Comment on
[EU 'age verification'] [Spec]: Proposal to introduce a mandatory alternative that does not require a specific OS.
This sounds like OpenID with extra steps. A signed JWT could serve the same purpose without reinventing the wheel and inherit all privacy and scope controls out of the box. For example, a site can send a userid and challenge that I hash before authorising my identity provider to attach a signed age attestation to. Provider can't see the hash contents and the site only gets to see the pre-verified age in the JWT and nothing else identifiable (could even be a regional yes/no of-age value or content flags).
All that said, you'd be hard pressed to find any company that wouldn't immediately regect something that could not be collected, sold, or abused. The law was never about the children in the first place and they're not about to have a change of heart on that any time soon.