You already own the phone. The operating system account came with the setup screen, and I signed into mine the same day I paid for the hardware. Senators Andy Kim, Adam Schiff, Cynthia Lummis, and John Barrasso want that account to carry your age, converted into a bracket, and they want covered apps, browsers, stores, and websites to request that live signal as the primary way of knowing how old you are.
The ID check moves off the porn site and into the machine sitting in your pocket.
The Silicon ID Card
Their vehicle is S. 5090, the Digital Age Assurance Act of 2026. Kim introduced it with Lummis, Schiff, and Barrasso on July 22, and it sits with the Senate Committee on Commerce, Science, and Transportation. A covered device in the text is a computer, a mobile device, or any other general purpose computer that can run an operating system. On a phone or a PC, that software comes from Apple, Google, or Microsoft, and the bill would make it emit the signal from a machine you already paid for.
To use the operating system, you have to establish an account that indicates your date of birth and your age. Existing accounts get pulled in too, unless the provider already has your age on file for a legal duty, its own terms, or a purchase. The operating system converts that age into four brackets: under 13, ages 13 through 15, age 16, and age 17 or older. It does not share the exact birthday. It emits a real-time signal through an application programming interface. Where it is technically feasible, that signal can ride a verifiable credential or a zero-knowledge proof.
Account holders under 17 have to link that operating system account to a parent or legal guardian account. The parent can view the child's bracket. Applications, browsers, application stores, and covered websites must request the signal and utilize it as the primary indicator of the user's age. A covered website, in the text, is a site already required under federal or state law to verify age before it lets you in. Those sites still have to ask the operating system, so the answer lives in the phone.
Enforcement sits with the Federal Trade Commission and state attorneys general. Civil penalties run up to $2,500 per negligent violation and $7,500 per knowing or intentional violation, and those fines can be multiplied by the number of children affected.
What the Phone Has to Say
Senator Lummis sold the bill as the version that keeps government IDs and facial scans out of the equation. The text matches that pitch on paper. The bill bars requiring a government-issued identification document, biometric information, or facial age estimation to generate the signal. A developer or covered website operator can request the standardized bracket and nothing more, and cannot hand that bracket to a third party. The same Act bars using the bracket for profiling or engagement optimization. Targeted advertising is unlawful toward a user the operator knows, or reasonably should know, is a child, and child here means under 17. Children's personal data cannot be transferred to data brokers. Contextual ads that do not rely on personal data stay allowed.
Here's the thing: moving the checkpoint into the operating system changes your relationship with the machine you bought. Once the requirement lives in the Apple, Google, or Microsoft ecosystem you already run, the hardware you paid for is the thing that has to vouch for your age before a covered app, a browser, a store, or a website will treat you as an adult.
Four age-verification bills are in Congress. The App Store Accountability Act and the Parents Over Platforms Act put the job on app stores. The Digital Age Assurance Act and the Parents Decide Act, H.R. 8250, put it on the operating system. An app-store rule stops at what you install. S. 5090 sits under the browser, so the same service you open in a tab still has to ask the phone. Browsers pull the live signal the device is already carrying and pass it to covered websites.
The Floor That Will Not Stay Still
The bill also creates a legal tripwire for the services you visit. Once a developer or covered website receives the operating system signal, it is deemed to have actual knowledge of your age bracket across every platform and point of access for that app or site. The Children's Online Privacy Protection Act already piles extra duties on anyone who knows a user is under 13. S. 5090 does not preempt COPPA.
The Digital Age Assurance Act also refuses to lock the states out. The App Store Accountability Act and the Parents Over Platforms Act fully preempt state age-verification laws. S. 5090 only preempts laws that conflict with it, and it lets states pass rules that are more restrictive, so the national OS signal still has to fire while the patchwork on top of it keeps growing.
Clear and convincing information that conflicts with the operating system signal triggers a process. Notice goes to you or a linked parent. There is a chance to correct it. The operating system is supposed to send a new signal, and the operator then has 30 days after a correction to issue a determination.
You can delete the account later, and the bill says the operating system must deidentify or securely delete the age data then. The Federal Trade Commission has a year after enactment to write rules, and the Act takes effect 18 months after it is signed, which means the bracket is not live today and the duty is already written: using the operating system I already run would require the account that carries it.
0 comments