<?xml version='1.0' encoding='utf-8'?>
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" version="3" ipr="trust200902" docName="draft-iab-agews-report-03" category="info" consensus="true" submissionType="IAB" xml:lang="en" number="9998" tocInclude="true" sortRefs="true" symRefs="true" prepTime="2026-06-15T23:55:06" indexInclude="true" scripts="Common,Latin" tocDepth="3">
  <link href="https://datatracker.ietf.org/doc/draft-iab-agews-report-03" rel="prev"/>
  <link href="https://dx.doi.org/10.17487/rfc9998" rel="alternate"/>
  <link href="urn:issn:2070-1721" rel="alternate"/>
  <front>
    <title abbrev="AGEWS Report">Report from the IAB/W3C Workshop on Age-Based Restrictions on Content Access</title>
    <seriesInfo name="RFC" value="9998" stream="IAB"/>
    <author initials="M." surname="Nottingham" fullname="Mark Nottingham">
      <organization showOnFrontPage="true"/>
      <address>
        <email>mnot@mnot.net</email>
      </address>
    </author>
    <author initials="M." surname="Thomson" fullname="Martin Thomson">
      <organization showOnFrontPage="true"/>
      <address>
        <email>mt@lowentropy.net</email>
      </address>
    </author>
    <date month="06" year="2026"/>
    <keyword>IAB workshop</keyword>
    <keyword>age gate</keyword>
    <abstract pn="section-abstract">
      <t indent="0" pn="section-abstract-1">The Workshop on Age-Based Restrictions on Content Access was convened by the Internet Architecture Board (IAB) and World Wide Web Consortium (W3C) in October 2025. This report summarizes the significant points of discussion and identifies topics that may warrant further consideration and work.</t>
      <t indent="0" pn="section-abstract-2">Note that this document is a report on the proceedings of the workshop. The views and positions documented in this report are those of the workshop participants and do not necessarily reflect IAB or W3C views and positions.</t>
    </abstract>
    <boilerplate>
      <section anchor="status-of-memo" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.1">
        <name slugifiedName="name-status-of-this-memo">Status of This Memo</name>
        <t indent="0" pn="section-boilerplate.1-1">
            This document is not an Internet Standards Track specification; it is
            published for informational purposes.  
        </t>
        <t indent="0" pn="section-boilerplate.1-2">
            This document is a product of the Internet Architecture Board
            (IAB) and represents information that the IAB has deemed valuable
            to provide for permanent record.  It represents the consensus of the Internet
            Architecture Board (IAB).  Documents approved for publication
            by the IAB are not candidates for any level of Internet Standard; see
            Section 2 of RFC 7841.
        </t>
        <t indent="0" pn="section-boilerplate.1-3">
            Information about the current status of this document, any
            errata, and how to provide feedback on it may be obtained at
            <eref target="https://www.rfc-editor.org/info/rfc9998" brackets="none"/>.
        </t>
      </section>
      <section anchor="copyright" numbered="false" removeInRFC="false" toc="exclude" pn="section-boilerplate.2">
        <name slugifiedName="name-copyright-notice">Copyright Notice</name>
        <t indent="0" pn="section-boilerplate.2-1">
            Copyright (c) 2026 IETF Trust and the persons identified as the
            document authors. All rights reserved.
        </t>
        <t indent="0" pn="section-boilerplate.2-2">
            This document is subject to BCP 78 and the IETF Trust's Legal
            Provisions Relating to IETF Documents
            (<eref target="https://trustee.ietf.org/license-info" brackets="none"/>) in effect on the date of
            publication of this document. Please review these documents
            carefully, as they describe your rights and restrictions with
            respect to this document.
        </t>
      </section>
    </boilerplate>
    <toc>
      <section anchor="toc" numbered="false" removeInRFC="false" toc="exclude" pn="section-toc.1">
        <name slugifiedName="name-table-of-contents">Table of Contents</name>
        <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1">
          <li pn="section-toc.1-1.1">
            <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.1"><xref derivedContent="1" format="counter" sectionFormat="of" target="section-1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-introduction">Introduction</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.1.2">
              <li pn="section-toc.1-1.1.2.1">
                <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.2.1.1"><xref derivedContent="1.1" format="counter" sectionFormat="of" target="section-1.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-views-expressed-in-this-rep">Views Expressed in This Report</xref></t>
              </li>
              <li pn="section-toc.1-1.1.2.2">
                <t indent="0" keepWithNext="true" pn="section-toc.1-1.1.2.2.1"><xref derivedContent="1.2" format="counter" sectionFormat="of" target="section-1.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-chatham-house-rule">Chatham House Rule</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.2">
            <t indent="0" pn="section-toc.1-1.2.1"><xref derivedContent="2" format="counter" sectionFormat="of" target="section-2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-overview-of-the-workshop">Overview of the Workshop</xref></t>
          </li>
          <li pn="section-toc.1-1.3">
            <t indent="0" pn="section-toc.1-1.3.1"><xref derivedContent="3" format="counter" sectionFormat="of" target="section-3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-key-takeaways">Key Takeaways</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.3.2">
              <li pn="section-toc.1-1.3.2.1">
                <t indent="0" pn="section-toc.1-1.3.2.1.1"><xref derivedContent="3.1" format="counter" sectionFormat="of" target="section-3.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-there-is-a-need-for-cross-c">There Is a Need for Cross-Cutting Collaboration</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.2">
                <t indent="0" pn="section-toc.1-1.3.2.2.1"><xref derivedContent="3.2" format="counter" sectionFormat="of" target="section-3.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-identifying-the-roles-invol">Identifying the Roles Involved Is Important</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.3">
                <t indent="0" pn="section-toc.1-1.3.2.3.1"><xref derivedContent="3.3" format="counter" sectionFormat="of" target="section-3.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-a-common-vocabulary-is-nece">A Common Vocabulary Is Necessary</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.4">
                <t indent="0" pn="section-toc.1-1.3.2.4.1"><xref derivedContent="3.4" format="counter" sectionFormat="of" target="section-3.4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-privacy-and-trust-expectati">Privacy and Trust Expectations Need Further Discussion</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.5">
                <t indent="0" pn="section-toc.1-1.3.2.5.1"><xref derivedContent="3.5" format="counter" sectionFormat="of" target="section-3.5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-more-than-one-approach-will">More Than One Approach Will Be Required</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.6">
                <t indent="0" pn="section-toc.1-1.3.2.6.1"><xref derivedContent="3.6" format="counter" sectionFormat="of" target="section-3.6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-mapping-the-risks-for-archi">Mapping the Risks for Architectures Is a Useful Next Step</xref></t>
              </li>
              <li pn="section-toc.1-1.3.2.7">
                <t indent="0" pn="section-toc.1-1.3.2.7.1"><xref derivedContent="3.7" format="counter" sectionFormat="of" target="section-3.7"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-safety-requires-more-than-a">Safety Requires More Than a Technical Solution</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.4">
            <t indent="0" pn="section-toc.1-1.4.1"><xref derivedContent="4" format="counter" sectionFormat="of" target="section-4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-security-considerations">Security Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.5">
            <t indent="0" pn="section-toc.1-1.5.1"><xref derivedContent="5" format="counter" sectionFormat="of" target="section-5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-iana-considerations">IANA Considerations</xref></t>
          </li>
          <li pn="section-toc.1-1.6">
            <t indent="0" pn="section-toc.1-1.6.1"><xref derivedContent="6" format="counter" sectionFormat="of" target="section-6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-informative-references">Informative References</xref></t>
          </li>
          <li pn="section-toc.1-1.7">
            <t indent="0" pn="section-toc.1-1.7.1"><xref derivedContent="Appendix A" format="default" sectionFormat="of" target="section-appendix.a"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-workshop-agenda">Workshop Agenda</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.7.2">
              <li pn="section-toc.1-1.7.2.1">
                <t indent="0" pn="section-toc.1-1.7.2.1.1"><xref derivedContent="A.1" format="counter" sectionFormat="of" target="section-appendix.a.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-introduction">Topic: Introduction</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.2">
                <t indent="0" pn="section-toc.1-1.7.2.2.1"><xref derivedContent="A.2" format="counter" sectionFormat="of" target="section-appendix.a.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-setting-the-scene">Topic: Setting the Scene</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.3">
                <t indent="0" pn="section-toc.1-1.7.2.3.1"><xref derivedContent="A.3" format="counter" sectionFormat="of" target="section-appendix.a.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-guiding-principles">Topic: Guiding Principles</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.4">
                <t indent="0" pn="section-toc.1-1.7.2.4.1"><xref derivedContent="A.4" format="counter" sectionFormat="of" target="section-appendix.a.4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-potential-impacts">Topic: Potential Impacts</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.5">
                <t indent="0" pn="section-toc.1-1.7.2.5.1"><xref derivedContent="A.5" format="counter" sectionFormat="of" target="section-appendix.a.5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-where-enforcement-hap">Topic: Where Enforcement Happens</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.6">
                <t indent="0" pn="section-toc.1-1.7.2.6.1"><xref derivedContent="A.6" format="counter" sectionFormat="of" target="section-appendix.a.6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-topic-available-techniques">Topic: Available Techniques</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.7">
                <t indent="0" pn="section-toc.1-1.7.2.7.1"><xref derivedContent="A.7" format="counter" sectionFormat="of" target="section-appendix.a.7"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-discussion">Discussion</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.8">
                <t indent="0" pn="section-toc.1-1.7.2.8.1"><xref derivedContent="A.8" format="counter" sectionFormat="of" target="section-appendix.a.8"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-summary-and-reflection">Summary and Reflection</xref></t>
              </li>
              <li pn="section-toc.1-1.7.2.9">
                <t indent="0" pn="section-toc.1-1.7.2.9.1"><xref derivedContent="A.9" format="counter" sectionFormat="of" target="section-appendix.a.9"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-outcomes">Outcomes</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.8">
            <t indent="0" pn="section-toc.1-1.8.1"><xref derivedContent="Appendix B" format="default" sectionFormat="of" target="section-appendix.b"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-workshop-participants">Workshop Participants</xref></t>
          </li>
          <li pn="section-toc.1-1.9">
            <t indent="0" pn="section-toc.1-1.9.1"><xref derivedContent="Appendix C" format="default" sectionFormat="of" target="section-appendix.c"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-potential-impacts">Potential Impacts</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.9.2">
              <li pn="section-toc.1-1.9.2.1">
                <t indent="0" pn="section-toc.1-1.9.2.1.1"><xref derivedContent="C.1" format="counter" sectionFormat="of" target="section-appendix.c.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-impact-on-children">Impact on Children</xref></t>
              </li>
              <li pn="section-toc.1-1.9.2.2">
                <t indent="0" pn="section-toc.1-1.9.2.2.1"><xref derivedContent="C.2" format="counter" sectionFormat="of" target="section-appendix.c.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-ecosystem-impact">Ecosystem Impact</xref></t>
              </li>
              <li pn="section-toc.1-1.9.2.3">
                <t indent="0" pn="section-toc.1-1.9.2.3.1"><xref derivedContent="C.3" format="counter" sectionFormat="of" target="section-appendix.c.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-implementation-and-deployme">Implementation and Deployment Difficulties</xref></t>
              </li>
              <li pn="section-toc.1-1.9.2.4">
                <t indent="0" pn="section-toc.1-1.9.2.4.1"><xref derivedContent="C.4" format="counter" sectionFormat="of" target="section-appendix.c.4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-security-and-privacy">Security and Privacy</xref></t>
              </li>
              <li pn="section-toc.1-1.9.2.5">
                <t indent="0" pn="section-toc.1-1.9.2.5.1"><xref derivedContent="C.5" format="counter" sectionFormat="of" target="section-appendix.c.5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-equity">Equity</xref></t>
              </li>
              <li pn="section-toc.1-1.9.2.6">
                <t indent="0" pn="section-toc.1-1.9.2.6.1"><xref derivedContent="C.6" format="counter" sectionFormat="of" target="section-appendix.c.6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-societal-impacts">Societal Impacts</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.10">
            <t indent="0" pn="section-toc.1-1.10.1"><xref derivedContent="Appendix D" format="default" sectionFormat="of" target="section-appendix.d"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-desirable-and-essential-pro">Desirable and Essential Properties of a Solution</xref></t>
            <ul bare="true" empty="true" indent="2" spacing="compact" pn="section-toc.1-1.10.2">
              <li pn="section-toc.1-1.10.2.1">
                <t indent="0" pn="section-toc.1-1.10.2.1.1"><xref derivedContent="D.1" format="counter" sectionFormat="of" target="section-appendix.d.1"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-functional">Functional</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.2">
                <t indent="0" pn="section-toc.1-1.10.2.2.1"><xref derivedContent="D.2" format="counter" sectionFormat="of" target="section-appendix.d.2"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-accountability-and-transpar">Accountability and Transparency</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.3">
                <t indent="0" pn="section-toc.1-1.10.2.3.1"><xref derivedContent="D.3" format="counter" sectionFormat="of" target="section-appendix.d.3"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-privacy-and-security">Privacy and Security</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.4">
                <t indent="0" pn="section-toc.1-1.10.2.4.1"><xref derivedContent="D.4" format="counter" sectionFormat="of" target="section-appendix.d.4"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-equity-2">Equity</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.5">
                <t indent="0" pn="section-toc.1-1.10.2.5.1"><xref derivedContent="D.5" format="counter" sectionFormat="of" target="section-appendix.d.5"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-jurisdiction-and-geopolitic">Jurisdiction and Geopolitical</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.6">
                <t indent="0" pn="section-toc.1-1.10.2.6.1"><xref derivedContent="D.6" format="counter" sectionFormat="of" target="section-appendix.d.6"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-usability">Usability</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.7">
                <t indent="0" pn="section-toc.1-1.10.2.7.1"><xref derivedContent="D.7" format="counter" sectionFormat="of" target="section-appendix.d.7"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-implementation-and-deploymen">Implementation and Deployment</xref></t>
              </li>
              <li pn="section-toc.1-1.10.2.8">
                <t indent="0" pn="section-toc.1-1.10.2.8.1"><xref derivedContent="D.8" format="counter" sectionFormat="of" target="section-appendix.d.8"/>.  <xref derivedContent="" format="title" sectionFormat="of" target="name-general-other">General/Other</xref></t>
              </li>
            </ul>
          </li>
          <li pn="section-toc.1-1.11">
            <t indent="0" pn="section-toc.1-1.11.1"><xref derivedContent="" format="none" sectionFormat="of" target="section-appendix.e"/><xref derivedContent="" format="title" sectionFormat="of" target="name-iab-members-at-the-time-of-">IAB Members at the Time of Approval</xref></t>
          </li>
          <li pn="section-toc.1-1.12">
            <t indent="0" pn="section-toc.1-1.12.1"><xref derivedContent="" format="none" sectionFormat="of" target="section-appendix.f"/><xref derivedContent="" format="title" sectionFormat="of" target="name-authors-addresses">Authors' Addresses</xref></t>
          </li>
        </ul>
      </section>
    </toc>
  </front>
  <middle>
    <section anchor="introduction" numbered="true" removeInRFC="false" toc="include" pn="section-1">
      <name slugifiedName="name-introduction">Introduction</name>
      <t indent="0" pn="section-1-1">Regulators and legislators around the world are increasingly restricting what can be made available to young people on the Internet in an effort to reduce the potential for harm.</t>
      <t indent="0" pn="section-1-2">In October 2025, the Internet Architecture Board (IAB) and the World Wide Web Consortium (W3C) convened the Workshop on Age-Based Restrictions on Content Access. This workshop brought together technologists, civil-society advocates, business interests, and government stakeholders to discuss the nuances of the introduction of such measures.</t>
      <t indent="0" pn="section-1-3">The primary focus was "to perform a thorough examination of the technical and architectural choices that are involved in solutions for age-based restrictions on access to content" with a goal of "build[ing] a shared understanding of the properties of various proposed approaches".</t>
      <t indent="0" pn="section-1-4">See the workshop announcement <xref target="ANNOUNCE" format="default" sectionFormat="of" derivedContent="ANNOUNCE"/> for details; papers and presentation materials are linked from the announcement. This report summarizes the proceedings of the workshop.</t>
      <section anchor="views-expressed-in-this-report" numbered="true" removeInRFC="false" toc="include" pn="section-1.1">
        <name slugifiedName="name-views-expressed-in-this-rep">Views Expressed in This Report</name>
        <t indent="0" pn="section-1.1-1">This document is a report on the proceedings of the workshop. The views and positions documented in this report were expressed during the workshop by participants and do not necessarily reflect the views or positions of the IAB or W3C, nor those of all participants.</t>
        <t indent="0" pn="section-1.1-2">Furthermore, the content of the report comes from presentations given by workshop participants and notes taken during the discussions, without interpretation or validation. Thus, the content of this report follows the flow and dialogue of the workshop but does not attempt to capture a consensus.</t>
      </section>
      <section anchor="chatham-house-rule" numbered="true" removeInRFC="false" toc="include" pn="section-1.2">
        <name slugifiedName="name-chatham-house-rule">Chatham House Rule</name>
        <t indent="0" pn="section-1.2-1">Participants agreed to conduct the workshop under the Chatham House Rule <xref target="CHATHAM-HOUSE" format="default" sectionFormat="of" derivedContent="CHATHAM-HOUSE"/>, so this report does not attribute statements to individuals or organizations without express permission.  Most submissions to the workshop were public and thus attributable; they are used here to provide substance and context.</t>
        <t indent="0" pn="section-1.2-2"><xref target="participants" format="default" sectionFormat="of" derivedContent="Appendix B"/> lists the workshop participants, unless they requested that this information be withheld.</t>
      </section>
    </section>
    <section anchor="overview-of-the-workshop" numbered="true" removeInRFC="false" toc="include" pn="section-2">
      <name slugifiedName="name-overview-of-the-workshop">Overview of the Workshop</name>
      <t indent="0" pn="section-2-1">The IAB/W3C Workshop on Age-Based Restrictions on Content Access brought together a diverse group of participants from technical, policy, regulatory, and research communities to examine how the Internet might accommodate demands for age-based access controls. Over three days, discussions traversed the intersection of technology, governance, human rights, and social expectations, with a recurring emphasis on privacy, accountability, and the preservation of the open architecture of the Internet.</t>
      <t indent="0" pn="section-2-2">The workshop began with a framing session that emphasized the Internet's original design as a universal, non-segmented space. Participants observed that the Web does not innately distinguish between adult and child users, and that governments are creating regulatory environments that shift responsibility from parents and individuals to service providers. The scope of discussion was tightly defined: not the morality or policy of age restrictions, but the technical, architectural, and human-rights implications of enforcing them. The challenge, many participants agreed, lay in building mechanisms that are accurate, respect privacy, maintain global interoperability, and avoid creating infrastructure that could be repurposed for censorship or surveillance.</t>
      <t indent="0" pn="section-2-3">Early exchanges focused on terminology and scope: whether "age verification" should be understood narrowly as identity checking or more broadly as "age assurance".  The conversation also touched on the diversity of cultural expectations about parental authority and the variety of legal frameworks emerging across jurisdictions. Some participants warned of "slippery slope" effects, where mechanisms designed for age checks might evolve into tools for broader identity enforcement. Several noted that while liability drives many policy decisions, technical design should aim to minimize harm and avoid over-centralization. The question of who bears responsibility for child safety -- platforms, regulators, or device manufacturers -- surfaced repeatedly.</t>
      <t indent="0" pn="section-2-4">Human-rights principles were foregrounded as a basis for evaluation. Privacy was discussed not only in terms of data protection law (including techniques like minimization) but also as protection from unwanted exposure or interaction. Freedom of expression and opinion was considered, particularly how both adults and children have rights to communicate, access information, and associate free from the chilling effects of surveillance or discrimination. The group revisited long-standing Internet design tenets, such as decentralization and the end-to-end principle, asking how they should inform modern architectures that could easily drift toward central control. Some argued that successful systems must remain open, interoperable, and reversible; others cautioned that any solution -- even a well-intentioned one -- would inevitably reshape the Internet's social and economic balance.</t>
      <t indent="0" pn="section-2-5">Technical sessions explored a spectrum of enforcement models: service-based, network-based, and device-based. Service-based enforcement systems place a compliance burden on websites, risking fragmentation and user fatigue from repeated verification flows. Network-based filtering -- already common in some jurisdictions -- offers broad coverage but limited accuracy and significant privacy trade-offs. Device-based enforcement, in which operating systems mediate access based on a one-time verification, were praised for their potential usability and consistency but criticized for potential concentration of power among major vendors. Many participants noted that a pluralistic approach is more likely to be successful, recognizing that no single architecture can meet all requirements equally across jurisdictions.</t>
      <t indent="0" pn="section-2-6">Privacy-enhancing technologies (PETs) such as anonymous credentials and zero-knowledge proofs (ZKPs) were discussed as promising, though not necessarily sufficient, tools. In particular, PETs don't address all privacy concerns and, likewise, don't address wider issues around access to underlying sources of truth. Furthermore, some participants cautioned that PETs cannot prevent circumvention or censorship and are relatively untested.  They also cautioned that open-sourcing code does not automatically make systems trustworthy. A recurring concern was that while credential-based verification may work well in countries with unified ID systems, it risks excluding people without access to such credentials and entrenching inequalities.</t>
      <t indent="0" pn="section-2-7">Discussions on parental controls and network operator roles highlighted practical tensions between effectiveness, usability, and user rights. Although some participants saw value in layered approaches combining device, service, and network measures, others noted the high complexity and low adoption of parental-control tools even where available. The workshop also revisited the ethical dimension: whether designing better tools might unintentionally legitimize overbroad or intrusive regulation.</t>
      <t indent="0" pn="section-2-8">By the third day, participants reflected on the need for collaboration across disciplines and institutions. Many acknowledged that while complete solutions are unlikely in the short term, articulating shared vocabulary, architectural roles, and evaluation properties was an essential foundation. There was broad agreement that future work should map risks against possible architectures, document trade-offs in neutral terms, and communicate clearly with policymakers to prevent outcomes that could undermine Internet openness.</t>
      <t indent="0" pn="section-2-9">The meeting closed with reflections on what process might be followed to take proposed solutions through a standards process. Both IETF and W3C representatives outlined how exploratory work might proceed within their respective frameworks, stressing that standardization would require consensus, open participation, and time.</t>
      <t indent="0" pn="section-2-10">While a workshop is not able to provide specific standards proposals or take positions on the advisability of regulatory proposals, it was suggested that leadership bodies, including the IAB and the Technical Architecture Group (TAG), could make statements to that effect.</t>
      <t indent="0" pn="section-2-11">While the current status quo -- where age restrictions are piecemeal, opaque, and often privacy-eroding -- was unsatisfactory to most participants, many cautioned that hasty solutions could entrench worse problems. This led to growing recognition that protecting children online must not come at the expense of the Internet's foundational freedoms and that sustained, multi-stakeholder collaboration is the only viable path forward.</t>
    </section>
    <section anchor="key-takeaways" numbered="true" removeInRFC="false" toc="include" pn="section-3">
      <name slugifiedName="name-key-takeaways">Key Takeaways</name>
      <t indent="0" pn="section-3-1">This section highlights aspects of discussion at the workshop that appeared to be most impactful.</t>
      <section anchor="collaboration" numbered="true" removeInRFC="false" toc="include" pn="section-3.1">
        <name slugifiedName="name-there-is-a-need-for-cross-c">There Is a Need for Cross-Cutting Collaboration</name>
        <t indent="0" pn="section-3.1-1">Many participants remarked that the workshop allowed them to appreciate perspectives that they had not fully considered previously. Although several substantial efforts have included industry, civil society, government, and technologists, collaboration across all stakeholders appears to be rare.</t>
        <t indent="0" pn="section-3.1-2">This was especially evident when considering the involvement of the technical community. Although there have been a number of consultations by governments and other bodies, involvement of the technical community is often limited to participation by the policy representatives of technology companies. This can lead to an underappreciation of the architectural impact and related harm of the design decisions made.</t>
        <t indent="0" pn="section-3.1-3">Architectures effective for the goals and less likely to have profound harmful consequences may require the cooperation of multiple actors fulfilling different roles (see <xref target="roles" format="default" sectionFormat="of" derivedContent="Section 3.2"/>). To that end, standardization may be especially important for interoperable, collaborative development of architectures involving both servers and clients.</t>
        <t indent="0" pn="section-3.1-4">Some participants also noted that approaches where liability rests only on one party -- for example, a content or platform provider -- are unlikely to lead to the desired results because this creates disincentives for the cooperation that is necessary for meaningful reduction of harm. An approach that considers the roles of the young, their parents, device manufacturers, operating system vendors, content providers, and society overall was believed to be more likely to succeed.</t>
      </section>
      <section anchor="roles" numbered="true" removeInRFC="false" toc="include" pn="section-3.2">
        <name slugifiedName="name-identifying-the-roles-invol">Identifying the Roles Involved Is Important</name>
        <t indent="0" pn="section-3.2-1">One of the more substantive discussions on architecture involved presentations on the functional roles involved in any system <xref target="HANSON" format="default" sectionFormat="of" derivedContent="HANSON"/>.</t>
        <t indent="0" pn="section-3.2-2">Four key roles were identified:</t>
        <dl indent="3" newline="false" spacing="normal" pn="section-3.2-3">
          <dt pn="section-3.2-3.1">Verifier:</dt>
          <dd pn="section-3.2-3.2">
            <t indent="0" pn="section-3.2-3.2.1">The verifier role determines whether a person falls into a target age range.</t>
          </dd>
          <dt pn="section-3.2-3.3">Enforcer:</dt>
          <dd pn="section-3.2-3.4">
            <t indent="0" pn="section-3.2-3.4.1">The enforcer is responsible for ensuring that a person who does not satisfy the verifier is unable to access age-restricted content or services.</t>
          </dd>
          <dt pn="section-3.2-3.5">Policy selector:</dt>
          <dd pn="section-3.2-3.6">
            <t indent="0" pn="section-3.2-3.6.1">The policy selector is responsible for determining which policies should apply to the user, based on their jurisdiction, status, or preferences.</t>
          </dd>
          <dt pn="section-3.2-3.7">Rater:</dt>
          <dd pn="section-3.2-3.8">
            <t indent="0" pn="section-3.2-3.8.1">The rater is responsible for determining whether content or services require age restrictions and the age ranges that apply.</t>
          </dd>
        </dl>
        <t indent="0" pn="section-3.2-4">In addition, it was noted that ratings and laws are often limited by geography or jurisdiction, so it is often necessary for services to first identify the applicable jurisdiction. It was generally accepted that this function often uses IP geolocation mappings, despite acknowledged limitations around accuracy and susceptibility, to circumvent using VPNs.</t>
      </section>
      <section anchor="a-common-vocabulary-is-necessary" numbered="true" removeInRFC="false" toc="include" pn="section-3.3">
        <name slugifiedName="name-a-common-vocabulary-is-nece">A Common Vocabulary Is Necessary</name>
        <t indent="0" pn="section-3.3-1">Early discussions highlighted how not all participants used the same terminology when referring to different activities or functions. There was a recognition of the value of shared language, and some participants pointed to <xref target="ISO-IEC-27566-1" format="default" sectionFormat="of" derivedContent="ISO-IEC-27566-1"/>. Definitions of key terms, as discussed by participants, include:</t>
        <dl indent="3" newline="false" spacing="normal" pn="section-3.3-2">
          <dt pn="section-3.3-2.1">Age assurance:</dt>
          <dd pn="section-3.3-2.2">
            <t indent="0" pn="section-3.3-2.2.1">Age assurance is an umbrella term for technology that provides some entity with information about the age of a person. This is understood to encompass multiple classes of specific methods, including age verification, age estimation, and age inference. Age assurance does not need to result in a specific age; age ranges are often preferred as they can have better privacy properties.</t>
          </dd>
          <dt pn="section-3.3-2.3">Age verification:</dt>
          <dd pn="section-3.3-2.4">
            <t indent="0" pn="section-3.3-2.4.1">Age verification refers to gaining high assurance that a person is within a given age range. Strong assurances are often tied to official or governmental documentation, so age verification can involve the use of government-issued digital credentials.</t>
          </dd>
          <dt pn="section-3.3-2.5">Age estimation:</dt>
          <dd pn="section-3.3-2.6">
            <t indent="0" pn="section-3.3-2.6.1">Age estimation uses statistical processes that process physical or behavioral characteristics of a person to produce a probabilistic value for how old someone is or whether their age is in a target range. A variety of techniques are used, the most common being facial age estimation, which uses machine learning models to estimate how old a person is based on still or moving images of their face.</t>
          </dd>
          <dt pn="section-3.3-2.7">Age inference:</dt>
          <dd pn="section-3.3-2.8">
            <t indent="0" pn="section-3.3-2.8.1">Age inference draws on data sources to determine whether a person fits a given age range. This method can require identification information, such as an email address or phone number, to find relevant records. For example, evidence of online activity prior to a certain date in the past might support the view that a person is older than a target threshold.</t>
          </dd>
          <dt pn="section-3.3-2.9">Age gating:</dt>
          <dd pn="section-3.3-2.10">
            <t indent="0" pn="section-3.3-2.10.1">Age gating is the process of restricting access to something based on the age of the person requesting access.</t>
          </dd>
        </dl>
        <t indent="0" pn="section-3.3-3">Relating these functions to the roles described in <xref target="roles" format="default" sectionFormat="of" derivedContent="Section 3.2"/>, all age assurance types fit the "verifier" role, whereas age gating applies to the "enforcer" role.</t>
      </section>
      <section anchor="trust" numbered="true" removeInRFC="false" toc="include" pn="section-3.4">
        <name slugifiedName="name-privacy-and-trust-expectati">Privacy and Trust Expectations Need Further Discussion</name>
        <t indent="0" pn="section-3.4-1">Privacy was a recurrent theme at the workshop, but it was clear that there are multiple considerations at play when talking about it. The question of privacy was often caught up in discussions of trust, where approaches each depend on different sorts of trust between the different actors.</t>
        <t indent="0" pn="section-3.4-2">Participants identified privacy as important to maintaining trust in any system that involves age assurance or age gating.</t>
        <t indent="0" pn="section-3.4-3">Where private information is used by the actors in a proposed architecture, those actors might need to be trusted to handle that private information responsibly. In that approach, the importance of different safeguards on personal information, such as the prompt disposal of any personal information -- a practice that many age verification providers promise -- becomes a core part of what might allow people to trust that system.</t>
        <t indent="0" pn="section-3.4-4">Several people observed that the sort of trust that is asked from people might not correspond with the role that certain entities play in people's lives. This will depend on context, where "adult" content providers generally serve anonymous users, whereas social media often already has a lot of personal information on users.</t>
        <t indent="0" pn="section-3.4-5">In either case, users might have no prior knowledge of -- or trust in -- providers that are contracted to provide age assurance functions. It was observed that one likely consequence of some arrangements is to train people to become more trusting of strange sites that ask for personal information.</t>
        <t indent="0" pn="section-3.4-6">Alternatively, it might be that trust in the system is not vested in actors, but in the system as a whole. This is possible if no information is made available to different actors, removing the need to trust their handling of private information. For this to be achievable, the use of ZKPs or similar cryptographic techniques was seen as a way to limit what each entity learns. However, some participants noted that these techniques do not address circumvention or censorship risks, still introduce new information into the ecosystem, and may concentrate trust in particular software implementations.</t>
        <t indent="0" pn="section-3.4-7">Other aspects of trust were considered equally important from different perspectives.  Services that rely on an independent age assurance provider need to trust that the provider makes an accurate determination of age, at least to the extent that they might be held liable in law.  They also need to trust that the service respects privacy, lest the use of a low-quality provider could create other forms of liability or drive away potential customers.</t>
      </section>
      <section anchor="waterfall" numbered="true" removeInRFC="false" toc="include" pn="section-3.5">
        <name slugifiedName="name-more-than-one-approach-will">More Than One Approach Will Be Required</name>
        <t indent="0" pn="section-3.5-1">A recurrent theme in discussion was the insufficiency of any particular age assurance technique in ensuring that people are not unjustifiably excluded. All age assurance methods discussed fail to correctly classify some subset of people:</t>
        <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-3.5-2">
          <li pn="section-3.5-2.1">
            <t indent="0" pn="section-3.5-2.1.1">Age verification that depends on government-issued credentials will fail when people do not hold accepted credentials. This includes people who do not hold credentials and those who hold credentials that are not recognized.</t>
          </li>
          <li pn="section-3.5-2.2">
            <t indent="0" pn="section-3.5-2.2.1">Age estimation produces probabilistic information about age that can be wrong by some number of years, potentially excluding people near threshold ages. This manifests as both false acceptance (people who are outside the target age range being accepted) and false rejection (people who are in the target age range being rejected). Where there is a goal of minimizing the false acceptance rate, that increases the number of false rejections.</t>
          </li>
          <li pn="section-3.5-2.3">
            <t indent="0" pn="section-3.5-2.3.1">Age inference techniques can fail due to lack of information.</t>
          </li>
        </ul>
        <t indent="0" pn="section-3.5-3">Discussion often came back to an approach that is increasingly recommended for use in age verification, where multiple methods are applied in series. Checks with lower friction -- those that require less active participation from people -- or that are less invasive of privacy are attempted first. Successive checks are only used when a definitive result cannot be achieved.</t>
        <t indent="0" pn="section-3.5-4">Some participants noted that inconsistent friction and invasiveness create a different kind of discrimination, one that can exacerbate existing adverse discrimination. For example, the accuracy of age estimation for people with African ancestry is often significantly lower than for those with European ancestry <xref target="FATE" format="default" sectionFormat="of" derivedContent="FATE"/>. This is attributed to the models used being trained and validated using datasets that have less coverage of some groups. People who are affected by this bias are more likely to need to engage with more invasive methods.</t>
        <t indent="0" pn="section-3.5-5">One consequence of having multiple imperfect techniques is the need to recognize that any system will be imperfect. That creates several tensions:</t>
        <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-3.5-6">
          <li pn="section-3.5-6.1">
            <t indent="0" pn="section-3.5-6.1.1">Some people will never be able to satisfy age assurance checks and will therefore be excluded by strict assurance mandates. Here, discussions acknowledged that purely technical systems are likely inadequate.</t>
          </li>
          <li pn="section-3.5-6.2">
            <t indent="0" pn="section-3.5-6.2.1">Some people who should be blocked from accessing content or services will find ways to circumvent restrictions. In this context, the term "advanced persistent teenager" was recognized as characterizing the nature of the "adversary": individuals who are considered too young to access content, but who are highly motivated, technically sophisticated, and have time to spare.</t>
          </li>
          <li pn="section-3.5-6.3">
            <t indent="0" pn="section-3.5-6.3.1">Offering more choices to people can improve privacy because they get to choose the method that suits them. However, when a chosen method fails, having to engage with additional methods has a higher privacy cost.</t>
          </li>
        </ul>
        <t indent="0" pn="section-3.5-7">Some participants argued that accepting these risks is necessary in order to gain any of the benefits that age-based restrictions might confer. Other participants were unwilling to accept potential impositions on individual rights in light of the insufficiency of restrictions in providing meaningful protection; see <xref target="holistic" format="default" sectionFormat="of" derivedContent="Section 3.7"/>.</t>
      </section>
      <section anchor="risks" numbered="true" removeInRFC="false" toc="include" pn="section-3.6">
        <name slugifiedName="name-mapping-the-risks-for-archi">Mapping the Risks for Architectures Is a Useful Next Step</name>
        <t indent="0" pn="section-3.6-1">How the identified roles (see <xref target="roles" format="default" sectionFormat="of" derivedContent="Section 3.2"/>) are arranged into architectures was some of the more substantive discussion. <xref target="JACKSON" format="default" sectionFormat="of" derivedContent="JACKSON"/> describes some of the alternatives, along with some of the implications that arise from different arrangements.</t>
        <t indent="0" pn="section-3.6-2">Throughout this discussion, it was acknowledged that active deployments tend to fall into a common pattern, where content providers are required to age-gate access and contract a third party to interpose that service. Several participants noted that this is a somewhat natural consequence of some of the constraints that actors are subject to.  <xref target="f-typical" format="default" sectionFormat="of" derivedContent="Figure 1"/> shows the typical deployment model for age-gated content and services, along with the roles from <xref target="roles" format="default" sectionFormat="of" derivedContent="Section 3.2"/>.</t>
        <figure anchor="f-typical" align="left" suppress-title="false" pn="figure-1">
          <name slugifiedName="name-typical-deployment-model">Typical Deployment Model</name>
          <artset pn="section-3.6-3.1">
            <artwork type="svg" align="left" pn="section-3.6-3.1.1"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="352" width="552" viewBox="0 0 552 352" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 32,32 L 32,80" fill="none" stroke="black"/>
                <path d="M 80,48 L 80,112" fill="none" stroke="black"/>
                <path d="M 128,120 L 128,304" fill="none" stroke="black"/>
                <path d="M 160,120 L 160,176" fill="none" stroke="black"/>
                <path d="M 184,48 L 184,112" fill="none" stroke="black"/>
                <path d="M 328,112 L 328,144" fill="none" stroke="black"/>
                <path d="M 328,240 L 328,272" fill="none" stroke="black"/>
                <path d="M 368,48 L 368,112" fill="none" stroke="black"/>
                <path d="M 368,144 L 368,240" fill="none" stroke="black"/>
                <path d="M 368,272 L 368,336" fill="none" stroke="black"/>
                <path d="M 464,48 L 464,112" fill="none" stroke="black"/>
                <path d="M 464,144 L 464,240" fill="none" stroke="black"/>
                <path d="M 464,272 L 464,336" fill="none" stroke="black"/>
                <path d="M 8,48 L 56,48" fill="none" stroke="black"/>
                <path d="M 80,48 L 184,48" fill="none" stroke="black"/>
                <path d="M 368,48 L 464,48" fill="none" stroke="black"/>
                <path d="M 192,80 L 360,80" fill="none" stroke="black"/>
                <path d="M 344,96 L 360,96" fill="none" stroke="black"/>
                <path d="M 80,112 L 184,112" fill="none" stroke="black"/>
                <path d="M 368,112 L 464,112" fill="none" stroke="black"/>
                <path d="M 368,144 L 464,144" fill="none" stroke="black"/>
                <path d="M 344,160 L 360,160" fill="none" stroke="black"/>
                <path d="M 176,192 L 360,192" fill="none" stroke="black"/>
                <path d="M 344,224 L 360,224" fill="none" stroke="black"/>
                <path d="M 368,240 L 464,240" fill="none" stroke="black"/>
                <path d="M 368,272 L 464,272" fill="none" stroke="black"/>
                <path d="M 344,288 L 360,288" fill="none" stroke="black"/>
                <path d="M 144,320 L 360,320" fill="none" stroke="black"/>
                <path d="M 368,336 L 464,336" fill="none" stroke="black"/>
                <path d="M 32,80 L 48,112" fill="none" stroke="black"/>
                <path d="M 16,112 L 32,80" fill="none" stroke="black"/>
                <path d="M 344,96 C 335.16936,96 328,103.16936 328,112" fill="none" stroke="black"/>
                <path d="M 344,160 C 335.16936,160 328,152.83064 328,144" fill="none" stroke="black"/>
                <path d="M 176,192 C 167.16936,192 160,184.83064 160,176" fill="none" stroke="black"/>
                <path d="M 344,224 C 335.16936,224 328,231.16936 328,240" fill="none" stroke="black"/>
                <path d="M 344,288 C 335.16936,288 328,280.83064 328,272" fill="none" stroke="black"/>
                <path d="M 144,320 C 135.16936,320 128,312.83064 128,304" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="368,320 356,314.4 356,325.6" fill="black" transform="rotate(0,360,320)"/>
                <polygon class="arrowhead" points="368,288 356,282.4 356,293.6" fill="black" transform="rotate(0,360,288)"/>
                <polygon class="arrowhead" points="368,192 356,186.4 356,197.6" fill="black" transform="rotate(0,360,192)"/>
                <polygon class="arrowhead" points="368,160 356,154.4 356,165.6" fill="black" transform="rotate(0,360,160)"/>
                <polygon class="arrowhead" points="368,80 356,74.4 356,85.6" fill="black" transform="rotate(0,360,80)"/>
                <circle cx="32" cy="32" r="6" class="opendot" fill="white" stroke="black"/>
                <g class="text">
                  <text x="268" y="68">Visits</text>
                  <text x="504" y="68">Rater</text>
                  <text x="536" y="68">+</text>
                  <text x="128" y="84">Browser</text>
                  <text x="416" y="84">Website</text>
                  <text x="508" y="84">Policy</text>
                  <text x="516" y="100">Selector</text>
                  <text x="252" y="132">Redirected</text>
                  <text x="308" y="132">To</text>
                  <text x="236" y="180">Evidence</text>
                  <text x="284" y="180">of</text>
                  <text x="312" y="180">Age</text>
                  <text x="416" y="180">Age</text>
                  <text x="416" y="196">Assurance</text>
                  <text x="516" y="196">Verifier</text>
                  <text x="416" y="212">Service</text>
                  <text x="252" y="260">Redirected</text>
                  <text x="308" y="260">To</text>
                  <text x="420" y="292">Age-</text>
                  <text x="252" y="308">Admitted</text>
                  <text x="416" y="308">Gated</text>
                  <text x="516" y="308">Enforcer</text>
                  <text x="416" y="324">Content</text>
                  <text x="212" y="340">or</text>
                  <text x="256" y="340">Blocked</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="left" pn="section-3.6-3.1.2">
   o
---+---  +------------+                      +-----------+
   |     |            |       Visits         |           |  Rater +
   +     |  Browser   |---------------------&gt;|  Website  |  Policy
  / \    |            |                  .---|           |  Selector
 /   \   +------------+                 |    +-----------+
               |   |      Redirected To |
               |   |                    |    +-----------+
               |   |                     '--&gt;|           |
               |   |     Evidence of Age     |    Age    |
               |    '-----------------------&gt;| Assurance |  Verifier
               |                             |  Service  |
               |                         .---|           |
               |                        |    +-----------+
               |          Redirected To |
               |                        |    +-----------+
               |                         '--&gt;|    Age-   |
               |           Admitted          |   Gated   |  Enforcer
                '---------------------------&gt;|  Content  |
                         or Blocked          +-----------+
</artwork>
          </artset>
        </figure>
        <t indent="0" pn="section-3.6-4">Some participants also noted that certain approaches may carry higher path-dependence risk once widely deployed, even if they remain theoretically possible to withdraw or replace. This can arise from accumulated architectural dependencies, operational integration with third-party services, and evolving expectations among users and service providers. As a result, architectures that tightly couple functionality with external verification services or embed assumptions about routine age signaling may increase the practical cost of transition if alternative approaches later emerge that address privacy, equity, or effectiveness concerns more effectively.</t>
        <t indent="0" pn="section-3.6-5"><xref target="f-device" format="default" sectionFormat="of" derivedContent="Figure 2"/> shows a deployment model for parental-control software, showing how the roles from <xref target="roles" format="default" sectionFormat="of" derivedContent="Section 3.2"/> might apply. Here, parental controls do any verification of age necessary and select policies; content ratings might be performed by websites or the parental-control software on the device, or both (noted with a "<tt>*</tt>" in the figure); enforcement is performed on-device.</t>
        <figure anchor="f-device" align="left" suppress-title="false" pn="figure-2">
          <name slugifiedName="name-parental-control-deployment">Parental-Control Deployment Model</name>
          <artset pn="section-3.6-6.1">
            <artwork type="svg" align="left" pn="section-3.6-6.1.1"><svg xmlns="http://www.w3.org/2000/svg" version="1.1" height="272" width="536" viewBox="0 0 536 272" class="diagram" text-anchor="middle" font-family="monospace" font-size="13px" stroke-linecap="round">
                <path d="M 32,32 L 32,80" fill="none" stroke="black"/>
                <path d="M 80,48 L 80,112" fill="none" stroke="black"/>
                <path d="M 80,208 L 80,256" fill="none" stroke="black"/>
                <path d="M 128,120 L 128,200" fill="none" stroke="black"/>
                <path d="M 184,48 L 184,112" fill="none" stroke="black"/>
                <path d="M 184,208 L 184,256" fill="none" stroke="black"/>
                <path d="M 368,48 L 368,112" fill="none" stroke="black"/>
                <path d="M 464,48 L 464,112" fill="none" stroke="black"/>
                <path d="M 8,48 L 56,48" fill="none" stroke="black"/>
                <path d="M 80,48 L 184,48" fill="none" stroke="black"/>
                <path d="M 368,48 L 464,48" fill="none" stroke="black"/>
                <path d="M 192,64 L 360,64" fill="none" stroke="black"/>
                <path d="M 192,96 L 360,96" fill="none" stroke="black"/>
                <path d="M 80,112 L 184,112" fill="none" stroke="black"/>
                <path d="M 368,112 L 464,112" fill="none" stroke="black"/>
                <path d="M 80,208 L 184,208" fill="none" stroke="black"/>
                <path d="M 80,256 L 184,256" fill="none" stroke="black"/>
                <path d="M 32,80 L 48,112" fill="none" stroke="black"/>
                <path d="M 172,120 L 196,168" fill="none" stroke="black"/>
                <path d="M 16,112 L 32,80" fill="none" stroke="black"/>
                <path d="M 196,168 L 212,168" fill="none" stroke="black"/>
                <polygon class="arrowhead" points="368,64 356,58.4 356,69.6" fill="black" transform="rotate(0,360,64)"/>
                <polygon class="arrowhead" points="200,96 188,90.4 188,101.6" fill="black" transform="rotate(180,192,96)"/>
                <polygon class="arrowhead" points="180,120 168,114.4 168,125.6" fill="black" transform="rotate(243.43494882292202,172,120)"/>
                <polygon class="arrowhead" points="136,120 124,114.4 124,125.6" fill="black" transform="rotate(270,128,120)"/>
                <circle cx="32" cy="32" r="6" class="opendot" fill="white" stroke="black"/>
                <g class="text">
                  <text x="268" y="52">Visits</text>
                  <text x="128" y="84">Browser</text>
                  <text x="248" y="84">(Rated)</text>
                  <text x="312" y="84">Content</text>
                  <text x="416" y="84">Website</text>
                  <text x="508" y="84">Rater*</text>
                  <text x="244" y="164">Rater*</text>
                  <text x="280" y="164">+</text>
                  <text x="252" y="180">Enforcer</text>
                  <text x="132" y="228">Parental</text>
                  <text x="236" y="228">Verifier</text>
                  <text x="280" y="228">+</text>
                  <text x="132" y="244">Controls</text>
                  <text x="228" y="244">Policy</text>
                  <text x="292" y="244">Selector</text>
                </g>
              </svg>
            </artwork>
            <artwork type="ascii-art" align="left" pn="section-3.6-6.1.2">
   o
---+---  +------------+       Visits         +-----------+
   |     |            |---------------------&gt;|           |
   +     |  Browser   |    (Rated) Content   |  Website  |  Rater*
  / \    |            |&lt;---------------------|           |
 /   \   +------------+                      +-----------+
               ^     ^
               |      \
               |       \__ Rater* +
               |           Enforcer
               |
         +------------+
         |  Parental  |  Verifier +
         |  Controls  |  Policy Selector
         +------------+
</artwork>
          </artset>
        </figure>
        <t indent="0" pn="section-3.6-7">An observation was made that laws often seek to designate a single entity as being responsible for ensuring that age restrictions are effective. That lawmakers feel the need to designate a responsible entity is due to constraints on how laws function, but one that creates other constraints.</t>
        <t indent="0" pn="section-3.6-8">Another constraint identified was the need for specialist expertise in order to administer all of the multiple different age assurance techniques; see <xref target="waterfall" format="default" sectionFormat="of" derivedContent="Section 3.5"/>. This means that there is a natural tendency for services to contract with specialist age assurance services.</t>
        <t indent="0" pn="section-3.6-9">Some of the proposed architectures were better able to operate under these constraints. Others required greater amounts of coordination, further emphasizing the importance of collaboration identified in <xref target="collaboration" format="default" sectionFormat="of" derivedContent="Section 3.1"/>.</t>
        <t indent="0" pn="section-3.6-10">In discussion of the constraints on different architectures, it was common for participants to point to a particular aspect of a given approach as carrying risks. Indeed, the final reckoning of risks produced a long list of potential issues that might need mitigation (see <xref target="impacts" format="default" sectionFormat="of" derivedContent="Appendix C"/>).</t>
        <t indent="0" pn="section-3.6-11">Architectures are not equally vulnerable to different risks, so a more thorough analysis is needed to identify how each risk applies to a different approach. An analysis that considers the constraints and assumptions necessary to successfully deploy different architectures is a contribution that would likely be welcomed by participants.</t>
      </section>
      <section anchor="holistic" numbered="true" removeInRFC="false" toc="include" pn="section-3.7">
        <name slugifiedName="name-safety-requires-more-than-a">Safety Requires More Than a Technical Solution</name>
        <t indent="0" pn="section-3.7-1">Experts in child safety frequently acknowledged that restricting access to selected content cannot be assumed to be sufficient. The task of ensuring that children are kept appropriately safe while preparing them for the challenges they will face in their lifetimes is a massively complex task.</t>
        <t indent="0" pn="section-3.7-2">A recurrent theme was the old maxim, "it takes a village to raise a child". This concept transcends cultural boundaries and was recognized. The roles played by parents, guardians, educators, governments, and online services in creating an environment in which children can thrive and grow were also discussed.</t>
        <t indent="0" pn="section-3.7-3">Content and service restrictions are likely only a small part of a suite of actions that combine to provide children with protection, but also support and encouragement. This theme was raised several times, despite the goal of the discussion being to explore technical and architectural questions.</t>
        <t indent="0" pn="section-3.7-4">Restrictions are necessarily binary and lacking in nuance. Though questions of what to restrict were out of scope for the workshop, discussions often identified subject matter that highlighted the challenges inherent in making simplistic classifications. Participants acknowledged the importance of the role of the adults who support children in their life journey. For example, on the subject of eating disorders, which can be challenging to classify, participants pointed to the importance of being able to recognize trends and inform and engage responsible adults. Ultimately, each child has their own challenges, and the people around them are in the best position to provide the support that best suits the child.</t>
        <t indent="0" pn="section-3.7-5">The concept of age-appropriate design was raised on several occasions. This presents significant privacy challenges in that it means providing more information about age to services. However, it was recognized that there are legal and moral obligations on services to cater to the needs of children of different age groups. This is a more complex problem space than binary age restrictions, as it requires a recognition of the different needs of children as they get older.</t>
      </section>
    </section>
    <section anchor="security-considerations" numbered="true" removeInRFC="false" toc="include" pn="section-4">
      <name slugifiedName="name-security-considerations">Security Considerations</name>
      <t indent="0" pn="section-4-1">Age verification has a significant potential security impact upon the Internet; see <xref target="trust" format="default" sectionFormat="of" derivedContent="Section 3.4"/>.</t>
    </section>
    <section anchor="iana-considerations" numbered="true" removeInRFC="false" toc="include" pn="section-5">
      <name slugifiedName="name-iana-considerations">IANA Considerations</name>
      <t indent="0" pn="section-5-1">This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-informative-references" pn="section-6">
      <name slugifiedName="name-informative-references">Informative References</name>
      <reference anchor="ANNOUNCE" target="https://datatracker.ietf.org/group/agews/about/" quoteTitle="true" derivedAnchor="ANNOUNCE">
        <front>
          <title>IAB/W3C Workshop on Age-Based Restrictions on Content Access (agews)</title>
          <author>
            <organization showOnFrontPage="true">Internet Architecture Board</organization>
          </author>
          <date/>
        </front>
      </reference>
      <reference anchor="CHATHAM-HOUSE" target="https://www.chathamhouse.org/about-us/chatham-house-rule" quoteTitle="true" derivedAnchor="CHATHAM-HOUSE">
        <front>
          <title>Chatham House Rule</title>
          <author>
            <organization showOnFrontPage="true">Chatham House</organization>
          </author>
          <date/>
        </front>
      </reference>
      <reference anchor="FATE" target="https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8491.pdf" quoteTitle="true" derivedAnchor="FATE">
        <front>
          <title>Face Analysis Technology Evaluation (FATE) Part 10: Performance of Passive, Software-Based Presentation Attack Detection (PAD) Algorithms</title>
          <author fullname="Mei Ngan">
            <organization showOnFrontPage="true"/>
          </author>
          <author fullname="Patrick Grother">
            <organization showOnFrontPage="true"/>
          </author>
          <author fullname="Austin Hom">
            <organization showOnFrontPage="true"/>
          </author>
          <date year="2023" month="September"/>
        </front>
        <seriesInfo name="NIST IR" value="8491"/>
        <seriesInfo name="DOI" value="10.6028/NIST.IR.8491"/>
        <refcontent>National Institute of Standards and Technology</refcontent>
      </reference>
      <reference anchor="HANSON" target="https://datatracker.ietf.org/doc/slides-agews-slides-where-enforcement-happens/" quoteTitle="true" derivedAnchor="HANSON">
        <front>
          <title>Where Enforcement Happens</title>
          <author fullname="Julia Hanson">
            <organization showOnFrontPage="true"/>
          </author>
          <date year="2025" month="October"/>
        </front>
        <refcontent>IAB/W3C Workshop on Age-Based Restrictions on Content Access</refcontent>
      </reference>
      <reference anchor="ISO-IEC-27566-1" target="https://www.iso.org/standard/88143.html" quoteTitle="true" derivedAnchor="ISO-IEC-27566-1">
        <front>
          <title>Information security, cybersecurity and privacy protection - Age assurance systems - Part 1: Framework</title>
          <author>
            <organization showOnFrontPage="true">ISO/IEC</organization>
          </author>
          <date year="2025" month="December"/>
        </front>
        <seriesInfo name="ISO/IEC" value="27566-1:2025"/>
      </reference>
      <reference anchor="JACKSON" target="https://datatracker.ietf.org/doc/slides-agews-where-enforcement-happens/" quoteTitle="true" derivedAnchor="JACKSON">
        <front>
          <title>Where Enforcement Happens</title>
          <author fullname="Dennis Jackson">
            <organization showOnFrontPage="true"/>
          </author>
          <date year="2025" month="October"/>
        </front>
        <refcontent>IAB/W3C Workshop on Age-Based Restrictions on Content Access</refcontent>
      </reference>
    </references>
    <section anchor="workshop-agenda" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a">
      <name slugifiedName="name-workshop-agenda">Workshop Agenda</name>
      <t indent="0" pn="section-appendix.a-1">This section contains a copy of the workshop agenda.</t>
      <section anchor="topic-introduction" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.1">
        <name slugifiedName="name-topic-introduction">Topic: Introduction</name>
        <t indent="0" pn="section-appendix.a.1-1">We will launch the workshop with a greeting, a round of introductions, and an explanation of the terms of engagement, background, goals and non-goals of the workshop.</t>
      </section>
      <section anchor="topic-setting-the-scene" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.2">
        <name slugifiedName="name-topic-setting-the-scene">Topic: Setting the Scene</name>
        <t indent="0" pn="section-appendix.a.2-1">Successfully deploying age restrictions at Internet scale has many considerations and constraints. We will explore them at a high level in order. The goal is to discuss within the group about the scope of topics that the workshop will seek to address.</t>
      </section>
      <section anchor="topic-guiding-principles" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.3">
        <name slugifiedName="name-topic-guiding-principles">Topic: Guiding Principles</name>
        <t indent="0" pn="section-appendix.a.3-1">Architectural principles give us a framework for evaluating additions and changes to the Internet. Technical principles are subject to a number of other considerations, in particular human-rights principles. We will review the principles that might apply to age-based restrictions, explain their function, impact, and how they are applied. Including human-rights impacts, such as:</t>
        <ul spacing="compact" bare="false" empty="false" indent="3" pn="section-appendix.a.3-2">
          <li pn="section-appendix.a.3-2.1">
            <t indent="0" pn="section-appendix.a.3-2.1.1">Privacy and Security</t>
          </li>
          <li pn="section-appendix.a.3-2.2">
            <t indent="0" pn="section-appendix.a.3-2.2.1">Safety and Efficacy</t>
          </li>
          <li pn="section-appendix.a.3-2.3">
            <t indent="0" pn="section-appendix.a.3-2.3.1">Censorship and Access</t>
          </li>
          <li pn="section-appendix.a.3-2.4">
            <t indent="0" pn="section-appendix.a.3-2.4.1">Access to the Internet</t>
          </li>
          <li pn="section-appendix.a.3-2.5">
            <t indent="0" pn="section-appendix.a.3-2.5.1">Freedom of Expression</t>
          </li>
        </ul>
        <t indent="0" pn="section-appendix.a.3-3">And effects on the Internet and Web architecture, such as:</t>
        <ul spacing="compact" bare="false" empty="false" indent="3" pn="section-appendix.a.3-4">
          <li pn="section-appendix.a.3-4.1">
            <t indent="0" pn="section-appendix.a.3-4.1.1">Deployment, Extensibility, and Evolution</t>
          </li>
          <li pn="section-appendix.a.3-4.2">
            <t indent="0" pn="section-appendix.a.3-4.2.1">Avoid Centralization</t>
          </li>
          <li pn="section-appendix.a.3-4.3">
            <t indent="0" pn="section-appendix.a.3-4.3.1">End-to-End</t>
          </li>
          <li pn="section-appendix.a.3-4.4">
            <t indent="0" pn="section-appendix.a.3-4.4.1">One Global Internet/Web</t>
          </li>
          <li pn="section-appendix.a.3-4.5">
            <t indent="0" pn="section-appendix.a.3-4.5.1">Layering and Modularity</t>
          </li>
        </ul>
      </section>
      <section anchor="topic-potential-impacts" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.4">
        <name slugifiedName="name-topic-potential-impacts">Topic: Potential Impacts</name>
        <t indent="0" pn="section-appendix.a.4-1">We now want to look at some of the higher-level considerations that apply regardless of approach. We will look at some different perspectives on how to think of the overall problem. Discussion will seek to find how those perspectives can be shaped to guide choices.</t>
      </section>
      <section anchor="topic-where-enforcement-happens" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.5">
        <name slugifiedName="name-topic-where-enforcement-hap">Topic: Where Enforcement Happens</name>
        <t indent="0" pn="section-appendix.a.5-1">The Internet standards community is in the unique position to make controlled changes to the architecture of the Internet, and so there are multiple ways and places to deploy age restrictions. We will examine the options, with an eye to the deployment properties of each location and configuration, as related to the architectural principles. In particular, it will consider the establishment of new roles as well as the use of existing ones.</t>
      </section>
      <section anchor="topic-available-techniques" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.6">
        <name slugifiedName="name-topic-available-techniques">Topic: Available Techniques</name>
        <t indent="0" pn="section-appendix.a.6-1">There are several active and proposed systems for age restriction on the Internet. We will review them from the perspective of their interaction with the architectural principles, potential impacts, and with consideration of the enforcement options. Including:</t>
        <ul spacing="compact" bare="false" empty="false" indent="3" pn="section-appendix.a.6-2">
          <li pn="section-appendix.a.6-2.1">
            <t indent="0" pn="section-appendix.a.6-2.1.1">Age verification: including server-side solutions using government identity systems and ZKPs</t>
          </li>
          <li pn="section-appendix.a.6-2.2">
            <t indent="0" pn="section-appendix.a.6-2.2.1">Age estimation: including biometrics and data analysis</t>
          </li>
          <li pn="section-appendix.a.6-2.3">
            <t indent="0" pn="section-appendix.a.6-2.3.1">Age "inference" approaches</t>
          </li>
          <li pn="section-appendix.a.6-2.4">
            <t indent="0" pn="section-appendix.a.6-2.4.1">In-network solutions</t>
          </li>
          <li pn="section-appendix.a.6-2.5">
            <t indent="0" pn="section-appendix.a.6-2.5.1">Classification and on-device/parental-control designs</t>
          </li>
        </ul>
      </section>
      <section anchor="discussion" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.7">
        <name slugifiedName="name-discussion">Discussion</name>
        <t indent="0" pn="section-appendix.a.7-1">We will follow up on incomplete discussions and revisit architectural learnings.</t>
      </section>
      <section anchor="summary-and-reflection" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.8">
        <name slugifiedName="name-summary-and-reflection">Summary and Reflection</name>
        <t indent="0" pn="section-appendix.a.8-1">We will summarize what we have discussed and learned thus far.</t>
      </section>
      <section anchor="outcomes" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.a.9">
        <name slugifiedName="name-outcomes">Outcomes</name>
        <t indent="0" pn="section-appendix.a.9-1">We will outline the potential outcomes, further actions, and next steps.</t>
      </section>
    </section>
    <section anchor="participants" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.b">
      <name slugifiedName="name-workshop-participants">Workshop Participants</name>
      <t indent="0" pn="section-appendix.b-1">Attendees of the workshop are listed with their primary affiliation. Attendees from the program committee (PC), the Internet Architecture Board (IAB), and W3C Technical Architecture Group (TAG) are also marked.</t>
      <ul spacing="compact" bare="false" empty="false" indent="3" pn="section-appendix.b-2">
        <li pn="section-appendix.b-2.1">
          <t indent="0" pn="section-appendix.b-2.1.1"><contact fullname="Steve Bellovin"/></t>
        </li>
        <li pn="section-appendix.b-2.2">
          <t indent="0" pn="section-appendix.b-2.2.1"><contact fullname="Hadley Beeman"/>, TAG (PC)</t>
        </li>
        <li pn="section-appendix.b-2.3">
          <t indent="0" pn="section-appendix.b-2.3.1"><contact fullname="Matthew Bocci"/>, IAB (Observer)</t>
        </li>
        <li pn="section-appendix.b-2.4">
          <t indent="0" pn="section-appendix.b-2.4.1"><contact fullname="Christian Bormann"/>, SPRIND</t>
        </li>
        <li pn="section-appendix.b-2.5">
          <t indent="0" pn="section-appendix.b-2.5.1"><contact fullname="Marcos Cáceres"/>, TAG (Observer)</t>
        </li>
        <li pn="section-appendix.b-2.6">
          <t indent="0" pn="section-appendix.b-2.6.1"><contact fullname="Andrew Campling"/>, 419 Consulting</t>
        </li>
        <li pn="section-appendix.b-2.7">
          <t indent="0" pn="section-appendix.b-2.7.1"><contact fullname="Sofía Celi"/>, Brave</t>
        </li>
        <li pn="section-appendix.b-2.8">
          <t indent="0" pn="section-appendix.b-2.8.1"><contact fullname="David Cooke"/>, Aylo</t>
        </li>
        <li pn="section-appendix.b-2.9">
          <t indent="0" pn="section-appendix.b-2.9.1"><contact fullname="Iain Corby"/>, Age Verification Providers Association</t>
        </li>
        <li pn="section-appendix.b-2.10">
          <t indent="0" pn="section-appendix.b-2.10.1"><contact fullname="Dhruv Dhody"/>, IAB (Observer)</t>
        </li>
        <li pn="section-appendix.b-2.11">
          <t indent="0" pn="section-appendix.b-2.11.1"><contact fullname="Nick Doty"/>, Center for Democracy and Technology (PC)</t>
        </li>
        <li pn="section-appendix.b-2.12">
          <t indent="0" pn="section-appendix.b-2.12.1"><contact fullname="Sarah Forland"/>, New America Open Technology Institute</t>
        </li>
        <li pn="section-appendix.b-2.13">
          <t indent="0" pn="section-appendix.b-2.13.1"><contact fullname="Jérôme Gorin"/>, École Polytechnique</t>
        </li>
        <li pn="section-appendix.b-2.14">
          <t indent="0" pn="section-appendix.b-2.14.1"><contact fullname="Alexis Hancock"/>, Electronic Frontier Foundation</t>
        </li>
        <li pn="section-appendix.b-2.15">
          <t indent="0" pn="section-appendix.b-2.15.1"><contact fullname="Julia Hanson"/>, Apple</t>
        </li>
        <li pn="section-appendix.b-2.16">
          <t indent="0" pn="section-appendix.b-2.16.1"><contact fullname="Wes Hardaker"/>, University of Southern California Information Sciences Institute</t>
        </li>
        <li pn="section-appendix.b-2.17">
          <t indent="0" pn="section-appendix.b-2.17.1"><contact fullname="Kyle den Hartog"/>, Brave</t>
        </li>
        <li pn="section-appendix.b-2.18">
          <t indent="0" pn="section-appendix.b-2.18.1"><contact fullname="Dennis Jackson"/>, Mozilla</t>
        </li>
        <li pn="section-appendix.b-2.19">
          <t indent="0" pn="section-appendix.b-2.19.1"><contact fullname="Leif Johansson"/>, SIROS Foundation</t>
        </li>
        <li pn="section-appendix.b-2.20">
          <t indent="0" pn="section-appendix.b-2.20.1"><contact fullname="Mallory Knodel"/>, Article 19</t>
        </li>
        <li pn="section-appendix.b-2.21">
          <t indent="0" pn="section-appendix.b-2.21.1"><contact fullname="Mirja Kühlewind"/>, IAB (Observer)</t>
        </li>
        <li pn="section-appendix.b-2.22">
          <t indent="0" pn="section-appendix.b-2.22.1"><contact fullname="Jonathan Langley"/>, Ofcom UK</t>
        </li>
        <li pn="section-appendix.b-2.23">
          <t indent="0" pn="section-appendix.b-2.23.1"><contact fullname="Veronica Lin"/>, Carnegie Mellon University</t>
        </li>
        <li pn="section-appendix.b-2.24">
          <t indent="0" pn="section-appendix.b-2.24.1"><contact fullname="Thibault Meunier"/>, Cloudflare</t>
        </li>
        <li pn="section-appendix.b-2.25">
          <t indent="0" pn="section-appendix.b-2.25.1"><contact fullname="Tom Newton"/>, Qoria</t>
        </li>
        <li pn="section-appendix.b-2.26">
          <t indent="0" pn="section-appendix.b-2.26.1"><contact fullname="Mark Nottingham"/>, IAB (PC Co-Chair)</t>
        </li>
        <li pn="section-appendix.b-2.27">
          <t indent="0" pn="section-appendix.b-2.27.1"><contact fullname="Georgia Osborn"/>, Ofcom UK</t>
        </li>
        <li pn="section-appendix.b-2.28">
          <t indent="0" pn="section-appendix.b-2.28.1"><contact fullname="Tommy Pauly"/>, IAB (PC)</t>
        </li>
        <li pn="section-appendix.b-2.29">
          <t indent="0" pn="section-appendix.b-2.29.1"><contact fullname="John Perrino"/>, Internet Society</t>
        </li>
        <li pn="section-appendix.b-2.30">
          <t indent="0" pn="section-appendix.b-2.30.1"><contact fullname="Eric Rescorla"/>, Knight-Georgetown Institute</t>
        </li>
        <li pn="section-appendix.b-2.31">
          <t indent="0" pn="section-appendix.b-2.31.1"><contact fullname="Beatriz Rocha"/>, Ceweb.br</t>
        </li>
        <li pn="section-appendix.b-2.32">
          <t indent="0" pn="section-appendix.b-2.32.1"><contact fullname="Omari Rodney"/>, Yoti</t>
        </li>
        <li pn="section-appendix.b-2.33">
          <t indent="0" pn="section-appendix.b-2.33.1"><contact fullname="Gianpaolo Scalone"/>, Vodafone</t>
        </li>
        <li pn="section-appendix.b-2.34">
          <t indent="0" pn="section-appendix.b-2.34.1"><contact fullname="Sarah Scheffler"/>, Carnegie Mellon University</t>
        </li>
        <li pn="section-appendix.b-2.35">
          <t indent="0" pn="section-appendix.b-2.35.1"><contact fullname="Andrew Shaw"/>, UK National Cyber Security Centre</t>
        </li>
        <li pn="section-appendix.b-2.36">
          <t indent="0" pn="section-appendix.b-2.36.1"><contact fullname="Aline Sylla"/>, German Federal Commissioner for Data Protection and Freedom of Information</t>
        </li>
        <li pn="section-appendix.b-2.37">
          <t indent="0" pn="section-appendix.b-2.37.1"><contact fullname="Martin Thomson"/>, TAG  (PC Co-Chair)</t>
        </li>
        <li pn="section-appendix.b-2.38">
          <t indent="0" pn="section-appendix.b-2.38.1"><contact fullname="Carmela Troncoso"/>, EPFL, the Swiss Federal Institute of Technology in Lausanne</t>
        </li>
        <li pn="section-appendix.b-2.39">
          <t indent="0" pn="section-appendix.b-2.39.1"><contact fullname="Benjamin VanderSloot"/>, Mozilla</t>
        </li>
        <li pn="section-appendix.b-2.40">
          <t indent="0" pn="section-appendix.b-2.40.1"><contact fullname="Tara Whalen"/>, World Wide Web Consortium (PC)</t>
        </li>
      </ul>
    </section>
    <section anchor="impacts" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c">
      <name slugifiedName="name-potential-impacts">Potential Impacts</name>
      <t indent="0" pn="section-appendix.c-1">During the workshop, participants were asked to name potential impacts -- whether positive or negative -- that could be seen in association with the introduction of age-based restrictions. This list is not exhaustive, focuses largely on the challenges surrounding the introduction of mechanisms, and does not imply that all points were agreed to by all participants.</t>
      <section anchor="impact-on-children" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.1">
        <name slugifiedName="name-impact-on-children">Impact on Children</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.1-1"><li pn="section-appendix.c.1-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.1-1.1.1">Children encounter online harm</t>
          </li>
          <li pn="section-appendix.c.1-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.1-1.2.1">Pushing kids to less safe resources</t>
          </li>
          <li pn="section-appendix.c.1-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.1-1.3.1">Kids lose the ability to explore on their own</t>
          </li>
          <li pn="section-appendix.c.1-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.1-1.4.1">Diminishing children's rights</t>
          </li>
        </ol>
      </section>
      <section anchor="ecosystem-impact" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.2">
        <name slugifiedName="name-ecosystem-impact">Ecosystem Impact</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.2-1"><li pn="section-appendix.c.2-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.2-1.1.1">Centralization</t>
          </li>
          <li pn="section-appendix.c.2-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.2-1.2.1">Fragmentation of the Internet</t>
          </li>
          <li pn="section-appendix.c.2-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.2-1.3.1">Increased costs for running a website</t>
          </li>
          <li pn="section-appendix.c.2-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.2-1.4.1">Chilling effects on use of the Internet</t>
          </li>
          <li pn="section-appendix.c.2-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.c.2-1.5.1">VPNs proliferate</t>
          </li>
          <li pn="section-appendix.c.2-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.c.2-1.6.1">Chilling effects on the publication of borderline content</t>
          </li>
          <li pn="section-appendix.c.2-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.c.2-1.7.1">Less content being available online</t>
          </li>
          <li pn="section-appendix.c.2-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.c.2-1.8.1">Restricting people to a few platforms/services</t>
          </li>
          <li pn="section-appendix.c.2-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.c.2-1.9.1">More use/utility of the Internet due to a perception of safety</t>
          </li>
          <li pn="section-appendix.c.2-1.10" derivedCounter="10.">
            <t indent="0" pn="section-appendix.c.2-1.10.1">More (or all) online services require a verified login</t>
          </li>
        </ol>
      </section>
      <section anchor="implementation-and-deployment-difficulties" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.3">
        <name slugifiedName="name-implementation-and-deployme">Implementation and Deployment Difficulties</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.3-1"><li pn="section-appendix.c.3-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.3-1.1.1">Device compatibility</t>
          </li>
          <li pn="section-appendix.c.3-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.3-1.2.1">"Advanced Persistent Teenagers"</t>
          </li>
          <li pn="section-appendix.c.3-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.3-1.3.1">Difficulties regarding jurisdiction checking</t>
          </li>
          <li pn="section-appendix.c.3-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.3-1.4.1">Spillover to other software (e.g., VPNs)</t>
          </li>
          <li pn="section-appendix.c.3-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.c.3-1.5.1">Displacing users from compliant to non-compliant sites</t>
          </li>
          <li pn="section-appendix.c.3-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.c.3-1.6.1">False sense of addressing the problem</t>
          </li>
          <li pn="section-appendix.c.3-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.c.3-1.7.1">Dealing with conflict of laws</t>
          </li>
          <li pn="section-appendix.c.3-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.c.3-1.8.1">Operators pulling out of territories</t>
          </li>
          <li pn="section-appendix.c.3-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.c.3-1.9.1">Increasing the footprint of the deep web</t>
          </li>
          <li pn="section-appendix.c.3-1.10" derivedCounter="10.">
            <t indent="0" pn="section-appendix.c.3-1.10.1">Imposition of cultural norms on other jurisdictions</t>
          </li>
          <li pn="section-appendix.c.3-1.11" derivedCounter="11.">
            <t indent="0" pn="section-appendix.c.3-1.11.1">Technical solutions are reused for other purposes (scope creep)</t>
          </li>
          <li pn="section-appendix.c.3-1.12" derivedCounter="12.">
            <t indent="0" pn="section-appendix.c.3-1.12.1">Dealing with obsolete and non-compliant systems</t>
          </li>
        </ol>
      </section>
      <section anchor="security-and-privacy" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.4">
        <name slugifiedName="name-security-and-privacy">Security and Privacy</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.4-1"><li pn="section-appendix.c.4-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.4-1.1.1">Increased cybersecurity risks</t>
          </li>
          <li pn="section-appendix.c.4-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.4-1.2.1">Fingerprinting risk</t>
          </li>
          <li pn="section-appendix.c.4-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.4-1.3.1">Ad targeting could get creepier</t>
          </li>
          <li pn="section-appendix.c.4-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.4-1.4.1">Needing to trust someone on their word without evidence</t>
          </li>
          <li pn="section-appendix.c.4-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.c.4-1.5.1">Normalizing online identity requests -- increase to phishing risk</t>
          </li>
          <li pn="section-appendix.c.4-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.c.4-1.6.1">Data breaches</t>
          </li>
        </ol>
      </section>
      <section anchor="equity" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.5">
        <name slugifiedName="name-equity">Equity</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.5-1"><li pn="section-appendix.c.5-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.5-1.1.1">Lack of access (e.g., due to lack of device support)</t>
          </li>
          <li pn="section-appendix.c.5-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.5-1.2.1">Refugees, stateless people, people without identity</t>
          </li>
          <li pn="section-appendix.c.5-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.5-1.3.1">Harm to vulnerable people</t>
          </li>
          <li pn="section-appendix.c.5-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.5-1.4.1">Not addressing other vulnerable groups (i.e., not age-based)</t>
          </li>
          <li pn="section-appendix.c.5-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.c.5-1.5.1">Lack of availability of redress mechanisms</t>
          </li>
          <li pn="section-appendix.c.5-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.c.5-1.6.1">Users' rights to restitution</t>
          </li>
          <li pn="section-appendix.c.5-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.c.5-1.7.1">Loss of control over and access to data</t>
          </li>
          <li pn="section-appendix.c.5-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.c.5-1.8.1">Risk to anonymity</t>
          </li>
          <li pn="section-appendix.c.5-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.c.5-1.9.1">Loss of ability to run software of your choice</t>
          </li>
        </ol>
      </section>
      <section anchor="societal-impacts" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.c.6">
        <name slugifiedName="name-societal-impacts">Societal Impacts</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.c.6-1"><li pn="section-appendix.c.6-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.c.6-1.1.1">Air cover for blocking the Internet</t>
          </li>
          <li pn="section-appendix.c.6-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.c.6-1.2.1">User control of the content they see online</t>
          </li>
          <li pn="section-appendix.c.6-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.c.6-1.3.1">Costs to society (e.g., regulatory overhead)</t>
          </li>
          <li pn="section-appendix.c.6-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.c.6-1.4.1">Increased online tracking and state surveillance</t>
          </li>
          <li pn="section-appendix.c.6-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.c.6-1.5.1">Use as a censorship mechanism</t>
          </li>
          <li pn="section-appendix.c.6-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.c.6-1.6.1">Advancing foreign policy goals with censorship</t>
          </li>
          <li pn="section-appendix.c.6-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.c.6-1.7.1">Abuse of guardians who don't cut off their wards</t>
          </li>
        </ol>
      </section>
    </section>
    <section anchor="desirable-and-essential-properties-of-a-solution" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d">
      <name slugifiedName="name-desirable-and-essential-pro">Desirable and Essential Properties of a Solution</name>
      <t indent="0" pn="section-appendix.d-1">During the workshop, participants were asked to nominate the properties that they believed would be advantageous or even essential for a solution in this space to have. This set of requirements and desiderata was recognized as not all being achievable, as some goals are in tension with others.</t>
      <section anchor="functional" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.1">
        <name slugifiedName="name-functional">Functional</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.1-1"><li pn="section-appendix.d.1-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.1-1.1.1">Underage don't access content that's inappropriate</t>
          </li>
          <li pn="section-appendix.d.1-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.1-1.2.1">Not trivially by-passable</t>
          </li>
          <li pn="section-appendix.d.1-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.1-1.3.1">Flexible enough to be provided through different means</t>
          </li>
          <li pn="section-appendix.d.1-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.1-1.4.1">Bound to the user</t>
          </li>
          <li pn="section-appendix.d.1-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.1-1.5.1">Reliable</t>
          </li>
          <li pn="section-appendix.d.1-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.1-1.6.1">Handles user-generated content</t>
          </li>
          <li pn="section-appendix.d.1-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.d.1-1.7.1">Enables differential experiences or age-appropriate design (not just blocking)</t>
          </li>
          <li pn="section-appendix.d.1-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.d.1-1.8.1">Agile by design -- assume adversarial engagement</t>
          </li>
          <li pn="section-appendix.d.1-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.d.1-1.9.1">Difficult to bypass</t>
          </li>
          <li pn="section-appendix.d.1-1.10" derivedCounter="10.">
            <t indent="0" pn="section-appendix.d.1-1.10.1">Accurate</t>
          </li>
        </ol>
      </section>
      <section anchor="accountability-and-transparency" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.2">
        <name slugifiedName="name-accountability-and-transpar">Accountability and Transparency</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.2-1"><li pn="section-appendix.d.2-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.2-1.1.1">Transparency and accountability regarding what is blocked</t>
          </li>
          <li pn="section-appendix.d.2-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.2-1.2.1">Minimizes the need for trust decisions</t>
          </li>
          <li pn="section-appendix.d.2-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.2-1.3.1">Can be independently/publicly verifiable and tested</t>
          </li>
          <li pn="section-appendix.d.2-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.2-1.4.1">Auditability</t>
          </li>
          <li pn="section-appendix.d.2-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.2-1.5.1">Appeal mechanism for incorrect labeling of content</t>
          </li>
        </ol>
      </section>
      <section anchor="privacy-and-security" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.3">
        <name slugifiedName="name-privacy-and-security">Privacy and Security</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.3-1"><li pn="section-appendix.d.3-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.3-1.1.1">Issuer-Verifier and Verifier-Verifier unlinkability</t>
          </li>
          <li pn="section-appendix.d.3-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.3-1.2.1">Unlinkability across components</t>
          </li>
          <li pn="section-appendix.d.3-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.3-1.3.1">Purpose limitation of the data processed</t>
          </li>
          <li pn="section-appendix.d.3-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.3-1.4.1">Security of data processed</t>
          </li>
          <li pn="section-appendix.d.3-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.3-1.5.1">Phishing-resistant</t>
          </li>
          <li pn="section-appendix.d.3-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.3-1.6.1">Doesn't process or transfer any more data than is necessary</t>
          </li>
          <li pn="section-appendix.d.3-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.d.3-1.7.1">Avoids becoming a tracking vector</t>
          </li>
        </ol>
      </section>
      <section anchor="equity-1" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.4">
        <name slugifiedName="name-equity-2">Equity</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.4-1"><li pn="section-appendix.d.4-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.4-1.1.1">Inclusive</t>
          </li>
          <li pn="section-appendix.d.4-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.4-1.2.1">Fair -- avoids or minimizes bias</t>
          </li>
          <li pn="section-appendix.d.4-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.4-1.3.1">Does not create inequalities (e.g., across education, other properties)</t>
          </li>
          <li pn="section-appendix.d.4-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.4-1.4.1">Discriminates solely upon age, not other properties</t>
          </li>
          <li pn="section-appendix.d.4-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.4-1.5.1">Works on open devices</t>
          </li>
          <li pn="section-appendix.d.4-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.4-1.6.1">Device independence</t>
          </li>
          <li pn="section-appendix.d.4-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.d.4-1.7.1">Usable by people of all ages to increase their safety online</t>
          </li>
          <li pn="section-appendix.d.4-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.d.4-1.8.1">User choice in who verifies their age, and how</t>
          </li>
          <li pn="section-appendix.d.4-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.d.4-1.9.1">No clear losers</t>
          </li>
          <li pn="section-appendix.d.4-1.10" derivedCounter="10.">
            <t indent="0" pn="section-appendix.d.4-1.10.1">Accessible to people with disabilities</t>
          </li>
          <li pn="section-appendix.d.4-1.11" derivedCounter="11.">
            <t indent="0" pn="section-appendix.d.4-1.11.1">Includes appeal mechanisms for incorrect age determinations</t>
          </li>
        </ol>
      </section>
      <section anchor="jurisdiction-and-geopolitical" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.5">
        <name slugifiedName="name-jurisdiction-and-geopolitic">Jurisdiction and Geopolitical</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.5-1"><li pn="section-appendix.d.5-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.5-1.1.1">Able to handle arbitrary composition of different jurisdictional requirements (possibly down to school level)</t>
          </li>
          <li pn="section-appendix.d.5-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.5-1.2.1">Applicable globally</t>
          </li>
          <li pn="section-appendix.d.5-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.5-1.3.1">Applies the rule of law in the jurisdiction where it applies universally</t>
          </li>
          <li pn="section-appendix.d.5-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.5-1.4.1">No concentration of power in any one entity (or small group of them)</t>
          </li>
          <li pn="section-appendix.d.5-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.5-1.5.1">No concentration of power in any country</t>
          </li>
          <li pn="section-appendix.d.5-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.5-1.6.1">Aligned to legal duties</t>
          </li>
          <li pn="section-appendix.d.5-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.d.5-1.7.1">Based upon a valid legal basis</t>
          </li>
        </ol>
      </section>
      <section anchor="usability" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.6">
        <name slugifiedName="name-usability">Usability</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.6-1"><li pn="section-appendix.d.6-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.6-1.1.1">Economically sustainable</t>
          </li>
          <li pn="section-appendix.d.6-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.6-1.2.1">Low friction for adults</t>
          </li>
          <li pn="section-appendix.d.6-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.6-1.3.1">Fast</t>
          </li>
          <li pn="section-appendix.d.6-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.6-1.4.1">Comprehensible by users</t>
          </li>
        </ol>
      </section>
      <section anchor="implementation-and-deployment" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.7">
        <name slugifiedName="name-implementation-and-deploymen">Implementation and Deployment</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.7-1"><li pn="section-appendix.d.7-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.7-1.1.1">Low dependency on a single root of trust</t>
          </li>
          <li pn="section-appendix.d.7-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.7-1.2.1">Enforceable by a good mix of technology and law</t>
          </li>
          <li pn="section-appendix.d.7-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.7-1.3.1">Broad deployability -- not expensive or complex</t>
          </li>
          <li pn="section-appendix.d.7-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.7-1.4.1">Decentralized</t>
          </li>
          <li pn="section-appendix.d.7-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.7-1.5.1">Future-proof</t>
          </li>
          <li pn="section-appendix.d.7-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.7-1.6.1">Ability to report/learn when there are issues in the system/telemetry</t>
          </li>
        </ol>
      </section>
      <section anchor="generalother" numbered="true" removeInRFC="false" toc="include" pn="section-appendix.d.8">
        <name slugifiedName="name-general-other">General/Other</name>
        <ol spacing="compact" type="1" indent="adaptive" start="1" pn="section-appendix.d.8-1"><li pn="section-appendix.d.8-1.1" derivedCounter="1.">
            <t indent="0" pn="section-appendix.d.8-1.1.1">Not perfect</t>
          </li>
          <li pn="section-appendix.d.8-1.2" derivedCounter="2.">
            <t indent="0" pn="section-appendix.d.8-1.2.1">Technically robust</t>
          </li>
          <li pn="section-appendix.d.8-1.3" derivedCounter="3.">
            <t indent="0" pn="section-appendix.d.8-1.3.1">Not a single, sole solution</t>
          </li>
          <li pn="section-appendix.d.8-1.4" derivedCounter="4.">
            <t indent="0" pn="section-appendix.d.8-1.4.1">Stable -- resilient</t>
          </li>
          <li pn="section-appendix.d.8-1.5" derivedCounter="5.">
            <t indent="0" pn="section-appendix.d.8-1.5.1">Alignment of incentives among participants</t>
          </li>
          <li pn="section-appendix.d.8-1.6" derivedCounter="6.">
            <t indent="0" pn="section-appendix.d.8-1.6.1">Simple to implement</t>
          </li>
          <li pn="section-appendix.d.8-1.7" derivedCounter="7.">
            <t indent="0" pn="section-appendix.d.8-1.7.1">Resistance to repurposing for censorship</t>
          </li>
          <li pn="section-appendix.d.8-1.8" derivedCounter="8.">
            <t indent="0" pn="section-appendix.d.8-1.8.1">Unable to be used for surveillance</t>
          </li>
          <li pn="section-appendix.d.8-1.9" derivedCounter="9.">
            <t indent="0" pn="section-appendix.d.8-1.9.1">Addresses risk of verification becoming over-prevalent</t>
          </li>
          <li pn="section-appendix.d.8-1.10" derivedCounter="10.">
            <t indent="0" pn="section-appendix.d.8-1.10.1">Accountable governance</t>
          </li>
          <li pn="section-appendix.d.8-1.11" derivedCounter="11.">
            <t indent="0" pn="section-appendix.d.8-1.11.1">Open Standards-based</t>
          </li>
        </ol>
      </section>
    </section>
    <section numbered="false" anchor="iab-members-at-the-time-of-approval" removeInRFC="false" toc="include" pn="section-appendix.e">
      <name slugifiedName="name-iab-members-at-the-time-of-">IAB Members at the Time of Approval</name>
      <t indent="0" pn="section-appendix.e-1">Internet Architecture Board members at the time this document was approved for publication were:</t>
      <ul spacing="normal" bare="false" empty="false" indent="3" pn="section-appendix.e-2">
        <li pn="section-appendix.e-2.1">
          <t indent="0" pn="section-appendix.e-2.1.1"><contact fullname="Ali C. Begen"/></t>
        </li>
        <li pn="section-appendix.e-2.2">
          <t indent="0" pn="section-appendix.e-2.2.1"><contact fullname="Matthew Bocci"/></t>
        </li>
        <li pn="section-appendix.e-2.3">
          <t indent="0" pn="section-appendix.e-2.3.1"><contact fullname="Roman Danyliw"/></t>
        </li>
        <li pn="section-appendix.e-2.4">
          <t indent="0" pn="section-appendix.e-2.4.1"><contact fullname="Dhruv Dhody"/></t>
        </li>
        <li pn="section-appendix.e-2.5">
          <t indent="0" pn="section-appendix.e-2.5.1"><contact fullname="Jana Iyengar"/></t>
        </li>
        <li pn="section-appendix.e-2.6">
          <t indent="0" pn="section-appendix.e-2.6.1"><contact fullname="Suresh Krishnan"/></t>
        </li>
        <li pn="section-appendix.e-2.7">
          <t indent="0" pn="section-appendix.e-2.7.1"><contact fullname="Warren Kumari"/></t>
        </li>
        <li pn="section-appendix.e-2.8">
          <t indent="0" pn="section-appendix.e-2.8.1"><contact fullname="Jason Livingood"/></t>
        </li>
        <li pn="section-appendix.e-2.9">
          <t indent="0" pn="section-appendix.e-2.9.1"><contact fullname="Mark Nottingham"/></t>
        </li>
        <li pn="section-appendix.e-2.10">
          <t indent="0" pn="section-appendix.e-2.10.1"><contact fullname="Yingzhen Qu"/></t>
        </li>
        <li pn="section-appendix.e-2.11">
          <t indent="0" pn="section-appendix.e-2.11.1"><contact fullname="Alvaro Retana"/></t>
        </li>
        <li pn="section-appendix.e-2.12">
          <t indent="0" pn="section-appendix.e-2.12.1"><contact fullname="Yaroslav Rosomakho"/></t>
        </li>
        <li pn="section-appendix.e-2.13">
          <t indent="0" pn="section-appendix.e-2.13.1"><contact fullname="Nick Sullivan"/></t>
        </li>
      </ul>
    </section>
    <section anchor="authors-addresses" numbered="false" removeInRFC="false" toc="include" pn="section-appendix.f">
      <name slugifiedName="name-authors-addresses">Authors' Addresses</name>
      <author initials="M." surname="Nottingham" fullname="Mark Nottingham">
        <organization showOnFrontPage="true"/>
        <address>
          <email>mnot@mnot.net</email>
        </address>
      </author>
      <author initials="M." surname="Thomson" fullname="Martin Thomson">
        <organization showOnFrontPage="true"/>
        <address>
          <email>mt@lowentropy.net</email>
        </address>
      </author>
    </section>
  </back>
</rfc>
