When a minor lies about age, who carries the legal risk?
- Authority
- Federal Trade Commission (FTC)
- Rule type
- regulation
- Jurisdiction scope
- US federal; US state; EU
- Source text
- Read primary rule text ↗
Treat under-13 signals as potential COPPA actual knowledge, do not rely on minors' age misrepresentations, and verify vendor biometric-data and accuracy claims.

Regulation & Ethics. Last verified: August 3, 2026. This article is a jurisdiction-scoped risk map, not legal advice. The source status matters here: the FTC’s February 25, 2026 COPPA enforcement-discretion statement is discussed from the FTC press release and a Cooley alert; the primary FTC legal-library page was not verified for this article, so the six conditions are not quoted verbatim.
The practical question is not hard to state. A minor says they are old enough, or an AI age-estimation tool returns an adult result, and the platform later learns the user was under the relevant age threshold. The legal risk does not simply follow the false statement. It follows the actor’s statutory role, what the actor learned or processed, and the jurisdiction that can enforce.
The liability map before the doctrine
| Actor | Failure scenario | Main legal hook | Working risk allocation |
|---|---|---|---|
| Platform or online service | The user self-declares as old enough, or an AI tool estimates the user as old enough, but the platform later has under-age information. | COPPA actual knowledge for under-13 users; state age-verification, parental-consent, adult-content, and social-media statutes; consumer-protection and privacy obligations. | Highest exposure. The minor’s lie is not a reliable shield once the platform has statutory duties or knowledge-triggering facts. |
| Age-assurance or age-estimation vendor | The vendor estimates age from a face, document, device signal, or other assurance flow and supplies a result to the platform. | Biometric-data classification, processor/service-provider duties, accuracy representations, contract indemnity, and privacy-law claims. | Separate exposure. The vendor may not own the child-facing statutory duty, but it may own the biometric, accuracy, retention, and disclosure problem. |
| Minor | The child or teen enters a false birth date, uses an adult account, or bypasses an age gate. | Possible state-specific criminal misrepresentation statutes; contract law limited by infancy doctrine. | Usually narrower exposure. A child’s misstatement may matter factually, but it is rarely a platform’s dependable civil defense. |
| Parent, app store, or distribution intermediary | A law shifts verification, consent, or disclosure duties to an app-store or distribution layer. | State app-store age-verification and parental-consent statutes; constitutional litigation over enforcement. | Jurisdiction-specific. The intermediary may become the compliance checkpoint, but litigation posture and statutory text control. |

That allocation is why “the user lied” is usually the beginning of the review, not the end. A false age statement may explain how the user entered the service. It does not answer who collected data, who had actual knowledge, who offered an age-estimation result, who retained a biometric template or face-derived signal, who owed notice or consent, or which regulator can sue.
U.S. platforms: COPPA exposure does not disappear because the first answer was false
For U.S. services, COPPA remains the first serious checkpoint when the user is under 13. The FTC announced on February 25, 2026, by a 2-0 vote, an enforcement-discretion policy intended to encourage operators of general-audience websites and online services to use age-verification technologies. The FTC framed the policy as enforcement discretion, not a COPPA rule amendment, and the research record for this article does not support treating it as a safe harbor. The policy also does not relax COPPA obligations for services that are primarily child-directed, and it does not bind state attorneys general bringing parens patriae actions under COPPA.
The operational consequence is awkward but important: an age-assurance flow can reduce one risk while creating another. If a general-audience platform uses a tool that returns or flags an under-13 result, that result may create actual knowledge and re-trigger COPPA duties. The same mechanism a product team wants to cite as diligence can become the fact that prevents the company from saying it did not know.
The FTC press release and the Cooley alert both describe the policy as conditional and limited; this article does not restate the six conditions because the primary legal-library text was not verified during preparation. Launch counsel should therefore treat the policy as an enforcement-discretion signal to validate against the primary statement, not as a blanket authorization to collect more age-related data or to ignore under-13 outcomes. [1][2]
Actual knowledge is a file-management problem, not just a product signal
The hard part for a platform is deciding what happens after the system produces an age signal. Who receives the under-13 flag? Is the value stored? Is it written into a user profile, a moderation queue, a fraud table, a vendor dashboard, or a customer-support ticket? Can trust-and-safety reviewers see it? Can the ad stack see it? Is it logged after an appeal? Those choices determine whether a company has built a narrow age gate or a durable knowledge record.
A platform that wants the benefit of age assurance has to own the downstream handling. If the service receives an under-13 result, suppresses it, and continues ordinary data collection, the problem is no longer the minor’s initial birth-date entry. It is the platform’s treatment of a knowledge-triggering fact.
State laws: enforcement posture may matter before the First Amendment question is finished
The state-law layer is no longer a theoretical patchwork. On July 6, 2026, the Supreme Court allowed Texas SB 2420, an app-store age-verification and parental-consent law, to be enforced while litigation continued. That posture matters even if a company expects to keep litigating constitutional defenses: an enforceable statute changes launch timing, vendor selection, parental-consent flows, and indemnity negotiations now, not after the First Amendment merits are finally settled. [3]
Advocacy sources should not be mistaken for neutral regulatory digests, but their numbers can still identify pressure points. EFF’s 2025 year-in-review described the year as one in which roughly half of U.S. states had mandates for age verification tied to adult content or social media, reported that nine states’ adult-content laws became effective in 2025, and attributed a 1,150% VPN-demand surge in Florida to the state’s age-verification regime. Those figures support a narrow point: users respond to age gates, and circumvention pressure is part of the compliance environment. They do not prove that every mandate is ineffective or unconstitutional. [4]
The IAPP has likewise treated emerging global and U.S. age-verification requirements as a legal patchwork rather than a single compliance model. That is the correct posture for counsel. A platform cannot assume that a COPPA-oriented design answers state adult-content rules, app-store obligations, social-media parental-consent statutes, or private-right-of-action exposure. [5]
Some state-law details in the current research record come from a secondary landscape page rather than primary legislative text. California AB 1043 is described there as effective January 1, 2027; Utah is described as using a 95% age-assurance standard; Virginia SB 854 and Nebraska LB 383 are also summarized, with Nebraska described as effective July 1, 2026 and carrying a $2,500-per-violation figure plus a private right of action. Those details should be treated as leads for primary-law verification before they are put into a launch checklist, contract schedule, or board memo. [10]
The practical failure rate is real, even when the legal defense is weak
Children lying about age is not an edge case. Jarvie and Renaud’s 2024 article in Children reports an Ofcom finding that 60% of UK 8-to-12-year-olds held social-media accounts despite 13-plus minimums, and a French survey finding that 44% of 11-to-18-year-olds had lied about their age online. Those are attitude-and-behavior indicators, not liability rules, but they make clear that any platform relying on self-declared age is relying on a known weak point. [6]
Bypass behavior has also moved beyond typing the wrong birth year. Public reporting describes children using AI age-altered selfies and deepfakes to defeat age checks. The point is not to provide a circumvention manual. It is to keep the risk analysis honest: when a platform chooses a particular age-assurance method, it is choosing a failure mode, an appeal burden, and a set of records that may later be reviewed by a regulator, court, or plaintiff’s lawyer. [7]

Vendors: the biometric classification question is still a risk fork
Age-estimation vendors sit in a different position from platforms. They may not decide the user relationship, the community rules, or the statutory age threshold. They do decide, or at least heavily influence, whether the age check uses a face image, a document scan, a liveness check, a derived age score, a retained audit artifact, or a deletion workflow. That puts the vendor in the biometric and accuracy layer even when the platform carries the child-facing statutory duty.
The unresolved issue is not whether every facial age-estimation system is always biometric data. It is whether a procurement lawyer can safely treat it as never biometric. Under GDPR Article 4(14), biometric data turns on technical processing of physical, physiological, or behavioral characteristics allowing or confirming unique identification. Some age-estimation systems are designed to estimate age rather than identify a person; some may still process face-derived measurements in ways that invite biometric-data arguments. The classification depends on the technical design, retention, matching capability, and legal forum.
The European signals are not uniform enough to support a clean procurement answer. The research record includes the UK ICO’s Yoti sandbox conclusion that facial age estimation was not special-category data in that context, but that primary sandbox source is not linked in the materials available for this article and should be verified before reliance. On the other side of the risk fork, CNIL stated on July 11, 2025, that AI cameras used to estimate age in tobacco shops were prohibited in the circumstances it examined. CNIL’s position does not decide every online age-estimation architecture, but it is enough to prevent “not biometric” from becoming a boilerplate assumption. [8]
Accuracy claims belong in the contract file, not the conclusion
Vendor-reported accuracy can be useful, but it is still vendor-reported unless independently benchmarked. A platform reviewing an age-estimation product should separate several questions that are often collapsed in sales material: how the model performs by age band, how it performs across demographic groups, whether the vendor stores images or only transiently processes them, whether an appeal path exists, and whether the customer receives age signals that could create legal knowledge.
The contract should also avoid treating “we only estimate age” as the end of the privacy analysis. The better questions are more concrete: what input is collected, what output is returned, what confidence score is exposed, what audit trail is retained, what deletion period applies, what subprocessors touch the data, and who answers if a regulator characterizes the processing differently from the vendor’s preferred label.
The minor’s own legal exposure is narrower
A child’s false age statement naturally draws attention, but it is usually not the load-bearing exposure for a platform. U.S. contract law’s infancy doctrine generally makes a minor’s promise easier for the minor to disaffirm than for the adult counterparty to enforce. That is why a terms-of-service checkbox or a birth-date representation is a weak civil shield when the user is a child.
There are state-specific exceptions and criminalized misrepresentation rules. Oregon provides a concrete example: ORS 165.805 makes it a Class C misdemeanor for a minor to falsely represent age in specified circumstances involving age-restricted entry, consumption, possession, or use. That kind of statute may matter in a narrow enforcement setting, but it does not convert the child into the main civil-risk bearer for a platform’s COPPA, privacy, or state-law compliance failure. [9]
Some jurisdictions may recognize fraud or misrepresentation arguments against minors in limited circumstances, but the research record for this article did not verify the relevant primary case text. Any minority line allowing stronger claims against a minor should therefore be treated cautiously unless counsel has checked the controlling state law and the facts fit the exception.
Where to put the risk in a launch review
A defensible launch review should not ask only whether the age gate can catch a lying user. It should ask what legal fact each actor creates when the gate works, fails, or produces an uncertain result.
- For the platform: identify every place an under-age signal can land, including logs, user profiles, moderation tools, customer-support systems, ad systems, and vendor dashboards.
- For COPPA: decide in advance what happens when the service receives an under-13 result, because that result may create actual knowledge rather than merely improve screening.
- For state laws: maintain a jurisdiction table by obligation type, not just by age threshold. Adult-content laws, social-media laws, app-store duties, parental-consent rules, and private rights of action are different launch constraints.
- For vendors: require technical documentation on inputs, outputs, retention, deletion, confidence scoring, demographic testing, subprocessors, and whether the vendor disputes biometric classification.
- For minors: do not rely on a false birth date or terms-of-service representation as the primary defense. It may be a fact in the record, but the platform’s statutory role will usually matter more.
The allocation rule is straightforward enough to use, but not simple enough to automate without legal review: platforms cannot bank on the minor’s lie, vendors carry a separate biometric and accuracy risk, and each conclusion has to be rechecked against the jurisdiction that can enforce.
References
- FTC Issues COPPA Policy Statement to Incentivize Use of Age Verification Technologies to Protect Children — Federal Trade Commission, February 25, 2026.
- FTC Issues COPPA Enforcement Discretion Policy to Incentivize Use of Age Verification Technologies — Cooley, March 2, 2026.
- Supreme Court allows Texas to enforce law requiring age verification and parental consent on app — SCOTUSblog, July 2026.
- The Year States Chose Surveillance Over Safety: 2025 in Review — Electronic Frontier Foundation, December 2025.
- Are new global age verification requirements creating a children’s online safety legal patchwork? — IAPP.
- Age Assurance and Children’s Privacy Online: A Review of Methods and Challenges — Children (Basel), 2024.
- Kids bypass age verification — Bitdefender.
- Caméras augmentées pour estimer l’âge dans les bureaux de tabac : la CNIL précise sa position — CNIL, July 11, 2025.
- ORS 165.805 Misrepresentation of age by a minor — Oregon Public Law.
- Social media age verification laws in the United States — Wikipedia.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →