Here's a bouncer standing outside a bar. He looks at your ID, sees you were born in 1994, hands it back, and lets you in. He doesn't photocopy it. He doesn't write your name in a ledger. He doesn't call your employer. Ten minutes later he's forgotten you exist.
That's age verification working properly. One question asked, one answer given, nothing kept.
Now imagine the same bouncer scans your ID into a database, stores a photo of your face, logs the time you arrived, and sells the whole file to a company you've never heard of. Same question. Wildly different consequences.
That second bouncer is what most of the internet is currently building.
Here's the frustrating part: proving you're over 18 without revealing who you are is a solved problem. Not theoretically solved but actually solved with working code AND deployed in real systems!
The trick is something cryptographers call a zero-knowledge proof, which sounds intimidating but is conceptually simple. Your phone, or your bank, or your government ID app already knows your birthdate. It can generate a mathematical token that says "this person is over 18" and hands that to the website. The website gets a yes. It never gets your name, your birthdate, your document number, or your face.
Better still, a well-designed token is single-use and unlinkable. Visit the same site tomorrow and it can't tell you're the same person who visited today. That's the difference between privacy and anonymity doing their separate jobs: the site learns a fact about you (privacy preserved) and can't build a profile out of repeated visits (anonymity preserved).
Regulators know this. The European Commission's age verification framework, published in April 2026 with a push for rollout by the end of the year, explicitly says verification should be proportionate and shouldn't be used to profile or track users. The EU's own age-verification blueprint app is built on exactly this double-blind principle: the issuer doesn't know which site you're visiting, and the site doesn't know who you are.
So the technology exists, the regulators have blessed it, and everyone agrees it's the right approach.
And then you go to actually use a website.
What you meet in the wild is rarely a cryptographic token. It's usually one of three things: upload a photo of your government ID, let us scan your face, or hand your credit card to a third party you've never heard of.
Each of these does the opposite of what the theory promised. Instead of proving one fact, you're surrendering a complete identity document. Instead of nothing being stored, something is almost always stored for compliance, for fraud prevention, for "up to 30 days," for reasons buried in a subprocessor agreement.
And this is the specific mechanism by which anonymity dies. Not with a ban, not with a law that says "you must use your real name." It dies because a pseudonymous account (the throwaway you made for a forum, the handle you've used for eight years, the account you deliberately kept separate from your professional life) gets permanently welded to a government ID at the moment of signup.
That weld is retroactive. Everything you posted before the verification is now attached to your legal name, sitting in someone's database, waiting.
Proton's CEO has put it bluntly: age verification as currently proposed, country after country, would mean "the death of anonymity online." That's not hyperbole about the concept. It's an accurate description of the implementations.
If you want a single incident that proves the whole argument, it's the Discord one. Discord's age-verification partner was breached, exposing government ID photos belonging to roughly 70,000 users.
Sit with the mechanics of that for a second. Those users didn't want to hand over their IDs. Most of them were probably nudged into it because an automated age-estimation model looked at their face or their behaviour and guessed wrong. The "easy" verification failed, so the fallback kicked in and the fallback is always the invasive one. Then the fallback leaked.
This is the pattern to watch: age estimation is the friendly front door, but it has an error rate, and the error handling is where your passport ends up in a stranger's S3 bucket. A system is not defined by its happy path. It's defined by what happens when the happy path fails.
Meanwhile the legal picture keeps shifting. Just this week, a split Sixth Circuit panel found that a lower court should have blocked Tennessee's age-verification law for social media, agreeing that the industry group challenging it had shown harm from compliance costs and loss of free speech liberties. Courts are still working out where the lines are, which means companies are building systems now, in a fog, optimising for "provably compliant" rather than "minimally invasive." Provably compliant means keeping records. Keeping records is the entire problem.
If you're evaluating a system (as a user, or as someone building one) there are four questions that separate the bouncer who forgets you from the one who files you.
There's no contradiction between keeping kids out of adult spaces and letting adults move through the internet unidentified. Those two goals are compatible. The maths works.
What doesn't work is the shortcut like the vendor who'll get you compliant by Friday, the model that guesses your age from a selfie, the fallback that quietly turns a privacy feature into an identity registry.
The debate is usually framed as safety versus anonymity, as though we're picking a side. We're not. We're picking between a good implementation and a lazy one, and lazy is winning because it ships faster and the harm shows up later, in someone else's breach notification.
Ask for the token. Refuse the photocopy.