Most teams building general-audience products read the wave of US age-verification laws as someone else’s compliance problem. Pornography sites, adult-content platforms, the obvious targets — not a discussion forum, a two-sided marketplace, a social feed, or an AI chat product. That reading was defensible eighteen months ago. It is now a mistake, and the reason is a single structural detail that has quietly become the load-bearing element of American age-verification law: the one-third rule.
The test is not “are you an adult website.” The test is whether one-third or more of the material you publish or host is “harmful to minors.” That is a ratio computed against your content, not a label you chose when you incorporated. And on July 9, 2026, Missouri Governor Mike Kehoe signed House Bill 1839 into law with exactly that threshold — and with statutory language broad enough that a social platform “answers to the same requirement once enough of what it hosts trips the threshold” (Biometric Update). The category you thought protected you does not. The ratio decides.
Where the one-third threshold came from, and why it now matters everywhere
The one-third test is not a Missouri invention. It is the Texas model, and it survived the highest possible stress test.
Texas HB 1181 required any commercial site on which “one-third or more of the content is harmful to minors” to verify that every visitor is 18 or older. The adult-industry trade group challenged it on First Amendment grounds, and in Free Speech Coalition, Inc. v. Paxton the Supreme Court, 6-3, upheld the statute on June 27, 2025. The majority applied intermediate scrutiny — not the strict scrutiny the challengers wanted — reasoning that the law only incidentally burdens adults’ access to protected speech while serving the state’s interest in shielding minors (Sidley). Whatever you think of the reasoning, the operational consequence is unambiguous: the one-third-of-content threshold is now constitutionally durable, and every state legislature that wanted an age-verification statute but feared it would be struck down got a validated template to copy.
They are copying it. Around half of US states now mandate some form of age gating for adult content or social media, and more laws take effect through 2026 (National Law Review). Missouri is simply the freshest: it converted an attorney-general rule into hard legislation, kept the one-third threshold, and layered on the enforcement teeth that make it a business problem rather than a policy statement. We mapped the messy state-by-state terrain in the US compliance patchwork; the one-third rule is the connective tissue running through most of it.
The ratio is a property of your platform, not a decision you made
Here is the part that catches general-audience operators off guard. On a dedicated adult site, the one-third test is trivially satisfied and everyone knows it going in. On a general-audience platform, the ratio is an emergent property of what your users post, what your algorithm surfaces, and how a given state defines “harmful to minors” — and it can cross the line without a single deliberate decision from your product team.
The definitions are doing a lot of work here, and they are broad. “Harmful to minors” is defined differently in each state, and the scope keeps widening: beyond sexually explicit material, some framings reach content that surfaces mature or violent posts, promotes self-harm or disordered eating, or encourages risky behavior (Built In). A subreddit-style NSFW corner, an unmoderated marketplace category, an adult section of a creator platform, a feed that algorithmically amplifies borderline content — each is a way a platform that never described itself as “adult” accumulates a content mix that a state attorney general can argue crosses one-third. And the newest statutes are explicitly reaching past pornography: state children’s-online-safety laws expanded well beyond social media in 2026, pulling in AI chatbots and other general-purpose products (MultiState).
The uncomfortable implication for a general-audience platform: your in-scope status is not a one-time legal opinion you can file and forget. It is a moving quantity that depends on content you do not fully control, measured against definitions that vary by state and are trending broader. “Are we a covered entity in Missouri this quarter” is closer to a monitored metric than a settled fact.
Three demands the statutes make — and none of them are “put up a wall”
When a platform accepts it might be in scope, the instinct is to bolt an ID-upload gate onto the front door. That instinct fails on all three of the things these laws actually require, using Missouri as the concrete template.
A real age determination — self-declaration is finished. The statute demands verification via digital identification, government-issued ID, or transactional data, performed through a third party. An “I am 18” checkbox is not compliance; it is documented negligence. Regulators on both sides of the Atlantic have made this explicit, most vividly when the UK’s ICO fined Reddit’s approach and made clear that self-declaration is not enough. Note also what counts and what does not: “transactional data” is not a free pass, because a credit card confirms a payment relationship, not an age — a distinction we spelled out in why a credit card is not proof of age.
No retention of identifying information. Missouri’s law specifies data-storage restrictions and prohibits the entity from retaining identifying information after verification (Biometric Update). This is not a nice-to-have; it is a statutory obligation, and it is in direct tension with the naive “collect IDs at the door” design. Every retained ID scan is both a compliance violation waiting to be found and a breach liability. The age-verification sector has already produced its own cautionary tales here — the wave of retention-driven breaches and the Persona/Discord exposure both trace back to systems that held identity data they should never have kept. A statute that forbids retention turns “don’t be a honeypot” from best practice into black-letter law.
Per-access penalty exposure. Missouri attaches an additional penalty of up to $250,000 where one or more minors accessed harmful material in violation of the requirement (Biometric Update). Read that carefully: the enhanced exposure is tied to minor access events, which means your defense is evidentiary. You need to be able to demonstrate, per determination, that a reasonable and effective check was applied. A gate that cannot produce that audit trail leaves you unable to rebut the state’s central factual claim.
Put together, the statute is not asking for a wall. It is asking for a verifiable, non-retaining, auditable age determination — which is a materially harder engineering problem than a document-upload form, and a materially easier one to get wrong.
Why the naive gate is the worst possible answer
Suppose a general-audience platform panics and drops a mandatory government-ID upload in front of every visitor. It manages to be simultaneously over-compliant and non-compliant, and commercially self-harming.
It nukes the funnel. The overwhelming majority of your visitors are lawful adults, and a document-and-selfie wall at the entrance is the single most reliable way to destroy conversion. We quantified this in detail in reducing age-verification drop-off: friction at the door is not a rounding error, it is the difference between a viable product and a dead one. A porn site can absorb that friction because the demand is inelastic. A general-audience platform competing for attention cannot.
It creates the honeypot the same law forbids. Collecting and holding IDs to prove you checked ages is precisely the retention the statute prohibits, and precisely the architecture that has produced the sector’s worst breaches. You would be manufacturing your own next incident to satisfy a requirement that never asked for it.
And it still may not be defensible, because a wall that verifies identity but keeps no minimal, privacy-preserving record of the determination gives you nothing to show the regulator when the per-minor penalty question arrives. Maximum friction, maximum liability, minimum evidentiary value. It is the worst cell in the matrix.
The architecture that answers the one-third rule
The design that actually fits has been the through-line of everything we build, and the one-third wave sharpens why each property matters. Four things separate a gate that survives a state attorney general from one that was overfit to a checkbox.
The threshold is configuration, not a constant. The line is 18 in these adult-content statutes, but the same platform is simultaneously subject to under-16 social-media rules elsewhere, COPPA’s under-13 logic in the US, and estimation-first 18-gates in the UK. A verification layer that hard-codes one age and one rule forces a rebuild for every statute. The orchestration model — resolve the unambiguous majority at near-zero friction, escalate only the contested band — has to treat the age line, the escalation methods, and the pass/fail logic as parameters keyed to jurisdiction.
Estimate first, so the lawful-adult majority never sees a wall. For an 18 determination, facial age estimation with a wide buffer clears the clear-adult tail without a document upload, keeping friction off the users who make up most of your traffic. That is the design the UK regulator’s own data has now validated at population scale, and we walked through how to read its accuracy honestly in the NIST FATE breakdown. Only the ambiguous buffer zone escalates to a stronger check — which is where the statute’s method constraints and no-retention rule get satisfied by design rather than by exception.
Prove the fact, then discard the identity. The escalation tier verifies age through a third party and returns an attestation — over-18, true or false — not a stored dossier. This is the point of privacy-first, no-surveillance architecture and of zero-knowledge age proofs: the platform learns the one bit it is legally required to know and holds nothing it is legally forbidden to keep. Missouri’s retention ban is not a constraint you engineer around; it is the default the architecture already assumes.
Resolved users are not re-interrogated, and every determination is logged as a fact, not a face. A lawful adult who has cleared the check re-presents a minimal reusable credential on return rather than running the gauntlet each session — friction you can afford to remove precisely because you kept a privacy-preserving proof rather than raw identity. And because each determination is instrumented against the actual age line, you can produce the audit trail that answers the per-minor-access penalty: evidence that a reasonable, effective check was applied, without a warehouse of ID scans behind it.
That combination — configurable threshold, estimation-first funnel protection, no-retention proof, and an auditable determination — is the shape the one-third rule demands. It is not a new category of technology. It is the layered model built so its age line can move and its escalation tier can carry statutory weight.
What a general-audience platform should do before an AG letter arrives
The mistake that will hurt is treating in-scope status as binary and permanent — deciding once that “we’re not an adult site” and never revisiting it as content, algorithms, and statutory definitions drift. The one-third rule makes that a live, monitored question.
Start by auditing your actual content mix against the one-third line in the states where you have meaningful traffic, using the broadest plausible reading of “harmful to minors,” because that is the reading a motivated attorney general will use. Treat the answer as a metric with a margin, not a verdict. Where you are near the line, or where your content is user-generated and therefore outside your direct control, assume you may cross it and build the gate before you are forced to build a bad one under deadline. The platforms that will struggle are the ones that discover they are covered from a demand letter and reach for the ID-upload wall in a panic; the ones that will not are the ones that already treat the age threshold as a parameter and the determination as auditable evidence.
Xident is built for exactly this shape. Age-threshold classification runs estimation-first and low-friction to clear the lawful-adult majority, configured against the line you need — 18 for the harmful-to-minors statutes, 16 or 13 elsewhere — rather than a hard-coded constant. The ambiguous band escalates to third-party verification that returns a proof, not a stored identity, satisfying the retention bans by construction. Returning users re-present a minimal token instead of repeating the check, keeping conversion intact. And because every determination is measured and logged against the actual boundary, you can produce the evidence the per-access penalties will demand. If your platform is general-audience but your content mix is drifting toward the one-third line, that is the architecture conversation to have now — while you are choosing your gate, not defending the absence of one.
This article is for general information and does not constitute legal advice. Free Speech Coalition, Inc. v. Paxton, Missouri HB 1839, and the various US state age-verification statutes referenced here were current as described at publication and remain subject to amendment, regulatory guidance, and ongoing litigation, and the application of a “one-third harmful to minors” threshold to any particular general-audience or social platform is fact-specific and contested. Validate your scope and compliance approach with qualified counsel in each jurisdiction against the rules in force.