Determining a user's age online has become central to youth protection policy. Social media companies now face mandates to deliver tailored features, usage caps, and notification restrictions based on whether users are minors. The practical success of these protections hinges on how platforms verify age—making the technical and procedural rules governing age assurance systems a critical implementation question.

Across the United States, these rules are taking shape through statutes, agency guidance, and court orders. A multi-state settlement with Meta last month set out detailed age assurance requirements the company must follow. California lawmakers recently approved legislation that would restrict certain engagement-driving features for users under 16, with implementation details still being drafted by state officials. These developments signal a fundamental shift: as youth online safety rules spread, authorities must grapple with harder questions about how age assurance should function, how to measure its effectiveness, and how to enforce compliance when systems fail.

New York has moved ahead on many of these fronts. The state's Stop Addictive Feeds Exploitation (SAFE) for Kids Act, enacted in 2024, tasked the New York Attorney General with drafting rules for how companies verify user age. The law aims to curb social media platforms' deployment of habit-forming features for young people. On July 28, the Attorney General released final rules that spell out requirements for how age assurance systems must perform, be tested, and be overseen. As similar frameworks emerge elsewhere, New York's approach offers an instructive early example—along with lessons about what future versions should improve.

New York's rules lay important groundwork. They reject the notion that age assurance can be a one-time box to check, completed by companies with minimal oversight. Instead, they call for continuous assessment of company systems against multiple benchmarks that weigh efficacy, user access, privacy, and other concerns. The rules also empower independent auditors, government agencies, and other parties to assess how well these systems work and hold companies accountable.

Yet the framework has notable shortcomings that other jurisdictions should address. Future rules ought to penalize false denials of access to eligible users more heavily, evaluate age assurance systems as integrated wholes rather than isolated components, and require public disclosure of how these systems perform in the real world. Closing these gaps will enable policymakers elsewhere to strengthen New York's model and create more robust age assurance governance.

The rules acknowledge that age assurance involves tradeoffs among competing goals

New York's rules implicitly recognize that age assurance should not aim solely at blocking minors from restricted content, but should weigh that goal against privacy, service availability, and inconvenience to adults. For example, platforms offering government ID-based age verification must also provide at least one alternative method that does not require ID. If all non-ID approaches yield unclear results, users who refuse to share government ID can pursue an appeal instead. This acknowledges that while government IDs offer strong age signals, many users lack them or prefer not to disclose them.

The rules also permit a user to be treated as an adult when two conditions hold: every age assurance method returns an inconclusive result, and the operator has no other evidence the user is a minor. These provisions show that New York does not treat accuracy as the sole objective, but balances it with access, user autonomy, and privacy.

Future rules should embed this balance more systematically

Upcoming rules could more thoroughly integrate consideration of competing values throughout their requirements. Under New York's rules, platforms are not generally required to offer users multiple age assurance options, even though different methods carry different privacy, accessibility, and usability costs. Mandating multiple options should become a standard baseline.

Rules should set accuracy standards for both false positives and false negatives

New York's rules require age assurance methods to meet accuracy thresholds for false acceptances (minors wrongly classified as adults) and to resist circumvention by minors. They do not, however, impose equivalent standards for false rejections (adults wrongly classified as minors). This creates an incentive for operators to deploy methods that are more likely to deny adults and other eligible users access to age-gated features. In reality, platforms must weigh access against the expense and complexity of offering multiple methods. Compliance with the rules should not be assumed to automatically push all operators toward sufficiently accurate age assurance.

New York does require that false rejections be measured during certification and that users have a way to appeal incorrect decisions. Requiring multiple methods and setting false rejection standards would better align availability with safety.

The rules set performance standards for individual age assurance methods

A key strength is that the rules establish concrete performance benchmarks for individual methods and mandate specific testing and annual third-party certification to verify compliance. Method-level standards prevent operators from relying on untested, convenient, or easy-to-deploy approaches that perform poorly in actual use. This matters especially when operators offer users only one or two options, making each method's performance critical to user success.

Future rules should measure end-to-end system performance more rigorously

Beyond individual method accuracy, future rules should establish comparable end-to-end performance standards and testing requirements for the full suite of methods a platform offers. This is essential because the overall accuracy of systems that route users through multiple methods cannot be deduced from individual method performance alone. A platform could meet requirements for each individual method yet still perform poorly overall due to how those components interact in real-world scenarios.

Beyond accuracy, New York's rules specify a quantitative circumvention detection target of 98%. Yet circumvention rates only have meaning within a specific context of circumvention techniques tested. Since some techniques are more potent than others, and defending against them involves different privacy and openness tradeoffs, any circumvention measurement inherently depends on which techniques are tested and how often. For this reason, future rules should employ qualitative circumvention detection and mitigation standards built into the certification process. These could require platforms to address the most widespread circumvention risks appropriately.

The rules establish a strong accountability framework

The rules recognize that effective age assurance demands more than a single compliance review. They construct a layered accountability system in which operators monitor continuously, accredited third parties conduct independent audits, users can dispute incorrect classifications, and information about newly discovered circumvention methods can originate outside the company and trigger further review. This structure allows operators to refine their age assurance systems as implementation unfolds and creates accountability mechanisms that do not depend solely on self-policing.

The rules are poised to generate substantial data about how age assurance systems operate in real deployments. Certification reports must document testing methods and findings, including false acceptance rates, false rejection rates, inconclusive results, and circumvention testing. Operators must also preserve certain data, such as monthly method attempts and monthly denials tied to circumvention.

Accountability information should be disclosed publicly

Neither certification reports nor operators' ongoing assessments are required to be released to the public. Consequently, much of what companies and auditors discover about age assurance successes, failures, and user impacts stays within those organizations, the auditors, and the Attorney General's office. Researchers, advocacy groups, and the broader public cannot independently evaluate these findings.

This gap matters because age assurance remains an emerging policy and technical domain, and real-world implementation will generate evidence that could inform future rule revisions, regulatory decisions, or system improvements. If results stay confidential, the public lacks a foundation for assessing rule effectiveness, and independent experts cannot contribute analysis to the Attorney General's enforcement work. Future rules should mandate that certification reports contain all data needed for independent age assurance evaluation and be made publicly available.

Conclusion

New York's rules represent an important early template for converting age assurance mandates into specific, enforceable rules. As courts, agencies, and legislatures tackle the same implementation questions, they can draw on New York's strengths while addressing its limitations—particularly regarding the balance between access and other priorities like privacy and user burden, assessing how age assurance systems function as unified wholes, and fostering transparency and independent review. Refining these elements will determine whether age assurance becomes a genuine tool for youth online safety or merely another compliance checkbox.

Source: Tech Policy Press