The global push for stricter regulations is reshaping how technology companies handle user data, especially when it comes to verifying the ages of users online. This effort aims to protect children from online risks, much like past attempts to create backdoors in encrypted systems for law enforcement. In recent years, several countries have introduced laws requiring operating systems and app developers to collect and transmit age-related data without revealing exact birth dates. In the United States, states like California, Illinois, and Colorado are leading the charge with new legislation. California’s Digital Age Assurance Act, set to take effect in 2027, requires operating systems to share a user’s age range with apps. Similar laws are being considered in other states, and at the federal level, the bipartisan Parents Decide Act aims to make age verification a standard feature across all new devices. Across the Atlantic, the European Union is focusing on digital identity through the eIDAS standards, which push for operating systems to integrate digital identity wallets. Meanwhile, Australia and the United Kingdom have also introduced strict mandates that indirectly push Apple and Google to implement these features at the operating system level. To comply with these regulations without disrupting user experience, major tech companies are developing advanced systems. Microsoft, for example, launched an Age API in 2026 that allows operating systems to verify a user’s age once and then send a simple, encrypted signal to apps. Digital identity wallets, such as Apple Wallet and Google Wallet, allow users to store official ID cards, enabling instant verification. Additionally, biometric technologies like facial recognition are being used to estimate age through AI, without storing personal data. These methods have been approved by regulatory bodies like the UK’s Ofcom. However, these systems raise significant privacy concerns. Users may be required to provide personal information, such as scanned IDs or undergo facial recognition, which could expose them to identity theft or fraud. Past data breaches, such as the exposure of 20 GB of personal data involving webcam models and the theft of 1.4 million coronavirus test records, highlight the risks of mishandled personal information. Once such systems are in place, governments could expand their use to verify other details, like location, potentially limiting access to services based on geographic restrictions. Edward Snowden has warned that these data collection practices, even those introduced for public health or safety, could lead to long-term surveillance infrastructure. He emphasized that once these systems are built, they can be expanded in ways that may infringe on personal freedoms. As governments seek to protect children online, the question remains: How much privacy should be sacrificed to ensure public safety?