Pornhub parent company Aylo sent letters to Apple, Google, and Microsoft urging that they adopt device-based age verification across their app stores and OSes
The company sent letters to Apple, Google, and Microsoft pushing for an alternative way to keep minors from viewing porn …
Context & Ripple Effects
Aylo’s earlier responses to age-verification mandates were service-level: it urged opposition to new state rules in 2023 and later planned IP-based blocks in Kentucky and Indiana.
By mid-2025, Aylo had agreed to use government-approved age-assurance methods in the UK. Its appeal to operating-system and app-store owners moves the enforcement question from individual adult sites toward the platforms that control devices and account ecosystems.
First-order effects
- Apple, Google, and Microsoft are directly asked to consider age-verification capabilities at the OS and app-store layer rather than leaving each pornography provider to run its own checks.
- Aylo positions device-level verification as an alternative to site-by-site compliance, but the letters themselves do not change access rules or establish a platform commitment.
Second-order effects
- If platform owners engage, adult-content providers and app developers could face pressure to integrate a common device-level age signal rather than deploy separate verification flows.
- The request sharpens the policy trade-off for platform gatekeepers: a shared control could reduce repeated checks for users, while making the platforms more central to privacy, eligibility, and enforcement decisions.
Third-order effects
- If regulators and services increasingly accept device-level proof of age, age assurance may consolidate around OS and app-store infrastructure instead of remaining a fragmented publisher obligation.
- That consolidation would extend platform gatekeepers’ role from app distribution to access control across the web; whether it occurs depends on platform adoption and regulatory acceptance.
The trend: Age-verification policy is increasingly testing whether device platforms, rather than individual websites, should become the primary enforcement layer for access-controlled content.