On 16 September, Ursula von der Leyen stood before the European Parliament and announced a policy that sounds unassailable: ban social media for children under 13, offer supervised "mini accounts" for teenagers, and make platforms prove their services are "safe by design."1 The EU KIDS Act, formally adopted the next day, would set a single, EU-wide age threshold across all 27 member states and reverse the burden of proof so that tech companies, not parents, must demonstrate safety before children use their services.
It is an ambitious vision. It also rests on an assumption that should make any European democrat uncomfortable: that the mechanics of enforcement — age verification, account deletion, design mandates — will actually deliver the protection promised. The evidence suggests otherwise. And if they don't, this is not a case of "safety versus privacy." It is the gradual, apparently reasonable erosion of the privacy, anonymity and free expression that define a free society — in exchange for a partially symbolic outcome. That is not a policy trade-off; it is a values failure.
The Australian Lesson
Australia was the world's first. In December 2025, the country banned social media for under-16s. Now, after nine months of the ban, we have hard data on what happens when a wealthy democracy with technical capacity tries to age-gate the internet.
The numbers are instructive. Australia's eSafety Commissioner, in the first formal longitudinal evaluation (published July 2026), studied over 4,100 children and families.2 The headline: 4.7 million under-16 accounts were removed from platforms. Sounds like a win.
Then the nuance: 81.5 percent of Australian under-16s were still using at least one age-restricted platform three months into the ban. That's a decline of only 4.4 percentage points from the 85.9 percent using them before. In other words, removing nearly 5 million accounts moved the needle almost imperceptibly.
How? The compliance was tactical. More than half of the children still using a platform said it never checked their age at all. Another 37 percent had accounts logged as 16+ — false declarations, misclassification, or parental help. Only 7.4 percent used a VPN. Most simply recreated accounts or browsed without logging in (YouTube and TikTok allow content use without an account). The platforms, facing the ban, had systematized a performance: they would let children retry age checks until they passed, or skip them entirely.
On wellbeing — the stated goal — the results were grimmer. There was no statistically significant decline in cyberbullying complaints or image-based-abuse reports in the first months. Daily social-media use barely moved. But there was a perverse side-effect: parental monitoring declined, because parents wrongly believed the ban had removed their children from social media, potentially increasing unsupervised exposure.
The account removals won the news cycle. The actual outcome — 81.5 percent still there, barely nudged, with false compliance across the board — tells the real story.
The UK: Geo-Blocking, Not Gates
Britain offers a counter-narrative, at least on the surface. After the Online Safety Act came into force on 25 July 2025, visits to the UK's most popular pornography sites fell by roughly a third.3 That number is real. But read it carefully, and it becomes a cautionary tale.
A large share of that decline is not age verification working. It is geo-blocking. Pornhub and other sites chose to block UK users outright rather than implement age checks.4 Traffic fell because the platform switched the country off, not because an age gate worked. The stat literally cannot distinguish a blocked minor from an adult on a VPN. And indeed, VPN use in the UK doubled — including among the determined minors the law aimed at.5
The compliance burden, meanwhile, fell on adults. Legitimate users faced identity-document upload or credit-card checks with third-party verification providers. Many found the friction too intrusive and simply stopped. The teenagers circumvented with VPNs. The deterministic effect: reduced traffic, but from a mix of geo-blocking and adult friction, with no clean proof that minors were blocked.
By July 2026, the UK House of Lords had opened an inquiry into the age-check regime, demanding answers on data breaches at verification vendors (exposing government IDs), failures to block targets, and the "stripping" of adult privacy.6 Even Ofcom's framing shifted. Its early reports touted success; its later summary was titled "Age checks helping make online experiences safer for UK children but job not done."7 The headline number, it turns out, flatters the policy.
The Privacy Machinery
To enforce any age limit, you have to know how old people are. The EU's answer is an age-verification app built on the European Digital Identity (eID) Wallet, using zero-knowledge proofs so platforms learn only "yes, over 13" without a person's name or birthdate.8
It sounds clever. Civil-liberties groups are not convinced.
In September 2026, EDRi — Europe's leading digital-rights organization — released a technical brief on the Commission's "privacy-preserving" tool. The headline: it fails on both counts. The zero-knowledge proofs are optional ("SHOULD," not "SHALL"). Unlinkability between age-verification and identity is not guaranteed. The batch-issuance design can still be linked back to a person with cooperation between issuer and service. And once the infrastructure exists, "privacy-preserving" can be quietly revoked — Belgium and Austria are already considering full-ID requirements. A 438-strong coalition of security and privacy scientists co-signed the warning.9
The deeper worry is architectural. To verify the age of a minority, everyone — every European adult — must submit to the age-check gate. Framed as a "children's protection," the machinery touches everyone. That is not a semantic quibble; it is a design choice that centralizes identity and age data in ways that, once built, prove hard to constrain. The CCIA warned the collection would "undoubtedly create an attractive target for cybercriminals."10 Even the European Consumer Organisation's director, Agustín Reyna, conceded: "Children clearly need better protection online, but age verification is not a silver bullet and would raise serious privacy and data-protection concerns of its own."11
The Real Trade-Off — and the Values at Stake
Here is where the framing matters, and it matters morally, not just analytically. The Commission frames the Kids Act as balancing "safety versus privacy." That is a false choice, and the evidence shows it.
What the evidence actually shows is: a set of means (age verification, account deletion, design rules) that appear to shift behavior only modestly, in exchange for building permanent, continent-wide identity and age infrastructure that everyone will have to pass through. The Australian data suggests the account-removal strategy delivers a headline (5 million accounts gone) but a muted real-world effect (81.5 percent still there). The UK data suggests the visit-count decline comes largely from geo-blocking and adult friction, not age-gate efficacy. The privacy critique suggests the "privacy-preserving" age app has structural vulnerabilities baked in.
If the means don't reliably reduce harm, then the trade-off is not "safety versus privacy" at all. It is privacy and liberty for everyone in exchange for a partial, symbolic, or uncertain outcome.
And once you see it that way, you have to ask a harder question — the one this proposal has so far avoided. Is a liberal democracy allowed to build mandatory, universal identity-and-age infrastructure on the slender, unproven premise that it protects children — when the mechanism for protecting them is itself doubtful, and the infrastructure touches every citizen, every adult, every time?
That is not a technical question. It is a question about what kind of society Europe wants to be. The right to move anonymously online, to read and speak without proving who you are, to be presumed neither criminal nor child until shown otherwise — these are not luxuries. They are the assumptions on which a free press, a free public sphere and a citizenry that can dissent without fear are built. When the machinery to verify everyone's age is justified by the protection of children, it is children's protection that is doing the work of normalising mass identity checks. And that normalization is permanent: once the infrastructure exists, "privacy-preserving" is a setting, not a guarantee — Belgium and Austria are already considering full-ID requirements.
This is the point the French Constitutional Court grasped when it struck down France's under-15 ban in August 2026, ruling it "not appropriate, necessary or proportionate" to children's freedom of expression.12 It is the point EDRi makes when it says age verification "marks the end of free access to the internet."13 These are not fringe objections. They are the considered view of a constitutional court and Europe's leading digital-rights organization, both saying: the cost, to everyone, of this way of protecting children is one a free society should not pay.
The Intellectual Trap
There is a sharper angle lurking here, one that reveals how constrained the Kids Act's framing actually is.
Several of the Act's safeguards — limits on algorithmic addictiveness, private-by-default profiles, bans on manipulative reward features — are not sensible only for children. They would benefit every user. If infinite scroll and attention-maximizing design are unsuitable for a 15-year-old because they are engineered to manipulate, the same logic applies to a 45-year-old. Either the design is harmful in itself (and should be fixed universally), or the line is drawn at a developmentally defensible but politically convenient place.
Von der Leyen herself conceded the premise. In her State of the Union, she promised a separate Digital Fairness Act would tackle addictive design and dark patterns that she called "harming everyone."14 The two files sit awkwardly together: one shields children from manipulative design; the other (a future proposal) would protect everyone.
EDRi sharpened the critique:15 if the safeguards are right for minors, why aren't they right for adults? The answer Europe gives says a lot about how it thinks about citizens, not just children. It suggests that universal design reform is too hard, too costly, too unpopular with industry — so Europe is piloting it on children first, with the fiction that it is a child-specific fix. That may be honest about the politics. It is not honest about what the law does.
Where This Lands
Let me state my position plainly, because the evidence drives there. I am on the side of not doing this.
The EU KIDS Act is not inevitably going to fail. The proposal is day one of a legislative process that will involve the European Parliament, the member states and real negotiations; the final law may be stronger in enforcement, sharper in technical standards, or narrower in scope. But that is not the point. The point is the direction the proposal commits Europe to — and the values it asks us to trade for protection that cannot be shown to work.
Every time a democracy has tried to age-gate the internet, the headline metrics (accounts removed, visits blocked) have outpaced the real-world effects (behavior barely shifted, circumvention trivial, harm un-reduced). The privacy machinery required to enforce age limits at scale is being sold as "privacy-preserving" even as a constitutional court, civil-liberties experts and 438 security scientists flag structural risks. And the design safeguards being locked to children are principles that, applied universally, would be genuine reform — but the universal version is being deferred.
The closing of the argument is what matters most. The safeguards the Kids Act would deny adults — limits on addictive design, private-by-default profiles, no manipulative reward tricks — are good for everyone. Regulate them for everyone, and the age-verification machinery becomes unnecessary. If the design cannot manipulate a 15-year-old without also manipulating a 45-year-old, then fixing the design for everyone solves the child-safety problem without requiring a single citizen to prove their age. The honest, liberal democratic answer is to reform the harmful design for all — not to build a surveillance gate for the few and call it child protection.
The KIDS Act inverts that. It declines the hard task — universal design reform, against trillion-dollar industry opposition — and chooses the easy, photogenic one: a ban, age checks, a story about protecting children. The privacy cost is real, universal and permanent. The protection is unproven, partial and reversible only at enormous effort. That is not a defensible balance. It is the worst of both worlds: it risks the rights of every European for a child-protection narrative that, on the best available evidence, does not do what it claims.
We are told to accept this because the ends justify the means. But when the ends cannot be shown to be achieved, and the means degrade the very rights a free society is built on, the only honest conclusion is that the means are the problem — and that a Europe that builds this for its children has quietly stopped believing in the values it claims to protect.
If we wouldn't give our own identities to lock the adults out, we should not be asked to do it to lock the children in.