The Same Bill In Every Country: How Age Verification Became the On Ramp To Digital ID

Staircase of age verification laws from UK OSA to digital ID mandate, a one-way ratchet

18 min read·Published Sep 29, 2026

0 0 votes
Article Rating

Part of Start Here

In a single year, two different legal orders on two different continents produced statutes that both reduce, in the same year, to the same four letters. In the United States, H.R. 7757 of the 119th Congress carries the short title “Kids Internet and Digital Safety Act”, the KIDS Act. In the European Union, the Commission adopted on 17 September 2026 a proposal numbered COM(2026) 681 final, titled “EU Keeping Internet Digital Spaces Accountable and Trustworthy”, the EU KIDS Act. Two legislatures, two legal traditions, one acronym. The convergence is not limited to the branding. UNICEF’s 2025 policy brief, drawing on a comparative analysis of six jurisdictions, found that “Eight common business obligations are emerging across jurisdictions”, with age assurance among them. This article is about how that convergence was assembled in public, who holds the pen at each link in the chain, and what kind of power each of those hands actually wields.

1. Two KIDS Acts, side by side

The American instrument is H.R. 7757, 119th Congress, short title verbatim from the congress.gov record: “Kids Internet and Digital Safety Act”, styled the KIDS Act. It was introduced on 3 March 2026, passed the House 267 to 117 on 29 June 2026, and was referred to the Senate Committee on Commerce, Science and Transportation on 13 July 2026. It consolidates language from roughly fourteen bills, including KOSA and COPPA 2.0, and the duty of care was removed in section 213(c)(2). The congress.gov record for H.R. 7757 is the authority on its current status.

The European instrument is COM(2026) 681 final, adopted by the European Commission on 17 September 2026, with the full title “EU Keeping Internet Digital Spaces Accountable and Trustworthy” and the EU KIDS Act as its working name. It rests on Article 114 of the Treaty on the Functioning of the European Union, the internal market legal basis. It is a proposal, not law. Under the ordinary legislative procedure it must be adopted jointly by the European Parliament and the Council, and no final adoption date appears in the document. Based on the typical duration of that procedure, any binding obligations would land years after adoption; that timeline is inference, and it is labelled as such.

What each actually does is where the convergence becomes visible. Both instruments treat age assurance, the technical verification or estimation of a user’s age, as a core regulatory obligation for online services rather than a term-of-art for a narrow category of content. UNICEF’s 2025 brief, “Keeping Children Safe Online: Trends in Online Platform Regulation and Emerging Lessons”, which examined Australia, the European Union, India, Kazakhstan, South Africa and the United Kingdom with developments as of June 2025, states as its finding 5: “Eight common business obligations are emerging across jurisdictions.” Age assurance and content age gating are among the eight. A note for accuracy, because it matters: UNICEF published a separate brief in June 2026, “When AI becomes a friend”, covering a different set of six jurisdictions, and its finding is a five element set of regulatory elements plus eight priority actions. The eight obligations finding belongs to the 2025 brief alone.

2. Who writes the language

The text of these statutes did not appear from nowhere. Each link in the chain below is documented in a primary source, and each is quoted from that source.

The chain begins in the United Kingdom. The official parliamentary record shows Amendment 109 to the Data Protection Bill, tabled at Report stage in the House of Lords by Baroness Kidron, a crossbench life peer, and agreed. That amendment became section 123 of the Data Protection Act 2018, which requires the Information Commissioner to prepare an age appropriate design code. Section 123(4) requires the Commissioner, in preparing the code, to have regard “to the United Kingdom’s obligations under the United Nations Convention on the Rights of the Child”. The UN Committee on the Rights of the Child issued General Comment No. 25 on children’s rights in the digital environment in 2021; OHCHR’s page dates it 2 March 2021 while the UN treaty body index records 24 March 2021, and the two official dates differ. The treaty body’s own text says it “explains how States parties should implement the Convention in relation to the digital environment and provides guidance on relevant legislative, policy and other measures”. Guidance, not law, but a statute now requires a British regulator to have regard to it.

The next link is a private standards body. IEEE published IEEE 2089-2021, titled “IEEE Standard for an Age Appropriate Digital Services Framework Based on the 5Rights Principles for Children”. The subtitle names the advocacy organisation in the standard itself. IEEE’s own material states that IEEE 2089 became the basis for CEN/CENELEC Workshop Agreement CWA 18016:2023, and that its standards are referenced in the Greek national strategy and in the Commission’s guidance on Article 28 of the Digital Services Act. Precision is required here: a CWA is a workshop agreement. It is not a European Standard and it is not law. 5Rights Foundation’s own annual report for the year ended 31 March 2023 states: “We were delighted that our advocacy reached the European Union which decided to adopt the 5Rights-inspired IEEE 2089 Standard as an EU Standard and the inclusion of the ‘children’s clause’ in the Digital Services Act.” That is the charity’s characterisation, in its own words. The European artefact it describes is the workshop agreement, and the “children’s clause” is Article 28 of the Digital Services Act.

The model travelled. 5Rights’ own website states that the California Age Appropriate Design Code, AB 2273, signed in September 2022, was sponsored by 5Rights. UNICEF’s 2025 brief found the eight obligations converging across six jurisdictions on three continents. WeProtect Global Alliance’s Global Threat Assessment speaks of a “third wave of legislative reform” and “improved harmonisation”, in the alliance’s own words. WeProtect’s Model National Response was co-submitted to the UN Global Digital Compact alongside 5Rights Foundation, ECPAT International, the ITU, UNICEF and World Childhood Foundation, per the submission’s own co-signatory list.

The final link is the standards summit. The Global Age Assurance Standards Summit, convened in Manchester between 14 and 16 April 2026, issued a communiqué that “welcom[es] the publication of ISO/IEC 27566-1, Age Assurance Systems, Part 1: Framework” and notes “the continuing development of ISO/IEC 27566-2 and ISO/IEC 27566-3, and welcoming the publication of IEEE 2089.1-2024”. Its Call to Action, item 1, states: “Regulators should reference internationally recognised standards, including ISO/IEC 27566-1, in guidance and enforcement activity to promote clarity, reduce fragmentation and enable consistent, auditable compliance across jurisdictions.” The summit was announced and hosted by the Age Check Certification Scheme, an “independent not-for-profit company limited by guarantee registered in England and Wales (11493870)”, whose founder and chief executive, Tony Allen, is recorded on the organisation’s own page as Technical Editor of the ISO/IEC 27566 series and Co-Chair of the UK Government’s Expert Panel on Age Restrictions.

Read the chain in one breath: a peer’s amendment becomes a statute, the statute requires regard to a UN committee’s interpretation, the advocacy organisation founded by the same peer lends its principles to a private standard, the standard becomes a workshop agreement, the workshop agreement is credited by the charity itself as an EU adoption, the pattern is validated by a UN agency’s comparative brief, harmonisation is celebrated by an alliance of governments and companies, and a communiqué calls on regulators to cite the standards in enforcement. Every link is on the public record.

3. Who is in the room

The organisations in this chain are not anonymous. Their legal forms, incomes and funders are published by themselves.

5Rights Foundation is a registered charity in England and Wales (number 1178581) and Scotland (SC049882) and a company limited by guarantee (11271356), with a Belgian ASBL arm, 5Rights EU. Its transparency page states: “We do not accept funding or in-kind donations from tech companies or their charitable or philanthropic arms.” The same page lists its institutional funders by year. The 2024 list includes the Council of Europe, IEEE SA, the Lego Foundation, the Archewell Foundation and Dove; the 2023 list includes IEEE SA and the Oak Foundation; the 2026 list includes the Council of Europe, the Oak Foundation and Safe Online. Two observations, both labelled. First, the fact that money moves from a funder to an organisation is not evidence of inducement, and this article asserts no such thing. Second, there is a definitional question that only the charity can answer: its 2024 funder list contains the Lego Foundation, IEEE SA and Dove alongside its statement that it accepts nothing from technology companies or their philanthropic arms. Whether any of those three falls within the charity’s own definition is not addressed on its page. We record the discrepancy and draw no conclusion from it.

WeProtect Global Alliance is a Dutch foundation, Stichting The WePROTECT Global Alliance. Its 2024 audited financial statements record income of €1,964,082, all from “other not for profit organisations”, and government grants of nil. Its funders are disclosed through its statement of project funding liabilities: OAK Foundation, the EU, Stichting Benevolentia, Together for Girls, the New Venture Fund, the Calf Fund, the Children’s Investment Fund Foundation and Snapchat, the last with a balance of €211. Its Global Policy Board, per its own governance page, includes Jacqueline Beauchere of Snap Inc., Emily Cashman Kirstein of Google, Julie Cordua of Thorn, the Australian eSafety Commissioner, a representative of the European Commission’s Directorate General for Migration and Home Affairs, a UK Home Office deputy director, and two UNICEF child protection figures.

ECPAT International is a Dutch stichting, KVK 34139743, head office in Bangkok. Its audited accounts for the year ended 30 June 2025 record grants and donations of USD 5,108,995, the largest items being the Oak Foundation at USD 1,211,087 and the Swedish International Development Cooperation Agency at USD 1,122,783. Thorn is a US 501(c)(3), EIN 27-0943677, with FY2024 revenue of $16,355,617 per its IRS Form 990 data. The Internet Watch Foundation is a UK charity, number 1112398, which states it is “primarily funded by the internet Industry and a grant from Nominet”.

The personnel overlaps are facts about seats, and we state them as nothing more. Ernie Allen chairs the WeProtect Global Policy Board and sits on Thorn’s board, where Thorn describes him as “Founding Chairman, WeProtect Global Alliance”. Julie Cordua is Thorn’s chief executive and a WeProtect board member. Guillaume Landry is ECPAT’s executive director and a WeProtect board member. Cornelius Williams chairs ECPAT’s supervisory board and sits on the WeProtect board as former director of child protection at UNICEF, where Sheema Sen Gupta, the current director of child protection, also sits. No conclusion about coordination follows from these facts beyond what the documents themselves record: these are the same bodies, sharing people, producing the harmonisation language quoted above.

One discrepancy in the record deserves plain statement. The Digital Futures Commission, funded by 5Rights, acknowledged “a contribution from the LEGO Group in 2020/21” in its own final report, while a vice president of the LEGO Group, Anna Rafferty, sat on the commission’s published list of commissioners. Separately, 5Rights’ transparency page lists the Lego Foundation among its 2024 funders. The LEGO Foundation’s machine readable grantee lists for 2021 and 2022 contain no grant to 5Rights; the 2023 to 2025 appendices are not machine readable and could not be checked by text search. Which LEGO entity the 5Rights entry refers to is unresolved. We put the question to the organisations rather than answer it by inference.

4. Unelected, and what kind of power each one holds

This is the spine of the article. The table below classifies each body in the age assurance stack by two questions: did any electorate choose it, and does its output bind anyone.

Body Elected? Output binding or advisory? What it decides in this stack
European Commission Unelected, appointed Binding Sole proposer of EU legislation; adopts implementing regulations; funds and publishes the age verification app
Commission Recommendation (EU) 2026/1035 of 29 April 2026 Unelected author Advisory, by Article 288 TFEU Sets the end 2026 rollout expectation and the EU Age Verification Scheme
Special Panel on Child Safety Online Unelected experts appointed by the Commission Advisory Recommendations to the Commission President on a common EU age limit for social media, co-chaired by Dr Maria Melchior and Prof. Dr Jorg M. Fegert, with the report presented on 13 July 2026
Ofcom Unelected, board appointed by the Secretary of State Binding Enforces the Online Safety Act 2023 age assurance duties, with penalties and criminal offences for breach
A crossbench life peer, and the amendment she tabled Unelected Binding once enacted Amendment 109 created the age appropriate design code duty in the Data Protection Act 2018
UN Committee on the Rights of the Child Unelected, not chosen by the public Advisory General Comment No. 25, which UK law requires the code to have regard to
ISO, IEEE, CEN-CENELEC Private, unelected Voluntary until cited in law ISO/IEC 27566-1:2025, IEEE 2089-2021, CWA 18016:2023
European Data Protection Board Unelected Advisory, binding in GDPR Article 65 disputes Statement 1/2025 on age assurance, adopted 11 to 12 February 2025

Three rows need expansion. The European Commission’s proposal monopoly is in the treaties: Article 17(2) TEU states that “Union legislative acts may only be adopted on the basis of a Commission proposal, except where the Treaties provide otherwise.” The European Parliament is directly elected and cannot initiate legislation. Commissioners are appointed under Article 17(7) TEU, with the Parliament consenting to the body as a whole.

Ofcom is the case where an unelected body wields criminal law. The Online Safety Act 2023, section 138, creates an offence, punishable on indictment with up to two years’ imprisonment, of failing without reasonable excuse to comply with a confirmation decision relating to the children’s online safety duties. What counts as “highly effective age assurance” is defined not in the Act but in Ofcom’s own codes and guidance, meaning an appointed regulator’s judgement determines which commercial methods are lawful.

The standards bodies are the third case, and the documented example of their output becoming binding is Commission Implementing Decision (EU) 2025/138 of 28 January 2025, which cites harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024, drafted by CEN and Cenelec, as conferring a presumption of conformity with Directive 2014/53/EU. Three standards written by private bodies became the operative measure of legal conformity, and an unelected executive decided which clauses, “with restrictions”, received that effect. The same shape applies inside eIDAS: Implementing Regulation (EU) 2025/1569 of 29 July 2025 requires attestations to be issued according to ETSI EN 319 401 v3.1.1 and the standards in its Annex II.

5. The enforcement layer, one app

The European Commission’s age verification app was built by the T-Scy consortium, composed of Scytáles AB of Sweden and T-Systems International GmbH of Germany, under a two year contract awarded by the Commission in early 2025, per the Commission’s own news release of 14 July 2025. The blueprint was published in July 2025, a pilot began the same month, a second version with a passport and identity card method followed in October 2025, and the Commission’s factpage states that “As of April 2026, the age verification app is technically ready”.

On 29 April 2026 the Commission adopted Recommendation (EU) 2026/1035. Article 288 TFEU is blunt: “Recommendations and opinions shall have no binding force.” But read what the recommendation does. Paragraph 5 “recommends that Member States make available, by 31 December 2026, an EU age verification solution”. Paragraph 10 encourages Member States to “mandate the use of age verification methods that conform to the EU Age Verification Scheme”. Paragraphs 8 and 9 reserve to the Commission, through Article 8 of Implementing Regulation (EU) 2025/1569 and the trusted lists, the power to decide which age verification providers count. Non-binding in form, gatekeeping in effect.

Underneath it sits the wallet. Regulation (EU) 2024/1183, eIDAS 2.0, requires a European Digital Identity Wallet to be available in every member state by 24 December 2026, with acceptance mandatory for online public services from that date and for banking, telecoms, healthcare, transport, energy, education and very large online platforms from 24 December 2027. The Commission’s age verification manual lists a pending use case: “Banking & payment: open bank account using your EUDI Wallet”. The same manual records automated verification at 1 to 5 euro cents per transaction against 1 to 5 euros for manual checks. And recital 12 of the Recommendation states that the app’s specifications are “aligned with those of the EU Digital Identity Wallets”. That sentence is the Commission’s own. The Commission’s material also places the app on the same technical lineage as the EU Digital COVID Certificate. A comparison between the two instruments has been widely attributed to the Commission’s President in coverage of the April 2026 announcement; it does not appear in the Commission’s written statement of 15 April 2026 that we could retrieve, and because we cannot cite a verbatim transcript, we do not quote it.

On privacy, the specification says apps SHOULD use zero knowledge proofs, not that they MUST. The distinction is the Commission’s own capitalisation. Against that backdrop, researchers at the SIROS Foundation argue that the proof of age attestation is transferable, that once issued it can be passed on. If they are right, the credential behaves less like a proof about a person and more like a bearer token: whoever holds it can use it. That is the researchers’ characterisation, not ours, and it is contested. The researchers state limitations of their own in the full analysis, which we link below rather than summarise conditions we have not verified line by line. We put the finding to the European Commission, to Scytáles AB and to T-Systems International, and we will publish their responses in full when received.

6. What is not established

Some of the wider story told about this apparatus is not documented, and saying so is part of the job. The digital euro is not decided: the European Central Bank is in a preparation phase with issuance no earlier than 2029. Programmability of money is a design option discussed in a 2020 Bank for International Settlements paper, not a deployed feature of anything. Cash payment limits and anti-money-laundering reporting requirements are real, but they are a separate legislative track from age verification. Conflating them weakens the documented case.

What is documented is this: the statutes, the amendment, the general comment, the standards, the workshop agreement, the recommendation, the implementing regulations, the contract, the deadlines, the funder lists, the board seats and the employment records. The policy network operates in the open. Its documents are published, its registers are public, its accounts are filed. Nothing in this article depends on secrecy, and nothing here alleges a conspiracy or an unlawful act by any named person or organisation.

Closing: the honest argument

Strip away the acronyms and one structural fact remains. An unelected executive holds a monopoly on proposing law. An unelected chamber produced a binding amendment. An appointed regulator defines, in guidance, which private verification methods are lawful, backed by a criminal offence carrying up to two years. Private standards bodies, answerable to no electorate, write frameworks that become binding when an unelected executive cites them, as Implementing Decision (EU) 2025/138 did with the EN 18031 series. A non-binding recommendation steers twenty-seven governments toward a single verification app built by two private contractors, on a credential rail that banks will be legally required to accept by 24 December 2027. Every one of those sentences traces to a document linked below, and the reader can check each link in an afternoon.

The people inside this machinery say their aim is protecting children, and their documents say so too. The question this article leaves with the reader is not about anyone’s sincerity. It is about consent: whether the architecture now being assembled, obligation by obligation, standard by standard, deadline by deadline, is one that any electorate was ever asked to approve. The record shows that none was.

Frequently asked questions

What is the difference between the US KIDS Act and the EU KIDS Act?

They are different instruments in different legal orders that share a four letter acronym. The US bill is H.R. 7757, short title “Kids Internet and Digital Safety Act”, introduced 3 March 2026, passed by the House 267 to 117 on 29 June 2026. The EU instrument is COM(2026) 681 final, “EU Keeping Internet Digital Spaces Accountable and Trustworthy”, proposed by the Commission on 17 September 2026 under Article 114 TFEU.

Was the EU age verification app really compared to the COVID certificate?

The Commission’s own published material places the app on the same technical lineage as the EU Digital COVID Certificate. A comparison between the two attributed to the Commission President circulates widely in coverage of the April 2026 announcement, but it does not appear in the Commission’s written statement of 15 April 2026 that could be retrieved, so this article does not reproduce it as a quotation.

Do zero knowledge proofs make the EU age verification app private?

The specification says applications should use zero knowledge proofs, not that they must. Researchers at the SIROS Foundation argue that the resulting proof of age is transferable, meaning it can be passed on once issued, which would make the credential behave like a bearer token. That is their contested technical finding, attributed here rather than adopted, and this article carries a standing offer to publish responses from the Commission, Scytales AB and T-Systems International in full.

Sources

0 0 votes
Article Rating
Published
Categorized as Blog
The Thrifty Dev, author at thethriftydev.com

By TheThriftyDev

Building smart with AI and automation. No fluff, just results.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Most Voted
Newest Oldest
TheThriftyDev Dispatch
Quit Google in One Weekend

The 48-hour migration playbook: what to move first, what to keep, and the exact apps that won't make you regret it on Monday.

No spam. Practical privacy, AI, backup and tool drops. Unsubscribe anytime.
0
Would love your thoughts, please comment.x
()
x