TL;DR: Cory Doctorow, the EFF Special Adviser and pluralistic.net author, published a structural critique of age verification mandates on June 23, 2026. The op-ed hit 819 points and 436 comments on Hacker News in 17 hours, the highest-engagement privacy thread in the State of Surveillance tracker since the Anthropic Fable 5 family. His argument: every age verification mandate (UK Online Safety Act, US state laws, EU platform rules, frontier-model lab policies) builds an identity-verification database that links a real person to a specific platform activity. That database is the next surveillance target. The structural read lands the same day five separate fresh breaks from the surveillance beat converge on the same underlying argument: the Anthropic July 8 rollout, the Madison Square Garden facial recognition activist dossier, the Mullvad "Block This. We Dare You" campaign, the UK Online Safety Act's facial age estimation, and Ben Werdmuller's "Signal/zines" Texas terrorism essay.
Doctorow's Argument: The Age Check Is the Entry Point. The Identity Database Is the Prize.
Doctorow's June 23 op-ed on pluralistic.net opens with a line designed to cut through the child-safety framing: "What we call 'age verification' is actually mass surveillance, so invasive and pervasive that it makes the ad-tech industry's commercial surveillance look like some kind of cypherpunk darknet pirate utopia."[1] The framing matters because it puts age verification on the same side of the surveillance ledger as the ad-tech industry that the same laws are nominally aimed at.
The structural argument: "Age verification" means everyone who does anything online will have to submit to fine-grained tracking and recording of all their online activities. The state wants to verify age. The platform wants to verify identity. The vendor in the middle (Persona, Yoti, or the next one) holds both. The database that links a real-world person to a specific platform activity is exactly what law enforcement, intelligence agencies, and private actors want, and the age check is just the entry point.[1]
Doctorow is specific about the data flow: "the same data that's being used to 'verify age' today will be used by ICE tomorrow to figure out who to round up for a concentration camp."[1] The Wired investigation he links confirms the trajectory: ICE has asked ad-tech and big-data companies about their tools for finding individuals, which is the federal-side demand signal for exactly the kind of identity database the age-verification mandates are building.[2]
The Coalition Behind the Mandates Includes the Companies the Mandates Are Supposed to Regulate
Doctorow's most uncomfortable observation: "it's not just a weird alliance of anti-Big Tech crusaders and the conspiratorial right that's pushing for age verification. They are unwitting allies of the very tech industry they think they're fighting."[1] The argument is that the ad-tech industry's commercial-surveillance apparatus benefits when the state mandates identity verification, because the mandates legitimize and accelerate the surveillance infrastructure the industry was already building for advertising purposes.
The age-verification vendors themselves sit in the same family as the ad-tech trackers they superficially oppose. Persona's government codebase, exposed in February 2026 on a FedRAMP-authorized government endpoint, runs 269 surveillance checks per user (facial recognition against watchlists, adverse media screening, crypto activity monitoring, government database lookups) and files suspicious activity reports directly with FinCEN and FINTRAC.[3] Yoti, the facial-age-estimation vendor, has been found uploading user selfies to its servers and shipping the data through trackers that could share verification attempts with data brokers. The Discord ID breach of October 2025 exposed 70,000 government ID photos submitted for age verification. The vendors are not neutral pipes. They are surveillance intermediaries with a mandate to collect.[4]
The Mandate Teaches Every Child to Use a VPN. The Next Move Is to Ban VPNs.
Doctorow is explicit about the second-order effect: "those tech industry insiders are fully aware that an 'age verification' mandate is really a way for the government to teach every child how to use a VPN. They're also fully aware that the next move is to ban VPNs."[1] The Express article he links, dated July 2025, confirms the UK is already on the path: the Labour government has a VPN ban on the table for the July legislative session.[5]
Australia's March 9, 2026 age-verification enforcement triggered a 1,150% spike in VPN usage the day the law went into effect. NordVPN jumped from #189 to #13 in the iPhone App Store, Proton VPN from #174 to #19. The state taught every Australian who wanted to read the internet without a checkpoint exactly which tool to use.[6] Wisconsin and Michigan responded by proposing VPN bans, literally outlawing the tool people used to avoid the surveillance. The UK House of Lords voted 207 to 159 in January 2026 to ban VPNs for anyone under 18. The pattern is exactly the one Doctorow names: mandate age verification, watch the VPN surge, ban the VPN.
The Facial Age Estimation Grift
Doctorow singles out the facial-age-estimation vendors by name: "Behind them is a long line of caliper-wielding grifters who claim they can use your phone's camera to distinguish a child who is 17 years, 364 days old from an adult who's just turned 18."[1] The GOV.UK guidance on facial age estimation he links confirms the technology is treated as legitimate regulatory infrastructure by the UK government, even though the empirical accuracy is contested and the false-rejection cost is borne by adults who look young.[7]
The surveillance-state cost is the same regardless of whether the vendor is accurate. The selfie goes to the vendor. The vendor has the selfie. The selfie is biometric data that, once breached, cannot be replaced. GrapheneOS documented the Yoti "reported to authorities" pattern in 2025: users who tried to bypass the Yoti age gate by spoofing or omitting data were flagged and reported.[8] The vendor's job is not to be accurate. The vendor's job is to be the checkpoint.
Five Stories From the Same Day Sit on the Same Beat
Doctorow's op-ed published at 14:04 UTC on June 23, 2026. The 23-hour window before the State of Surveillance cycle 1 read on June 24 at 07:01 UTC produced five fresh breaks that all sit on the age-verification-as-surveillance beat:
- Anthropic updated its privacy policy to verify both age and identity, fourteen days before the July 8 rollout. The corporate-press pickup of the 860-point Anthropic ID verification thread surfaces the age-verification angle: Persona, the verification vendor, will also handle age checks.[9]
- Madison Square Garden used facial recognition to build a dossier on activists who had previously opposed the venue's own facial recognition program. 404 Media's Joseph Cox published the investigation on June 23. The dossier was used to bar activists from MSG venues including Radio City Music Hall and the Beacon Theatre.[10]
- The Mullvad "Block This. We Dare You" campaign launched the same day. The VPN provider is publicly challenging governments and copyright enforcement agencies to block its traffic, treating the act of trying to ban a privacy tool as the marketing channel.[11]
- Ben Werdmuller published "Signs you're a dangerous terrorist: using Signal, moving zines," a counter-surveillance essay that landed 42 points and 6 comments on Hacker News. The piece is the personal-stakes complement to the structural read: what counts as a "suspicious" online pattern is determined by whoever holds the surveillance data.[12]
- The UK Online Safety Act's facial age estimation is the regulatory backbone. The GOV.UK guidance Doctorow links is the operational document. The same vendor ecosystem (Persona, Yoti) shows up in the UK regulations, the Anthropic policy, the Discord age gate, and the Hinge and Tea dating-app verification flows.
Five stories. One beat. The identity-verification-as-surveillance-infrastructure pattern runs through all of them. Doctorow's op-ed is the structural read of the same argument the five stories are the daily news of.
Why It Harms Adults Too
Doctorow's final move is to reject the framing that the only people affected are the children the laws are nominally aimed at: "Online surveillance is being used to raise the prices you pay and lower the wages you're offered."[1] The data flow that starts with a child proving their age to access a website ends with an adult being denied a loan, a job, or a lease because the same data broker packaged the activity log with credit and identity data and sold it to a buyer who didn't have to disclose the source.
Doctorow on the regulatory vacuum: "America hasn't updated its consumer privacy laws since 1988 (when Congress banned the disclosure of your VHS rentals). The EU has the GDPR, but it also has Ireland, the country where all GDPR cases against Big Tech go to die, because any tax haven inevitably becomes a crime haven."[1] The structural read: the regulatory infrastructure that would have prevented the age-verification surveillance buildout is the regulatory infrastructure that has been gutted or captured. The age-verification mandates are not a substitute for consumer privacy law. They are a workaround for the absence of consumer privacy law, and the workaround builds the very infrastructure the missing law would have prohibited.
What to Watch
- The July 8 Anthropic ID rollout. 14 days from the article date. The first wave of users who fail verification will be permanently locked out of the top Claude models, per Anthropic's own support article. The verifiable signal is the user count in the Persona "verification failed" tier on or after July 8.
- The August 2 EU AI Act high-risk deadline. 39 days from the article date. Age verification of AI output falls inside the high-risk category for biometric inference. The first EU AI Act enforcement action against a US frontier-model lab is the structural precedent.
- The UK July legislative session. The Express piece Doctorow links is from July 2025. A full year later, the VPN ban is still on the table. A vote before the August recess is the structural event to watch.
- Any state-level US age-verification rollback. The state-level statutory counterweight to the age-verification surveillance buildout is the lever. Watch for state-level data-broker-licensing laws (California, Texas, Oregon) and state-level age-verification law amendments (Utah, Louisiana).
- EFF or Wired follow-up coverage. Doctorow's editorial authority is the single highest in the privacy beat. A 900-point Hacker News threshold cross (81 points away at the cycle 1 compound) is the engagement signal that a major outlet is likely to pick it up.
Sources
- Cory Doctorow, pluralistic.net : What we call "age verification" is actually mass surveillance (June 23, 2026)
- Wired : ICE Asks Companies About Ad Tech and Big Data Tools (2025)
- State of Surveillance : Researchers Expose Persona: Age Verification Firm Reports Users to Feds (February 20, 2026)
- State of Surveillance : Age Verification Is Building a Mass Surveillance System, ID by ID (January 27, 2026)
- Express : VPN ban on the table for July as Labour pushes new legislation (July 2025)
- State of Surveillance : Age Verification Triggers VPN Crackdown Across Three Continents (March 25, 2026)
- GOV.UK : Facial age estimation: technical guidance and standards
- State of Surveillance : Yoti, GrapheneOS, and the Age Verification Vendor That Reports You to the Authorities (2025)
- State of Surveillance : Anthropic to Require ID Verification for Certain Capabilities July 8 (June 21, 2026)
- 404 Media : Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition (June 23, 2026)
- State of Surveillance : Daily Surveillance Briefing, June 24, 2026: Age Verification Is Mass Surveillance (June 24, 2026)
- Ben Werdmuller, werd.io : Signs you're a dangerous terrorist: using Signal, moving zines (June 23, 2026)
- Hacker News : What we call "age verification" is actually mass surveillance (HN id 48645173, 819 points, 436 comments, posted 2026-06-23 14:04 UTC)