Governments from the UK to Europe, Australia and Brazil have taken a tough stance on online age checks, arguing these controls are vital to protect children, but according to security scientists, they risk exposing users to unprecedented privacy and data collection risks.
Penning an open letter to lawmakers around the world, a collection of 371 security and privacy academics warned that the mass rollout of age-assurance technologies must be paused until their impact is better understood, and until regulators can demonstrate that such systems are technically feasible.
Arguing that current debates over regulating social media, AI chatbots, and messaging apps go “well beyond what has ever happened in our offline lives”, and lack the inherent privacy provided by ID document-based checks in the real world, as users, both adult and children, are forced to reveal far more information to service providers.
“Age estimation and age inference technologies are highly privacy-invasive,” reads the letter.
“They rely on the collection and processing of sensitive, private data such as biometrics, or behavioural or contextual information, for example, language use. Therefore, deploying these age assurance methods at a large scale facilitates data collection and exploitation.
“The mandate to implement age assurance justifies new forms of data collection by online services, especially for age estimation and age inference. This in itself increases privacy risks, with data being potentially abused by the provider itself or its subcontractors, or third parties that get access to it.”
We have already seen these risks play out – in October, official ID photos of around 70,000 Discord users collected for age-verification were leaked following the breach of a third-party service provider.
The scientists also cautioned that effective age‑assurance systems would be near impossible to implement, require global collaboration, and result in huge costs, yet there would still be no guarantee they would address underlying harms.
Noting that, at the moment, age checks are easy to get around using VPNs, bought or borrowed credentials, or even AI deepfake tools to change appearance, the researchers said that the mechanisms available to introduce effective age assurance technology are unreliable and prone to abuse.
Technically Unworkable
Focusing on the sheer technical scale of the challenge, the researchers argue that for age‑assurance systems to function at all, they would need to operate at internet scale, but the trust infrastructure required to support them simply doesn’t exist, with the prospect of enforcing such a system globally “seems doubtful”.
Again, this issue is already widely recognised, with VPN signups surging in the UK last year following the Online Safety Act’s restrictions on porn sites – a loophole which the government has so far left untouched.
Recommended
- UK Gov Launches ‘World’s Most Ambitious’ Consultation on Social Media Use
- X Under Fire Over ‘Staggering Amplification of Hate’ During UK Riots
- Big Tech Faces EU Digital Services Act Reckoning
Further, the letter argues that age‑assurance checks are not only ineffective but can actively undermine online safety, pushing users, especially children and teens, toward riskier corners of the internet where they are more exposed to malware, scams, and people seeking to exploit or monetise them.
“We believe that it is dangerous and socially unacceptable to introduce a large-scale access control mechanism without a clear understanding of the implications that different design decisions can have on security, privacy, equality, and ultimately on the freedom of decision and autonomy of individuals and nations,” concludes the letter.
The stance runs counter to broad agreement that the internet needs tougher, more reliable age‑verification measures, especially within the UK, where research shows that 69% of the public support the introduction of age checks.
With Labour mulling an outright ban, or at least punishingly restrictive limits on children’s access to the internet, public support may be all but guaranteed, yet the backlash will be swift if the measures prove heavy‑handed or unworkable.
Join the Conversation at ITSX Summit
How is customer service and IT support evolving in the age of AI, automation, and digital transformation?
Join us at the ITSX Summit in Edinburgh on 5th March, to unpack the future of ITSM, ESM, Self Service, and User Experience.
The event will bring together senior leaders from IT, Service Management, and UX, providing an ideal forum for shared learning, collaboration, and high-level networking.
Register now to secure your free place at ITSX Summit.





