> if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls).
If it's a header, you can strip it out at the browser level, the user level, the kernel level, the hardware level, the router level, the router OS level, the router hardware level, or at the ISP level, depending on what a parent (or a state) desired.
The teeth are only necessary for the websites, which are never going to conform to the law anyway, whether through a header or through device attestation, without draconian Chinese-level enforcement that has never been seen in the West before. This new contract will have to be enforced at both endpoints. You will need the ID (whatever you want to call it) to get onto the network, whether you're an individual or the site being visited.
The idea that device attestation is going to bother the Moldovan tube site your kid gets pirated porn through is a surprisingly ignorant fantasy, especially when it comes from technical people. The Pirate Bay is still up. Megaupload is up and runs better than ever. People have 20 year old torrent site accounts. OS-level age attestation must be a first step, because it won't work.
And as to it not being enforced either by the hardware or by identity verification of the user, that's an impossibility. A kid can also overwrite an operating system, or even just overwrite the important part; so that means that either only attested operating systems can be installed, or no user is trusted at any time without state verification.