Editor’s Note: This article was first published in Future Forward, Volume 1, No. 2.
The world is as digital as it has ever been, with huge parts of our lives now resting online. Our connections, friendships, jobs, education, and entertainment all exist there in one way or another.
And for years, age verification online was kept plain and simple. A game or website would ask for your birthday. You input it, whether it was the real one or not, and if the date marked you as old enough, that was usually enough to enter.
That era seems to be on the edge of disappearing as governments now increasingly pressure online platforms to actually know the legitimate age ranges of the people behind their accounts.
Gaming is getting pulled into that conversation too as games become more than just places to play. Games now act like social networks, with voice chats, direct messages, livestreaming, marketplaces, virtual currencies, and user-generated content where children and adults can interact.
With these kinds of inevitable intertwining in ages, protecting younger players in these spaces becomes necessary.
But we now have to uncomfortably ask what players might have to give up just to prove how old they are.
Games already know a lot about us
Modern games already generate enormous amounts of behavioral information.
Research published in the Fordham Intellectual Property, Media and Entertainment Law Journal found that gaming platforms can collect information through cameras, microphones, sensors, social features, cookies, location services, and other technologies.
A separate study published in Entertainment Computing found that gameplay data can potentially reveal or help infer a player’s age, interests, skills, emotions, consumption habits, and personality traits.
Think about how much a game can learn simply by watching you play.
How long do you stay online? What do you buy? Who do you play with? Which modes keep you engaged? When do you quit?
Now add a government ID, facial scan, mobile number, or payment information into that ecosystem, and a dilemma now begins to form.
These companies already know a lot about how we behave online, so how comfortable should we be giving them even more? Can we really assume all of that information is being used purely for the user’s benefit and not for profiling, monetization, or purposes we never really agreed to?
Getting ID’ed to play online and why
Stricter forms of age verification may ask users for government identification or verification through a financial institution or mobile provider. Other systems can use selfies and AI to estimate whether someone falls within a certain age range.
It is no longer simply clicking, “Yes, I am 18”, because platforms increasingly need some reason to believe you actually are.
It would be easy to frame all of this as governments simply invading privacy, but that ignores legitimate concerns about why these rules are appearing. Online games can connect children with strangers, expose them to inappropriate content, facilitate spending, and provide communication tools that can be abused.
The UK has been particularly aggressive in addressing these risks through its Online Safety Act and subsequent child-safety measures. The direction of policy is increasingly focused not only on what children can access but also on what features they should be able to use.
A teenager might still be allowed to play a game while communication with strangers or other higher-risk features are restricted based on age.
That is more nuanced than simply banning a game, and that nuance matters.
But for any of this to work, platforms first need some reliable way of determining whether a user is actually a teenager.
So how do you prove someone’s age without learning too much about them?
Protecting privacy by collecting more information, they say
It is a little ironic asking users to surrender sensitive information in the name of privacy and safety.
It is like asking somebody to give you their house keys so no strangers get in their home.
Uploading an ID creates another valuable piece of information that needs to be processed, secured, and eventually deleted properly away from the user’s hands. While facial age estimation avoids handing over an identification card, it introduces biometric concerns of its own.
Third-party verification complicates things further.
Even if the game itself never sees your passport, another company may still have to process it. That means placing trust in whoever handles that information.
PC Gamer highlighted this concern while examining the UK’s age-verification rollout. Collections of sensitive verification information can become attractive targets for attackers, while fake verification pages can trick users into voluntarily submitting IDs or facial images.
A system that is supposed to make people safer can itself become a target when implemented poorly or when handed to the wrong people.
All this possible compromise because of information we think age verification needs.
Prove my age, not my identity
A game generally does not need to know my real name, home address, passport number, and exact birthday. It just needs to know whether I am old enough.
That should guide where age verification goes next.
Privacy-focused systems can use data minimization, where a verification provider processes whatever information is necessary but only gives the game the answer it needs.
Instead of:
This is Juan Dela Cruz, born on this date, with this government ID.
The platform should ideally receive:
This user is over 18.
Technologies such as zero-knowledge proofs could push this further by allowing users to prove something is true without revealing all the information behind that proof.
The platform gets its answer.
The user keeps more of their data.
That sounds considerably better than uploading copies of IDs to every game, social network, and website that asks in the name of “safety.”
Safety shouldn’t require knowing everything
Stronger age-verification systems will continue appearing as more responsibility is placed on developers and platforms to protect younger users, and that is not necessarily a bad thing.
The old birthday box was never much of a safeguard anyway, but replacing an ineffective system with one that demands unnecessary amounts of personal information simply creates a different set of problems.
Platforms need a middle ground where enough information can be processed to distinguish children from adults without turning every player into a fully identified profile.
Safer games and keeping privacy do not have to come at the expense of one another. Ideally, platforms should only need us to prove what is necessary, without asking for everything else.
