A new post from the Electronic Frontier Foundation, co-authored with Sheila B. Lalwani, a doctorate student and recent COMPASS Fellow hosted by EFF, argues that the usual debate about age verification is framed the wrong way. The title says it plainly: "When No ID Means No Internet." For anyone following age verification laws, VPN privacy and anonymous browsing, the argument deserves attention.
The excerpt available from the post is short, so this article sticks to what it states and to widely understood context about how these systems work.
Why age verification is more than a privacy tradeoff
Age verification proposals are often presented as a simple bargain: give up a little privacy and children are better protected online. The EFF's post says that framing "overlooks a more fundamental question."
That question, as we read it, is about access. If a website can only be used after you show identification, then the ability to read lawful information depends on whether you are willing and able to produce an ID. Privacy cost is one part of the problem. The larger part is who gets to see what, and on what terms.
This matters because the information in question is lawful. Adults are entitled to read it, and so are many teenagers. A mandate that turns every visit into an identity check changes the default of the open web from "come as you are" to "papers, please." Some people may not have the right documents, may not be comfortable sharing them, or may have good reasons to keep their browsing separate from their legal identity.
What sites collect: ID, biometrics, and breach risk
Age checks are not abstract. To confirm someone's age, a service typically has to collect something: a government ID image, a face scan, or other personal details. Either the site or a third-party verification vendor handles that data.
That creates several concerns worth understanding:
- Stored identity data. Any record that links a real identity to a browsing activity can become a target, and can be misused if it is mishandled.
- Sensitive categories. Biometric and ID data cannot be easily changed if it leaks, unlike a password.
- Linking. A verified identity attached to an account can connect activity across sites that previously had no idea who you were.
None of this requires a particular breach to be a legitimate concern. It follows from the design: the more places that hold identity documents, the more places that can fail.
How age verification laws, VPN privacy and anonymous browsing collide
VPNs sit awkwardly in this picture. Many people use them to keep their browsing from their internet provider, to protect their location, or to reach information in places where access is restricted. A VPN also changes the apparent location of a user, which can matter when a law applies only to residents of a certain state.
That is why lawmakers and commentators now treat VPNs as a "loophole." One industry association piece in recent search results notes that no state law requiring age verification includes an exception for children who use a VPN, and a Tom's Hardware report from May 2026 describes an EU research arm labeling VPNs a loophole as age-verification laws drive record adoption.
The EFF's framing helps explain why this is concerning. If the goal is to make sure anonymous access to lawful information is closed off, then tools that provide anonymity become targets too. For VPN users, three things are at stake:
- Anonymity. Identity checks undercut the idea of reading or browsing without being identified.
- Circumvention tools. Pressure on VPNs as a workaround puts the tools themselves in the spotlight.
- Stored identity data. Even if you never use a VPN, the ID you hand over has to live somewhere.
This is no longer hypothetical. Utah's law, covered in our look at how Utah's SB 73 targets VPN use, took effect on May 6, 2026, and is described as one of the most aggressive online age-verification laws in the United States.
What This Means For You
For most readers, the practical effect is that more sites and apps may ask you to prove who you are before showing content you could previously open freely. Some of those requests will be legally required. Others may be introduced by platforms trying to get ahead of new rules.
The EFF's point is that the cost is not only the data you hand over. It is also the chilling effect of knowing your lawful reading habits may be tied to your name. People researching health, sexuality, politics, or personal safety may reasonably hesitate if an ID is the entry fee.
A VPN can still protect your connection from local network observers and your internet provider. But a VPN does not erase an identity you have already provided to a site, and it is not guaranteed to satisfy or sidestep any particular legal requirement. Treat it as one privacy layer, not a full solution.
What privacy-conscious readers can do now
- Audit your accounts. Look through the services you use and note which now ask for ID, a selfie, or a date of birth.
- Share the minimum. If a check is optional, consider whether the content is worth the exposure. If it is required, find out who actually handles the data.
- Read the privacy terms. Look for how long verification data is kept and whether a third party processes it.
- Separate identities. Avoid reusing the same email and credentials across verified and unverified services.
- Keep your expectations realistic about VPNs. They protect traffic in transit; they do not change what a verified account already knows.
- Pay attention to local rules. Laws vary by state and country, and they are changing fast.
The bottom line
The EFF's argument shifts the question from "how much privacy should we trade away?" to "should lawful information require ID at all?" That reframing is useful for anyone weighing age verification laws, VPN privacy and the open web. To see how these rules are already reaching VPN use in practice, read our article on Utah's SB 73, then take ten minutes to review which of your accounts and sites now ask for your ID.




