Not sure how viable this is in the US due to reasons but a centralized auth service could in theory not provide any PII back to the service requesting an age verification, and the auth provider wouldn't necessarily have to be get data back from the service except for the first time a user registers an account.