Legal News

Social Media Bans and User Verification: An Age-Old Problem

Whilst social media shaped my generation, the platforms of 2026 bear little resemblance to those we first encountered. 
Algorithmic amplification, infinite scroll, and engagement-maximising design have produced something qualitatively different from the early internet. The evidence of harm is harder to dismiss than it once was.

0 in 10adolescents showed problematic social media use, up from 7% in 2018 (WHO, 2022)

Given the above, it is unsurprising that the government's announcement that under-16s will be banned from social media has been broadly welcomed. The harder question, which has received less attention: how you actually verify someone's age?

“Governments of the Industrial World, you weary giants of flesh and steel, I come from Cyberspace, the new home of Mind. On behalf of the future, I ask you of the past to leave us alone. You are not welcome among us. You have no sovereignty where we gather.” 

John Perry Barlow: A Declaration of the Independence of Cyberspace, 1996

The Privacy and Security Risks of Age Verification

Age verification is not a new problem. Around 2010, the standard approach was to ask users to enter a parent’s email and your date of birth (a method so ineffective that, according to several ancient web forums, I am apparently somewhere between 50 and 100 years old!)

Recent amendments to the Children's Wellbeing and Schools Act 2026 require the government to impose age or functionality restrictions for under-16s, but the legislation does not resolve the technical question of how platforms establish a user's age with any reliability. Short of a compulsory digital identity scheme, no mechanism currently does. 

We have already seen how this plays out in practice. Following the Online Safety Act 2023, UK users must verify their age on pornographic sites using photo ID. Two problems immediately arise. The first is a cybersecurity problem: submitting sensitive identity documents to websites of dubious reliability creates obvious opportunities for fraud and impersonation. The second is a privacy problem: attributing data about sexual preferences to an identifiable individual creates clear risks around blackmail and discrimination. For now, both issues are largely academic, because a VPN renders the requirement trivially bypassable. 

Note

When age verification requirements took effect on 25 July 2025, Proton VPN downloads surged by 1,400% over that weekend. Daily VPN users more than doubled, rising from around 650,000 before the deadline and peaking at over 1.4 million in mid-August - which is presumably why the government are now considering banning those too.

Harmful content generates calls for age verification; this generates evasion by users; this generates calls for tougher age verification, such as application to VPNs, in a reinforcing cycle. As the pipelines of harmful content is not reduced, calls for age restrictions are unlikely to reduce.” 

Jim Killock: The Social Media Policy Ratchet, 2026

Applying similar checks to social media could prove to be far more problematic. Scaling this infrastructure across every major social media platform means combining a verified identity with the volume of sensitive personal data those platforms already hold – creating lucrative targets for both cybercriminals and government surveillance. 

Can Social Media Age Restrictions Actually Work?

Even accepting that these risks are a price worth paying, it is unclear whether the regulations will be effective. The borderless nature of cyberspace renders national regulation without cross-jurisdictional consensus incomplete and easily circumvented. A second structural problem follows: you cannot regulate the online experience for a subset of users without changing it for everyone else.

A prior question is worth putting: is an outright ban the most effective instrument available? Regulatory alternatives - ending the endless scroll, tightening rules governing teen accounts,  genuine parental controls rather than nominal ones - address some of the same harms without requiring the de-facto abolition of online anonymity. Non-legal interventions, including blanket phone bans in schools, or raising greater awareness among parents, may prove more tractable still. The social media ban reflects a legitimate concern. Whether the infrastructure needed to enforce it is worth the cost it imposes on us all is a question the government has not yet answered.

Jared Higgins
Founder, PupillagePulse