Real Safety AI Foundation / Research

Children, Schools, and Youth Policy

The Gate and the Playground: Age Attestation, Exclusion, and the Architecture of Verified Peer Space

Publisher: Real Safety AI Foundation

Working paper. Not peer reviewed.

Written
July 2026
Version
v0.3
Pages
27

Abstract

The age assurance debate has settled into a standoff between child safety and privacy in which each side concedes the other has a real interest and neither produces an architecture that serves both. This paper argues that the framing is wrong. The binding constraint on age assurance is neither safety nor privacy. It is exclusion, and exclusion is a distribution problem rather than a cryptographic one. The cryptography required to prove that a person is over a given age without disclosing the person’s name, birthday, face, or any other attribute has existed since 1983, and the hardware required to bind a credential to the human presenting it is a deployed W3C standard. What does not exist is a credential that reaches everyone. Every scheme now on the table requires the subject to apply, to pay, to travel, to produce documents, or to own a device manufactured by one of the two companies the scheme is meant to regulate, and each of those requirements falls on the same populations: the poor, the undocumented, and the disabled. This paper proposes the distributive inversion. A boolean age predicate, blind signed by the issuing state, delivered on free standalone hardware, issued at birth alongside the identifiers a government already assigns, and entitled rather than applied for. It further argues that age assurance requires two credentials and not one, because a binary attestation that a holder is over eighteen forces responsible guardians to make platforms blind to the children they are trying to protect, and that the correct deliverable of the architecture is composition rather than exclusion: a space in which every occupant is a verified peer, every occupant’s guardian has consented, and intensive supervision therefore raises no adult privacy objection because there is no adult inside to raise one. It argues that supervision is not an addition to the gate but the only mechanism that detects a compromised credential, which converts the rule against treating a gate as a discharge from a policy preference into an architectural necessity. It rejects the zero retention instinct on the ground that a child groomed at thirteen and disclosing at sixteen needs the record to exist, and proposes instead that the objection to retention was never duration but custody and purpose, resolved by escrow. The paper closes by identifying what the architecture does not solve, including the guardian who is himself the threat, the impossibility of binding an infant, the severing of relationships at band boundaries, and the bystander, who never approaches a gate at all and for whom no credential architecture can substitute for a rule keyed to the data subject.

Keywords

  • age assurance
  • age verification
  • zero-knowledge proof
  • blind signature
  • hardware credential
  • digital identity
  • COPPA
  • child safety
  • disability
  • exclusion
  • content moderation
  • verified peer space

Plain language slides

First slide of the plain language summary of The Gate and the Playground: Age Attestation, Exclusion, and the Architecture of Verified Peer SpaceOpen the 34-slide summary (PDF)

Suggested citation

Gilly, Travis. "The Gate and the Playground: Age Attestation, Exclusion, and the Architecture of Verified Peer Space." Real Safety AI Foundation Working Paper, July 2026. https://realsafetyai.org/research/gate-playground/

Other versions

This paper is also posted on SSRN.

SSRN version

References (49)

  1. Alaggia, R., Collin-Vézina, D., & Lateef, R. (2017). Facilitators and barriers to child sexual abuse (CSA) disclosures: A research update (2000–2016). Trauma, Violence, & Abuse, 20(2), 260–283.
  2. Bundesrat Drucksache 139/21, Entwurf eines Gesetzes zur Einführung eines elektronischen Identitätsnachweises mit einem mobilen Endgerät [Draft Act introducing electronic proof of identity on a mobile device] (Ger. Feb. 12, 2021). https://dip.bundestag.de/drucksache/139-21/250501
  3. Cabello-Hutt, T., Cabello, P., & Claro, M. (2018). Online opportunities and risks for children and adolescents: The role of digital skills, age, gender and parental mediation in Brazil. New Media & Society, 20(7), 2411–2431.
  4. Camenisch, J., & Lysyanskaya, A. (2001). An efficient system for non-transferable anonymous credentials with optional anonymity revocation. In B. Pfitzmann (Ed.), Advances in Cryptology: EUROCRYPT 2001 (pp. 93–118). Springer.
  5. Carah, N., Demaio, S., Holly, L., Kickbusch, I., & Williams, C. (2024). Beyond banning: Our digital world must be made safer for young people. Health Promotion Journal of Australia, 36(1). https://doi.org/10.1002/hpja.938
  6. Cavallini, C., et al. (2025). Early adolescents and exposure to risks online: What is the role of parental mediation styles? Social Sciences.
  7. Chaudhuri, B. (2022). Programmed welfare: An ethnographic account of algorithmic practices in the public distribution system in India. New Media & Society, 24(4), 887–902. https://doi.org/10.1177/14614448221079034
  8. Chaum, D. (1983). Blind signatures for untraceable payments. In D. Chaum, R. L. Rivest, & A. T. Sherman (Eds.), Advances in Cryptology: Proceedings of Crypto 82 (pp. 199–203). Springer.
  9. Children’s Online Privacy Protection Act of 1998, 15 U.S.C. §§6501–6506.
  10. Chudnovsky, M., & Peeters, R. (2021). A cascade of exclusion: Administrative burdens and access to citizenship in the case of Argentina’s national identity document. International Review of Administrative Sciences.
  11. Collings, S. J., Griffiths, S., & Kumalo, M. (2005). Patterns of disclosure in child sexual abuse. South African Journal of Psychology, 35(2), 270–285. https://doi.org/10.1177/008124630503500207
  12. de Montjoye, Y.-A., Hidalgo, C. A., Verleysen, M., & Blondel, V. D. (2013). Unique in the crowd: The privacy bounds of human mobility. Scientific Reports, 3, 1376. https://doi.org/10.1038/srep01376
  13. de Montjoye, Y.-A., Radaelli, L., Singh, V. K., & Pentland, A. S. (2015). Unique in the shopping mall: On the reidentifiability of credit card metadata. Science, 347(6221), 536–539. https://doi.org/10.1126/science.1256297
  14. Gesetz über eine Karte für Unionsbürger und Angehörige des Europäischen Wirtschaftsraums mit Funktion zum elektronischen Identitätsnachweis [eID-Karte-Gesetz] [Act on a card for Union citizens and EEA nationals with an electronic proof of identity function] (Ger. June 21, 2019). https://www.gesetze-im-internet.de/eidkg/
  15. Common Sense Media. (2025, April 10). AI risk assessment: Social AI companions. Common Sense Media. (Rating: unacceptable; use case review; conducted with input from the Stanford Brainstorm Lab for Mental Health Innovation.)
  16. Edelman, L. B. (1992). Legal ambiguity and symbolic structures: Organizational mediation of civil rights law. American Journal of Sociology, 97(6), 1531–1576.
  17. Edelman, L. B., Uggen, C., & Erlanger, H. S. (1999). The endogeneity of legal regulation: Grievance procedures as rational myth. American Journal of Sociology, 105(2), 406–454.
  18. European Parliament and Council. (2024). Regulation (EU) 2024/1183 of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework. Official Journal of the European Union, L, 2024/1183.
  19. Fairhurst, M., Li, C., & Da Costa-Abreu, M. (2017). Predictive biometrics: A review and analysis of predicting personal characteristics from biometric data. IET Biometrics, 6(6), 369–378. https://doi.org/10.1049/iet-bmt.2016.0169
  20. Finkelhor, D., Turner, H., & Colburn, D. (2022). Prevalence of online sexual offenses against children in the US. JAMA Network Open, 5(10), e2234471.
  21. Fry, D., et al. (2025). Prevalence estimates and nature of online child sexual exploitation and abuse: A systematic review and meta-analysis. The Lancet Child & Adolescent Health.
  22. Gambs, S., Killijian, M.-O., & Núñez-del-Prado Cortez, M. (2014). De-anonymization attack on geolocated data. Journal of Computer and System Sciences, 80(8), 1597–1614. https://doi.org/10.1016/j.jcss.2014.04.024
  23. Gilly, T., & Mattheus, R. (2026). Harm blindness in digital child protection policy: A systematic stakeholder, sentinel and legal analysis of Australia’s under-16 social media ban. In K. Ringmar Sylwander, G. Shekhawat, & S. Livingstone (Eds.), Children’s rights under pressure in a digital world: Proceedings of the International Communication Association pre-conference (pp. 60–65). Digital Futures for Children centre, LSE and 5Rights Foundation. https://researchonline.lse.ac.uk/id/eprint/138632/
  24. Isikut tõendavate dokumentide seadus [Identity Documents Act] (Est. Feb. 15, 1999), Riigi Teataja. https://www.riigiteataja.ee/akt/77253
  25. Livingstone, S., Ólafsson, K., Helsper, E. J., Lupiáñez-Villanueva, F., Veltri, G. A., & Folkvord, F. (2017). Maximizing opportunities and minimizing risks for children online: The role of digital skills in emerging strategies of parental mediation. Journal of Communication, 67(1), 82–105.
  26. Martin, A., et al. (2020). Exclusion and inclusion in identification: Regulation, displacement and data justice. Information Technology for Development.
  27. Manay, N., & Collin-Vézina, D. (2019). Recipients of children’s and adolescents’ disclosures of childhood sexual abuse: A systematic review. Child Abuse & Neglect, 98, 104192.
  28. Mathews, B., et al. (2025). Characteristics of first disclosure of child sexual abuse: Age, delay, recipient, and feeling of support. Child Abuse & Neglect.
  29. McElvaney, R. (2013). Disclosure of child sexual abuse: Delays, non-disclosure and partial disclosure. What the research tells us and implications for practice. Child Abuse Review, 24(3), 159–169. https://doi.org/10.1002/car.2280
  30. Mukherjee, A., & Sahay, S. (2019). Sinking under its own weight: Case of Aadhaar mediated entitlements in India. In P. Nielsen & H. C. Kimaro (Eds.), Information and Communication Technologies for Development: Strengthening Southern-Driven Cooperation as a Catalyst for ICT4D (pp. 472–485). Springer. https://doi.org/10.1007/978-3-030-18400-1_39
  31. Narayanan, A., & Shmatikov, V. (2008). Robust de-anonymization of large sparse datasets. In 2008 IEEE Symposium on Security and Privacy (pp. 111–125). IEEE. https://doi.org/10.1109/SP.2008.33
  32. Personalausweisgesetz [PAuswG] [Identity Card Act] (Ger. June 18, 2009), BGBl. I at 1346.
  33. Personalausweisgebührenverordnung [PAuswGebV] [Regulation on fees for identity cards and eID cards for Union citizens and EEA nationals] (Ger. Nov. 1, 2010). https://www.gesetze-im-internet.de/pauswgebv/
  34. Personalausweisverordnung [PAuswV] [Regulation on identity cards, eID cards for Union citizens and EEA nationals, and electronic proof of identity] (Ger. Nov. 1, 2010). https://www.gesetze-im-internet.de/pauswv/
  35. Ólafsdóttir, B., et al. (2024). A case study on the inclusiveness of biometric technologies for individuals with congenital disabilities. In Proceedings of the 13th Nordic Conference on Human-Computer Interaction. ACM.
  36. Poh, N., et al. (2025). Biometric bound credentials for age verification. In Proceedings of the International Conference of the Biometrics Special Interest Group (BIOSIG).
  37. Rao, U., & Nair, V. (2019). Aadhaar: Governing with biometrics. South Asia: Journal of South Asian Studies, 42(3), 469–481. https://doi.org/10.1080/00856401.2019.1595343
  38. Riaz, I., et al. (2024). Loss of fingerprint features and recognition failure due to physiological factors: A literature survey. Multimedia Tools and Applications.
  39. Rose, S. E., & Middling, L. R. (2025). Preteens social media use: Parents’ and children’s perceptions of what mediation approaches are used and why. British Journal of Developmental Psychology, 43(3), 771–786. https://doi.org/10.1111/bjdp.12552
  40. Rosenberg, M., White, J., Garman, C., & Miers, I. (2023). zk-creds: Flexible anonymous credentials from zkSNARKs and existing identity infrastructure. In 2023 IEEE Symposium on Security and Privacy (pp. 790–808). IEEE.
  41. Samdal, O., Budin-Ljøsne, I., Haug, E., Helland, T., et al. (2023). Encouraging greater empowerment for adolescents in consent procedures in social science research and policy projects. Obesity Reviews, 24(S2). https://doi.org/10.1111/obr.13636
  42. Schittenhelm, C., et al. (2024). Cybergrooming victimization among young people: A systematic review of prevalence rates, risk factors, and outcomes. Adolescent Research Review.
  43. Thimm-Kaiser, M., & Keyes, K. M. (2025). US state policies regarding social media: Do policies match the evidence? The Milbank Quarterly, 103(S1), 337–365. https://doi.org/10.1111/1468-0009.70021
  44. Wang, K., et al. (2023). Biometrics-based mobile user authentication for the elderly: Accessibility, performance, and method design. International Journal of Human-Computer Interaction.
  45. UK Passport Service. (2005). Biometrics enrolment trial: Report. Atos Origin.
  46. UKPS biometric enrolment trial. (2005). Biometric Technology Today. https://www.sciencedirect.com/science/article/abs/pii/S0969476505703684
  47. W3C. (2021). Web Authentication: An API for publicly accessing public key credentials, Level 2 [W3C Recommendation]. World Wide Web Consortium. https://www.w3.org/TR/webauthn-2/
  48. Zafeiropoulou, A., et al. (2025). Age verification in the context of the EUDI Wallet: Balancing privacy and security. In Proceedings of the 16th International Conference on Information, Intelligence, Systems and Applications (IISA). IEEE.
  49. Zhong, W., Luo, J., Luo, L., & Lyu, Y. (2025). The role of social robot in enhancing social–emotional skill development in children with autism: A three-level meta-analysis. Journal of Computer Assisted Learning, 41(6). https://doi.org/10.1111/jcal.70154

All research