Apple introduced expanded age assurance capabilities for the App Store to support compliance with new or emerging regulations in multiple jurisdictions, including Brazil, Australia, Singapore, Utah, and Louisiana. As of Feb. 24, 2026, Apple began blocking downloads of 18+ rated apps in Brazil, Australia, and Singapore unless the user is confirmed to be an adult, using what Apple describes as “reasonable methods” for age confirmation. Apple also expanded the Declared Age Range API (iOS/iPadOS/macOS) and related platform components (including PermissionKit’s Significant Change API, a new StoreKit age-rating property type, and App Store Server Notifications) to provide developers with an age category plus signals about the assurance method and whether regulatory requirements apply; in Brazil, certain disclosures (e.g., loot boxes) can drive an app’s rating to 18+.
Broader policy debate continues around online age assurance in the U.S. and internationally, with jurisdictions adopting or considering stricter mandates and platforms preparing new verification requirements. Public skepticism remains elevated due to backlash against age-gating (including reported VPN usage spikes in response to the UK’s requirements) and concerns about data security following breaches at age-verification providers (e.g., Sumsub disclosing a previously undetected 2024 compromise). The policy environment is also being shaped by U.S. state laws and litigation, including the Supreme Court’s decision in Free Speech Coalition v. Paxton upholding Texas’s age verification law, while proponents argue that privacy-preserving age assurance approaches are becoming more technically mature and scalable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Apple said that for new Apple account holders in Louisiana, age categories can be shared with apps via its API starting July 1, 2026, when requested by developers.
Apple said that for new Apple account holders in Utah, age categories can be shared with apps via its API starting May 6, 2026, when requested by developers.
Apple started enforcing age checks in the UK through a new iOS update, extending its age-assurance measures to another market. This represents a new geographic rollout beyond the countries previously listed in Apple's February 2026 changes.
Apple introduced expanded age-assurance tooling in beta, including updates to the Declared Age Range API, StoreKit age-rating properties, PermissionKit, and App Store Server Notifications to help developers comply with new regulations.
Beginning February 24, 2026, Apple started blocking downloads of 18+ rated apps in Brazil, Australia, and Singapore unless the App Store can confirm the user is an adult using what it calls reasonable methods.
In December 2025, a federal court issued an injunction against Texas’s App Store Accountability Act, signaling that app-store-level parental-consent requirements may face distinct First Amendment challenges.
Lawfare cites a delayed breach disclosure by age-verification vendor Sumsub as another example of the security and transparency problems surrounding age-assurance providers.
The article references an incident in which Discord users’ identification documents were exposed in customer-service systems, underscoring privacy and data-handling risks tied to platform age verification.
The Lawfare analysis cites a breach at age-verification vendor AU10TIX as an example of systemic security risk in the age-assurance industry, noting that the incident occurred despite the company holding ISO 27001 certification.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcearstechnica.com
Open sourcehelpnetsecurity.com
Open sourcelawfaremedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.