Skip to main content
Back to Blog
· 8 min read

The Age of Verification - How the West Is Building a Surveillance State in the Name of Safety

We are living through one of the most consequential quiet revolutions in the history of the internet. It is not happening with dramatic speeches or tanks in the streets. It is happening through regulations, child protection frameworks, and technical standards that claim to make the digital world safer. In reality, they are constructing the architecture of permanent identification and mass surveillance across the West.

The Current Landscape

In Europe, the battle has centered for years around what critics call Chat Control. In July 2026, after the temporary legal basis for voluntary scanning of private messages for child sexual abuse material expired in April, the European Parliament and Council revived it through procedural maneuvers until April 2028. Platforms can once again scan unencrypted communications. End-to-end encrypted services such as Signal and WhatsApp remain formally exempt, for now. The permanent regulation, often called Chat Control 2.0, continues to loom, with proposals that have repeatedly threatened client-side scanning and the effective end of private messaging.

In the United Kingdom, the Online Safety Act has already forced age verification onto pornography sites and is expanding pressure onto social media. The result has been predictable: massive spikes in VPN usage, easy technical bypasses including using video-game characters to fool facial age estimation, and a wave of investigations and fines by Ofcom. Adults are being pushed to upload government IDs or submit to facial scans simply to access legal content. Children still find ways around the systems. Privacy-conscious users are treated as suspects by default.

Across the European Union, the push for age verification and digital identity is accelerating. The Commission has promoted an age-verification blueprint and is rolling out the European Digital Identity Wallet, with Member States expected to offer wallets by the end of 2026. Politicians frame this as privacy-preserving. In practice, it moves the West toward a world where access to large parts of the internet requires proving who you are to a system that can record, link, and potentially leak that proof.

These are not isolated policies. They form a pattern: every new restriction is justified by the protection of children, and every technical solution expands the capacity for identification and monitoring of the entire population.

The Central Obsession: Age and Identity Verification

The political class has converged on a single obsession. They believe the internet's core problem is that people can act without proving their age or identity. The proposed cure is mandatory or quasi-mandatory verification, for pornography, social media, messaging, and increasingly for any service deemed risky.

The problem is not the goal of protecting children. The problem is that the solutions on offer are either technically unworkable, dangerously invasive, or both.

Why the Current Solutions Fail

Let us examine the main approaches being pushed:

Government ID Upload or Document Scanning

Users photograph their passport or national ID and send it to a platform or third-party verifier. This creates centralized or semi-centralized honeypots of highly sensitive identity documents. History shows these databases will be breached. When they are, the damage is permanent: identity theft, blackmail, and the ability to link real-world identities to online activity at scale. It also excludes people without traditional documents and normalizes the idea that accessing the internet requires surrendering government-issued identity.

Facial Age Estimation and Biometric Scanning

Systems analyze a face to estimate age. These systems are inaccurate at the margins, easily fooled, biased across demographics, and still collect biometric data. Even when the image is supposedly deleted, the process itself trains the expectation that your face is a key to online access. Biometric data, once compromised, cannot be changed.

Credit Card or Financial Verification

Requiring a credit card to prove adulthood sounds simple. It excludes the unbanked, creates financial surveillance vectors, and still fails against determined minors using family cards. It also links financial identity to browsing habits.

Anonymous Age Tokens Issued by Platforms or Governments

Many proposals claim to offer privacy-preserving age checks via digital wallets or third-party providers. In reality, most current designs still require an initial identity check that is recorded somewhere. The token may hide the exact identity from the website, but the issuer knows who requested it, when, and often for what purpose. This creates a powerful logging and correlation capability. Anonymous to the website is not the same as anonymous to the system.

Client-Side Scanning and On-Device Analysis

The most extreme proposals involve scanning content on the user's device before encryption. This breaks the security model of end-to-end encryption, creates a privileged scanning agent that can be expanded to other categories of content, and introduces a massive new attack surface. Once the capability exists on every phone, mission creep is not a risk; it is a certainty.

All of these approaches share fatal flaws. They treat every user as a potential threat. They create new databases or new points of control. They introduce single points of failure that will be breached. They enable mass profiling over time. They restrict the freedoms of the many in the name of controlling the few. And they fail at their stated goal while succeeding at expanding surveillance capacity.

A Better Path: Cryptographic Verification

Mandatory identity or age verification for the entire population is undesirable. The default state of the internet should remain permissionless and pseudonymous. Most online activity does not require knowing who someone is.

However, if societies insist on verifying certain attributes in specific high-risk contexts, there is only one class of technical solution that does not inevitably become a surveillance infrastructure: undisclosed cryptographic proofs of identity, more precisely, zero-knowledge proofs of attributes.

In this model:

  • A user obtains a credential from a trusted issuer, for example a government or regulated authority, that cryptographically attests to an attribute such as over 18 or resident of country X.
  • When a service needs to check that attribute, the user generates a zero-knowledge proof. The proof demonstrates that the user possesses a valid credential with the required attribute, without revealing the credential itself, the user's identity, or any other data.
  • The service learns only the single bit of information it needs: yes or no on the attribute. It learns nothing else.
  • No central database of who accessed what is created by the verification process. There is no massive identity graph. There is no honeypot of ID scans.
  • Double anonymity is possible: the issuer does not learn which services the user is accessing, and the service does not learn who the user is.

This is not theoretical. Zero-knowledge proof systems capable of this already exist and are being refined. The difference between this approach and everything currently being pushed is fundamental. Current solutions create persistent records and linkable identities. Properly designed cryptographic attribute proofs do not.

If online verification of age or identity is going to be imposed in limited domains, this is the only architecture that prevents the transformation of the internet into a permanent checkpoint system. Anything less, ID uploads, facial scans, persistent tokens tied to real identities, client-side scanning, builds the infrastructure of mass surveillance under the banner of safety.

The Stakes

Mass surveillance does not arrive announcing itself as tyranny. It arrives as a series of reasonable-sounding protections. Protect the children. Stop the terrorists. Prevent the scams. Each step is presented as limited and necessary. Each step expands the capacity to identify, track, and control.

A free society does not require every citizen to prove their identity to speak, read, or associate online. A free society does not treat anonymity as inherently suspicious. A free society does not build systems that make the private lives of millions legible to the state and to corporations simply because a minority abuse the tools of privacy.

Bottom Line

You still have a choice. You can reject the premise that safety requires universal identification. You can insist that any verification, if it must exist, be narrowly targeted, cryptographically private, and incapable of creating permanent records. You can refuse the false trade-off that says you must surrender privacy to protect the vulnerable.

The alternative is a digital world in which every login is a checkpoint, every conversation is potentially scanned, and every citizen is pre-emptively treated as a risk to be managed. That world is not safer. It is merely more controlled. And control, once built, is rarely surrendered.

The fight is not against the protection of children. The fight is against the construction of a surveillance architecture that will outlast every politician currently selling it as temporary and necessary. History will not be kind to those who traded the open internet for the illusion of safety.