The Age Verification Industry Just Told On Itself
- Julie Barrett

- Jul 14
- 4 min read
Updated: 4 hours ago

Parents and legislators keep hearing the same reassurance: age verification technology can confirm someone is over 18 without ever revealing who they are. Age, not identity. That's the pitch behind nearly every state and federal age-verification proposal moving through statehouses right now.
That reassurance doesn't come from a fringe source. It comes from the Age Verification Providers Association (AVPA), the global trade body representing the companies that build this technology. And in a recent piece on their own site, AVPA made an argument worth reading closely, because buried inside their own defense of the industry is an admission that undercuts the pitch itself.
What AVPA Actually Argues
AVPA's piece takes aim at a specific line of criticism: the argument that age verification is really just identity verification wearing a different label. Their concern isn't that this criticism is merely wrong, it's strategic. They warn that if critics keep repeating the "age checks are identity checks" framing, the public will eventually assume identity disclosure is already baked into every age-verification system, whether or not that's true. That assumption, they argue, would make it easier for platforms to justify collecting real identity data down the road, since the public will already believe that's the status quo.
To make their case that age and identity really are separable, AVPA points to a range of technologies: biometric age estimation, bank-derived age signals, and age attributes pulled from digital identity wallets. Each is designed, they say, to confirm a user meets an age threshold without disclosing who that user actually is.
It's a coherent argument, and it deserves a fair hearing before any critique. The industry has, in fact, invested real effort into building systems that minimize what gets shared with the website or app asking "how old are you?" That much is true.
The Sentence That Undoes the Argument
One sentence in AVPA's own piece gives away more than they intend. Describing how digital wallet systems work, they note that even when an authoritative identity document is used to originally establish someone's age, the wallet itself only needs to disclose a data-minimized age attribute afterward.
An identity document (a driver's license, a passport, some government-issued credential) is still used to establish the person's age in the first place. The "privacy-preserving" part only kicks in after that. The platform asking "are you over 18?" may never see a name or a document number. But somewhere upstream, a system already verified exactly who that person is in order to issue the credential that now answers "yes" on their behalf.
That's not eliminating the identity check, it's just relocating it, moving it earlier in the pipeline, to a point where it's harder to see, harder to scrutinize, and easier to defend as "just age verification."
What "Upstream" Looks Like in Practice
This isn't a hypothetical. The architecture AVPA is describing maps onto a real, existing standard: ISO 18013-5 and its successor 18013-7, the technical specifications underlying the mobile driver's license (mDL). This is the same standard the federal government has already built into law for one use case (TSA's mDL acceptance rule at airport security) developed through an ISO working group that includes both the Department of Homeland Security and commercial vendors building state-level mDL systems.
In other words, the infrastructure connecting an "age, not identity" credential back to a fully verified government identity already exists. It isn't a slippery-slope prediction. It's the plumbing the technology runs on today, for a purpose Congress has already approved in at least one context. Extending it to age verification for social media, app stores, or AI chatbots doesn't require inventing anything new; the rails are already there, waiting for the next justification to run through them.
Privacy-Preserving Doesn't Mean Breach-Proof
Even setting aside where the identity check happens, "designed for privacy" is a design goal, not a guarantee. In March 2026, Spain's data protection authority, the AEPD, fined the age-verification vendor Yoti €950,000 for GDPR violations connected to how it handled age-verification data. Yoti is not some obscure outlier; it's one of the more prominent vendors in exactly the space AVPA represents.
The fine matters here for a narrow reason: it's a real-world instance of a "privacy-preserving" system failing at the privacy part, from an actual regulator, not a theoretical concern raised by skeptics. The architecture can be built with the best privacy intentions in the world and still fail once it's deployed at scale, handling real data, under real commercial pressure.
What to Watch For
AVPA's own piece worries that if the public stops believing the distinction between age and identity, the outcome will be worse privacy protections, not better ones. That's a fair concern, framed honestly and it's worth turning back on the industry itself. The distinction is worth preserving. But it can only be preserved by looking at the actual architecture underneath a system, not by accepting the marketing language at face value.
The next time a bill or a vendor promises "age, not identity," the useful question isn't whether the platform sees your name. It's where the age attribute originally came from, who verified it, and what record that verification created upstream. That's the part the reassurance leaves out and it's the part parents and legislators deserve a straight answer to before any of these systems become law, not after.


Comments