Schneier: AI-Based Age Verification Trivially Bypassed
What Happened
Schneier flagged on May 15 that vendor age-verification systems mandated by recent state and EU laws can be bypassed with low-effort visual disguises. The systems rely on facial age estimation models that degrade under adversarial visual conditions that aren't even adversarial in the technical sense.
My Take
This is the regulatory cycle's recurring failure — legislators mandate a technical solution before it works, vendors ship anyway, compliance gets checked off, kids walk through it in a wig. The real risk for businesses isn't kids getting past the gate; it's that companies will get sued when "AI-verified" turns out to be a fig leaf. If you're implementing age gates because of new law, do not rely on a single vendor's model — layer it with payment-method checks and document upload, or you're buying false comfort.
Read Original Source