Key points
- The Internet Architecture Board warns that age assurance relying on service provider checks will fail and leave youth less safe online.
- IAB says device-based mechanisms, such as those already shipped by Apple and Google, are currently the most promising approach to age checks.
- The board's concerns echo Australia's social media ban for under-16s, where a study found children using social media as frequently as before.
The Internet Architecture Board (IAB) says it is concerned that age assurance approaches that rely on service provider checks will not only fail, but also leave youth less safe on the internet.
IAB, which provides long-range technical direction for the internet's development since 1979, said age checks are better done on users' own devices than on the services they visit.
That assessment is tied to where the technology currently stands, but not a fixed conclusion.
Many current efforts frame age restrictions as something service providers or network infrastructure must enforce, the IAB said.
The IAB statement names no particular jurisdiction, but the architecture it describes is the one Australia legislated.
Among the concerns of the board is the creation of unproven new infrastructure such as third-party age assurance services that will concentrate sensitive data about everyone into a small number of high value targets.
"Requiring individual sites to collect such data reduces online privacy and increases risks of identity theft," IAB said in its first formal position on age assurance.
Other approaches such as blocking access to services that don't perform age checks requires visibility into internet traffic to identify which ones to block.
This would put pressure on encryption that users, commercial entities and governments rely on.
Youth routing around age assurance via service providers and networks are also exposed to cybersecurity risks if they use free virtual private networks (VPNs) of unknown provenance, shared or fraudulent credentials, or grey-market apps, IAB noted.
IAB also warned that as service-level age check mandates differ significantly between jurisdictions, they fragment the internet, and make it less global.
"Because today’s age-assurance proposals are largely vendor offerings certified against regulatory criteria, system-level properties like resilience, privacy, and decentralisation often escape scrutiny," IAB said.
Earlier this month, the Australian government mounted a defence of its social media ban for children under 16 which includes A$49.5 million penalties for non-compliant providers.
A study by the eSafety watchdog found that children aged 10 to 15 were using social media as frequently as they had before it was introduced on December 10 2025.
Device-based age checks available from Apple and Google
Given the current maturity of enabling technologies, mechanisms built into a user's own device are the most promising approach, the IAB said.
In principle, the IAB said, an age signal established on the device can confirm a user is old enough to reach some content without disclosing their identity to every site, without those checks becoming linkable across sites, and without concentrating sensitive data into a handful of breach targets.
The board's advice to policymakers follows from that assessment, but sits apart from it.
Mandates should specify outcomes rather than particular technologies, the IAB said.
This enables better mechanisms to be adopted as they mature, and should require open, interoperable interfaces so no single vendor or platform becomes indispensable, it added.
Both Apple and Google have shipped age-checking mechanisms, although these are not open standards.
Apple's Declared Age Range application programming interface (API) returns an age band rather than a birthdate; it is available in Australia, Brazil, Singapore, Utah and Louisiana.
Google's Play Age Signals API works in a similar fashion through the Family Link feature and is available in Australia too.
Microsoft, meanwhile, is working with age assurance partners Yoti and Verifymy for its online stores, to allow users to reach 18-plus rated content.
This lets users choose between a facial age estimation, official document scan, a credit card or email based verification with mandatory enforcement beginning this month.
Meta this week settled with nearly all US states, and agreed to pay up to US$18 billion over the next decade as well as restricting teenagers' use of Facebook and Instagram to two hours a day, blocking all access from midnight to 6am unless parents consent to it.
IAB held a multi stakeholder workshop on age-based restrictions in October last year, together with the World Wide Web Consortium (W3C).
It published a report on the workshop as the Request for Comments (RFC) 9998 document, assembled by Cloudflare standards lead Mark Nottingham and Mozilla engineer Martin Thomson, both located in Australia, who chaired the meeting.
Listed workshop participants included representatives from Apple, Vodafone, UK's Ofcom and National Cyber Security Centre (NCSC), along with United States and European universities and digital rights advocacy organisations and staffers from age verification companies.

Integrate 2026
Security Exhibition & Conference
NiCE World APAC 2026
iTnews State of Security Breakfast Melbourne
NiCE World APAC 2026



