Protecting teens online shouldn’t require mandatory facial scans for digital users
Laws aimed at protecting minors online are pushing social media companies to verify age more aggressively, and facial age estimation has become one of the most appealing tools for doing that. Platforms must distinguish between children, teenagers, and adults with more certainty, making selfie-based checks and backup ID requests look like practical ways to show compliance. However, this is quickly shifting a broad policy problem into a biometric one, where access to ordinary online services can depend on literally showing your face.
While facial age estimation may offer platforms a convenient way to respond to youth online safety demands, that convenience comes with serious privacy costs. Required facial scans lower the baseline of privacy for everyone, especially teens, and create a regime where access to everyday social spaces depends on individuals surrendering sensitive information about their faces and, in many cases, their identities. If lawmakers continue to enact youth safety laws that pressure companies to apply facial scans in ways that may conflict with existing biometric laws, they risk creating a system that may protect teens in ways while exposing them, and everyone else, to long-lived surveillance and data trails that are difficult to escape.
How facial scans work and where they are being used
On social media, age assurance is increasingly centering on age estimation, in which users capture a selfie or short selfie video with their phone, and the system estimates whether they appear above or below key thresholds like 13, 16, or 18 years old. Platforms use that result to allow changes, block accounts, or impose teen settings. Supporters, including many regulators and some youth online safety advocates, describe the method as faster and less burdensome than asking every user for an ID. Vendors also say they estimate age rather than identify people, delete facial templates quickly, and keep selfies only briefly for limited support or fraud purposes. Even so, platforms and vendors may keep logs showing when checks occurred, what methods were used, and how accounts were categorized, and those records can be tied back to account identifiers long after the facial data is gone.
Meta’s implementation of Yoti, a digital identity and age assurance company, on Instagram and Facebook shows how this works. If Instagram believes an account holder is under 18 years old and the user tries to change that, it can send that user to Yoti for analysis of a selfie video. Yoti then estimates whether the person appears to be over 18 and sends that result back to Meta. Its tests have expanded across the United Kingdom, Europe, Canada, Australia, and Japan, and similar flows have begun appearing on Facebook in Australia. Yoti also presents facial age estimation as part of a broader age assurance system that can include document-based checks, while highlighting that it estimates age rather than identifying the person.
Data privacy and de-anonymization risks for users
Requiring facial scans for age estimation or verification raises several privacy concerns. It forces users to surrender body-derived information to access what is now part of ordinary online life. A selfie or selfie video may capture a user’s face, surroundings, and sometimes other people, and the system then converts the face into a numerical representation, often described as a template or embedding, so it can estimate age. Even if that representation is deleted quickly, the scanning process still changes what the platform knows and what it can record about them.
The data trail can extend well beyond the initial scan, which also makes the system a cybersecurity target. Selfies can be stored for days or weeks, logs of checks and outcomes may be retained much longer for compliance and auditing, and failed checks may push users into uploading a government ID or other backup document. In practice, that can leave behind a long-lived record of who was checked, when they were checked, what they were told, and how they got through the process.
In October 2025, hackers accessed a third-party verification vendor and exposed over 70,000 user IDs and personal documents of users of the chat and media platform Discord. The records came from users who had been flagged as under 18 after a face-based or similar age check and then uploaded their ID on appeal to prove they were over 18. Discord began using that verification process to comply with the United Kingdom’s Online Safety Act, which had taken effect three months earlier. Age-check records, ID uploads, and related logs create an ongoing data security risk after the original assurance step is over. Compliance systems can also become a honeypot when age screening depends on third-party vendors and support workflows.
Facial age estimation also does not fully eliminate the risks associated with facial recognition. The underlying templates are designed to capture stable aspects of a face that allow comparison and inference, and research on facial embeddings shows that these representations can support re-identification and, in some cases, face reconstruction when they are preserved and matched across datasets. When those templates, selfies, or logs are tied to account identifiers and combined with signals like friend networks, location data, and content history, they can help build a far more detailed picture of a user’s identity and behavior online.
The normalization of facial age checks also shifts expectations around online anonymity and pseudonymity. When access to a service or otherwise legal content depends on submitting a face image, users have fewer ways to participate without connecting their identity to their real-world identity, which can chill anonymous access and raise First Amendment concerns. Teenagers have First Amendment rights online, too, including the right to access otherwise legal speech and to use platforms to speak and receive information. That pressure affects everyone, but it may be felt most strongly by teenagers, who are the group most often asked to prove who they are and how old they are before they can continue using a platform. It also burdens adults who must scan their face simply to prove they are old enough, especially when a system mistakenly flags them as under 18 and forces them to appeal.
Legal practices and emerging tensions
Biometric privacy laws already treat face data as sensitive and place meaningful limits on how companies can collect, store, and use it. In Illinois, Texas, Washington, and other states, businesses generally need consent before collecting biometric information, and they must limit disclosure and destroy the data once the original purpose has been met or the retention period has ended. These restrictions frame facial data as sensitive information that should be tightly controlled rather than held indefinitely or reused for related purposes. They also make companies think carefully about how long to keep biometric records and what exactly they do with them after age checks are completed.
At the same time, youth online safety laws are putting more pressure on platforms to identify minors with greater certainty. California’s Age-Appropriate Design Code and similar state measures encourage businesses likely to be accessed by minors to estimate users’ ages with reasonable certainty or apply child-friendly defaults to everyone. Proposed state and federal youth safety laws, such as the KIDS Act currently in Congress, add more pressure by requiring reasonable age assurance without requiring a specific method. International rules have also helped make facial age estimation more common because United Kingdom and Australian laws have both encouraged age assurance tools that include facial scanning. As a result, companies have more reason to adopt facial age estimation as a practical compliance tool, especially when they want a method that works at scale.
Together, these laws push companies in opposite directions. Biometric rules push them to collect less face data and keep it for shorter periods, while youth safety laws push them to assure age more aggressively and retain records showing what steps were taken. Facial age estimation keeps gaining traction even though it raises the privacy concerns that biometric laws are meant to reduce. In theory, strong biometric and privacy laws could limit these systems and push platforms toward the least intrusive methods. But in practice, the unresolved space between proving age and collecting less data is exactly where companies are building new, more invasive age assurance infrastructures.
Lawmakers should proceed carefully
Facial age estimation may help platforms satisfy age-related rules, but it does so by making face scans a more routine part of online access. Lawmakers should avoid enacting laws that pressure companies to use facial scans as a default to estimate age, especially for teenagers. Facial scans, like government ID requirements, create serious privacy risks by requiring people to hand over sensitive personal information just to access ordinary online spaces. Turning age assurance into a biometric checkpoint risks making online access less private, less secure, and less open than the problem lawmakers are trying to fix.
The post Protecting teens online shouldn’t require mandatory facial scans for digital users appeared first on Reason Foundation.
Source: https://reason.org/commentary/protecting-teens-online-shouldnt-require-mandatory-facial-scans-for-digital-users/
Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.
"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
LION'S MANE PRODUCT
Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules
Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.
Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.

