
FIRE warns age verification is quietly becoming identity verification
An analysis from FIRE argues that the global wave of age checks is turning into identity verification, and that the resulting surveillance infrastructure will be hard to dismantle once built.
An analysis published in FIRE’s Expression newsletter argues that the wave of age-verification rules spreading across the world amounts to something much larger: confirming a user’s age increasingly means confirming who that user is. The author, Sarah McLaughlin, a senior scholar for global expression at the Foundation for Individual Rights and Expression, calls it the arrival of a “papers, please” internet, in which taking part in public discussion depends on handing personal documents to platforms and to the third-party services they rely on.
Australia’s under-16 ban as a test case
Australia’s social media ban for under-16s took effect in December 2025 and has become the model other countries study. By the government’s own compliance research, roughly seven out of ten children were still using social media months after it began, and a study released in the British Medical Journal found little evidence of immediate substantive reductions in reported social media use by adolescents under 16. Phones are already banned in Australian schools, so the law targets what children do in their own time.
What age checks actually collect
Platforms face heavy fines unless they take sufficient steps to keep under-16s logged out, which in practice means collecting biometric data, government-issued IDs or other personal information. Snapchat, for instance, works with Singapore-based k-ID and accepts a banking connection, an ID scan or a selfie to establish an age range. Australia’s own Age Assurance Technology Trial found “concerning evidence” that, without specific guidance, providers were over-anticipating what regulators might want later and collecting and retaining more personal data than necessary. The risk is not hypothetical: weeks before the ban started, a breach at a third-party customer-service app Discord used mainly for age-assurance complaints exposed government ID images, names, usernames, email addresses and limited billing details of nearly 70,000 Australians. The government also acknowledges new phishing opportunities created by confusion around the rules.
Britain, Europe and the American path
The UK is preparing its own under-16 ban, which Prime Minister Keir Starmer promised would be “Australia-plus” before he resigned; officials have openly discussed targeting VPNs to stop evasion, and the children’s minister has floated age-gating VPN use. France, Spain, Indonesia, Malaysia, Greece, Denmark, Norway, the United Arab Emirates and the European Union are moving in similar directions. In the United States, at least 19 states have passed laws on minors’ access to social media and more than 20 have age-verification laws for adult-content sites, while the federal Kids Online Safety Act has been folded into a broader House package and negotiated with the White House. Both versions would effectively require platforms to verify ages and would override state law. FIRE warns the result is a legislative infrastructure of surveillance that will be very difficult to tear down once it is built.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.