Regulatory Tailwinds Build a Case for Identity Verification Vendors

Regulatory Tailwinds Build a Case for Identity Verification Vendors

By Ian Tang and Kate Lardner
Capstone TMT Analysts
July 23, 2026

    The Bottom Line

      Capstone believes identity verification and infrastructure providers are an attractive investment prospect, as converging regulatory pressure and emerging industry guidelines on children’s privacy, bot prevention, agentic artificial intelligence (AI), and data privacy spur compliance-driven demand for online platforms to verify that users are human and of the required age.

  • Regulatory scrutiny of data privacy, identity security, and children’s safety has intensified as bots, agentic AI, and deepfakes make it difficult for online platforms to distinguish human users from automated ones. These trends have put pressure on platforms to increase their verification capabilities.
  • Converging regulatory concerns will drive demand for identity verification providers, as firms invest in more robust methods of determining user identity. Drivers include children’s online privacy, live events ticketing, access-based litigation against data scrapers, agentic AI, deepfakes, and synthetic fraud.
  • Identity verification providers are well positioned to benefit from regulatory tailwinds despite First Amendment concerns and biometric data regulations that pose moderate risks. While some large platforms have already developed partnerships with vendors, we see the most significant opportunity in mid-sized and smaller online platforms that lack the resources to develop these capabilities in-house.

Overview

As the capabilities of bots (nonhuman automated actors) and agentic AI agents improve, online platforms can no longer assume they know who or what is accessing or using their services. This growing concern has spurred a wave of legal claims, industry standard-setting efforts, legislative action, and agency enforcement aimed at authenticating and controlling access to online platforms and services. Meanwhile, online companies including social media platforms, gaming providers, AI chatbots, video platforms, and app stores face increasing pressure to protect youth user bases from exposure to harmful or explicit content, prompting the platforms to strengthen their age assurance capabilities and feature/content restrictions.

We define the “identity” sector broadly to include companies that verify, secure, and manage access to services or systems through measures such as age verification, biometric authentication, and bot detection. This includes traditional identity and access management providers and a new generation of vendors focused on consumer verification and nonhuman identity. We expect such providers to see increasing opportunities as policy issues and legal uncertainties persist and online platforms scramble to ensure compliance and protect their infrastructure.

Capstone expects opportunities for identity verification providers due to tailwinds from the following policy or regulatory developments:

Children’s online safety: Legal and legislative pressure to ensure children’s online privacy has made platforms more inclined to improve their age assurance and verification capabilities. Children’s online privacy legislation is seen as a priority in Congress and at the state level, bolstered by increasing social media addiction and product liability litigation. States such as Florida and Mississippi have also enacted age verification laws, although legal challenges to these initiatives are ongoing. The EU has taken a centralized approach, ramping up Digital Services Act (DSA) enforcement against Big Tech companies for age verification failures. The EU is also developing an age verification app to protect children from inappropriate content online.

  • Although we believe a platform-level age verification mandate through federal legislation or a court order is unlikely in the US due to First Amendment constraints, we expect platforms to proactively invest in third-party age assurance technology. This would enable them to stay ahead of evolving legal requirements or to age-gate specific features considered riskier if available to younger audiences. For example, in response to litigation pressure, Roblox Corp. (RBLX) recently rolled out a site-wide age estimate feature that uses third-party technology from an identity verification company. Some large platforms have already developed partnerships with third-party vendors, but we believe the most significant opportunity lies with midsize and small online platforms that lack the scale and resources to develop these capabilities in-house.

Adult content: Demand for identity and age assurance services will continue from platforms hosting adult content, given the established constitutionality of age verification mandates in this context. Unlike social media and general online platform age verification mandates, which have faced significant First Amendment and Section 230 headwinds, age verification requirements for adult content have already been deemed constitutional by the US Supreme Court. In Free Speech Coalition v. Paxton (2025), the Court upheld a Texas law requiring internet pornography websites and platforms to verify the age of viewers. The ruling has led other states such as Louisiana to enact similar bills. Capstone expects continued expansion of adult content-specific age verification mandates, especially given the increasing number of AI-generated explicit deepfake images and videos. This trend suggests a legally durable growth driver for identity verification providers given its stronger constitutional grounding.

Real fans and ticket scalping: Concerns regarding live event ticket fraud and inflated prices on the secondary ticket market due to bot activity will increase demand for biometric identity providers and bot detection services. The live events ticketing market, especially the secondary market, has drawn flak as fake ticket sale incidents and excessive prices have angered both industry stakeholders and legislators. In March 2025, President Donald Trump issued an executive order directing the Federal Trade Commission (FTC) to “rigorously enforce” the Better Online Ticket Sales Act of 2016, which prevents ticket resellers from buying concert tickets in bulk and reselling them at higher prices. The FTC has subsequently sued major ticket platforms, including Live Nation Entertainment Inc. (LYV)/Ticketmaster, and exposed other violations. Additionally, bills have been introduced at both the federal and state levels to limit speculative ticketing (i.e., listing tickets without possessing them), a practice often involving bots.

  • Even if ticketing legislation is enacted, softened language and exemptions are likely to limit its impact on bot-driven fraud. Hence, we expect artists and platforms to continue adopting their own verification solutions. Some artists have taken it upon themselves to ensure that ticket buyers are legitimate fans, using tools such as Ticketmaster’s Verified Fan program and other biometric identity products. This presents an opportunity for identity providers.

Data scraping for AI training: Increased access-based litigation against AI companies, and data scrapers will drive demand for bot detection and access-control vendors. Copyright infringement lawsuits against AI platforms over training data have spanned years, with mixed, fact-specific outcomes. Therefore, platforms such as Alphabet Inc. (GOOGL)-owned Google and Reddit Inc. (RDDT) are increasingly shifting litigation focus to access rather than use, via the largely untested Digital Millennium Copyright Act’s (DMCA) anti-circumvention provisions, the Computer Fraud and Abuse Act (CFAA), and breach-of-contract/terms-of-service claims. With this approach, plaintiffs avoid facing fair use defenses as it targets bypassing access controls rather than copying content. Post hiQ Labs v. LinkedIn, scraping publicly available data is considered largely safe, but plaintiffs are now testing whether access controls and technological barriers such as CAPTCHAs (Completely Automated Public Turing test to tell Computers and Humans Apart) and bot-detection systems qualify as “technical protection measures” under the DMCA.

  • Although Capstone believes that plaintiffs’ DMCA theories will be difficult to prove, we expect such litigation to be a tailwind for identity and access-control vendors regardless of how courts rule. To prevail on a DMCA claim, platforms must demonstrate they have implemented effective technological protection measures such as identity verification systems to prevent unauthorized scraping. We expect litigation to drive investment in bot detection, identity verification, and access control systems as platforms seek more visibility into who or what is accessing their services.

AI agents: Abstract legal questions on agentic AI have put pressure on platforms to intensify user verification processes and develop tools to identify AI agents. With the emergence of autonomous AI agents such as Perplexity AI’s Comet that can browse the web and complete tasks on a person’s behalf, platforms may increasingly develop new ways to determine what is accessing a service and at whose instruction. This issue is playing out in Amazon.com Inc.’s (AMZN) November 2025 lawsuit against Perplexity. The lawsuit alleges that the Comet AI shopping agent disguised itself as a regular user to access Amazon’s website without authorization, in violation of the CFAA. In March 2026, a federal judge granted Amazon a preliminary injunction, finding it was likely to prevail on its claims. The matter is stayed while on appeal.

  • Additionally, in June 2026, Senator Mark Warner (D-VA) released a discussion draft of the AI Access, Gatekeeper Exchange, and Nondiscriminatory Transfer Act, which would require online platforms to grant access to authorized AI agents, opening up the marketplace for agentic AI. A final decision in the Amazon v. Perplexity case may be years away, and we expect regulation on agentic AI to lag, but industry stakeholders are beginning to fill the gap. Not only are platforms increasingly investing in ways to verify users’ humanity, but companies that manage logins and identity verification are also developing capabilities to verify the legitimacy of AI agents, expanding the definition of a “user.”

Deepfakes: The rise of deepfake images and synthetic identity fraud has accelerated demand for more advanced verification technology. Fueled by concerns about their own digital likeness, members of Congress, as well as industry, have taken notice of AI output-side harms including deepfakes and violations of the right of publicity. For example, ByteDance’s release of Seedance prompted a strong response from film studios on the unauthorized use of likeness. Similarly, the Nurture Originals, Foster Art, and Keep Entertainment Safe (NO FAKES) Act of 2026, pending in the Senate, would establish a federal right for individuals to protect their own image and likeness against unauthorized AI-generated replicas. The Stop Identity Fraud and Identity Theft Act of 2026, introduced in January, would direct the Treasury Department to help states modernize their identity systems and digital IDs to reduce identity fraud. We expect this growing policy attention, along with rising fraud rates, to create an opportunity for identity vendors.

Capstone identifies the following as policy or regulatory risks for investors in the identity space:

Companies that collect biometric data from Illinois residents without consent or notifying them face litigation risk under the state’s Biometric Information Privacy Act (BIPA). The 2008 law requires companies collecting biometric data to inform individuals about the data being collected and obtain their written consent. BIPA contains provisions for a private right of action, allowing individuals to sue directly and seek statutory damages of $1,000-$5,000 per violation even if there was no actual harm. The statute has been aggressively enforced, generating over $1.5 billion in settlements since 2008, although a 2024 amendment now caps repeated collections from the same individual as a single violation.

  • Companies collecting biometric data that maintain consistent, clear consent processes and transparency policies are largely shielded from litigation risk. However, companies without proper BIPA compliance systems in place are vulnerable to fines.

First Amendment challnges may complicate the implementation of age and identity verification requirements. Policymakers have struggled to craft age-verification mandates without running into First Amendment concerns. Several state laws, including those in Arkansas, Utah, Texas, Mississippi, and California, have faced court challenges on constitutional grounds from industry groups such as NetChoice and the Chamber of Progress. Although the US Supreme Court denied NetChoice’s request to temporarily block Mississippi’s Walker Montgomery Protecting Children Online Act (HB 1126), a 2024 statute imposing age verification requirements, Justice Brett Kavanaugh said in a concurring opinion in that decision that the statute would “likely violate its members’ First Amendment rights.” This roadblock will continue to complicate efforts at both the state and federal levels to require age gating, although some platforms have implemented these measures voluntarily to minimize exposure to product liability litigation.

User hesitation to undergo identity verification could narrow customer pools. If Congress enacts a measure requiring online platforms to implement strict age verification measures, we expect a sizable number of adult users would stop using the services. Surveys estimate that 32% of US adults are opposed to using a digital identity, a reluctance also reflected in the aftermath of Roblox’s voluntary implementation of age verification measures, where only 51% of global daily active users completed the proactive age checks.

Market Dynamics

With regulations on children’s online safety and data privacy intensifying, the age assurance solutions market, spanning passive age estimate products and active biometric-based age verification tools, is projected to record 17.3% CAGR during 2025-2030 (see Exhibit 1). We expect both established identity verification vendors and emerging entrants to be well positioned to capture share in this quick-moving market.

Exhibit 1: Forecast of Global Third-party Age Assurance Solutions Market Growth, in $B

Source: Liminal

Read more from Capstone’s TMT team:
Why DMCA Claims Against Web Scrapers Face Long Odds
AI-Resistant Moats for Established Software Providers
Which Subscription-Reliant Firms Will Face Risks Under Potential FTC Rule

Have a question?

We want to hear from you. Let us know your question and a research analyst will get back to you promptly. We love to discuss our research.

Connect

Our Latest Insights

Federal Agency Actions Provide Clues to Future Star Ratings Reforms

Federal Agency Actions Provide Clues to Future Star Ratings Reforms

The Medicare Advantage (MA) Star Ratings program has served as the primary quality measurement mechanism for MA since 2012. It determines which plans earn a Quality Bonus Payment (QBP) and how much rebate funding they have available to build competitive supplemental...

5 Key Takeaways from HLTH Europe 2026

5 Key Takeaways from HLTH Europe 2026

1. The Future of AI Is Enablement, Not Replacement AI continues to be a major topic and, while players noted both real disintermediation risk and potential for new opportunities, two key themes emerged around the future of AI. First, the name of the game is...