Proving Your Age to an AI Companion App: Why the Checks Are Multiplying and What to Share

Privacy & protection

Not long ago, an AI companion app only wanted a tick in an "I am 18" box. Now many want proof: a selfie, a scan of your ID, or a check run by an outside company. Legislation is behind the shift, and the checks are not going away.

We may earn a commission from links on this page. It never changes a rating.

Age checks have come in two waves. The first targeted pornography sites. The second reached AI chatbots that can generate sexual material or play the part of a companion, and companion apps are now caught up in both.

The rules driving the change

Canada. No federal law currently forces these apps to verify age. Two bills are worth watching. Bill S-209, the Protecting Young Persons from Exposure to Pornography Act, would require age verification or age estimation from commercial providers of pornographic material. It cleared the Senate in April 2026 and was at second reading in the House of Commons in late September 2026, so it is not law. Bill C-34, the Safe Social Media Act, was tabled on 10 June 2026. It would set a minimum age of 16 for social media and give AI chatbot services a duty to act responsibly toward children, overseen by a new Digital Safety Commission. It has not passed either. Until one of them does, the checks Canadians meet mostly come from foreign rules or a company's own policy.

United Kingdom. Under the Online Safety Act, services hosting pornography had to put "highly effective age assurance" in place by 25 July 2025. Ofcom had warned providers in 2024 that generative AI chatbots capable of producing pornographic content are covered. In 2026 it opened investigations into AI services, one of them a companion chatbot provider, over how they check age. Penalties can reach £18 million or 10% of worldwide revenue.

United States. The Supreme Court ruled in June 2025 that a Texas law requiring age verification on sites with a large share of sexual content was valid (Free Speech Coalition v. Paxton). That opened the door to similar state laws. Separate companion chatbot laws in California and other states add protections for users known to be minors, which gives apps a reason to learn who their users are. See AI companion laws in the US for the state-by-state detail.

The platforms themselves. Character.AI ended open-ended chat for under-18s in November 2025, using behavioural age estimation, third-party checks and ID as a last resort. OpenAI started rolling out age prediction in ChatGPT in early 2026.

Comparing the methods

Age verification methods ranked by how much personal data each one exposes: self-declaration, behavioural estimation, facial age estimation, bank or mobile operator checks, and ID document upload

Ordered, roughly, from least to most data shared.

ApproachWhat happensWhat you give up
Ticking a box or typing a birth dateYou state your own ageNothing that can be checked, so it no longer passes in regulated markets
Behavioural estimationThe app guesses your age from how you use itUsage data it already holds
Facial age estimationSoftware judges your apparent age from a selfieA face image, which reputable providers normally delete afterwards
Bank, card or carrier checkYour bank or mobile provider vouches that you are an adultA simple yes or no from a third party
ID documentA photo of a passport or licence, frequently with a selfieThe most sensitive information of the lot
Digital ID or age tokenA reusable credential that says "over 18"Only the age claim, in the better designs

Passing a check with minimal exposure

  • Take the gentlest route on offer. When facial estimation or a bank check is listed beside ID upload, ID is seldom the smarter pick.
  • Look for a named specialist. A dedicated verification company with a published retention policy is a safer holder of your data than an app keeping your passport photo in its own systems. The incidents described in AI companion data breaches show why that matters.
  • Find the retention wording. "Deleted immediately after verification" is the phrase to hope for.
  • Keep your real name out of the account email where you can. A check proves an age; it should not tie your identity to your chat history.
  • If an app holds your documents, you can ask it what it has kept. Private-sector organizations covered by PIPEDA must generally answer access requests, and you can complain to the Office of the Privacy Commissioner of Canada if the answer is unsatisfactory.

What changes in daily use

Where this is going

Proving age is turning into a standard requirement for any service that leans towards adult material. The argument has moved on from whether to check to how to do it without creating fresh privacy problems. Reusable age tokens, which confirm "over 18" without revealing who you are, look like the best answer. Until they are widespread, the advice stays simple: choose the least invasive method on offer, and favour apps that rely on specialist verifiers over ones that collect documents themselves.

Frequently asked questions

Why is my AI girlfriend app suddenly asking for ID?

Several jurisdictions, including the UK and a number of US states, now expect services with sexual content or AI companions to keep minors out using a check that actually works. Typing in a birth date does not meet that standard there, so apps that serve those markets have added stronger steps.

Should I hand my ID to an age-check company?

That depends on who is asking and what they keep. Favour options that never store your document, such as a selfie-based age estimate or a confirmation from your bank or mobile carrier. If ID is the only route, look for a named verification specialist with a clear retention policy instead of the app holding the photo itself.

Would a VPN get me past the check?

Often it would, on a technical level. But it can breach the app's terms, alter the prices and payment methods you are shown, and put you under another country's rules. It also leaves your privacy untouched, because the app keeps your chats either way.