Age Verification Laws Risk Building Mass Surveillance

In March 2026, 438 security and privacy researchers from 32 countries signed an open letter with a blunt message for lawmakers worldwide: stop deploying age verification systems until someone actually studies whether they work, and what they break in the process. The signatories include some of the most respected names in cryptography and security research — people whose work underpins the encryption protecting everyday internet traffic.

Their full statement is dense and technical, written for policymakers rather than a general audience. If you’d rather read a plain-language summary — including a concrete case study of Austria’s draft law — Der Standard published a strong German-language piece that walks through exactly why one national rollout is running into the problems the scientists describe. We’ve also covered this debate before, but the scale of expert agreement behind this letter is what makes it worth a closer look.

Checks apply to everyone, not just minors

The letter’s starting point is scope. Offline age checks — a bouncer glancing at an ID — are narrow, leave no record, and only happen occasionally. Online proposals go much further: to chat with friends, read the news, or search for information, every user, adult or minor, would need to prove their age. The letter argues this scale of identity-checking has never existed in offline life, and it comes with none of the built-in privacy a paper ID check has.

Four ways these checks get bypassed

The scientists identify specific circumvention methods already observed in live deployments: borrowed or purchased credentials, VPNs that route around jurisdiction, and increasingly, AI-generated faces or deepfakes designed to fool age-estimation cameras. A market for valid accounts and workaround tools tends to appear within days of a check going live. If you’re weighing a VPN as part of your own setup, it’s worth understanding what it actually protects against — the letter notes this exact tool is now being discussed for regulation as a side effect of age-verification enforcement.

Age estimation trades one risk for a worse one

Because not every service can assume users have a government ID or a compatible app, many — Discord, Roblox, ChatGPT among them — have turned to age estimation: guessing a user’s age from a photo, video, or browsing behavior. The letter is sharply critical of this approach. These systems rely on biometric and behavioral data that is inherently sensitive, are known to have high error rates, are biased against certain groups, and can be fooled with something as simple as a fake beard. The letter cites a concrete harm: 70,000 Discord users had their government ID photos leaked after appealing failed age checks — a real breach caused directly by the “solution.”

Building trust infrastructure at internet scale is not trivial

Even with a working verification method, someone has to build the plumbing: trusted issuers, key distribution, revocation, cross-border interoperability. The letter points out that securing basic web traffic (HTTPS) took decades to get right industry-wide. Europe’s EUDI Wallet is meant to solve some of this, but hasn’t been rolled out, and doesn’t yet address revocation or use outside the EU. Austria’s own ID Austria system is a live example of the gap — it currently has no support for the zero-knowledge proofs its own draft law assumes, a point we explored in more depth in our look at ID Austria, the EUDI Wallet, and Switzerland’s eUID.

Infrastructure built for one purpose rarely stays there

The letter’s sharpest warning is about what happens after deployment. Access-control infrastructure built to check age can be repurposed to restrict access for reasons that have nothing to do with child safety — the letter explicitly cites Iran’s internet shutdowns as a preview of what centralized control over access can become. It also warns that if enforcement moves to the browser or operating-system level, it hands even more control over what content is reachable to a small number of major American tech companies. That’s a familiar shape: rules justified by protecting children ending up expanding surveillance for everyone, a pattern we also saw when the EU revived message-scanning powers under similar reasoning.

What the letter is actually asking for

The signatories are not opposed to protecting children online — several study online harms to minors directly. Their ask is narrower and harder to dismiss: a moratorium on large-scale deployment until there’s real evidence age assurance works and a clear public accounting of what it costs in privacy, equality, and security. They also point to a more direct alternative — regulating the addictive algorithmic design of social platforms, which is closer to the actual source of the harm than an identity checkpoint at the door.

Key Takeaways

  • 438 security and privacy researchers from 32 countries are calling for a moratorium on rushed age-verification rollouts.
  • Working systems have to check every adult, not just minors — there’s no way to verify age without asking everyone.
  • Age-estimation tools (biometric guessing) are unreliable, biased, and have already caused real data breaches, like the Discord ID leak.
  • No global trust infrastructure for age verification exists yet, and building one safely has historically taken decades.
  • Access-control systems built for child safety can be repurposed for broader censorship — the letter points to Iran as a precedent.

Photo: Zulfugar Karimov via Pexels

Mastodon
Scroll to Top