Age verification laws: what a directory operator actually has to do in 2026

Why this stopped being a rule nobody enforced
For most of the last decade, an age verification bill for adult websites was something you could read about and safely ignore. Courts kept striking these laws down under strict scrutiny, the standard that is hardest for a government to satisfy, and operators who never built a check paid no price for it. That changed on June 27, 2025, when the United States Supreme Court decided Free Speech Coalition v. Paxton, upholding a Texas law requiring age verification for sexually explicit sites in a six to three ruling. The Court applied intermediate scrutiny instead, a lower bar the state could actually clear.
The practical effect showed up within months. States that had similar bills sitting in committee or paused by an injunction moved them forward, because the constitutional question that used to stall them was settled. By the middle of 2026, roughly twenty six states had an age verification law of this kind in force, West Virginia the most recent to join in June. Courts that had blocked comparable laws before Paxton have mostly let them stand since, including an appeals court that sent a challenge to a near identical Indiana law back down with instructions to rule for the state.
None of this stayed inside the United States. The United Kingdom's Online Safety Act made age assurance for pornographic content enforceable from July 25, 2025. Germany went further still: from December 1, 2025, its media regulator gained the power to order banks and payment providers to stop processing for a site that does not use an approved verification method, reaching platforms based anywhere as long as they serve German visitors. Three different legal systems moved on the same question inside six months, which is not a coincidence so much as each one watching the others succeed.
If your directory has been treating age verification as a feature to add once a regulator complains, that plan no longer works. The complaint now comes with a fine attached, and in more than one country the fine can reach your bank account before it reaches your inbox.
What the laws actually require, and why one answer will not cover them
Most of the twenty six US states use a similar trigger: a site falls under the law once roughly a third of its pages carry content that would be considered sexually explicit for a minor. Kansas set the bar lower, at a quarter. A handful of other states skip the percentage entirely and use looser language like "a substantial portion of its content," which is harder to plan around precisely but functions the same way in practice: if a meaningful share of your listings and photos would embarrass you in front of a regulator, the whole site is in scope, not just those pages.
What counts as compliance, and what happens if you skip it, differs by state in ways that matter to how you budget risk. Texas and Alabama require a specific health warning notice on the site in addition to the age check itself, with statutory wording you cannot paraphrase. Tennessee classifies a violation as a felony, which is a different order of exposure than a fine. Kentucky and North Dakota do not rely on a state agency to enforce the law at all: a private lawsuit does the enforcing instead, with Kentucky's statute setting damages at ten thousand dollars per violation before legal costs.
That range, from a paperwork requirement to a criminal charge to an open-ended private lawsuit, means a single company-wide policy of "we check everyone the same way" does not actually cover you. You are running twenty six separate compliance regimes that happen to share a name, and the honest way to manage that is a checklist per state your traffic reaches, not one global toggle you switch on and consider finished.
The same fragmentation exists abroad, in a different shape. UK regulator Ofcom accepts several verification methods including photo identification, credit card checks and facial age estimation, and expects operators to pick one that is "highly effective" rather than merely present. Germany's regulator keeps a specific approved list of certified providers, and a method that satisfies Ofcom is not automatically on that list. A single verification vendor integrated once will rarely satisfy every market you serve; check the approved method for each jurisdiction before you assume the box is ticked.
The exposure now reaches past the fine itself
Ofcom has not been shy about using the power it was given. AVS Group Ltd was fined one million pounds in December 2025 for inadequate checks across eighteen adult websites it operated. Kick Online Entertainment SA was fined eight hundred thousand pounds in February 2026 for the same failure, plus a separate penalty for not answering the regulator's information request on time. By the middle of 2026, Ofcom had issued at least seven such fines against different operators, ranging from fifty thousand to one point three five million pounds, and the pace of new cases has not slowed.
The scope of what counts as an adult service is also widening faster than most operators expect. In January 2026, Ofcom opened a formal investigation into X over its Grok chatbot generating sexualised images on request, and a separate one into an AI companion service called Joi.com. Neither operates a directory of listings in any traditional sense; both were treated as falling under the same duty because of what their output actually was. A regulator's definition of "adult content" is drifting toward what a service produces, not what a site calls itself.
This is where the exposure stops being only a legal line item and starts touching the account you already fought to get approved. Germany's payment blocking power is the clearest version of this: an acquirer that discovers age verification failures in one market has every reason to treat that discovery the way it already treats a spike in chargebacks, because from where the acquirer sits both are the same kind of risk signal. Expect the underwriting conversation to start including age verification as a standard question within the next renewal cycle, the same way it already asks about your moderation policy.
The uncomfortable part is that none of these fines were levied against operators who had done nothing. Several had some form of age gate in place; regulators found it too easy to click past, or found no evidence it had been checked for effectiveness after launch. A verification step that exists on paper but was never tested against how an actual sixteen year old would try to get around it is close to worthless, and it is exactly the gap these investigations have been finding.
What checking an age actually costs
Three broad methods are in active use, and they price very differently. Facial age estimation, where a photo produces an estimated age with no document required, is the cheapest: one provider's published pricing lists it at ten cents per check, with a document check available on the same integration for fifteen cents and a fuller identity bundle for thirty three cents. Document-based identity verification from a larger provider runs close to a dollar fifty per check at published rates, and a mid-market vendor's self-serve pricing lists a range from eighty cents to just over two dollars depending on the check type, on top of a monthly minimum that runs from well under fifty dollars up to a little over two hundred.
Some of the best known names in the sector do not publish a price at all and negotiate per contract, so treat any number you cannot find on a vendor's own pricing page as a starting position rather than a fact. Ask three providers for a quote against your real expected volume before picking one, the same discipline that pays off once a payment processor starts asking its own underwriting questions. The monthly minimum often matters more than the per-check price for a directory that is not yet at scale, since a plan with an included volume can cost less in year one than a lower per-check rate with no floor.
Do not build this yourself. Estimating an age from a photograph or validating a government document is a narrow, liability-heavy problem that a specialist vendor has already solved, tested against fraud attempts, and can defend when a regulator asks exactly how the check works and how it was validated. This is one part of the stack where the instinct to save money by building in-house costs the most if it turns out to be wrong, because the bill for getting it wrong is a regulatory fine, not a support ticket.
It is worth being clear about what this check is not. It is a different requirement from confirming that the person posting a listing is a real, consenting adult: that check protects the marketplace from fraudulent advertisers, while age verification protects against a minor viewing the content at all. Most directories eventually need both running side by side, often through different providers, on different pages, checking different things at different points in the visit.
Building a policy that survives being asked to prove it
Start by mapping every market that sends you meaningful traffic against its actual requirement, not a general sense of "most places now require this." For each US state, the UK, Germany and any other country in your top traffic sources, write down the content threshold that triggers the law, the accepted verification methods, and the penalty class, before you decide how to serve that market rather than after a fine shows up in a search for your provider's name.
Geoblocking a market instead of building for it is a legitimate business decision, not a failure of nerve, and it is one several platforms have made openly for markets where the enforcement risk outweighs the traffic. If a jurisdiction sends a small share of your visitors and its penalty class is criminal or an uncapped private lawsuit, blocking it while you evaluate the real compliance cost is a defensible choice, and one you can revisit once the numbers or the law change.
Keep a record of every verification event: a timestamp, the method used and the result, retained for as long as the relevant law requires and no longer than that for the underlying document or image. Regulators have shown they will tolerate an individual check that fails; what they punish is being unable to produce evidence that any check happened in the first place. A log that proves the gate ran is worth more than a gate that merely exists.
Review the whole map on a fixed schedule, at least once a quarter, because the direction of travel has been one way since the Paxton ruling and shows no sign of reversing. A market that was unenforceable in 2024 is issuing seven figure fines in 2026, and the pace of new state laws and new regulator actions means a policy written a year ago is probably already out of date somewhere in your traffic.
The first concrete step, if none of this exists yet: pick one verification provider that can run both facial estimation and document fallback through a single integration, decide today which markets you serve with full confidence and which ones you geoblock until the calculation changes, and put the decision in writing before a regulator's letter forces you to write it under worse conditions.


