Politicians promise safety. They roll out age checks for social media. Yet the measures demand something far more sweeping. Everyone must prove who they are online.
Mullvad VPN laid out the stakes in stark terms last week. Its analysis frames these rules not as child protection but as the start of government-controlled access across the internet. The company argues big tech already knows users’ ages through its surveillance business model. Forcing identity verification on all users simply hands authorities and corporations new tools to track speech and behavior.
Countries have raced ahead. Australia banned social media for those under 16 and began enforcement in late 2025. Indonesia and Brazil followed with similar restrictions this year. Proposals or laws now exist in Denmark, Portugal, Malaysia, France, Spain, Turkey, Germany and Sweden. The European Commission launched an EU age verification app in April 2026. Ursula von der Leyen outlined broader EU-wide restrictions one month later. In the United States half the states have passed or introduced measures. Recent reporting from the Electronic Frontier Foundation shows nine states activated such rules in 2025 alone. Half the country now requires some form of age screening for social media or adult content.
But here’s the catch. Most systems aren’t simple guesses about age. They require identity verification. Users upload government ID, submit to facial scans or rely on third-party services that link back to real names. A 2025 Discord breach exposed ID documents from 70,000 users. That incident, covered by the BBC, revealed exactly how fragile these databases can be.
Privacy advocates warn of the chilling effect. Once identity ties to every post or visit, criticism of power carries new risks. In the UK authorities arrest 30 people daily for online posts deemed grossly offensive. German police have raided homes over insults directed at politicians. One case, dubbed Pimmelgate, involved officers searching a residence after a vulgar remark about a public figure. Canadian officials during 2022 trucker protests used social media data to freeze bank accounts of supporters. These examples, drawn from Mullvad’s review and reporting by Reclaim the Net, show how identification turns anonymous expression into a traceable act.
And the slope feels slippery. Bypassing national rules with VPNs has lawmakers eyeing those tools next. The UK passed legislation granting secondary powers to restrict VPNs with minimal oversight. France’s digital affairs minister called VPNs the next item on her list. Utah made circumvention via VPN illegal. Discussions continue in the EU and several U.S. states. EFF’s December 2025 briefing cataloged ten risks, from data breaches to eroded anonymous speech. It noted that once users hand over immutable details like passport scans or biometrics the information lingers. Hackers or governments can exploit it later.
Proponents claim technology offers solutions. Zero-knowledge proofs could verify age without revealing identity. Some systems estimate age through device data or behavioral signals. Yet implementation varies wildly. Many platforms default to the easiest path: collect IDs through vendors. A CNBC investigation published in March 2026 detailed how these gates already pull millions of adults into surveillance systems designed for minors. Companies face pressure to comply while balancing legal exposure and user backlash.
Courts have pushed back in places. Federal judges blocked parts of Virginia and other state laws on First Amendment grounds. The Harvard Law Review examined these cases in February 2026 and suggested intermediate scrutiny might apply given impacts on speech. Justice Kavanaugh called one Mississippi measure likely unconstitutional in a recent concurrence. Still enforcement pushes forward. California’s SB 976 heads toward age verification rules by late 2026 despite legal challenges. Minnesota, New York and others layer on parental consent or time limits.
Even supporters show hesitation. A UK Ipsos poll found 69 percent back checks in principle yet few want to share ID for dating apps or pornography sites. Only 14 to 19 percent expressed willingness. Public skepticism runs high about effectiveness and data security. Ofcom in Britain demands highly effective age assurance for porn sites from mid-2025 onward. Guidance emphasizes risk assessments yet stops short of prescribing exact methods.
So what does success look like? Platforms already profile children to sell ads. Forcing them to block those same users through identity gates feels backward to critics. Politicians could demand changes to algorithms or advertising practices directly. Instead they build infrastructure for universal identification. That infrastructure doesn’t vanish once kids are protected. It scales.
Recent developments in Malaysia illustrate the pace. The country began rolling out mandatory verification for major platforms this week targeting users under 16. Local reports from The Star and New Straits Times describe teenagers shifting to search engines or outdoor activities. Parents call for closer supervision. Yet the global pattern holds. Each new law normalizes the idea that access to information and conversation requires state-approved proof of identity.
Tech companies protest compliance costs and technical hurdles. Privacy groups document rising data risks. One leading age verification provider suffered a breach that exposed names, licenses and other details for months. Another analysis from Georgia Tech researchers in May 2026 found many sites fail to enforce their own checks while still collecting sensitive information that leaks to third parties.
The conversation rarely addresses root causes. Social media design rewards engagement over well-being. Parents lack tools or time to monitor use. Schools and communities could teach digital literacy more aggressively. These paths demand less centralized control. They preserve space for adults to speak and read without constant logging.
But momentum favors verification. From Brussels to state capitals the message repeats. Protect children. Verify everyone. The Mullvad post concludes that real aim may be broader oversight. Its timing, published just days ago, coincides with Malaysia’s rollout and ongoing U.S. state-level battles. The piece has circulated widely on X today with users linking back to the original.
History offers warnings. Tools built for one purpose expand. Anonymity enabled dissidents, whistleblowers and ordinary people exploring sensitive topics. Remove it and self-censorship follows. What seems acceptable today shifts with political winds. Speech once protected becomes risky when tied to a name and address stored in multiple databases.
Alternatives exist. Double-blind systems where verifiers confirm age without learning identity. Browser-level signals. Strengthened parental controls that don’t require platform-wide surveillance. These options receive less attention amid the rush to legislate. Lawmakers face pressure from constituents alarmed by headlines about addiction and exploitation. They reach for visible action even if it reshapes the internet’s fundamental openness.
The result is an emerging system where logging on demands documentation. Post something controversial and the record links back. Browse certain topics and the trail follows. For activists in repressive settings the danger multiplies. For everyone else the friction and privacy loss accumulate quietly.
Industry insiders tracking these shifts see a crossroads. Either societies accept pervasive identity layers as the price of safety or they demand narrower solutions that shield children without sacrificing adult rights to private thought and expression. The technology exists for both paths. The policy choices made in 2026 will determine which one prevails.
Recent NBC News coverage from April highlighted expert concerns about compliance headaches and data security. A Governing magazine piece in May noted 19 states have passed related laws with 40 states introducing hundreds of bills this year. The pace shows no sign of slowing. As more nations join Australia, Brazil and Indonesia the pressure on holdouts grows. VPN usage spikes in affected countries. Workarounds proliferate until lawmakers target those too.
This isn’t abstract. A teenager in Sweden researching gender identity or a dissident in Turkey organizing protest both lose cover when every account requires verified ID. The same systems that block harmful content also map who reads it. Governments gain leverage. Corporations gain data. Users lose options.
Debate will continue in legislatures and courtrooms. Technical experts will propose privacy-preserving methods. Yet the core tension remains. Age verification as practiced today is identity verification. And identity verification changes what the internet can be. It trades one set of risks for another potentially deeper set. Whether that bargain delivers safer childhoods or simply more controlled adults is the question now playing out in policy rooms from Washington to Kuala Lumpur.


WebProNews is an iEntry Publication