The Road to the Surveillance State Is Paved With Good Intentions
A radical new model for internet governance is being fast-tracked through France's National Assembly. The government has decreed that children under fifteen must be barred from social media. The idea has obvious merit, given the toxic and hellish landscape of corporate social media. The side-effect, however, is that from September this year anyone in France attempting to post a cat meme will have to prove their age to the state’s satisfaction. The result is a digital identity checkpoint before you're allowed to speak online.
Political momentum for similar legislation is now building with predictable haste in Spain, Portugal, the United Kingdom, Greece, and Ireland, all taking their cues from an earlier Australian experiment. The French legislation serves as a blueprint for a fundamental reshaping of the European internet, and one that Ireland will enthusiastically push for during its EU council presidency later this year.
The irony is painful. The UK government abandoned plans to create digital ID cards for accessing public services just months ago after a public revolt. Now it wants to forge ahead with digital ID cards for your thoughts instead, slipping the same infrastructure past critics by wrapping it in the sacred cause of child protection.
And let's be clear about the context: as French and British authorities have aggressively cracked down on social media posts critical of Israel's destruction of Gaza by demanding platforms hand over user identities and removing content en masse, the chilling effect of mandatory identification isn't theoretical. It's already here. Add a layer of universal verification on top of that precedent, and anonymity evaporates. The whistleblower, the dissident, the citizen sharing unfiltered outrage, all become much easier targets.
Surveillance isn’t a side-effect, it’s the point
The French law is a textbook exercise in political judo: using moral panic to legitimise infrastructure that, as the Electronic Frontier Foundation warns, excels at "surveillance, censorship and exclusion." Blanket bans and identity gates are authoritarian responses to a complex social problem, and they solve nothing. Teens barred from Instagram don't vanish from the social internet; they go elsewhere.
There's no shortage of potential solutions. We could force platforms to disable their addictive algorithms and to remodel their user intefaces for children. We could mandate, as Chinese platforms do in their "youth modes", limited access times and that a substantial share of content served to young users be educational or creative rather than optimised for frenzied engagement. We could fund digital literacy and family support and mental health services, equipping young people with the skills they need instead of just locking them out of the digital world completely.
In France and Spain they keep talking about regaining "digital sovereignty" and taking back power from the tech oligarghs but if that means anything, it should mean building open, public-service alternatives. Open platforms that are designed for human flourishing and where parents can direct their children instead. One path creates a controlled corridor that leads to the same toxic place; the other attempts to cultivate a healthier landscape altogether.
But in a final twist of self-sabotage, the nuclear option our governments are choosing hands more power to the foreign tech oligarchs they claim to oppose. Rather than fostering native, open-source alternatives that might actually break Big Tech's grip, the European solution outsources the machinery of control to Meta, Google, and X, making them the state-mandated gatekeepers of European civic life.
Where does it end?
A fourteen-year-old in Marseille, barred from TikTok, fires up a VPN. A journalist in Dublin, wary of handing her passport details to Mark Zuckerberg, migrates to a Mastodon instance in Finland. An activist in London posts under a pseudonym on Nostr, where no central entity exists to enforce identity checks.
What's the state's next move in the name of child protection?
Do we order national firewalls to block decentralised platforms that refuse to play identity cop? Do we ban the VPNs that puncture this digital border? This isn't speculation: the UK's Online Safety Act guidance already contemplates requiring platforms to "take proportionate steps" to prevent circumvention, including restricting VPN access.
This is the authoritarian spiral. Each layer of control begets the need for a deeper, more invasive one. The initial “simple” ban demands universal surveillance. The surveillance depends on the elimination of workarounds. The workarounds justify the policing of privacy tools and decentralised networks.
Age verification mandates are already in effect across the web, often demanding sensitive documentation from users. And this data is not held as securely as you might think. Discord, an instant messaging platform, has had to apologise (too little, too bloody late!) after a breach leading to the disclosure of tens of thousands of users' photo IDs and other very sensitive information. But it hasn't forced a rethink. They're forging ahead with a global age verification mandate from next month.
"There should be no right trumping the right of a child to be protected online." Patrick O'Donovan, Minister for Communications
This isn't child protection. It's security theatre that will fail the children it claims to shield, potentially driving them underground to less safe spaces, while succeeding spectacularly at its unstated goal: installing a universal identity layer over European speech.
Once the infrastructure exists to verify your age, it exists to verify your identity. And once your identity is linked to your words, the state (or the corporation that holds the keys) can silence you with a keystroke. First they came for the fifteen-year-olds. But the architecture they're building doesn't stop there. It never does.