Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Age Verification topic
No spam. Unsubscribe anytime.
Age verification and enforcement take center stage as AG and experts weigh methods
Summary
Committee members pressed presenters on practical age-verification methods and enforcement after the Attorney General’s office cited a Roblox settlement; witnesses urged probabilistic/behavioral inference ('constructive knowledge'), layered approaches, and care to avoid data-retention risks.
Get email alerts on the Age Verification topic
No spam. Unsubscribe anytime.
Members of the Joint Interim Committees focused a sustained line of questioning on how to verify users’ ages without creating new privacy or security risks.
Brad Chenoweth, the attorney general’s office representative, cited the office’s recent $12.2 million settlement with a platform over age-verification practices and asked presenters what constitutes "reasonable" age verification. Rob Ellavel and Professor Arbel cautioned that biometric or documentation-heavy verification can be spoofed or create attractive breach targets. Ellavel suggested a legal construct called "constructive knowledge," which relies on the behavioral signals companies already collect—connections, clicks, follow lists—to infer whether an account likely belongs to a minor. He said constructive knowledge avoids requiring users to upload sensitive documents that could be hacked and still places legal obligations on operators who “should have known” the user was a minor.
Professor Arbel told the committee that all age-verification methods are probabilistic and should be matched to risk: lower-risk content can rely on behavioral inference, while high-risk access (for example, to information on harming others) should require stronger assurance measures. Arbel noted that layered systems can combine inference with supplemental checks (driver’s license, Social Security indexing) when high certainty is needed, and he emphasized proportionality in sanctions and record-retention rules.
Ellavel and other presenters also warned lawmakers about ‘‘cure periods’’—statutory deadlines that allow a company to fix an identified problem before enforcement—and argued that cure periods can make enforcement ineffective because companies can alter systems once alerted, erasing evidence and frustrating litigation or AG actions.
The hearing left several technical and legal details open. Committee staff were asked to task LSA with researching model legislation and enforcement models used in other states and to gather age-verification vendor options for follow-up review.

