Policymakers’ Guide to Developing Age Assurance Legislation

Policymakers’ Guide to Developing Age Assurance Legislation. By: Scott Babwah Brennen, Lama Mohammed, and Afnan Abbassi After years of debating if and how we should verify the ages of users to restrict minors from accessing harmful digital content, it is happening in the U.S. In the last several years, dozens of U.S. states have enacted laws requiring adult content websites, social media platforms, and app stores to verify users’ age. And while we should continue to interrogate the value of requiring age assurance, it is essential that we now also consider how to enact these policies in ways that best protect user privacy, security, and speech rights. There is no perfect way to implement age assurance; each approach will involve significant trade-offs. For example, while requiring users to submit government IDs may make systems more accurate, doing so raises the risk of both privacy violations and unjust exclusion. It is essential that lawmakers understand the trade-offs of each option to balance the choices they must make when drafting age assurance legislation. Below, we offer a guide for state lawmakers considering new age assurance requirements. We map out six key decision points that lawmakers will confront in crafting age assurance legislation, elucidating both the set of choices and the trade-offs inherent in each. We draw heavily on what states have already done, or at least considered, to map out real options for state lawmakers. Decision Point 1: What is age assurance meant to accomplish? Lawmakers establish age assurance requirements to protect minors. There are several distinct ways lawmakers generally pursue this. Restricting minors’ access to harmful content or features. Trade-offs There is broad public support for limiting minors’ access to harmful or inappropriate content or features. However, the courts have long held that minors do have limited First Amendment rights. In that there is no single understanding of what constitutes “harmful” or “inappropriate,” overly broad definitions may restrict important or beneficial content. Information about sexual health, LGBTQ+ content, or sexually explicit art or literature could be limited by overbroad efforts to limit “inappropriate” sexual content. Similarly, efforts to protect children from “harmful” social media features or platforms likely limit their ability to express themselves. Once they turn 18, minors will gain full access to all legal content. Restrictions on access to social media or AI platforms may leave minors unprepared to use them safely and responsibly. Simultaneously, it is impossible to restrict minors’ access to content without also imposing some burden on adults. Until Paxton v. FSC, the courts had determined that online age verification imposes a significant and unconstitutional burden on adults’ access to legal content. Finally, broad restrictions on minors’ access to content restrict parents’ control over what their children access online. Rather than leaving the decision to parents or guardians about what content is appropriate for their children, these approaches relocate that decision making authority to the government. Example: Wyoming HB 43 Requiring parental consent for minors to access apps or content. Once determined that an account belongs to a minor, some laws require that the account be associated with a parent or guardian.  Trade-offs This approach grants parents control over what content their children access. Yet, requiring parental consent poses significant functional challenges. Consent requirements may fail if parents are not actively involved in their children’s lives. The burden of repeated consent requirements, such as approving account creations or certain followers, may prove untenable for parents who choose to bypass the system. Example: Nebraska LB 383 Restricting access to certain features or setting defaults. Rather than limit access to entire platforms, some lawmakers are considering laws that would require platforms to restrict only certain content or features for minors, or to set default settings for minors. Trade-offs This approach preserves minors’ access to apps while reducing access to the most concerning content or features. It permits apps to target controls to different age groups and has a higher chance of surviving First Amendment scrutiny as narrowly tailored.  However, implementing this poses significant technical challenges. Smaller companies may struggle to accurately age-gate specific features or content. It also poses significant privacy risks. Apps must maintain age data or regularly reassess user ages. This may mean holding on to sensitive data, rerunning age assurance multiple times.  Example: Nebraska LB 504 Decision Point 2: Who will assess ages? Whatever the reason for age assurance, legislators must verify which party should be responsible for verifying a user’s age; these include: The user Over the past several decades, self-declaration, in which the user attests that they are over (or under) an age cut-off, has been the most common method of age assurance.  Trade-offs Self-declaration protects user privacy by preventing apps from collecting sensitive or personal data. In contrast to other approaches, it is both easy to implement and presents little friction for users, most of whom have experience with these systems.  Example: California AB 1043 First-party service (which grants access) Trade-offs Targeted applicability. Only apps that pose specific risks to children are required to implement age assurance measures, thereby limiting restrictions on access to legal adult speech. Rather than granting a single company (such as an app store) the ability to control access to thousands of apps, requiring each app that gives access to content to implement age assurance, decentralizes decision making across the entire ecosystem.  On the other hand, every app that conducts its own age assurance creates significant friction for users. User experience suffers when users must repeatedly undergo age assurance processes. This also likely imposes non-trivial compliance costs—especially for start-ups or smaller companies, which may give larger, more established companies a competitive advantage. Similarly, first-party assurance poses significant privacy risks, as every covered app must collect users’ personal data, or hire a commercial firm to do so. This vastly increases the number of companies that must collect, store, and process personal data.  Finally, distributing compliance across the entire ecosystem may lead to reduced oversight and lower compliance rates. Few state Attorney General offices will have sufficient resources to