Texas, Utah and Louisiana now require app stores to check your teen's age and collect your approval for every download and every in-app purchase. California joins on January 1, 2027. The Supreme Court declined to block the Texas law on May 28, 2026, so the prompts landing on your phone this school year are permanent rather than provisional. The gate decides which apps your teen installs and which charges clear. It sees nothing that happens inside an app you already approved: the hacked-friend DM, the trade offer, the job that pays in gift cards. A 14-year-old still answers those alone.

What the law changed on your teen's phone

Four states passed App Store Accountability Acts. Three of them govern devices in your house today.

  • 1
    Texas SB 2420, effective January 1, 2026. App stores verify age, link every minor account to a parent account, and collect consent per transaction.
  • 2
    Utah SB 142, effective May 7, 2026. Same structure, same consent requirement.
  • 3
    Louisiana, effective July 1, 2026. Same structure.
  • 4
    California AB 1043, effective January 1, 2027. A narrower rule. The store collects an age signal at account setup and passes it to developers, with no per-download consent step.

All four sort users into the same four buckets: under 13, 13 to 15, 16 to 17, and adult. Developers read that bucket through a store API and adjust what the app shows. In the three active states the store must also ask you before each download, each app purchase, and each in-app purchase. Bundled or one-time blanket consent does not satisfy the statute. Apple handles the approvals through Family Sharing and Ask to Buy; Google routes them through supervised accounts described in its parent guide to Google Play.

The legal fight is still running. A federal judge blocked the Texas law in December 2025 on First Amendment grounds. The Fifth Circuit allowed enforcement in late May 2026, and the Supreme Court declined to intervene on May 28, 2026, per reporting from the Texas Tribune. Plan around a system that stays.

The purchase gate does real work

Give the laws credit where the evidence supports it. Per-purchase approval attacks a documented harm. The FTC ordered Epic Games to pay $245 million over purchase flows that charged players, many of them children, for items they never meant to buy. A single confirmation button that a parent controls removes most of that surface.

Two spending patterns we cover in detail get weaker under this rule: the variable-reward loop that drives Robux overspending, and the free trial that renews into a subscription the family forgot about. Both depend on a frictionless charge. The consent prompt adds friction at the exact moment it helps.

The second benefit is quieter. Linking the accounts produces a list of what your teen has installed. Most parents have never seen that list.

The gate fires at installation and at checkout. Nothing about a message, a friend request, a link, a voice note, or a group chat crosses that line. If the risk arrives inside an app your teen already has, no state law in the country generates a prompt.

The scam arrives after the gate

Picture a Tuesday in October. Discord went through approval in March. At 9:47 PM an account your teen has shared a server with for two years sends a message: help me win this tournament, vote here, takes ten seconds. The account belongs to a real friend whose password leaked last week. The link opens in a browser. Your teen signs in to a page that looks like the login screen from an hour ago.

Nothing in that sequence is an install. Nothing is a purchase. The app store never learns it happened.

That shape covers most of what costs teens money and account access:

  • 1
    The hacked-friend link. Trust comes pre-loaded because the sender is real. Walk the chain in our first-30-minutes response guide.
  • 2
    The trade or giveaway offer. A quitting player hands over an account full of Limiteds, and the verification step drains the teen's inventory instead.
  • 3
    The job that pays for a favor. Money lands in the teen's account with instructions to forward most of it. We break down how money-mule recruitment reaches teens and why the bank calls the teen first.
  • 4
    The recovery scam. After a first loss, a stranger offers to get the account or the money back for a fee. The second loss usually exceeds the first.

The scale is in federal data. In an April 2026 data spotlight, the FTC put 2025 losses to scams that began on social media at $2.1 billion, against $261 million in 2020. Social media was the contact method in close to 30% of all fraud reports. More than 40% of people who lost money on those platforms said it started when they ordered something from an ad. Every one of those contacts happened inside an installed app.

Teens route around perimeters

An old phone in a drawer signs into a different account. A sibling's login skips the family group. The browser version of a service loads without any store involvement. A second account created on school wifi never touches the parent link at all.

None of this makes teenagers devious. A gate that costs 30 seconds to bypass gets bypassed by a bored 15-year-old on a Sunday. Keep the perimeter and stop treating it as the plan.

Consent fatigue is the failure nobody legislated

Per-download consent with no bundling has a predictable arithmetic problem. A teen setting up a school year installs a dozen apps in a week: a class tool, two group chats, a scheduling app, three games their friends already play. You approve the first three after looking. By the eighth prompt you approve from the lock screen while making dinner.

At that point the approval still satisfies the statute and tells you nothing. The signature survives; the judgment behind it is gone. Two questions restore it, and they cost about twenty seconds: what is this app for, and who is already in there with you?

Five things worth doing this month

  • 1
    Finish the account link. Many families stop at the first prompt and never complete the family group, which leaves the teen device in a half-configured state. Set it up fully on Apple or Google in one sitting.
  • 2
    Read the installed-app list with your teen, not about them. Ask which ones they use daily. The three they forgot they had are the interesting part.
  • 3
    Take the stored card off the teen account. Purchase approval protects more than install approval, and a saved card undermines it.
  • 4
    Agree on an amnesty rule now. Anything shown to you before money or credentials move gets no punishment. Teens hide the first loss, and hiding it is what turns one loss into a recovery scam.
  • 5
    Run one scenario together this week. Fifteen minutes of practice with a real scam pattern beats a lecture your teen has already tuned out. The FTC keeps a plain-language reference on recognizing phishing and on protecting kids online.

Let your teen meet the message before a scammer does

A friend's account sends a link at 9:47 PM. The LifeQuest scenario puts your teen inside that chat with the same three seconds of social pressure and lets them find out what each answer costs. Free, no signup, plays in a browser.

Play the free scenario

The part the law cannot reach

Age verification sorts your teen into a bucket labeled 13 to 15 or 16 to 17, then hands them a phone. Inside the approved apps they get the same messages, the same offers, and the same pressure as anyone else. Judgment is the remaining variable, and no statute produces it.

The tools built to teach that judgment aim younger than most parents realize. Google's own documentation places Interland with children aged 7 to 12, and the alternatives in that category follow: quizzes, badges, cartoon islands. A ninth grader opens one, recognizes the register within seconds, and closes it. We mapped the gap and the options in our guide to safety tools built for ages 13 to 17.

LifeQuest works the other way around. Your teen plays a five-minute branching scenario where a friend's hacked account, a fake recruiter, or a group chat applies pressure in real time. They choose. The consequence lands on screen. Nothing about their choices reports back to you, which is the reason they keep playing, and it puts LifeQuest in a different category from the monitoring apps parents usually compare. Browse the full online safety world to see the scenario library.

Keep the age gate. Approve the downloads. Then spend fifteen minutes on the part the gate was never built to cover.

FAQ

Which states require app store age verification in 2026?

Texas SB 2420 took effect January 1, 2026, Utah SB 142 on May 7, 2026, and Louisiana on July 1, 2026. California AB 1043 follows on January 1, 2027 with a narrower age-signal rule and no per-download consent step.

Does app store age verification stop scams inside apps?

No. The check happens at installation and at checkout. A phishing DM from a friend's hacked account, a trade offer, a fake job pitch, or a deepfake in a group chat all arrive inside an app you already approved, and none of them trigger a prompt.

Do I have to approve every single download?

In Texas, Utah and Louisiana, yes. Those statutes require consent for each download, each app purchase and each in-app purchase, and they do not permit one-time or bundled consent. Apple uses Family Sharing and Ask to Buy; Google uses supervised accounts in Google Play.

Can my teenager get around app store age verification?

Often. An older device on a different account, a sibling's login, the browser version of the same service, or a second account created outside the family group all bypass the store-level check. Treat it as a boundary on installation rather than a guarantee about what your teen sees.

What should I do instead of relying on the age gate?

Finish the family link, review installed apps together, remove stored cards from the teen account, agree on an amnesty rule for reporting a mistake, and give your teen supervised practice with the pressure patterns scammers use. Judgment inside an approved app is the part no store policy covers.

Sources