Who checks that the child is a child?
If device makers become the authority that labels people as children, what stops an adult who wants contact with children from being labelled a child? On current evidence, this is a real gap, and almost no public guidance addresses it.

Pornhub and others have been pushing for device-level age verification for years. This is a conversation I had face to face with a member of Pornhubs senior management a few years ago in London. I met with them to discuss the huge volume of fetishized Roblox content on their platform. Roblox avatars recorded in game participating in sexual acts, then uploaded for an adult audience. My concern was that it was normalizing this kind of behavior, so I threw some questions at them. How do you know it is not a child’s avatar? Is this child exploitation in plain sight? To their credit, within 24 hours Roblox, and every alternative spelling of it, was gone and is still unsearchable.
On Tuesday, Pornhub came back to Australia, although not for everyone and not everywhere. Aylo, the company that owns it, announced that Australians who have confirmed they are adults through Apple’s age check can once again see the full site on an iPhone or iPad. Everyone on Android or a desktop computer is still looking at the cut-down version that has been in place since March. Pornhub went dark in a long list of US states, Texas, Utah and Florida among them, in preference to complying with laws that require sites to check ID, and Aylo has spent those same years telling American lawmakers that the check belongs on the device.
Utah, Texas and Louisiana have each passed laws that put the age check at the app store, and California has passed one that requires operating systems to send an age signal to apps from 2027.
Consider how Apple’s system works. If you have not confirmed that you are 18, your device treats you as though you might not be, and the web content filter and Communication Safety switch on by default. To be treated as an adult you need a credit card in your own name or a scan of government ID. To be treated as a child you need a birth date and nothing more.
As a way of filtering content that is sensible, and a phone that stays safe for a child until somebody proves they are a grown-up is the right place to start. The trouble begins when the same signal is given a different job. Apps are starting to use age signals from the operating system to build spaces where children can only talk to other children, and if “child” in that system really means “no adult proof was offered”, then an adult who offers no proof walks through the door with everyone else. Content filters protect the person holding the device, and they do nothing for the children that person goes on to contact.
We already know how this plays out because we saw it when Roblox made chat depend on age checks, so that users could only talk to people in a similar age band, WIRED found age-verified accounts for children as young as nine for sale on eBay within days, for about US$4. 7NEWS reported Australian listings for accounts verified as 13 to 15 with voice chat already switched on. eBay removed the listings and Roblox says it bans account trading, yet the moment a system promises that verified children will only meet other verified children, a child-verified account becomes something worth buying, faking or borrowing, and pretending to be a teenager is one of the oldest grooming tactics there is.
So I have been down a rabbit hole looking for who is watching.
In the UK, Ofcom and the ICO say age checks should bind the proof of age to the person presenting it, which in principle cuts both ways, and Apple’s Declared Age Range API can tell an app how an age was confirmed, so a developer can separate a confirmed age from a declared one if they choose to look. What I could not find anywhere globally was guidance from a regulator, or documentation from Apple or Google, on stopping adults from being handed child status at the device level, or on who is responsible when an app relies on that status to connect children with one another.
Apple is pushing itself into a role where this scenario will matter more than anyone is talking about. I wrote about this a few months ago as my concern as someone with a background in information security is that in web security a certificate authority is the trusted body that vouches for a website so your browser never has to check again, and Apple is becoming something very like that for age verification. It means Apple, and not a regulator, decides what counts as proof, which is why a credit card is accepted and a debit card is refused. It means protection follows the account and not the child and for now it means child-safe defaults belong to the families who bought one brand of phone.
It is worth remembering that Apple once argued against this. In its February 2025 white paper, the company said that requiring age verification at the app marketplace level “is not data minimization”. eSafety has welcomed the device protections while making clear that every service, Pornhub included, still answers for its own obligations, and the government’s Age Assurance Technology Trial, on which I held an advisory board role, flagged the governance problem that comes with control sitting in the hands of a small number of global players.
Before this model becomes the default for childhood online, there are three questions I would put to every platform and every regulator. When an app says “children only”, is it relying on a confirmed child age or merely the absence of adult proof? Who checks that a child account is still being used by a child once setup is over? When an adult does get inside, is it the app or the operating system that answers for it?
The protections Apple has switched on are real and I am glad of them. The work ahead is making sure the rules behind them are written in public, where parents, teachers and children can read them and argue with them, long before they are fixed in one company’s settings screen.













Comments