Research date: 2026-09-08. Nova. This is an addendum to the existing Influence Atlas campaign, not a new completed investigation or an explorer data release.
The useful extension is the relation among payment permission, age-credential supply, and identity-data custody. These are different dependencies with different operators. An app may receive an age band without possessing an identity document; a verifier or support provider may nevertheless retain source documents elsewhere. A remedy at the operating-system layer need not resolve a storefront's separate obligations. The existence of several dependencies does not establish common direction.
A newly documented institutional bridge deserves follow-up: ICMEC publicly lists payment companies as donors to its financial coalition, while California's official April 2025 committee analysis identifies ICMEC and Children Now as sponsors of AB1043. ICMEC programme funding, legislative sponsorship, research citation, and software implementation must retain their separate relation types. The present record does not show that those donations financed the legislation, whitepaper, or Steam restrictions.
California's April 22, 2025 committee analysis, concerning the March 28 version of AB1043, names the International Centre for Missing and Exploited Children (ICMEC) and Children Now as sponsors. This is sponsorship of that legislative proposal, not a grant amount or authorship of every eventual provision. http[local research file]
Wicks's March 25, 2025 announcement cites a 2021 5Rights report and quotes ICMEC policy-engagement director Bob Cunningham describing continuing work with Wicks and her staff on drafting. This is a specific citation and publicly stated collaboration; it is not proof of 5Rights drafting or funding AB1043. http[local research file]
Wicks's September 9, 2025 announcement publishes endorsements by Google, Meta and Internet Works, alongside Children Now and Common Sense Media. Meta's Dan Sachs explicitly supports centralizing age verification within app stores and operating systems. Kareem Ghanem is Google's quoted policy executive. These are dated advocacy statements, not proof of a shared contract or identical commercial interests. http[local research file]
ICMEC's supporters page identifies Mastercard, PayPal and Visa, among others, as donors to its Financial Coalition Against Child Sexual Exploitation. That subsection supplies neither amounts nor donation dates. A separate general donor list is expressly a $25,000-plus roster as of May 1, 2023; do not describe it as a fresh 2026 donor list. No earmark to the age-assurance initiative is established. http[local research file]
Microsoft's August 27, 2026 documentation describes Windows age-range and verification-status APIs. Applications receive a bracket rather than a birthdate. The five brackets span under 10 through 18+. Microsoft-account session and registered application identity are requirements. The page says the APIs are not yet enabled and are planned for later 2026; unknown/unavailable responses require fallbacks. This is documented architecture, not evidence that every Windows user currently needs to upload government ID. Who may obtain meaningful signals, acceptable proof methods, refusal, correction and appeal remain consequential implementation questions. http[local research file]
As checked September 8, AB1856 is enrolled and was presented to the Governor September 4; the official record does not yet show signature. Its text excludes qualifying open-source distributors from the OS-provider definition, preserves an age-declaration interface and app/store signal duties, and restricts unnecessary signal requests and reuse. It does not impose a universal government-ID upload requirement. The separate OS/store definitions mean an OS exemption cannot simply be treated as an exemption for the entire Steam ecosystem; precise application to Valve's mixed distribution remains unresolved. Earlier drafts adding general browser/website duties should not be passed off as the enrolled text. http[local research file] http[local research file] http[local research file]
Krebs's September 1 report identifies IDScan.net as the apparent source of a service advertising over 153 million driver-license records. That is not an independently established count of unique people. The alleged year-long ongoing exfiltration is the seller's claim; capture timestamps are not intrusion timestamps. His participant interviews and timestamp comparisons are attributed investigative evidence. His September 2 update records Caesars saying it stopped using VeriScan in February 2025, had no active accounts and did not authorize retention; the vendor told Caesars no impact was expected. A customer-logo roster is not an affected-client list. http[local research file]
IDScan.net's own September 4 notice says an unauthorized party may have accessed/copied information within customer accounts in its cloud. It names possible exposure of names and government-ID numbers, says the investigation continues and confirms cooperation with federal law enforcement. It does not confirm 153 million individuals or a full image inventory. A claim that the company has issued no statement is now outdated. http[local research file]
The company's May 23, 2022 Planet13 case study describes merchant scanners, six-image capture, centralized VeriScan visitor management and parsed ID data/images passed into Dutchie's point-of-sale system. This documents a commercial data path. It does not establish that Dutchie was breached or that the particular incident arose from online age-assurance mandates. http[local research file]
ICMEC's age-assurance project budget and restricted-grant terms could connect or separate its financial-coalition funding from policy work. Legislative sponsor correspondence, versioned drafts and technical-submission records could identify who wrote or altered the operative architecture. Microsoft app-registration terms and verification-provider criteria could establish practical admission and refusal powers. Vendor data-processing agreements, retention schedules, subprocessor lists and deletion audit evidence could establish where an identity check leaves durable copies. IDScan's forensic account inventory and breach notices would clarify actual incident reach.
The video also raises LG telemetry, litigation against Valve, ownership predictions and a broad data-monetization motive. Those were not established by this bounded intake. They remain separate leads, not new factual links in the atlas.
Primary pages and public original reporting were inspected through the web tool. No stolen records or criminal service were accessed. Direct archival capture of the Wicks page failed (web open 502; Python certificate-chain failure); indexed full-page text was available and read. No local raw-page capture is claimed. This intake does not modify the tested explorer or its portable bundle, and does not restart the paused heartbeat. Additional agent findings are appended below when received.
The supplied policy-site PDF is also hosted on ICMEC's official CDN. Agent inspection found byte-identical copies and no named writer, project funder or credited corporate partner. The February 7, 2025 filename is not independently verified publication timing. The proposal calls for device-based verification, local or other secure OS-managed storage, and OS review/approval of website API integrations before age data is shared. Apple, Google and Microsoft are named as needed collaborators rather than proven participants. This supplies a policy-design record concerning API admission authority; it does not prove Microsoft implemented that paper or that its privacy claims have been validated. http[local research file] http[local research file]
The legal operator of AgeVerificationPolicy.org remains unresolved. Its displayed AV Policy Source copyright and links to ICMEC/Free Speech Coalition do not establish ownership or a formal partnership.
Read discord-age-assurance-verification-2026-09-08.md for the separately sourced review. Discord's August 10 primary methods page names k-ID/Veratad for document checks, k-ID/Stripe for the credit-card experiment and Google Wallet for an age-group/country signal. Credit and Wallet routes remain labelled limited tests; this pass found no official September 8 global-launch confirmation. The October 2025 age-appeals support incident concerns a different custody path and must not be assigned to those verification providers. These are vendor relationships and distinct rollout states, not evidence that Stripe directs Discord policy.
Retain these findings as a sourced intake pending the next atlas content revision. Highest-priority new node: ICMEC, with distinct financial-programme donor, legislative-sponsor and technical-proposal relationships. New infrastructure nodes include Windows age-signaling, k-ID, Veratad, Google Wallet and IDScan.net/VeriScan. Never connect IDScan to Discord without a separate source. Priority questions concern programme earmarks, drafting provenance, provider admission, credential refusal/correction, retention and deletion duties. No public release or automated restart occurred.