An app could carry a 17+ rating in Apple’s store while an underage user got past its age limit. Texas now requires Apple to ask whether someone creating an Apple Account is an adult—or has parental consent. The label described the software; the new question concerns the person trying to get it.
Key takeaways
- A 2021 investigation found that age limits were easy to evade across roughly 80 age-restricted App Store apps, including dating, sex, and gambling services.
- From June 4, affected people creating an Apple Account in Texas had to confirm they were 18 or older or obtain parental consent.
- Apple’s UK rollout with iOS 26.4 requires a credit card or ID for mandatory age confirmation tied to certain app access and purchases.
- Australian researchers created 50 test accounts across nine platforms and were never asked to verify age despite an under-16 ban.
- Meta’s August 2026 attorney-general settlement framework contemplates “reliable age signals” supplied by Apple and Google operating systems and app stores.
A 2021 investigation found age limits easy to evade across roughly 80 age-restricted App Store apps, including dating, sex, and gambling apps. That failure did not mean Apple had assigned the wrong ratings. A store can accurately classify an app without knowing who is opening it.
Age assurance is becoming a shared access-control layer for the consumer internet, rather than a check each social platform performs alone. The decisive contest is over liability routing: whether developers establish age and parental permission for themselves, or Apple and Google issue reusable signals through accounts, operating systems, and stores—and take on the identity, privacy, and enforcement work that follows.
The rating described the app, not its user
App stores were built to distribute, review, bill for, and govern software. An age rating helped a parent or user judge an app before downloading it; it was not proof that the person behind the screen met the rating. Each service could then impose its own sign-up rule or parental control, often without knowing what another service had learned about the same user.
In 2021, a proposal for device-setup age checks identified the missing connection: Apple and Google could determine a user’s age when a device was set up, then share an appropriate signal with apps implementing child-safety features. The proposal was already about an interface, not a better warning label. It placed the age claim where many apps could use it.
Legislation supplied a reason to build that interface. Coverage of U.S. age-verification laws puts approximately half of states in the enacted-or-advancing category. California’s Assembly passed a bill assigning age-verification duties to device makers and app stores, with Google and Meta supporting it. States have not agreed on one responsible party, but enough have assigned duties beyond the individual app to make an account-level answer valuable.
Texas turns an account fact into a developer interface
In October 2025, Apple told developers it planned to update its Declared Age Range API and add Texas age APIs for Apple Account users ahead of a January 1, 2026, start date. A federal judge temporarily blocked the Texas app-store law before that date. After an appeals-court ruling, Apple said that, from June 4, affected users creating an account in Texas had to confirm they were 18 or older or obtain parental consent.
The API matters because an account check and an app’s decision are separate operations. Apple can establish an age range or account status; a developer must decide which features to make available under the applicable rule. A parent’s authorization to create an account does not, by itself, settle what that child may do inside every app. WhatsApp’s parent-managed under-13 accounts show the distinction: Meta withholds Meta AI, Channels, and Status from those accounts even after the parent-child relationship has been set up.
Apple’s UK implementation shows how much evidence may sit behind a small eligibility result. With iOS 26.4, Apple began requiring a credit card or ID for mandatory age confirmation tied to certain app access and purchases. A developer might need only an age band, not a card number or an identity document. But Apple still has to ask for evidence, handle a failed check, and decide when the result can be used. For someone seeking an ordinary weather or sports app, Texas-related coverage raised the concern that this work could begin before the app is downloaded.
Android already mediates an app’s access to sensitive device services. Age assurance applies a related control in the other direction: an operating system or store can mediate a person’s access to software. That reversal makes consent architecture concrete. The account holder, the app provider, and the platform operator each make a different decision; no single age check makes the other two disappear.
Apple, Google, and Meta disagree over who pays for proof
Sources describing state-bill negotiations said Apple and Google favored self-attested age checks without private lawsuits, while Meta backed bills placing verification duties on app stores rather than platforms. Google called Utah’s app-store bill an effort by Meta and others to offload child-safety duties onto stores. Those positions concern different costs as much as different technologies: asking for evidence, protecting it, passing a usable result to developers, and defending the result when it is challenged.
Meta has a reason to want proof from upstream. Its August 2026 attorney-general settlement framework contemplates “reliable age signals” from Apple and Google operating systems and app stores. One issuer could spare a service from asking every user for the same underlying evidence. It could also make Apple or Google the first party asked why an account was classified incorrectly. Store operators, meanwhile, would be taking on an identity-adjacent duty inside the distribution businesses they already run. Google Play’s gatekeeping role would extend from deciding how developers reach users to helping decide which users may reach developers.
Self-attestation keeps that upstream job comparatively light, but a declaration and an independently tested age signal do not offer the same assurance. Meta says its settlement requires an age-assurance standard subject to independent testing. Neither an API name nor a parental-consent screen answers how reliably a minor is identified, what evidence was used, or which party must correct an error.
A store check cannot finish an app’s job
Ohio places parental-consent duties on platforms serving users under 16. The UK ICO and Ofcom have asked social-media platforms to use highly effective checks against under-13 accounts. Both approaches leave an app responsible for behavior inside its service, even if an operating system supplies an age signal. Apple can condition a download; WhatsApp still has to decide whether an under-13 account sees Status.
Mandates also do not guarantee that a user encounters a gate. In one Australian study, researchers created 50 test accounts across nine platforms and were never asked to verify age, despite an under-16 ban. The Australian researchers tested whether platforms asked for verification, not how accurately any particular method determined a user’s age. A reusable signal is useful only where a service requests it and acts on it.
Regulators have left that request at different addresses. Texas assigns duties to marketplaces and developers; Ohio directs a duty to platforms; UK regulators press social services directly. Apple has already shown, through its EU App Store changes, that it can apply different store rules by geography. Age APIs give developers a way to receive a local answer from a common account system, while giving the account operator another jurisdiction-specific decision about access.
Frequently asked questions
Does the Texas Apple Account requirement apply to people who already have an Apple Account?
The piece establishes the requirement for affected users creating an account in Texas from June 4. It does not specify whether, when, or how existing account holders face a comparable check.
What evidence must a Texas user submit to prove age or secure parental consent?
The Texas description in the piece says users must confirm adulthood or obtain parental consent, but does not identify the underlying evidence or verification method. Apple’s UK implementation shows one possible model—credit card or ID—but that does not establish the Texas method.
What exact information will an app receive from Apple’s age APIs?
The piece says Apple can establish an age range or account status, while developers decide which features to allow. It does not specify the API’s fields, age bands, retention rules, or whether apps receive a consent indicator alongside an age result.
How can a user correct an incorrect age classification?
The piece identifies error correction as unresolved: it says neither an API name nor a parental-consent screen establishes which party must correct an error. That leaves the appeals process and responsibility between platform, store, and app unspecified.
How account-level age assurance moved upstream
- 2021 — A proposal called for Apple and Google to determine age during device setup and share an appropriate signal with apps.
- October 2025 — Apple told developers it planned to update its Declared Age Range API and add Texas age APIs ahead of a January 1, 2026 start date.
- January 1, 2026 — The planned Texas start date cited by Apple; a federal judge temporarily blocked the app-store law before it took effect.
- March 26, 2026 — Apple rolled out mandatory UK age verification with iOS 26.4, requiring a credit card or ID for certain access and purchases.
- August 28, 2026 — Meta’s attorney-general settlement framework described using reliable age signals from Apple and Google operating systems and app stores.
The 17+ label still describes the app. In Texas, the lock has moved to the Apple Account.