Zero Knowledge, Full Record: Age Verification And The Infrastructure The Privacy Label Ignores
The “privacy-preserving age verification” label should be understood at two separate levels: on the one hand, it accurately describes a mechanism, yet on the other, it misleadingly describes a system. The protection it refers to covers a single exchange between a user and a website; the infrastructure that makes that exchange work requires knowing who the user is. The former may be preserving privacy, but the latter certainly doesn’t.
That distinction has consequences. The label converts a structural question about architecture into a resolved technical claim, and every objection to age verification on privacy grounds encounters the same response before it can be made: “But it is privacy-preserving!”
The reality is that that response is wrong about the architecture, even where it is right about the cryptography.
What the mechanism sees and who keeps track
Zero-Knowledge Proof (ZKP) is a genuine cryptographic technique. It allows a user to prove a property to a website, in this case, that they meet an age threshold, without revealing the underlying identity data. Think of it as a nightclub door: the staff member checks a membership card, confirms you are old enough to enter, and waves you through without writing anything down. The door sees only the result. The membership office that issued the card, however, holds the complete file: your name, address, the documents you provided, and the date of issue.
On the internet, the website identifies that the threshold is met and nothing else. That protection is real. But before a ZKP can be presented, an Identity Provider must have verified the user’s age and issued a credential. The zero-knowledge applies to the website. The Identity Provider, however, retains the knowledge that the system depends on.
Georgetown computer scientist Steven Bellovin, in a 2025 paper, examines the full architecture of privacy-preserving credential schemes and identifies the obstacles to deploying them at population scale as “possibly insurmountable.”
The definitional problem goes further. An open letter published in March 2026 and signed by over 400 security and privacy researchers from 32 countries identifies a gap between what “privacy-preserving” promises and what deployed systems deliver. In rigorous cryptographic usage, unlinkability means that no entity, including the system’s own central authority, can connect data points across interactions. In deployed systems, the term is applied in a weaker sense: external verifiers cannot link individual sessions, but the central authority retains a complete view of user activity. Where regulators do not mandate the stricter interpretation, systems default to the easier, centralised implementation while claiming privacy compliance. That central authority becomes a single point of failure: a breach, a subpoena, or a decision to act in bad faith removes the protection the architecture was supposed to provide.
When Discord implemented age verification for UK users under the Online Safety Act, government ID images were held by a third-party verification vendor. A breach of that vendor’s systems in October 2025 exposed approximately 70,000 users’ government ID photographs. Compliance with the UK Online Safety Act created the data store. The data store created the target. As the Electronic Frontier Foundation (EFF) observed, centralised credential handling creates a target regardless of which vendor holds the data.
The infrastructure it requires: the building behind the door
For credential-based age verification to function, Identity Providers must exist, be trusted, and be accessible to the full population subject to the regulation. Countries with strong national digital identity systems, Estonia being the example most cited in the technical literature, are better positioned to build this infrastructure. Most EU Member States, and the UK, are not.
The access problem predates any particular technology. Identity verification requirements create barriers that affect the same populations regardless of which system enforces them: elderly people without smartphones, rural populations without access to in-person verification offices, homeless people without stable addresses, and refugees whose documentation existing systems do not recognise. Basically, the costs of identity verification fall hardest on people who already find access to state services difficult.
The EU’s proposed answer is the EU Digital Identity Wallet. The Commission has committed to keeping the wallet optional, with paper alternatives always available. Age verification, however, breaks that commitment in any application where a paper substitute cannot function. Where age gates are mandatory, the optional wallet becomes a gating requirement, in the same way that a passport is technically a document you chose to obtain, but in practice, the only means of passage once border checkpoints require it.
The wallet’s design makes the problem worse. It will aggregate age, address, phone number, health insurance status, driver’s licence, diplomas, and potentially commercial records. Bart Preneel, Professor of Applied Cryptography at KU Leuven, speaking in an information labs video capsule on age assurance, notes that service providers who accept the wallet credential may request attributes beyond what the verification purpose requires. The optional and narrow infrastructure is then likely to become the mechanism through which a broader data request is normalised.
A further constraint operates at the device level. Privacy-preserving credential systems that depend on complex cryptographic protocols require hardware capabilities not present on all devices. The researchers’ open letter notes that this steers users toward devices from mainstream manufacturers while excluding open operating systems favoured by those most concerned with their privacy. The manufacturer providing the necessary hardware or cryptographic library then holds effective control over the verification ecosystem.
That risk has already materialised in the EU’s own wallet rollout. A Follow the Money investigation published on 18 June 2026 found that the Netherlands and Italy have built wallet implementations where integration with Google and Apple became “unconditional”: users require an account with one of those companies to use the national wallet. The Commission’s technical specifications do not mandate this dependency; it emerged because using the verification software provided by Google and Apple was the easiest path for developers to meet the requirements. Jaap-Henk Hoepman, Associate Professor of Digital Security at Radboud University, put the question directly: if dependence on Google is not necessary, why introduce it? Germany and France have cited digital sovereignty explicitly as a reason to build implementations that do not depend on US platforms at their core. The Commission, asked about the divergence, said it was “considering” further clarifying the technical requirements.
At a time when digital sovereignty dominates the political discourse and the EU calls for strategic independence from US technology platforms, the infrastructure it has mandated is, in several Member States, being constructed on top of those same platforms.
Circumvention: all the available exits
Effective age gating requires closing every available exit. A Virtual Private Network (VPN) can route traffic through a jurisdiction without age verification requirements. A service provider outside EU regulatory reach offers equivalent content without compliance obligations. Secondary markets for false credentials develop wherever primary credential requirements are imposed.
The comparison that recurs in technical literature is the Great Firewall of China, not as a political equivalence but as a structural description of how gating infrastructure behaves once built. It escalates in response to circumvention, expands in scope over time, and the users it fails to capture migrate not to safer environments but to less regulated ones. Preneel puts the security consequence directly: users who bypass age verification become more exposed than before, operating outside GDPR coverage on platforms that treat data collection as a primary revenue model.
When privacy evaporates and discrimination sneaks in
Zero-knowledge credential systems are technically demanding. They require infrastructure that most platforms cannot build or fund. Where the cryptographic approach is unavailable, platforms deploy age estimation instead: biometric analysis of face images, voice recordings, behavioural patterns, and usage histories.
The technical performance of age estimation creates an additional problem alongside the privacy one. A 2025 interdisciplinary review of online age gating found that estimation algorithms perform poorly near legally significant age thresholds. Research by the US National Institute of Standards and Technology (NIST) has documented significant race and gender effects on facial recognition performance; age estimation inherits these. A system that makes its highest rate of errors at the precise boundaries that determine access to services, and with error rates that vary by demographic group, is both a privacy problem and a discrimination problem.
The label in policy: caring only about the sign on the door
Heather Burns, writing in May 2026, invokes the late Professor Ross Anderson’s formulation: the idea that complex social problems are amenable to cheap technical solutions is “the siren song of the software salesman.” Burns documents a decade-long pattern in which civil society advocates raising technical objections to age verification were positioned as opponents of children’s safety, while vendors with products dependent on regulatory mandates had consistent and uncontested access to policymakers.
The March 2026 open letter signed by 438 researchers, including Ronald Rivest, co-inventor of the RSA cryptography algorithm, and Roger Dingledine, co-creator of Tor facilitating anonymous browsing, calls for a moratorium on age assurance deployment until scientific consensus is established on whether these systems are effective and what harms they produce. Their conclusion is the same as Burns’: the mandate is running ahead of the evidence, and the architecture it is building will not be easy to dismantle once deployed.
The Stop Killing the Internet campaign, launched in the UK in direct response to announced social media age restrictions, captures the sequence that Bellovin identifies as mission creep: credential infrastructure built for one purpose provides the architecture for others.
A lock on a structurally unsound house and a misleading label
The EU’s Digital Services Act, the GDPR, and the upcoming Digital Fairness Act provide a legislative basis for directly addressing design harms: regulating addictive features, restricting algorithmic recommendation systems that amplify harm, and limiting data collection practices lacking a legitimate basis.
Age verification is a lock on a door. The harm it is designed to address, and that affects adults and minors alike, sits in the building. Focussing on the lock while leaving the unsound construction unchanged addresses neither the harm nor the architecture that produces it.
“Privacy-preserving age verification” is a label that describes one verified moment in a long chain of institutional knowledge. The Identity Provider knows who you are. The credential database is an attack surface waiting to be found. The fallback to biometric estimation reads your face. The label names the narrowest component of the architecture and presents it as the character of the whole authentication chain. What the mechanism preserves is privacy at a single point of handoff. What the system does with everything preceding and following that handoff is a different question, and the label has no answer to it. But for some, hiding behind a label seems enough.
Written by Caroline De Cock, LL.M., Head of Research
