Assigning Responsibility for Age Assurance: Recommendations for Youth Online Safety

KGI’s Assigning Responsibility for Age Assurance examines how policymakers can allocate responsibility for age assurance across the digital ecosystem. It provides practical recommendations for assigning age assurance obligations in ways that support youth online safety while appropriately accounting for tradeoffs involving privacy, competition, accessibility, and openness.

Download PDF

As governments around the world increasingly adopt age assurance requirements intended to make online experiences safer for young people, a key policy question is how responsibility for age assurance should be allocated across the digital ecosystem.

Establishing a user’s age and using that information to provide age-appropriate online experiences involves a series of related functions, including assessing a user’s age, communicating age information to the relevant service, and implementing the protections, defaults, or restrictions associated with that age signal. These functions can be carried out by different actors – including app developers, operating system providers, app stores, device manufacturers, and dedicated age verification providers – with important implications for privacy, service availability, competition, and resistance to circumvention.

KGI’s Assigning Responsibility for Age Assurance: Recommendations for Youth Online Safety examines how responsibility for age assurance should be allocated for the case where age assurance requirements are imposed to establish safer defaults for youth. The brief argues that, regardless of how users’ ages are assessed or communicated, app developers should retain primary legal responsibility for ensuring that the age information they rely on to apply age-appropriate settings satisfies applicable legal requirements.

This brief complements KGI’s Age Assurance Online, which assesses existing age assurance technologies, and Age Assurance Rules: An Implementation Guide, which provides broader recommendations for designing effective implementation rules.

The brief offers five recommendations to help policymakers assign responsibility for different age assurance functions to the appropriate entities:

  • Assign responsibility for complying with youth safety requirements to app developers. For safer defaults use cases, legal mandates should put the responsibility for meeting youth safety requirements – including the adoption or reliance on age assurance systems sufficient to meet those requirements – on the entities that are in a position to act on age information most directly: app developers.
  • Focus device intermediary obligations on operating system providers. Focusing on a single type of intermediary avoids overlapping or duplicative obligations, and operating systems already serve the general purpose of signaling user or device information to apps.
  • Limit age assurance obligations on operating system providers to supplying robust privacy-preserving age signals to apps that request them. Age signaling obligations imposed on operating systems should be limited to developing the capability to transmit a privacy-preserving age signal, only when necessary, and with technical privacy guarantees whenever feasible.
  • Restrict age assurance requirements on operating system providers to mobile device operating systems only. Targeting mobile environments focuses interventions on the contexts where youth are most likely to experience harm.
  • Do not undermine competition in app distribution. If policymakers impose age assurance obligations on app stores, those requirements should not assume that operating systems and app stores are controlled by the same company, nor should they create incentives that favor such arrangements.

Age assurance can play a role in supporting safer online experiences for young people, but only when implemented in ways that are responsive to the harms being addressed and that appropriately balance the benefits of age assurance against the costs to privacy, service availability, competition, and openness. As policymakers continue to explore age assurance mandates, new obligations should ensure that responsibility for youth safety requirements remains with app developers, as they are the actors best positioned to prevent harm.

Where policymakers choose to involve device intermediaries, such as app stores, operating system providers, or device manufacturers, their role should be narrowly tailored to transmitting privacy-preserving age signals to services that have a legal obligation to act on them. By drawing on these recommendations, policymakers can better support effective age assurance while avoiding unnecessary tradeoffs. Policies that extend beyond this limited role risk creating significant costs for privacy, competition, and open technology ecosystems without meaningfully improving protections for youth.

Resources

Age Assurance Online
Age Assurance Online Report Overview
Age Assurance Rules
Assigning Responsibility for Age Assurance

Close