Writer and digital-rights activist Cory Doctorow has argued that internet age-verification rules amount to broad surveillance because services must evaluate adults as well as children before deciding who may enter. His essay challenges a growing policy consensus that minimum-age rules can address online harm without creating a larger identity and tracking infrastructure.
Doctorow begins from a qualified premise: some children experience real harm online, but research about the scale and causes is complex and often interpreted too confidently. He describes an alliance between critics of large technology platforms and socially conservative groups, each supporting age limits for different reasons. His central claim is that enforcement cannot be confined to minors because a service has to inspect or profile every user to identify which ones are underage.
Possible mechanisms include document checks, facial age estimation and analysis of existing behavioral data. Doctorow is particularly skeptical of systems that claim to distinguish people just below and just above a legal threshold through a camera. He also argues that widespread circumvention through virtual private networks could lead governments to consider restricting VPN use, adding another layer of control. These are the author’s predictions and judgments, not outcomes independently established by the supplied evidence.
The essay connects age assurance with the advertising industry’s established collection of behavioral data. Recommendation systems can use such data to steer vulnerable users toward material involving eating disorders, misogyny or other harms. In Doctorow’s view, requiring more observation to protect children from harms enabled by observation is internally contradictory. He says policy should instead begin with limits on commercial surveillance.
The piece contrasts the United States, whose federal consumer-privacy framework Doctorow describes as outdated, with the European Union’s General Data Protection Regulation. He argues that enforcement weaknesses and the political influence of US technology companies prevent existing privacy approaches from providing an adequate counterweight. The source includes numerous links, but the supplied packet does not contain those underlying studies and reports, so their findings are not independently summarized here.
Doctorow also warns about reuse: information collected today to estimate age could later be applied to advertising, pricing, employment, immigration enforcement or other government purposes. That risk depends heavily on system design, retention rules, legal restrictions and whether verification can be performed without persistent identity data.
The essay is advocacy, but it identifies a practical test for proposed laws. Policymakers should specify what data is collected from all users, who receives it, how long it exists, whether access can remain anonymous, how errors are appealed and whether a less intrusive method can meet the same child-safety goal. Without those answers, “age verification” describes an objective while obscuring the infrastructure required to enforce it.


