12 min read

When Visa and Mastercard Became the Internet's Age Gate: Why 'Add a Credit Card' Is Not an Age-Assurance Strategy

In 2025, Steam and itch.io pulled or hid adult content not because a law told them to, but because their payment processors did. Card networks have quietly become the most powerful age-and-content regulator online — with no statute and a kill switch. And the reflexive platform response, 'make users put a credit card on file,' fails as age assurance on every axis. Here's why, and what to build instead.

An abstract payment-card rail acting as a gate in front of a stream of platform content, illustrating how card networks have become a de facto age and content regulator that platforms try to satisfy with a single credit-card-on-file checkbox

In the summer of 2025, two of the largest distribution platforms for independent games changed their content policies within days of each other — and neither change was ordered by a court, a parliament, or a regulator. On July 15, Valve began pulling adult-themed titles from Steam, telling developers the games “may violate the rules and standards” of its payment processors. A week and a half later, itch.io deindexed all adult NSFW content from its browse and search pages, stating plainly that its ability to process payments through Stripe and PayPal was “critical for every creator on the platform” and that it had to “prioritize” that relationship. The trigger in both cases was a campaign by an advocacy group, Collective Shout, that wrote not to the platforms but to Visa, Mastercard, and PayPal.

That is the part worth sitting with. The most consequential age-and-content decision made about these platforms in 2025 was made by the companies that move the money, not by anyone with a mandate to govern speech or protect children. Card networks have become the internet’s de facto age regulator — and unlike a statute, their rules come with no published threshold, no appeals process, and a remedy more severe than any fine: offboarding from the payment rail, which for most consumer platforms is an extinction event.

This post is about that shift, and about the reflexive response it has produced in compliance teams everywhere — “just make users register a credit card” — which is the wrong fix whether you measure it against the law, against the card networks’ own programs, or against the user you are trying to verify.

Two Regulators, One Checkbox

Every consumer platform that touches age-restricted content now sits between two pressures that have converged on the same demand from opposite directions.

On one side is statutory age-assurance law: the UK’s Online Safety Act and Ofcom’s “highly effective age assurance” standard, the US patchwork of state laws, the EU’s evolving regime. These tell you that you must verify age and that weak methods — self-declaration, an unverified date-of-birth field — do not count. Ofcom and the ICO reinforced exactly this in their March 25, 2026 joint statement: age assurance must be risk-based and technology-neutral, and “self-declaration alone is not considered effective.”

On the other side is a set of private contractual regimes that most engineers have never read but that bind every platform with a checkout: Mastercard’s adult-content standards (in force since October 2021) and its broader Business Risk Assessment and Mitigation program, and Visa’s Integrity Risk Program (VIRP). These require acquirers to monitor, manage, and if necessary offboard any merchant whose content poses a legal or brand-reputation risk, and they impose documented age and identity verification obligations on adult merchants. They are not laws. They are terms of access to the only payment infrastructure that matters at scale.

Both pressures say the same three words — verify user age — and platforms, under-resourced and frightened of losing their payment rail, are trying to satisfy both with a single, cheap signal: a card on file. Steam’s UK implementation, rolled out August 29, 2025, is the canonical example. To unlock “mature content,” a UK user must add a credit card to their account and clear a £0 authorization. One checkbox, aimed at two very different regulators. It satisfies neither well.

How a Payment Rail Became a Content Policy

The mechanism is worth understanding precisely, because it explains why this lever is so much sharper than legislation.

A platform does not connect to Visa or Mastercard directly. It connects to an acquiring bank, which is contractually responsible to the networks for the merchants in its portfolio. When a campaign flags a platform’s content to the networks, the pressure flows downhill: the network reminds the acquirer of its brand-risk obligations, and the acquirer — facing its own fines and the threat to its network membership — leans on the merchant. The merchant’s choice is not “comply or pay a penalty.” It is “comply or lose the ability to take payments at all.” For Steam, itch.io, Patreon, Gumroad, or any platform whose entire revenue runs over those rails, that is not a negotiation.

This is why the 2025 purges looked nothing like legal enforcement. There was no notice-and-comment, no defined category of prohibited content published in advance, no proportionate remedy, and no neutral arbiter. Mastercard, for its part, has publicly maintained that it does not change its policies to target lawful content and does not direct which legal goods a merchant may sell — and the structural point holds regardless of which side you believe about motive. Whether the networks are enforcing a narrow rule against illegal material or, as critics argue, functioning as a morality regulator by proxy, the leverage is the same and the due process is absent. A private risk program, triggered by an advocacy letter, reshaped what millions of adults could buy, with the platforms absorbing the blame and the card networks bearing none of the governance burden.

Two details from the same episode show how blunt the instrument is. First, the Steam and itch.io sweeps caught a swath of LGBTQ+ and entirely legal content alongside the material that was actually targeted, because “brand risk” is a far wider net than “illegal.” Second, within days of Steam’s UK credit-card gate going live, users had already published bypass methods. A control that over-blocks legitimate content while under-blocking the determined teenager is the worst of both worlds — and it is the predictable result of bolting an age policy onto a payment instrument.

Why “Card on File” Fails as Age Assurance

Set aside the politics and evaluate the credit-card-as-age-gate purely as engineering. It fails on four independent grounds.

It is a payment instrument, not a proof of age. A card answers “can this account move money,” which is a different question from “is this human an adult,” with different failure modes. We made the full version of this argument in a credit card is not proof of age, and the core point is jurisdictional: the UK can lean on credit cards because UK card issuers require holders to be 18+, which is why Ofcom lists a credit-card check as one acceptable method. That property does not travel. In the United States, a minor can be an authorized user on a parent’s card and can hold a debit card at any age, so “card on file” carries no reliable age signal at all. A method that only works in one country because of a local banking quirk is not an age-assurance strategy; it is a coincidence you are renting.

It is exclusionary. Gating adult access behind credit-card ownership locks out the large population of adults who are unbanked, debit-only, or simply choose not to keep a card on a gaming account. You have not built an age check; you have built a wealth-and-banking-status check that happens to correlate loosely with age. That is precisely the kind of accessibility and drop-off failure that converts verified adults into abandoned sessions.

It conflates the wrong identity. Binding age to a payment method means a shared card, a family card, or a borrowed card silently grants access to whoever holds it — no liveness, no binding to the person actually in the session. The bypasses that appeared on Steam within days exploited exactly this gap.

And it does not even satisfy the card networks’ own programs. This is the irony most platforms miss. The Visa and Mastercard adult-content rules do not ask for consumer card-on-file; they demand documented age and identity verification of the people depicted in and uploading content, content review before publication, and complaint-and-takedown processes. Asking a buyer to register a card does nothing for those obligations. Platforms are deploying a control that addresses neither the statute nor the contract — purely as a panic response to the threat of deplatforming.

The Real Problem: You Outsourced Your Age Layer to Your Acquirer

Step back and the deeper issue is structural, not tactical. The reason Steam and itch.io were so exposed in 2025 is that their only mechanism for reasoning about whether a user is an adult was tied to payment. When your single age signal lives inside the checkout, the entity that controls the checkout controls your content and identity policy. You have outsourced one of your most important trust-and-safety functions to your acquiring bank, and you discover the terms of that arrangement only when a letter lands on a network’s desk.

A platform with an independent, robust age-assurance layer is in a categorically different position. It can answer the regulator’s question (“are minors kept out of adult content by a highly effective method?”) and the acquirer’s question (“is your age gating genuine, or a checkbox?”) with the same defensible evidence — and it can do so without making payment a prerequisite to browse, and without handing a single private intermediary a veto over what its adult users may access. The goal is not to defeat the card networks. It is to stop being hostage to them because age verification was never a capability you owned.

Decouple Age From Payment

What does owning that layer actually look like? Four properties, each of which the card-on-file approach lacks.

Age is verified as its own step, not inferred from a transaction. The user proves an age band because the platform asked them to, through a method built for that purpose — not as a side effect of entering card details. This is the only way to satisfy a regulator that has explicitly said payment-adjacent self-declaration is insufficient.

The method scales by risk. The vast majority of users clear a threshold with privacy-preserving facial age estimation that returns an age band, not an identity. Only users who land near the threshold get escalated to stronger evidence — a document scan or an NFC chip read of an ID — so the friction lands where it is actuarially warranted instead of taxing everyone with a card-entry wall.

The sensitive computation stays off your infrastructure. On-device age estimation means the platform never receives the face image; the estimate is produced on the user’s device and only a result crosses the wire. You retain the decision — an auditable record that a check happened and what it concluded — not the documents or biometrics behind it, which is the privacy-first posture that keeps you from becoming a breach liability while still giving an acquirer or regulator the evidence trail they want.

And the proof is reusable. A reusable, bound age credential lets a user who verified once present that proof again without repeating the whole flow, which is what keeps a real age gate from cratering conversion the way a credit-card wall does. Verify the person, not the payment, and you can prove adulthood on a free account, a debit purchase, or no purchase at all.

The Honest Limits

Intellectual honesty requires naming what age assurance does not solve. The Steam and itch.io purges were not, at root, about age — they were about content categories that the networks deemed brand-damaging, and a perfectly age-gated platform can still have an entire content vertical objected to. Robust age verification will not make a card network comfortable with material it has decided it does not want on its rails. That is a separate fight, and it is genuinely unresolved: the concentration of two companies’ control over the internet’s payment layer is a competition-and-governance problem that age technology cannot fix.

But “it doesn’t solve everything” is not “it doesn’t matter.” The single most powerful lever campaigns like Collective Shout pulled was the claim that platforms exposed minors to adult content. A genuine, demonstrable age-assurance layer removes that lever — the most damaging and most frequently true one — and converts the conversation from “you are endangering children” to “adults are accessing adult content through a verified gate.” It moves you from the position itch.io was in, with nothing to point to but a payment relationship, to a position where you have an independent, auditable answer. It strengthens your standing with regulators and acquirers alike. It does not make you immune; it makes you defensible, which is the most any platform in this environment can realistically be.

How Xident Fits

Xident was built to be the age layer a platform owns, precisely so that age assurance is never something you have to borrow from your payment processor. We verify age as a first-class step, not a byproduct of checkout, so the result satisfies a regulator that has ruled card-adjacent self-declaration insufficient. We classify across bands (+12, +15, +18, +21, +25) rather than a single binary wall, so the same integration serves a 13+ access rule and an 18+ content gate. Most users clear the threshold with on-device facial age estimation that never sends a face image to your servers, with a buffer-zone step-up to document or NFC verification only near the line. We retain the decision, not the documents — an exportable, auditable record of what was verified and when — which is the evidence an acquirer’s brand-risk review or an Ofcom information request actually asks for. And because the output is a reusable, bound credential, a user verifies once and presents that proof anywhere, so a real age gate doesn’t behave like the credit-card wall that locks out every adult without a card on file.

If you are weighing how to meet a statutory age-assurance duty and withstand payment-processor scrutiny without conflating the two, our vendor security checklist walks through the questions that separate a check you can defend from one that just clears a demo.

The lesson of 2025 is not that card networks are villains or saviors — it is that a platform with no age capability of its own will have that capability supplied, on someone else’s terms, at the worst possible moment. Steam reached for a credit card because it had nothing else to reach for. Build the age layer you own, keep it independent of the payment rail, and the next time a letter lands on an acquirer’s desk, you will have an answer that belongs to you.

If you operate a platform that needs an age check decoupled from its checkout, start here.

Share this article

Ready to implement age verification?

Get started in minutes with our simple SDK. Free trial includes 100 verifications.

Book a 20-minute demo