What happens when lawmakers prohibit mandatory digital ID but still make companies responsible for knowing which users are children? The mandate disappears from the text. The pressure to verify everyone remains.
Idaho confronted that problem directly in SB1299. The law establishes six protections designed to keep age verification from becoming permanent digital identity infrastructure. Government cannot require a person to use digital identification. Physical identification must remain valid wherever it is already accepted. A person cannot be forced to surrender, unlock, or provide access to a device. Information used in a transaction cannot be retained, tracked, or repurposed beyond that transaction. A credential cannot quietly become a shared identifier across government agencies. And citizens can enforce those protections themselves rather than depending entirely on a state agency to decide whether a violation deserves action.
That is the standard I used to examine three Arizona bills this session. None met it, but they failed in very different ways.
HB2311 regulated conversational AI services used by minors. The bill began the session with serious digital identity and surveillance problems. Its requirements applied when an operator knew with "actual knowledge or reasonable certainty" that a user was under 18. That language matters. A company facing legal liability for failing to identify a minor will not simply wait for a child to announce his age. It will look for ways to determine age from account information, behavior, language, usage patterns, device signals, or third-party verification services. The bill never needed to say, "Verify every user." Liability could produce the same result. That is how soft digital ID systems are built: government does not always issue a direct command, it establishes penalties for getting the answer wrong and lets companies build the surveillance necessary to protect themselves.
Arizona's Senate recognized part of that danger and added substantial protections. The final bill prohibited operators from conditioning access solely on the use of digital identification, restricted biometric age verification, limited how age-assurance data could be collected, used, retained, and shared, required a probable-cause warrant before government could compel access to compliance data, prohibited operating-system, app-store, and device-level age mandates, and barred the bill from being used as a predicate for broader digital ID requirements or online tracking.
Credit where it's due: Julie Barrett at Conservative Ladies of America mapped this same three-bill comparison first, in a June 12 breakdown of HB2311's amended protections against HB2991's Senate rewrite. My read here confirms her findings against the enacted bill text and extends the comparison to include HB2920.
Those were real improvements, and they also revealed something important: Arizona lawmakers understood that child-safety legislation can become digital identity infrastructure unless the law explicitly blocks it. But the amendments did not remove the underlying requirement that operators distinguish minors from adults with "reasonable certainty." Operators would still have to infer, classify, monitor, or verify users, because the obligations imposed by the law depended on knowing who was a minor.
The formal digital ID mandate was gone.
The compliance pressure remained.
HB2311 therefore did not pass the test. It contained some of the strongest anti-surveillance language considered in Arizona this session, but it surrounded a liability structure that still pushed companies toward age identification. The bill also relied entirely on Attorney General enforcement: families could not sue directly, and total civil penalties against an operator were capped at $500,000.
Governor Katie Hobbs cited those enforcement limitations when she vetoed the bill on June 19. She was right about the enforcement gap, but adding a private right of action would not have cured the age-identification pressure built into the bill. HB2311 had better guardrails than the other Arizona proposals. It was still not a safe bill.
HB2920 took a more direct route: it applied age verification at the app-store level. App stores would determine a user's age category, link minor accounts with parent accounts, obtain parental consent for downloads and purchases, maintain compliance records, and transmit age information to app developers. That architecture reaches far beyond one dangerous platform or one category of content. It creates an identity layer at the entrance to the entire app ecosystem. Before a person downloads a Bible app, banking app, political app, messaging app, game, news service, or social platform, the app store must know whether that person is an adult or a child.
Once that classification exists, it becomes reusable. It can follow the user from the operating system to the app store and from the app store to developers, and each download and consent decision can become part of an ongoing compliance record.
Supporters describe that system as parental empowerment. But parents are not being given better tools to supervise their own children. Technology companies are being ordered to classify every user so government rules can be applied at the account level. That transfers authority upward: parents become the justification for the system, while app stores, verification vendors, developers, and state regulators operate it.
HB2920 did include meaningful enforcement. Parents and minors could bring civil actions, and the Attorney General could pursue substantial penalties, which makes it stronger than a law that leaves every enforcement decision to one elected official. But enforcement cannot repair the architecture. A right to sue after identity data is mishandled does not answer why the state required the identity system to exist in the first place.
HB2920 died in committee without reaching a floor vote. It deserved more scrutiny than it received.
HB2991 began as a narrower parental-oversight bill. The House-passed version gave parents visibility into issues such as usage time, blocked users, and messages from people who were not connected to their children. Those are actual parental tools.
Then the Senate replaced the bill. The rewrite shifted the system toward app stores and operating systems. It required age and parental-consent signals to move through the technology ecosystem and made those signals available to developers on an ongoing basis. That was the exact infrastructure the Senate had just added language to HB2311 to prevent.
HB2311 said its requirements could not be used to force age assurance at the operating-system, device, or app-store level.
HB2991 built age assurance at the operating-system and app-store level.
HB2311 required data minimization, deletion rules, limits on sharing, and warrant protections.
HB2991 lacked equivalent protections.
HB2311 prohibited using its framework as a predicate for broader digital identification.
HB2991 created the predicate.
That is more than an inconsistency between two bills. It shows why policy architecture matters more than legislative labels.
Both bills were described as protecting children, but only one acknowledged that operating-system-level age identification creates unacceptable surveillance risks.
The other required the same infrastructure.
HB2991 also relied on Attorney General enforcement rather than giving families a direct cause of action, combining broad identity infrastructure with weak citizen enforcement. The Senate advanced the rewritten bill through Committee of the Whole in June, but it never received a final vote.
Three Arizona bills approached online child safety from different directions. HB2311 placed meaningful guardrails around privacy and government access, but left a liability structure that pressured companies to identify minors with "reasonable certainty." HB2920 gave families a way to sue, but built age classification into the app-store ecosystem. HB2991 pushed the same architecture into operating systems and app stores while omitting the protections Arizona senators had already recognized as necessary.
The lesson is not that Arizona needed to combine the best pieces of all three bills. The deeper problem is the premise underneath them: to apply special government rules to children online, a platform must first determine who the children are, and to determine who the children are reliably, it must examine, infer, or verify the age of everyone. That is the step lawmakers keep avoiding.
Age verification is not a small feature added to a child-safety bill. It is identity infrastructure. The system may begin with a narrow purpose, but the data, vendors, APIs, account classifications, consent records, and enforcement mechanisms will not remain narrow simply because the legislative findings said the word "children." Once the infrastructure exists, the next bill does not need to create a digital identity system. It only needs to authorize one more use for the system already operating.
Real child protection should strengthen parents. It should give them functional controls, visibility into what their children encounter, meaningful consent tools, and legal standing when companies conceal or cause harm. It should hold platforms accountable for documented misconduct without requiring every American to prove who they are before accessing lawful information.
Parents should not have to surrender everyone's digital anonymity in order to protect their own children.
That is not parental empowerment.
It is government-supervised access to the internet, built one child-safety bill at a time.
This is our read of the bills. We encourage you to read them yourself and reach your own conclusions. The sources are public and cited below.
© 2026 InPublic Systems - All Rights Reserved.
Legislative and policy intelligence for conservative advocacy organizations.
(425) 298-6627