Every one of these laws is written about kids. Every one of them ends up checking you. As governments race to keep under-16s off social media, the enforcement has a catch nobody puts in the press release: you can't verify that teenagers are teenagers without making everyone prove their age. Haven't been asked to scan your face or upload an ID for an ordinary app yet? Give it time. The odds are moving in one direction.
The dominoes
Australia went first, banning under-16s from social platforms in late 2025 — and the follow-on has been fast. At least a dozen countries have restrictions in place or in the works, with more tightening parental-consent and verification rules around the edges. Vietnam's ruling party just ordered platforms to run identity checks and stop under-16s from posting, commenting, or even reacting. The UK is promising rules that go "further than any country in the world." France, Canada, Denmark, Spain, Norway — all moving this year.
And the honor system is over. Regulators aren't accepting a typed-in birthday anymore. The new standard is layered proof: government ID uploads, AI age estimation that analyzes your face from a selfie or video, voice recognition in some places, behavioral signals underneath it all.
The math they don't advertise
An age gate can't be selective — that's the structural catch. No platform can check only the 15-year-olds. It has to sort everybody, so every adult walks through the same scanner. Which means laws sold as child protection are quietly standing up ID infrastructure for the whole internet. And infrastructure, once built, has a way of finding new jobs.
Each method has its own bill. Upload your driver's license and a government document — the skeleton key of identity theft — now lives on servers run by a platform or some third-party verification vendor you'd never heard of last year. Do the face scan and you've normalized handing biometrics to companies with, let's say, uneven security track records. Either way, your account is now easier to tie to the real you — which chills the anonymous corners of the internet that actually matter, whether that's a whistleblower, someone quietly researching a diagnosis, or a person who'd just rather not be a row in a database.
And a centralized pile of ID scans and face data? That's not a maybe-target. That's a when-target.
Shrinking your exposure
The laws aren't optional, but your choices within them help. When a platform offers it, pick on-device or estimation-based checks over document uploads — a face-age estimate that's processed and tossed beats an ID scan that sticks around. Before you upload anything, look at who's receiving it (the platform itself, or a named verifier?) and whether they promise to delete verification data afterward. Never, ever verify through a link that arrived by email or text — that's this era's perfect phishing bait; use the app's own settings instead. And if some random service demands ID for no defensible reason, treat that as the warning it is.
The bigger question
Nobody's saying the child-safety goals are fake. The machinery being built for them is real too, though — and machinery outlives intentions. Once the internet runs on verified identity, the question stops being "how old are you?" and becomes "who are you?" — with unverified slowly turning into suspicious. Maybe that's a trade worth making. Just make it with your eyes open, starting with a good look at whatever you're asked to hand over this year.
Image: Borys Zaitsev, via Pexels





