Act (Hawley), S. 3062 — GUARD Act of 2025, as introduced (119th Congress), AI Companions, AI and Privacy, Raine v. OpenAI, Inc., American Psychological Association (APA)