There is still no single federal law requiring age verification for general online access in the United States. What exists instead, as of October 2026, is a fast-growing patchwork: 27 states now require age verification on adult-content sites, led by Texas, Louisiana, Tennessee, Utah, and Virginia; Florida, Utah, Arkansas, and Virginia have passed social-media laws for minors with very different fates in court; New York has set a January 2027 start date for its feed-based rules; and California and Colorado are pushing age signals into app stores and operating systems. Each law has its own scope, threshold, and enforcement posture. Some are fully in force. Some are tied up in First Amendment litigation. One has already been upheld by the U.S. Supreme Court. If you run a platform, forum, store, or community with US users, "wait for Washington" is no longer a compliance strategy — but neither is building fifty bespoke gates.
No federal blanket law does not mean no federal exposure
COPPA still applies to services directed at children under 13, and the FTC's 2026 COPPA Policy Statement signals enforcement discretion in favour of age verification technologies that are accurate, secure, clearly disclosed, and data-minimal. A sloppy age gate that hoards identity documents can create federal privacy exposure even in states with no age-check statute at all. See the FTC COPPA 2026 policy breakdown.
Quick answer
- Who must comply: Adult-content publishers in 27 states; social platforms with minor users in Florida and, depending on appeals, Utah and Virginia; feed-driven platforms in New York from 25 January 2027; app developers under California's AB 1043 from 1 January 2027.
- What's federal: No blanket law. COPPA (under-13) plus the FTC's 2026 posture favouring accurate, secure, data-minimal verification.
- Court status: Adult-content laws are winning. Texas HB 1181 upheld by SCOTUS on 27 June 2025; Tennessee's injunction vacated in November 2025. Social-media laws are split: Arkansas permanently blocked (March 2025), Virginia SB 854 blocked (February 2026), Florida HB 3 enforceable pending appeal.
- The trap: Per-state checkbox pages, or document KYC that turns your database into a PII vault under CCPA and state privacy laws.
- Recommended approach: One integration with configurable thresholds per state (13+/16+/18+/21+), privacy-first tokens, and minimal data retention.
- How AgeOnce helps: Single API or WordPress plugin; signed age tokens and an Audit ID; no ID storage on your servers. Product-side summary: US age verification compliance. Run the live demo.
No federal blanket law — and why that makes compliance harder, not easier
In the EU, platforms can at least plan around one instrument (the DSA) and one technical blueprint. In the US, the absence of a federal age-verification statute means the action happens in state legislatures and state attorney general offices, each moving at its own speed and defining "minor," "covered platform," and "reasonable verification" differently.
Two federal anchors still matter:
- COPPA governs services directed at children under 13 and imposes parental-consent and data-handling duties — unchanged in scope, newly energetic in enforcement.
- The FTC's 2026 COPPA Policy Statement effectively grades age-verification technology. Tools that are accurate, secure, give clear notice, and minimise retention are treated favourably; tools that quietly accumulate identity data are not. That posture rewards the same architecture most state laws are converging on: prove the threshold, keep almost nothing.
The practical consequence: you cannot copy one state's rulebook nationwide, but you can standardise on one verification architecture that satisfies the strictest common denominator — effective assurance, configurable thresholds, minimal retention.
The state patchwork at a glance
The table below summarises where the major state regimes stand as of October 2026, with adult-content and social-media laws shown as separate rows because the same state can have one in force and the other blocked. Treat it as a map, not legal advice: several of these laws are in active litigation, and status can change with a single ruling.
| State | Law and lane | Status (October 2026) | What it requires |
|---|---|---|---|
Texas | Adult content (HB 1181, Civ. Prac. & Rem. Code ch. 129B) | In force. Upheld 6-3 by the US Supreme Court on 27 June 2025 (Free Speech Coalition v. Paxton). | 18+ before access where more than one-third of content is harmful to minors; verifier may not retain identifying information. |
Louisiana | Adult content (Act 440, La. R.S. 9:2800.29) | In force since 1 January 2023. Private right of action. | 18+ via digitized ID, government ID, or transactional-data method. |
Tennessee | Adult content (Protect Tennessee Minors Act) | In force. Sixth Circuit vacated the preliminary injunction on 4 November 2025 and remanded under Paxton. | 18+ before access; applies beyond commercial entities; criminal provision. |
Utah | Adult content (SB 287) | In force since 3 May 2023. Private right of action. | 18+ via digitized ID or commercial verification. |
Utah | Social media minors (Minor Protection in Social Media Act) | Preliminarily enjoined by a federal court on 10 September 2024. | Age assurance for all account holders; restrictions and parental tools for minors. |
Virginia | Adult content (SB 1515, Va. Code 8.01-40.5) | In force since 1 July 2023. Civil liability. | 18+ via commercial database or other commercially reasonable method. |
Virginia | Social media under 16 (SB 854) | Took effect 1 January 2026; preliminarily enjoined on 27 February 2026. State has appealed. | Age verification for all users; one hour per day default for under-16s. |
Arkansas | Social media minors (Act 689) | Declared unconstitutional and permanently enjoined on 31 March 2025. Appeal pending in the Eighth Circuit. | Not enforceable. Arkansas also has a separate adult-content age verification law that is in force. |
Florida | Social media minors (HB 3, Fla. Stat. 501.1736) | Enforceable. Eleventh Circuit stayed the injunction on 25 November 2025; appeal argued 10 March 2026. The Attorney General has begun enforcement. | No accounts under 14; parental consent for 14- and 15-year-olds on platforms with addictive features. A separate HB 3 section covers adult-content sites. |
New York | SAFE for Kids Act (addictive feeds, nighttime notifications) | Final rules released 28 July 2026. Law takes effect 25 January 2027. | Determine whether a user is under 18 before serving algorithmic feeds or overnight notifications; parental consent otherwise. |
California | Age-Appropriate Design Code (AADC) | Ninth Circuit, 12 March 2026: age-estimation duty no longer enjoined (remanded); data-use and dark-pattern rules remain enjoined as vague. | Estimate the age of child users or apply child-level privacy protections to everyone. |
California | Digital Age Assurance Act (AB 1043) | Signed 13 October 2025. Operative 1 January 2027. | OS providers collect age at account setup and expose an age-bracket signal API; app developers must request it. |
Colorado | Age Attestation on Computing Devices (SB 26-051) | Enacted 2026. Takes effect 1 July 2028. | OS and app-store age-bracket signals; up to $2,500 per affected minor for negligent violations. |
Verified against statutes, court orders, and attorney general releases on 1 October 2026. Twenty-seven states have adult-content age verification laws; this table shows the most-cited ones plus the social-media and platform-signal laws that are often confused with them. Court status can change with a single ruling.
Three patterns are worth reading out of that table. First, adult-content laws are the most battle-tested: Texas survived the Supreme Court, and Tennessee's injunction was lifted on the strength of that ruling. Second, social-media-minor laws are the most litigated: Arkansas's is permanently blocked, Virginia's and Utah's are enjoined, while Florida's is being enforced after an appeals court stayed the injunction. Third, the newest wave targets infrastructure, with California (January 2027) and Colorado (July 2028) pushing age signals into app stores and operating systems.
Adult-content laws by state: the 27-state list
Louisiana started the wave with Act 440 on 1 January 2023, and the model spread quickly. By September 2026 the Free Speech Coalition tracker listed 27 states with adult-site age verification laws: Alabama, Arizona, Arkansas, Florida, Georgia, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Mississippi, Missouri, Montana, Nebraska, North Carolina, North Dakota, Ohio, Oklahoma, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, West Virginia, and Wyoming.
Most follow the Texas template: a commercial site where more than one-third of the material is sexual material harmful to minors must verify that visitors are 18 or older, and the verifier may not retain identifying information. The variations matter if you operate in several states. Four states (Indiana, South Dakota, Tennessee, and Missouri) apply their laws to all covered sites, not just commercial entities. Five (Florida, Indiana, Kansas, Kentucky, and Wyoming) apply only to residents of that state. Enforcement is a mix of attorney general actions and private lawsuits by parents. The statute-level walkthrough, penalties, and the architecture the retention bans effectively require are in the Texas HB 1181 compliance guide; the operational side for adult platforms is in adult content age verification.
Three lanes of state regulation
Grouping the statutes by target makes the patchwork legible. Almost every US age law falls into one of three lanes.
Lane 1: Social media and minors
Utah, Arkansas, Florida, and Virginia went after social media accounts for users under 18, typically requiring age assurance plus parental consent for minors. This is the lane the courts have resisted most: Arkansas's Act 689 was permanently enjoined on 31 March 2025, Utah's Minor Protection in Social Media Act has been enjoined since September 2024, and Virginia's SB 854 (age verification plus a one-hour daily default for under-16s) was blocked on 27 February 2026, two months after taking effect. Florida's HB 3 is the exception: the Eleventh Circuit stayed the injunction in November 2025, and the Florida Attorney General is enforcing the under-14 ban and the parental-consent rule for 14- and 15-year-olds while the appeal is decided. New York's SAFE for Kids Act is narrower and, arguably, smarter: it targets addictive algorithmic feeds and nighttime notifications served to minors, with AG-enforced penalties of up to $5,000 per violation. The Attorney General released final rules on 28 July 2026, and the law takes effect on 25 January 2027. If your product has a feed, ranking algorithm, or push-notification layer, this is your lane — covered in depth in our NY SAFE, Texas, and California guide. Community platforms should also review the forums use case, since UGC communities with minor-accessible registration increasingly resemble "social media" in statutory definitions.
Lane 2: Adult content publishers
Texas HB 1181, Louisiana, Tennessee, and 24 other states require commercial publishers of sexual material harmful to minors to verify that visitors are 18+ before access. This is the lane with the clearest legal footing after June 2025 (more on that below) and the steepest per-day penalties — Texas allows up to $10,000 per day for missing verification, $10,000 per instance of retained identifying information, and up to $250,000 more where a minor accesses covered material. Notably, most of these statutes prohibit the verifier from retaining identifying information, which is a legislative push toward third-party, data-minimal providers rather than merchant-side ID collection.
Lane 3: Design codes and platform-level age signals
California's Age-Appropriate Design Code (AADC) moved forward after the Ninth Circuit narrowed its injunction on 12 March 2026: the court held that the duty to estimate the age of child users (or apply child-level protections to everyone) is not facially unconstitutional and sent it back to the district court, while leaving the data-use and dark-pattern provisions enjoined as vague. Meanwhile, California's Digital Age Assurance Act (AB 1043), signed in October 2025 and operative 1 January 2027, requires operating systems to collect age at account setup and expose an age-bracket signal that app developers must request. Colorado's SB 26-051 does the same from 1 July 2028. Even if platform-level signals eventually carry some of the load, web operators will still need their own gates for browser traffic — app-store APIs do not cover your website, your WooCommerce checkout, or your gaming community.
$10,000/day
Maximum Texas HB 1181 penalty for operating without required age verification, plus up to $250,000 if a minor accesses covered material
Court challenges: social-media laws blocked, adult-content laws upheld
The litigation picture splits cleanly by lane, and any compliance plan should be built to survive rulings in both directions.
Social-media-minor laws keep losing at the district court level. A federal court permanently enjoined Arkansas's Act 689 on 31 March 2025 as a content-based restriction that was not narrowly tailored; the state's appeal is pending in the Eighth Circuit. Virginia's SB 854 was preliminarily blocked on 27 February 2026, with the judge finding the law both over- and under-inclusive; Virginia has appealed. Utah's social-media act has been enjoined since September 2024. Florida is the counter-example: the Eleventh Circuit stayed the HB 3 injunction on 25 November 2025, and at oral argument in March 2026 the panel pressed the industry plaintiffs hard on standing, so Florida is enforcing while the appeal runs.
Adult-content laws have gone the other way. The U.S. Supreme Court upheld Texas HB 1181 on 27 June 2025 in Free Speech Coalition v. Paxton, applying intermediate scrutiny and holding that the law only incidentally burdens adults' protected speech. On the strength of that ruling, the Sixth Circuit vacated the injunction against Tennessee's law on 4 November 2025. That pair of decisions is the single most important development in US age-gate law: it establishes that well-scoped 18+ checks on adult content are constitutionally viable, and it has emboldened legislatures in both red and blue states.
Betting your compliance posture on courts striking down every state age law is a losing strategy after June 2025. Betting your users' identity documents on every law surviving is a losing strategy too. The architecture that wins either way keeps proof strong and data small.
Where the hedging belongs
Court status changes fast. Virginia's and Utah's blocks are preliminary, not final; Arkansas's permanent injunction and Florida's stay are both on appeal. The defensible operator posture is to comply with laws currently in force, monitor stayed ones, and keep your data handling clean enough that no outcome strands you with a retention problem.
One integration for a fifty-state problem
If you serve users in multiple states, the wrong answer is fifty flows. The right answer is one verification integration with configurable policy:
- Threshold per surface and jurisdiction. The same integration should enforce 18+ on adult content, 21+ on restricted SKUs, and 16+ or parental flows where a social-media-minor law applies — driven by configuration, not code forks.
- Method that regulators treat as effective. Self-declared birth years fail every statute in the table above. ID + liveness, accredited digital ID, or validated estimation (where a statute permits it) are what "commercially reasonable" now means.
- Retention that survives any court outcome. If a state law you complied with is later struck down, you do not want to explain to a CCPA plaintiff why you are still holding a vault of driver's licences collected under it.
The conversion stakes are real. Industry UX benchmarks commonly cite 40–60% registration abandonment when document upload is required at sign-up. A gate that satisfies the Texas AG but halves your funnel is not a win — which is why the first full verification should happen once, and returning users should get a lightweight reverification that feels like unlocking a phone.
40–60%
Typical registration abandonment when document upload is required at sign-up (industry UX benchmarks)
Privacy-first tokens, not ID vaults
Your platform does not need names, document numbers, or selfie files. It needs a reliable, provable answer: is this user above the required threshold?
The privacy-first pattern — the same one the FTC's 2026 posture rewards and Texas-style retention bans effectively mandate — works like this:
- The user completes photo ID matching + liveness in the browser, once, with the verification provider.
- The provider derives the threshold and returns a signed outcome (for example
18+ verified) plus an Audit ID to your application. - No ID images, document numbers, or biometric archives touch your database. If a regulator asks, the Audit ID proves the check happened; if an attacker breaches you, there is no document vault to steal.
That is the core argument in why tokens beat ID galleries: compliance and breach risk are not a trade-off when the architecture is right.
CCPA and multi-state privacy exposure
Holding only a verification outcome, timestamp, and audit reference dramatically shrinks what a database leak exposes — which matters for breach notification duties, vendor security reviews, and class-action exposure under CCPA and the growing set of state privacy laws.
At AgeOnce your application receives only an age threshold and an Audit ID — not names, document images, or biometric archives.
See how we do itHow verification options compare
| Traditional document KYC (Onfido, Jumio-class) | Wallet / age-estimation only | AgeOnce | |
|---|---|---|---|
| First-time UX | Full ID scan + selfie on every new site | App download or selfie-only (varies by risk) | In-browser ID + liveness once |
| Return / second site | Often full ID again | Depends on wallet adoption | In-browser face reverification |
| Data on your server | Risk of storing vendor payloads if misconfigured | Wallet or vendor may hold attributes | Signed threshold + Audit ID only |
| CCPA / breach exposure | High if IDs are retained locally | Lower if vendor handles storage | Low — no document gallery on your side |
| WordPress / SMB fit | Poor without enterprise budget | Mixed — user must adopt extra apps | Plugin or API in hours, not months |
| NY SAFE / TX HB 1181 / CA AADC | Can work if methods are effective and data-minimal | Varies — estimation alone may not meet all gates | ID + liveness first; reverification with fresh audit trail |
How verification approaches compare for US-facing registration, communities, and restricted commerce.
Enterprise document-KYC suites and government wallet apps remain the right tools for AML programmes and accredited identity schemes. For web age gates across a state patchwork, the requirements are different: defensible assurance, per-state configurability, minimal PII, and a flow adults will actually complete.
Integration paths: API for custom stacks, plugin for WordPress
| Integration path | Best for |
|---|---|
Next.js, React, Node.js, Python, headless SaaS, mobile apps — redirect, callback, signed token + Audit ID | |
bbPress, BuddyBoss, membership sites, vape/alcohol checkout — install, configure gates, no custom ID storage |
Custom SaaS and modern frameworks
The AgeOnce API uses an OAuth-style redirect: send the user to verify, receive an authorization code on callback, exchange it server-side for a signed token and Audit ID, and gate routes on the token. For a Next.js, React, Node, or Python backend, the work is a redirect URL, a callback handler, token validation, and a session flag — often a day or less. The API vs plugin comparison covers when each path fits.
WordPress and WooCommerce
A large share of US small-business sites — vape and alcohol stores, supplement shops, hobby forums, membership communities — run on WordPress. State laws do not carve them out. The AgeOnce plugin enforces gates at WooCommerce checkout, forum registration, or member-area access with per-threshold rules and no ID storage on your server. Setup, OAuth credentials, and checkout rules live on the WordPress age verification page.
WordPress age gates in under 3 minutes
Install the AgeOnce plugin, connect OAuth, and gate WooCommerce checkout or forum registration — no ID storage on your server.
How ready is your platform? A 2-minute self-assessment
Reading about statutes is one thing; knowing which gaps apply to your stack is another. Check off what you already have in place below — based on your score, you will get an honest readiness verdict and the single most useful next step, whether that is fixing verification methods, closing configuration gaps, or validating an already-solid setup.
Where does your platform stand?
Check what you already have in place. You will get a readiness assessment and the most useful next step for your situation. Progress is saved in this browser.
Next step: one integration, every state
The US patchwork will keep shifting — new statutes, new injunctions, new appellate rulings. What should not shift is your architecture: effective verification, configurable thresholds, signed tokens instead of ID vaults, and an audit trail that satisfies whichever AG comes asking.
Run the live demo — ID + liveness once, then in-browser reverification on return, with per-state thresholds from one integration. Compare volume tiers on pricing. On WordPress or WooCommerce? Start from the WordPress age verification setup page and gate checkout or registration today.
Frequently asked questions
No general federal age verification law covers all online access. COPPA applies to services aimed at children under 13, and the FTC's 2026 COPPA Policy Statement favours accurate, secure, data-minimal age verification technologies. Several states have passed their own laws for social media, gaming, or adult content.
Twenty-seven states have adult-content age verification laws as of September 2026, including Texas, Louisiana, Tennessee, Utah, Virginia, Florida, and North Carolina. Social-media laws for minors exist in Florida, Utah, Arkansas, and Virginia but several are blocked in court. New York's SAFE for Kids Act takes effect on 25 January 2027. California's AB 1043 app-store age signals start 1 January 2027; Colorado's follow on 1 July 2028.
Adult-content laws are. The Supreme Court upheld Texas HB 1181 on 27 June 2025, and the Sixth Circuit lifted the injunction against Tennessee's law in November 2025. Social-media laws are mixed: Arkansas's was permanently struck down in March 2025, Virginia's SB 854 was blocked in February 2026, Utah's is enjoined, while Florida's HB 3 is enforceable pending appeal after the Eleventh Circuit stayed the injunction in November 2025.
The FTC's 2026 COPPA Policy Statement says it will use enforcement discretion for age verification technologies that are accurate, secure, provide clear notice, and minimise data retention. Well-designed privacy-first tools are less likely to be targeted.
Self-declared birth years are insufficient where statutes require effective assurance. Regulators and courts accept photo ID matching with liveness, accredited digital identity, and validated age estimation where a statute permits it. Several adult-content laws also prohibit verifiers from retaining identifying information from the check.
Comply with laws currently in force in states you serve, monitor stayed or blocked statutes, and keep data handling minimal so any outcome does not leave you with an ID vault. One integration with configurable thresholds per state or product surface is more resilient than rebuilding flows per ruling.



