Huh, I read up on Privacy Pass, and it really does seem to have the properties I'm looking for. Taking the government as the issuer/attester, it seems like the endpoint (origin) gives a challenge to the user (client), the user requests a token from the government (which, critically, the government can verify without knowing the user's ID), and uses this token to respond to the endpoint's challenge. Thus, the government might learn that some user accessed that particular endpoint (depending on the exact setup used), but cannot learn who it was. And since it does not know the user's identity, it cannot censor a particular user, only potentially a particular endpoint.
I also don't really see how present physical identity could be proven in a privacy-preserving manner, if you don't trust the government or endpoints not to abuse that physical data. Alas, even if I take your word for it, I doubt that governments would implement such an indirect system for age verification in practice, especially since they might want to revoke any erroneously-issued tokens.
(And even if anonymous non-circumventable age gating were to become a reality, I still wouldn't be a fan of differential privacy regulations for minors, since many ordinary sites would become inaccessible to teenagers from following the path of least resistance. Either impose the regulations on all users, impose them gradually depending on age, or don't impose them at all.)