Commission to present social media ban with age-verification requirement

At the State of the European Union address in July 2026, Ursula von der Leyen announced plans for an EU legislative proposal banning social media access for younger users, with implementation relying on a dedicated age-verification application. The Commission had previously promoted this tool as "technically ready and soon available for citizens to use," though the characterization drew immediate criticism. Rather than delivering a finished product, the Commission released only a blueprint—a reference design intended to guide Member States in developing their own applications, accompanied by a demonstration version. The proposal draws technical specifications from the eID Wallet framework, which all EU governments must provide to residents by the end of 2026, and the Commission refers to this age-verification system as the 'mini-wallet'.

Digital rights advocates argue that online safety objectives need not depend on mandatory, universal age verification. Should lawmakers proceed with age-gating mechanisms, however, the systems must meet the highest standards for privacy, security and data protection while remaining accessible without discrimination. The Commission claims its offering meets these criteria, yet substantial gaps remain between the promise and the technical reality. Examining the control infrastructure now being rapidly deployed reveals significant shortcomings.

Batch issuance leaves privacy gaps unaddressed

The foundation itself presents problems: the mini-wallet architecture depends on the eID Wallet, which already contains notable privacy vulnerabilities. The European Commission appears to be relaxing privacy safeguards mandated by law for the Wallet. Legislation requires the system to "ensure" unlinkability where applicable—meaning your age-verification activities should remain disconnected from your actual identity. The Commission has reframed this obligation to merely "hinder" linkability, suggesting difficulty rather than impossibility in making connections. This represents a weak starting position for the new age-verification measure.

The mini-wallet's technical specifications do not guarantee unlinkability. Age verification relies on a 'trust anchor'—a dependable source, in this case your government-issued ID paired with the mini-wallet through biometric matching. This approach creates barriers: those without proper identification documents, suitable devices, or willingness to submit to facial recognition face exclusion. Proving age over 18 to a restricted service without disclosing identity or ID information is technically feasible through cryptographic methods like Zero Knowledge Proofs (ZKPs). The Commission's technical specifications reference ZKPs but do not mandate their use.

The blueprint employs the permissive language "SHOULD" when addressing Zero Knowledge Proofs, rather than the binding "SHALL":

  • Age-verification applications "SHOULD implement the Zero-Knowledge Proof mechanism specified"
  • Service providers receiving age credentials "SHOULD implement the Zero-Knowledge Proof verification mechanism"
  • Credential issuers "SHALL support batch issuance of Proof of Age attestations" and "SHALL set the timestamp […] with a precision that limits the linkability information"

Rather than requiring deployment of the most robust privacy technologies, the blueprint mandates 'batch issuance'—a technique offering inadequate privacy safeguards. Under batch issuance, providers distribute multiple single-use credentials; presenting different ones to various age-gated services prevents those services from recognizing overlapping users. However, these credentials retain identifying elements unique to each user or credential—salts, hashes, public keys, signatures, timestamps—that providers can trace back to individuals. Cooperation between credential providers and websites, whether voluntary or compelled, would enable identification across services. Batch issuance complicates tracking but does not prevent it, making it unsuitable as a standalone privacy-preserving mechanism.

Zero Knowledge Proofs alone cannot guarantee privacy

While the absence of mandatory ZKP requirements is problematic, making them compulsory would still not ensure a genuinely privacy-preserving system. The blueprint recommends that "an Attestation Provider also acts as the provider of an Age Verification App to which it issues attestations." Concentrating both credential issuance and presentation authority in one entity facilitates easier surveillance—the issuer, such as the state, gains simpler access to observe whenever credentials are presented to age-gated services.

Additionally, the blueprint states the Attestation Provider is "not required" to retain permanent records of age attestations. Data minimization demands stronger language: providers "SHALL NOT store any permanent information related to a Proof of Age Attestation." Depending on actual system architecture, linkability could still occur through backend transaction processing, network-level communications, or correlation of issuance and presentation patterns. As 438 security and privacy researchers have emphasized, if the central authority managing the system possesses technical capacity to connect data points, privacy breaches become inevitable upon system compromise, legal demands, or malicious action.

Mandating ZKPs alone proves insufficient for achieving strict unlinkability. Centralized age-verification systems require comprehensive independent evaluation ensuring data collection minimization, proper separation of actors and roles, restricted logging and retention, and privacy-protective network technologies where applicable. The problem extends beyond the documented security flaws discovered in the Commission's demonstration app, where independent review identified fundamental, elementary security deficiencies.

Twenty-seven potentially divergent implementations create oversight challenges

Comprehensive independent evaluation becomes essential if privacy-preservation claims merit credibility. The eIDAS Regulation mandates that governments publish their eID Wallet applications as open source, theoretically enabling public code inspection. However, the Regulation permits governments to withhold transparency regarding "source code for the libraries used, communication channel or other elements that are not hosted on the user device" when justified. Critically, this transparency requirement applies only to national eID Wallets, not to national age-verification applications, which may or may not integrate with or derive from the eID Wallet.

Several governments are already deploying age-verification systems incorporating proprietary components. Denmark's application contains proprietary client-side code, preventing meaningful independent public examination. Given the surveillance potential of age-verification apps and wallets for monitoring online behavior, any impediment to system auditability undermines user confidence.

Multiple governments indicate they will not adopt the Commission's proposed technical specifications. This could result in 27 distinct age-verification applications, each with different designs, technologies and privacy standards. Each system would require independent auditing at deployment and throughout operation. Identifying problems offers limited recourse—only public pressure—to compel governmental improvements. Once infrastructure exists, the 'privacy-preserving' designation can be abandoned or rendered meaningless without warning. Several EU Member States already contemplate systems requiring disclosure of legal identity, not merely age, for social media (Belgium) or video-sharing platform access (Austria).

Age verification represents the termination of unrestricted internet access. Rejection of this infrastructure—at both EU and national levels—remains possible while alternatives exist. Online safety can be achieved through different approaches.

Source: EDRi (European Digital Rights)