That "Verify Your Age" Button Just Took Way More Than Your Birthday
Here's something that will change how you think about every "verify your age" screen you've ever clicked through: a bouncer at a bar doesn't need to know your name. He doesn't need your address. He doesn't need your ID number, your middle name, or whether you have a clean driving record. He needs to know exactly one thing — are you over 21? The moment he confirms that, his job is done. He doesn't write it down. He doesn't keep a copy of your license. He just waves you in and moves on.
Now think about what happens when a website asks you to "verify your age." Most of us assume we're doing the digital version of that same exchange. But in a lot of cases? We're handing a bouncer our entire filing cabinet — and he's keeping it.
Proving you're "old enough" is a single yes-or-no question — and the safest age verification systems answer it without ever needing your name, address, or ID on file.
Washington State is now testing an age verification system built around exactly this idea. The goal, according to the pilot's framing, is that user privacy will be protected. That sounds nice. But what does it actually mean, technically? And how do you tell the difference between a system that genuinely forgets your information — and one that quietly keeps it forever?
That's what we're going to figure out. By the end of this, you'll be able to look at any "age check" screen and instantly know whether it's asking for a fact or collecting your identity. Those are completely different things.
Two Very Different Kinds of "Age Check"
When a website wants to confirm you're old enough to see its content, it basically has two paths. Think of them as the lightweight approach and the heavy approach. This article is part of a series — start with Philippines Biometric Ai Privacy Review What It Means For Yo.
The lightweight approach: facial age estimation. You look at your phone or webcam, an AI analyzes your face, and within seconds it guesses your age. No ID uploaded. No document scanned. The AI checks things like the depth of lines around your eyes, the fullness of your cheeks, the texture of your skin — mapping what RealEyes describes as thousands of facial landmarks to produce an age estimate. Fast, low-friction, and — here's the catch — not always right.
This is where it gets genuinely interesting. According to OneID, the age group most likely to get incorrectly flagged by facial estimation — kicked out of the fast lane and forced into a slower, more invasive verification — is people aged 18 to 24. Exactly the people who are actually old enough. Their faces are harder for AI to read confidently, so the system hedges and demands more proof. The irony is almost funny, except it means young adults who are perfectly eligible end up surrendering more personal data than older users just to prove the obvious.
The heavy approach: document verification. You upload a photo of your driver's license or passport. The system reads your birthdate (using OCR — optical character recognition, basically software that reads text from images — and MRZ processing, which decodes the machine-readable strips on official IDs). It checks that the document looks legitimate. Then it compares your face to the photo on the document to confirm it's really you. Legally airtight. Also data-intensive in a way that should make you pause.
That number — from Veriff — explains why simple single-step checks keep failing. Roughly 1 in 17 verification attempts involves someone actively trying to game the system. That's why the most thorough systems layer multiple signals together: document checks, facial comparison, behavioral patterns, even network data. More signals mean better fraud detection. They also mean more of your information being collected and analyzed.
The Misconception That's Making This Worse
Here's what almost everyone gets wrong, and it's completely understandable why: most people assume that when they upload their ID to an age-check screen, that document gets stored somewhere — probably on the platform's servers, probably forever. So they resign themselves to it. Well, I guess they have my ID now. Whatever. Previously in this series: 419 Arrested For Fake Videos The One In Your Group Chat Coul.
The reality is more complicated — in a way that's actually good news, when the system is designed correctly. Privacy-first age verification works like this: your document or photo goes in, the system extracts the one piece of information it needs (your birthdate, or a simple "over 18: yes/no"), and then it deletes the evidence. What comes out the other end isn't your ID. It's a result. Approved or denied.
The technical term for the gold-standard version of this is a zero-knowledge proof — which sounds intimidating but means something simple: the system proves a fact is true without ever seeing the underlying data. Imagine a magic trick where the magician confirms you have an ace without ever looking at your cards. According to New America, this kind of privacy-preserving architecture exists and works — the problem is that most commercial platforms weren't built this way, because they were originally designed for advertising targeting and fraud prevention, not age gating. They're collecting more than they need because that's what their systems were already set up to do. It's not always sinister. It's often just... inertia.
"No technology available is entirely privacy-protective, fully accurate, and guarantees complete coverage of the population." — Electronic Frontier Foundation, December 2025
That quote from the Electronic Frontier Foundation is worth sitting with for a second. Pick any two: privacy, accuracy, or coverage. You can't fully have all three at once. A facial estimate is private and fast but misses people. A document check is accurate and comprehensive but collects more data. This is the real trade-off that Washington State — and every other state wrestling with this — is trying to solve.
What Washington's Pilot Is Actually Testing
Washington's HB 2112 — the legislation behind the pilot — takes a specific stance on the data retention problem. The American College of Pediatricians reports that the bill includes civil penalties of $10,000 per instance for platforms that improperly retain identifying information after a verification check is complete. That's the mechanism that forces the separation — not a polite request to please delete user data, but a financial consequence for keeping it.
The "optional" framing in the pilot is also deliberate. Requiring age verification and protecting privacy can actually pull in opposite directions: mandatory systems push platforms toward document collection (because that's what holds up legally), while optional participation gives platforms and developers room to test lighter-touch alternatives. The Daily Chronicle notes that ACLU testimony at the HB 2112 hearing raised concerns about exactly this tension — that even well-intentioned age verification laws can create data collection infrastructure that outlasts its original purpose. Up next: Your Face Isnt A Password One Country Just Made That The Law.
At CaraComp, we work with facial recognition systems every day, and this distinction — between confirming a fact and collecting an identity — shows up constantly in how these systems are designed. The technical architecture of "check and forget" is genuinely different from "check and retain." It's not a policy choice layered on top of the same system. It's a different system, built differently, from the ground up.
What You Just Learned
- 🧠 Age estimation vs. age verification — facial AI guesses your age fast; document checks confirm it legally but collect more data
- 🔬 The design choice that matters — a privacy-first system returns a yes/no result and deletes the proof; most platforms weren't built that way
- ⚠️ The 18–24 problem — the people most likely to be incorrectly challenged by facial AI are young adults who are actually eligible
- 💡 The EFF trade-off — no system is simultaneously private, accurate, AND fully inclusive. Every approach gives something up
When any site asks you to "verify your age," the useful question to ask is: are they confirming a fact, or collecting my identity? A system that only needs to know you're old enough should never need your name, your address, or a permanent copy of your ID. If it's asking for all of that, it's doing more than an age check.
So the next time you hit one of those "confirm your age" screens, try asking yourself what the site actually needs. Does it need to know who you are — your name, your address, your full ID number? Or does it only need to know whether you're old enough?
Those are two completely different questions. The bouncer at the door only has to answer one of them. The best digital age checks work exactly the same way — they answer the question, then forget they ever asked.
The ones that remember everything? They were never just doing an age check.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Your ID Shouldn't Be the Price of Proving You're 18
Western Australia is testing age checks that answer just one question — "old enough?" — without collecting your name, address, or ID number. Here's why that tiny difference protects a lot.
digital-forensicsThat "Weird Fingers" Deepfake Trick? It's Why You'll Get Scammed Tonight
Most people think deepfakes get caught by visual glitches. The real catch? A three-layer evidence trail that starts long before you look at the pixels. Learn the method that actually works.
digital-forensicsStop Watching the Face: 3 Places Deepfakes Quietly Fall Apart
The face in a deepfake can look completely real. The tell is somewhere else entirely. Learn the three places fake videos quietly fall apart — and why your instincts are aimed at the wrong target.
