Correct me if I am wrong the base problem, but we're not trying to lock down the OS. We're trying to limit the adult internet to children right?
The problem here is that the OS and all applications on them would need to change their behavior based on the mode.
So the AuthZ event can occur at the remote web server (or server serving the API). Yes, those would have to change. The AuthN event would supported by the web browser (or other software) making the call to the remote server. So yes, those would have to support the check of the CPU flag.
How are you going to prevent ROM flashing or storage replacement to modify the OS or other software?
Legal protections, not technical ones. This is the same method we use to prevent someone from setting up a distillery in their kitchen and making their own whiskey. There's nothing technologically limiting people from doing this, only laws. Also, the only people breaking the law to circumvent the child protections would be children, or adults purposefully trying to assist children in bypassing this check. The children committing the crime would be handled in the existing juvenile justice system the same way an under-aged child that is caught with alcohol. An adult assisting children with circumvention would be prosecuted the same way as an adult that buys booze for under-aged children.
In this system, no adults would have to age verify. No adult identity would be sent anywhere. All devices are "adult" by default.