

It’s a policy unlikely to protect children and all but assured to endanger the data privacy of users of all ages and to violate the First Amendment.
J ust in time for Christmas, certain members of Congress are hard at work in their policy shops, fashioning a massive lump of cybersecurity coal with which to gift American users of electronic devices. This isn’t so surprising. The end of the year is always a time when legislators try to push their pet projects and legislation past the finish line. Bad policy is often smuggled into law in must-pass omnibus packages.
On December 11, Representative John James (R., Mich.) introduced the App Store Accountability Act (ASAA). The bill would, among other things, require app stores to verify users’ ages and obtain parental consent for minors. The ASAA may be the final age-verification bill of the 118th Congress, but it is by no means the first. Similar measures have been proposed in the House and the Senate.
The intent of these bills is noble. Government has a major part to play in protecting children, both online and off. That is obvious. But in attempting to keep children safe, lawmakers must ask whether the proposed policies will, in fact, succeed in that objective and whether they will inflict unintended harms. Age-verification mandates seem unlikely to protect children and are all but assured to endanger the data privacy of users of all ages and to violate the First Amendment.
Mandated age verification — at the device, app store, or platform level — is a bad idea. Age verification would be accomplished either by submitting government documentation (e.g., an ID) or through something like a facial scan. That would likely create troves of sensitive personal data, ready to be stolen by hackers. And it is not just children, but all users, whose data will be put at risk. Everyone would have to submit to age checks if they were mandated.
The mandates would also create First Amendment concerns when they blocked access to speech platforms. Judges have found age-verification requirements to be unconstitutional when applied to platforms. Similar arguments would likely be leveled at mandates at the app-store level. First, judges have ruled that age-verification laws place impermissible burdens on speech. What’s more, age verification would likely compromise the user’s identity, and the Supreme Court has found that the First Amendment encompasses a right to anonymous speech.
Moreover, as in the opinion of France’s national data-protection agency, there is no software “that satisfactorily meets” the “three requirements” of “sufficiently reliable verification, complete coverage of the population and respect for the protection of individual’s data and privacy and their security.”
Online age verification can’t reasonably be equated with brick-and-mortar age checks at a bar or tobacco shop. Collecting and processing the kind of data needed to complete online age verification is a far more intensive and privacy-invasive process than simply flashing an ID. These mandates are, therefore, far more problematic (especially given that they gatekeep the core constitutional right to free speech).
Many experts doubt that the purported benefits of app-store age verification would materialize, but it cannot even be considered without assessing the very real corresponding risks. Children will not be made safer by laws that require them and their parents to expose large amounts of personal information to cybercriminals.
From the network level to the operating-system level to the app level, there are myriad digital child-protection features already available to parents. The responsibility for raising children, both online and off-, should fall primarily to parents, as it always has. It is true that tech companies can and should do more to improve kid-safety features (the sooner the better), but it is particularly foolish to urge government to enact dangerous and unconstitutional laws when so many solutions to the identified problem are already available in the market.
That doesn’t mean that there are no affirmative steps Congress can take to protect children. For example, the Invest in Child Safety Act would provide badly needed resources to law enforcement, giving authorities the ability to bring more online predators to justice. At the state and local level, policymakers should design digital-literacy programs for children and families to help them remain safe in the online world.
Moving into the new year, Congress should make cybersecurity a top priority as it developa policy for devices, online platforms, and artificial intelligence. Privacy and data security should also be top priorities. Threats from cybercriminals are ever present, and policy makers should do everything in their power to strengthen the cybersecurity protections American users rely on.
The ASAA, however well intentioned, should be soundly defeated.