France’s attempt to prevent minors under 15 from accessing social media has run into a problem that goes well beyond TikTok, Instagram, or X: to verify who is a minor, it may also be necessary to verify who is an adult. The French Constitutional Council has blocked the law scheduled to take effect on September 1, 2026, citing its restrictions on freedom of expression and communication as disproportionate, and questioning the safeguards intended to protect privacy during age verification.
The key points of age verification in 20 seconds
- France has overturned the social media ban for minors under 15 as originally designed.
- The issue affects not only minors: verifying age may require checking the age of millions of adults as well.
- Australia already allows analysis of activity, photos, voice, connections, and even location signals.
- Europe calls for systems that are proportional and as non-intrusive as possible.
- The debate involves protecting children, anonymity, privacy, and internet access control.
Thus, the French ruling introduces a tricky technical and legal issue. One thing is legally establishing that a minor cannot use a certain service, and another is building the infrastructure to permanently demonstrate that each person trying to access is of the permitted age.
The European Data Protection Board (EDPB) had already warned about this problem. Its position does not reject age verification outright, but states that it must use the least intrusive method possible and protect users’ personal data.
This distinction is crucial because, under the seemingly simple phrase “age verification,” very different technologies are used: from a credential certifying someone is over a certain age to identity documents, facial recognition or estimation, and automated behavior analysis.
The technical problem: proving you’re 16 without proving who you are
The ideal solution would be straightforward: a platform asks if a user is over a certain age and receives only an answer like “yes, they are over 16”, without knowing their name, date of birth, ID, address, or any other data.
Technically, systems based on this principle can be designed using digital credentials and cryptographic proofs that reveal only the necessary attribute.
The problem arises when platforms also need to detect attempts to circumvent the prohibition.
Australia permits monitoring how far this model can go. Starting from December 2025, certain platforms must adopt reasonable measures to prevent minors under 16 from maintaining accounts. The eSafety regulator makes clear that simply entering a date of birth is no longer sufficient.
Platforms may use signals such as:
- Account age and user behavior;
- Language used and content interacted with;
- Facial analysis of photos and videos;
- Age estimation via voice;
- Patterns of activity compatible with school hours;
- Relationships with other users that seem to be minors;
- Membership in youth-oriented communities;
- IP addresses, GPS location, device language, and timezone;
- Terminal identifiers, phone number, and system configuration.
The declared goal is to detect minor accounts and prevent evasion mechanisms, including forged documents, AI-manipulated content, or VPNs. But the technical outcome could also be a system capable of analyzing users more deeply, even if they haven’t committed any infractions.
This significantly changes the scope of the debate.
A regulation designed to control minors could end up incentivizing platforms to know even more about all their users.
From a birthdate to analyzing face, voice, IP, and behavior
Until recently, creating an account by simply entering a birthdate was common. It was an easy system to deceive but also minimally intrusive.
If governments make platforms legally responsible for preventing minors from accessing, that simple field is no longer enough.
The platform needs additional evidence.
They can request a document. They can use an external identity verification provider. They can estimate age via a photograph. Or they can infer it by observing behavior.
Each alternative introduces different risks.
Providing a document allows for reasonably accurate verification of a birthdate but turns everyday internet access into an operation linked to civil identity.
Facial estimation avoids necessarily knowing the name but requires biometric processing or image analysis and introduces margins of error.
Behavioral analysis is even more peculiar. Deciding whether someone seems to be 14 or 25 might require observing what they consume, when they connect, how they write, whom they chat with, or what photos they post.
Australia explicitly recognizes several of these signals within its system. Even a user who has already passed a verification can be reassessed if later signs suggest they might be under 16.
In other words, verification can shift from a one-time check during account creation to an ongoing assessment.
The paradox: protecting minors’ privacy by gathering more information
There is also a significant contradiction that cannot be ignored.
Much of the recent European digital regulation aims to limit the collection of personal data and reduce citizen tracking. But implementing certain age restrictions may actually require new identification, inference, or classification mechanisms.
The EDPB itself emphasizes that age verification must respect principles like necessity, proportionality, and data minimization. The system should process only the strictly necessary information to achieve its goal.
This issue has also reached the European Parliament. A parliamentary question submitted in March 2026 warned about the risks of using identity documents, facial recognition, and external verification providers, both in terms of privacy and the potential for databases to be compromised.
That does not mean every age verification system necessarily entails mass surveillance.
Architectures exist that are specifically designed to prevent this. The European Commission is working on solutions where the service can verify that someone is over a certain age without necessarily receiving their full identity.
Much of the technological debate should focus on not just verifying age but on what the verifier learns during the process and what information it retains afterward.
Spain will face the same challenges
Spain also aims to implement a similar barrier for minors under 16. So, sooner or later, it will have to confront the same questions that arose in France.
Who verifies the age?
Is it the social network, an external company, or a government infrastructure?
Is identification necessary?
Can facial recognition be used?
Is the result stored?
Can the same credential be used across different services?
Can this verification later be linked to the user’s activity?
These technical questions are almost as important as the age cutoff itself.
Because verifying age and identifying a person should not automatically be the same operation.
A well-designed system should be able to tell a website that someone is of a certain age without providing additional information. The service should only know “over 16,” not necessarily their name, address, or exact date of birth.
This principle will be especially relevant if controls extend beyond social media.
Once an infrastructure for verifying millions is in place, it can technically be reused for other services: adult content, video games, e-commerce, apps, certain audiovisual content, or any category that future legislation might restrict by age.
This raises the risk of function creep: a technology created for a specific purpose might end up being used for many others. That is precisely why legal and technical safeguards should be established before broad deployment.
Australia demonstrates the system’s potential growth
Australia offers a particularly interesting example because its prohibition for minors under 16 is already operational.
Facebook, Instagram, Snapchat, Threads, TikTok, Twitch, X, YouTube, Kick, and Reddit must implement measures to prevent accounts from users under that age.
The Australian system seeks safeguards. The government does not require users to rely solely on an official document or government digital ID, and platforms must offer reasonable alternatives. Additionally, data collected for age verification cannot be freely used for other purposes like advertising.
But its operation illustrates the complexity of the issue.
If a minor can lie about their birthdate, alternative signals are needed. If they use manipulated documents, it must be checked. If they connect via a VPN, the real connection point must be determined. If they pass initial checks, behavioral analysis can be used later to flag inconsistencies.
Each layer designed to prevent evasion may require another layer of user information.
And the more effective the system is meant to be, the greater the temptation to monitor.
Protecting minors without creating a fully identified internet
The French ruling does not resolve the European debate but introduces a significant boundary. Protecting minors is a legitimate goal; however, that doesn’t automatically mean any method used to achieve it is proportionate.
France now needs to rewrite its legislation. President Emmanuel Macron has tasked Prime Minister Sébastien Lecornu with preparing a new text that considers constitutional objections, aiming to have it ready before spring 2027.
For the tech sector, the discussion should go beyond the usual clash between governments and social media companies.
The issue directly involves digital identity, cryptography, biometrics, data protection, anonymity, cybersecurity, and internet architecture.
The key question isn’t just whether a 14-year-old should have access to TikTok.
It’s also about deciding whether, to prevent that, millions of adults will have to prove they are adults first, what information they will need to provide, and who can keep it.
Australia’s experience shows that truly enforcing age restriction can require much more than just checking a birthdate. France has just reminded us that there is a constitutional boundary between protecting and controlling.
Technology can help build systems that verify attributes without turning every internet access into a full personal identification. If Europe chooses to extend age barriers, that distinction will be crucial to prevent a policy aimed at minors from resulting in an permanent verification infrastructure for all users.
Frequently Asked Questions
Why did France block the social media ban for minors under 15?
The Constitutional Council considered that the proposed system disproportionately restricted freedom of expression and communication, and that the safeguards related to age verification and privacy were insufficient.
Does verifying age require showing a ID?
Not necessarily. Credentials and other mechanisms can be used to prove only that a person is above a certain age. The system’s design determines how much personal data is ultimately revealed.
Can a social network analyze photos or behavior to estimate age?
Yes. Australia considers signals that include facial analysis of photos and videos, voice, behavior, social connections, activity, IP address, and certain device data to identify potential users under 16.
What is the main privacy risk?
The risk that an obligation initially meant to prevent minors from accessing services leads to widespread mechanisms for identifying, inferring, or tracking adult users. That’s why European data protection authorities emphasize necessity, proportionality, and data minimization.

