On 24 September 2026, a federal judge in Utah signed a 40-page opinion that contained one sentence every engineer who has ever built a geo-gate should pin above their desk: geolocation perfection is not presently possible.
The case is Aylo, the company behind Pornhub and several other large adult sites, against Utah's Division of Consumer Protection. The law at issue is SB 73, the Online Age Verification Amendments, which took effect in May and added a deceptively small clause to Utah's 2023 age-verification regime. The clause said a person counts as accessing a site from Utah if they are physically in Utah, whether or not they used a VPN, proxy, or anything else to disguise where they were. Judge David Barlow granted a preliminary injunction against that provision, finding Aylo likely to win on a dormant Commerce Clause theory: a state cannot impose a rule whose practical effect is to burden every user everywhere else.

The legal fiction at the centre of the case: that an IP address reliably tells you where a person is standing.
The reasoning matters more than the outcome. Utah's attorney general argued the statute only asked for reasonable efforts. The court pointed out that the word "reasonable" does not appear in the text the legislature actually passed, which turns the provision into strict liability. Miss one user, face liability. Barlow wrote that the law requires entities like Aylo to geolocate users with perfection, then noted that both sides agreed perfection is unavailable. The arithmetic that follows is brutal and was spelled out in the opinion: to be safe, you verify all 28 million of your users, in Salt Lake City and Honolulu alike.
The signal stack, and where each signal breaks
Strip away the politics and this is a classification problem that a lot of us have been handed in less dramatic forms: payments fraud, licensing restrictions, regional content rights, gambling compliance. The toolkit is always the same, and so are its holes.
IP-to-location databases are the first layer. They are good at country and considerably worse below that. Mobile traffic is the obvious failure: carriers route subscribers through a handful of CGNAT egress points, so a phone in Provo can present an IP that a database places two states away. Satellite links behave similarly. Corporate split tunnels put a remote employee's traffic on the head office's address. University networks, hotel Wi-Fi and airport lounges all lie by design, not by malice.

Consumer VPN apps changed the economics of circumvention: one toggle, no technical skill required.
The second layer is data centre detection. Flag the ASNs belonging to hosting providers and known VPN exit ranges, then treat traffic from them as suspect. The lists go stale within days. Providers rotate address space, residential proxy networks rent out real home connections by the gigabyte, and Apple's iCloud Private Relay sends ordinary iPhone traffic through an egress that looks nothing like the subscriber's neighbourhood. Blocking all of it means blocking a slice of your legitimate customers who simply bought a privacy product or a corporate laptop.
The third layer is where it gets interesting legally. Utah's lawyers proposed cross-referencing device time zone, browser language, currency preference and account history, and the judge even repeated the example: a genuine Utah user is unlikely to be running an India time zone, Hindi browser locale and rupee transactions all at once. The draft administrative rules published on 1 September, which could have taken effect on 8 October, went further and required "commercially reasonable geolocation obfuscation detection systems", alongside hints about watching connection latency.
Here is the part that rarely makes it into the compliance spec. Time zone, locale, currency and round-trip latency are the exact attributes that make up a browser fingerprint. A mandate to collect and correlate them is a mandate to fingerprint every visitor, which is precisely the practice that privacy browsers randomise, that ad-tech regulation in Europe treats as processing requiring consent, and that Ghana's Data Protection Act makes you justify as a lawful purpose. Teams we work with in Accra shipping into US and EU markets end up building one system that satisfies a state geolocation rule and immediately fails a data-minimisation review somewhere else. There is no configuration that passes both.
False positives are the real cost line
Classifier accuracy conversations tend to fixate on the users you fail to catch. In a strict liability regime the business damage sits on the other side of the matrix.
Run the numbers against the figure the court used. At 28 million users, a 1 percent false positive rate on "this person is obfuscating" is 280,000 people pushed into an identity check they should never have seen. At 3 percent it is 840,000. Every one of those is a support ticket, a conversion loss, and in the worst case an ID document uploaded to a vendor that now holds a breach-worthy pile of driver's licences. Age-verification vendors bill per attempt, not per pass, so your false positive rate is also a direct line item.
When we build gating logic now, we stopped returning booleans. A location decision should carry a confidence score and the reasons behind it, because a year later someone will need to explain to a regulator or a customer why a specific request was blocked.
from dataclasses import dataclass, field
@dataclass
class GeoVerdict:
region: str | None
confidence: float # 0.0 to 1.0
signals: list[str] = field(default_factory=list)
def decide(verdict: GeoVerdict, policy):
if verdict.confidence >= policy.block_threshold:
return "gate", verdict.signals
if verdict.confidence <= policy.allow_threshold:
return "allow", verdict.signals
return "step_up", verdict.signals # cheap, reversible friction
Three outcomes instead of two. The middle path matters: a soft challenge, a self-declared region with a logged attestation, or a delayed check costs a fraction of a full identity verification and keeps the user in the funnel. Thresholds live in config, versioned per jurisdiction, because the law changes faster than your release cycle.

Age-gating laws are aimed at minors, but the compliance burden lands on every adult user of the service.
What this ruling does and does not settle
The injunction is preliminary and narrow. It blocks the actual-location provision only. Utah's underlying 2023 age-verification law is untouched and still enforceable, and Aylo never challenged the clause that forbids covered sites from publishing instructions about VPNs. Utah legislators have already signalled they will redraft during the next session, and the obvious fix is cheap: insert the word "reasonable", define a safe harbour, and most of the constitutional problem evaporates while the engineering problem stays exactly where it was.
That is the thing worth planning around. Courts are now willing to say on the record that perfect geolocation does not exist, which is useful precedent, but legislatures will keep writing rules that assume otherwise, and other states are drafting their own versions right now. Someone will eventually pass a reasonableness standard, and then the question becomes what a defensible effort looks like in your codebase.
Start building the evidence for that answer before you need it. Log every gating decision with its signals and its confidence, keep the thresholds and rule versions in source control, measure your false positive rate against a sample you actually audit, and give blocked users a route to appeal that a human reads. A team that can show its working will survive a regulator's questions. A team with a single opaque boolean somewhere in middleware will not.








