Deniability-as-a-Service: Age Signals, AML, and the Outsourcing of State Power
Google's Age Signals API is not a surveillance tool, but a compliance shield that deputizes tech monopolies as identity brokers for the administrative state.
By Simon Ferris
Sparked by Google will expand age checks on Android worldwide till the end of the year · discussion

Recently, Google published a developer blog announcing the new 'Age Signals API', which predictably kicked off a multi-hundred-comment outrage cycle on Hacker News. The tech commentariat immediately framed this OS-level age verification as a privacy-destroying panopticon, describing it as a cynical moat built by a surveillance capitalist desperate to hoard telemetry under the guise of child safety. I am darkly amused, as someone who frequently studies the invisible plumbing of global finance, by how often the engineering mindset misreads the actual incentive gradients of the administrative state. Rather than attempting a brazen power grab, Google is reacting to an escalating systemic burden by providing a standardized compliance shield for developers who would otherwise be crushed by regulatory enforcement in California and Europe.
Consider the physical reality of the API itself. If a platform monopoly were constructing an omnipresent surveillance apparatus, one would expect the underlying plumbing to demand and store highly granular, state-issued biometric truths. Instead, observe the actual JSON payload returned to a calling application. It yields a probabilistic, heavily abstracted bucket—a boolean flag buried in the response roughly resembling {"is_child": true}.
Why deploy such a fuzzy tool? Because this API is engineered to generate a bureaucratic artifact. When your application reaches out to the operating system and effectively asks whether the user is legally permitted to view a specific screen, it simply queries the local kernelspace. The OS then checks a locally cached heuristic, likely derived years ago when an allegedly adult user first associated an email address with the device, and passes back a binary signal. (Ask your legal counsel; modern data protection regimes frequently turn straightforward database queries into radioactive liabilities, incentivizing everyone to know as little as legally permissible while still passing the audit.)
Imagine you are an independent mobile developer. You built a nice little software-as-a-service application that serves images to users, earning perhaps a few thousand dollars a month in subscription revenue. Suddenly, under the emergent global regime for digital safety, you are staring down existential regulatory risk. Under the UK's Age Appropriate Design Code, you face fines that reach 10% of global turnover. Under the legislative requirements underpinning the Online Safety Act, non-compliance carries penalties stretching up to £18 million.
(A brief aside on corporate structure: compliance departments scale sub-linearly with revenue but possess a massive fixed-cost floor. A megacorp can absorb a twenty-person policy team investigating anomalous identity metrics as a rounding error on a Tuesday. An independent developer facing a single regulatory inquiry over a minor bypassing an age-gate simply ceases to trade.)
Consider the alternative facing our hypothetical mobile developer. If the operating system does not provide this signal natively, the developer must integrate a third-party identity verification vendor. This entails prompting every prospective user to photograph their physical driver's license and upload it to an unfamiliar server before they can view a meme. Conversion rates would crater. Customer acquisition costs would skyrocket. The entire unit economics of the consumer internet would permanently invert. If you are legally compelled to manually verify the government IDs of your user base before rendering a JPEG, your business model collapses under the weight of operational friction. You cannot self-insure against the administrative state. You must find a way to outsource the liability.
Let us trace the liability upstream to see where it pools. How does Google absorb this immense risk on your behalf? The answer, buried quietly in the legalese, is that they absolutely refuse to. If you scrutinize the Google APIs Terms of Service, you will note that they offer these features 'AS IS' and explicitly disclaim all liability for damages arising from their use. Google provides an auditable paper trail to show regulators, without absorbing the direct legal risk of a determined fourteen-year-old successfully spoofing their birth year on an initial device setup screen. They are selling infrastructure that facilitates plausible deniability.
This exact structural dynamic has played out before, largely invisibly, in the plumbing of high finance.
The U.S. Treasury understands that banks cannot realistically interdict every illicit dollar flowing through the global economy. Consequently, when the USA PATRIOT Act dramatically expanded anti-money laundering requirements, the federal government formalized an intricate waterfall of Know Your Customer (KYC) checks and Suspicious Activity Reports (SARs). This apparatus manages risk probabilistically rather than seeking absolute perfection.
In 2023 alone, U.S. financial institutions filed nearly four million Suspicious Activity Reports. The vast majority of these documents will never be read by a human investigator, let alone result in a cinematic federal raid. But that is entirely beside the point. When a junior compliance officer fills out a SAR because a customer repeatedly deposits $9,500 in physical cash, the bank acts strictly as an administrative functionary generating a bureaucratic artifact. They are creating a cryptographic proof for the regulator that they followed the agreed-upon process. If the customer later turns out to be operating a narcotics syndicate, the bank pulls the database logs, gestures at the SAR, and demonstrates that they dutifully checked the legally mandated boxes. The bank's charter survives. The state gets its intelligence. The institutional risk is successfully contained.
The Age Signals API functions as the digital equivalent of a Suspicious Activity Report. It allows a developer to punt the operational friction of identity verification up to the operating system layer, transforming an existential legal threat into a routine system call. When a regulatory body eventually knocks on the developer's door to ask why a minor was exposed to age-restricted material, the developer simply points to the structured logs. We asked the OS. The OS returned the authorized JSON payload. We relied on the state-approved infrastructure.
Regulators are applying the exact same financial plumbing playbook to the internet. Westminster and Brussels are completely aware that teenagers will figure out how to bypass age gates. (The state implicitly accepts that youth possess infinite time and ingenuity to bypass digital locks. The goal of the regulation is not impenetrable security; the goal is generating a standardized audit trail so that failures can be processed bureaucratically.) The state requires a systemic, auditable firewall to exist so they can heavily fine the non-compliant outliers who refuse to play the game, while granting safe harbor to businesses that dutifully integrate with the approved infrastructure.
Regulating ten million independent software vendors is practically impossible. Deputizing two mobile operating system monopolies, however, allows a motivated parliamentary committee to enforce compliance downward onto the entire developer ecosystem through a single, highly leveraged vector.
For the average retail user of the internet, the immediate friction will likely be limited to occasionally clicking an OS-level modal confirming you belong in the correct probabilistic bucket to read a particular forum or download an application. The plumbing changes will remain largely invisible to you.
But as a participant in the digital economy, observe the tectonic shift happening beneath the surface. Within five years, Apple and Google will be legally recognized as the only entities capable of attesting to digital identity across the western internet. This outcome requires no violent market conquest or grand technological breakthrough. The administrative state simply demanded that the tech industry construct a centralized compliance department, and the major platform operators were the only entities who could afford the bill. They will mediate your access to the digital world not because they desperately want to track you, but because the law has made it financially ruinous for anyone else to try.