Skip to content
Websites & online business

Age verification laws for websites — which sites now have to check, and how

For two decades it was safe to assume that a US law making adults prove their age before reading something online would not survive the First Amendment. That assumption ended on 27 June 2025, when the Supreme Court upheld the Texas statute in Free Speech Coalition v. Paxton. The live question is no longer whether these laws stand. It is which sites they reach, what a check has to do, and what you are forbidden to keep afterwards — and the answers are narrower than the headlines and wider than most operators assume.

9 min readPublished How we write these

The short version

  • The state adult-content statutes reach a narrow class: commercial sites where sexual material harmful to minors crosses a composition threshold. Texas uses more than one-third of the material, Kansas 25% of the webpages viewed in a calendar month, and several states name no proportion at all.
  • Paxton applied **intermediate** scrutiny, not strict scrutiny and not rational basis. The reasoning depends on the material being unprotected as to minors, so it does not validate age-gating a general-audience site.
  • A self-declared date of birth is not a listed method anywhere in this family. The statutes name government ID, transactional-data lookups and, in some readings, digital identification — and the Court expressly declined to decide whether Texas allows face scans.
  • The mandate comes with a retention ban. Texas forbids the site or its vendor from retaining any identifying information, at $10,000 per instance on top of $10,000 per day of non-compliance; Kansas gives the individual their own damages claim for it.

The statutes that matter here are a specific family, not a general internet age limit: state laws requiring commercial sites that publish sexual material harmful to minors to verify that a visitor is 18 or over. Conflating them with the app-store and social-media laws — which do something different and sit on much less settled ground — is the most common error in advice written since the Supreme Court ruled.

Which sites actually have to check

Coverage turns on a composition threshold, and no two statutes state it the same way. Texas reaches a commercial entity that knowingly and intentionally publishes or distributes material on a website "more than one-third of which is sexual material harmful to minors". Kansas draws its line at material appearing "on 25% or more of the webpages viewed on such website in any calendar month" — a share of traffic, measured monthly, rather than a share of the library. Trackers of the field record a third formulation, "substantial portion", and a number of states that name no proportion at all.

Same idea, incompatible denominators: total material, pages actually viewed in a month, and in some states nothing to divide by. There is no single calculation that answers the question everywhere, and no regulator computes it for you. The assessment is yours, made before anyone asks, and it is the first thing an attorney general's office will want you to show your working on.

How much assurance each kind of site owes

Shop, blog, SaaS
Child-directed service
App stores and developers
Adult-content sites

No age step

Neutral age screen

Age category and consent

Identity-grade verification

Only the top band is an identity check. The bands below it are answered by a question, a signal from someone else, or nothing at all — and moving up a band because the news said age verification is now lawful is a mistake.

What Paxton held, and the three questions it left open

The Court applied intermediate scrutiny — rejecting both the strict scrutiny the challengers wanted and the rational-basis review the Fifth Circuit had used. The reasoning is worth getting exactly right. Adults do have a right to access material that is obscene only to minors, and being made to verify burdens that right. But, the majority held, "adults have no First Amendment right to avoid age verification", so the burden is incidental to regulating something the First Amendment does not protect at all: a minor's access to obscene-for-minors material. Requiring proof of age is "an ordinary and appropriate means" of enforcing an age line, no different in kind from the ID check at a counter. The vote was 6–3, with Justice Kagan dissenting.

What that reasoning does not do is bless age checks for speech that is protected for minors. Every step of it depends on the covered material being unprotected as to the people being excluded. A statute gating a general-audience site or a social network asks a different question, and the Court did not answer it.

Two readings of the same decision

The wide reading

  • Age checks are settled
  • Any site can be gated
  • Scrutiny no longer bites

What the Court said

  • Obscene-to-minors material only
  • Intermediate scrutiny still applies
  • Protected speech untouched

The holding turns on content unprotected as to minors. Nothing in it reaches a general-audience site.

Commentary overstated this ruling in both directions. It is neither a green light for age-gating the web nor a narrow curiosity — it is a holding about one category of material.

Three questions were expressly reserved, and each of them is operational. Footnote 7 declines to decide whether a covered site must age-gate all of its content or only the obscene-to-minors subset, and whether "obscene to minors" means obscene to every minor or to any minor. Footnote 14 declines to decide whether the Texas statute even permits face scans: Texas said it does, the challengers said it does not, and the Court held it need not resolve the disagreement because a state is not obliged to pick the least restrictive method. An operator running facial age estimation in Texas is therefore acting on an open question, not a settled permission.

What counts as a reasonable method, and what never has

No statute in this family accepts a self-declared date of birth or an "I am over 18" button. Texas requires digital identification, or a commercial system verifying age by government-issued identification or "a commercially reasonable method that relies on public or private transactional data" — a defined term that expressly names records from mortgage, education and employment entities. Kansas requires a commercially available age and identity database, or any other commercially reasonable method, with the attorney general empowered to approve methods and standards. The splash page that was the industry norm before 2023 is now evidence of non-compliance rather than a defence to it.

The methods, cheapest first

  1. Self-declared age

    Not a listed method in any of these statutes. It is the failure they were written against.

    Free
  2. Transactional data lookup

    Named in the Texas definition. Invisible to the user, and fails on anyone with a thin record.

    Cents per check
  3. Facial age estimation

    Needs a buffer above 18 and a second route for everyone it declines. Legality varies.

    Per check, plus a fallback
  4. Government ID via a vendor

    Accepted everywhere and the largest breach surface. The vendor should return yes or no and keep nothing.

    Highest friction

Covered sites run these as a cascade, not a choice — cheapest first, ID as the last resort.

Facial age estimation is deployed against a challenge age set well above 18 precisely because accuracy degrades near the boundary; NIST publishes an ongoing evaluation of how far the estimates drift.

A VPN is the visitor's decision, not yours, and nothing in this family obliges you to defeat one. What the statutes do reach is location, and they reach it broadly: the Kansas duty runs to any person "who is a resident of this state or who is located in this state at the time of such attempted access". Residency alone is enough, which means geo-blocking an IP range is a mitigation rather than a defence.

The data you are forbidden to keep

This is the half of the mandate that gets built wrong, because it inverts the usual compliance instinct to retain proof. Texas provides that a commercial entity performing the check, or a third party performing it for them, "may not retain any identifying information of the individual". The penalty is separate and additive: $10,000 for each instance of retention, on top of $10,000 for each day the site operates without verification, and up to a further $250,000 where a minor got through because of the failure. Kansas takes a different route to the same place and makes a company that knowingly keeps identifying information after granting access liable to that individual in damages, with fees.

The consequence is architectural rather than editorial. A vendor that receives the document, returns a yes or a no and keeps nothing is the compliant shape; storing the ID image "for audit purposes" converts your compliance control into your largest liability. Nothing from the check should reach your logs, your error tracker or your analytics, and the storage the cascade sets belongs in the inventory behind your cookie policy. Note too how wide the definition can be — the Kansas list of identifying information runs to biometric information, search activity, photos, voice recordings and geolocation, none of which reads like an ID document.

Website terms of use template

Free, and the place the eligibility representation, the account-termination right and the age-related warranties actually live. Draft it against the check you run, not the one you intend to build.

Open

Who enforces it, and how it reaches a site with no office in the state

There are two enforcement models and the difference matters more than the headline penalty. Texas is attorney-general-only: the AG may sue in a Travis County district court for an injunction, a civil penalty and fees, and no private claimant appears in the chapter. Kansas runs both tracks. The AG can seek $500 to $10,000 per violation, and separately the parent of a minor who got through may sue for actual damages, statutory damages of not less than $50,000, and costs — with each access counted as a separate violation. That last clause is the number that should worry a covered operator, because exposure then scales with traffic rather than with elapsed days.

Physical presence is not the hook and never was. These statutes define the duty around the visitor rather than the business: Kansas expressly, and Texas by attaching the obligation to any individual attempting to access the material, wherever the entity sits. Many covered sites have responded by geo-blocking whole states rather than litigating jurisdiction, which tells you what their counsel makes of the argument.

The check is moving up the stack

The newer laws do not ask the site to verify anyone. Texas's App Store Accountability Act, in force since 1 January 2026, requires an app store to verify the age category of every account holder in the state — child, younger teenager, older teenager or adult — to affiliate a minor's account with a parent account, and to obtain consent for each individual download or purchase. Blanket consent covering multiple downloads is itself a violation. Developers must rate their apps, notify the store before significant changes, read the category the store exposes, and delete that data once the check is done. A breach is a deceptive trade practice under the Texas consumer statute.

It is in force, but on a procedural footing rather than a resolved one. A federal district court preliminarily enjoined the Act in December 2025; the Fifth Circuit stayed that injunction; and on 6 July 2026 the Supreme Court denied the challengers' emergency applications to vacate the stay, with no noted dissents. That is not a ruling on the merits, and the Fifth Circuit appeal is still live. Utah enacted the first such law and its obligations run on their own, later timetable.

If you do not publish adult content

For most sites the honest answer is that none of this reaches you, and the correct response to the news is to do nothing. The ordinary obligations — the legal pages a site has to publish, and terms that are actually binding on the person who clicked — do not change. What does reach a general-audience site is narrower and older: COPPA, if your service is directed to children or you acquire actual knowledge of a user under 13. That is a different statute with a different trigger, and it does not mandate verification at all — it asks for a neutral age screen and verifiable parental consent before collection, and the FTC has long said a neutral third-party age screen does not by itself give you actual knowledge of a child's age.

One recent move is worth knowing if you have been avoiding age screening for fear of what it would tell you. On 25 February 2026 the FTC issued a COPPA policy statement saying it will not pursue operators that deploy age-verification technology and collect personal information solely to determine age, provided the data is deleted promptly, the method is reasonably accurate, third parties are trustworthy, notice is given and the information is kept secure. That is enforcement forbearance rather than a rule change, and the Commission has said a formal rule review will follow — but it removes the perverse incentive not to look.

The direction of travel is that the check happens once, higher up, and arrives at your service as a claim about the visitor rather than a document from them. Texas's app-store law already works that way: it hands a developer an age category and a consent flag, and forbids keeping either once used. A site built to read and act on an assertion it did not collect — and to say so honestly in its privacy policy — will be in better shape than one that has built an ID upload it will spend the next few years unbuilding. The obligation worth engineering for is not the gate. It is the signal, and the discipline of keeping nothing after it passes.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Does my website need age verification?

Only if sexual material harmful to minors makes up enough of it to cross a state threshold — more than one-third of the material in Texas, a quarter of the pages viewed in a month in Kansas, and in several states no stated proportion at all. Selling age-restricted goods, hosting user content or having some mature material well below the line does not trigger these statutes.

Is an "I am over 18" checkbox ever enough?

Not under any of the adult-content statutes. They list specific methods: government-issued identification, digital identification, or a commercially reasonable method drawing on public or private transactional data such as mortgage, education or employment records. A self-declared date of birth is the thing these laws were written to displace. It remains adequate for a neutral COPPA age screen, which is a different obligation entirely.

Can a state sue me if I have no office there?

Yes. The duty attaches to visitors who are resident in or located in the state at the time of access, not to businesses established there — the Kansas statute says exactly that, and Texas frames the obligation around the individual attempting to access the material. Enforcement has been aimed at operators well outside the enforcing states, and most of them have chosen to geo-block rather than test the jurisdictional argument.

Do I have to block VPNs?

No statute in this family requires you to detect or defeat a VPN, and none makes you liable for a visitor who misrepresents their location through one. The catch is the reverse: because the duty runs to residents as well as to people physically present, blocking an IP range is a sensible mitigation but not a complete answer, and enforcers have shown interest in how easily a block is bypassed.

Does running an age check create a privacy problem of its own?

It creates two. The statutes themselves forbid retaining identifying information, with penalties per instance in Texas and a private damages claim in Kansas, so keeping the evidence is its own violation. And collecting data from someone who turns out to be under 13 raises federal questions — which the FTC addressed in February 2026 by declining to pursue operators who verify age, delete promptly and keep the data secure.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week