Age checks are spreading faster than the technology to verify age safely, and the current laws are turning the open web into a worse place for everyone. Not just kids.
I have been reading the age verification coverage since the early Pornhub and YouPorn ID checks of the 2010s, and the situation in 2026 is meaningfully worse than the 2020 law-and-order version. The methods are more invasive. The platforms covered are broader. The reasoning has shifted from “block the worst content” to “build a permanent record of who uses the internet.” More than 370 researchers have warned about it in writing. Politicians are ignoring them anyway.
This is not an argument against protecting kids online. It is an argument against doing it in a way that breaks the privacy floor for the other 95% of users who are not kids, and who never agreed to show ID to log into Reddit.
How we got here
Age verification has been around for decades, mostly in the form of credit card checks or “click here if you are 18” gates on porn sites. These worked badly but at least they did not require uploading identity documents. In 2026 the standard method is biometric, meaning your face. Some vendors use ID document uploads. Others use behavioral signals. Almost all of them create a permanent record somewhere.
The change from the old, easily bypassed credit card model to the new biometric model happened in three waves. First came the adult content laws, starting with the UK Online Safety Act in 2023 and the equivalent in several US states. Then the social media laws, pushed by Australia and the EU. Now the conversation has moved to VPNs, with officials in multiple countries openly suggesting that anonymous VPN use should require age verification. The escalation is consistent and not slowing down.
The political logic is simple. Children are protected, so the policy is good. The technical reality is harder. Children can use their parents’ verified accounts. VPNs and Tor (The Onion Router, a network that bounces traffic through multiple relays to hide its origin) make point-of-access blocking ineffective. The result is a system where adults prove their identity to do anything online, and children who want to bypass the system already know how to do so.
Countries that already require it
As of June 2026, the working list of countries with active age verification mandates for social media platforms includes Australia, Brazil, Greece, Malaysia, Turkey, the United Kingdom (partially), and the United States (partially). Most EU member states are debating or implementing their own versions following the bloc’s 2025 Digital Services Act guidance.
The list of countries actively debating or evaluating age verification laws for the same platforms is longer. It includes the European Union as a whole, Canada, India, Indonesia, Japan, Mexico, New Zealand, the Philippines, Singapore, South Korea, and Vietnam, plus several additional US states beyond the partial-coverage ones already listed. The UK has also floated extending its adult-content age checks to social media broadly.
What is harder to find is a list of countries definitively saying they will not adopt age verification. Switzerland has been the clearest holdout. Most countries are at least “evaluating.” Treating this as a regional outlier rather than the global default is not realistic anymore.
What the verification actually looks like
The biometric case is the one privacy advocates worry about most. You upload a photo of your face to a vendor, the vendor’s algorithm estimates your age, and the result is stored on the vendor’s servers or shared with the platform. There are three vendors that keep coming up in coverage: Yoti, Jumio, and Onfido. Each one has its own data retention policy and each one stores data in jurisdictions that may not have your country’s privacy laws.
ID document upload is the second tier. You photograph your passport or driver’s license, an algorithm extracts the name and date of birth, and the document goes to a vendor for processing. The vendor deletes the document after a configurable period, usually 7 to 30 days. The vendor does not always delete the derived data.
The third tier is what regulators are pushing hardest right now and also the one that does not work well in practice: behavioral analysis. Estimate the user’s age from how they type, what they click, what time of day they use the platform. The accuracy is roughly 60% for adult-vs-child classification, which is not good enough to put behind an enforcement mechanism.
For any of these methods to work in practice, the platform needs a verified identifier to bind the age check to. Email addresses can be thrown away. Phone numbers are closer, since SIM swapping is annoying. Government IDs are the only thing that really sticks, which is why every law points in that direction eventually.
What is at risk
Three things, in declining order of how much they matter.
The first is anonymity. The point of age verification is to attach a verified identity to a user account. Once the binding exists, the platform knows who you are. Law enforcement requests, subpoenas, data breaches, and the platform’s own business needs all become more dangerous because the link is real. The Tutanota blog post that originally inspired this piece (Tuta is a German end-to-end encrypted email provider) pointed out that this is the inverse of how an open internet is supposed to work. The default for any account should be “I am not who I say I am,” not “I have proven who I am to use this site.”
The second is the chilling effect (the tendency of people to self-censor or avoid speaking when they know they can be identified). Adults who use Discord to discuss politics, who post on Reddit about mental health, who use a throwaway account for a sensitive question, all of those use cases get harder when the platform knows your legal name. The behavior change is invisible until it is gone.
Third is the cost to the platform. Every additional ID check is a friction point that loses users. Estimates from the adult content side suggest 10 to 30% of would-be subscribers abandon at the verification step. For platforms that depend on user growth, that is a serious number. The product and policy teams end up arguing about whether to verify everyone (safe but expensive) or sample (cheap but legally risky).
The VPN discussion is the new line
The newest escalation is the conversation around requiring age verification for VPN use. The argument runs: a child using a VPN can bypass the age checks, so the VPN itself should require age verification to prevent that. The argument is internally consistent and entirely backwards in its conclusion.
VPNs are not just a tool for bypassing parental controls. They are a security and privacy tool used by journalists, activists, remote workers, security researchers, and anyone who connects to public WiFi. Requiring ID to use one means requiring ID to do the equivalent of installing antivirus. It also does not work, because the same child who can bypass a website age check can bypass a VPN age check by using someone else’s account or by writing a 10-line proxy.
If VPN age checks became real, the actual outcome would be that privacy-conscious adults get fingerprinted onto yet another system, while determined 14-year-olds use Tor. The policy would not achieve its stated goal and would harm everyone it incidentally touched.
What I would tell past me
If I could send a message back to the version of me that did not pay attention to age verification debates, I would say three things.
- The shape of these laws changed in 2023. The credit card and click-here gates of the 2010s are not coming back. Biometric and document-based methods are the new floor, and the floor keeps dropping.
- Anonymity online is not a fringe preference. It is the default state that lets people talk to their doctor, report a workplace issue, or look up sensitive information without leaving a permanent record. Laws that erode it hurt everyone.
- No single country blocking this will hold the line. Three jurisdictions adopting a standard pulls the others along within 18 to 36 months. Watching the UK and Australia is the right starting point, but the EU, the US, and the larger Asian markets are not far behind.
- The technical floor is dropping fast. Biometric checks in 2026 are the new normal, and the political class is already discussing the next tier (VPN age checks and identity-linked payment rails). Each step feels incremental until you look at the cumulative curve.
Trade-offs
The new laws are not free for the platforms. A biometric age check on every signup adds 30 to 90 seconds to the registration flow and loses 10 to 30% of would-be accounts in the process. For a platform that depends on network effects (features that become more valuable as more people use them), this is a real cost. The privacy guarantees on the data are also uneven across the three big vendors, and the vendor you pick affects your long-term regulatory exposure.
For users, the trade-off is the harder one. Either you accept that showing ID is the new price of using most online platforms, or you refuse and lose access to services that are increasingly hard to live without. There is no third option at the individual level. The lever is collective: pushing for client-side verification (where the age check happens on your device and never sends the ID anywhere) and minimum-data retention policies would help, but neither is on the table in the current bill drafts.
If you are an adult who values their privacy, the practical move is to start using services that do not require age verification and to push back politically through whatever channels your jurisdiction offers. If you are a parent, the harder question is how to talk to your kids about why some of their favorite platforms suddenly ask for ID, because the answer “so adults know who you are” is not reassuring for anyone.
The migration will take years. The decisions are being made now, and most of them are in the worst direction.