Age Signals (OS-level age signals).
Age signals are age-bracket indicators that an operating system or app store passes to an app through an API, such as under 13 or 18 and over, based on the age declared when the device account was set up.
For a CIAM team, an age signal is a claim, not a profile field. Store it with its provenance (which OS or store sent it, and which API), the time you received it, and the bracket. Then decide how long it stays fresh. A bracket read at install on a shared tablet tells you less a year later than a bracket read at this morning's login. The apex architecture post makes the same point: model the age signal as a claim with provenance, not a column on the user table.
Keep the signal and verification separate. AB 1043's signal is self-declared at device setup. It is good enough to set defaults and to trigger the duties that come with actual knowledge. It is not proof of age for a high-risk feature. When a flow needs stronger assurance, step up to another method and record which method produced the result.
The signal also changes your legal position. Under AB 1043, receiving the signal means you are deemed to know the user's bracket. Once your login or onboarding flow reads it, your consent, data minimization, and parental-consent logic need to act on it. Apple's Declared Age Range API can also signal when parental consent is needed for significant app updates.
Expect more than one method in practice. A September 2026 Biometric Update panel described wallets and mobile driver's licenses as a fast preferred path, with facial age estimation covering everyone else, and orchestration across methods. ISO/IEC 27566-1 is the age assurance standard to track.
Common questions
What is an age signal?
An age signal is an age-bracket value, such as under 13 or 18 and over, that the operating system or app store passes to an app through an API. It comes from the age declared when the device account was set up, so the app does not need to ask for a birthdate.
Is an age signal the same as age verification?
No. Under AB 1043 the age is self-declared at device setup, with no ID or facial check. Treat it as a declared claim from a known source, not as verified age. Stronger methods such as digital wallets, mobile driver's licenses, or facial age estimation sit above it.
What does California AB 1043 require from app developers?
From January 1, 2027, operating system providers must give developers a real-time age signal on download or launch. A developer that receives the signal is deemed to have actual knowledge of the user's age bracket, so it must apply the obligations that come with that knowledge. Penalties reach $7,500 per affected child for intentional violations.
Which platforms offer age signal APIs today?
Apple offers the Declared Age Range API, which returns an age category and can indicate whether regulatory requirements apply. Google offers the Play Age Signals API in beta. It has been live in Brazil since March 17, 2026, and Google said on July 29, 2026 that it will expand to all markets by the end of 2026.
Related terms
In the guides
Customer Onboarding and Progressive Profiling: The Conversion-Aware CIAM Pattern
Every field at signup costs conversion. Progressive profiling defers data collection to the moment of contextual need: better UX, better data quality, better GDPR posture, all at once.
Identity Data Modeling: The Decision You Cannot Cheaply Undo
How to model users, organizations, memberships, and roles in B2B SaaS before the schema locks in, and why a tenant_id column on the user table is the most expensive shortcut in the category.
Identity Verification and Proofing (IDV/KYC): A CIAM Guide for 2026
How to prove a real person matches a claimed identity at signup: document capture, liveness, authoritative-data checks. The 2026 stack, the deepfake escalation, and where CIAM ends.