
The core question in Europe’s push for online child safety is not whether to verify age, but how to do it without turning the internet into an ID checkpoint for everyone. The Commission’s answer is a narrow, privacy-preserving proof-of-age layer—if governments and platforms hew to the technical blueprint rather than drift toward convenience shortcuts that would erode anonymity.
At a Glance
- EU policymakers are pursuing age checks as a child-protection measure, not a population-wide identity regime.
- The official design centers on anonymous proof-of-age, using cryptographic credentials that reveal “over 18” but not who you are.
- Privacy and civil-liberties groups warn that real-world deployments often backslide into intrusive data collection and de facto identity checks.
- The policy’s success hinges on strict technical safeguards, credible certification, and viable non-digital alternatives that keep the system inclusive.
What the EU is actually building: proof-of-age, not identity disclosure
Brussels has cast the project squarely as a child-safety intervention: give services a reliable way to tell adults from minors so they can keep children off adult-only platforms and apply age-appropriate features elsewhere. The Commission’s materials describe an architecture that allows a user to present a yes/no proof—“over 18,” “over 15”—without disclosing name, address, date of birth, or document numbers. The formal guidance is explicit: tools should rely on anonymous proof-of-age technologies and deliver the highest practicable privacy and data-protection standards. Reuters summarized the core promise crisply: the app can verify age “without disclosing exact age, identity, or any other personal information”.
Mechanistically, this means separating one-time issuance from repeated presentation. At issuance, a trusted party checks a person’s age boundary once—potentially against a national eID, passport, or other attested source—and then minting a cryptographic credential that encodes only the relevant attribute (e.g., “is over 18”). When presented to a platform, that credential yields a verifiable yes/no response, with no identity fields and no ability for the platform to correlate presentations across sites. The Commission’s blueprint commits to that data-minimization model: the identity is checked only at issuance; subsequent proofs exclude identity data; relying services learn only the age threshold result.
Why this approach emerged now: harmonization and the child-safety turn
Europe’s shift reflects years of uneven, often ineffective age gates—checkboxes, self-declaration, and brittle AI “age estimation”—paired with growing political pressure around minors’ exposure to adult content, targeted advertising, and addictive design. Regulators prefer a common standard to a patchwork of national mandates and vendor offerings that nudge platforms into costly, duplicative integrations. The Commission’s recommendation is non-binding today but engineered to guide enforcement under existing instruments, particularly where the Digital Services Act contemplates proportionate access controls in service of protecting minors. A harmonized proof-of-age layer gives platforms compliance certainty and, in theory, a uniform privacy bar they cannot undercut piecemeal.
The blueprint also aims to be forward-compatible with the European Digital Identity Wallet ecosystem, where selective disclosure and zero-knowledge techniques are baseline design goals. Interoperability matters: if proof-of-age rides inside the same privacy-preserving credentialing stack as other attributes, the market avoids parallel, less private solutions spawned solely for age checks.
The live controversy: privacy by design on paper versus practices in deployment
Civil-liberties and security researchers do not dispute the intent; they dispute the likely outcome. The Electronic Frontier Foundation argues that age-verification mandates, as historically implemented, chill speech, raise barriers to access, and jeopardize anonymity and security. The concern is structural: once services must screen for age, the cheapest, fastest path often involves document uploads to third parties, broad data collection, and cross-service identifiers—precisely what the cryptographic blueprint is designed to avoid. EDRi’s position paper widens the lens, pointing to heightened breach risks, pervasive tracking, and the chilling of legitimate activity, especially for vulnerable users who rely on pseudonymity to participate safely online.
Some critics collapse the distinction between identity proofing and ongoing identity disclosure. Journalist Taylor Lorenz argues there is no way to confirm age without confirming identity at every step, asserting that verification inherently de-anonymizes users. That is a pointed claim—but it does not wrestle with selective-disclosure credentials, which let a user bootstrap a one-time identity check into many future age attestations that do not reveal identity. In other words, identity may be involved at issuance; it need not leak at presentation if the system follows the cryptographic design.
What would make the system safe enough in practice
The difference between a civil-liberties-preserving age check and a surveillance backdoor is not rhetoric; it is engineering, governance, and market incentives. Four guardrails are decisive. First, strict selective disclosure by default: tokens must encode only age thresholds with unforgeability and unlinkability, so that a platform cannot stitch together activity across sites. The blueprint’s language on proofs that contain no identity data is necessary here, and certification must verify that property in live code, not just in documentation.
Second, hard separation of roles and logs: issuers should not learn where credentials are presented, and relying services should not learn the user’s source document or identifier. That implies privacy-preserving verification protocols and audit regimes that punish correlation. Third, inclusion pathways: people without smartphones, compatible IDs, or digital wallets must have equal access through offline or paper-based routes—otherwise the system becomes a gatekeeper that structurally excludes marginalized users, a central critique in advocacy literature. Fourth, real incident response: credential revocation without doxxing, vulnerability disclosure programs, and oversight that can compel fixes when vendors stray from the rules. Claims of “anonymous by design” will not survive first contact without this operational spine.
Comparing alternatives: estimation AI, document uploads, and carrier checks
Common substitutes fare worse. Face-based “age estimation” avoids documents, but accuracy gaps across demographics and lighting conditions make it risky as a gatekeeper; error-driven overblocking can be as exclusionary as an ID wall. Pure document upload systems centralize sensitive data, raise breach liability, and invite secondary uses. Mobile-carrier checks create coverage gaps and new linkage points to real-world identities. Against this menu, a properly implemented verifiable-credential model—crisp attribute, no identity leakage, cryptographic assurance—delivers the best privacy-to-assurance ratio available today, provided certification and enforcement keep vendors honest.
Tim Sweeney is unhappy with the EU’s new Kids Act proposal.
The EU Commission has proposed an EU-wide minimum age of 15 for minors to create social media accounts, therules also cover online games and add new safety and age-verification requirements.
Sweeney called the idea… pic.twitter.com/Y8hVZr3Dxb
— Pirat_Nation 🔴 (@Pirat_Nation) September 17, 2026
The bottom line: the policy is viable, if the blueprint rules the build
On the evidence, the EU’s child-safety age-verification project does not require identity checks for all adults. The official design choices—anonymous proof-of-age, selective disclosure, no identity in the presented proof—directly reject that outcome. The risks critics flag are real not because the cryptography is flawed, but because deployments drift: vendors seek growth, platforms favor frictionless onboarding, and regulators can privilege speed over rigor. Europe can resolve that tension the same way it has in payments security and data protection: certification anchored in testable technical criteria, red-teaming before scale, and meaningful penalties for correlation, logging, or data capture outside the age-attribute itself.
If that governance is in place, Europe can raise the floor for minors’ online safety without converting adult participation into an identity checkpoint. If it is not, the skeptics will be right—not about what the policy says, but about what, in practice, it becomes.
Sources:
commission.europa.eu, table.media, euronews.com, europarl.europa.eu, euperspectives.eu, fpf.org, digital-strategy.ec.europa.eu, reuters.com



