The EU Says 'Child Safety'. The Reality is Mandatory ID Verification for Every Adult.
A new European proposal aims to protect children online, it started with social media and now expands to AI assistants. It would require every adult to verify their identity to use basic AI chatbots. Here is why mandatory age gates threaten digital privacy and how xPrivo is fighting back.
Just imagine you open your laptop to ask an AI assistant something. You want a quick answer for a basic problem that you know can be answered quickly and good by an AI. It can also be something personal, like a symptom you're scared of. A legal problem you're embarrassed about. A draft or business idea you're not ready to show anyone. Before you can type a word, a government app on your phone has to confirm you're old enough to be trusted with your own thoughts.
That's not a dystopian imagination for a science fiction novel because the plan the European Commission presents exactly this proposal on Thursday (17th September), under a name built to sound unobjectionable: the EU Kids Act.
This now affects us too! xPrivo is a European company, built by Europeans, for people who want to use AI without giving up their privacy. It's a strange feeling to watch the same union we operate in and believe in, propose the thing that could break the product we built for its citizens. We built xPrivo on one belief: nobody should need permission to ask AI for help or ask simple questions, and nobody should need to prove who they are just to use the internet.
What the EU Kids act will be about
Leaked drafts, confirmed by POLITICO, Bloomberg, Reuters and Euractiv over the past week, lay out an age ladder. Accounts run entirely by parents under 13. Restricted "introductory" accounts from 13 to 15. Full independence from 15 on. The same ladder covers social media, video platforms, games, and AI chatbots, with a narrow carve-out for strictly educational tools. Companies will also pay a new fee to bankroll Brussels's enforcement machine. Look past the press release, and the mechanism is simple. To prevent children under the age of fifteen from accessing the app, every user, including adults, must first be verified. Adults need to confirm their age with a digital ID or face scan each time they want to use a restricted app under the EU Kids Act. Read these sentences again. It sounds a little different from "protect children online", doesn't it?
Brussels knows the privacy objection is coming, so it built an answer: a verification app using zero-knowledge proofs, designed to confirm your age without exposing your identity and without leaving a trail of where you've used it. Impressive engineering, right? Also beside the point for most of the internet, because building that system is expensive and slow, and the Act reportedly lets platforms use other age-verification technology from public authorities or private vendors, as long as it clears a "privacy and security standard". That clause is an open invitation. Any company unwilling to build its own privacy-grade system can just reach for a third party instead: outfits like Persona, AU10TIX, Sumsub, Veriff, or IDmerit, whose entire business is scanning your passport, your driver's license, and your face, then holding onto the file. We don't have to guess how that goes, because it's already happened, repeatedly. AU10TIX, the verifier behind TikTok, Uber and X, left admin credentials exposed for over a year, handing anyone who found them a direct line to names, birth dates, ID numbers, and document photos. Persona, one of the largest identity verification vendors and the one processing age checks for Reddit and other platforms complying with age-verification laws, suffered its own breach in October 2025, then had internal government-dashboard code exposed again in February 2026. IDmerit left close to a billion KYC records sitting on an unsecured database. Sumsub sat on an 18-month-old intrusion before finally disclosing it. None of this is a worst-case hypothetical scenario. The identity-verification industry is used to this, and the EU Kids Act is about to hand that industry a captive market of every internet user in Europe. Even Anthropic, the company behind Claude, already routes parts of its own identity verification through Persona, collecting a government ID and a live selfie. Users can't independently verify what happens to the data once it's collected, nor can they confirm whether it will be linked to their account for "safety" reasons. In any case, if a company founded by AI researchers chooses to outsource identity checks to a vendor with a history of breaches, it's reasonable to assume that most companies racing to meet a Brussels deadline will do the same, if not worse.
xPrivo is loved by its thousands of daily users across the globe because it doesn't ask for anything. It works because you don't need a profile or an email address tied to your chat history. You don't even need an account to ask the AI simple questions. A mandatory identity checkpoint in front of the chat box instantly eliminates the anonymity and ease of use of the platform. Asking questions and getting work done should not be protected by a identity checkpoint. Period.
A parenting job, outsourced to Brussels
Nobody credible wants toddlers doomscrolling. However, deciding when a child gets a phone, who they talk to, and how long they're online is a parent's responsibility, not the job of a commission that treats a chatbot, which can be used to learn new things, the same as TikTok. This law won't make parents better at parenting. It will only make every adult prove that they're not fourteen.
Freedom was the whole point
The internet was supposed to be the one place you could ask a question, read something, or talk something through without anyone standing at the door checking papers. That default is what's actually on the table this week: whether looking something up or asking an assistant for help stays a right you simply have, or becomes a privilege you first have to qualify for. A society that requires ID for simple, harmless things doesn't get safer. Every checkpoint you add teaches people that access is conditional, that someone else decides whether they're allowed in, and that privacy is a favor rather than a baseline. Privacy and freedom aren't features we bolt onto a product. They're the reason a product like xPrivo needs to exist at all.
The safety plan that undercuts itself
Powerful AI models can already run offline on ordinary laptops with no operator or guardrails. If you lock the front door on hosted, moderated assistants, some teenagers won't wait until they're fifteen. They'll find a stripped, uncensored model running locally instead, where nobody is watching. Just take a look at the Qwen3.8-27-Uncensored AI model. There are plenty of tutorials on how to set up this model on your MacBook and it can even run with the open-source offline xPrivo. A privacy-respecting assistant with real safeguards is safer than an offline model without brakes. Bolting the front door while leaving the side door open isn't safety by design. It's just for show and will fail the first week it meets actual teenagers.
Where xPrivo stands at the moment
There are no stored profiles. Your conversations are not linked to your identity. There's no third-party vendor holding your passport photo in a database with a history of breaches. We're also pushing harder into open-source, offline tools so that, even if Brussels gets its way, there will be a version of xPrivo that never has to ask for permission to exist. The vote hasn't happened yet, but we must fight for privacy and freedom. Privacy is a human right.
Begin a private chat with xPrivo: https://www.xprivo.com/