There is a really good way to do this that solves most concerns: https://blog.google/innovation-and-ai/technology/safety-secu...
The only real downside to this is that a 0kp cannot be reliably tied to an identity of the person using the device and thus tickets could be proxied/shared around with semi technical tools (and/or an ai agent tasked with creating a proxy). This really isn't solvable without device-level attestation[0], as if a website needs to reliably say "this person is actually this person" then it needs all pieces of data itself.
This could be solved by adding in a still privacy-preserving step like "The device is doing periodic face id scans and matching them to an identity, and constantly renews/re-presents to the age assurance consumer", but that has its own drawbacks[0].
0: Namely, lock in to devices that can do this, and that includes basically guaranteeing a double digit percentage of adult humans would not have access due to their device being old, unsupported, missing the hardware, etc. And with so many humans excluded, you would not have mass adoption. Probably also excludes rooted devices if we bring in attestation of unmodified software.