• Hashed Out
  • Posts
  • The Internet Wants to Know How Old You Are

The Internet Wants to Know How Old You Are

Protecting children online increasingly requires proving who's an adult. Can we do that without giving up our privacy?

Walk into a bar and order a drink, and the bartender may ask to see your ID. What do they actually need to know?

Not where you live. Not your driver's-license number. Not necessarily your exact birthday.

They need to know one thing: Are you old enough to buy alcohol?

Yet to prove that single fact, most of us hand over a document containing our name, photograph, date of birth, address, identification number, and sometimes other personal details.

We've accepted that arrangement because physical IDs were designed to prove identity, not individual facts about us. Now the internet is confronting the same problem on a much larger scale.

Governments increasingly want websites and online platforms to distinguish children from adults. Social networks, video services, online games, AI companions, gambling sites, pornography, and other digital services may all have legitimate reasons—or legal obligations—to know whether a user has reached a particular age.

But that creates an uncomfortable question: How should the internet prove how old you are?

  • Should you upload a driver's license?

  • Submit a passport?

  • Take a selfie?

  • Allow a company to analyze your behavior?

And perhaps most importantly: Should proving that you're over 18 require proving exactly who you are?

That question is quickly becoming one of the most important privacy debates of the digital age.

The Internet Was Built Without Age

For most of the internet's history, age verification has been remarkably unsophisticated.

You've probably seen it.

Enter your date of birth. Or: Click here if you are over 18.

The obvious weakness is that the internet generally has no idea whether you're telling the truth.

A 14-year-old can type a different birthday. A child can click the same “Yes, I'm over 18” button as anyone else. For years, that limitation was largely tolerated. But the online world children inhabit today is very different from the internet of twenty years ago.

Children and teenagers increasingly spend time on social-media platforms, streaming services, multiplayer games, messaging apps, creator platforms, and artificial-intelligence tools.

Governments have become increasingly concerned about addictive design, inappropriate content, contact with strangers, targeted advertising, AI companions, and the amount of time young people spend inside these systems.

This week, the European Commission proposed a new KIDS Act that would create age-based rules for social media across the European Union. Under the proposal, children under 13 would not be allowed to use social-media services, 13- and 14-year-olds would be limited to parent-managed accounts with restricted features, and users 15 and older could manage their own accounts. Social-media and video-sharing platforms would also be required to verify age when new accounts are created.

The proposal also reaches beyond social media. Online games, video-sharing services, and AI companions used by minors would face additional safety requirements.

Whatever one thinks about the exact age limits, the technical challenge is obvious. If governments want different rules for children and adults, websites need some way to know which is which. And that's where things become complicated.

“Age Verification” Isn't One Thing

When people hear the phrase age verification, they often imagine uploading a driver's license.

That's one method. But it is far from the only one.

There is actually a spectrum of approaches, each involving different tradeoffs between convenience, accuracy, and privacy.

Self-Declaration

This is the familiar birthday box. You tell the website how old you are. It's easy. It collects relatively little information. And it's also extremely easy to defeat.

Age Estimation

A platform can attempt to estimate someone's likely age using information it already has.

That might include account history, patterns of activity, the kinds of content someone interacts with, or other signals. This can avoid requiring an identity document.

But it creates its own concern: How much should a company analyze your behavior simply to decide how old you might be?

Facial Age Estimation

Some services ask users to take a selfie or short video. Software analyzes facial features and estimates whether the person falls above or below a particular age threshold.

This is different from facial recognition. The goal is not necessarily to identify who someone is. It is to estimate how old they appear to be.

That difference matters. But so do questions about accuracy, bias, biometric information, and what happens to the image afterward.

Document Verification

A service can ask for a passport, driver's license, or other government-issued credential. This may provide a strong age signal. It also presents the original bartender problem.

If a website only needs to know whether you're over 18, why should it receive your full name, home address, identification number, and exact birth date?

Digital Proof of Age

This is where things become much more interesting.

Instead of giving the website your identity document, a trusted digital system could simply confirm:

Over 18: Yes.

The website learns the fact it needs. And potentially nothing else. That changes the problem entirely.

The Privacy Paradox

The goal behind many age-verification proposals is protecting privacy and safety—particularly children's privacy and safety.

Yet badly designed age verification could have the opposite effect. Imagine an adult visiting an age-restricted website. Today, that person might be able to browse without telling the website much about themselves.

Now imagine that the site is required to verify age. The most obvious solution would be: Upload your ID.

Suddenly, a website that previously knew almost nothing about the visitor could potentially receive extraordinarily sensitive personal information.

Or perhaps the site asks for a selfie. Now facial information is part of the transaction.

Or perhaps it evaluates behavior across multiple services. Now the process intended to protect privacy requires additional profiling.

That creates a paradox: To protect children from revealing too much online, we could end up asking everyone to reveal more.

Fortunately, that isn't the only possible design.

Prove the Fact, Not the Person

The European Union's developing age-verification system illustrates a different approach.

The EU has created a technical blueprint for an age-verification app that is designed to allow someone to prove they meet an age threshold without revealing their exact age, identity, or other unnecessary personal information.

A person's age could initially be established using a trusted source such as an identity card, passport, electronic identity system, banking app, or another approved method.

But the website wouldn't necessarily receive that underlying information.

Instead, it could receive something much simpler: This person is over 18: TRUE

That's it.

No address. No exact date of birth. No identification number. Potentially not even a name.

This concept is sometimes called selective disclosure.

Rather than treating identity as one giant package of personal information, we begin treating it as a collection of individual facts. Imagine the difference.

Today you might show a driver's license containing:

Name: Jane Smith
Date of birth: June 12, 1994
Address: 123 Main Street
License number: 123456789
Photo: Jane Smith
State: Virginia

when the business actually needs to know only:

Over 21? ✓ Yes

That's a fundamentally different approach to digital identity.

Your Identity Could Become a Collection of Facts

Once you understand selective disclosure, age verification begins looking like part of a much bigger technological shift.

Consider all the situations where we reveal more about ourselves than necessary.

  • A business wants to know whether you live in a particular state.

    • Does it need your entire driver's license?

  • A website wants to know whether you're a student.

    • Does it need to know your student number, major, and home address?

  • A company wants to confirm that someone is a licensed physician.

    • Does it need access to unrelated personal records?

  • A service wants to know whether you qualify for a senior discount.

    • Does it need your precise birth date?

Digital credentials could allow people to prove individual attributes instead.

  • Over 18: Yes

  • Virginia resident: Yes

  • Licensed physician: Yes

  • Current student: Yes

  • Membership valid: Yes

The organization checking the credential gets the answer it needs without necessarily receiving the underlying personal information.

That could make digital identity very different from the physical documents we've relied on for generations.

How Can You Prove Something Without Revealing It?

This idea can sound almost impossible. How can someone prove something about you without learning the information behind the proof?

One answer involves cryptography. The EU's age-verification blueprint includes technology known as zero-knowledge proofs.

Despite the intimidating name, the basic idea is surprisingly intuitive. Imagine that you know the secret combination to a locked passage. You want to prove to someone that you know the combination. But you don't want to tell them what it is.

If the system is designed correctly, you can demonstrate repeatedly that you possess the secret without ever revealing the secret itself.

A zero-knowledge proof applies a similar principle mathematically. You prove that a statement is true without exposing the underlying information that makes it true.

For age verification, the statement might be: I am at least 18 years old.

The system verifies that statement. But your exact birth date remains private.

That's a powerful idea because it changes the assumption we've lived with for decades:

Proving something about yourself does not necessarily require identifying yourself completely.

Who Should We Trust to Confirm Our Age?

Of course, selective disclosure doesn't eliminate every problem. Someone still has to establish that the underlying fact is legitimate.

That raises another question: Who should we trust to confirm facts about us?

Governments are one obvious answer because they already issue passports, driver's licenses, and national identity documents. But governments aren't the only possibility.

A bank may already have verified your identity.

An operating-system provider such as Apple or Google could potentially store credentials inside a digital wallet.

A telecommunications company could know how long an account has existed and who owns it.

A specialized verification provider could act as an intermediary.

Different institutions could potentially issue different credentials. And each model involves tradeoffs.

A government-issued digital credential may be authoritative, but some users may be uncomfortable with government involvement in online identity.

A technology company's system may be convenient, but it could give that company even greater influence over how people identify themselves online.

An independent verification company introduces another organization that has to be trusted with potentially sensitive information.

There is no purely technical answer.

Digital identity is also a question of institutional trust. Who gets to say that you are who—or what—you claim to be?

What Happens to Anonymity?

That question becomes particularly important when we think about adults.

Children's safety understandably dominates the public discussion around age verification. But adults also have legitimate reasons to use the internet without attaching their complete identity to everything they do.

  • Someone might anonymously research a health condition.

  • Seek help for addiction.

  • Explore questions about sexuality.

  • Read about a religion they are considering joining.

  • Participate in a support group.

  • Research a politically sensitive topic.

Or simply visit a legal adult website without wanting that activity permanently connected to their identity. The internet has historically allowed a considerable amount of movement between identified and anonymous spaces. Age verification could change that—depending on how it's designed.

There is an enormous difference between:

Prove who you are. And: Prove that you're allowed to be here.

The first creates an identity system. The second creates an authorization system.

A privacy-preserving internet should try to avoid confusing the two.

Accuracy Matters Too

Privacy isn't the only challenge. Any age-assurance system can make mistakes.

A facial estimator could decide that a 17-year-old looks 20. It could decide that a 24-year-old looks 16.

Behavioral systems might incorrectly classify users whose habits don't match whatever patterns the system expects.

People may lack the particular type of identification a service accepts. Some users may struggle with biometric systems because of disabilities, poor camera quality, or other factors.

That means robust age-verification systems also need:

  • Alternative methods.

  • Clear appeals.

  • Accuracy testing.

  • Accessibility.

  • Secure data handling.

  • Strict limits on what happens to information after age has been verified.

In February, it announced that it generally would not pursue certain COPPA enforcement actions against eligible sites that collect personal information solely for determining a user's age—provided they follow safeguards. Those safeguards include using the information only for age verification, deleting it promptly when it is no longer needed, protecting it appropriately, disclosing what is being collected, and taking reasonable steps to ensure the verification method is accurate.

That points toward a useful principle for all digital identity systems:

Collect only what you need. Use it only for the reason you collected it. Keep it only as long as necessary.

Simple in theory. Much harder in practice.

This Is Bigger Than Age Verification

The current push to protect children may accelerate technology that becomes useful far beyond social media. Once people have secure ways to prove individual facts about themselves, many everyday interactions could change.

Imagine checking into a hotel and proving you're the reservation holder without handing over a physical document to be photocopied.

Proving you're licensed to operate a vehicle without revealing your home address.

Confirming insurance coverage without exposing unrelated medical information.

Verifying a professional credential instantly.

Proving you're eligible for a government service without providing a full identity file to every organization involved.

The larger change would be subtle but important. Today, digital identity often works like this:

Tell me who you are, and then I'll decide whether you're allowed to do something.

A more privacy-preserving system could increasingly work like this:

Prove that you're allowed to do it. I don't need to know anything else.

That's a very different internet.

The End of the Checkbox

For years, the internet solved the age problem with a checkbox.

Yes, I'm over 18.

Everyone understood that the system was imperfect. Governments increasingly appear unwilling to accept that answer.

The European Union's new proposals are only the latest sign that online services are moving toward more meaningful age assurance. And the debate is unlikely to stop with Europe. The FTC has already begun adapting its approach to age-verification technologies in the United States as well.

That makes the design choices we make now unusually important.

We could build an internet where proving your age requires sending identification documents, facial images, or other sensitive information to more organizations.

Or we could build systems designed around a different principle: Reveal less.

Prove the fact that matters. Keep everything else private.

The best digital identity system may not be the one that knows the most about you.

It may be the one that knows exactly what it needs to know—and nothing more.

Stay ahead of the curve with the latest in Web3 culture and innovation. Subscribe to Hashed Out for exclusive insights, case studies, and deep dives into the decentralized future.

Help Grow Hashed Out And Get Rewarded With Premium Content & Merchandise

If you believe in a more open, fair internet — help us build it, one reader at a time.

Web3 adoption starts with curiosity. Share Hashed Out with someone who’s ready to explore.

You’re not just sharing a newsletter — you’re inviting someone into the future of digital life.

Refer 3 friends and unlock premium content. The more you share the more rewards you unlock, including Hashed Out mugs or tote bags, and exclusive community memberships.