A Kid Drew a Fake Mustache and Beat Age Verification. Now What?

The UK's first Online Safety Act report card is in: 32% of kids have bypassed age checks, nearly half say it's easy, and one in four parents helped. Here's what this means for your family — and why laws alone won't keep your child safe.

A fifteen-year-old in the UK used an eyebrow pencil to draw a mustache on his face. Then he held his phone up for the age verification selfie. The system scanned his features, decided he was old enough, and let him through.

His mother caught him mid-act. She told Internet Matters researchers about it. And when I read that detail buried in a May 2026 report about whether the UK's Online Safety Act is actually protecting children, I sat with it for a while. Because we spent years arguing about whether governments should pass online safety laws. Several did. And now we have the first real data about whether those laws are doing what we were promised.

The answer is complicated. And if you're a parent in the US watching 19 states pass their own versions of these laws right now, you need to hear it.

The first report card is in

The UK's Online Safety Act took effect in 2024, making it one of the first comprehensive attempts in the world to legally require platforms to protect children. Internet Matters — a UK nonprofit focused on child online safety — just published their May 2026 assessment, surveying 1,270 children aged 9 to 16 and their parents.

Some of the numbers look encouraging on first pass. Sixty-eight percent of kids and 67% of parents said they've noticed more safety features — better reporting tools, content filters, block options. About half of children said they'd been asked to verify their age recently. And 54% reported that the content they see online feels more child-friendly than before.

If you stopped there, you'd think the law was working.

Don't stop there.

Kids are getting through, and they know it

Forty-six percent of children in the survey said age checks are easy to bypass. Only 17% called them difficult. A third of children — 32% — said they'd already gotten past age verification. The most common method was the oldest trick in the book: entering a fake birthday. Thirteen percent did that. Nine percent used someone else's login. Eight percent used someone else's device.

And then there are the creative solutions. TechCrunch reported on kids using makeup and drawn-on facial hair to fool selfie-based age estimation. Fortune covered Gen Alpha kids sharing tips on how to pass these checks. Euronews documented the trend spreading across platforms.

This isn't a failure of one company's technology. It's a structural problem. Age estimation tools that rely on facial analysis were never designed to handle people actively trying to fool them. And children, by nature, are motivated problem-solvers when something they want is behind a gate.

Parents are part of the bypass

Here's the number that hit hardest: 26% of parents in the survey said they'd allowed their child to bypass age checks. Seventeen percent actively helped them do it.

That sounds contradictory until you think about how families actually work. A parent sets up a gaming account for their nine-year-old and enters their own birthday so the child can play with friends. A parent lets their twelve-year-old use a messaging app they're technically too young for because it's how the soccer team coordinates. A parent shares their login to a streaming service and doesn't think twice about the age settings.

None of these parents think they're undermining child safety. They're solving the problem in front of them: their kid wants to do the thing their friends are doing, and the age gate feels arbitrary. The law treats all age-gated content as equally risky, so parents who've already decided a particular app is fine for their child see the restriction as an obstacle, not a safeguard.

The result is a system where a quarter of the adults it's designed to empower are actively working around it.

Half of kids still experienced harm in the past month

Despite the safety improvements, 49% of children in the Internet Matters survey said they experienced some form of online harm in the past month. That number didn't budge much from pre-regulation baselines.

The report points to a gap between the harms the law addresses and the harms kids actually describe. The Online Safety Act focuses on illegal content, content harmful to children, and age-inappropriate material. It puts the burden on platforms to identify and remove this content or restrict access to it.

But children told researchers that their biggest day-to-day concern wasn't encountering a specific piece of harmful content. It was the sheer amount of time they spend online and the difficulty of stepping away from it. The law doesn't touch that. It doesn't address addictive design patterns, infinite scroll, or notification systems engineered to pull kids back in. It targets content, not the architecture that keeps children glued to it.

Bitdefender's analysis put it directly: platforms evolve faster than legislation.

AI is creating harms the law didn't anticipate

The Internet Matters report flagged another blind spot: children are regularly encountering AI-generated content they can't distinguish from real content. Deepfake videos, synthetic images, AI-generated audio — these didn't exist at the scale they do now when the law was drafted. The report found that children frequently see AI-generated material and lack the tools to identify it as artificial.

The World Economic Forum's March 2026 analysis ranked online harms as a top-12 global risk over the next two years, with AI-driven harms specifically ranked in the top five over a ten-year horizon. The UN warned in January 2026 about AI being used for automated grooming, deepfake exploitation of minors, and synthetic child sexual abuse material.

None of this falls neatly into the categories the UK law created. The law tells platforms to remove harmful content. But when AI generates harmful content faster than moderators can flag it, and when children can't tell real from synthetic, the removal model starts to crack.

What's happening in the US right now

If you're reading this from the United States, all of this matters because we're walking the same road. As of April 2026, at least 19 states have enacted laws addressing how children access social media, with nearly 300 state-level child safety bills introduced this year alone. Twenty-six states now require age verification to access adult content sites. Virginia's social media restrictions for kids under 16 took effect in January 2026. Massachusetts is moving to ban social media accounts for kids under 14. The federal Kids Online Safety Act was reintroduced in the 119th Congress.

But the enforcement picture is a mess. CNBC reported in March 2026 that the age verification tools spreading across the US come with their own risks — adults are being surveilled in the process. Several state laws are already tied up in court. Georgia's law was enjoined in 2025. Utah's laws remain blocked pending appeal. The patchwork of different state requirements means platforms face contradictory compliance obligations depending on where a user lives.

And the newest frontier — states like Idaho, Oregon, and Washington have started regulating AI companion chatbots for minors, requiring operators to prevent chatbots from claiming sentience or initiating sexual conversations with children. This is important, but it's reactive. These laws respond to documented incidents of harm. They don't prevent the next category of harm we haven't encountered yet.

The FTC issued a COPPA policy statement in February 2026 aimed at encouraging platforms to use age verification — but "encouraging" is doing a lot of heavy lifting in a sentence about protecting children.

What this actually means for your family

The UK report card tells us something parents need to internalize: legislation is necessary, but it is not sufficient. Laws create floors. They set minimums. They give regulators tools to punish bad actors after the fact. What they don't do is sit next to your child at 10pm when the algorithm serves them content they're not ready for.

Here's what the data supports doing right now.

Talk about age verification with your kids before they encounter it. If a third of children are bypassing these checks, your child has either done it or knows someone who has. The conversation isn't "don't lie about your age online" — it's "here's why that age gate exists, here's what's on the other side, and here's what I need you to come to me about."

Audit your own participation. If you've set up accounts using your own birthday, shared logins, or helped your child get around a restriction you thought was silly — you're in the 26%. That doesn't make you a bad parent. But it means the safety system doesn't include your family anymore. Decide intentionally which restrictions to keep and which to override, rather than doing it on autopilot.

Recognize that "more safety features" doesn't mean "safe." Sixty-eight percent of families noticed better reporting tools and content filters. That's progress. But reporting tools work after a child has already seen something. Filters catch known categories of harm. Neither helps with AI-generated content your child can't identify as fake, or the design patterns that make it hard for them to put the phone down.

Build AI literacy into the conversation now. The UK report flagged this as an urgent gap: children are encountering AI-generated content constantly and lack the ability to evaluate what's real. This is a skill you can teach at the dinner table. Pull up a video together and ask: does this look real? What clues tell you it might not be? How would you check? The AACAP's guidance on AI and children offers a good starting framework.

Don't wait for the law to catch up. Regulation moves in years. AI moves in months. Your child's exposure window is measured in minutes. The law will get better — the UK's report is evidence that accountability produces at least partial results. But your family's safety plan can't depend on a timeline you don't control.

The mustache problem isn't about mustaches

A teenager drawing facial hair to trick a camera is funny. It made the rounds on Slashdot and TechCrunch and got the predictable round of "kids are clever" reactions. And they are clever. That's the point.

The assumption underlying every age verification law is that there is a technical barrier children cannot cross. The UK's first year of data says otherwise. Kids are creative, persistent, and motivated. They share workarounds with each other at school. They watch tutorials. They draw mustaches with eyebrow pencils and laugh when it works.

The fix isn't a better mustache detector. The fix is a generation of kids who understand why the gate exists, who have adults they trust enough to talk to about what they find on the other side, and who have been taught to think critically about everything a screen shows them — whether it was made by a person, an algorithm, or an AI they can't tell apart from either.

Laws set the floor. Parents build the house. The UK's report just showed us that the floor has cracks. Let's build anyway.

Digipalz gives kids the tools to think critically, stay safe, and speak up — before they need a crisis line. Learn how it works.