Governments worldwide are enacting policies that threaten to fundamentally change the Internet landscape.
Recently, France’s highest judicial authority, the Constitutional Council, overturned a proposed bill aimed at restricting social media access for individuals under 15. The council determined that the Macron administration’s legislation, slated to take effect on September 1, infringed upon freedom of expression and the right to privacy for all Internet users, irrespective of age.
One of the key arguments against the bill was that it would necessitate the universal verification of users’ ages, including adults, without sufficient privacy protections in place:
“By prohibiting minors under the age of 15 from accessing certain online services, the law inherently requires every person, even an adult, to prove their age before accessing them.”
This concern about online age verification was highlighted in our post from November 19, 2024, titled Will Online Age Verification Be the Trojan Horse for the Mass Rollout of Digital IDs?:
[A]ge verification… nets everyone — not merely those under 16, but nearly anyone wishing to use the Internet. As members of the Australian government acknowledged, everyone will soon be required to prove their age in order to engage with social media. This will likely mean utilizing the government’s newly launched digital ID application, myID:
RE: Social Media Ban for Under16's (aka the trojan horse Digital ID for ALL Australians)
So the Federal Labor Gov't have confirmed at Senate Estimates that ALL Australians will have to go through an age verification process to access social media, not just under 16 year olds.… pic.twitter.com/LgPu5DXdek
— Glen Schaefer (@hardenuppete) November 10, 2024
The ruling from the French Constitutional Court serves as a significant setback for President Emmanuel Macron, who has invested considerable political effort into this initiative. As illustrated in the video below, Macron has even urged other European nations to adopt similar measures. Notably, France is one of seven EU Member States currently piloting the EU’s age verification application.
Thank you @emmanuelmacron for organising this discussion on the safety of our children online.
With the DSA, we have EU-wide rules.
And now we have an EU-wide app.
It’s piloted in 🇫🇷 🇩🇰 🇬🇷 🇮🇹 🇪🇸 🇨🇾 🇮🇪
And soon available to all.
Online platforms are held accountable.
Parents… https://t.co/PQQgZisvPP
— Ursula von der Leyen (@vonderleyen) April 16, 2026
The Constitutional Council affirmed that protecting children is a valid goal. In its decision, it pointed out that social networks can expose minors to risks such as addiction, social isolation, pornography, harassment, and fraud. Yet, it deemed Macron’s proposed bill too broad a solution for the issue at hand. Other concerns raised by the court included:
- The law did not delineate conditions under which parents could “in the child’s interest” decide to lift the restriction or allow access to specific services.
- Lawmakers failed to articulate clear rules regarding age verification processes and the safeguards necessary to protect users’ privacy.
- The legislation lacked clarity on how and under what conditions individuals’ online data would be collected and used.
As noted by Reclaim the Net, the ruling stands as a victory for privacy and freedom, albeit potentially short-lived:
The contentious bill would have forbidden those under 15 from creating social media accounts, with implementation scheduled for September 1. Accounts established prior to that date would have been required to close within four months, and platforms would have had to implement age verification systems that infringe upon privacy.
…
“The Council holds that the contested provisions disproportionately infringe upon the freedom of expression and communication while failing to provide adequate legal safeguards to respect individuals’ privacy,” the decision stated.
As previously indicated since 2024, online age verification is often a guise for the implementation of digital ID systems that are now nearing rollout. The rationale of “protecting children” frequently serves as a compelling pretext for enacting socially unpalatable policies. A gated Internet, with concurrent losses in online anonymity and privacy, represents one of the least accepted of these policies.
Australia was the first to restrict social media access for those under 16, introducing this measure in December of last year. In the UK, lawmakers are expected to vote on similar restrictions by Christmas. Countries including Spain, Greece, and Denmark have announced plans for minimum age legislation, while the EU is set to implement a continent-wide system closely resembling Australia’s, which has proven less than effective.
In the US, three states—California, Colorado, and Illinois—have enacted laws mandating age verification for operating systems before users can engage with their devices. Meanwhile, Congress is deliberating over analogous legislation. In Latin America, Brazil now requires age assurance for products and services prohibited for minors, with other nations such as Indonesia, Malaysia, Canada, New Zealand, India, and South Korea following suit.
Globally, countries are embracing policies that are poised to drastically alter the functioning of the Internet, incorporating social media age restrictions, operating-system-level age verification mandates, digital identity frameworks, and algorithmic safety regulations. As the British technologist Wayne Horkan points out, this shift is occurring within a constrained timeframe, with numerous laws scheduled to be enacted between 2025 and 2027:
Across North America, Europe, Australia, and parts of Asia, lawmakers are incrementally constructing a regulatory landscape in which access to digital platforms increasingly hinges on verifying specific user attributes, primarily age but potentially extending to others in the future. Although the individual initiatives vary in scope and execution, they converge on a shared principle: platforms cannot regulate user experiences without first understanding their users.
Consequently, we are witnessing the emergence of what could be termed an age-gated internet.
Such terminology should not be limited to referring merely to pornography filters or parental controls. Instead, it signifies a broader architectural evolution where online services increasingly require systems capable of discerning whether a user is a child, a teenager, or an adult before determining which content or features that user may access.
This signifies a deeper change which can be summarized as follows:
Multiple regions are transitioning toward identity-mediated access to digital services.
In this model, the Internet does not merely respond to information requests; it first categorizes the requesting entity, subsequently determining what the user is permitted to view, do, or partake in.
The implications of such a paradigm extend beyond the loss of online privacy and anonymity to potential barriers to accessing essential online services. Elevated security threats also emerge as factors of concern. Remarkably, within mere moments of the launch of the EU’s age verification app in April, IT security experts and hacktivists were already identifying significant weaknesses within the security framework.
The “age verification app” the EU wishes to impose globally was hacked within 2 minutes.
Step 1: Present a “privacy-respecting” but hackable solution.
Step 2: Get hacked (you are here).
Step 3: Remove privacy to “fix” it.Result: a surveillance tool masquerading as “privacy-respecting.”
— Pavel Durov (@durov) April 17, 2026
As the Electronic Frontier Foundation has repeatedly cautioned, age verification methods are incompatible with privacy and data security:
Ultimately, age verification systems function as surveillance systems. Mandating such measures compels websites to require visitors to submit information, including government-issued IDs, to companies like AU10TIX. The likelihood of hacks and data breaches involving this sensitive information is not merely a hypothetical scenario; it’s a matter of when, not if, this data will be compromised.
Cory Doctorow has described online age verification as the “latest consensus hallucination to take over our political classes” and argues that it is “a notion that manifestly does not exist”:
You cannot “verify” the age of an internet user — you can only strive to attribute every byte traversing the entire internet to distinctly identified individuals:
This comes at a great cost. It poses significant risks for future dictators, identity thieves, and potential exploiters of children who will gain access to the stolen, leaked, and poorly secured databases generated by this ineffectual effort.
Indeed, “doomed.” Because even for minors, “age verification” serves merely to introduce them to VPNs. This was entirely obvious the moment “age verification” was proposed, yet our lawmakers chose to ignore repeated warnings.
VPNs act as anonymity shields, allowing users to conceal their online activities and access restricted content. Their usage has surged as governments impose increasingly strict regulations on Internet accessibility. In response, authorities have threatened to ban children from employing VPNs or to classify them as “loopholes that need addressing.”
The UK Children’s Commissioner advocates for mandatory age checks on VPNs, a tool relied upon by millions for privacy, safety, and free expression.
During a discussion on BBC Newsnight, Rachel de Souza categorised VPNs as a “loophole” within the Online Safety Act and stated that verifying users’ ages is one of her top… https://t.co/YczlrbIIPp
— Reclaim The Net (@ReclaimTheNetHQ) August 20, 2025
The EU hasn’t banned VPNs. Yet.
But they have officially classified them as a “loophole that needs closing.”
— IT Guy (@T3chFalcon) July 7, 2026
“Politicians have now realized that people are utilizing VPNs to safeguard their privacy and circumvent these intrusive regulations,” EFF cautions. “Their solution? To outright ban VPNs… and this struggle is being waged by individuals clearly lacking an understanding of the technology involved.”
NC reader Baron Aroxdale echoed this sentiment in a previous post, highlighting that VPN bans risk causing severe disruptions to the Internet:
VPNs are standard components in corporate IT. They merely enable remote computers to connect across a virtual network. Support for VPNs is usually integrated into operating systems, and hardware networking firms customarily supply desktop applications for configuring VPNs on their routers.
VPNs are as commonplace as internet proxies or email. You cannot simply “ban” them without jeopardizing the backbone of modern IT—which has relied on them since the late 1990s.
It appears someone may have finally informed the UK government of this important consideration…
Britain just pressed the one button it never touches: “Leave it alone.”
The “Online Safety” Minister just confirmed on BBC: We’re NOT imposing age restrictions on or banning VPNs. No passports, no blocks.
Tools that allow you to evade the UK’s creeping censorship remain unrestricted.
A rare win for common… https://t.co/twK3all85g
— Reclaim The Net (@ReclaimTheNetHQ) July 17, 2026
Doctorow draws a parallel between the current fixation on online age verification and the long-standing attempts to “ban working cryptography”:
To outlaw effective cryptography, you need to ban free/open source software, inspect every device entering your nation, and construct a Great Firewall blocking any site that might offer functional cryptography. You render it impossible to reliably update software in pacemakers, anti-lock brakes, and nuclear power plants while simultaneously facilitating identity theft, espionage, and corporate spying — and it still won’t succeed!
Nevertheless, this will not deter governments from making such attempts. The EU’s recent passage of its temporary Chat Control legislation exemplifies their willingness to employ overtly anti-democratic means.
The EU Parliament REJECTED Chat Control, yet they are now compelling us to vote on it AGAIN to revive it. What kind of democracy is it if we’re forced to re-vote on the same issue until they achieve their desired outcome?
My colleague @MarketkaG explained the situation very… pic.twitter.com/veRJZgMVbW
— Fidias Panayiotou (@Fidias0) July 8, 2026
The European Parliament voted AGAINST Chat Control. 314 to 276.
And it passed regardless.
Let me explain: they required 361 votes to reject it. On the final day before recess, every empty seat counted as a yes.
They lost the vote. They won the legislation.
That’s not democracy. That’s a…
— Sven Clement (@svnee) July 9, 2026
The temporary Chat Control legislation allows messaging services and platforms to scan for already-identified child sexual abuse material; it does not compel such actions, unlike the permanent legislation being advocated by the EU Commission. According to Brussels Signal:
The more controversial permanent proposal pushed by Brussels (the comprehensive Child Sexual Abuse Regulation) could impose wider obligations while raising significant concerns regarding encryption and mass surveillance. It remains under negotiation and has yet to be adopted.
The European Parliament has repeatedly underscored the need for targeted and proportionate measures.
The extension follows the previous temporary rules expiring on April 3, 2026, after MEPs rejected a renewal on March 26 by a vote of 311 to 228, with 92 abstentions. Controversial procedural maneuvers enabled the issue to return for urgent debate before the summer break.
Digital rights groups have critiqued this process, asserting it limited comprehensive discussions on long-term ramifications.
Critics, including some MEPs and digital rights organizations, contend that this undermines democratic oversight and raises serious privacy concerns regarding encrypted communications.
They argue that this derogation, despite being more limited than Chat Control 2.0, still suspends fundamental rights.
[Former Pirate Party MEP Patrick] Breyer stated: “The progression of Chat Control against the will of the majority of voting MEPs is absurd and undermines democracy.”
…
Breyer noted that the legislation embodies a mass surveillance mentality.
The same applies to online age verification, which extends beyond mere surveillance; it aims to establish control. Despite the recent ruling from the Constitutional Council, the struggle over age verification is far from resolved in France. Macron has directed Prime Minister Sébastien Lecornu to revise the ban “as swiftly as possible” to ensure its implementation before the spring 2027 elections.