Opening an app should not require knowing who I am. Age assurance is becoming less like a gate and more like infrastructure. Prompted by Jerry Fishenden’s latest thinking on citizen-held credentials, this article asks what comes after age verification: how identity, authentication, authorisation, and attributes should relate; why civil identity is so often introduced unnecessarily; and whether the internet can establish what it needs to know without knowing who we are.
Continue reading