Global age verification mandates spark privacy backlash amid surveillance fears
From Australia’s under-16 ban to the EU’s new verification app, governments are tightening online controls, but critics warn these measures undermine anonymity and enable mass surveillance.
A coordinated global legislative trend is reshaping the digital landscape, with governments implementing or proposing mandatory age verification for social media and online services. While authorities cite child safety as the primary justification, privacy advocates and digital rights organisations argue that these measures serve as a precursor to state surveillance and the erosion of online anonymity. The push has seen significant developments in Australia, the European Union, the United Kingdom, and the United States, with critics warning that the infrastructure built for age checks can easily be repurposed for broader control.
Australia has already enforced a ban on social media for users under the age of 16, joining a growing list of nations including Indonesia and Brazil that have introduced similar restrictions. In Europe, the European Commission launched an age verification app in April 2026, with Commission President Ursula von der Leyen presenting plans for EU-wide age restrictions. The initiative aims to provide a privacy-focused solution, yet analysts note that the underlying architecture still requires users to identify themselves to state issuers, potentially allowing authorities to link credentials to specific online activities.
The United Kingdom has passed legislation granting the government power to impose social media restrictions for children under 16 via secondary legislation, bypassing extensive parliamentary scrutiny. Beyond social media, the UK is considering identity verification for virtual private network (VPN) services, a move that would align it with countries such as China and Russia in opposing anonymity tools. This follows similar legislative moves in the United States, where Utah has banned the use of VPNs to circumvent age restrictions, and federal proposals are emerging for operating system-level identity verification.
In the United States, a patchwork of state-level laws is taking shape, with California passing legislation requiring identity verification at the operating system level starting in January 2027. Brazil has also enacted a law mandating verification at both the app store and operating system levels, imposing fines of up to $10 million for non-compliance. These measures have raised concerns about the feasibility of maintaining open-source systems, with some analysts suggesting that authoritarian governments may eventually move to ban uncontrolled devices entirely to enforce total compliance.
Critics argue that the current approach to age verification is fundamentally flawed, noting that social media companies already possess detailed data on their users. By forcing identity verification through third-party systems or operating system integrations, governments are creating a centralised infrastructure that can be abused. The EU’s app, while marketed as anonymous, lacks zero-knowledge proof functionality in its current form, meaning that if a user posts content deemed inappropriate, the state could potentially identify them through the issuer. This has led to warnings that the rush for verification is being used as a pretext for mass surveillance, with similar tactics previously observed in attempts to scan encrypted communications in the US and EU.


