Nobody Knows How Old You Are

A wave of laws now requires websites to know whether you’re a child. The awkward truth is that the internet has no good way to find out — and every bad way costs someone something.

Somewhere in Britain right now, a grown adult is holding their phone up to their face, tilting it toward the window for better light, trying to look convincingly over eighteen at a camera. The camera is not impressed. Maybe it shaves a few years off because of the lighting, or adds a few because of a bad angle, or simply gets confused, as these systems measurably do, by darker skin. The adult tries again. Somewhere else, a fifteen-year-old is passing the same check using a photograph of a video game character — this has actually worked — or just typing “1998” into a dropdown menu, the way people have been lying about their age online since the dropdown menu was invented.

This is the strange new ritual of the age-verified internet, and it rests on a fact that almost nobody involved in passing the laws wants to say out loud: the internet does not know how old you are, has never known, and currently has no reliable, privacy-preserving way to find out. A technical assessment published in January by the Knight-Georgetown Institute — written by Eric Rescorla, Zander Arnao and Alissa Cooper, people who build internet infrastructure rather than opine about it — concluded that no single method of establishing age online is sufficient on its own, that every system can be circumvented, and that it is “not technically feasible” to block all minors without also blocking large numbers of adults. The demand behind the laws is reasonable. The mechanism the laws assume exists does not.

The menu of bad options

Consider what’s actually on offer. Self-declaration — the checkbox, the birth-year dropdown — works for nobody and was never meant to; it’s a liability posture wearing a costume. Document upload asks every site that wants to check your age to also hold your government ID, which means multiplying the number of databases full of passports and driver’s licenses by every forum, app and adult site on earth. We already know how that goes, because it has already gone: last fall, a former age-check partner of Discord leaked the government IDs of some 70,000 users. Discord’s subsequent attempt to roll out age verification globally was reversed after user backlash and pushed into 2026, with its CTO promising that most users would never see a check and that face scans would run entirely on-device. The lesson was not subtle. Every ID collected is an ID waiting to be breached, and the fear of handing a passport to a porn site is itself a chilling effect on perfectly lawful adult behavior.

So the industry has converged on the option that feels most like magic: point your face at the camera and let a model guess. The trouble is that guessing is precisely what it does. A 2024 NIST evaluation of facial age-estimation algorithms, as summarized by the industry group CCIA, found best-case mean errors of around three years even on clean, visa-quality photos, and errors of three to five years for people aged eighteen to twenty-four — which is to say, the systems are least certain exactly where the law needs them to be most certain. The Knight-Georgetown report notes the same weakness at the threshold, and adds that some techniques perform worse for people of African heritage and for women. A system that is reasonably good at telling a forty-year-old from a ten-year-old, and noticeably worse at telling a seventeen-year-old from a nineteen-year-old, is a system optimized for the question nobody is asking.

Card checks, the remaining option, quietly convert age into income. According to CCIA’s figures, a large majority of teenagers and most low-income college students lack access to a credit card, and meaningful shares of young adults lack accepted photo ID at all. Age verification by payment instrument doesn’t verify age; it verifies that you are the kind of person banks have already vouched for.

The deadline machine

None of this is an argument that the underlying concern is fake. Parents are not imagining the internet their children inhabit, and the lawmakers now passing age-assurance requirements across numerous US states, the UK, Australia and the EU are responding to something real. The problem is the legislative move that follows: write a deadline, declare that a mechanism shall exist by then, and let the market sort it out. This is how you get the worst version of every option — the cheapest face-estimation vendor, the broadest ID collection, the most aggressive data retention — because the law does not reward the system that fails gracefully. It rewards the system that ships. It is not a coincidence, as a NIST researcher told Ars Technica, that developers submitting age-estimation prototypes for evaluation rose fourfold in two years. A mandate is a market signal, and the market is answering with exactly the speed and exactly the care you’d expect.

The deeper contradiction is one the Knight-Georgetown authors make visible without quite editorializing: the stricter the threshold, the worse everything gets. A check that merely separates children from adults can tolerate some error. A check that must separate a seventeen-year-old from an eighteen-year-old cannot tolerate any, and so it demands more data, more documents, more certainty than the technology can honestly supply — with the burden falling hardest on the people the systems already misread. Accuracy at the boundary is the entire ballgame, and the boundary is where the accuracy isn’t.

So the honest position is an uncomfortable one, because it refuses both available endings. It is not “regulation is futile” — the harms are real, and doing nothing is also a choice with victims. And it is not “protect the children, whatever it takes” — because “whatever it takes” currently takes the form of ID honeypots, racially skewed face scans and financial gatekeeping, none of which reliably stops a determined fifteen-year-old with a photograph of Sam Porter Bridges. What the report’s authors suggest instead is unglamorous: layered signals, parental consent for the under-eighteens where it’s the most practical mechanism, and a frank admission that perfect enforcement is not on the menu.

That admission is the thing the laws are designed to avoid making. A statute that says “verify age” sounds like a solution; a statute that says “reduce harm, imperfectly, at some cost to everyone” sounds like a surrender. But the internet’s ignorance of your age is not a bug awaiting a patch. It is closer to a physical fact, like the fact that a locked door stops honest people. We have built an entire civic ritual — the phone tilted toward the window, the passport photographed on the bedspread — around pretending otherwise. The least we could do is notice who the ritual actually excludes, who it exposes, and who strolls straight past it, dropdown menu in hand.