SHOW ME YOUR ID: Carney doubles down on sweeping internet regulation bill

Prime Minister Carney says his government will push ahead this fall with sweeping social media regulations that would create a new federal Digital Safety Commission and impose new rules on online platforms.

“We are fighting for Canada to lead the world in building the smart, safe digital tools of the next decade,” Carney told Liberal MPs ahead of Parliament’s return.

“This fall we will press ahead with the Act to protect Canadians online,” he said.

Bill C-34, the Safe Social Media Act, was introduced by Canadian Identity and Culture Minister Marc Miller in June.

The legislation would create a Digital Safety Commission with regulatory and enforcement powers over the online platforms covered.

It would require regulated platforms to address seven categories of “harmful content,” including child sexual exploitation, any content that ‘foments hatred’, incites violence or promotes terrorism or violent extremism.

The legislation also targets content that “undermines, weakens or destroys fundamental institutions or political, economic or social stability in Canada” when it could cause a serious risk to the health or safety of the public.

Keep reading

The Mexican Government Is Cutting Off Users Who Refuse to Register Their Phone Lines

The Mexican government and Mexican telecommunications companies have disconnected millions of phone lines belonging to citizens who failed to register their phones with their identities. The move comes just two months after the government announced a delay in the registration deadline due to less than half of the country complying.

In early September, Mexico’s Telecommunications Regulatory Commission (CRT) released a statement claiming that about 9.55 million phone numbers ending in “1” were registered. The CRT said about 1.9 million had been temporarily deactivated for failing to register on time. The agency claimed more than 1.16 million were reactivated after registration.

In June, the CRT announced a staggered extension for citizens to register their mobile phone lines with their identification. The new deadlines were based on the final digit of the phone number, with phone numbers ending in “0” given until August 15 to comply, numbers ending in “1” given until September 1, and so on until December 31.

While announcing the numbers for September 1 registration, the CRT reiterated its claimed purpose for linking phone numbers to individual identities, stating:

“This link seeks to eliminate anonymity on mobile lines to contribute to the fight against crimes committed through cell phones, such as fraud and extortion.”

However, since the cancellation of phone lines has begun, Mexican citizens have been posting on social media detailing their skepticism. They are increasingly concerned about how their data might be stored and who might have access to it.

These concerns are particularly prescient after numerous hacks of Mexican government databases, including one in late 2025 in which hackers used Claude AI to gain access to private information. As one user wrote:

“I’m really upset: because they didn’t register my line, they suspended my service and I was left without data. I paid for the phone, I pay the balance, and the service too. Why do I have to give more personal information just to use it? More citizen info doesn’t mean more security.”

Some users said they had registered in time, but were still disconnected.

“They suspended my line, my deadline hasn’t passed yet, the app says my line is already registered… and then what? I’ve been waiting for over two hours for a turn in the chat and on the phone and nothing, just a bot”

Keep reading

EU’s Social Media Ban Could Bring ID Checks for Adults

As expected, European Commission President Ursula von der Leyen has announced that the EU Kids Act will propose that no child under 13 should be allowed on social media, while 13 and 14-year-olds should have limited accounts.

The announcement, just in time for the EU’s planned digital ID rollout, was made in von der Leyen’s State of the European Union address in Strasbourg on Wednesday.

According to von der Leyen, the Act would ensure that “no social media under the age of 13. No personal account under the age of 15.”

Children between the ages of 13 and 14 will be allowed a limited account, with a limited set of features, and with a time limit of one hour a day, and parents will have to set up and supervise these “mini accounts.”

Von der Leyen also said that the Act would reverse the burden of proof, so that instead of regulators having to prove that a service is unsafe, it will be up to the platforms to prove that their product is safe for minors.

The Commission President also took aim at Big Tech, saying, “I am aware that many perceive the power of big tech as overwhelming and impossible to roll back. I disagree.” She added, “Europe has the power to act. It is us who decide the rules, not Big Tech.”

The scope of the Act will cover social media, video sharing platforms, app stores, online games, as well as AI companions and chatbots, with a focus on “high-risk” services, although the definition of that category is not yet clear.

Other rules that have been reported as part of the Act are age checks for every new account, with existing users also subject to “proportionate” checks, taking into account the time they have been subscribed to a service. Verification will be done via an app, either the one developed by the Commission or a national equivalent. These apps will only return information about whether a user is over or under a certain age.

The draft also reportedly seeks to ban certain design features, such as infinite scrolling, autoplay, and push notifications, as well as artificial notifications and rewards. The text is said to state that “technology companies bear primary responsibility for making their products safe.”

Fines for non-compliance can reach up to 6% of a company’s global annual turnover, while a supervisory fee will be introduced to make sure the Commission can enforce the new rules.

The Commission’s app was presented by von der Leyen in April in Brussels, and at the time, she said it was “fully open source. Everyone can check the code.”

But security consultant Paul Moore took the Commission up on that and found that the app stores sensitive data on phones and leaves it unprotected. According to Moore, he was able to hack the app in under two minutes.

The Commission first responded to this by saying the app was ready and could always be improved. A week later, a spokesperson described the version presented as “a demo version.”

Keep reading

Revolut Leak Shows the Cost of Constant ID Collection

Online bank Revolut has revealed that it gave out sensitive personal and financial information of an undisclosed number of its customers in response to a fake government request.

The information that was handed over to an “unauthorized third party” reportedly includes names, dates of birth, occupations, addresses, phone numbers, account numbers, transaction histories (including Bitcoin), and even copies of government-issued IDs and onboarding verification selfies.

Revolut claims that derived biometric face data was not.

The company said that the data was handed over in response to an email that came from a real government agency’s domain, but was not actually sent or authorized by that agency.

The email passed several authentication checks (SPF, DKIM, and DMARC) that are designed to establish the authenticity of a message’s origin and integrity, but do not verify the legitimacy of the legal request itself.

Revolut said that it complied with the request “under the reasonable belief that it was an authentic government agency request” – and only later found out that it was not.

Revolut said it later realized its mistake, blocked the email address, and reported the incident to the relevant authorities.

Revolut said that only a “limited” number of its customers were affected by the data leak, and that the company’s systems were not hacked, nor was any money stolen.

The story broke on September 11 when Revolut customers started receiving an email notice about a data leak, and the news was picked up by media outlets the following day.

Keep reading

Google May Ask Canadian Adults for ID or Selfies

The digital ID age verification agenda has landed in Canada. Google has announced it is introducing age verification in Canada. Google Canada’s government-affairs and public-policy director Jeanette Patell announced on September 14 that the rollout will happen over the coming days.

Google will use machine learning to surveil users and estimate whether an account holder is over or under 18, using “signals” from data already gathered and tied to that account, such as “the types of information a user has searched for” and “the categories of videos they’ve watched on YouTube.”

The announcement post by Patell is filled with references to protecting children, but also reveals that the model may produce false positives, i.e., classify an adult as a minor.

Such a user can provide a government ID or a selfie to correct the estimate.

As for why an adult would want to “correct” their classification, it turns out that if they don’t, they will be treated like a child by Google.

According to the announcement, those who are “likely” under 18 will get YouTube Digital Wellbeing reminders to take a break and go to bed, as well as “safeguards” that limit repetitive viewing of some categories.

Keep reading

California Is Building an Internet of Age Checks and Identity Gates

California Governor Gavin Newsom has signed two controversial age verification bills into law: AB 1709 and SB 1119.

Newsom was quoted as saying that Thursday was “a good day for our children,” but both laws will also impact adults by forcing online services to distinguish between users based on age.

AB 1709 deals with features on social media that are considered addictive, such as personalized feeds and autoplay, and prohibits these for California users under 16.

Before being allowed to use these features, users must be verified under the California Digital Age Assurance Act, or another statutory age-determination method. The Act in turn relies on age-bracket signals from operating systems and app stores, which are based on age or birthdate information provided by users. The law includes data-minimization and sharing restrictions, and does not require passports or face scans from all users.

AB 1709 will in effect mean that children will be able to use social media accounts, but without access to personalized feeds, which is how many people discover new content and information, and is a key component of how these platforms work.

But the law doesn’t only affect children; adults who want to use the covered features must also verify their age. In reality, this means that companies behind the platforms will have to act as arbiters of who can and cannot use what features.

Keep reading

Microsoft Brings “Age Verification” System To Windows

Just in time for the global digital ID agenda playing out, Microsoft has published instructions for developers on how to use an API that is not yet active.

The API, or programming interface, is designed to let apps on the Windows 11 operating system find out a user’s age bracket, and whether that age has been verified by an “identity provider.”

The age bracket is very broad: under 10, 10-12, 13-15, 16-17, and 18 and over. The verification status, on the other hand, can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable, or NotApplicable.

Microsoft does not go into what these identity providers will be, or what evidence they will use to verify a person’s age. The company only says that the second value returned by the API will show “whether the user’s age has been independently verified by the identity provider.”

Microsoft frames this as a way to improve privacy, by giving app developers a way to determine a user’s age without actually knowing their date of birth, or any other personally identifiable information. According to Microsoft, this is a “privacy-preserving mechanism” that will allow apps to comply with regulations concerning child safety. But, as we’ve seen from bills that call for this type of technology to be installed in operating system, this is all about normalizing age checks (and therefore ID checks) at all stages of digital life.

In this case, an age signal does not directly expose the user’s age or date of birth. Instead, it provides a way to adapt content, features, or access controls in an app based on the user’s age range and age verification status. For example, an app can use the age signal for user-generated content, social or communication tools, in-app purchases, virtual currencies, or maturity-rated media.

Microsoft goes into some detail about how developers can use the API, but notes that it is not yet available and will not return any useful data until it is turned on later in the year. For now, the company is providing the documentation ahead of the release to give developers a head start.

In January 2024, Microsoft was more cautious about the possibility of creating a system to determine a user’s age online. At the time, the company said it was exploring various methods and seeking expert input, but was not sure that the technical solution was there yet.

“There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user’s age without risking trade-offs such as potential security, privacy, and human rights risks,” a Microsoft blog post said at the time.

California has since created its own framework for age verification.

Keep reading

Meta Settlement Ignites Global “Child Safety” Digital ID Push

The ink on the multi-billion dollar settlement agreement that Meta struck with 47 US states, the District of Columbia and a number of US territories has barely had time to dry – and already, officials and campaigners in the US, the EU, the UK, and at the UN are using it to press for similar rules to be imposed elsewhere.

In the UK, Work and Pensions Secretary Pat McFadden said that Meta should apply the new rules in that country as well, while the government there has its own plans to ban social media for under-16s and impose nighttime curfews.

“We don’t want a situation where young people in America have got a higher rate of protection than young people in the UK,” he said.

The British plan is to ban social media for those under 16 by spring 2027, and impose nighttime curfews on older teenagers, the Independent is reporting. To enforce this, platforms will have to know whether a user is a child or an adult, stepping up the pressure on companies to introduce age checks.

In the EU, the Commission is also piling on the pressure on Meta to “export” the US deal.

“We expect adequate management of screen time, appropriate parental controls on these platforms,” said digital spokesperson Thomas Regnier. “It is now up to the company to propose these commitments within the European Union in order to also protect our children here.”

The official revealed that the Commission has already been in talks with Meta since the US agreement was announced, and that the goal is to give children in the EU “at least” the same protections as those in the US.

Meanwhile, UN High Commissioner for Human Rights Volker Türk is using the settlement to call for global protections for children from what he says is the harm caused by excessive social media use.

In the US, District of Columbia Attorney General Brian Schwalb, one of those behind the lawsuit that led to the settlement, said that Meta “will not be the last” company to be forced to agree to such terms.

His California counterpart, Rob Bonta, said that Meta is “not the only player in the industry” to have “visited enormous mental health harms on kids through their products and their designs,” and added, “others rightfully must be held accountable.”

The settlement contains financial incentives for states to bring similar cases against other companies. Snap, TikTok, and YouTube are mentioned by name in this context.

Not everyone is happy with the deal, however. Arturo Béjar, a former Meta employee who was a witness in the trial, said the protections are insufficient and that the product remains harmful.

“The limitations that are in the agreement are the equivalent of saying: ‘Well, you can smoke as many cigarettes as you can in two hours a day,'” he said. “It doesn’t make the cigarettes any safer.”

Meta responded by saying that Béjar is ignoring some of the other provisions of the settlement, such as non-algorithmic feed defaults and stronger parental controls.

“We have a huge raft of built-in protections,” a spokesperson said, and argued that teenagers also derive “substantial” benefits from using social media.

Keep reading

ID Verification Breach Exposes Millions of Sensitive Identity Documents

If you ever needed more proof that governments pressuring companies to collect ID data from customers or users is a bad idea, you only have to look at what happened this week. A dark-web service advertised on August 31 has been offering over 153 million scans of driver’s licenses, more than 10 million other identity cards, over 3 million travel documents and/or international IDs, and at least 579,000 medical cards.

The data apparently stems from a company hired to verify people’s identities. The service, called Nexus, was advertised on the Russian-language cybercrime forum Exploit.

Security researcher Brian Krebs found that a blank search on Nexus returned about 11.5 million result pages with roughly 15 results per page. This would support the claim that there were over 153 million license scans in the database, and the number increased by nearly 400,000 in 24 hours.

Nexus itself claimed to have “continuously exfiltrated new data for over a year into our private database” – but this is not verified and could be an advertising claim.

What Krebs was able to verify is that his own Virginia license was among those available on the site. He searched with permission for the licenses of more than a dozen friends and relatives; nine people whose records appeared said that the attached timestamps matched or closely tracked their travels.

In the case of Krebs and his mother, the timestamps corresponded to a June 2025 car rental from Hertz. Their records were created seconds apart, matching their account that they handed both licenses to the rental representative at the same time.

Krebs’s record contained three pairs of images showing the front and back of the license in visible light, infrared, and ultraviolet.

Privacy researcher Zach Edwards also found his license on Nexus. Its timestamp matched a trip to Las Vegas, where he had presented the document to TSA, the Aria hotel and the Planet13 dispensary. Edwards said the dispensary was the only one of the three places where he knew the license had been scanned.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading