Verified by Default: Verification Mandates Require a Standard They Have Never Defined
By Pranav Verma '29
In June 2025, the Supreme Court upheld Texas HB 1181 in a 6-3 decision, ruling that states may require age verification for websites where a third or more of the content is harmful to minors. (1) Within weeks, two dozen states with similar laws on their books cited the ruling as evidence that their statutes were constitutional, with each requiring that the method used must be “reasonable” or “commercially reasonable,” which is imprecise. (2)
Additionally, since 2018, banks have been required under the Customer Due Diligence Rule (CDD) to verify customer identity before opening accounts using “reasonable” methods, (3) and the EU’s Electronic Identification, Authentication, and Trust Services (eIDAS) 2.0 regulation requires member states to deploy digital identity wallets with “selective disclosure” capabilities by December 2026, without specifying further. (4) In 2022, the CNIL, France’s data protection authority, examined six commercially available age-verification methods and found none could reliably verify age while protecting user privacy. (5)
Zero-knowledge proofs, cryptographic protocols that confirm a fact without relaying the underlying data, offer an approach for legislatures to standardize “reasonableness.” However, the proof only covers the final verification step, leaving the authenticity of the underlying credential unaddressed, which current legal frameworks fail to consider.
What Paxton Did Not Settle
Texas HB 1181 lists document submission and digital identification as examples of verification methods without excluding other approaches or specifying what any method must guarantee. (6) The Supreme Court in Free Speech Coalition, Inc. v. Paxton asked only whether HB 1181 was substantially related to protecting minors, the standard for intermediate scrutiny, and held that it was. (7)
Kagan, however, noted in her dissent that intermediate scrutiny does not require the least restrictive means, so the majority never had to ask whether a less invasive method could have satisfied the same interest. (8) Such a requirement in the statute would have changed what the Court was deciding, all while safeguarding user privacy without undermining identity verification mechanisms.
Thus, while Paxton settled the constitutional question of whether states may mandate verification, it left open the question of what a mandated verification method must prove, and to what degree of certainty.
The CDD Rule presents the same issue. Financial Crimes Enforcement Network (FinCEN) examiners assess, on a case-by-case basis, whether a bank's verification practices were reasonable, with no standard for banks to aim for. (9) Additionally, France’s SREN law, which prohibits sites from making online pornographic content available to minors, resulted in an Arcom standard requiring a double-blind verification option for adult content sites by April 2025, describing the zero-knowledge property without attaching a required certainty level. (10)
Furthermore, eIDAS 2.0 mandat es selective disclosure without specifying any cryptographic standard that an auditor could check against. (11) In each case, the drafters reached for an ordinary word to describe a precision-dependent requirement and failed to specify further.
The Mathematics
Goldwasser, Micali, and Rackoff established in 1989 that it is possible to convince a verifier that a statement is true without disclosing the “witness,” the underlying data. (12) In the case of age verification, a platform would receive confirmation that a user exceeds an age threshold without a birthdate or other identifying information ever leaving the user's device.
The protocol has two formal properties. A false claim can pass the verifier only with some small fixed probability, the soundness error 𝜖, which in zk-SNARK constructions (succinct, non-interactive arguments of knowledge developed from the work of Goldreich, Micali, and Wigderson) sits at 2-128. (13) The verifier also learns nothing but the truth value of the claim, a condition demonstrated by showing that a simulator with no access to the witness can produce transcripts statistically indistinguishable from those of a real exchange. (14)
These properties produce numbers that can be written into statutes and checked against an implementation. The National Institute of Standards and Technology (NIST) specifies minimum key lengths for encryption, and the FDA specifies acceptable false-positive rates for diagnostics. Verification law has never done any of this, which means "commercially reasonable" leaves both developers and the courts working from different assumptions.
The Issuance Gap
While the soundness guarantee covers the proof, it says nothing about the assumptions of the proof.
A zero-knowledge proof that a user is over 18 years old only confirms that a credential attesting to that property exists and traces to an issuer the verifier trusts. A 16-year-old who obtained a state ID on a forged birth certificate holds a credential that passes every cryptographic check with full soundness. The protocol performed as expected; the failure was in the process that produced the valid credential.
In 2022, the CNIL was unable to find any available methods that could resolve both issues. (15) Thus, NIST SP 800-63-4, released in July 2025, separates identity proofing assurance, the process by which an issuer verifies the real-world fact before issuing a credential, from authentication assurance, the process by which a holder later proves possession of that credential. (16)
Yet, every verification statute discussed here collapses them into a single “reasonableness” standard and places the consequence of failure on the user, who loses access regardless of which party caused the breakdown. A soundness standard would fix the authentication side, and the proofing side should sit with whoever issued the underlying credential, with an exception for user fraud.
What The Statute Should Actually Require
Paxton demonstrated what courts do when asked to evaluate an undefined standard: they defer to the legislative interest, leaving critical technical questions unaddressed. (17) Closing this gap will require two rules because the proof and the credential operate independently, and a remedy for one would not treat the other.
For the proof, a verification method should be deemed compliant if it meets a stated maximum soundness error and discloses no attribute beyond the one being checked. That language is domain-neutral; it applies equally to an age-verification statute, a CDD Rule amendment, and eIDAS implementation frameworks. Regulators already incorporate technical standards by reference in other precision-dependent contexts, so there is no structural reason verification laws cannot do the same.
For the issuance side, primary liability should rest with whoever supplied the false document, not with the issuer who processed it in good faith. A DMV that issued an ID on a forged birth certificate and a bank that accepted a customer-provided document without independent confirmation under the CDD Rule's permissive reliance provisions represent different situations. (18) The issuer should still face a modest fine scaled to what verification it was required to perform and enough to encourage investment in better forgery detection without treating an honest mistake as malicious.
Conclusion
As the CNIL had discovered in 2022, there are no available methods that can verify one’s age without compromising their privacy. Since Paxton, over two dozen states have passed laws that mention "reasonableness" and go no further. Zero-knowledge proofs offer legislatures an answer to the proof side of the problem, one that can be audited and precisely written into statute.
However, they do not resolve the issuance side. A statute that writes only a soundness standard into law will have fixed the part of the problem that was already closest to being solved, while leaving the part that determines who is responsible when the credential was never accurate exactly where it started.
Endnotes
Free Speech Coalition, Inc. v. Paxton, 606 U.S. 461 (2025).
Mayer Brown, "Little Users, Big Rules: Tracking Children's Privacy Legislation," January 28, 2026, https://www.mayerbrown.com/en/insights/publications/2026/01/little-users-big-rules-tracking-childrens-privacy-legislation.
Customer Due Diligence Requirements for Financial Institutions, 31 C.F.R. § 1010.230 (2018).
Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 (eIDAS 2.0), Art. 5a.
CNIL, "Online Age Verification: Balancing Privacy and the Protection of Minors," 2022.
Tex. Health and Safety Code § 129B.002 (2023).
Paxton, supra note 1, at 478.
Ibid. at 501 (Kagan, J., dissenting).
31 C.F.R. § 1010.230(b)(2); Davis Wright Tremaine, "Trust Issues: April 2026," April 3, 2026, https://www.dwt.com/blogs/privacy--security-law-blog/2026/04/trust-issues-april-2026.
Arcom, Référentiel technique sur la vérification de l'âge pour la protection des mineurs contre la pornographie en ligne (adopted October 9, 2024; published October 11, 2024), https://www.arcom.fr/sites/default/files/2024-10/Arcom-Referentiel-technique-sur-la-verification-de-age-pour-la-protection-des-mineurs-contre-la-pornographie-en-ligne.pdf
Kenneth A. Bamberger et al., "Verification Dilemmas in Law and the Promise of Zero-Knowledge Proofs," Berkeley Technology Law Journal (forthcoming).
Shafi Goldwasser, Silvio Micali, and Charles Rackoff, "The Knowledge Complexity of Interactive Proof-Systems," SIAM Journal on Computing 18, no. 1 (1989): 186–208.
Jens Groth, "On the Size of Pairing-Based Non-Interactive Arguments," in Advances in Cryptology, EUROCRYPT 2016 (Berlin: Springer, 2016), 305–326; Oded Goldreich, Silvio Micali, and Avi Wigderson, "Proofs that Yield Nothing But Their Validity," Journal of the ACM 38, no. 3 (1991): 690–728.
Goldwasser, Micali, and Rackoff, supra note 12.
CNIL, supra note 5.
National Institute of Standards and Technology, Digital Identity Guidelines, SP 800-63-4 (2025), § 2.1.
Congressional Research Service, "Supreme Court Upholds State Age-Verification Requirement for Certain Websites," LSB11354, August 28, 2025, https://www.congress.gov/crs-product/LSB11354.
Nicolin Decker, "Proof Without Exposure: Zero-Knowledge Proofs as a Cryptographic Framework for Institutional Financial Compliance," SSRN, April 17, 2025, https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5170329; 31 C.F.R. § 1010.230(b)(2).



Comments