CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulation

Age Verification Software: EU Plan Verifies Downloads via API

age verification software parents may soon have to unlock children's online lives, phone screen showing app store download age gate
A phone screen shows an app store download blocked by an age verification software prompt, illustrating the leaked EU Kids Act proposal. Illustration: CaraComp

Picture this: your kid wants to download a game. Instead of just hitting install, they hit a wall asking them to prove how old they are, right there in the app store, before the game even opens. That's not a hypothetical. It's what a leaked European proposal, nicknamed the "EU Kids Act," could turn into normal life for millions of families within the next couple of years.

Age verification software is at the center of a leaked EU plan that would require proof of age not just for adult content, but for online games, AI chatbots, and social media, all checked at the moment you try to download or sign up. The plan leans on identity checks, document based age confirmation, and compliance standards borrowed from fraud prevention and KYC systems used elsewhere online. Verification at the storefront level would apply to age-restricted products of every kind, and some vendors are already testing facial age estimation alongside document checks tied to an api connection with regulators watching closely, including protections aimed at minors.

Here's the headline fact nobody's talking about enough: this isn't about one app or one country. The leaked draft, reported first by Euractiv and covered in detail by outlets like Hardware Busters, would move age checks to the download button itself, meaning Steam, Epic Games, Google Play, and the Apple App Store become the checkpoint for basically every game sold in the European Union. Same rules would stretch to AI chat tools and social apps. One framework, one continent, dozens of everyday digital habits.

25+
U.S. states have already passed their own age verification laws, adding pressure on companies before the EU even finalizes its plan
Source: reporting summarized by researchers covering the EU Kids Act draft

Why age verification software, identity checks, compliance, and verification are moving to the download button

For years, age checks lived inside apps. You'd open a social media app, type in a birthday nobody bothered to check, and that was that. The leaked EU Kids Act flips that model. Instead of trusting each platform to police itself, the proposal would have age verification software running at the storefront level, meaning the app store itself confirms your age before you even see the download button. It's a shift from "trust the app" to "trust four or five giant companies that control nearly all app distribution" for identity checks and compliance. This verification shift also means every download becomes a verification checkpoint, not just an occasional one.

That matters more than it sounds like it should. Right now, if one game studio has a sloppy age check, it's that studio's problem. Under this model, Apple, Google, Epic, and Valve (the company behind Steam) become the single point of failure or success for an entire continent's worth of games, AI tools, and social platforms. Concentrate that much responsibility in that few hands, and you'd better hope they get it right, because there's no plan B if they don't. Compliance failures at this scale would ripple through every online storefront at once, and verification gaps at even one company could undercut verification efforts everywhere else.

And here's the part that should make any parent pause: the age itself isn't even locked in yet. According to reporting on the leaked draft, the European Commission's own expert panel recommended 13 as the baseline age, but France has been pushing hard for 15. That's not a rounding error. That's a two-year gap that changes which of your kid's friends get locked out of a game, an AI tutor, or a group chat, and whether a user meets minimum age requirements at all under either version of the law. Regulations at the EU level would eventually need to settle that gap before verification can be applied consistently.

Age verification software, document based age checks, verification, and liveness tests already being tested across Europe

This isn't coming out of nowhere. Trilligent has reported that five EU countries are already running pilot programs testing pieces of this system, working out the technical kinks before any continent-wide law locks in. The EU's preferred method leans on something called zero-knowledge proofs (a way to prove a fact, like "I'm over 16," without handing over the actual birth certificate or ID card behind it). In theory, that's the privacy-friendly version of age checks. In practice, privacy researchers aren't convinced it's ready for the size of rollout being proposed. Some vendors already offer a document based age verification service online, pairing an uploaded ID with a liveness check, a quick selfie scan meant to confirm the document actually matches the person holding it, which is one way fraud gets caught before it reaches a minor's account. Verification vendors describe this combined selfie and document flow as the current gold standard for online verification, even as facial matching technology keeps improving. This article is part of a series, start with Biometric Based Authentication A Face Is Just 512 Numbers.


What compliance and verification rules would the EU Kids Act set for online games, AI, and social media?

The EU Kids Act is a leaked draft proposal that would require age verification software across online games, AI services, and social media platforms in the European Union, not just adult content sites. It groups all three categories, games, AI, and social apps, under one set of compliance rules, with identity checks happening at the app store or download level instead of inside each individual app. Verification would need to happen before the download completes, not after, and compliance teams would need to document every verification event for regulators.

According to the researcher analysis summarized from All About Cookies, the draft outlines four separate age bands, meaning different rules and different levels of parental control kick in depending on how old a child is. That's a more layered system than most parents are used to, and it echoes COPPA style thinking already familiar to U.S. parents. Right now, most platforms treat "under 13" as one blanket category. This proposal treats a nine-year-old, a twelve-year-old, and a fourteen-year-old as three different risk profiles, each requiring different levels of document proof, different verification steps, and different levels of parental sign-off, especially for access to age-restricted products like mature-rated games.

Every single time an age authentication mandate goes into effect, the internet shrinks some.

cited in researcher analysis, Electronic Frontier Foundation

That quote sounds dramatic, but it's grounded in something real. Every age gate that gets added is also a data collection point that didn't exist before. Ask yourself: who's holding the record of your kid's identity check? How long do they keep it? Can it be sold, leaked, or subpoenaed later? Those aren't paranoid questions. They're the actual mechanics of how age verification software works once it's live, especially when a compliance vendor is handling fraud detection, verification logs, and document storage on a platform's behalf.

Why age verification software, privacy checks, and parental consent matter for families right now

  • It's not optional anymoreonce a storefront requires it, every app on that store inherits the requirement, whether the app maker wanted it or not, and compliance becomes a condition of staying listed, with verification checked at every download
  • 📊 The threshold is still being fought over13 versus 15 changes who gets locked out, and nobody outside Brussels has a say yet, including which underage users would need explicit parental consent to proceed
  • 🔮 Data brokers are already in the loopsome existing age estimation tools lean on data brokers checking the email you signed up with, which means more of your identity and online history gets passed around, not less, even before formal verification kicks in
  • 🌍 It won't stay in Europewith 25+ U.S. states already running their own versions, companies are being pulled in different directions at once, and that usually means the messiest, most data-hungry option wins by default

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Age verification software checks before and after the app store becomes the checkpoint

It helps to see the shift side by side. Right now, most age checks are a birthday field you type into an app once. Under the leaked proposal, the check happens earlier, gets tougher, and gets repeated across way more services, with more identity, verification, and document checks built in. Here's the contrast:

Before the EU Kids ActUnder the leaked proposalVerification status
Age check happens inside each app, one at a timeAge verification software runs at the app store or download button, covering games, AI, and social media at onceVerification centralized
Self-reported birthday, rarely checkedZero-knowledge proof or public-authority tool required to confirm age without handing over full ID documentDocument verification optional
One blanket "under 13" categoryFour separate age bands, each with different parental control requirementsVerification tiered by age band
Age threshold set by each platformThreshold still undecided, caught between the Commission's recommended 13 and France's push for 15Regulations pending on minors' threshold
Enforcement scattered across thousands of apps, minimal compliance checksEnforcement concentrated in a handful of app store companies, with formal compliance audits expectedVerification audited

What is age estimation and how is it different from age verification, KYC, verification, and document checks?

Age estimation guesses your age from signals like your email history or browsing habits, often through data brokers, without asking for formal identity proof. Age verification software, on the other hand, asks for actual confirmation, sometimes a government ID document, sometimes a newer privacy tool like a zero-knowledge proof, similar in spirit to the identity and KYC checks banks already run for fraud prevention. Facial matching and liveness checks are increasingly bundled into this verification step too. Estimation is faster and less invasive on paper, but critics argue it just moves the data collection somewhere less visible instead of removing it, and it offers far weaker verification than a document based check. Previously in this series: Biometric Data Privacy Walmart Keeps 512 Face Numbers Podcas.


Whether an online age check verifies identity to protect your kid or just collects more data

That's the exact tension sitting at the center of this proposal, and it's worth naming out loud. The goal, keeping kids away from content and contact that isn't right for them, is a good one. Nobody sane is arguing against that. But "prove your age" has a way of quietly becoming "hand over your identity document, your email history, and a photo of your face," and once that data exists somewhere, it doesn't just evaporate when the age check is done.

Here's one useful thing you can actually do, starting now, before any of this becomes law: when a service asks your family to confirm that a child meets an age threshold, check whether it's asking for a yes-or-no confirmation (are you over 13, yes or no) or a full identity document upload. The first is a much smaller footprint. The second is where you want to ask harder questions, like where that document gets stored and for how long, and whether the compliance vendor doing the verification has any public track record around fraud or data handling. That single distinction, confirmation versus documentation, is the fastest gut check a parent has right now, and it applies whether the technology solution used is a simple checkbox or a full identity and facial scan.

Key Takeaway

Age verification software is about to move from a background annoyance on adult websites to a front-door requirement for games, AI tools, and social apps across the EU, and the four age bands under discussion mean your family could face different rules depending on exactly how old your kid is on the day they hit download.

Look, nobody's saying age gates are inherently bad. Kids do stumble into content and conversations they're not ready for, and plenty of that happens through AI chatbots now too, not just social feeds. But there's a difference between a smart, narrow check and a system that quietly builds a data trail every time a 14-year-old wants to play a game with friends. More than 25 U.S. states already have their own age verification laws on the books, and companies are already stuck reading different rulebooks for different regions, some leaning on an api connection to a third party identity verification service rather than building checks in house. Add an EU-wide framework covering games, AI, and social media into that mix, and you get a genuinely messy few years while everyone figures out what "reasonable" actually looks like for online compliance and verification.

The real kicker? Regulators still can't agree on whether the line should be 13 or 15. If the people writing the law can't settle that basic number, how confident should anyone be that they'll nail the harder calls, like what counts as a "risky" AI chatbot, which games are too addictive for a 12-year-old, or which age-restricted products need the strictest document checks of all? That's the actual test of this whole plan, and right now, it's still an open question with your kid's download button, verification method, and regulations still hanging in the balance.

age verification software: Frequently Asked Questions

What is the leaked EU Kids Act and does it actually exist as law yet?

The EU Kids Act is a leaked draft proposal, not a finished law. It was reported by Euractiv and covered by outlets tracking the leak, describing plans to require age verification software across online games, AI services, and social media in the European Union. The age threshold, either 13 or 15, is still being debated, and the proposal hasn't been finalized or passed yet, so no identity, verification, or compliance rule is currently in effect, and no regulations have been confirmed. Up next: Biometric Based Authentication A Face Is Just 512 Numbers Po.

Will age verification software require my child's ID document or just a birthdate?

That depends on which method a platform uses. Some age verification software relies on a full identity document, while newer privacy-focused tools use zero-knowledge proofs, meaning a service can confirm someone is over a certain age without seeing their actual ID or birth certificate. The leaked EU draft says any technology solution used should be privacy-preserving, but privacy researchers note it hasn't been proven at large scale yet, and questions about fraud resistance and verification accuracy remain open.

Why might parents soon have to unlock children's online lives under this proposal?

Reporting on the leaked draft, including coverage from EuroWeekly News, describes a system with four separate age bands, each tied to different parental consent requirements. That means depending on a child's exact age, a parent might need to actively approve or unlock certain app features, games, or AI tools rather than a child simply self-reporting their birthday once and moving on, with verification repeated at each new age band.

How is age verification software different from age estimation and biometric age checks?

Age verification software asks for direct proof of age, sometimes an identity document, sometimes a privacy tool like a zero-knowledge proof, sometimes a biometric age scan tied to a live selfie and facial age estimation. Age estimation instead guesses age using indirect signals, like how long an email address has existed, often pulled through data brokers. Estimation feels less invasive on the surface, but it can still involve companies collecting and holding onto personal data behind the scenes without much compliance or verification oversight.

Which companies would actually run these identity, verification, and compliance checks under the EU Kids Act?

Under the leaked proposal, the check would largely happen at the app store or download level, meaning companies like Apple, Google, Epic Games, and Valve (which runs Steam) would become responsible for confirming age before someone can download a game, AI app, or social platform. Some may use Yoti's age verification service or a similar third party vendor rather than building identity checks from scratch, and others may use iDenfy's age verification service for document, verification, and liveness review, which concentrates compliance in a small number of companies instead of spreading it across every individual app developer.

Is age verification already happening anywhere else besides the EU, and does COPPA play a role?

Yes. More than 25 U.S. states have already passed their own age verification laws, and COPPA already sets baseline rules for how U.S. platforms handle children's data and consent, with regulations specifically protecting minors. Countries like Australia have pushed platforms such as Steam to add age checks tied to things like credit cards. This EU proposal would add another major region to that patchwork, meaning global companies now have to satisfy several different sets of compliance and verification rules at once, which tends to push them toward the strictest, most document heavy, most data hungry option.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search