The EU’s Age Verification Plan Is a Digital Gatekeeper. One Developer Just Proved There’s a Better Way.

You probably haven’t heard about the EU’s age verification proposal yet. But by the time it passes, your phone will decide if you’re allowed to read the news, log into a forum, or even see a dating app.

And the scariest part? The only way to prove your age will be through Android or iOS. No Linux. No custom ROMs. No privacy-first browsers. Just the two operating systems that already own your data.

I saw this firsthand. A developer posted a proposal to the EU’s digital identity repository, and the response was deafening silence. Because the proposal threatened something powerful: the idea that age verification has to be OS-dependent.

But here’s the truth they don’t want you to know: OS-dependent age verification is not about security. It’s about control.

The technical argument is simple: Apple and Google already have biometrics, device attestation, and secure enclaves. Why build something new? But ask yourself: what happens when a teenager in a privacy-respecting home uses a GrapheneOS phone? They’re locked out. What happens when a European citizen refuses to use a US-based cloud for identity attestation? They’re locked out.

That’s the tension. The EU wants to protect children, but it’s building a walled garden that excludes everyone who doesn’t play by Apple and Google’s rules.

One developer proposed an alternative: use existing web standards — WebAuthn, verifiable credentials, and a decentralized trust model. No OS required. No gatekeeper. Your identity stays yours, and the verification happens on your terms.

This isn’t a technical pipe dream. The spec exists. It’s open. It’s auditable. And it solves the exact same problem without forcing millions of users into a digital monoculture.

The twist? The opposition isn’t coming from the EU. It’s coming from the very companies that claim to champion privacy. They want age verification as a platform feature because it locks users into their ecosystem. Once you’re verified through Apple, leaving is painful. Your identity is tied to their hardware.

This isn’t about age verification. It’s about digital sovereignty. The EU has spent years fighting for data protection, only to hand the keys of identity verification to two US corporations.

So what can you do? Read the proposal. Comment on the GitHub issue. Share it with anyone who cares about an open web. Because the next time someone tells you age verification is a settled technical problem, remember: the only thing settled is who gets to decide who you are.

We have a choice. We can build a system that belongs to everyone — or we can hand the internet to the two companies that already own our attention.

Choose wisely.

FAQ

Q: Isn't OS-dependent age verification more secure because it uses hardware attestation?

A: Hardware attestation is a feature, not a requirement. The open standard proposal uses WebAuthn and verifiable credentials, which can be just as secure while being OS-agnostic. The real security risk is centralization: a single OS vendor becomes a single point of failure and control.

Q: What does this mean for me as a regular user?

A: If OS-dependent verification becomes law, every website that requires age verification will effectively force you to use an iPhone or an Android device. No alternative OS, no privacy-focused browser, no custom firmware. You lose the freedom to choose your digital identity provider.

Q: Isn't the EU just trying to protect children? Why is this controversial?

A: Protecting children is a noble goal. The controversy is about the method. An open standard can achieve the same safety outcome without handing monopoly power to Apple and Google. The real question is: why are policymakers ignoring the safer, more equitable solution?

📎 Source: View Source