Wisconsin’s Governor Just Killed an Age Verification Bill — And Exposed the Fault Lines Splitting America’s Internet Policy

Wisconsin Governor Tony Evers vetoed an age verification bill, citing First Amendment and privacy concerns. The decision exposes deep contradictions in the nationwide push for mandatory identity checks online — laws that critics say benefit Big Tech while threatening open-source developers and free speech.
Wisconsin’s Governor Just Killed an Age Verification Bill — And Exposed the Fault Lines Splitting America’s Internet Policy
Written by Juan Vasquez

Wisconsin Governor Tony Evers vetoed an age verification bill on Friday, making his state one of the few to explicitly reject the wave of legislation sweeping the country that would require websites to confirm users’ ages before granting access to certain content. The veto wasn’t quiet. It was pointed, deliberate, and rooted in constitutional concerns that supporters of these bills have largely failed to address.

The bill, Assembly Bill 93, would have required commercial websites and apps that publish material deemed “harmful to minors” to verify the age of users before allowing access. Evers, in his veto message reported by the Free Speech Coalition, cited First Amendment problems and the practical impossibility of implementing age-gating systems without creating new privacy risks for every adult forced to hand over identification just to browse the internet. He wasn’t wrong.

But this isn’t just about Wisconsin. The veto lands at a moment when more than two dozen states have either passed or are actively considering age verification mandates, and when the federal government is circling the same policy space with increasing interest. What Evers did — and what he said while doing it — throws into sharp relief a set of contradictions that the age verification movement has been papering over for years.

Start with the basic architecture of these laws. Nearly all of them require some form of identity verification: a government-issued ID upload, a facial age estimation scan, or a third-party identity service. The stated goal is protecting children from pornography and other harmful content. That’s a goal almost no one opposes in principle. The problem is the mechanism.

As WebProNews has reported extensively, the age verification bills proliferating across state legislatures share a common DNA — and much of it traces back to lobbying efforts by large technology companies and third-party identity verification vendors who stand to profit enormously from mandatory compliance regimes. The bills don’t just regulate pornography sites. Their language is often broad enough to encompass social media platforms, search engines, app stores, and in some cases, open-source software distributors who have no capacity to implement age-gating infrastructure at all.

That’s the quiet part. The loud part is children’s safety.

Wisconsin’s AB 93 followed the template. It targeted “commercial entities” that distribute material harmful to minors, a category that courts have historically struggled to define with precision. The bill would have imposed liability on website operators who failed to verify ages, creating a compliance burden that falls disproportionately on smaller operators while giving large platforms — which already collect vast amounts of user data — a structural advantage.

Evers saw through it. His veto message emphasized that the bill would “chill constitutionally protected speech” and force adults to submit to surveillance-style identity checks simply to access legal content. He also noted the privacy implications: any system that collects government IDs or biometric data at scale becomes a target for hackers, data brokers, and government agencies seeking to build profiles of citizens’ online behavior.

This isn’t hypothetical. System76, the Linux hardware manufacturer, has publicly warned that age verification mandates are functionally a surveillance infrastructure project dressed up as child protection legislation. The company’s leadership has argued that the bills serve a dual purpose for Big Tech: they shift liability away from platforms that profit from algorithmic amplification of harmful content, and they create a new market for identity verification services that the same companies are positioned to dominate.

It’s a neat trick. Platform companies that have spent years refusing to meaningfully moderate content or redesign addictive recommendation algorithms now get to point at age verification as the solution — a solution that happens to require every user to identify themselves, that happens to entrench existing monopolies, and that happens to push compliance costs onto competitors and open-source alternatives that can’t afford to build or buy verification systems.

The pattern is visible across the country. In California, AB 1043 would force a verification mandate on every developer, including individual open-source contributors who distribute software through repositories like GitHub. The bill’s language makes no meaningful distinction between a multinational social media company and a solo developer maintaining a content filtering tool. Both would face the same legal exposure. As WebProNews documented, Linux distributions and open-source projects have been caught in the crossfire of a bill that was ostensibly written to protect children from pornography but whose actual text reaches far beyond that stated purpose.

California’s bill includes a 2027 compliance deadline. That timeline would force a massive restructuring of how software is distributed in the state — and because California’s market gravity tends to pull national and international compliance along with it, the effects wouldn’t stop at the state border.

Illinois has its own version. SB 3977 takes a similarly expansive approach, defining covered entities broadly enough to capture open-source projects, nonprofit educational platforms, and small commercial sites that host user-generated content. The bill’s sponsors have framed it as a common-sense measure. Its critics — including digital rights organizations, privacy advocates, and the open-source software community — see it as an age-gating machine that could swallow entire categories of lawful speech and software distribution.

Colorado offered a glimmer of pragmatism. The state considered exempting open-source software from its age verification mandates, acknowledging that volunteer-maintained projects can’t realistically implement identity verification systems. That exemption, if adopted, would represent a significant concession to reality. But it also highlights the absurdity of the broader legislative approach: if you have to carve out exemptions for entire categories of software because compliance is physically impossible, perhaps the underlying mandate is poorly designed.

And that brings us back to Wisconsin.

Governor Evers didn’t just veto a bill. He articulated a constitutional argument that has been building in federal courts for months. In multiple states, age verification laws have been challenged on First Amendment grounds, and courts have frequently sided with challengers. The core issue is straightforward: requiring adults to identify themselves before accessing legal content is a prior restraint on speech. It doesn’t matter that the content in question may be distasteful or that the government’s interest in protecting children is compelling. The question is whether the chosen mechanism — mandatory, universal identity verification — is the least restrictive means of achieving that interest. Courts have repeatedly found that it is not.

The Supreme Court’s 2004 decision in Ashcroft v. ACLU addressed this directly, holding that filtering software installed by parents was a less restrictive alternative to government-mandated age verification for online content. Two decades later, the technology has changed, but the constitutional framework hasn’t. States pushing age verification laws are walking into the same legal wall that Congress hit in the early 2000s.

Some legislators know this and don’t care. The political incentive to vote for anything labeled “child protection” is enormous. The political cost of opposing such a bill — even on principled constitutional grounds — is high. Evers absorbed that cost. Most politicians won’t.

The industry dynamics make the picture murkier. As WebProNews has detailed, the largest technology companies have quietly supported age verification frameworks that would impose compliance costs on competitors while building out identity infrastructure that these same companies are uniquely positioned to monetize. Google, Apple, and Meta already operate identity verification systems at scale. A legal mandate requiring every website to verify user ages doesn’t threaten them — it threatens everyone else. The small forum operator. The independent news site. The open-source project maintainer in a basement in Milwaukee.

That’s the real redistribution happening under the surface of these bills. Not a redistribution of safety, but of market power. Mandatory age verification raises barriers to entry across the internet, and the companies that already sit at the top of the stack benefit most from higher barriers.

Meanwhile, the evidence that age verification actually protects children is thin. Studies from the UK, which implemented its own version of age verification requirements under the Online Safety Act, have shown that determined minors easily circumvent these systems using VPNs, shared credentials, or simply accessing content through platforms that don’t comply. The children most at risk — those in unstable homes, those being exploited, those without parental oversight — are precisely the ones least likely to be protected by a system that assumes a functioning household with engaged adults managing device access.

What does work? Device-level parental controls. Operating system-level content filtering. Education. Direct intervention by platforms to detect and remove child sexual abuse material. Investment in law enforcement units that investigate exploitation. None of these solutions require building a national identity verification infrastructure. None of them require every adult to hand over a driver’s license to read a website.

But none of them are as politically convenient as a bill that lets a legislator say they voted to protect children.

The Free Speech Coalition, which represents adult entertainment companies but has increasingly become a voice for broader digital rights concerns, praised Evers’ veto and called on other governors to follow suit. The organization has been a lead plaintiff in several federal challenges to state age verification laws, winning injunctions in Texas, Indiana, and other states where courts found the laws likely unconstitutional.

Those legal victories haven’t slowed the legislative momentum. If anything, they’ve accelerated it. Legislators in states that haven’t yet passed age verification bills see the court challenges as a reason to draft their versions more carefully — or more aggressively. Some bills now include provisions attempting to insulate themselves from First Amendment challenges by framing age verification as a “time, place, and manner” restriction rather than a content-based regulation. Legal scholars are skeptical that this reframing will survive judicial scrutiny, but it shows how determined the political class is to push these measures through.

The federal angle is heating up too. Multiple bills in Congress would establish national age verification requirements, preempting the state-by-state patchwork. Some of these federal proposals include privacy protections that state bills lack — requirements that verification data be deleted immediately, prohibitions on using age verification systems for other purposes, and liability provisions for companies that mishandle identity data. But even the best-drafted federal bill faces the same constitutional problem: you’re still requiring adults to prove their identity before accessing legal speech.

So where does this go? The most likely near-term outcome is continued fragmentation. States will keep passing bills. Courts will keep blocking them. The compliance burden will fall on smaller operators who can’t afford legal challenges, while large platforms will either comply selectively or lobby for federal preemption that locks in their preferred verification frameworks. Open-source software communities will face existential questions about whether they can continue distributing software in states with broad age verification mandates. And children — the supposed beneficiaries of all this legislative activity — will continue to access whatever content they want through the same workarounds they’ve always used.

Governor Evers’ veto won’t stop the movement. But it provides a template for the argument that needs to be made more often and more loudly: that the Constitution doesn’t permit the government to build a checkpoint at the entrance to the internet, no matter how sympathetic the justification. That privacy is not a luxury to be traded away for the appearance of safety. And that the companies pushing hardest for age verification mandates are the same ones that created the problems these mandates claim to solve.

Wisconsin said no. The question is whether anyone else will.

Subscribe for Updates

CompliancePro Newsletter

The CompliancePro Email Newsletter is essential for Compliance Officers, Risk Analysts, IT professionals, and regulatory specialists. Perfect for professionals focused on navigating complex regulatory landscapes and mitigating risk.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us