Across the world governments are adopting policies that threaten to radically transform the Internet.
At the end of last week, France’s highest court, the Constitutional Council, blocked a bill that seeks to ban social media access for under-15s. The court ruled that the Macron government’s ban, which was scheduled to enter into force on September 1, violated freedom of expression and the right to privacy — for all Internet users regardless of age.
One of the central arguments for blocking the bill is that it would mean blanket verification of all users, including adults, without establishing sufficient safeguards to protect privacy:
“By prohibiting minors under the age of 15 from accessing certain online services, the law inherently requires every person, even an adult, to prove their age before accessing them.”
This is the entire point of online age verification, as we warned in our Nov. 19, 2024 post, Will Online Age Verification Be the Trojan Horse for the Mass Rollout of Digital IDs?:
[A]ge verification… traps everyone in its web — not just under-16s but just about anyone who wants to use the Internet. As members of the Australian government recently admitted, everyone will soon have to prove their age to use social media. And that will presumably mean having to use the government’s recently launched digital ID app, myID:
The French Constitutional Court’s ruling represents an embarrassing setback for President Emmanuel Macron, who has invested significant political capital in this flagship legislation. As the video below shows, Macron has even encouraged other European countries to follow suit. France is also one of seven EU Member States being used to pilot the EU’s age verification app.
Thank you @emmanuelmacron for organising this discussion on the safety of our children online.
With the DSA, we have EU-wide rules.
And now we have an EU-wide app.
It’s piloted in 🇫🇷 🇩🇰 🇬🇷 🇮🇹 🇪🇸 🇨🇾 🇮🇪
And soon available to all.
Online platforms are held accountable.
Parents… https://t.co/PQQgZisvPP
— Ursula von der Leyen (@vonderleyen) April 16, 2026
The Constitutional Council believes protecting children is a legitimate objective. In its ruling, it explicitly recognises that social networks can expose children to addiction, isolation, pornography, harassment and fraud, and that the protection of the best interests of the child may justify limiting access to online services in the future.
However, Macron’s proposed bill was considered too blunt an instrument for the problem at hand. Other issues flagged by the court:
- The law does not provide for conditions under which parents may, “in the interest of the child, decide to lift the ban, to limit its scope or to allow access to certain services.”
- Lawmakers “had failed to set out clear rules on how people should prove their age and what limits should apply, meaning there were not enough legal safeguards in place.”
- The legislation also did not establish how, with what limits or with what guarantees individuals’ online data would be collected.
As Reclaim the Net notes, the ruling is a win for privacy and freedom, though its impact may be short-lived (more on that later):
The controversial bill would have banned those under 15 from opening a social media account, and it would have come into effect from September 1. Accounts that were already opened by September 1st would have had to be closed within four months, and platforms would have had to introduce age verification systems, which curb privacy.
…
“The Council holds that the contested provisions, on the one hand, disproportionately infringe upon the freedom of expression and communication and, on the other, fail to provide the legal safeguards necessary to ensure the right to respect for private life,” the decision said.
As we have repeatedly warned since 2024, online age verification is being used as a Trojan Horse for digital ID systems, which are now more or less ready to roll out. “Protecting the children” is always a seductive pretext for launching otherwise socially unpalatable policies. And there are few more socially unpalatable policies than a gated Internet, with all that entails (loss of online anonymity and privacy, increasing access controls for platforms…).
Australia was the first to ban under-16s from accessing social media platforms, in December last year. UK lawmakers are expected to vote on similar measures by Christmas. Spain, Greece, and Denmark have announced plans to launch minimum ages while the EU prepares to launch a bloc-wide system closely modelled on that of Australia, which seems to be anything but effective.
In the US, three states — California, Colorado and Illinois — have approved laws requiring operating systems to verify your age before you can use your computer. Congress is weighing similar legislation. In Latin America, Brazil now requires age assurance for products and services that are not allowed for children and adolescents. Other countries on a similar path include Indonesia, Malaysia, Canada, New Zealand, India and South Korea.
All over the world countries are adopting policies that threaten to radically transform the way the Internet functions, including social media bans for minors, operating-system-level age verification mandates, digital identity infrastructures and algorithmic safety regulations. As the British technologist Wayne Horkan notes, this is all happening in a very narrow window of time, with many of the laws scheduled to come into force between 2025 and 2027:
Across North America, Europe, Australia, and parts of Asia, policymakers are gradually constructing a regulatory environment in which access to digital platforms increasingly depends on the verification of certain user attributes, most commonly age, but potentially others in the future. The individual initiatives differ in scope and mechanism, yet they converge on the same operational premise: platforms cannot regulate user experiences without knowing something about the user.
The result is the quiet emergence of what might be called an age-gated internet.
This term should not be understood narrowly as referring only to pornography filters or parental controls. Instead, it describes a broader architectural transition in which online services increasingly require systems capable of determining whether a user is a child, a teenager, or an adult before deciding what content, features, or algorithmic pathways that user may access.
The deeper shift can be summarised in a single observation:
Multiple regions of the world are moving toward identity-mediated access to digital services.
In such a system, the internet does not simply respond to requests for information. It first classifies the requesting entity. Only then does it determine what the user is permitted to see, do, or participate in.
The dangers of such a system go beyond the loss of online privacy and anonymity to the loss of access to basic online services. That’s not to mention the elevated security risks. Within literal minutes of the launch of the EU’s age verification app in April, IT security consultants and hacktivists were already finding glaring flaws in the security architecture.
The “age verification app” the EU wants to impose on the world got hacked in 2 minutes.
Step 1: Present a “privacy-respecting” but hackable solution.
Step 2: Get hacked (you are here).
Step 3: Remove privacy to “fix” it.Result: a surveillance tool sold as “privacy-respecting”.
— Pavel Durov (@durov) April 17, 2026
As Electronic Frontier Foundation has repeatedly warned, online age verification is incompatible with privacy and data security:
In the final analysis, age verification systems are surveillance systems. Mandating them forces websites to require visitors to submit information such as government-issued identification to companies like AU10TIX. Hacks and data breaches of this sensitive information are not a hypothetical concern; it is simply a matter of when the data will be exposed, as this breach shows.
Cory Doctorow describes online age verification as the “latest consensus hallucination to take over our political classes” and as “a thing that manifestly does not exist”:
You can’t “verify the age” of an internet user — you can only attempt to attribute every byte that traverses the entire internet to affirmatively identified persons:
This comes at enormous cost. It is a gift to every future dictator, every identity thief, and every would-be sexual exploiter of children, who will have access to the hacked, leaked, and badly secured troves of data that this doomed effort produces.
Yes, doomed. Because even when it comes to kids, “age verification” is just a way of convincing young people to familiarize themselves with VPNs. This was entirely obvious from the very instant that “age verification” was mooted, and yet our policymakers pretended they couldn’t hear the chorus of people who pointed it out to them.
Since VPNs function as anonymity masks that allow users to hide their online activity and access restricted content, their popularity has grown as governments have sought to impose increasingly draconian restrictions on Internet use. As their popularity has grown, governments have responded by threatening to ban children from using VPNs or treating them as “a loophole that needs closing”.
The UK Children’s Commissioner wants mandatory age checks on VPNs, a tool millions rely on for privacy, safety, and free expression.
On BBC Newsnight, Rachel de Souza called VPNs a “loophole” in the Online Safety Act and said verifying users’ ages is one of her top… https://t.co/YczlrbIIPp
— Reclaim The Net (@ReclaimTheNetHQ) August 20, 2025
The EU hasn’t banned VPNs. Yet.
but they’ve officially described them as a “loophole that needs closing.”
— IT Guy (@T3chFalcon) July 7, 2026
“Politicians have now discovered that people are using VPNs to protect their privacy and bypass these invasive laws,” EFF warns. “Their solution? Entirely ban the use of VPNs… And that battle is being fought by people who clearly have no idea how any of this technology actually works.”
NC reader Baron Aroxdale raised a similar point in the comments section of a previous post, noting that VPN bans are unlikely to work — at least not without causing serious damage to the internet along the way:
VPNs are a very standard part of business IT. They are simply a means to connect remote computers together on the same virtual network. Support for them is normally inbuilt into operating systems, and hardware network companies will normally provide desktop applications to support VPN setup on their routers.
VPNs are about as common as internet proxies or email. You can’t just “ban” them without breaking the backbone of modern IT systems since the late 1990s.
It seems that someone may have actually informed His Majesty’s Government in the UK of this niggling fact…
Britain just pressed the one button it never touches: “Leave it alone.”
The “Online Safety” Minister just admitted on BBC: We’re NOT banning or age-gating VPNs. No passports, no blocks.
The tools that let you dodge the UK’s creeping censorship stay free.
A rare W for common… https://t.co/twK3all85g
— Reclaim The Net (@ReclaimTheNetHQ) July 17, 2026
Doctorow likens the current obsession with online age verification with that perennial fave, “bans on working cryptography”:
To ban working cryptography, you have to outlaw free/open source software. You have to inspect every device that comes into your country. You have to erect a Great Firewall that blocks every site that might carry working cryptography. You make it impossible to reliably update the software in pacemakers, anti-lock brakes and nuclear power plants, and you make it easy for identity thieves, foreign powers and corporate spies to raid your government, your corporations, and your households — and it still won’t work!
But that won’t stop governments from trying. If the EU’s recent bulldozing into law of its temporary Chat Control legislation is any indication, they will use flagrantly anti-democratic means if necessary.
The EU Parliament REJECTED Chat Control, but now they are forcing us to vote it AGAIN to revive it. What kind of democracy is this if we’re forced to vote on the same issue over and over until they get the result they want?
My colleague @MarketkaG explained the situation very… pic.twitter.com/veRJZgMVbW
— Fidias Panayiotou (@Fidias0) July 8, 2026
The European Parliament voted AGAINST Chat Control. 314 to 276.
And it passed anyway.
Let me tell you how: they needed 361 votes to say no. On the last day before vacation. Every empty seat counted as a yes.
They lost the vote. They won the law.
That’s not democracy. That’s a…
— Sven Clement (@svnee) July 9, 2026
Brussels’ temporary Chat Control legislation allows messaging services and platforms to scan communications for already-identified child sexual abuse material, primarily images and videos; it does not mandate it, unlike the permanent legislation being pushed by the EU Commission. From Brussels Signal:
The more controversial permanent Chat Control proposal pushed by Brussels (the full Child Sexual Abuse Regulation), which could impose broader obligations and has raised significant concerns about encryption and mass surveillance, continues to be negotiated separately in trilogues and has not (yet) been adopted.
The European Parliament has repeatedly emphasised the need for targeted, proportionate measures.
The extension comes after the previous temporary rules lapsed on April 3, 2026, once MEPs rejected an extension on March 26 by 311 votes to 228, with 92 abstentions, and follows controversial procedural manoeuvres that brought the issue back to the plenary on an urgent basis before the summer recess.
Digital rights groups have criticised the process, arguing it limited full debate on long-term implications.
Critics, including some MEPs and digital rights groups, argue the move undermines democratic scrutiny and raises concerns over privacy and encrypted communications.
They say the derogation, despite being more limited than Chat Control 2.0, suspends a fundamental right nonetheless.
[Former Pirate Party MEP Patrick] Breyer said: “The fact that Chat Control is moving forward against the will of the majority of voting MEPs is a farce and damages democracy.”
…
Breyer said at heart, this legislation has a mass surveillance approach.
The same goes for online age verification, though it’s not just about surveillance; it’s about control. Despite the Constitutional Council’s recent ruling, the battle over age verification is far from over in France. Macron has instructed Prime Minister Sébastien Lecornu to rewrite the ban “as quickly as possible,” so that it is in force before the spring 2027 election.














