Home

Donate
Perspective

Age Verification is an AI Cybersecurity Problem

Logan Kolas / Oct 1, 2026
Republish

During testing evaluations with safeguards turned down, two OpenAI models silently bypassed the security guardrails in their testing environment, hopped onto the open internet, and attacked the open-source company Hugging Face. As reporting rolled in, politicians were alerted to an AI future of elevated cybersecurity risk. What they are yet to discover is how that risk may soon expose the privacy and cybersecurity downsides of laws designed to protect children online.

For years, privacy advocates warned that age verification laws risk exposing users’ most sensitive data. When consumers access these apps, companies or the vendors they contract with must first determine whether the user is underage. Adults and parents must prove they are not kids. In many cases, this requires users to turn over sensitive personally identifiable information to companies—driver's licenses, birth certificates, passports, even selfies.

As this data exchanges hands, it increases the attack surface by creating honey pots of data hackers can target and exploit. Even the most privacy-protective technological techniques, like zero-knowledge proofs, can leave a “goldmine for hackers” earlier in the verification chain, because they still require identity checks.

The European Union offered one of the clearest examples of this supposedly privacy-protective model in action. European Commission President Ursula von der Leyen introduced an app that uses zero-knowledge proofs, so platforms see only cryptographic proof that a user is of age—only after setting up the app with government-issued ID or similar credential—and concluded that platforms have “no more excuses.” Unfortunately, security consultant Paul Moore claimed to be able to hack a public version of the app in less than two minutes.

Age assurance is similarly flawed because estimates fail and users can often only appeal by turning over their sensitive data. Hackers infamously breached Discord’s third-party vendor, exposing about 70,000 government-issued IDs that consumers forked over to appeal automated age estimates that erroneously flagged them as possible minors.

Those numbers, while significant, harmful, and newsworthy, pale in comparison to the 153 million US and Canadian driver’s license scans a dark-web service listed earlier this month, which were reportedly traced back to the Louisiana-based company IDScan.net. The company acknowledged in a notice earlier this month a data security incident where an unauthorized third party may have accessed or copied customer information in its cloud. The breach has not been tied to social media age verification laws–IDScan.net’s core business model is in-person and retail age verification–but the company may have a commercial interest in online age verification given that they sell remote ID checks and track state age verification bills.

Now, in a world of rapidly advancing AI technologies, traditional barriers to cyberattacks are falling. These new tools make it easier than ever for low-sophistication attackers, and even partially autonomous cyberattack operations, to breach improperly stored datasets, exposing just how much user data sits unprotected online. In the last year, 71 percent of organizations have experienced at least one identity-related security breach. A quarter of total malicious breaches are now AI-enabled.

Adults are harmed when their data is leaked, but kids suffer more. Unlike adults, children rarely monitor their credit scores or personal information, which gives hackers more years to create “synthetic identities” that are often only discovered after the child becomes an adult and applies for financing—car leases, apartment rentals, mortgages, student loans.

To combat the privacy challenge, many companies are turning to AI-powered age estimation techniques, which require companies or vendors to collect biometric information like selfies or videos to verify ages. Although age estimation techniques often collect less data than full ID checks, when biometric data is breached, the consequences are more severe: facial structures and biological factors are lifelong identifiers that do not change, which leave kids susceptible to lifelong AI-driven harms like deepfakes and impersonation scams.

After years of debate, more than half the states have codified an age verification law, especially for adult content. Social media laws, meanwhile, have mostly been tied up by courts in First Amendment litigation. But multiple laws have been enacted as courts allowed enforcement while they are under judicial review.

If the dam breaks, more age-verification laws will come online, and information accumulation will put America on a collision course with its newly discovered AI-augmented cybersecurity reality.

Sadly, that outcome may be unavoidable regardless. As courtroom decisions replace prudent policymaking, industry will increasingly turn to age checks as legal cover and as a pressure release valve from social media anxiety.

The hope is that age verification technology will soon improve to a point where companies need not collect any consumer information to completely and accurately verify user ages without severe cybersecurity downsides. But that world does not yet exist.

So it falls to the states to harden their networks against growing AI cybersecurity risk. That will involve the normal protocols: stress testing, employee training, and real-time security patches. But it must also involve more advanced cyber defense: states must vet their existing laws for impediments to cybersecurity, and where the government runs a system–or requires vendors to store sensitive consumer data, like IDs or selfies–that system should have in place protocols and standards for autonomous, AI-powered cyber breach detection and defense.

Even those measures will be imperfect and susceptible to workarounds. In the end, the only way to guarantee that all consumer data is protected from the growing threat of cybersecurity breaches is not to collect it in the first place.

Support Tech Policy Press
If you've found our work helpful, consider supporting us.

Authors

Logan Kolas
Logan Kolas is the Director of Technology Policy at the American Consumer Institute, a nonprofit education and research organization.

Topics

Related

Analysis
When Age Gating Puts User Privacy at RiskJanuary 14, 2026
Perspective
How Offline ID Checks Could Help Solve the Age Verification Head-ScratcherJanuary 7, 2026