Every fight about age checks so far has happened at the edge of a website. On 8 September Britain moved device-level age verification as deep as it goes, into the operating system of the phone in a child’s hand.
Lisa Nandy told Parliament the government will introduce primary legislation requiring major tech platforms to build device-level protections for children. In June the government had given industry three months to come back with roadmaps. Apple and Google came back with real work. The government said it was not enough.
The age check is moving into the device. Whoever runs that check becomes the most powerful identity gatekeeper in the country.
On 8 September 2026 the UK government committed to primary legislation requiring device-level protections for children, and said it will also require apps children use to prevent them accessing or sharing nudity. No bill has been introduced yet. The government has said that if platforms build and ship the technical solutions first, it will reassess whether legislation is needed. The open question is what device-level age verification will actually ask of an adult. Read the statement in full: Lisa Nandy’s statement on protecting children online, GOV.UK.
What the public record shows.
The oral statement to Parliament on 8 September 2026 is short and worth reading end to end. In June the government challenged industry on a three-month timeline to set out roadmaps for strengthening device-level protections, with a view to preventing children from taking, sharing or viewing nude images on phones and tablets. Since then, officials from the Department for Digital, Culture, Media and Sport and the Home Office ran what Nandy called an unprecedented work programme with Apple and Google, working with senior leaders and engineers.
Both companies delivered. The statement records significant commitments, meaningful changes at the operating level, and progress in the blocking rather than blurring of nude imagery on underage devices. It also credits Apple’s rollout earlier this year of operating-system level age assurance tied to safety features, preventing a child from receiving or sharing nude imagery on iMessage or FaceTime.
Then comes the line the industry needs to sit with. “These proposals are a step in the right direction. However, the truth is, Madame Deputy Speaker, they do not meet the scale of this crisis.” The numbers behind it are in the statement: the Internet Watch Foundation believes 91% of these images are self-generated by children themselves, around 9,000 child sexual abuse offences each year involve an online element, and under-18s are the subject of almost a quarter of online blackmail.
Two commitments followed. The government will introduce primary legislation to require major tech platforms to build in device-level protections for children, to be introduced as soon as it can. And it will require apps that children use to prevent them from accessing or sharing nudity, with legislation to be explored. Nandy’s framing: “we will give tech companies the chance to lead, we will not give them the chance to lag.”
Two details are doing more work than the headlines suggest. The first is that no bill exists yet. This is a commitment to legislate, not a statute, and the statement says explicitly that if platforms in scope develop and implement technical solutions while the work is ongoing, the government will reassess whether legislation is necessary.
The second is what the statement does not specify, which is how device-level age verification is actually meant to work. Biometric Update reports the model as protections switched on by default with age verification required to lift them, and the Guardian notes that a nudity block implies client-side scanning, where content is checked by software on the device before it is encrypted or sent. The mechanism is not settled. That is exactly why now is the moment to argue about it.
Device-level age verification puts one gatekeeper in front of everything.
Start with what is right about this. One check at the operating system layer beats the same check repeated by forty apps. It is less friction for the user, fewer copies of the same evidence, fewer places for that evidence to sit. Anyone who has watched a person upload the same driver licence to six services in a month knows the current model is absurd. We wrote about that absurdity in Your Client Verified Last Week. Why Are They Doing It Again?
Now the part nobody is saying out loud. Device-level age verification concentrates the check. The entity that runs it for every phone in Britain is not a feature, it is national identity infrastructure operated by two companies headquartered elsewhere. If the mechanism turns out to be document upload, the country will have normalised handing a passport to a device vendor as a condition of adulthood, for an entire population, in one step. Regulation would have created the largest identity honeypot in the UK by accident.
The failure mode is never the check. It is what the check keeps afterwards. That is the pattern behind every identity breach we have written about, and it does not care whether the collector is a nightclub, a verification vendor or an operating system.
This is what privacy KYC fixes.
Privacy KYC is a simple discipline. Verify the person once against the authority that actually issued the document, keep the signed result, and from then on present the attribute rather than the evidence. The output of an age check should be one bit: over the threshold, or not.
Device-level age verification done properly means the device learns that the user is an adult. It does not learn their name, their date of birth or their document number, and no image of anything is stored anywhere to be leaked later. The technology is a verifiable credential signed by the issuing authority and held by the person, presented with selective disclosure so only the asserted attribute travels. This is not theoretical. It is the same architecture we described in Seven Things That Make Self-Sovereign Identity Different, and it is running at national scale in Thailand today.
A device-level gate built on privacy KYC gives the government the enforcement it wants and gives the public a check they will actually accept. A device-level gate built on document upload gives the government a headline and the country a liability.
Three jurisdictions, one direction of travel.
Britain is not moving alone, and the pattern across the three markets is consistent. On 9 September the transition period inside Australia’s App Distribution Services Code ended, which we covered in Australia’s Age Gates Just Reached the App Store. Australia’s parliament has since passed the Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Bill 2026, doubling the maximum penalty and extending the eSafety Commissioner’s information-gathering powers to third parties including age assurance and app store providers. In Ireland, Coimisiun na Mean opened the first investigation under the Online Safety Code on 8 September, examining whether age assurance on a major platform is effective, and stating plainly that a measure based solely on self-declaration is not.
Regulators have stopped asking whether a check exists. They are asking whether it works, who can see the evidence, and who is left holding it. Those are the same three questions device-level age verification raises, and the only answer that passes all three at once is a proof the verifier can trust and cannot keep.
Questions we are getting this week.
Has the UK passed a law on device-level age verification?
No. The government has committed to introducing primary legislation and said it will do so as soon as it can. There is no bill and no timetable in the statement.
Could Apple and Google avoid the legislation?
The statement says that if platforms in scope develop and implement technical solutions while the government’s work continues, it will reassess whether legislation is necessary. That makes this a deadline as much as a policy.
Does an operating system age check replace the Online Safety Act?
No. Existing duties on services stay in force. A device signal is one input. It is not customer due diligence, it is not an audit trail, and a regulated business still owns its own obligations.
Does device-level age verification mean handing my ID to Apple or Google?
It depends entirely on the mechanism, which has not been settled. It does not have to. A verifiable credential held by the user can prove an age threshold without revealing identity to the party asking.
Will device-level age verification spread beyond the UK?
Australia already pushed the same obligation onto app distribution platforms, and Ireland is now testing effectiveness through enforcement. Once one major market sets a device standard, vendors tend to ship it everywhere rather than maintain two builds.
What should a business do now?
Ask your age assurance provider one question in writing: after the check, what do you still hold? If the answer includes an image of a document, you have a breach waiting on a calendar you do not control.
Where ShareRing sits in this.
We have been building the architecture that device-level age verification needs since 2018, before any of these regimes existed. We took part in the Australian Government’s Age Assurance Technology Trial, and we are a member of the Age Verification Providers Association. In Thailand, Prompt Pass was delivered by TKC, Transformational and ShareRing, with ShareRing building the verifiable credential layer underneath it. That last one matters most, because it is the difference between arguing that privacy-preserving age assurance is possible and pointing at a country where the public is already using it.
If you want the longer version of why we think most digital identity has been built backwards, it is in I Hate Digital ID, So We Built the Version That Doesn’t Suck.
The check is coming. Let’s make it the right one.
The argument about whether children need protecting online is over, and it should be. The argument still live is what the check costs everybody else, and that one gets decided in the next few months while a bill is being drafted. Every business that runs an age gate today is casting a vote in that argument through the vendor it chooses.
The version of device-level age verification we are building proves the fact and keeps nothing. Come and see how it works at ShareRing Advanced Age Verification, or start building a verification workflow today.
By Rohan Le Page, Founder and Co-CEO of ShareRing
#DeviceLevelAgeVerification #AgeAssurance #OnlineSafetyAct #DigitalIdentity #PrivacyKYC #Private #Secure #Verified
More from our Blog, The Privacy Stack
Australia’s App Store Age Checks Start Today. 3 Companies Already Moved.
From 9 September 2026 the age assurance requirements in Australia's App Distribution Services Code are enforceable. App stores must run appropriate age assurance before letting anyone download an...
Learn moreThailand Post Just Launched Verifiable Credentials. This Is What National Adoption Looks Like.
A national postal service just started issuing verifiable credentials to the public. Not a pilot. Not a roadmap slide. A live service, in citizens' hands, right now. Thailand...
Learn moreWhen Birth Certificates Get Hacked, the Database Was Always the Problem
Pattaya Mail reported birth certificates being hacked in Thailand. The fix is not a bigger wall. It is removing the honey pot. Privacy KYC moves identity off central...
Learn more