Requires manufacturers of internet-enabled devices to conduct commercially reasonable age assurance to determine whether a user is a covered minor and shall provide all websites, online services, online applications and mobile applications on such user's internet-enabled device and/or application store manufactured by the covered manufacturer with a digital signal that such user is a covered minor via a real-time application programming interface (API).
This bill would add a new article to New York’s General Business Law creating a “device-level age assurance” framework for internet-enabled devices. It requires covered manufacturers—defined to include device manufacturers, operating system providers, and application stores—to determine, at device activation, whether a user is a minor using commercially reasonable age-assurance methods. The bill directs the Attorney General to issue regulations identifying acceptable methods and accuracy standards, and it bars reliance on self-reported age alone. Information collected for age verification must generally be deleted immediately after the age-determination attempt, subject to other legal requirements.
If a user is identified as a covered minor, the manufacturer must transmit a real-time digital signal through an API to websites, online services, applications, and app stores on that device indicating the user is a minor. The bill also requires that these protections be built into operating system and app store updates by default for devices sold after the effective date. It includes nondiscrimination provisions preventing manufacturers from treating their own services more favorably than third-party services and from degrading service, raising prices, or otherwise penalizing users because of compliance with the law. Enforcement is assigned to the Attorney General, who may seek injunctions, restitution, disgorgement, damages, civil penalties of up to $10,000 per violation, and destruction of unlawfully obtained data, but the bill creates no private right of action.
The bill would amend the General Business Law by creating a new Article 45-A governing age assurance on internet-enabled devices. It would impose new compliance obligations on device makers, operating system providers, and application stores operating in or affecting New York, while also authorizing the Attorney General to promulgate implementing regulations and enforce the law through civil actions. The measure would affect how minors are identified and how age-related signals are shared across devices and digital services, and it would require data minimization and deletion practices tied to age verification.
No committee transcript or vote record was provided, so there is no recorded debate or roll-call history to gauge formal legislative sentiment. Based on the bill text and caption, the measure appears aimed at child safety and online age verification, suggesting a consumer-protection rationale. At the same time, the bill’s detailed compliance requirements and enforcement provisions indicate it is a significant regulatory proposal for technology companies.
The main points of contention likely involve privacy, feasibility, and scope. Supporters would likely emphasize protecting minors online and giving parents and regulators stronger tools to limit inappropriate access, while critics may argue that device-level age assurance is technically difficult, costly, and potentially intrusive. The requirement to share a minor-status signal via real-time API, the ban on self-reported age alone, and the Attorney General’s broad rulemaking and enforcement authority are likely to be the most debated features, especially among device manufacturers, operating system providers, app stores, and privacy advocates.