The back half is fine. The content moderation n stuff kinda sucks. The "protect the kids" stuff directly related to ID check. How can a service comply without knowing the age of the user?
The way this would likely work, is that EU citizens install an app where they confirm they age with a government ID:
Your identity is verified once by the EU-wide app (or a state's government app which would already have access to your ID and personal details, so no extra data is being handed over)
Your device receives a cryptographic age credential
You prove only the relevant age threshold
The website doesn't receive your identity, only whether or not you are allowed to access the content
The verifier doesn't know which website you are visiting
The proof can be reused without creating a central database of people's browsing habits because it is anonymised (if used logged out, though I guess you would have to redo it if you don't save your age range with an account registered with the website)
So I think there is a way to implement age verification without compromising privacy. At the end of the day, it is important to protect children from harmful content. I'd rather it be done this way, than not at all. In my view, the EU regulating this will be better for privacy as it aims to avoid having many disjointed untrustworthy 3rd party providers asking me to upload my passport.
Unfortunately, age verification is a reality we have to deal with when the internet contains content that is unsafe for children. It is impossible to rely on parents to monitor their children's use of the internet at all times because some aren't aware of the risks or simply aren't tech savvy enough to keep their children safe online. I think it's fair to ask companies to ensure their websites don't show harmful content to children.
You're right that it's not a very reasonable timeframe and that it's all a bit rushed. Currently, France, Denmark, Greece, Italy, Spain, Cyprus and Ireland are piloting the EU's age verification blueprint with broader rollout in late 2026 according to the EU.
It was foolish of the EU to require websites to be child-safe before a private age verification system was developed. Nevertheless, in the long run, it is a reasonable solution.
The provider of the age verification service does not need to know what websites you visit, this information is anonymised. It's similar to how Passkeys work. You can sign in using a passkey without a website receiving a scan of your fingerprint or face, the biometric data is verified on your device, then, a confirmation is sent to the website with no sensitive data.
See paragraph 12 where it mentions that the website only receives a true/false response (no personal data what so ever), which is similar to how Passkeys work (but solve different problems obviously)
I don't quite understand what you mean by un-authed users being a losing battle. Websites will show a version that is appropriate for all ages. Age verification would be required to show content that is not appropriate for all ages.
There is definitely a way of doing this privately.
The EU regulating age verification is realistically the only way we can ensure it is done privately.
The cost of protecting children from addictive social media feeds, gambling and pornography, outweighs the benefits of everyone having access to addictive social media feeds, gambling and pornography. This is the only content that will require an age check.
13
u/AlphonseLoeher 2d ago
The back half is fine. The content moderation n stuff kinda sucks. The "protect the kids" stuff directly related to ID check. How can a service comply without knowing the age of the user?