Summary

  • RFC 9998 distinguishes age verification, estimation and inference from the separate act of age gating, and records that every method can exclude or misclassify some people.
  • A serial design may begin with a lower-friction method and offer a more invasive fallback, but an inconclusive result is not an underage finding and does not supply consent or another authority for extra collection.
  • An age-check escalation receipt should preserve the reason, additional disclosure, user choice, linkability boundary, deletion promise and appeal route without retaining the sensitive evidence itself.

The first screen asks only for a low-friction age signal. It returns inconclusive. The next screen requests a government document. If that also fails, a face image or an external database lookup may follow. At the end, the interface displays one final state: verified or blocked.

That final state erases the most important part of the transaction. Which method failed? Was it inaccurate, unavailable, unsupported or simply unable to reach the required confidence? Who decided that another method could be offered? What new data did it demand? Could the person withdraw or choose an alternative? What was deleted after the abandoned attempt?

RFC 9998 does not standardize answers to those questions. It is an Informational report from the October 2025 IAB/W3C workshop, not a standard, law or consensus specification. Its value is to expose the architectural seams that an implementation can otherwise hide.

One result can conceal four different authorities

The report separates four roles. A verifier assesses whether a person falls within a target range. An enforcer controls access. A policy selector determines which rule applies, perhaps using jurisdiction or status. A rater decides whether the content or service belongs behind an age restriction.

Those roles can be performed by one organization or several, but their decisions do not become identical. A correct age-range assertion can be applied under the wrong jurisdiction. A correct policy can act on an incorrect content rating. An accurate verifier can feed an enforcer that offers no meaningful appeal. An access decision can be technically faithful to its inputs while the inputs remain disputed.

The common label age verified therefore says too little. It does not identify the method, threshold, policy version, content class or decision owner. Nor does blocked prove that a person was underage. It can mean that evidence was missing, a credential was unrecognized, a model was uncertain, a device lacked support, a service was unavailable or the person declined further disclosure.

Good governance refuses to rewrite those different states into a moral judgment about the user.

Verification, estimation and inference fail differently

RFC 9998 uses age assurance as the umbrella. Verification seeks high assurance, often through official credentials. Estimation applies statistical methods to physical or behavioral characteristics. Inference draws conclusions from other records and can require identifiers such as an email address or telephone number. Gating is the separate enforcement act.

Credential verification can exclude people who have no accepted document or whose document is not recognized. Estimation is probabilistic: a threshold produces false acceptance and false rejection, with the usual trade-off that lowering one can raise the other. Inference may have too little data. None of those conditions establishes that the person is below the threshold.

This distinction matters most near the boundary. A 17-year-old and an 18-year-old can be affected by the same estimation error in opposite ways. A stateless adult and a child without documentation can both lack an accepted credential. A privacy-conscious person can leave too little history for inference. The system sees missing confidence; the people experience different causes and consequences.

The workshop repeatedly considered a serial approach: begin with a method that creates less friction or demands less private information, then use another method when the first cannot produce a definitive result. This can be more usable than forcing maximum disclosure on everyone. It can also build a disclosure staircase in which the people least well served by the first method must climb highest.

Failure is not a collection authority

An implementation needs a rule for offering the next step. It does not follow that the previous failure supplies the legal basis, informed choice or proportionality judgment for that step. A database lookup does not become necessary merely because an estimate was uncertain. A face image does not become proportionate merely because a credential wallet was unsupported. A phone number does not become harmless merely because it is convenient.

The distinction is especially important when the fallback changes the kind of risk. The first method may disclose only an age range, while the second exposes a persistent identifier. A local device check may become a remote query. A one-time presentation may become linkable across services. A rough estimate may be replaced by a document containing name, birth date, nationality and document number.

Encryption can protect that exchange in transit. It cannot answer whether the exchange should occur, who may retain it or whether the same identifier will later be used for advertising, fraud scoring, law enforcement or unrelated access control. RFC 6973's data-minimization framework includes collection, use, disclosure, retention, identifiability, sensitivity and access. A securely stored excess is still excess.

RFC 9998 lists purpose limitation, unlinkability, phishing resistance and avoidance of tracking as desirable properties. It also notes that people may have no prior reason to trust an unfamiliar contracted verifier. Training users to submit identity material to a new screen whenever a check fails can normalize exactly the behavior that phishing defense tries to prevent.

Privacy-enhancing proof does not erase governance

Zero-knowledge proof and anonymous-credential designs can reduce what a verifier learns. Instead of disclosing a birth date, a person might prove only that an age threshold is satisfied. That is a meaningful improvement, not a magic seal.

The report records several remaining questions. Who supplies the underlying source of truth? Can presentations be linked by an issuer, verifier, implementation or device? Does the mechanism concentrate trust in a small software layer? What happens to people without compatible credentials? Does the system become a convenient tool for censorship or a broader identity requirement? Can a highly motivated user bypass it?

A cryptographic proof can minimize an attribute while leaving policy selection, content rating, software integrity, revocation, availability, error correction and enforcement untouched. The proof should therefore narrow the receipt, not abolish it. If the verifier learns less, the record can say exactly that. It should not upgrade “minimal disclosure” into “no governance risk.”

Unequal error can become unequal intrusion

The workshop report warns that accuracy can vary among populations. It cites NIST work in discussing facial-analysis performance, while the cited NIST IR 8491 has a bounded subject: passive, software-based presentation-attack detection. It is not a universal scorecard for every age-estimation product.

The governance point does not require exaggeration. If one method produces inconclusive results more often for a group, a serial workflow will send that group to the fallback more often. If the fallback is more invasive, the system imposes an unequal privacy price even when the final acceptance rate looks similar.

Aggregate success can hide that path. A dashboard may show 95 percent verification while omitting that one cohort provided an age-range token and another provided a face image plus a document. It may count a later pass as if the first error never happened. It may record abandonment as user choice without showing what the next screen demanded.

Measurement must therefore retain denominators and transitions: result by initial method; escalation rate; additional data class; abandonment; appeal; reversal; time to remedy; and deletion evidence. Cohort analysis requires its own lawful, minimized basis. The remedy for hidden bias cannot be unlimited demographic collection.

The escalation receipt records the seam, not the identity

An age-check escalation receipt begins with a transaction-scoped pseudonymous identifier. It names the requested range, policy version, content class, jurisdiction signal and uncertainty. It identifies the policy selector, rater, verifier and enforcer as separate roles.

For each method it records only what is needed to explain the transition: method class; data categories requested; expected error boundary; outcome as pass, fail, inconclusive or unavailable; and the reason a definitive result was not reached. It then records which policy version permitted the next method to be offered, what additional categories it would collect, what alternative or withdrawal path existed, and the person's separately captured choice.

The receipt also preserves the linkability boundary among issuer, verifier, enforcer and repeated presentations; the retention or deletion commitment for an abandoned path; the final content-rating and enforcement decisions; and the appeal owner, deadline and remedy. An override needs an owner and expiry. A changed model, jurisdiction rule, content rating or retention term creates a new receipt version.

It should not contain the raw document, face image, phone number, email address, browsing history, credential payload or reusable cross-site token. The purpose is to prove why the system moved between methods without creating a second identity archive.

This receipt is an editorial operating proposal. It is not an RFC 9998 structure, an IAB or W3C recommendation, a protocol extension or a legal conclusion.

Appeal is part of accuracy

RFC 9998 lists appeal mechanisms for incorrect age determinations and incorrect content labeling among desirable properties. That placement matters. Appeal is not customer-service decoration added after an “accurate” technical system. It is one of the mechanisms by which an imperfect system becomes correctable.

A useful appeal does not merely run the same model again or demand the most invasive evidence by default. It can offer a genuinely independent method, explain which decision is disputed, separate content rating from age determination, preserve access to a bounded alternative where policy permits, and provide a route to correction and restitution.

The receipt makes that possible because it prevents the final denial from swallowing its causes. A reviewer can see whether the dispute concerns identity evidence, threshold error, jurisdiction, rating, enforcement or deletion. The person need not reconstruct the architecture from a generic error message.

Safety cannot be reduced to a gate

The workshop did not deny the importance of protecting children. It recorded that access restrictions are only part of a wider environment involving families, educators, services, governments and other institutions. Binary restriction cannot express every child's circumstances or every harmful context.

That is precisely why evidence boundaries matter. A passed check proves no general safety. A blocked request proves no harm was prevented. A failed check proves no bad intent. An architecture should report its actual decision without borrowing the moral authority of the objective it serves.

Lu Heng's minimum-initial-specification principle gives the shared layer a disciplined size. Standardize only enough to let independent actors interoperate and remain accountable; leave local policy choices visible rather than disguising them as technical necessity. The Policy Mirror adds the corresponding duty: every public record should reflect the authority that actually made the decision.

For serial age checks, that means keeping the seam. The first method may fail. The second may be offered. But the space between them must contain an explicit rule, a bounded data request, a real choice and a remedy—not a silent conversion of uncertainty into permission.

Sources