EU’s Social Media Ban Could Bring ID Checks for Adults

As expected, European Commission President Ursula von der Leyen has announced that the EU Kids Act will propose that no child under 13 should be allowed on social media, while 13 and 14-year-olds should have limited accounts.

The announcement, just in time for the EU’s planned digital ID rollout, was made in von der Leyen’s State of the European Union address in Strasbourg on Wednesday.

According to von der Leyen, the Act would ensure that “no social media under the age of 13. No personal account under the age of 15.”

Children between the ages of 13 and 14 will be allowed a limited account, with a limited set of features, and with a time limit of one hour a day, and parents will have to set up and supervise these “mini accounts.”

Von der Leyen also said that the Act would reverse the burden of proof, so that instead of regulators having to prove that a service is unsafe, it will be up to the platforms to prove that their product is safe for minors.

The Commission President also took aim at Big Tech, saying, “I am aware that many perceive the power of big tech as overwhelming and impossible to roll back. I disagree.” She added, “Europe has the power to act. It is us who decide the rules, not Big Tech.”

The scope of the Act will cover social media, video sharing platforms, app stores, online games, as well as AI companions and chatbots, with a focus on “high-risk” services, although the definition of that category is not yet clear.

Other rules that have been reported as part of the Act are age checks for every new account, with existing users also subject to “proportionate” checks, taking into account the time they have been subscribed to a service. Verification will be done via an app, either the one developed by the Commission or a national equivalent. These apps will only return information about whether a user is over or under a certain age.

The draft also reportedly seeks to ban certain design features, such as infinite scrolling, autoplay, and push notifications, as well as artificial notifications and rewards. The text is said to state that “technology companies bear primary responsibility for making their products safe.”

Fines for non-compliance can reach up to 6% of a company’s global annual turnover, while a supervisory fee will be introduced to make sure the Commission can enforce the new rules.

The Commission’s app was presented by von der Leyen in April in Brussels, and at the time, she said it was “fully open source. Everyone can check the code.”

But security consultant Paul Moore took the Commission up on that and found that the app stores sensitive data on phones and leaves it unprotected. According to Moore, he was able to hack the app in under two minutes.

The Commission first responded to this by saying the app was ready and could always be improved. A week later, a spokesperson described the version presented as “a demo version.”

Keep reading

Bipartisan House Bill Would Ban Social Media Accounts For Under 16s

Two US House of Representatives members, one from each of the dominant parties, have introduced a bill to ban under-16s from having accounts on “addictive” social media.

And if an account is discovered to belong to an under-16, the proposal, dubbed the 16 & Up Social Media Act, seeks to cut them off from their online speech, by having the account terminated.

The bill was introduced by Erin Houchin, a Republican from Indiana, and Jake Auchincloss, a Democrat from Massachusetts, on September 11, 2026, and has the support of psychologist Jonathan Haidt, who said that the goal is “to stop addictive design entirely.”

The bill covers services that are available to the general public, have searchable and followable usernames, and where user generated content is the primary purpose. These platforms must also allow users to share content, have features that promote engagement, and use personal information for advertising, marketing, or recommendations.

Specific features that are targeted include infinite scroll, autoplay, push alerts, usage-based badges, and personalized recommendations.

As for the way the bill seeks to achieve its goal, it would require companies to “know” a user is under 16, and delete that account. But on page 11, the text states that “knows” means “to know or should have known.”

That opens the door to pressuring companies to investigate the age of their users, or shut them out if there’s doubt. Adults who are flagged would then have to challenge the decision. The bill does not explicitly require government ID uploads for every user, nor does it prescribe a specific age-checking technology.

The bill would have to be passed and then have its provisions come into force in order to start affecting users and companies, but if that happens, existing accounts would have to be identified within 60 days of enactment, users notified within 180 days of enactment, and accounts removed within 30 days of that notification.

Keep reading

Australia Wants to Remake the Internet in the Name of “Safety”

The Australian government has published its proposed Digital Duty of Care legislation, a plan that it says will give people more control over their social media feeds, but which opponents fear is a way to introduce more online censorship.

The exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 was published on September 8 for consultation, and it is not yet law. The deadline for submissions is noon on September 22, and Communications Minister Anika Wells said the plan is to formally introduce the bill to Parliament in October.

We obtained a copy of the draft for you here.

In the words of Prime Minister Anthony Albanese, “This is not about giving government control, it is about giving people control.”

And while the proposal is often referred to as My Feed, My Way, it is not about banning algorithms, but giving new and existing users a choice between feeds based on recommendations, and one that shows posts from accounts they follow.

But beneath this choice, there is a broader change to the Online Safety Act 2021 that would be introduced by the Digital Duty of Care bill, and that is to impose a duty on those behind online services to ensure a safe online environment as far as reasonably practicable.

This duty would apply to a wide range of services, including social media, messaging, games, hosting, search, app stores, internet providers, AI services enabling generated material to be shared through covered services, as well as certain equipment providers.

The minister in charge would be able to exempt services that are low-risk or minimally used. The proposal is designed to protect adults from what is described as seriously harmful material and conduct, while under-18s would have additional protection against harmful content and design features.

The list of harmful content and conduct that the draft seeks to protect adults from includes child sexual abuse, threats of violence, encouragement of self-harm, and support for listed terrorist organizations.

For children, the list includes pornography, encouragement of disordered eating, hostile attitudes towards women or gender equality, glorification of crime, dangerous stunts, abuse and bullying.

However, the minister would have the power to add more categories of harmful material or conduct by issuing a legislative instrument.

Wells must first seek and consider advice from eSafety, and the instrument can be disallowed by Parliament.

The draft bill also targets features that the government considers to have negative behavioral impacts, such as recommendation systems, endless feeds, and engagement-feedback tools, as well as time-limited content. Social media services would be required to stop these features for children under 16.

The proposal also includes a system of risk assessment that online services would have to conduct at least once a year, and keep for six years. These assessments would have to be provided to the eSafety commissioner on request.

eSafety Commissioner Julie Inman Grant, who has a history of censorship demands, would be in charge of enforcing the scheme, which would bring maximum company penalties of A$109.2 million.

The draft bill does contain some safeguards, such as the definition of reasonably practicable, which takes into account the risk, available measures, cost, and the potential for a measure to have a disproportionate effect on privacy.

The duty of care does not extend to lawful communications occurring in private solely between consenting adults, the draft bill states.

Opposition leader Angus Taylor on September 6 said he feared the proposal was “an attempt by the government to censor social media,” while One Nation leader Pauline Hanson said that Australia should be moving away from government censorship, not “building the Orwellian machinery for it.”

The Greens, on the other hand, have supported the idea of making sure users have a choice when it comes to feeds, but they want to make sure that users have to opt in to have their feeds curated by algorithms.

White House spokesman Kush Desai reacted by saying that President Trump “has unequivocally warned trading partners against imposing digital services taxes, fines, and other forms of extortion on America’s leading technology sector.”

Desai added that “the administration remains committed to raising these issues with our trading partners.”

Communications Minister Anika Wells sought to downplay the significance of the White House statement, telling News24 that the US was responding to broader questions that also included Australia’s tax arrangements, and not only the Digital Duty of Care proposal.

“We’re a sovereign nation, we have the right to defend Australian parents and kids and we’ll do that,” Wells said.

The government’s proposal has been portrayed as giving users a choice between personalized recommendation feeds and those that show posts from accounts they follow.

Keep reading

California Is Building an Internet of Age Checks and Identity Gates

California Governor Gavin Newsom has signed two controversial age verification bills into law: AB 1709 and SB 1119.

Newsom was quoted as saying that Thursday was “a good day for our children,” but both laws will also impact adults by forcing online services to distinguish between users based on age.

AB 1709 deals with features on social media that are considered addictive, such as personalized feeds and autoplay, and prohibits these for California users under 16.

Before being allowed to use these features, users must be verified under the California Digital Age Assurance Act, or another statutory age-determination method. The Act in turn relies on age-bracket signals from operating systems and app stores, which are based on age or birthdate information provided by users. The law includes data-minimization and sharing restrictions, and does not require passports or face scans from all users.

AB 1709 will in effect mean that children will be able to use social media accounts, but without access to personalized feeds, which is how many people discover new content and information, and is a key component of how these platforms work.

But the law doesn’t only affect children; adults who want to use the covered features must also verify their age. In reality, this means that companies behind the platforms will have to act as arbiters of who can and cannot use what features.

Keep reading

Microsoft Brings “Age Verification” System To Windows

Just in time for the global digital ID agenda playing out, Microsoft has published instructions for developers on how to use an API that is not yet active.

The API, or programming interface, is designed to let apps on the Windows 11 operating system find out a user’s age bracket, and whether that age has been verified by an “identity provider.”

The age bracket is very broad: under 10, 10-12, 13-15, 16-17, and 18 and over. The verification status, on the other hand, can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable, or NotApplicable.

Microsoft does not go into what these identity providers will be, or what evidence they will use to verify a person’s age. The company only says that the second value returned by the API will show “whether the user’s age has been independently verified by the identity provider.”

Microsoft frames this as a way to improve privacy, by giving app developers a way to determine a user’s age without actually knowing their date of birth, or any other personally identifiable information. According to Microsoft, this is a “privacy-preserving mechanism” that will allow apps to comply with regulations concerning child safety. But, as we’ve seen from bills that call for this type of technology to be installed in operating system, this is all about normalizing age checks (and therefore ID checks) at all stages of digital life.

In this case, an age signal does not directly expose the user’s age or date of birth. Instead, it provides a way to adapt content, features, or access controls in an app based on the user’s age range and age verification status. For example, an app can use the age signal for user-generated content, social or communication tools, in-app purchases, virtual currencies, or maturity-rated media.

Microsoft goes into some detail about how developers can use the API, but notes that it is not yet available and will not return any useful data until it is turned on later in the year. For now, the company is providing the documentation ahead of the release to give developers a head start.

In January 2024, Microsoft was more cautious about the possibility of creating a system to determine a user’s age online. At the time, the company said it was exploring various methods and seeking expert input, but was not sure that the technical solution was there yet.

“There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user’s age without risking trade-offs such as potential security, privacy, and human rights risks,” a Microsoft blog post said at the time.

California has since created its own framework for age verification.

Keep reading

Meta Settlement Ignites Global “Child Safety” Digital ID Push

The ink on the multi-billion dollar settlement agreement that Meta struck with 47 US states, the District of Columbia and a number of US territories has barely had time to dry – and already, officials and campaigners in the US, the EU, the UK, and at the UN are using it to press for similar rules to be imposed elsewhere.

In the UK, Work and Pensions Secretary Pat McFadden said that Meta should apply the new rules in that country as well, while the government there has its own plans to ban social media for under-16s and impose nighttime curfews.

“We don’t want a situation where young people in America have got a higher rate of protection than young people in the UK,” he said.

The British plan is to ban social media for those under 16 by spring 2027, and impose nighttime curfews on older teenagers, the Independent is reporting. To enforce this, platforms will have to know whether a user is a child or an adult, stepping up the pressure on companies to introduce age checks.

In the EU, the Commission is also piling on the pressure on Meta to “export” the US deal.

“We expect adequate management of screen time, appropriate parental controls on these platforms,” said digital spokesperson Thomas Regnier. “It is now up to the company to propose these commitments within the European Union in order to also protect our children here.”

The official revealed that the Commission has already been in talks with Meta since the US agreement was announced, and that the goal is to give children in the EU “at least” the same protections as those in the US.

Meanwhile, UN High Commissioner for Human Rights Volker Türk is using the settlement to call for global protections for children from what he says is the harm caused by excessive social media use.

In the US, District of Columbia Attorney General Brian Schwalb, one of those behind the lawsuit that led to the settlement, said that Meta “will not be the last” company to be forced to agree to such terms.

His California counterpart, Rob Bonta, said that Meta is “not the only player in the industry” to have “visited enormous mental health harms on kids through their products and their designs,” and added, “others rightfully must be held accountable.”

The settlement contains financial incentives for states to bring similar cases against other companies. Snap, TikTok, and YouTube are mentioned by name in this context.

Not everyone is happy with the deal, however. Arturo Béjar, a former Meta employee who was a witness in the trial, said the protections are insufficient and that the product remains harmful.

“The limitations that are in the agreement are the equivalent of saying: ‘Well, you can smoke as many cigarettes as you can in two hours a day,'” he said. “It doesn’t make the cigarettes any safer.”

Meta responded by saying that Béjar is ignoring some of the other provisions of the settlement, such as non-algorithmic feed defaults and stronger parental controls.

“We have a huge raft of built-in protections,” a spokesperson said, and argued that teenagers also derive “substantial” benefits from using social media.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading

Mark Zuckerberg’s Meta Calls on YouTube and TikTok to Match Its Teen Safeguards

Mark Zuckerberg’s Meta will pay $18 billion to settle a federal lawsuit accusing it of fueling a teen mental health crisis, but nearly a third of that sum depends on whether TikTok and YouTube agree to adopt the same safeguards. The social media giant is now directly calling on its largest competitors to follow Zuckerberg’s lead.

The settlement announced just days into a trial brought by a coalition of state attorneys general, resolves claims that Meta hooked children on its platforms and ignored the resulting harms, including anxiety, depression and suicide, to protect its profits. Meta will pay 70 percent of the total, about $12.7 billion, upfront. The remaining $5.3 billion only gets released if TikTok and Google’s YouTube together pay a matching $5.3 billion and adopt the same restrictions Meta is imposing on itself.

Those required changes include a one-hour daily usage limit for teens, a “night mode” that blocks access during bedtime hours, and age verification measures. Meta agreed to a two-hour daily limit for teens on Facebook and Instagram, which would drop to one hour if TikTok and YouTube fall in line. The night mode default would block teen access from midnight to 6:00 a.m. Most provisions in the settlement are set to last 10 years.

Meta is also banning filters for “cosmetic surgery and extreme makeup,” removing “Likes” and other reactions from teen posts by default, and strengthening parental oversight tools. The settlement leaves Meta’s recommendation algorithm, the system that decides what content teens see, untouched.

Meta published an open letter calling out its rivals directly, writing that “these protections will only be truly effective if we work with our peers — TikTok and YouTube — to put the same measures in place.” As of Wednesday afternoon, neither company had responded, despite multiple requests for comment. TikTok recently settled a separate, unrelated case with the DOJ for $400 million over children’s privacy.

Keep reading

Google To Expand Play Age Signals API to All Users Worldwide

Just in time for the global digital ID push, Google will roll out its Play Age Signals API to all Google Play users worldwide by the end of 2026. This gives Android apps an easy way to ask Google how old its users are.

Google Play’s vice president of product management, Paul Feng, announced the expansion on July 29. Australia and Canada come first by mid-August, followed by “a full global rollout to all users later this year.” Apple launched its own version, the Declared Age Range API, worldwide in February.

An app calls the API while it’s running and Play answers with the band the user falls into, 0-12, 13-15, 16-17, or 18+ by default. Developers can redraw those bands in the Play Console. A developer who sets minimum ages of 13 and 17 gets users sorted into 0-12, 13-16, and 17 and over.

The feedback arrives as a lower and an upper bound, and the top band carries no upper bound, so an adult in that setup comes back as ageLower = 17, an age floor with no ceiling. A user who declined to share gets no band at all, only a NOT_SHARED status. Google’s rules bar any other use of the answer, “including, but not limited to, advertising, marketing, user profiling or analytics.”

To parents, Google says the API as “a privacy-preserving tool that puts parents in the driver’s seat.” A parent enters a child’s range once in the Family Link app, 16-17 rather than an exact birth date and every app that has built in the API can read it. Google says sharing is off until a parent opts in and that the setting can be changed or switched off at any time.

That default lasts until a law overrides it and Texas already has and you only have to look at the latest senate bill that we just covered to know exactly how this “privacy” preserving plan can end up being anything but. Adults can share their own range when an app asks. “Providing a safe online experience and protecting users from harm is a top priority at Google Play,” Feng wrote in his announcement.

Apps receive more than a band. Google’s developer pages say an app can receive “users’ age verification or supervision status, age ranges, and other applicable signals,” and the status field can also come back VERIFICATION_REQUIRED. A developer knows when a user declined to share and when an age was verified rather than declared, and Google leaves it to each app to decide what to accept. TechRadar, citing reports, says users who fail to complete verification can be blocked from downloading a wide range of apps, not just those with adult ratings.

The API went live in Brazil on March 17, the day the Digital ECA took effect. That law bans the “I am over 18” checkbox and threatens fines of up to 50 million reais, about US$9.44 million, or 10 percent of a company’s Brazilian revenue. Texas followed.

Play began returning ages and running an age verification flow for Texans who created accounts after May 28, once a federal appeals court stayed the December 2025 injunction that had blocked the state’s App Store Accountability Act.

Keep reading

Paxton “Child Safety” Plan Puts Legal Speech at Criminal Risk

Texas Attorney General Ken Paxton, who is currently running for the US Senate, and pushing online digital ID age verification checks in the name of “online safety,” has announced a data center plan that, among other things, vows to “protect children” by making data center companies criminally liable if the centers they operate “empower AI chatbots that undermine children’s safety.”

Paxton is effectively promising to author legislation that would introduce a novel form of liability, aimed at data centers – the physical and hardware part of the internet’s infrastructure – for the content that is generated by software running on their servers.

This is a clear departure from the principle, enshrined in Section 230 of the Communications Decency Act (CDA), that internet infrastructure is not liable for third-party, user-generated content.

And, while Paxton’s plan speaks of chatbots that “undermine children’s safety” – a broad and vague term that can easily be abused to censor speech – the actual target could be any chatbot, and any speech.

And the liability would be criminal.

Paxton is quoted as saying in a post on X: “My Texas First Data Center Plan will protect our grid, our communities, and our children while ensuring America beats Communist China in the AI race,” he wrote.

Keep reading