Great take. I'll just add a bit: Number 1 is dead end. I will write an article about it.
If you look how the new EU age verification works - it's strong attestation + zero knowledge age prover combined with your digital id.
Goodbye open systems.
The app itself is open source, but the age proof will fail unless it's generated by an app compiled and signed by the state authority, on a certified device.
We only have web, hacking certified devices and your point no 2. But since normies don't care, building network effects will be incredibly difficult. nostr:note1vx6cu8wxyqfgw6kyp80c9unkgr2z3vm42muc8k2mc2zx0683whesn9f0sf