Getting Age Assurance Right: A Risk-Based Framework for High-Risk Online Features

Source 
Author 
Coverage Type 

In “The Kids Aren’t Alright Online: How to Build a Safer, Better Internet for Everyone,” Public Knowledge argued that age assurance—the practice of verifying an online user’s age—should be a narrow tool, not a policy solution. The most important thing lawmakers can do for children online is require technology companies to design safer products—not deputize parents and children to police systems that were never built with kids’ wellbeing in mind in the first place. But that argument, intentionally, left a question open: when age assurance is appropriate, how should it work? The policy moment demands an answer. More than 25 states have now passed some form of age assurance requirement, and the legislative patchwork is still growing. At the federal level, the Federal Trade Commission issued an Enforcement Policy Statement in 2026 promoting the adoption of age-verification technology under the Children’s Online Privacy Protection Act (COPPA), marking the first time a federal agency has affirmatively incentivized specific age-verification approaches through the promise of enforcement forbearance, or the temporary suspension of enforcement actions by an agency. The FTC's guidance is significant not just for what it says, but for what it leaves unsaid.


Getting Age Assurance Right: A Risk-Based Framework for High-Risk Online Features