What you have just experienced is a tipping point
An internet where you must state your identity at every door is an internet where you are never anonymous by default again. That is a serious setback for our privacy — as if, to walk down the street, you were required to wear a t-shirt with your first and last name on it. Our dossier details what the law actually requires, what it already looks like elsewhere, and what we all lose along the way.
1. What the law already requires — where you are
If you are reading this in Britain or in Australia, this is not a warning about the future. It is a description of your present.
In the United Kingdom, the Online Safety Act came fully into force on 25 July 2025. It requires "highly effective age assurance" for any content judged "harmful" — a deliberately broad category that covers pornography, but also suicide, self-harm and eating-disorder content. In Australia, access to social media has been banned for under-16s since 10 December 2025, backed by penalties of up to A$49.5 million — the most far-reaching scheme of its kind in the world.
The point that changes everything is arithmetic, not ideology: to stop under-16s (or anyone else) reaching a platform, you have to check the age of every single user. The ban targets minors; the burden of proof falls on 100% of the people who use the internet. And the two dominant ways to prove your age are to photograph an identity document or to hand your face to a biometric estimation system. Either way, to prove how old you are, you first have to prove who you are.
This is not a fringe reading. It is what the regulators' own numbers show, once the schemes actually run.
Sources: Ofcom, Online Safety Act guidance; Australian Online Safety Amendment (Social Media Minimum Age) Act 2024; eSafety Commissioner.
2. "Anonymous" age verification is a promise that cannot be kept
Public debate is full of designs described as privacy-preserving: double-blind schemes, single-use tokens, "zero-knowledge" cryptographic proofs, the forthcoming European digital-identity wallet. The architectures differ; the promise is always the same: prove your age without anyone knowing who you are. Take that promise seriously — and look at it squarely.
Proving an age means answering the question: "how old is this person?" The question contains the identity. If nobody, at any link in the chain, knows who you are, then nobody can know how old you are. An age attestation attached to no identified person attests to exactly one thing: that someone, somewhere, is old enough. Anyone can present it. It is worth nothing.
What "anonymous" architectures actually do is move the knowledge of your identity — never remove it. For the attestation to be worth anything, someone must have identified you: the state, your bank, your phone carrier, the verification provider. "Anonymous" only ever means that the platform doesn't know. The link that knows still exists; it now concentrates the identities of an entire country's internet users, and by construction it becomes the primary target. Section 3 shows what happens to the data when that target gives way.
The promise's last refuge is storing the proof on your device. No central server, the argument goes, so no target. But the problem does not disappear: it changes address. The vault is now the phone — tens of millions of consumer phones, whose collective security is that of the least-updated device in circulation. And a locally stored proof cannot escape the structural dilemma of the whole scheme:
- either the proof stays permanently bound to your verifiable identity — and you must identify yourself to use it: the promised anonymity is gone;
- or it is not — and it can be lent, extracted, copied. A teenager doesn't need to "hack" anyone: they borrow an adult's phone, the way they already borrow an adult's account (section 6). At national scale, a transferable attestation becomes a commodity — and a market appears wherever a constraint creates demand (section 12).
An age credential can be anonymous or non-transferable. Not both. Every real-world system resolves that dilemma one way or the other — and either way, the original promise is broken.
This section cites no study: it is an argument, and each of its premises can be checked in the sections around it. If someone shows you a system that claims to escape it, ask a single question: who knows who I am — and what happens when I hand my phone to someone else?
3. Data breaches are not a hypothesis

This is the simplest argument, because it requires no projection: it has already happened.
On 3 October 2025, Discord announced that one of its customer-support providers, 5CA, had been compromised. On 8 October, the platform confirmed that roughly 70,000 users may have had photographs of their official identity documents — passports, driving licences — exposed. Those documents had been supplied for age-verification checks. The attackers claimed far larger volumes (more than two million photos, unverified).
Three lessons, all of which transfer directly to any age-verification scheme:
- The breach was not at Discord. It was at a subcontractor. Multiplying "trusted third parties" multiplies attack surfaces.
- The data should never have been retained. The Register put the problem bluntly: nobody could explain why the provider was still storing these documents.
- You cannot reissue a passport. A compromised password is replaced in thirty seconds. A passport is not.
As Maddie Daly, of the Electronic Frontier Foundation, puts it: age-verification systems are surveillance systems, and anyone who hands over their data can never know where it ends up.
Sources: NBC News — nbcnews.com; The Verge; The Guardian; The Register — theregister.com and theregister.com; Proton — proton.me; Bitdefender — bitdefender.com — October 2025.
4. What the UK's own first months show
Documented within days of the Online Safety Act taking full effect:
- A VPN explosion. Proton VPN reported a 1,400% jump in sign-ups within minutes of the deadline, and up to 1,800% on downloads. NordVPN recorded +1,000%. By the following weekend, half of the UK App Store's top ten free apps were VPNs; Proton VPN overtook ChatGPT for the number-one spot.
- The volume. According to the Age Verification Providers Association, an additional 5 million age checks are carried out every day in the UK — for pornographic sites alone.
- Absurd collateral damage. The blocking swept up access to international news (coverage of Gaza and of the war in Ukraine), classical works of art, music on Spotify, Discord conversations, video games, stop-smoking resources, and even peer-support forums for people trying to overcome porn addiction — which now demand that you hand over biometric data to enter.
- Wikipedia. The encyclopaedia brought legal proceedings against the UK government, arguing that a "Category 1" classification would force it to verify the age of its readers and the identity of its contributors. Wikipedia announced it would not comply.
- Opinion turning. Within one week of enforcement, support for the law measured by YouGov fell from 80% to 69%. 26% of Britons said they had run into new restrictions.
One commentator summed it up: when a child-protection law's chief achievement is teaching children to use a VPN, the objective may have been missed.
Sources: Reason, 10 examples of absurd fallout from the U.K.'s Online Safety Act, 6 August 2025 — reason.com; The Guardian; Cybernews — cybernews.com; CEPA, Access Denied: The UK Online Safety Act Misses Its Mark — cepa.org; Ofcom, Age checks to protect children online — ofcom.org.uk; YouGov, How have Britons reacted to age verification?, August 2025 — yougov.co.uk.
5. What Australia's own regulator shows — and the argument at the centre
Australia's ban is the most complete in the world. Its results are available, and they were documented by the regulator itself.
- One month in, 4.7 million minors' accounts had been deactivated. The Prime Minister declared the measure was working.
- Three months in, the eSafety Commissioner found that a substantial proportion of under-16s were keeping their accounts, creating new ones, or getting past the verification systems. Around 70% of the minors concerned were still reaching the platforms. Between January and March, only 310,000 further accounts were affected.
- A peer-reviewed evaluation in the British Medical Journal (University of Newcastle), surveying more than 400 adolescents before, and again three months after, the ban took effect, found insufficient evidence of any significant fall in use, and substantial circumvention. More than 85% of under-16s were still using the targeted apps — even though two-thirds of them had come up against an age check.
- The political response was not to re-examine the scheme, but to harden it: doubling the fines (from A$49.5 million to A$99 million) and expanding the regulator's powers.
This is the most important mechanism to grasp, and the legal scholar Michael Geist has stated it plainly: the better the privacy protection, the less effective the ban. The workarounds — a false date of birth, a parent's or big brother's account (for once, Big Brother is how you escape the watching; Orwell wouldn't have dared put that in 1984), private browsing, a VPN — can only be shut off by identifying all users more intrusively. "Strengthening" the law therefore means, mechanically, less privacy and more surveillance. There is no version of this scheme that is both effective and respectful of anonymity. It is a trade-off, not an engineering problem waiting to be solved.
Sources: eSafety Commissioner, Social Media Minimum Age compliance reports, March and June 2026 — esafety.gov.au; British Medical Journal, 24 June 2026 — bmj.com; Michael Geist, The Data on Australia's Social Media Ban: The Better the Privacy Protection, the Less Effective the Ban, July 2026 — michaelgeist.ca; Al Jazeera, 16 January and 27 June 2026 — aljazeera.com and aljazeera.com; Reuters.
6. The ratchet, and where it points — the French preview

Every workaround you close forces a wider identification of everyone else. The chain is always the same:
- close the false date of birth → verify everyone's identity;
- close the borrowed account → verify identity at every log-in, not just at sign-up;
- close the VPN → check the identity of VPN users, or treat anyone who encrypts their connection as a suspect by default.
At no point does this process converge on something both effective and private. It converges on the permanent identification of everyone. And to see the next rung of the ladder, you do not have to speculate — you can look across the Channel, at a country running a few steps ahead in the open.
On 21 July 2026, the French National Assembly gave final approval to a law banning access to social media for under-15s, by 279 votes to 81 — new accounts blocked from September 2026, all existing accounts from 1 January 2027. France thus joined the same road as the UK and Australia, on the same logic, and its officials have already written down what the next stage looks like.
- The regulator warned in advance. In its formal opinion of 14 January 2026, France's Council of State (Conseil d'État) judged a blanket ban disproportionate under EU law, and recommended targeted measures rather than an absolute prohibition covering every social-media service.
- The VPN is openly named as the next target. On 30 January 2026, days after the first reading, the minister for AI and digital affairs, Anne Le Hénanff, was asked on France Info about the obvious workaround. Her reply: VPNs are the next item on her list. She acknowledged the loophole while defending a step-by-step strategy — if the law protects 65–70% of children, they carry on. No bill targeting VPNs has been tabled, and the government has said it never intended to ban them for adults. Anyone claiming VPNs are illegal in France is wrong.
- But the mechanism has already been drafted. During the passage of France's 2023 "SREN" digital law, one amendment proposed that VPN providers themselves verify their users' age, on a standard set by the regulator — the same regime as for pornographic sites and social networks. The penalty for failing: a fine equal to 1% of worldwide turnover. A second amendment, withdrawn before debate, proposed that any user identified as connecting through a VPN be treated by default as a minor until proven otherwise. Neither passed. Both are public, and they describe the next step with a precision no interview could match.
Note that using a VPN is entirely legal — in France as in the UK and Australia — and is recommended as basic digital hygiene by security agencies, including France's own national cybersecurity agency. Millions of people use one for remote work, for a public Wi-Fi connection, or simply to protect their data.
Sources: Council of State opinion of 14 January 2026; France Info, La Matinale, 30 January 2026; SREN amendment no. 232 — assemblee-nationale.fr; amendment no. CS504 (withdrawn) — assemblee-nationale.fr; eSafety Commissioner; British Medical Journal; ANSSI recommendations.
7. What you will not find here
You will not find a how-to for getting around any of these laws. That is deliberate, and it is not legal caution.
A law whose effectiveness rests on the public's technical ignorance is not a law that protects: it is a law that sorts. It applies to those who don't know how to get around it, and lets through those who do — which is very nearly the exact opposite of the population it claims to protect. Publishing the methods would prove nothing that the British and Australian regulators have not already demonstrated, with figures, in their own reports.
8. The right to anonymity exists
You often hear that anonymity online is a tolerance, or even an anomaly. In law, that is false.
The European e-Commerce Directive still sets out the principle of anonymous use of open networks such as the internet. The Court of Justice of the European Union holds that users of electronic communications are entitled to expect, absent their consent, that their communications remain anonymous and are not recorded. The European Court of Human Rights — whose Convention still binds the United Kingdom — ties this principle to freedom of expression. Requiring someone to prove their identity before they may speak is the exact inverse of that principle.
The EU legal basis for age-verification mandates is contested, too. Article 28 of the Digital Services Act requires platforms to give minors a high level of privacy and safety — and its paragraph 3 states expressly that it does not require platforms to process additional personal data to work out whether a user is a minor. A verification mandate does precisely the opposite. A case concerning the French SREN law — the age-verification requirement for pornographic sites — went all the way to the CJEU: the Advocate General had cast doubt on whether the French scheme complied with EU law; on 16 June 2026 the Court ultimately held that protecting minors can justify such national measures. That dispute turned on the e-commerce directive; the argument over Article 28 of the DSA remains open for social networks.
Sources: Directive 2000/31/EC — eur-lex.europa.eu; CJEU, La Quadrature du Net and Others, Joined Cases C-511/18, C-512/18 and C-520/18, 6 October 2020 — curia.europa.eu; ECtHR, Standard Verlagsgesellschaft mbH v. Austria (no. 3), app. no. 39378/15, 7 December 2021 — hudoc.echr.coe.int; Regulation (EU) 2022/2065 (DSA), art. 28 — eur-lex.europa.eu; CJEU, WebGroup Czech Republic and NKL Associates, Case C-188/24, judgment of 16 June 2026 — curia.europa.eu.
9. What is actually lost

The "I've got nothing to hide" argument assumes anonymity only serves to conceal. In practice it underpins a social infrastructure that is mostly invisible while it works:
- journalists' sources;
- whistleblowers;
- survivors of domestic abuse rebuilding a life without being traced;
- people looking up information about their health, their sexuality or an addiction without it being tied to their legal name;
- teenagers exploring an identity they cannot yet reveal at home.
None of these uses is left-wing or right-wing. None survives a requirement to identify yourself first.
Age verification also excludes, mechanically and beyond minors: people without an identity document, people who are not comfortable with digital tools, and people whom biometric systems recognise less reliably — the racial and gender biases of these systems are well documented.
10. Social media is not only harmful
This site does not claim commercial social networks are harmless. They are not: recommendation algorithms built to maximise time spent, the surfacing of suicide-related content to teenagers documented by Amnesty International in 2025, US rulings against Meta and Google over addictive mechanisms — all of it is real, and the problem is the advertising business model, not the age of the users.
The platforms themselves are not fighting age verification, incidentally: they are fighting over who has to do it. Meta spent $26.3 million on US federal lobbying in 2025 — a company record — and openly supports, alongside Snap and X, the "App Store Accountability" laws passed in Utah and then Texas: these hand age verification to Apple's and Google's app stores, that is, to everyone except the social networks themselves. Apple and Google push back in mirror image, each arguing it is the other's job to collect your data. When every giant lobbies for the surveillance to be run by its competitor, "it's for the children" deserves to be read for what it also is: a fight over who bears the cost.
But the research also establishes benefits, and ignoring them distorts the debate:
- A measurable optimum at moderate use. The OECD report Growing up in the social media age (2026) describes an inverted U-shaped relationship between children's social media use and their socio-emotional well-being: no use and heavy use are both associated with lower well-being, moderate use with higher well-being. Students reporting moderate use even outperform non-users in mathematics. A blanket ban does not aim at the optimum the data describe: it outlaws it.
- Social connection and reduced isolation. Adolescents draw a sense of belonging and peer support from being online, especially valuable for those whose offline support network is thin.
- Marginalised young people. A systematic review published in the Journal of Medical Internet Research (2022) concludes that social media can support the mental health of LGBTQ+ young people through peer connection, identity-building and social support — in an environment that offsets heteronormative settings. The 2023 US Surgeon General's advisory likewise notes that marginalised youth can benefit in specific ways from these connections.
- Geographic isolation. LGBT+ young people in rural areas report higher online use and support than their urban peers: the digital compensates for a lack of nearby support.
- Identity, skills, engagement. The literature identifies relatively safe spaces for self-expression, skill development, pursuing interests, and opportunities for civic engagement.
One synthesis in JMIR Mental Health proposes an explicit alternative to bans: stop reaching for ineffective prohibitions, acknowledge the real benefits, and build adolescents' emotional-regulation skills and autonomy. It is slower than a law. It is also what works.
Sources: OECD, Growing up in the social media age, OECD Digital Economy Papers No. 385, 2026 — oecd.org; Berger et al., Sexual Health, 2021 — pubmed.ncbi.nlm.nih.gov; JMIR systematic review, 2022 (PROSPERO CRD42020222535) — jmir.org; Social Media Use in Adolescents: Bans, Benefits, and Emotion Regulation Behaviors, JMIR Mental Health, 2024 — mental.jmir.org; Digital Wellness Lab (Boston Children's Hospital) — digitalwellnesslab.org; U.S. Surgeon General, Advisory on Social Media and Youth Mental Health, 2023 — ncbi.nlm.nih.gov; Amnesty International, Dragged into the Rabbit Hole, 2025 — amnesty.org; OpenSecrets, Meta lobbying expenditure, 2025 — opensecrets.org; CNBC, 26 March 2025 — cnbc.com; TechCrunch, 27 March 2025 — techcrunch.com; CNN, 13 March 2025 — cnn.com.
11. Parental controls already exist
There is an obvious point the public debate has carefully stepped around: the tool already exists. Every mainstream operating system, mobile or desktop, ships with complete, perfectly functional parental controls — Family Link on Android, Screen Time on iPhone, iPad and Mac, Microsoft Family Safety on Windows.
App restrictions, content filtering, screen-time limits, approval of installs and purchases: it is all there, at no extra cost, with nothing to prove, and without anyone's identity document being sent to anyone.
The decision stays where it makes sense — in parents' hands, device by device, child by child — instead of requiring 100% of the population to identify itself. A scheme that protects minors without registering adults already exists; it is simply less spectacular than a law.
Sources: official documentation — Google Family Link; Apple Screen Time; Microsoft Family Safety.
12. Where this site comes from
This site is French. It was built in response to the French law of 21 July 2026 — but as the pages above make clear, that law is not a French peculiarity. It is one country's version of a policy the UK and Australia are already running, and the argument it makes is the same wherever the scheme lands.
The idea came from a question asked publicly on X by a French journalist specialising in tech. He was probing a blind spot in the law: since platforms won't know our names — pseudonymity is meant to be preserved — what stops the wholesale resale of "verified adult" accounts? He imagined the appearance of "swarms of 'adult' accounts at €50 a time."
The question has no reassuring answer, and that is the whole problem. A market appears wherever a constraint creates demand. Verified accounts will be resold. "Validation services" will spring up, hosted outside the country, with no obligation to delete, no supervisory authority, no recourse. Some will be outright scams. Others will work — and will therefore be databases of real-world identities bolted onto named accounts, exactly the kind of infrastructure that eventually leaks.
Notice the price of our "complete" offer: €50. It is not an accident. It is the figure a specialist journalist reached off the top of his head, three days after the vote, imagining this market. We invented nothing: we built the shop window. It took us a few days. The people who do it for real will not have our scruples — and they will not tell you, at the end, that nothing was collected.
So the real question is this: would you be willing to pay to stay anonymous?
If your answer is no, know that others will say yes — and that this market will exist, because the demand will be there.
If your answer is yes, ask yourself at exactly which point anonymity stopped being a right and became a paid-for service.
The people who voted for these laws are not your enemies. They are your representatives — that is the whole meaning of the mandate they hold. A representative who is never contradicted ends up believing they were right.
Write to yours. Politely, firmly, in your own name. A reasoned message from an identifiable voter carries more weight than a thousand anonymous comments — and there is an irony there we'll leave you to enjoy.
➡️ United Kingdom — find your MP and their contact details — search by your postcode on the UK Parliament website.
➡️ Australia — find your federal member — and, for the online-safety scheme specifically, the office of the eSafety Commissioner. If you are elsewhere, write to whoever represents you: the trajectory is not confined to one country.
➡️ To contact this site's author: @FranceMajorite, on X — pseudonymously, while that is still possible.
Going further
- Electronic Frontier Foundation — digital rights: eff.org
- Open Rights Group — UK digital civil liberties: openrightsgroup.org
- Digital Rights Watch — Australian digital rights: digitalrightswatch.org.au
- La Quadrature du Net — the French digital-rights group behind much of the reporting above: laquadrature.net
This site is a work of satire. It offers no service, collects no data and never has. The facts, figures and quotations above are sourced and verifiable; we encourage you to trace every source back rather than take our word for it.