"Oh, those? Those are just compliance tits. Ignore those. It's just a thing that came a few years after we finally got rid of the cookie banners. The companies wanted certain protections awarded only to 18+ sites. But you can't just declare yourself an 18+ site, so some sites post the most minimal amount of imagery that constitutes erotic nudity. That's why Google's graphic for the past few months has just been that one with the two dots in the middle of the o's."
> Announcer: Ladies and gentlemen, in order to achieve an "R" rating today, a motion picture must contain full frontal nudity, graphic violence, or an explicit reference to the sex act. Since this film has none of those, and since research has proven that R-rated films are by far the most popular with the moviegoing public, the producers of this motion picture have asked me to take this opportunity to say "Fuck you."
> [the MPAA R-rating logo appears on the screen]
While the reasons may elude, the ubiquity speaks to something foundational.
I'm not actually willing to take that as read. It's just the word "fuck". You may personally find it distasteful and you're welcome to discourage your children from using it but it seems like you're committing Pargin's Blunder here (mistaking norms specific to your social group for universal truths).
Yes, this causes problems.
> and then if you make it a standard there needs to be testing for compliance
Why would there need to be any additional testing? If anything I'd expect "may" foods to need less testing than an accident-prone "no" food.
https://www.fox9.com/news/new-us-food-label-law-unintended-e...
> Some companies include statements on labels that say a food "may contain" a certain product or that the food is "produced in a facility" that also uses certain allergens. However, such statements are voluntary, not required, according to the FDA, and they do not absolve the company of requirements to prevent cross-contamination.
> Instead, some companies have taken a different approach. Officials at Olive Garden said that starting this week, the chain is adding "a minimal amount of sesame flour" to the company’s famous breadsticks "due to the potential for cross-contamination at the bakery."
> Many companies now routinely attach Prop 65 warning labels to any product of theirs that they think might possibly contain one of the 900 listed chemicals without testing to see whether the chemical is really present in their product and without reformulating their product, because it is cheaper to do so than to run the risk of being sued by Prop 65 enforcers.
Ha! At one point some years back, in an internal presentation somebody used an image of an old computer that if you really, really squinted and looked closely, had a topless woman in ascii art in a small area of the computer screen. It was so hard to see that most of us didn't even notice, but one eagle eye did and caused a whole shit storm around it. If the presenter would have said, "Those are just compliance tits" I think my life would have been complete :-D
It would be detrimental to the cause, which is to collect everyone's ID.
Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.
Better to not hold the data in the first place.
They're collecting more than ever.
I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.
Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.
Seeing as how these companies get hacked all the time, (https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...) , I don't think it's unreasonable to resist this.
Furthermore, I think many folks have reservations about requiring an ID checkpoint to utilize a computer. Obviously it's not that bad yet, but I don't think it's hyperbolic to state that the landscape is certainly trending in that direction, and it's absolutely not unreasonable to point out that governments and institutions to have a material interest in setting up access controls on who can and can't use the internet (read: participate in society).
Which is why the people trying to do it always pull out the misdirect about ZK proofs. Those don't fix anything because a system that actually preserved privacy wouldn't be able to prove that the user is over 18, only that someone is over 18, not necessarily them. And that in turn means you're setting up a rug pull. You roll out a system which is indistinguishable from the perspective of ordinary people from the one that screws them, and then that system can't actually exclude minors so what follows is calls to change it to stop protecting privacy, at which point the people trying to collect everyone's ID will be arguing that you already have to show ID.
It also presumes you would even get a privacy-preserving implementation to begin with, which a pretty credulous assumption given how these things usually go.
Exactly. Which in turn requires you to have some way of tying those accounts to that ID, which was supposed to be the thing to be prevented.
The whole thing is pointless.
If you dont microregulate technology how can you regulate the consequences of regulating technology?
The regulators need this.
Then, Chase knows you've verified your ID somewhere, the relay knows that some Chase user verified themselves at Pornhub, and Pornhub knows that the user is over 18, without knowing their identity or what bank they're using.
You could also do this with ZKPs and device integrity protection. The latter is more secure but more complex, the former is much simpler and openness friendly.
How has the anti-competitive lock-in scam of "device integrity protection" entered the discussion? Using ZK proofs without it has exactly the same effect.
There are far too many attestation-passing insecure devices to expect attestation to have any security value against attackers who can choose any of those devices on purpose.
Also, I’d rather a company know “he has an account at Bank of America” than “His full government name is Bit Masher and his driving license number is 9”
In the US we just assume no one does what they say they do.
This is fantastic, except that the idea of mandatory government software only available on chosen proprietary platforms feels way worse.
If there were a way to crypto-notarize a third-party wallet token etc blah blah, then it would be interesting.
At the end of the day though, this is about protecting the powerful, not the kids.
For what reason should I trust a bank?
GP's hypothetical here is that Anthropic or other service provider who wants to do "age verification" could partner with (among others) your bank [1], where bank can answer yes/no to "is this user >= 18?", without revealing any other personal info to the SP. Allegedly.
[1] via an intermediary, no doubt. Trying to do a "full-mesh" of partnering of every SP with every bank directly would not scale.
For what reason?
> Since you know, they have your money.
You may trust them with your money, but does not equate to trusting them with anything else. Principle of least privilege, if you will. Anthropic has your chat data, which in many ways is more valuable than money, so if the only bar for free lying giving out your personal details is trusting a business with something of yours then why bother with this complex scheme and give Anthropic all of your personal information directly?
This doesn't really make any sense and it feels like it's just an attempt to be contrarian.
Banks by law require substantial PII in order to even do business with you.
And those laws are extremely invasive and should be repealed. It's offensive to have a law that de facto requires you to identify yourself in order to pay for a newspaper subscription or buy contraceptives over the internet.
But that's not the issue in this case. It's that the bank knows your name and what you buy -- already very bad -- but now you want to create a path to tying that information to everything you do on the internet.
You feel like it's an attempt to be contrarian not to inform your bank about everything that you do?
Society has reached a dangerous point.
That is technically true, but keep in mind that in the early days of banking banks expected you to provide that information without the hand of the law requiring it. The laws you speak of came into effect after the fact to normalize across the industry what the banks were already doing. History is repeating itself in tech, and we already know lawmakers are waiting with bated breath to do their thing all over again just as they did in banking once critical adoption is there.
I expect what you are trying to get at is that you are willing to trust a bank because giving them your life story was already normalized before you were born, so you have never thought to question it. Whereas tech doing the same now feels new and scary. However, that's a funny way to look at it as the kids born in the future, who never knew the world where you could use the internet anonymously, will see giving tech their ID as being no different than how you see giving your bank your ID.
Although I can understand why you would now question why any business that does little more than store numbers on a computer needs a comprehensive profile on you by law or otherwise. Normalized does not equal sensible. That is a fair point.
How do you expect that they will give you your money when you walk in to a branch and ask for a withdrawal? Or that they'll replace a lost card? Surely you'd expect them to verify your identity.
But it would also be completely reasonable to authenticate the customer exclusively using mechanisms other than government ID. You can already make a withdrawal using your bank card and PIN. If you lose your card you could sign into their website using your password and request a new one etc.
Consider what happens if you lose your government ID. Your bank has much better ways to authenticate you at that point than the government does. Government ID has a major bootstrap problem, whereas patronizing a service doesn't because a new account with no money in it belongs to whoever is signing up for it regardless of who they are, and you can at that point give them a bank card and have them provide a password and email address etc. that allows you to identify them in subsequent transactions without ever needing their name.
The technical solution offered earlier was to have a trusted third-party only be willing to answer the "is this person 18+?" question. Of course, the same works for banks. The trusted third-party can answer "does this person own this account?" without needing to reveal to the bank any other information about you.
Now, that still leaves open the question of who you can trust. If you can trust a business run by people then that allows you to trust a bank, sure, but it also allows you to trust a tech company, so why not just give the tech company your ID and skip all that technical complexity? Understandably the broader idea presented earlier was that you cannot trust businesses operated by people, but then that includes banks, so...
For the sake of discussion, if we accept that technical solution and the need for a trusted third-party that is a business run by people, surely it should at least be a business that does nothing but offer profile trust to minimize the blast radius? For what reason would we want that business to have their hand in other activities like chat or banking?
Banks are subject to much stricter regulation than any tech company is or ever will be (IMO, I could end up surprised).
I trust my bank to know who I am and keep track of my money. I trust big tech to lose or misinterpret my data, to close my account for no reason, etc, and to face zero consequences for those failures -- not even fines.
That's true, but remember what we're talking about: Using banks (or another trusted third-party) to assert your age instead of having big tech collecting your personal information themselves. There is context here. Writing comments in a vacuum makes no sense.
In that context it is understood that only incentive for big tech to follow the proposed is regulation, but if you are going to push regulation on them then you can regulate them just as much as banks.
Your broader point that, in the real world, there isn't much political will to push any of that regulation is also no doubt true, but, again, writing comments in a vacuum makes no sense. The hypothetical of big tech adopting a third-party attestation system was already understood to be just that: hypothetical.
This person? There's your PII right there. The ad seller's dream.
https://yoti.my.site.com/yotisupport/s/article/What-is-a-Rem...
If you include the anonymous version are you calling a basic cookie an "advertiser's dream"? Then that's not something new they would get if the cookie tracked age verification. And you can reset cookies every visit (or more often). The "that person" of a site-specific session cookie is not a big deal for privacy.
The "user identifiers" are just having an account. That's when it's not set to be anonymous in the first place.
When it is set to be anonymous, it doesn't do this.
I have used these KYC services before. There is the option to get access to all user data - but unless there is evidence to the contrary, we have to take their word for it, for now.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...
Seems more likely this is designed to stave off similar laws /regulations to what the social media platforms are now being hit with, and moving liability from Anthropic to parents. If dad lets kid use his Claude account for a school project, and Claude ends up telling the kid to hurt himself, it’s now dad’s fault.
Easy to see how Anthropic could decide it’s not with the exposure to liability and regulatory actions.
[1] https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml...
[2] https://sd18.senate.ca.gov/news/governor-newsom-signs-adams-...
California already has BPC §§ 22601-22606 to protect people from chatbots encouraging self-harm and I don't see a legitimate reason why they had to ratchet up the restrictions.
This law seems a blatant regulatory capture grift by OpenAI to calcify their teen mode into law and hurt competitors. https://openai.com/index/supporting-california-bill-advance-...
No, they know who you are. 1 in 3 already use AI for mental health advice among many other things.
People want to talk to their therapist after an argument with their husband or when their boss fires them, not Friday after next.
“And the next time you feel your heart going out of rhythm, just hold your breath, and remember I will see you again a couple of weeks from now.”
Ah wait, no they don’t, because “resilience” is a worthless concept in emergencies, both mental and physical.
Therapists will likewise encourage you to build up resilience so that "a relationship ended" is not a crisis, and also build support networks of real people who can really come visit you when you need urgent support.
There are also, of course, crisis hotlines.
I'm not sure where you live. I know almost all colleges in the US have walk in free mental health counseling, along with free telesupport. My company has onsite mental health professionals who you can talk to or call at any time. There are free mental health clinics all over my city. There's mental health professionals who did daily outreach with the homeless and addicts in our city.
This doesn't even start to list all of the available apps you can download from your health care provider for free resources that are available to you.
This might have been true 30-40 years ago, but even over the last decade during and after covid, healthcare providers have put a huge emphasis on mental health and counseling to give people an abundance of resources to help them - when they need help, not in four days when someone is available.
I've been to two universities and this was not the case from the university itself, especially outside of normal business hours. If you didn't have an emergency, you had to wait months, if you had an emergency (I was explicitly told the only way to see someone anytime soon was if I said I'd kill myself if I didn't get an appointment and then they'd see if there was someone available) you might be able to talk to someone sooner. After hours emergencies maybe the psych ward at the hospital would see you? There's free resources, but universities aren't really providing much.
Can't see that coming to bite you.
It absolutely does, you just believe you can decide for others what’s harmful for them.
Given there have been multiple suicides driven by LLMs. I really doubt that.
LLMs can barely identify gaps in their own software designs, and they are provably good at making software.
The worst problem with mental health care is that there is no "you're better" metric. There is if your bone breaks and heal. There is for surgery of various things. But mental health seems to follow Parkinson's Law, and expands to the number of sessions available, whether it helps or not. And at X00$/session, yeah gets costly quick.
So if something trained on all psychiatric literature costs $20/month subscription, that's a substitute therapist. Whether it's clinically trained or not.
With that kind of benchmark comparison, it’s not all that hard for AI to present some kind of favorable value proposition, even if also inconsistent but with a harder ceiling on the upside.
I doubt that this statement is true.
Now, for the next "teen committed suicide after talking to AI therapist" headline, Claude can deflect the blame to the parents for not supervising their child enough.
Your honor, the user manual in the box did say "don't put children in the microwave."
Do you really think most people use fake data on a paid service? I don't think so.
Every middle schooler in high schooler in America is snickering right now... :)
Your dismissal is so much weaker than the post you're replying to.
the conspiracy aspect is alleging a conspiracy without providing any evidence, which is apparently how 90% of people function now. Calling someone a liar because you invented a conversation in your head isn't entirely sane
Nobody alleged a conspiracy.
> Calling someone a liar because you invented a conversation in your head isn't entirely sane
That's not why they said that. This is a ridiculous criticism of OP.
Claude Product Manager: Give me 2sec...
LOL. Yeah kids have loved homework and writing essays since forever
Laws like COPPA in the US, the UK Age Appropriate Design Code, and EU GDPR carry statutory penalties of over $50,000 per violation if minor data or chat sessions are mishandled without explicit parental consent.
For an enterprise and developer-focused company like Anthropic, minors contribute negligible revenue while representing 90% of the catastrophic regulatory risk. From a pure cost-benefit perspective, outsourcing age verification to an external vendor and shutting down the under-18 demographic is simply the cheapest way to wipe that liability off their books.
I know this isn't what you meant, but I can't help but laugh at the thought of a parent consenting: "I consent to the mishandling of my child's data"
As to your actual point, yes, I assume they are trying to reduce liability, especially if they're gearing up to an IPO.
But for the life of me I'll never understand why people extend this very human idea to faceless for-profit companies that time and time make it evident only one thing matters to them, money. If it can make them more money, they'll do it that way.
This is about reducing liability and making everyone else responsible for their inability to manage their community.
You're hopelessly naive if you think this is all they get out of it.
Truly naive is the mirror you're looking into.
We agree these are useless contrivances, but positing constantly that "this is just some great surveillance game" as opposed to the offloading of government responsibilities to private industry in the hope of removing all social regulatory liabilities?
Naive is how you spell that.
Why have this sort of argument/"come back" become so popular on HN? Where you learned to reply/debate, reddit? Did I ever make such a claim anywhere in this submission?
Maybe try actually responding to something I've said rather than just creating your own imaginary arguments no one said.
If you post slop, you should expect slop replies.
It’s like people claiming that Alexa is listening to their conversations to spy on them… when the reality is much worse. Every website you visit and app you download is spying on every single action you take, and they’ve gotten so good at it that they don’t need to listen to your conversations. They already know stuff about you without you even saying it out loud.
Superstition in pigeons: https://psycnet.apa.org/record/1948-04299-001
10+ years ago you were considered a lunatic if you told people that putting internet-connected cameras and microphones everywhere is a bad idea because their TV would be used to spy on them, that their cameras would be accessed by the police without their consent for surveillance, or that car company employees would watch them walk around naked through the cameras on their car.
Any data on that? Because to me it sounds like “because they are sometimes true, we should assume they are always true”
But I’m open to data.
Are you capable of identifying dystopian movements the single moves of which get justified as "for people's good"?
That the impacts on adults are negligible compared on children is irrelevant, because they are multiplied by 0, since they don't apply to you, so you only consider the infitesimal effect it has on you as an adult.
For any parent with a child, it goes the other way, but with a slightly different mechanic. There is an effect on the adult, but it is so minor compared to the effect on children, that the proportionality causes you to dismiss the minor inconvenience it poses to adults, since you are focusing on the question of what happens to children.
Nothing wrong with being (very) selfish though, just pointing out the dynamic.
Can you elaborate? I do have children, and I don't view it as any platforms job to police their Internet usage. I appreciate parental controls, but if they have Internet access it's my job to teach them to use services safely and keep an eye on their activities
For my kids.
This effort trains them to expose their full name and home address and their real face to all the sites and services that request it. Predators dream, really.
If the age verification was done in the privacy-preserving ways, it would be okay, but already several high profile leaks and scandals proved this is the exercise in data collection and deanonymisaiton.
In first year university I was 17. Imagine being that person today: 90% of the class can use LLMs, but you can't.
Can you fathom that childhood is only tiny part of everyone life, and negative impacts on adults are, mathematically, bigger in anyone's life than same impact on children?
It get even tinier if you factor that the slice of life were someone is old enough to use Claude, willing to do so and minor at the same time is really small.
Even more if you try to articulate how Claude could be more harmful to an educated minor than any other activities.
The loudest parents absolutely cannot. I don't know if this is because of the sleep-deprivation-induced brain damage that caring for a tiny human for their first year or so gives you or what, but there are some very loud, very neurotic people out there who appear to have forgetten that humans live for sixty to a hundred years.
Childhood is a tiny slice of life and if these folks had the time and ability to sit down and think very clearly and carefully, they'd see that making it so much harder for parents, relatives, and authority figures to get away with child abuse -sexual or otherwise- does far more to keep minors safe than removing those minors' ability to talk to adult strangers.
Hell, being able to talk to adult strangers is one way minors can both realize that they're being abused and find a way to get out of that abusive situation. To borrow a dark meme, it's hard to know that Penis Inspection Time isn't a legitimate activity when you can't talk to anyone who knows better.
You're essentially arguing to poison a well instead of inconveniencing yourself. You have agency, you're allegedly intelligent. But it sounds like you're so dependent on Claude you can't even conceive of using an alternative.
There are NUMEROUS alternatives available. If you lack the agency to subvert the check or implement an alternative that's on you.
A minor that's educated enough to build their own is a different topic, but so many unmotivated or uniformed humans would quit if Claude simply didn't work. The barrier to entry is supposed to be the validation of comprehension.
I don't use Claude whatsoever.
> There are NUMEROUS alternatives available. If you lack the agency to subvert the check or implement an alternative that's on you.
I know there is, but I also know this trend of age verification bullshit is coming for everything, and that's a problem.
Once everyone is used to handing over an ID to use AI, eventually it will be restricted to a small group. If you get on the naughty list you will be banned from ever doing knowledge work again.