Three of the four biggest gaming platforms now ask British players to prove their age before they can look at a mature-rated game. Xbox, PlayStation and Steam have all rolled out checks to satisfy the UK’s Online Safety Act. On Steam the proof is a credit card with your name and address on it — and the interesting part is not that the check exists, but what each platform decided to ask you for.
Clicking “Yes, I’m 18” no longer satisfies UK law. Ofcom’s guidance calls for verification that is highly effective, and a self-declared tick box is not. Something had to replace it. What replaced it is a question about identity, and different companies answered that question very differently.
What Steam actually asks for
Valve’s implementation is narrow. To view or buy mature-rated titles from the UK, your Steam account needs a valid credit card carrying your name and address. If you already had one linked — and most paying customers do — you were verified silently and probably never noticed. If you did not, the store pages simply stopped loading until you added one.
The logic is that credit cards are issued only to adults, so the bank has already done the age check and Valve can lean on it. That has a real privacy advantage worth acknowledging: Valve never handles your passport, your driving licence, or your face. It asks a question the payment network has already answered.
Compare that with the alternative that has become common elsewhere — uploading a photograph of a government ID, or submitting to a facial age estimate. Those systems require you to hand a document or a biometric to a company, or more often to a third-party vendor you have never heard of and did not choose. Valve’s approach avoids creating that pile of documents entirely. Given the options available, it is the less invasive design.
Every age check is really a question about how much identity the internet is allowed to demand before it shows you a page.
A proxy is not a check
The trouble with using a credit card as a stand-in for age is that it measures something else. It measures whether you have a credit card.
Those are not the same population. Plenty of adults bank exclusively with debit cards, prepaid accounts, or app-based providers that never issue credit. They are over eighteen and they cannot prove it to Steam. There is no appeal to a proxy: either the card exists or the store page stays dark.
Developers noticed the effect quickly. Several makers of mature-rated indie games reported their UK visibility falling after the requirement landed, with one developer describing a 35% drop in UK page views in the week that followed. That is the part people miss when they discuss age checks purely as a child-safety measure. A gate on a storefront is also a gate on a small studio’s discoverability, and small studios do not have the marketing budget to route around it.
This sits alongside a separate change on 16 July, when Steam updated its publishing rules to prohibit content that breaches the standards of its payment processors. Some adult-oriented games were removed. Two different mechanisms — one regulatory, one commercial — ended up pointing the same direction, which is why the reaction from players merged them into a single grievance and why campaigns were aimed at the card networks as much as at Valve.
The pattern is global now, and predictable
The UK went first, in July 2025. Others followed, and the sequence has been remarkably consistent each time.
- United Kingdom — age checks took effect 25 July 2025. VPN downloads in the country surged into the millions, and forum discussion about working around the rules jumped sharply in the following weeks.
- Brazil — mandatory verification went live 17 March 2026. Proton reported Brazilian sign-ups rising roughly 250% in a single day.
- Australia — restrictions arrived in March 2026, and VPN downloads in the country reportedly close to tripled.
Researchers tracking public discussion between May 2025 and April 2026 found threads about circumventing age checks growing from a single thread to dozens per month. The consistent finding across all of it is that the laws changed behaviour more than they changed access — and that a large share of the objection was not from people trying to reach adult content at all. It was from adults who did not want to attach their legal identity to their browsing in order to prove a fact about their birthday.
Now the tools themselves are in scope
Which brings us to the part we have an obvious stake in, so we will be direct about the bias before making the argument.
Regulators and research bodies in the UK and EU have started describing VPNs as a loophole in age verification, and there is active discussion about whether circumvention tools should fall within the scope of these rules. One VPN developer reportedly saw downloads climb by around 1,800% in the first month after the UK Act took effect, and numbers like that are exactly what draws regulatory attention.
We think the framing is wrong, and not only because of where we sit. A VPN is general-purpose network infrastructure. The same encrypted tunnel that annoys a regulator is what protects a journalist on hotel Wi-Fi, a remote worker on a shared office network, and an ordinary person whose internet provider would otherwise log and monetise every domain they visit. Treating the tunnel as a circumvention device because some people use it for circumvention is the same reasoning that would treat a car as a getaway vehicle.
What a VPN does not do here
We are not going to sell you something that is not true, so let us be plain about it.
A VPN does not make you eighteen, and it does not defeat an age check that is anchored to a payment method. Steam is not asking where you are. It is asking for a card in your name. Changing the country your traffic appears to come from does not produce a card, and we would not suggest using one to misrepresent your age to a platform that is legally obliged to ask.
It also does not undo what you hand over voluntarily. Once you log into an account and enter card details, that service knows exactly who you are, whatever route your packets took to get there. Encryption protects data in transit. It does not protect data you typed into a form.
What a VPN is genuinely good at is narrower and more useful than the marketing usually suggests: it stops the networks between you and a service — your ISP, the café router, the hotel gateway — from reading or recording which services you connect to, and it stops those services from seeing your home IP address. On a shared or hostile network, and against ISP-level tracking, that is the whole benefit, and it is a real one.
The question worth asking about any age check
Age verification on gaming platforms is not going away; if anything the list of countries requiring it will be longer in a year. So the useful question is not whether to accept it, but which implementations deserve trust.
When a service asks you to verify, look at three things. What is it asking for — a bank-mediated signal, a document scan, or a biometric? Those carry wildly different consequences if breached; a card token is replaceable, your face is not. Who receives it — the platform itself, or an outsourced vendor whose name appears in no privacy policy you have read? How long is it kept — a check that verifies and discards is a fundamentally different product from one that builds a permanent identity file.
Judged that way, Valve’s credit-card route is clumsy, exclusionary to people without credit, and bad for small developers selling mature games. It is also, on the specific axis of how much personal data it accumulates, one of the better implementations currently deployed. Both of those things are true, and the debate would be more useful if it held them at the same time.