India will check your child's age with an ID, not a face scan

A family mark standing for a parent approving a child's account

Something small showed up on Indian phones this month. A box inside WhatsApp asking for a date of birth, with a line saying that upcoming laws in India require the platform to ask. As IANS reported on 7 August, the test is running with a limited set of users, it is optional, and Meta says skipping it changes nothing about how the app works.

You can ignore the box. Do not ignore the reason it is there.

What India has actually decided

India notified its Digital Personal Data Protection Rules on 13 November 2025, and the interesting part is not the rules so much as the calendar attached to them. The heavy obligations, the ones about consent and how a company may handle your data, take effect on 13 May 2027.

On that date two things become true at once for Indian children. Any company processing the personal data of someone under 18 must first obtain verifiable consent from a parent or guardian. And children may not be tracked or behaviourally monitored, with a narrow exception for real-time location where it genuinely serves the child’s safety. That second one is not a setting a parent can switch on. It is simply off.

Notice the number. Under 18, not 13 and not 16. India has drawn the line at the very top of childhood, and drawn it across services generally rather than social media specifically. A chatbot answering a fifteen year old’s questions about photosynthesis sits inside that line.

The token, not the face

Here is what makes this a story worth following from outside India.

There are broadly two ways to establish how old someone is online. You can guess, with a model trained to estimate age from a face or from patterns of behaviour. Roblox went that way when it made a face scan the price of chatting, and TikTok’s facial age estimation is doing similar work under Europe’s new rules. Or you can ask for proof, and route it through a state identity system.

India picked proof. The rules describe how: a company can rely on identity and age details it already holds reliably, or it can accept a virtual token issued by an authorised entity, including bodies tied to DigiLocker, India’s government-backed document wallet. The practical shape of it is a parent demonstrating, through Aadhaar-linked infrastructure, that they are an adult and that this child is theirs. The platform receives a yes or a no instead of a document.

That is arguably kinder to privacy than posting your child’s face to an estimation model. It is also, at the scale of India, a colossal amount of new plumbing to build in nine months.

Identity documents laid out on a desk
India's model runs the age check through a government identity token rather than a photo of a face.

Why India is the place this gets tested

Because India’s young people are already the heaviest users of the thing being regulated.

India is OpenAI’s second largest market, with more than 100 million weekly users. In February 2026 the company said that 18 to 24 year olds account for nearly half of all the messages Indians send to ChatGPT, and that people under 30 account for 80% of usage there. OpenAI has been leaning into that: from 4 November 2025 it offered a full year of free ChatGPT Go, a plan that normally costs under five dollars a month, to anyone in India who signed up during the promotion.

So the country with one of the youngest heavy AI user bases anywhere is also the country preparing to demand a verified parental yes for every one of those users who has not turned 18.

The labs, meanwhile, are approaching the same problem from the opposite direction. On 18 August OpenAI launched ChatGPT for Teens, a version for 13 to 17 year olds that blocks romantic and sexual conversation and leans towards study help rather than finished essays. A user lands in it either by saying they are a teenager or by OpenAI’s age assurance estimating that they are under 18 from signals such as the kinds of questions they ask. As ABC News noted in its report, that system estimates. It does not verify.

Guessing on one side, proving on the other, and both operating inside the same child’s afternoon.

A pair of hands holding a phone
WhatsApp started asking some Indian users for a date of birth in August 2026.

The parts that could break

Worth saying plainly, because enthusiasm for age checks tends to outrun the evidence that they work.

A July 2025 analysis in Tech Policy Press argued that the consent framework rests on assumptions that do not hold across all of India. It cited a 2022 figure that only 38% of Indian households have digital literacy, and pointed out that parents frequently help their own children misrepresent their age online, which is a fairly complete answer to any system whose last line of defence is parental judgement. A child whose parent has no usable ID does not fail gracefully in this design. They simply cannot be consented for.

There is a cost on the privacy side too. The analyst Bronwyn Howell, quoted in a 17 August report by Biometric Update, made the point that even a system storing no Aadhaar numbers still generates query logs showing which platform asked about whom and when, which she called “a surveillance database even if no individual Aadhaar number is stored”. Our own view is that this trade is real and under-discussed, and that “we only pass a yes or no” is a claim to check rather than accept.

For a parent reading this in Singapore, the local read is simple enough. Singapore went a different way, putting age assurance duties on the app stores. India is running the largest live experiment in the ID-token model that exists anywhere. Whichever approach turns out to be workable at a billion-person scale is the one that gets copied, including here.

The birth year has stopped being decorative

For twenty years, the year a ten year old typed into a sign-up form was a fiction everyone tolerated, parents included. That is ending. The age on an account is turning into the switch that decides which product your child actually gets: whether a chatbot will discuss certain things, whether an app may profile them, whether anyone needs to ask you first.

So do the boring thing this weekend. Open the accounts your child genuinely uses, the messaging app, the game, the AI they ask questions of, and find out what age each of them believes your child to be. Correct the wrong ones now, while it is a two minute change in settings rather than a verification wall with your ID on the other side of it.

Was this useful?

Sources

  1. MeitY notifies Digital Personal Data Protection Rules, 2025 · SCC Online
  2. MeitY notifies final Digital Personal Data Protection Rules 2025 · Bar and Bench
  3. Parental Consent is a Conundrum for Online Child Safety · Tech Policy Press
  4. Meta's WhatsApp age-check trial faces challenge from India's digital ID plans · Biometric Update
  5. WhatsApp tests age-verification feature in India ahead of DPDP Act implementation · IANS
  6. OpenAI says 18- to 24-year-olds account for nearly 50% of ChatGPT usage in India · TechCrunch
  7. OpenAI offers free ChatGPT Go for one year to all users in India · TechCrunch
  8. OpenAI launches ChatGPT for Teens, promising a more age-appropriate chatbot · ABC News