Europe just moved to gate much of the internet behind age checks, and security researchers say the official app is already leaking sensitive data.
Story Snapshot
- The European Commission rolled out an age-verification solution tied to child-safety rules under the Digital Services Act.
- Brussels says the tool proves only age status, not identity, and aims to protect children from harmful content.
- Security researchers and privacy regulators warned of vulnerabilities, circumvention, and privacy harms, citing specific flaws.
- Critics fear a shift toward identity-gated access that could track people across the web despite “privacy-first” promises.
What the European Commission Announced and Why It Matters
The European Commission said a feature-ready age verification solution is now available for use across the bloc. Officials framed it as a tool to help platforms meet child-safety duties under the Digital Services Act. The Commission described the system as privacy-preserving and focused on a yes-or-no age check. It positioned the app as a common method Member States can adopt or adapt. The Commission highlighted child protection as the main goal of the effort.
Commission materials explain that the blueprint reached feature-ready status in April 2026. The plan invites national authorities and platforms to integrate the tool or build on it. The stated design aims to reduce data sharing by proving only an age threshold to a website. The Commission also tied the work to broader guidance on the protection of minors online, signaling a coordinated enforcement track under the Digital Services Act.
How the System Is Supposed to Protect Privacy
Commission guidance points to “anonymous proof-of-age” and “zero-knowledge” methods that avoid sending identity data to websites. Officials say the app lets users confirm they are over a set age without sharing a name or birthdate. The policy line stresses data minimization and strong privacy standards. The Commission argues this approach sets a high bar that platforms and national systems can meet while still blocking minors from adult content or features.
Supporters say the tool offers a clear path for companies that must restrict access to pornography, gambling, or other adult spaces. They argue consistent checks across Europe will reduce loopholes and make enforcement more predictable. The Commission signals that services can choose alternatives if they match privacy and effectiveness. The stated aim is a harmonized baseline that reduces risk to children while avoiding mass data collection by platforms.
What Researchers and Regulators Say Could Go Wrong
Security researchers told reporters they found serious flaws soon after launch. One consultant said the app stored sensitive data on a user’s device without proper protection. Another ethical hacker said he could bypass biometric checks on a phone unlocked by someone else. A cryptography researcher warned that a verified device could be reused by another person to claim adult status. These claims point to both privacy exposure and easy circumvention risks.
European Commission President von der Leyen on the launch of age verification for social media users in the EU:
For every user under the age of 18, platforms must adhere to the principle of "safety by default." No toxic or addictive features, no traps, etc.
Now, age will be… pic.twitter.com/RsOmep0DkL
— 𝕊𝕡𝕣𝕚𝕟𝕥𝕖𝕣 𝕻𝕣𝕖𝕤𝕤 (@SprinterPress) September 17, 2026
France’s data protection authority warned that current age checks are intrusive and can be worked around. It cautioned that forcing identification can link a person’s identity to their browsing, which can chill lawful activity. The regulator urged more privacy-friendly models that do not expose more data than needed. These warnings echo years of civil-liberties concerns about turning identity into a gate for normal online life.
Why This Fight Resonates in the United States
American readers see a familiar tension here. Many parents want stronger rules to shield kids from addictive feeds and explicit content. Many citizens also fear that “show your papers to log on” becomes the norm. The European plan says it hides identity while proving age. Critics counter that scanners, logs, and weak links can still reveal who you are. Both sides agree that poor design or rushed rollout could harm the very people the rules aim to protect.
For conservatives, the risk looks like another centralized system that grows government reach and creates new breach targets. For liberals, the risk looks like exclusion and tracking that hits the vulnerable hardest. For everyone tired of elite solutions that miss real-world faults, the early flaw reports feel like another “trust us” promise that leaked on day one. Strong child safety and strong privacy are both possible, but they demand slow, verifiable work, not slogans.
What to Watch Next: Tests, Audits, and Real Enforcement
Independent code audits will decide whether the “privacy-first” design holds up in practice. Clear fixes for any on-device leaks, biometric bypasses, and token misuse will be key. National data authorities will judge whether deployments meet privacy law. Platforms will have to prove their integrations do not expand tracking. If Europe can deliver a tool that truly gates by age without identity, that could set a global bar. If not, expect pushback and legal challenges.
Readers should watch for three signals. First, documented security patches with transparent change logs. Second, regulator findings on compliance and necessity. Third, evidence that minors are actually shielded without locking out lawful adult access or creating new surveillance trails. The core test is simple: protect kids without building a data dragnet. Europe says that is the plan. The coming months will show if the code matches the promise.
Sources:
youtube.com, digital-strategy.ec.europa.eu, cyberinsider.com, edpb.europa.eu, techpolicy.press, edri.org
© dailyanswer.org 2026. All rights reserved.












