CLOSED NETWORK
no trackers

US Age Verification Laws: Every Bill, Every Deadline (Live Tracker)

A living record of every US age verification law — federal and state — with effective dates, primary sources, and what each one actually says. Updated continuously.

Last updated: 2 September 2026. This is a living page. I update it as laws pass, take effect, get enjoined, or die in committee. Every claim here is sourced to a bill page, an enacted statute, or a court docket — not to a summary of a summary. Where I could not verify something, I say so rather than quietly dropping it.

I started this tracker because I kept getting the same question in different forms: is the thing I read about real, and does it apply to me? The honest answer is that it depends on which of about forty overlapping laws you mean, and most coverage does not distinguish between a bill filed, a bill passed, a law in effect, and a law currently blocked by a federal judge. Those are four very different things and only one of them changes what happens when you pick up your phone.

So: the whole board, in one place.

What changed in this update (23 August): I got something wrong and I am correcting it at the top rather than burying it. AB 1709, California's so-called social media ban, does not ban social media and does not require ID or biometrics. I had described it the way almost everyone has. Then I read the operative text. There is now a section on it below. Also new: AB 1856 was amended on the Senate floor on 21 August and reset to second reading with days left in the session; AB 1856 did clear Appropriations 7-0 on 13 August, which the previous version of this page left unresolved; Missouri's statute lands on 28 August and I have now read the penalties off the enrolled act; and I have corrected what this page said about AB 1856 dropping its website expansion, which turns out to be half the story.

The one thing to understand first

Age verification is not a website problem any more. It has been moving down the stack for five years, and each layer down is harder to route around than the one above it.

Age verification is moving down the stack: website, app store, operating system, the device itself, and pending federal legislation

When the check lived on the website, you could choose not to visit the website. When it moved to the app store, you could sideload. Now it is moving into the operating system — and in Illinois, into any internet-enabled device including your laptop.

That last step is the one worth paying attention to, because an age attribute that lives in the OS and is queryable by any application is a new thing in the world. It is a persistent, always-on identity primitive that did not exist before. Once it exists, the question stops being "should we have this" and becomes "what else should it return."

Where the laws are

Tile map of the United States showing which states have OS or device-level age verification laws, app store laws, harmful-content age verification, and which have vetoed such bills

A note on the counts, because published figures disagree and I would rather explain the disagreement than pick a number and look authoritative. Sources put the harmful-content total anywhere from 25 to 27 depending on whether they count laws enacted or laws in force, and depending on whether they have caught up with the two 2026 additions. My count is 27 enacted, listed below with dates. If you see 25 somewhere, that source is probably counting states with laws already in force as of early 2026 and has not added West Virginia or Iowa.

Tier 1 — the operating system and device laws

Three states have enacted these. They are the reason this page exists.

State Law Signed Effective Open source exempt?
California AB 1043, Digital Age Assurance Act 13 Oct 2025 1 Jan 2027 No — AB 1856 would add one, see below
Illinois HB 5511, P.A. 104-0664 31 Jul 2026 1 Jan 2028 No
Colorado SB26-051, Age Attestation on Computing Devices 3 Jun 2026 1 Jul 2028 Yes

California AB 1043 requires operating system providers to present an interface at account or device setup collecting the user's birth date or age, then expose an age signal to apps and app stores through a real-time API. Every new phone and tablet sold in California will classify its user by age range at first boot. Penalties run up to $7,500 per affected child.

Colorado SB26-051 does the same thing, with a longer runway and a materially better exemptions section. Passed the Senate 28–7 and the House 40–23. Devices set up before 1 July 2028 need a retrofit interface before 1 January 2029.

Illinois P.A. 104-0664 is the newest, the broadest, and the one almost nobody covered properly — including me, until this week. It passed the Illinois Senate 57–0 and cleared House concurrence 113–0. Not one recorded no vote at the end.

Its scope is worth reading slowly. "Covered manufacturer" means a manufacturer of an internet-enabled device, an operating system provider, or an application store — three categories, not one. "Operating system provider" is defined as "a commercial or non-profit entity that controls the Internet-enabled device's operating system." The words non-profit are in the statute. And "internet-enabled device" is defined to include personal laptops and desktop computers, not just phones.

Read those three definitions together and the law reaches a non-profit foundation distributing a free operating system for a laptop. That is not a strained reading. That is the plain text.

To be fair to Illinois, parts of the drafting are genuinely more careful than Colorado's. The signal is shared only on separate prior user consent for a specific operator. Signals must be encrypted. An operator may request a signal no more than once a year. And "deemed actual knowledge" is scoped to the specific device rather than following you across every platform, which is how Colorado wrote it. Those are real privacy improvements and I will not pretend otherwise.

The problem is who it applies to, and what it does not exempt.

The open-source question

This is the part of the story that matters most if you run Linux, GrapheneOS, LineageOS, or anything else you compiled yourself.

Scorecard comparing California, Colorado and Illinois on whether open-source operating systems are exempt from age verification requirements

Colorado wrote an exemption, and it is smarter than it has been reported. Section 6-30-105(3)(e) of the enacted act exempts:

an operating system provider or developer that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software without any platform-imposed technical or contractual restrictions imposed by the provider or developer on installing all modified versions.

Almost every write-up of this clause stops after "copy, redistribute, and modify" and calls it a Linux exemption. The rest of the sentence is the whole sentence. This is not a test of what licence you use — it is a test of whether the people shipping the software let you install your own modified build. It is an anti-lockdown provision. A signed, unlockable bootloader fails it regardless of how many GPL components are inside.

I have seen the claim circulating that this exemption covers BSD but excludes GPL code, on the theory that copyleft counts as a "restriction." Having read the enacted text, I do not think that holds — the restriction the statute cares about is one imposed on installing modified versions, which is precisely what GPLv3's anti-tivoization language exists to guarantee. That analysis was published in April and the language moved afterwards. I would not assert it either way on air without a court or an AG opinion, but I would not repeat the GPL claim as settled either.

Colorado also excludes free public code repositories from the definition of "covered application," and excludes code repository providers and containerised software distribution from "covered application store." GitHub, GitLab, Docker and Podman-style distribution stay out of scope.

California's session ends on 31 August, and AB 1856 is not over the line. AB 1856, authored by the same legislator who wrote AB 1043, would add the same style of carve-out. It came off the Senate Appropriations suspense file on 13 August with a 7-0 do-pass and was read a second time the same day. Then, on 21 August, the Senate read it a third time, amended it on the floor, and ordered it back to second reading. That is a reset, not a death — the Assembly did the identical manoeuvre on 18 May and the bill advanced the next day — but it burns days the bill does not have, and because the Senate amended it, the Assembly must now concur before it can go to the Governor. As I write, the text of that 21 August floor amendment has not been published, so nobody outside the building knows what it says. The newest posted version is still the 1 July Senate amendment. If AB 1856 does not pass by 31 August, AB 1043 still takes effect on 1 January 2027 — with no open-source exemption at all. AB 1043 is already law; AB 1856 only amends it. That distinction matters and a lot of coverage misses it.

A correction to what this page said about AB 1856 and the web. I previously wrote that the plan to extend age-gating to browsers and websites was dropped. That is half right, and the wrong half. The 1 July amendment did strike the browser as a transport — the definitions of "browser," "browser provider" and "internet website operator" are gone, and your browser will not be handing your age to every site you visit. But the same amendment rewrote the actual-knowledge clause so that a developer receiving an OS signal is deemed to know your age range "across all platforms of an application, including an internet website owned, maintained, or controlled by a developer" — and it holds "even if the developer willfully disregards the signal." The web did not leave the bill. It changed vehicles. Once an app on your phone has your age band, that knowledge follows you to that company's website, on your laptop, in a different session, with no prompt and no check. The EFF removed its opposition after the open-source exemption was added and the browser transport was dropped, while maintaining that AB 1043 itself is unconstitutional.

Illinois shipped with nothing. I read the enrolled text end to end. The only exemptions in the Act are for entities whose primary purpose is news media, and for broadband internet access providers. There is no licence-based carve-out, no repository carve-out, no container carve-out. Colorado has all three. Illinois has none, and its definitions explicitly reach non-profits and laptops.

Neither federal bill — S. 5090 nor H.R. 8250 — contains an open-source exemption in any published summary I have found. I have not been able to confirm that against the full bill text, so treat that as absence of evidence rather than confirmed absence.

The Linux plumbing, and where it actually stands. This comes up every time, so: the data layer shipped and the API layer did not. systemd merged a birthDate field into its JSON user records on 18 March 2026 — a full date, not a bracket, readable by any process that can query userdb and writable only by an administrator. The pull request explicitly cites AB 1043, Colorado SB26-051 and Brazil's Lei 15.211 as motivation. But the application-facing interface that would let an app actually ask has now been proposed twice and closed twice. Aaron Rainbolt's org.freedesktop.AgeVerification1 specification was closed after community pushback. David Edmundson's xdg-desktop-portal draft, PR #1922, was closed by a maintainer on 13 April 2026 without merging. No desktop environment has shipped a backend, and as of today there is no active proposal.

I am flagging this because the widely shared version of the story — "age verification is already in your Linux box" — is half right, and the wrong half matters. The storage is there. Nothing queries it. Correction worth making in public: my own working tracker carried PR #1922 as open and under review for two days, because I trusted a third-party compliance status page that still lists a pull request closed in April as active. Check the pull request, not the tracker. Including mine.

California AB 1709 — the bill everyone is describing wrong, including me

If you have read anything about AB 1709, you have read that California is about to ban under-16s from social media and make every adult in the state show government ID or submit to a face scan to use an algorithmic feed. I have seen that description from advocacy groups I respect, from think tanks, and from most of the press. I repeated a version of it myself.

I have now read the operative text — most recently amended in the Senate on 28 August 2026. It does not say that.

Update, 1 September. AB 1709 is no longer a pending bill. On 31 August the Senate read it a third time and passed it, and the Assembly concurred in the Senate amendments the same day. It is at engrossing and enrolling, on its way to the Governor, who has until 30 September 2026 to sign or veto. If he does nothing it becomes law anyway.

Update, 2 September. I flagged that vote as single-sourced rather than tidy it away, and it has now resolved — so here is the answer. Leginfo's votes database caught up overnight and confirms the Senate tally at 39-0, with a named roster of thirty-nine and one senator not voting: Cabaldon. The Assembly concurrence, which had no tally at all when I wrote this, is 78-0. Both figures are now double-sourced and I am stating them flatly.

The sister-bill discrepancy resolved too, and it is worth a sentence because it went the other way. AB 1856's history prints 39; its votes page prints 40, with forty names. The two rosters differ by exactly one member — Cabaldon again, who voted aye on 1856 and did not vote on 1709. Forty is right and the history line is simply wrong. When a legislature's own records disagree, the roster is the document that can be counted.

It is not an account ban. Section 22683(a)(1) reads: "A covered platform shall not provide an addictive feature to a user who is under 16 years of age." And then (a)(2), immediately after: "This subdivision does not prohibit a covered platform from permitting a user who is under 16 years of age to create or maintain an account on the covered platform if that user is not provided with any addictive feature." A fifteen-year-old can have an Instagram account under this bill. They just cannot be given a personalised feed or autoplay.

It does not ask for your ID. Here is the entire verification mechanism, Section 22684(a)(1): "Before providing an addictive feature to a user, a covered platform shall verify the age of a user pursuant to the Digital Age Assurance Act." That is AB 1043 — the operating-system signal described at the top of this page. If that fails, subsection (a)(2) sends the platform to Health and Safety Code 27001(a)(1)(B), which is SB 976's "reasonably determined the user is not a minor... pursuant to regulations promulgated by the Attorney General."

That is the whole list. There is no third option. The words "government-issued identification" and "biometric" do not appear anywhere in the bill.

Why this is worse, not better

It would be comfortable to treat this as good news. It is not, and the reason is the whole thesis of this page.

A law that says "check ID at the door" is a law you can challenge. There is a specific burden, on a specific person, at a specific moment, and courts have been striking those down — that is what the injunction column further down this page is full of.

AB 1709 does not contain a mechanism to challenge. It imports one. It points at AB 1043, which is already law and takes effect on 1 January 2027, and at an Attorney General rulemaking that has not happened yet. The bill's authors did not have to defend an age check, because the bill does not create an age check. It creates demand for one that is being built somewhere else, by someone else, on a different timetable.

Watch what this means in practice. There is no prompt. There is no upload. There is no moment where you are asked for anything. Your operating system already knows your age band because you typed a birthday at device setup, and the platform simply asks it. The absence of friction is not the absence of surveillance. It is what surveillance looks like once it is finished being built.

The same pattern is on this page three times now: California relocating its website reach into a knowledge clause instead of a gate, Alliance Defending Freedom writing in its own committee filing that age estimation replaces age verification precisely because verification gets enjoined, and now AB 1709 declining to specify a mechanism at all. Three different drafting shops. No coordination. One conclusion: stop writing gates.

The other things in AB 1709

  • Penalties are the largest of any bill on this page. Up to $50,000 per affected minor for a knowing violation and $25,000 for a negligent one, enforced by the Attorney General or a local prosecutor. No private right of action. For comparison, AB 1856 runs $2,500 and $7,500.
  • "Addictive feature" got much narrower on 13 August. It is now a closed list: an addictive feed, autoplay, and anything the Attorney General later adds by regulation. The earlier draft covered notifications, endless scroll, "functional equivalents," and any feature that learns from your behaviour to prolong engagement. All of that was struck.
  • The bill explicitly blesses consuming the OS signal. A feed does not become an "addictive feed" merely because it uses "device communications or signals concerning whether the user is a minor." AB 1709 and AB 1856 are designed to interlock.
  • The oversight body was quietly defanged in the same amendment. The e-Safety Advisory Commission went from advising the Attorney General on "implementation and enforcement" to being "purely advisory" and "not binding upon, and shall not be imputed to, any agency or department of the state." Struck from its annual report: compliance rates among covered entities, and enforcement actions taken. And struck from its membership rules: a specific bar on commissioners having "a financial interest in an entity that is subject to regulation by the commission," replaced with generic Political Reform Act coverage. It gained a better-specified membership and a weaker mandate in the same pass. I have not seen this reported anywhere.

Status: read a second time and ordered to third reading on 17 August 2026. It is ahead of AB 1856 procedurally. Like AB 1856, it dies if it does not pass by 31 August, and it needs Assembly concurrence after that.

Every deadline that matters

Timeline of US age verification deadlines from August 2026 through January 2029

Date What happens
13 Aug 2026 California Senate Appropriations released AB 1856 from suspense, 7-0 do-pass. Read second time the same day
21 Aug 2026 AB 1856 read a third time, amended on the Senate floor, and ordered back to second reading. Amendment text still unpublished
31 Aug 2026 Happened. AB 1709 passed the Senate 39-0 and the Assembly concurred the same day, 78-0 — both tallies now confirmed against the roster. AB 1856 had already cleared on 26-27 Aug. The Legislature went into final recess on adjournment that night
1 Sept 2026 AB 1856 was enrolled. AB 1709 remains at engrossing and enrolling. Neither is chaptered; the Governor's clock is what matters now
30 Sept 2026 Governor's deadline on AB 1709 and AB 1856. Signature, veto, or silence — silence enacts them
26 Aug 2026 The Meta trial ended in a consent judgment, entered by Judge Gonzalez Rogers. See below
14 Sept 2026 Further case management conference in the Meta MDL, Oakland
~27 Aug 2027 Meta's age-assurance framework deadline under the consent judgment
14 Aug 2026 Last day for California fiscal committees to report bills
28 Aug 2026 Missouri harmful-content AV statute takes effect. Covers sites where more than a third of content is harmful to minors. $10,000/day, up to $250,000 if a minor gets through. The AG rule has been live since Dec 2025 — see Tier 3
31 Aug 2026 Last day for either California house to pass bills
Pending, no date Utah SB 73 VPN provisions. Correction, now settled. I previously gave 3 Sep 2026. That date is dead: on 27 Aug 2026 the parties jointly stipulated to extend the non-enforcement period, and on 28 Aug Judge Barlow entered a docket text order acknowledging their agreement "to extend and continue the period of forbearance" (ECF 65, 66). No replacement date is public — the stipulation is not in the docket. The real trigger is Judge Barlow's ruling on the preliminary injunction, argued 30 Jul 2026, still outstanding
1 Sept 2026 Fifth Circuit hears NetChoice v. Murrill (26-30016), En Banc Courtroom, New Orleans — Louisiana's appeal of the permanent injunction against its social-media minor-consent law
10 Sept 2026 Georgia's blue-ribbon study committee meets in Augusta. Agenda still unannounced
28 Oct 2026, 2pm Fourth Circuit hears NetChoice v. Jones (26-1252) — Virginia. The court has now denied a stay pending appeal twice
Oct 2026 Judge Gonzalez Rogers rules in the 29-state Meta trial
1 Jan 2027 California AB 1043 (OS age signals); California SB 976; Alabama app store law; South Carolina HB 4591; New Hampshire HB 1460
31 Dec 2026 Utah App Store Accountability Act private right of action takes effect — parents may sue app store providers and developers. Secondary sourcing; verifying against enrolled HB 498
6 May 2027 Utah app store law — full compliance deadline
1 Jul 2027 Minnesota HF 4138; California AB 1043 transition period ends
1 Jan 2028 Illinois P.A. 104-0664 — manufacturer interface deadline
1 Jul 2028 Colorado SB26-051 takes effect; Illinois operator signal requests begin; Illinois retrofit deadline
1 Jan 2029 Colorado retrofit deadline for devices set up before July 2028

Tier 2 — app store laws

Four states, and these are already live. The detail most coverage misses: they apply to all apps available to residents of the state, not just apps aimed at children. A flashlight app has compliance obligations.

State Law Effective
Texas SB 2420 1 Jan 2026 — enforceable now
Utah App Store Accountability Act Staged: provider duties 6 May 2026, full compliance 6 May 2027
Louisiana App Store Accountability Act 1 Jul 2026
Alabama HB 161 1 Jan 2027

Apple and Google have both built for this. Apple's Declared Age Range API returns an age category — under 13, 13–16, 16–18, 18+ — along with signals about how that age was assured, without exposing a birth date. Google Play's Age Signals API is in beta doing the same job.

I want to be straight about this: the Declared Age Range design is the least-bad engineering in this entire space. Bands instead of birth dates, with assurance metadata. If you have to build the thing, that is roughly how you would build it. The problem is not the current field list. The problem is that once the OS knows your age band and every app can query it, nothing about the architecture stops a future statute from widening what the API returns. Good version-one design does not constrain version three.

Tier 3 — harmful-content laws, 27 states

These are the "upload your ID to visit an adult site" laws, generally scoped to sites where a third or more of the content is sexual material harmful to minors. The Supreme Court upheld the Texas version in Free Speech Coalition v. Paxton in June 2025 under intermediate scrutiny, which is why the count has climbed so fast since.

Enacted 2023: Arkansas, Louisiana, Mississippi, Montana, North Carolina, Texas, Utah, Virginia
Enacted 2024: Alabama, Idaho, Indiana, Kansas, Kentucky, Nebraska, Oklahoma
Enacted 2025: Arizona, Florida, Georgia, Missouri, North Dakota, Ohio, South Carolina, South Dakota, Tennessee, Wyoming
Enacted 2026: West Virginia (HB 4412, effective 12 June), Iowa (HF 864, signed 4 June, effective 1 July), Missouri (expanded, effective 28 August)

One clarification on Missouri, because it trips people up. The statute above takes effect on 28 August, but Missouri has been gated since 1 December 2025 under a separate rule promulgated by the Attorney General under the Merchandising Practices Act — Pornhub shut off access to the state within hours of that rule taking effect. If you read that Missouri "gets age verification this month," that is the second instrument, not the first.

Eight more states have pending bills, including Ohio HB 84, Michigan SB 191 and Pennsylvania SB 603.

The courts stopped being a brake

For three years the pattern was predictable: a legislature passes an age-verification law, NetChoice or the CCIA sues, a district judge enjoins it, and the thing sits in appellate limbo. That pattern broke twice this month, in opposite directions, and neither break has much to do with the First Amendment.

A New Mexico court ordered age verification with no age-verification statute behind it. On 6 August, Judge Bryan Biedscheid of the First Judicial District entered final judgment against Meta in State of New Mexico v. Meta Platforms. A March jury had already found 75,000 violations of the state's Unfair Practices Act and imposed the maximum penalty, $375 million. The bench phase added $567 million, held that Meta's platforms constitute a public nuisance, and rejected the Section 230 defence as to products Meta knowingly designed. Total: $942 million, plus five years of court-supervised reforms that include "more rigorous age verification for New Mexico users" and semiannual compliance reports filed with the court.

The same ruling shows where the judicial ceiling sits, and this part did not make the headlines. The court expressly declined to order hard age verification. Its stated reason was the vintage of the enabling statute — New Mexico's Child's Online Privacy Act dates to 1998 — and the conclusion that it cannot order Meta to make children submit personal data or be passively tracked, even for age-verification purposes. Judge Biedscheid called age assurance tools "unproven technology." The judge who fined Meta $942 million is also the judge who refused to make Meta scan children's IDs. Attorney General Raúl Torrez has said he will take the gap to the legislature next session.

Sourcing note added 1 September 2026. I want to be straight about how solid the numbers above are, because I have since tried to verify them against the record and could not. What is independently corroborated is the case itself — State of New Mexico v. Meta Platforms, D-101-CV-2023-02838, Judge Bryan Biedscheid — and a jury verdict dated 24 March 2026, cited by the D.C. Court of Appeals in In re Meta Platforms (No. 26-OA-0001, 16 July 2026). But that citation describes it specifically as a "jury verdict on liability" and says nothing about money.

The 75,000 violations, the $375M, the $567M, the $942M total and the five-year reform list all trace to a briefing deck the New Mexico Department of Justice handed legislators on 25 August, not to a court record I can reach. Searching the available federal corpus for that judgment returns nothing. New Mexico's own state-court lookup is behind a CAPTCHA, so I cannot close the loop either way — this is unverified, not disproven.

One more thing, and it cuts against the section above: the line about the court declining to order hard age verification comes from a footnote on that same DOJ slide, which reads "The Court stopped short of mandating hard age-verification, citing judicial restraint." That is a litigant characterising a judge's reasoning, on a slide whose main body lists rigorous age verification as an ordered reform. The slide contradicts itself. Until I can read the judgment, treat this whole passage as New Mexico DOJ's account of its own win.

The Ninth Circuit then removed the shield that made all of this survivable. On 10 August a panel dismissed Meta's and TikTok's appeals as premature in the consolidated social media addiction litigation. In a 24-page opinion, Judge Jacqueline Nguyen held that Section 230 provides a defence against liability, not blanket immunity from being sued. That distinction is why more than 3,000 federal cases are still alive.

And on 12 August, 29 states put it to trial. On 26 August it ended — not in a verdict, but in a consent judgment.

Jury selection began in Oakland before Judge Yvonne Gonzalez Rogers, with Colorado, Kentucky, California and New Jersey leading on the design and consumer-protection claims. I wrote here that her decision was expected in October. It did not take that long. The docket records the jury trial as completed on 26 August 2026, with a total time in court that day of forty-nine minutes, and on the same day Judge Gonzalez Rogers entered a consent judgment between Meta and the state attorneys general.

The settlement covers 51 jurisdictions — 47 states plus the District of Columbia, Puerto Rico, American Samoa and the Northern Mariana Islands. Florida, New Mexico and Texas are not in it. The money is roughly $12.2 billion guaranteed and up to about $17.1 billion. I am rounding deliberately: the guaranteed schedule is itemised in the agreement, but the ceiling is arithmetic derived from it rather than a figure the document states, and I would rather round than quote a precise number the record does not contain.

The part that belongs on this page is not the money. It is section II.A.1, which reads that within one year of the effective date, Meta will adopt an age assurance framework. The judgment was entered on 26 August 2026, which puts that deadline at roughly 27 August 2027.

Read that against everything above. Every tier on this page is a legislature telling a company to check ages, and every one of them can be challenged — Louisiana's was enjoined as to ten named platforms, Arkansas and Ohio have been through the courts, NetChoice has a case in nearly every circuit. This one cannot be. There is no statute here to strike down. Meta agreed to it. The United States is getting age assurance on its largest social platform through a document that no First Amendment challenge can reach, because there is no defendant who wants to challenge it.

And it does not stop at Meta. The agreement names Snap, TikTok and YouTube as Core Industry Members and ties a second phase to industry-wide adoption. It also distinguishes commercially available age-assurance methods, which get a presumption of compliance, from proprietary ones, which do not — a quiet but consequential nudge toward third-party age checking as the default. None of the three has announced anything yet. I am watching all of them.

The layer below all of it — a Texas court switched off a domain

Every tier above is a rule about what a company has to do. This one is different. It is a rule about whether a name resolves at all.

On 4 June 2026, Judge Maya Guerra Gamble of Travis County signed a writ of attachment in State of Texas v. Kick Online Entertainment, filed four days later. It directs Verisign — the American company that operates the .com registry — to place motherless.com on "a registry lock, hold, or similar status until replevied by Defendant." Fourteen days after signing, the domain dropped out of the .com zone file. Not blocked in Texas. Gone, for everyone on earth.

The chain that got there is mundane, which is the point. Texas sued Kick Online Entertainment, a Luxembourg company, in April 2024 under HB 1181. Kick never appeared. Civil penalties were entered by default on 30 September 2024, followed by a permanent injunction requiring age verification. Kick ignored that too. Unable to reach the company, Texas reached its property instead — through the one custodian in the chain that is unambiguously American.

What Verisign applied was serverHold, plus server-level prohibitions on deleting, transferring or updating the name. A registrar lock can be lifted by the registrar. A registry lock can only be lifted by Verisign. Without an entry in the zone file, a domain does not resolve for anybody, anywhere.

Three things in the order deserve to be read slowly.

One — foreignness became the justification rather than the obstacle. Among the court's stated grounds that the writ is "appropriate and justified" is the finding that "Defendant is not a resident of this state and is a foreign corporation." The state's inability to reach a company became the reason to take its property.

Two — the bond runs one way. Kick can recover the domain by posting $9,140,000, conditioned on implementing age verification that conforms with Texas Civil Practice and Remedies Code chapter 129B and affirming that it will satisfy the 2024 penalties. Texas posted nothing: the order provides that "the State of Texas is not required to post a bond prior to the issuance of the Writ of Attachment."

Three — it pre-authorises itself. The order closes with the line that "as many writs as the State deems necessary shall issue." The number of future seizures is set by the attorney general, not by a judge weighing each one. Nothing in the order confines the tool to pornography, or even to age verification.

I want to be precise about sourcing, because this is the most consequential item on this page and the order is a scanned PDF with no text layer. The language quoted above is as published by Reclaim the Net, which obtained and posted a copy of the order, and it matches Tech Times' independent reading of the same document. I have not been able to machine-read the scan myself. Treat the quotes as reliable but second-hand until someone has read it line by line.

Two caveats that cut against the alarm, and they belong right here. This is a trial court order and it binds nobody outside this case. And no court has heard the other side, because Kick never showed up — the whole framework rests on an uncontested default.

Here is why this sits on a privacy page and not a domain-industry one. Every other tier on this list is defeated, degraded, or at least complicated by the tools I usually recommend. A VPN changes where you appear to be. It cannot conjure a zone-file entry that no longer exists. This is the first rung of the age-verification stack that personal tooling does not reach at all, and the honest response to it is not a better VPN. It is an argument about who gets to hold that switch, and that argument happens at ICANN and in appellate courts rather than in your settings menu.

The VPN front

This one goes directly at the toolkit, so I want to be precise about it.

Utah SB 73 is the only enacted US law targeting VPN use around age gates. It does not ban using a VPN. What it does is make you a Utah user for liability purposes even when you connect through one, and it prohibits covered platforms from providing instructions, assistance, or encouragement about using a VPN to bypass verification. That second part is a speech restriction on privacy education wearing a child-safety hat.

The VPN provisions are not yet enforced, and as of 1 September the date I and everyone else were quoting is dead. Utah's Department of Commerce and Aylo agreed on 27 April to hold off until 3 September 2026 — but on 27 August the parties filed a joint stipulation to extend that, and on 28 August Judge David Barlow entered a docket text order acknowledging "the parties' agreement to extend and continue the period of forbearance." (ECF 65 and 66.)

There is no new date. The stipulation itself is not in the public docket, and the words September, expire and expiration appear nowhere in the docket text — against 42 occurrences of preliminary injunction in the same corpus, so that is a real absence rather than a search that missed. The honest position is that the freeze continues indefinitely until Judge Barlow rules. He heard argument on the preliminary injunction on 30 July 2026 and has not ruled.

Worth noticing what the extension implies: the stipulation is bilateral. Aylo agreed not to change its Utah geofencing either. Neither side wanted the cliff. Anyone telling you Utah is currently enforcing a VPN ban is wrong, and anyone telling you enforcement starts on 3 September is now also wrong. Aylo's argument is worth understanding: if Utah residents can reach a site through a VPN from anywhere, then verifying "Utah users" means verifying everyone on earth. A state law becomes a global standard by accident.

The strangest development of the month: the pornography industry is now lobbying for OS-level age verification. Aylo, which owns Pornhub, sent an open letter to more than 300 lawmakers, governors and attorneys general calling site-level age verification laws "performative, ineffective, and unenforceable" — and then asking those same lawmakers to "mandate operating system providers like Apple, Microsoft and Google" to render every phone, tablet and computer child-safe by default. It points to its UK arrangement as the model, and it advertises, as a selling point, that under that scheme "VPNs do not work to circumvent these blocks."

Sit with that for a second. A pornography company is marketing VPN-proof blocking as a feature.

The rebuttal came from the age-verification vendors, which tells you how scrambled these coalitions have become. The Age Verification Providers Association called device-only checks "a false choice," argued for a layered model on a proximity principle — you check at the door of the casino, not at the entrance to the shopping centre — and warned that routing everything through three operating system vendors "creates a single point of failure, concentrated market power and, some may also fear, even more data harvesting opportunities, while excusing adult platforms completely from their duty of care."

The map most people carry into this fight — privacy advocates on one side, the state on the other — does not describe what is happening. On the specific question of OS-level mandates, Aylo is aligned with a bipartisan Senate quartet, and the people making the market-concentration argument are the ID-checking vendors whose business model depends on the answer.

Michigan has a filed bill that goes further — it would reach the promotion or sale of circumvention tools — but it has no hearing scheduled.

Wisconsin is the interesting one, and I had it wrong in an earlier draft of my own notes. The VPN provision was struck from the bill in February 2026 after sustained public pressure, and Governor Evers then vetoed the whole age verification bill on 3 April 2026, making him the first US governor to do so. That reads like a clean win for privacy.

It is not a clean win, and this is the single most important paragraph on this page.

In the same veto message, Evers objected that the bill made every user hand over identification while doing nothing to stop operators selling that data to brokers or the government — and he proposed device-based age verification as the better alternative. The governor who killed the ID-upload bill on privacy grounds endorsed the operating-system model. That is where mainstream privacy politics currently sits. If your argument against OS-level age gates assumes the people pushing them are acting in bad faith, that argument does not survive contact with the Evers veto. The people pushing this genuinely believe it is the privacy-protective option, and the strongest version of the counter-argument has to engage with that rather than around it.

And the practical point for anyone who reaches for a VPN by reflex: a VPN changes where your traffic appears to come from. It does not change what your device broadcasts about you. Against an OS-level age signal, it does nothing at all.

Federal

Nothing has passed. A great deal is moving.

Bill What it does Status
S. 5090 Digital Age Assurance Act Nationalises the California OS-level model. Four brackets, ZK proofs named in statute, data-broker ban, antitrust teeth against app store self-preferencing Senate Commerce, no hearing scheduled
H.R. 8250 Parents Decide Act Same architecture, blunter. DOB at OS setup, parent verification for under-18s House Energy & Commerce
KOSA Duty of care for platforms Out of Senate Commerce by unanimous voice vote, 5 Aug 2026
SCREEN Act (S. 737) Federal AV mandate for explicit content Voted 15–13 to advance on 5 Aug — failed for lack of quorum. Not dead, lost on attendance
KIDS Act (H.R. 7757) Broad package including AV for explicit sites Passed House 267–117, 29 Jun 2026. Awaiting Senate
GUARD Act (S. 3062) AV for "AI companions" Pending

S. 5090 deserves credit where it is due. It is bipartisan — Kim and Schiff alongside Lummis and Barrasso — and it is the best-designed bill in this space: age brackets rather than birth dates, verifiable credentials and zero-knowledge proofs named in the statutory text, a ban on selling bracket data or feeding it to brokers, and per se Sherman Act treatment for platforms that impose stricter age requirements on third-party apps than their own.

And there is a gap between the press release and the statute that I think is worth naming. The release says the bill keeps government IDs and face scans "out of the equation." The statutory language says only that the Act shall not be interpreted as requiring those methods. It does not prohibit them. Registration is self-attested at setup, but a "clear and convincing information" trigger lets a developer override the signal and escalate to the OS provider for verification — and the bill does not specify how that verification happens. That undefined escalation path is the door through which ID checks walk back in.

There is also a horse-trade in the background worth watching: reporting indicates the White House and Senate negotiators have discussed bundling a federal age verification mandate with three-year preemption of state AI regulation. If that lands, the patchwork ends and a single national floor for identity-linked internet access replaces it — traded for something entirely unrelated to children.

What I am watching next

  • Every day to 31 August — AB 1856 and AB 1709 on the California floor. Two bills, eight days, and both need Assembly concurrence after they pass. AB 1709 is the one further along.
  • The 21 August AB 1856 floor amendment text, whenever it posts. The specific thing to look for: whether it cleans up the references to "browser provider" and "internet website operator" that are still scattered through the bill even though the July amendment deleted both definitions. A bill that ships with dangling references to actors it no longer defines is a bill that was assembled in a hurry.
  • 28 August — Missouri's statute joins the AG rule that has been live since December.
  • Judge Barlow's ruling in Aylo v. Utah, undated. The most consequential pending decision on this page for anyone using a VPN.
  • October — Judge Gonzalez Rogers rules. If she orders age restrictions nationwide, every tier on this page is suddenly downstream of one courtroom.
  • Whether Texas files a second domain writ. The order authorises as many as the attorney general wants. The second one is what tells you this is a programme rather than a one-off.
  • Whether any state copies Colorado's exemption language. It exists, it is drafted, it has passed a legislature. That makes it handable to any other statehouse.
  • Whether S. 5090 or H.R. 8250 gets a hearing before the calendar runs out.

What this page is not

It is not legal advice, and it is not complete. There are roughly forty overlapping statutes here plus an active litigation docket in at least eight circuits, and I am one person with a microphone. If you find something wrong — a date, a vote count, a bill number, a state I have miscoloured on the map — tell me and I will fix it and note the correction. I would rather be corrected in public than be confidently wrong in a place people are using as a reference.

The reason I keep this updated rather than writing one post and moving on is that the shape of the thing only becomes visible over time. Any single law looks like a narrow response to a real problem. All of them together look like an architecture. That architecture is being built right now, in public, with bipartisan support and near-unanimous votes, and the window to shape it is measured in months.

— Simon

Sources & further reading

Enacted state laws

The registry writ

The Oakland trial and the Ninth Circuit

The Linux stack

California, AB 1043 and AB 1856

Open source

Federal

VPNs and Wisconsin

Litigation

// Encrypted Dispatches

Become A
Smaller Target.

One email per week. Real privacy news, working tools, no fearmongering. We don't sell your address. We don't even want your real email address.

Subscribe
5,000+ readers · unsubscribe in one click · consider supporting the show