Skip to content
Independent reporting
, , ,

The Digital ID Gatekeeper Is Coming To Windows

The Digital ID Gatekeeper Is Coming To Windows
Share X Facebook Email

For most of the personal computer’s history, the relationship was simple: you owned the machine, opened a program, and expected it to obey. But Microsoft is preparing Windows for a very different digital future–one in which applications may first ask the operating system what kind of person is sitting behind the screen and whether that person has been verified.

Microsoft’s new Windows Age APIs will allow participating apps to request the age range of a signed-in user. Windows can report that the user is under 10, 10-12, 13-15, 16-17, or 18 and older. It can also tell the app whether that age has been verified, remains unverified, or whether the user has opted out.

Microsoft describes this as a privacy-preserving system because applications receive an age bracket rather than a precise birthday. But behind that reassuring language sits a much larger change: Windows is being equipped to serve as an identity gatekeeper between the user and the software.

The computer will not simply open the door. It will be able to tell the app whether the user carries the right credentials to enter.

Protecting Children–or Classifying Everyone?

The immediate justification is child safety. Apps could use the signal to restrict mature media, social features, user-generated content, communications, in-app purchases, and virtual currencies. Parents understandably want children protected from pornography, predators, addictive platforms, and inappropriate commercial practices.

But a system cannot reliably identify children without also classifying adults. If an application must know who is under 18, every adult may eventually be expected to prove that he or she is over 18.

California is already pushing technology companies in this direction. Its Digital Age Assurance Act, scheduled to take effect in 2027, requires covered operating-system providers to offer an interface for recording a user’s age or birth date and to transmit an age-range signal to qualifying applications.

What begins as a child-protection measure can therefore become an identity requirement for the entire population. Once the infrastructure exists, age may be only the first attribute it is used to verify.

var images = [],
index = 0;
images[0] = ““;
images[1] = “
“;
images[2] = “
“;
images[3] = “
“;
index = Math.floor(Math.random() * images.length);
document.write(images[index]);
//done

Microsoft Once Warned About The Danger

Microsoft itself recognized the threat only a few years ago. In 2024, the company acknowledged that there was no clear technical solution capable of accurately verifying age without potentially creating serious tradeoffs involving privacy, security, civil rights, government surveillance, anonymity, and freedom of expression.

Those dangers have not vanished. The pressure to implement the technology has simply grown.

Microsoft’s current system requires the user to be signed into a Microsoft account, and its documentation says identity-provider age signals are presently retrieved only for Microsoft accounts. Apps must also request access to account information, and users can withhold consent.

But what happens when refusing consent means losing access?

Share X Facebook Email

The Kingdom Watch Brief

The day’s essential headlines, without the noise.

A concise briefing delivered directly to your inbox.

Free to join. Unsubscribe any time.

Powered by Reach Response