On August 5, the Senate Commerce Committee voted to advance the CHATBOT Act, a bill that would require age verification for minors using AI-powered chat services. The vote was 14-12, mostly along party lines, and the coverage that followed was predictable: privacy advocates warned of a slippery slope toward national ID, civil libertarians invoked the UK’s Online Safety Act as a cautionary tale, and tech trade groups issued statements about the chilling effect on innovation.

All of that is true, and all of it misses the point.

The real story is not whether the government will soon demand your driver’s license to use a chatbot. The real story is that a sprawling, privately operated identity-verification industry is being built right now—funded by compliance mandates, blessed by regulators, and almost entirely invisible to the public debate about anonymity. The CHATBOT Act is not a speech bill. It is a procurement bill.

The Infrastructure Nobody Is Debating

Consider what actually happens when a platform is told to verify ages. It does not build the technology itself. It contracts with a third-party vendor—Clear, ID.me, Yoti, Incode, or one of a dozen lesser-known firms that have spent the last three years scaling up precisely for this moment. These companies collect government IDs, biometric scans, and device fingerprints, then issue a token that says “this user is over 13” or “over 18” without revealing the underlying data to the platform. The platform gets compliance; the vendor gets a permanent record of who you are and what you do online.

This is not a hypothetical architecture. It is already live across more than two dozen states that have passed age-gating laws for adult content and social media. New York’s Safe By Design Act, signed by Governor Hochul on May 26, extends the logic to a wide range of online services. The CHATBOT Act would add another layer. Each new mandate funnels more users into the same handful of identity providers, and each new user makes those providers’ databases more comprehensive and more valuable.

“The privacy crowd thinks the fight is about whether the government gets to see your ID,” a lobbyist for one of the major identity-verification firms told me, leaning against the bar at the Hamilton Hotel after a Senate hearing last month. “The government doesn’t want to see your ID. It wants us to see your ID, and it wants us to be liable if we get it wrong. That’s the whole business model.”

The UK Already Ran This Experiment

The comparison to the UK is apt, but not for the reasons most American critics think. The UK’s Online Safety Act, amended again this year by the Children’s Wellbeing and Schools Act, does not require users to upload passports to browse the web. What it does is create a regulatory environment in which platforms face enormous fines—up to £18 million or 10% of global turnover—if they fail to protect children. The rational response for any platform is to outsource age assurance to a third party and wash its hands of the liability. Ofcom, the UK regulator, has published detailed guidance on which vendors meet its standards, effectively curating a market.

The result is not a government database of every internet user. It is something more durable: a government-endorsed market for private identity surveillance, with built-in regulatory moats that make it extraordinarily difficult for new entrants to compete. The UK did not nationalize identity. It privatized it, and made the privatization mandatory.

America is following the same playbook, state by state and now bill by bill, with less central coordination but the same structural outcome. The CHATBOT Act’s backers talk about protecting children. The vendors talk about privacy-preserving zero-knowledge proofs. Nobody talks about what happens when three companies hold the identity credentials of 200 million Americans and every online service you use depends on their APIs.

What the Anonymity Debate Overlooks

The predictable right-of-center response to all of this is to defend anonymity as a bulwark against government overreach. It is a principled position, and it is losing. Not because the arguments are weak, but because the infrastructure is being built on an entirely different track—one that does not require winning the philosophical argument about anonymity at all.

By the time a court rules on whether Florida’s age-verification law violates the First Amendment, millions of Floridians will already have uploaded their IDs to comply with it. By the time Congress debates a federal privacy bill that might preempt state age-gating laws, the vendor ecosystem will be entrenched enough to lobby against any provision that threatens its revenue. The infrastructure creates its own constituency, and that constituency does not care about your theory of online speech.

This is the angle the anonymity debate consistently overlooks: the war is not being fought over whether you have a right to be anonymous. It is being fought over who gets paid when you prove you are not. The CHATBOT Act is a skirmish in that larger conflict, and the side that understands the stakes is not the one writing op-eds about Orwell.

The Uncomfortable Question

None of this is to say that age verification is inherently illegitimate, or that protecting children online is a pretext. The harms are real, and the public demand for action is genuine. But the mechanism we are choosing—mandatory third-party identity verification—has consequences that extend far beyond the stated policy goal, and those consequences are being treated as an implementation detail rather than a structural choice.

If you are a conservative who believes in limited government and free markets, you should be deeply uncomfortable with a regulatory regime that effectively designates a handful of private companies as the gatekeepers of online life. If you are a progressive who worries about corporate surveillance, you should be equally alarmed that the compliance layer is being built by firms whose business model depends on collecting and linking identity data across platforms.

And if you are neither, you should at least ask why the most consequential piece of internet infrastructure since the browser is being assembled in committee hearings and vendor RFPs, with almost no public attention to who owns it, who audits it, and what happens when it fails.

The CHATBOT Act will probably pass. The identity-verification industry will grow. Anonymity will become a luxury good, available to those who can afford VPNs and burner phones and the technical sophistication to route around the compliance layer. Everyone else will log in with their face and their government ID, and the platforms will call it safety.

That is not a dystopian prediction. It is a business plan.

Sources