For most of the personal computer's history, the relationship was simple: you owned the machine, opened a program, and expected it to obey. But Microsoft is preparing Windows for a very different digital future--one in which applications may first ask the operating system what kind of person is sitting behind the screen and whether that person has been verified.
Microsoft's new Windows Age APIs will allow participating apps to request the age range of a signed-in user. Windows can report that the user is under 10, 10-12, 13-15, 16-17, or 18 and older. It can also tell the app whether that age has been verified, remains unverified, or whether the user has opted out.
Microsoft describes this as a privacy-preserving system because applications receive an age bracket rather than a precise birthday. But behind that reassuring language sits a much larger change: Windows is being equipped to serve as an identity gatekeeper between the user and the software.
The computer will not simply open the door. It will be able to tell the app whether the user carries the right credentials to enter.
Protecting Children--or Classifying Everyone?
The immediate justification is child safety. Apps could use the signal to restrict mature media, social features, user-generated content, communications, in-app purchases, and virtual currencies. Parents understandably want children protected from pornography, predators, addictive platforms, and inappropriate commercial practices.
But a system cannot reliably identify children without also classifying adults. If an application must know who is under 18, every adult may eventually be expected to prove that he or she is over 18.
California is already pushing technology companies in this direction. Its Digital Age Assurance Act, scheduled to take effect in 2027, requires covered operating-system providers to offer an interface for recording a user's age or birth date and to transmit an age-range signal to qualifying applications.
What begins as a child-protection measure can therefore become an identity requirement for the entire population. Once the infrastructure exists, age may be only the first attribute it is used to verify.
Microsoft Once Warned About The Danger
Microsoft itself recognized the threat only a few years ago. In 2024, the company acknowledged that there was no clear technical solution capable of accurately verifying age without potentially creating serious tradeoffs involving privacy, security, civil rights, government surveillance, anonymity, and freedom of expression.
Those dangers have not vanished. The pressure to implement the technology has simply grown.
Microsoft's current system requires the user to be signed into a Microsoft account, and its documentation says identity-provider age signals are presently retrieved only for Microsoft accounts. Apps must also request access to account information, and users can withhold consent.
But what happens when refusing consent means losing access?
An "opt-out" button provides little protection if applications begin denying communication features, purchases, media, or other services to anyone whose status remains unverified. People may retain the theoretical freedom to refuse while being progressively excluded for exercising it.
Soon We May All Be Asked To Prove We Are Human
Age verification is arriving as the internet faces an even greater identity crisis.
Artificial intelligence can already create convincing faces, voices, photographs, documents, and videos. Deepfakes can impersonate political leaders, pastors, family members, and corporate executives. Criminals can clone a loved one's voice, manufacture an emergency, and demand money before the victim realizes the call was artificial.
AI agents will deepen the problem. These systems are becoming capable of operating computers, opening accounts, sending messages, making purchases, and completing online tasks with decreasing human supervision. Hackers and organized criminals will use them to automate fraud, overwhelm security systems, infiltrate communities, and create armies of believable digital identities.
In that environment, "Are you old enough?" may soon be followed by an even more consequential question: "Are you actually human?"
Simple CAPTCHA tests will not be enough. Platforms may demand government identification, facial scans, device credentials, financial-account confirmation, or digital identity wallets. The more convincing artificial people become, the more difficult anonymous humans may find it to prove they are real without revealing exactly who they are.
Deepfakes and AI fraud could succeed where earlier digital ID campaigns struggled. People who would never voluntarily accept universal identity checks may embrace them when presented as the only way to distinguish humans from machines.
The Operating System Becomes The Trust Broker
Windows occupies the perfect position to manage this new system. Instead of every application independently verifying every user, the operating system can become the central trust broker.
Today, Windows is preparing to report an age bracket and verification status. Tomorrow, similar architecture could potentially tell an application that a person's identity is verified, a device belongs to that person, a transaction was initiated by a human, or an AI agent has permission to act on someone's behalf.
The threats driving this transformation are real. Deepfakes will ruin reputations. AI-powered fraud will steal money. Bots will make online communities increasingly difficult to trust. But real dangers can still be used to justify systems carrying dangers of their own.
The infrastructure being built promises safety, privacy, and convenience. It may also establish a new principle: before your computer obeys you, an outside authority must confirm that you are authorized to proceed.
Children provide the first justification. Deepfakes, hackers, and AI agents may provide the next. The final result could be a digital world in which anonymity is treated as suspicious, identity becomes the price of participation, and permission comes before access.