Google's Age API Avoids ID Uploads — but It Still Won't Stop Determined Teenagers
Key Takeaways
- Google is expanding its Play Age Signals API globally, allowing app developers to access age range data for child accounts without requiring ID uploads or selfie verification.
- The system relies on parents setting age ranges in Google's Family Link app — it's fully opt-in and can be turned off at any time, meaning it won't catch every minor.
- The rollout is partly a compliance response: Texas, Louisiana, and Utah have passed laws requiring app stores to implement age verification, and the US Supreme Court has paused a lower court injunction allowing the Texas law to take effect.
- Google itself acknowledges the system won't stop determined minors who create alternative accounts or simply don't have parents who bother setting it up.
Google is beginning a global rollout of its Play Age Signals API, an age verification system for the Play Store that, notably, doesn't require anyone to upload a government ID or take a selfie, according to reporting by Ars Technica.
Instead, it's built on top of Google's existing Family Link app: parents set an age range for their child's managed account, and apps can query that range to tailor content and experiences accordingly. The ranges are dynamic, updating as kids get older. And crucially, it's opt-in — parents choose whether to share age data, and can turn it off at any time.
Despite how age verification evolved online, this is worth acknowledging as a meaningfully different approach from what we've criticized in most age verification legislation. The systems embedded in laws like Iowa's adult content law, or proposed under the KIDS Act, typically require identity documents — government IDs, biometrics — processed by third-party verification vendors.
Google's API moves that requirement one step back: it relies on a parental account relationship that parents have already established, rather than demanding fresh identity documentation from every user. That's a more proportionate design.
The rollout is partly driven by compliance pressure. Texas, Louisiana, and Utah have passed laws placing age verification obligations on app stores, and the US Supreme Court recently paused a lower court injunction, allowing the Texas law to take effect. Google began testing the API in Brazil last year as it became clear these laws were coming. Australia and Canada are next for the rollout, with full global availability expected by the end of 2026.
What it doesn't solve — and what that tells us
Google is candid about the limits. The system won't stop determined minors: kids can create alternative accounts, lie about their ages, or simply use a device that isn't connected to a Family Link account. Not all parents will bother setting age ranges. The company acknowledged this directly in its announcement.
That honesty is useful, because it cuts to the core of the problem with age verification as a policy tool. The most compliant, privacy-respecting implementation — the one that avoids ID uploads, relies on existing parental infrastructure, and lets parents opt in rather than forcing everyone to participate — still doesn't reliably keep determined teenagers away from content they're motivated to access. What it does do is create a friction point for casual access, and that has some value.
But the gap between "creates friction" and "reliably verifies age" is the gap that legislators consistently paper over when they pass these laws. Texas's law requires developers to actively use age-gating features — meaning it's not enough for Google to offer the API; developers have to implement it. And if a determined minor just creates a new account and lies, the entire infrastructure exists primarily to create compliance documentation rather than to change behavior.
I think Google's approach is the least bad version of something that is structurally limited regardless of how well it's designed. The underlying demand — verify the age of every internet user before granting access — isn't a technical problem waiting for a better solution.
It's a policy objective that trades everyone's privacy for a safety gain that the evidence consistently shows is marginal at best.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
