AI
Microsoft Ties Copilot Access to Sign-In and Age
Microsoft’s youth AI safety plan packages a Copilot sign-in wall, an under-13 cutoff, and a Windows age-signal API that other apps can query.
Microsoft on September 10, 2026 published a youth AI plan that forces every Copilot user to sign in and bars children under 13. The post also folds a new Windows age-signal layer into that same child-safety wrap, so other apps can ask the operating system how old someone is.
Chief Digital Safety Officer Mike Jackson and Chief Privacy Officer Cari Benn wrote that Safe Participation Framework for young people is meant to keep protection and opportunity on the same track. The product changes underneath it are narrower, and they last longer than a policy essay.
AI is creating new ways for young people to learn and create. Those experiences must be safe, age-appropriate, and private. pic.twitter.com/yXwJRS7JOw
— Microsoft On the Issues (@MSFTIssues) September 10, 2026
Every Copilot Chat Now Starts With a Microsoft Account
Children and families should not have to choose between the protections they need and the opportunities technology can provide.
Mike Jackson and Cari Benn, Microsoft On the Issues, September 10, 2026
The Copilot rule that follows that line is blunt. All users must sign in, and access is restricted for children under 13, or at a higher age where local law requires it. Supplemental terms that took effect on August 18, 2026 already said you need a Microsoft account and must be at least 13, so Thursday’s framework is restating a gate that had already moved into the contract.
Microsoft Support’s Copilot pages for young people still describe a teen band from 13 to 17. In that band the assistant is allowed to answer homework questions, draft text, and make images, with extra limits on how the account is used.
WHAT COPILOT CHANGES FOR USERS 13 TO 17
- No personalization: Results are not tailored to a teen profile.
- No personalized ads: Ads may still appear, but Microsoft says they are based on the live query, not a stored profile.
- No training on chats: Conversations from users under 18 are not used to train models.
Parents can still block the Copilot app or set screen-time limits through Microsoft Family Safety on Windows, Xbox, and Android, and through Apple Screen Time on iPhone. Those controls manage a product that is now account-bound. A child without a qualifying account does not get a supervised Copilot mode; they get a closed door.
School-managed Microsoft 365 Copilot Chat uses the same floor on a different product. Students aged 13 and over can get it through eligible Education licences, and students under 13 are not eligible. Institutions set age-group flags on the tenant. Microsoft’s published education guidance does not add a separate parental-consent step for those 13-to-17 school accounts.
Three Pillars and a Long Product List
Jackson and Benn grouped the work under three headings, then pointed at shipping features rather than a new law. Safety by design, age-differentiated experiences, and education and empowerment are the labels. The inventory underneath is Copilot, Bing, Xbox family tools, Windows Family Safety, and a developer API.
THE THREE PILLARS MICROSOFT NAMED
- Safety by design: Find foreseeable risks early, test how features land, and add safeguards in proportion to those risks.
- Age-based experiences: Treat children, teens, and adults as different users, using Xbox-style family tools as the pattern for Copilot.
- Education and empowerment: Put tools and teaching in front of families, because software alone cannot deliver safe use.
On the safety side, Bing has tightened blocks on child sexual abuse material in generative AI features, including image-upload paths in Bing Video Creator, and has expanded SafeSearch worldwide to more classes of harmful content. Microsoft dates that child-safety stack to PhotoDNA in 2009. Copilot, the company said, now steers users toward crisis-support resources when self-harm risk is detected, nags for breaks, offers reporting tools, and adds guardrails against delusional outputs, its phrase for answers that feed a false story about the user or the world.
The education pillar is a toolkit, not a filter. Earlier in 2026 Microsoft launched Behind the Chat: A Human Guide to Safe AI Conversations, with classroom material and parent guides, and said it will push those resources through Europe, Asia, and the Americas in fall 2026. Over the next year it wants deeper work with researchers, AI Safety Institutes, governments, and civil society. That is the part of the post that admits the product list will not finish the job.
Windows Apps Can Ask for an Age Bucket
The piece of Thursday’s write-up that changes other companies’ software is not Copilot’s login prompt. It is the Windows Age API, documented for developers on September 8 by Rob Mauceri, a distinguished engineer on Windows Digital Safety. Windows, he wrote, should turn a Microsoft account into a single pipeline: account, then age signal, then the right experience.
Apps that declare the userAccountInformation capability, and that the user allows to read account information, can call GetUserAgeRangeAsync and receive five age-group ranges for apps instead of a birthday. GetAgeVerificationStatusAsync reports whether that age has been verified, left unverified, or opted out. CheckAgeStatusAsync, which maps users to child, minor, or adult under regional rules, comes in a later update.
AGE GROUPS WINDOWS CAN RETURN
| Age group | Range the API returns |
|---|---|
| Under 10 | 0 to 9 |
| 10-12 | 10 to 12 |
| 13-15 | 13 to 15 |
| 16-17 | 16 to 17 |
| 18+ | 18 and older |
If the signal is missing, the call returns null, and Microsoft tells developers to keep a fallback rather than guess. Identity-provider signals currently resolve only for Microsoft accounts. Other account types get null unless an administrator has set a default through Group Policy or MDM. The APIs run on Windows 11, on the user in the current process, and Microsoft says they are broadly available to Windows Insiders now and will reach all Windows users soon.
WHAT WE KNOW
- Public return value: Microsoft’s developer docs say the APIs return a coarse age bucket and a verification status, not an exact age or date of birth.
- Who can call: The app must be entitled, the user must consent, and random packages are not supposed to query age on their own.
- Where it applies: Games, media with maturity ratings, in-app purchases, and AI features are the examples Microsoft lists.
WHAT IS UNCONFIRMED
- General availability date: Microsoft has not named a day when the APIs leave the Insider channel.
- CheckAgeStatusAsync: The child, minor, or adult classifier is promised in a future update, with no ship date on the blog.
That is the second-order shift. Copilot can enforce 13 using its own account graph. The Age API invites every other Windows app to do the same without standing up a birth-date form. Families stop configuring each title. Developers inherit Microsoft’s buckets. The operating system becomes the age desk.
The Age Signal Starts as a Birth Date
Microsoft’s privacy claim is that apps receive only the signal they need. Security researcher Xusheng Li, writing on September 4 after reversing the still-gated code, said that is not the whole path. On Windows 11 25H2 build 26200.9168 the public call still returned E_NOTIMPL because a DigitalSafetyAPI flag was off, but UserMgrProxy.dll was already in the image.
Li traced this sequence: the calling app loads that DLL, the DLL asks Windows for an identity token, the token carries a birthdate claim, the DLL computes an age, then the public API returns a range. Because the DLL loads inside the requesting process, he wrote, that process can hook the decoder or read memory and recover the date of birth. Capability checks can keep a stranger app out. They cannot hide data from an app Microsoft has already allowed, once the token is in that app’s own address space.
WHERE THE PRIVACY CLAIM SPLITS
- The documented API: Microsoft Learn says no exact age or date of birth is returned to the caller.
- The current plumbing: Li says the birthdate claim is decoded inside the calling process before it is reduced to a bucket, and that a later preview build of UserMgrProxy.dll still used that design.
Those two statements can both be true, because they describe different layers. Families who take the framework at face value will hear “privacy-preserving age signals.” App vendors who read the reverse-engineering note will hear that a birthday still crosses the process boundary. Microsoft can still move the conversion into a broker before the feature reaches every PC. Until it does, the youth-safety API is also an identity API with a known leak path for authorized callers.
Singapore, Brazil, and Australia Already Verify Once
Age buckets from a self-reported Microsoft account are one thing. High-confidence proof that someone is an adult is another, and that is the rail Microsoft is laying for stores and, later, for apps that call GetAgeVerificationStatusAsync. Microsoft Age Verification, or MAV, stores a verified status on the account so a user can verify age once across Microsoft apps.
Mauceri’s post says that check is already live in Microsoft storefronts in Singapore, Brazil, and Australia, with more regions to follow as local rules expand. The slogan on the Windows blog is verify once, then use that status everywhere. Microsoft Support’s age-assurance pages describe methods that include facial age estimation, a document upload, and a government login such as Singpass. Windows setup in France and some other markets is also being rewritten so parental controls and consent screens show up before the first afternoon on a new PC.
Put next to Copilot’s sign-in rule, MAV is the adult half of the same design. Children are kept off Copilot by the account graph. Adults who want 18+ store content, and apps that need a verified adult, are asked to prove age once at Microsoft and then carry that badge around Windows. The child-safety essay on September 10 is how that account architecture gets introduced to parents.
Schools Signed Binding AI Privacy Terms on September 9
A day before the consumer framework, Microsoft Vice Chair and President Brad Smith stood with American Federation of Teachers President Randi Weingarten and United Federation of Teachers President Michael Mulgrew in New York and announced a National AI Safety and Privacy Standard. U.S. districts can fold those terms into Microsoft customer contracts, which makes them enforceable in a way a blog post is not.
The binding AI privacy rules for schools bar student and educator data from being used to train models, sold, or repurposed. They also require human oversight of AI decisions and plain-language explanations for families. Smith said the standard sets a high bar and that Microsoft will extend the agreement to every school district in the country. Weingarten called it an iron-clad privacy deal with real teeth, and said anything less than enforceable terms is a wish list, because federal and state rules have not done the work.
That school track and the consumer Copilot cutoff are not the same product. Districts get contract language. A 12-year-old on a home PC gets no Copilot, even with a parent standing there. Weingarten had already asked, in a May speech, for a screen ban from kindergarten through second grade, a ban on student-facing AI in elementary school, and a ban on social companion chatbots for students under 16. Los Angeles Unified, New York State United Teachers, and New York City Public Schools with Mayor Zohran Mamdani had already adopted similar limits. Microsoft’s September 9 deal is how the company answers that pressure without waiting for Congress.
THE DATES BEHIND THE FRAMEWORK
- August 18, 2026: Copilot supplemental terms require a Microsoft account and a minimum age of 13, or older where local law says so.
- September 8, 2026: Windows documents the Age API and MAV, and says Insider builds can call the new signals.
- September 9, 2026: Microsoft and the AFT announce contract terms that stop school data from training models.
- September 10, 2026: Jackson and Benn publish the Safe Participation Framework and present those shipping changes as one youth-safety program.
Read as a week, it is not a sudden conversion to child safety. It is a consumer login rule, an operating-system age bus, and a school contract, stapled together for parents and regulators on Thursday.
The Supervised Path Google Still Offers
Microsoft chose a hard consumer cutoff. Google still lets some children under 13 use Gemini through a parent-managed Family Link account, with extra guardrails on those supervised logins. OpenAI’s ChatGPT also uses a 13-year floor, with parental permission required under 18. Microsoft’s own education Copilot Chat matches the 13-year line but routes consent and age flags through the school tenant instead of a parent popup.
The gap matters because children are already on these bots, with or without a qualifying account. Australia’s eSafety Commissioner surveyed 1,950 children aged 10 to 17 between February 2 and March 4, 2026, and found that 78% of children aged 10 to 17 had used an AI assistant. ChatGPT led at 70%. Copilot and Gemini were tied at 20%. Meta AI was at 14%.
HOW AUSTRALIAN CHILDREN AGED 10 TO 17 USE ASSISTANTS
- Any assistant: 78% had used one.
- ChatGPT: 70% had used it, the most-named tool in the survey.
- Copilot and Gemini: 20% each.
- Meta AI: 14%.
HOW THE BIG ASSISTANTS SET THE FLOOR
| Product | Minimum age | Path under 13 | Extra teen limits |
|---|---|---|---|
| Microsoft Copilot (personal) | 13, or older by local law | None | No personalization, no model training on chats, no personalized ads |
| Microsoft 365 Copilot Chat (school) | 13, with an eligible Education licence | Not eligible | School sets age-group flags; Microsoft does not add a separate parent-consent step |
| Google Gemini | 13 for a personal account | Parent-managed Family Link accounts | Supervised accounts get extra filters, including image generation off for minors |
| OpenAI ChatGPT | 13 | None | Parental permission required under 18 |
Microsoft’s framework tells families they should not have to pick between safety and access. The Copilot that actually shipped picks for them. Under-13s are out. Teens get a thinner, signed-in assistant. Windows, in parallel, is preparing to tell any entitled app which bucket the signed-in user falls into, and to let a store in Singapore, Brazil, or Australia prove adulthood once and reuse the result. That is a child-safety program, and it is also an identity program. The Age APIs are on Insider PCs now. Everyone else, Microsoft says, gets them soon. The Copilot floor does not wait: sign in, and be 13.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
